信息网络安全 ›› 2018, Vol. 18 ›› Issue (8): 79-85.doi: 10.3969/j.issn.1671-1122.2018.08.011

• • 上一篇    下一篇

网络安全态势感知关键技术研究及发展趋势分析

陶源1,2(), 黄涛3, 张墨涵4, 黎水林1,2   

  1. 1.公安部第三研究所,上海 200031
    2.信息安全等级保护关键技术国家工程实验室,北京100142
    3.公安部网络安全保卫局,北京100741
    4.华中科技大学,湖北武汉430074
  • 收稿日期:2018-06-20 出版日期:2018-08-20 发布日期:2020-05-11
  • 作者简介:

    作者简介:陶源(1981—),男,江苏,高级测评师,博士,主要研究方向为等级保护、大数据安全;黄涛(1982—),男,山东,博士,主要研究方向为网络安全、大数据安全;张墨涵(1995—),男,北京,硕士研究生,主要研究方向为大数据安全;黎水林(1981—),男,湖北,高级测评师,硕士,主要研究方向为信息网络安全。

  • 基金资助:
    国家重点研发计划[2018YFB0803503]

Research and Development Trend Analysis of Key Technologies for Cyberspace Security Situation Awareness

Yuan TAO1,2(), Tao HUANG3, Mohan ZHANG4, Shuilin LI1,2   

  1. 1. The Third Research Institute of Ministry of Public Security, Shanghai 200031, China
    2. National Engineering Laboratory for Key Technology of Classified Information Security Protection, Beijing 100142, China
    3. Cyber Security Bureau of Ministry of Public Security, Beijing 100741, China
    4. Huazhong University of Science and Technology, Wuhan Hubei 430074, China
  • Received:2018-06-20 Online:2018-08-20 Published:2020-05-11

摘要:

文章阐述了网络安全态势感知是当前保护关键信息基础设施和重要信息系统的重要手段和重点发展方向。通过研究分析APT攻击的技术特点,以及云平台和大数据平台的安全风险,文章得出了需要从可视、可知、可管、可控、可溯和可预警这6个方面来实现网络安全态势感知。文章综合研究了国内外网络安全态势感知系统的技术现状,分析了网络安全数据源采集、数据分析,以及网络态势评估、网络威胁评估和网络态势预测等主要功能和关键技术,得出了网络安全态势感知系统的未来发展趋势是深度融合大数据和人工智能技术,其基础设施应该是动态扩展的并能提供精准预测和防御处置建议。文章对于网络安全态势感知系统的研发、建设、测评和监管都具有很好的指导意义。

关键词: 网络安全, 态势感知, 云计算, 大数据

Abstract:

The article expounds that cyberspace security situational awareness is an important means and key development direction for protecting critical information infrastructure and important information systems. By analyzing the technical characteristics of APT attack, and the security risk of cloud platform and big data platform, a conclusion is got that the cyberspace security situation awareness needs to be realized from five aspects: visibility, knowable, manageable, controllable, traceable and early warning. The domestic and foreign technical status of cyberspace security situation awareness system is researched comprehensively. The main functions and key technologies of network security data source, big data analysis, cyberspace situation assessment, cyberspace threat assessment and cyberspace situation prediction are analyzed, and the future development trend of cyberspace security situation awareness system is obtained. With the integration of big data and AI technology, the infrastructure of cyberspace security situation awareness system should be dynamically expanded, and the accurate prediction and defense disposal recommendations can be proved. So that good guiding significance is proved for research, development, evaluation and supervision of cyberspace security situation awareness system.

Key words: cyberspace security, situation awareness, cloud computing, big data

中图分类号: