信息网络安全 ›› 2015, Vol. 15 ›› Issue (9): 245-248.doi: 10.3969/j.issn.1671-1122.2015.09.054

• 入选论文 • 上一篇    下一篇

基于大数据的公安网安全事件检测方案

戴晓苗(), 管磊, 胡光俊   

  1. 公安部第一研究所,北京 100048
  • 收稿日期:2015-07-15 出版日期:2015-09-01 发布日期:2015-11-13
  • 作者简介:

    作者简介: 戴晓苗(1984-),女,浙江,工程师,硕士,主要研究方向:网络安全;管磊(1982-),男,河南,工程师,硕士,主要研究方向:网络安全;胡光俊(1980-),男,山西,副研究员,博士,主要研究方向:网络安全。

A Solution to Detecting Security Incidents in Police Network Based on the Big Data Technology

Xiao-miao DAI(), Lei GUAN, Guang-jun HU   

  1. The First Institute of the Ministry of the Public Security, Beijing 100048, China
  • Received:2015-07-15 Online:2015-09-01 Published:2015-11-13

摘要:

文章从专用网络的APT事件说起,引出了对公安网中安全事件应对方法的思考;紧接着根据公安网的业务特点和数据优势,借助于大数据分析技术,提出了一个针对公安网的安全事件发现方案。该方案结合攻击过程和公安业务特点,构建了攻击模型和业务模型,为判别异常网络行为提供了理论依据;在人工研判机制的介入和机器学习的反复训练过程中,不断完善和优化数据模型,从而更加准确地识别未知风险和发现安全事件,并进行及时有效的干预。

关键词: 公安网, 大数据, 攻击模型, 业务模型, 图数据库

Abstract:

This paper starts from the apt incident in the private network, triggers the thinking of the solutions to security incidents of the police network. Then, according to the business characteristics and the advantage of big data of the police network, this paper presents a solution of security incident detection with big data analysis technology. The solution combined with attack process and business characteristics, constructs the attack model and the business model, which provide a intelligent analysis theory. In the artificial judgment mechanism and machine learning process, the data model could be improved and optimized, so that helping identifying unknown risks and security incidents, and early intervention.

Key words: police network, big data, attack model, business model, graph database

中图分类号: