Journal of Information Security Reserach ›› 2022, Vol. 8 ›› Issue (2): 190-.

Previous Articles     Next Articles

Research and Design of Unified Platform for Vulnerability Management

  

  • Online:2022-02-05 Published:2022-01-23

统一漏洞管理平台研究设计

刘畅;   

  1. 1 (中国邮政储蓄银行 信用卡中心 北京 100040)
  • 通讯作者: 作者介绍:刘畅,1992年,硕士研究生,工程师,主要从事信息安全。E-mail:liuchang5@psbcoa.com.cn。
  • 作者简介:作者介绍:刘畅,1992年,硕士研究生,工程师,主要从事信息安全。E-mail:liuchang5@psbcoa.com.cn。

Abstract: With the development of the network technology, information security has been paid more and more attention. As one of the most frequently used attacking methods, security vulnerability has also been widely concerned. At present, Most of the organizations or enterprises rely on manual methods to manage vulnerabilities, and do not have unified tracking、 disposition、 display and analysis. These methods are not only inefficient, but also error-prone. A unified platform for vulnerability management was proposed, which allowed the automatic closed loop controlling of the life cycle of vulnerabilities. The platform integrated different vulnerability management capabilities into specific functional modules. General development languages and standards-based service interfaces were developed to allow integration of this platform with other infrastructure platform systems or network security tools. Practices show that, this platform can effectively improve the performance of the vulnerability management, and make vulnerability management to be centralized, streamlined and automated.

Key words: network security, vulnerability, automation, life cycle, closed-loop management

摘要: 随着网络技术的发展,信息安全越来越受到人们的重视。安全漏洞做为攻击者最常利用的攻击手段之一,也受到了广泛关注。当前各大组织或企业进行漏洞管理的时候大都依赖于人工的方式,且缺乏统一的跟踪处置和展示分析,这样不仅效率较低,而且容易出错。针对这一问题,设计了一款统一漏洞管理平台,利用一体化平台实现漏洞全生命周期的自动化闭环管理,将不同的漏洞管理能力集成在特定的功能模块。同时使用通用的开发语言和标准的服务接口方便与其他基础服务平台系统或网络安全工具进行协同联动。实践表明,该平台可有效提高漏洞管理效能,实现了漏洞管理的集中化,流程化和自动化。

关键词: 网络安全, 漏洞, 自动化, 生命周期, 闭环管理