信息安全研究 ›› 2020, Vol. 6 ›› Issue (9): 0-0.

• 学术论文 •    

一种基于流量与日志的专网用户行为分析方法

张建平,李洪敏,贾军,卢敏   

  1. 中国工程物理研究院总体工程研究所
  • 收稿日期:2020-09-10 出版日期:2020-09-10 发布日期:2020-09-12
  • 通讯作者: 张建平

A Method of User Behavior Analysis Based on Network Flow and Log in Private Network

  • Received:2020-09-10 Online:2020-09-10 Published:2020-09-12

摘要: 专用网络中的用户行为监管是保障专用网络信息安全的重要手段。针对专用网络中单一依靠网络流量和终端安全软件日志进行分析存在的片面性问题,结合网络流量分析、网络安全态势分析、用户画像和用户行为分析等技术,提出一种基于流量与日志的分析方法。通过系统架构,从基础平台层、数据分析层和展示层进行了实现。结合专网网络监管的核心需求,通过改进专用中用户终端安全软件的监测方法,设计核心资产异常流量的监控策略、异常终端流量的监控策略、运维流量的监控策略、构建用户关键行为的数据画像,实现了专用中用户关键行为监测的系统。在实际专用网络中的应用表明,该方法能够有效监测专用网络的用户关键行为,可为专用网络的用户行为监管提供借鉴作用。

关键词: 用户行为分析, 网络流量分析, 专用网络, 安全态势, 用户画像

Abstract: The supervision of user behavior in private network is an important means to ensure the information security. In view of the one-side problems existing in the private network solely relying on the network flow and the terminal security software log, we propose a method based on the traffic and log analysis, combining with the technology of network flow analysis, network security situation analysis, user portrait and user behavior analysis. Through the system architecture, we implement a system from the basic platform layer, data analysis layer and display layer. Combined with the core requirements of private network supervision, by improving the monitoring method of user terminal security software in private network, we realize a monitoring system of users' key behaviors in private network. The core function of the system is to monitor the abnormal flow of core assets, operation and maintenance flow, and build the data portrait of users' key behaviors. The application in the real private network shows that this method can effectively monitor the key user behavior of the private network, and provide reference for the user behavior supervision other private networks.

Key words: User Behavior Analysis, Traffic Analysis, Private Network, Situation Awareness, User Profile