信息安全研究 ›› 2020, Vol. 6 ›› Issue (10): 0-0.

• 信创安全专题 •    

面向国产生态的 网络安全事件运维技术研究

王妍,吕遒健,马秀   

  1. 中国科学院信息工程研究所
  • 收稿日期:2020-10-09 出版日期:2020-10-10 发布日期:2020-10-10
  • 通讯作者: 王妍

Discussion on Network Security Operation and Incident Automatic Disposal Technology for Domestic Product Ecology

  • Received:2020-10-09 Online:2020-10-10 Published:2020-10-10

摘要: 当前复杂严峻的国际形势迫切需要我国发展自主可控的基础软硬件产品及其生态产业链,日趋完善的产业链推动了网络国产化替代工程的大范围推广.长期以来,外部网络攻击以及内部威胁等网络安全事件持续发生,针对国产产品生态构建的网络,如何充分整合自主可控产业链的优势,提升网络安全运维与事件处置的能力,是网络安全运维人员关注的热点问题.本文将结合国产产品生态及其所建设网络的特点,基于先进的自动化网络运维技术手段,对网络安全运维与事件自动化处置机制关键技术进行探讨,通过构建多源数据融合管理能力以及生态内产品间协同能力,解决长期以来运维所面临的数据碎片化、事件处置效率低下等问题,实现网络内安全事件的综合分析以及快速高效的自动化响应、处置,提升国产产品生态的网络安全运维能力,增强网络的主动防御能力.

关键词: 国产生态, 网络安全运维, 事件处置, 自动化响应, SOAR

Abstract: With the increasingly complex and serious of the international situation, it’ urgent for China to develop basic software and hardware products and their ecological industrial chain based on autonomy and control. The improvement of the industrial chain has promoted the widespread promotion of network localization alternative projects. For a long time, cyber security incidents such as external cyber-attacks and internal threats have occurred frequently. It is a hot issue for network operators how to fully integrate the advantages of the independent and controllable industrial chain, and improve the ability of network security operation and incident disposal. This paper will combine the domestic product ecology and the characteristics of network construction, discuss the key technologies of network security operation and automatic event disposal mechanism technology, build multi-source data fusion between management ability as well as ecological products within the coordinated ability, solve the long-term problems of data fragmentation and low efficiency of event disposal, realize the comprehensive analysis of security incidents as well as efficient automatic response and disposal, and enhance the network security operation ability of domestic product ecology.

Key words: domestic product ecology, network security operation, event handling, automatic response, SOAR