信息网络安全 ›› 2017, Vol. 17 ›› Issue (2): 79-84.doi: 10.3969/j.issn.1671-1122.2017.02.012

• • 上一篇    下一篇

广电全台网统一接入平台的网络安全策略研究

蔡晶晶(), 钱晓敏   

  1. 浙江省广播电视集团,浙江杭州 310000
  • 收稿日期:2016-12-24 出版日期:2017-02-20 发布日期:2020-05-12
  • 作者简介:

    作者简介: 蔡晶晶(1991—),女,浙江,工程师,本科,主要研究方向为网络信息安全;钱晓敏(1970—),男,浙江,高级工程师,本科,主要研究方向为网络通信、数据库。

Research on the Network Security Strategy of the Unified Access Platform of Radio & TV Whole-station Network

Jingjing CAI(), Xiaomin QIAN   

  1. Zhejiang Radio & TV Group, Hangzhou Zhejiang 310000, China
  • Received:2016-12-24 Online:2017-02-20 Published:2020-05-12

摘要:

随着网络技术及其应用的快速发展,广电系统也全面启用了全台网统一接入平台作为连接电视频道节目制播网、新媒体平台以及播出中心的统一接入枢纽平台。多平台的融合在带来高效和便利的同时,也引入了网页挂马、数据被窃取、业务受攻击和内网入侵等安全威胁,因此信息数据采集、传输、处理和存储过程中的保密性、完整性和可用性等也成为广电全台网统一接入平台急需解决的安全问题。文章通过分析广电全台网统一接入平台安全管理研究现状及存在的风险,指出风险产生的主要原因,如软硬件问题、设计问题及管理问题等,并依据存在的风险及基于常规的信息安全策略提出适合全台网统一接入平台的基本安全策略。同时,在提出的基本安全策略构基础之上,文章还提出了全台网系统基础建设中物理安全、网络及边界安全、系统及应用安全、数据安全、审计安全和管理安全等具体的实施方法。

关键词: 统一接入, 平台安全, 安全策略, EAD

Abstract:

With the rapid development of network technology and its application, a new media platform and broadcast center, as an unified access platform of whole-station network to connect television program and broadcast network. Multi-platform integration brings efficiency and convenience, but also introduces new security threats such as Web Trojan, data theft, business attack and intranet intrusion, etc. Therefore, the confidentiality, integrity and availability of information in the process of data collecting, transmitting, processing and storing have become the urgent problems to be solved. In this paper, the security management status and security risks of the unified access platform for broadcasting and TV stations are analyzed. The main causes of the risks, such as hardware and software problems, design problems, and management problems, are presented. Based on the existing risks and conventional information security policies, the basic security strategies for the unified access platform are proposed. Based on the proposed basic security policies, the specific implementation methods about physical security, network and boundary security, system and application security, data security, audit security and management security are also constructed.

Key words: unified access, platform security, security policy, EAD

中图分类号: