信息网络安全 ›› 2021, Vol. 21 ›› Issue (3): 1-6.doi: 10.3969/j.issn.1671-1122.2021.03.001

• 等级保护 • 上一篇    下一篇

基于URL智能白名单的Web应用未知威胁阻断技术研究

黄长慧(), 胡光俊, 李海威   

  1. 公安部第一研究所,北京 100048
  • 收稿日期:2020-12-20 出版日期:2021-03-10 发布日期:2021-03-16
  • 通讯作者: 黄长慧 E-mail:huangch@gov110.cn
  • 作者简介:黄长慧(1981—),女,黑龙江,副研究员,硕士,主要研究方向为网络与信息安全、大型专网终端安全、网络攻防技术|胡光俊(1979—),男,山西,副研究员,博士,主要研究方向为大数据网络安全、大型专网安全纵深防御、网络攻防技术、恶意代码防范|李海威(1984—),男,河北,工程师,硕士,主要研究方向为大数据分析与应用、专网安全、主机安全和网络攻防技术

Research on Unknown Threat Blocking Technology of Web Application Based on URL Intelligent Whitelist

HUANG Changhui(), HU Guangjun, LI Haiwei   

  1. First Research Institute of the Ministry of Public Security of PRC, Beijing 100048, China
  • Received:2020-12-20 Online:2021-03-10 Published:2021-03-16
  • Contact: HUANG Changhui E-mail:huangch@gov110.cn

摘要:

在网络空间对抗不断加剧的情况下,我国各重要行业单位信息化深度发展过程中建设的大量Web应用系统的安全面临严峻考验,各行业单位防护技术及措施存在不足,急需建立有效技术防护体系。文章提出一种基于URL智能白名单的Web应用未知威胁阻断防护方案,从合规行为角度入手,以访问控制白名单和非合规行为阻断为核心,通过建立业务白名单动态模型、URL访问控制白名单,实现应对Web应用未知威胁的主动防御体系,提升我国重要行业单位Web应用系统安全防护水平。

关键词: URL白名单, 未知威胁阻断, 动态建模

Abstract:

With the increasing confrontation in cyberspace, the security of a large number of Web application systems constructed in the process of information development of important industry units in China is facing severe challenges. Protection technology and measures of various industries are insufficient, and it is urgent to establish effective technical protection system. This paper proposes an unknown threat blocking protection scheme for Web applications based on URL intelligent whitelist. This scheme proceeds from the perspective of compliance behavior, taking access control whitelist and non-compliance behavior blocking as the core. Through building dynamic model of business whitelist and URL access control whitelist, this scheme establishes an active defense system against unknown threats of Web applications which can improve the security protection level of Web application system of important industry units in China.

Key words: URL whitelist, unknown threat blocking, dynamic modeling

中图分类号: