信息安全研究 ›› 2020, Vol. 6 ›› Issue (1): 85-90.

• 技术应用 • 上一篇    下一篇

大数据环境下情报驱动的网络安全漏洞管理

郭锡泉1,陈香锡2   

  1. 1. 清远职业技术学院
    2. 清远市网络空间安全工程技术研究开发中心
  • 收稿日期:2020-01-14 出版日期:2020-01-15 发布日期:2020-01-14
  • 通讯作者: 郭锡泉
  • 作者简介:郭锡泉,1979年生,博士,副教授,主要研究领域网络安全技术、信息安全管理. 陈香锡, 1997年生,大专,Web安全工程师,主要研究领域Web安全.

IntelligenceDriven Network Security Vulnerability Management in the Big Data Environment

  • Received:2020-01-14 Online:2020-01-15 Published:2020-01-14

摘要: 研究大数据环境下情报在网络安全漏洞管理中的应用.分析组织进行网络安全漏洞管理的方法和相关的情报资源,指出当前存在不重视漏洞管理、不重视漏洞情报和忽视大数据特点的弊端.提出情报驱动的网络安全漏洞闭环管理机制,构建大数据环境下情报驱动的网络安全漏洞管理框架.校园网的应用实践表明,该框架是有效的,充分发挥了情报的作用和价值.

关键词: 大数据, 网络安全, 情报, 漏洞管理, 威胁情报, 漏洞数据库

Abstract: The purpose of this paper is to study the application of intelligence in network security vulnerability management under big data environment. The methods and related information resources of network security vulnerability management are analyzed, and the disadvantages of ignoring vulnerability management, vulnerability information and big data are pointed out. The intelligencedriven closedloop management mechanism of network security vulnerabilities is proposed, and the intelligencedriven network security vulnerability management framework in big data environment is constructed. The application practice of campus network shows that the framework is effective and gives full play to the role and value of intelligence.

Key words: big data, network security, intelligence, vulnerability management, threat intelligence, vulnerability database