李小雪, 皇甫涛, 陈涛, et al. Study and application of telecom operators system security state baseline[J]. 2012, 25(12): 31-35. DOI: 10.13992/j.cnki.tetas.2012.12.006.
Study and application of telecom operators system security state baseline
摘要
安全基线是一个业务系统的最小安全保证
即该业务系统最基本需要满足的安全要求。本文首先提出了安全基线的内容
并把系统安全状态基线作为重点
讨论了系统文件状态基线建立的目标
并给出了创建基线和检测改变的过程。之后
提出了4种系统状态基线创建方法
并对每种方法的优劣进行了详细分析
指出了适用场景。最后
对一种开源的系统状态基线创建工具FTimes进行了介绍
并搭建测试平台实现了自动创建系统状态基线并检测改变的功能。
Abstract
ecurity baseline is the minimum security guarantee of a business system.The content of security baseline is discussed
system security state baseline and its goals are focused and presented.Proposes four mechanics of creating state security baseline of a specified system
and comparison of those techniques is made.Introduces an open source system security state baseline creating tool named FTimes
and set up a test bed to implement automation functions of creating baseline and change detection.