王姗姗, 曹鹏. Building service security system covering "terminal, pipe and cloud"[J]. 2017, 30(8): 26-31. DOI: 10.13992/j.cnki.tetas.2017.08.006.
构建覆盖“端管云”的业务保障系统
摘要
随着移动化、云化、物联网的发展
业务安全呈现出边界模糊
环境不受控
数据攻击
攻击手段隐蔽等特点
传统老三样在新攻击形式下漏洞百出
单项技术无法保护业务安全
外挂作弊、二次打包、应用仿冒、病毒木马、恶意吸费、系统入侵攻击等问题严重
因此
业务安全防护必须端到端系统化。本文设计并提出了端到端业务保障系统
通过"端侧安全组件+云端安全网关"的端云联动架构
提供应用安全、通道安全、数据安全、主机及系统安全等核心安全能力
为移动互联网及物联网等领域业务安全提供全周期保护。
Abstract
With the development of mobile
cloud and Io T
the security of services is characterized by unclear boundary
uncontrolled environment
data attack and so on. The traditional ways of defense face serious problem while lots of new attacks appearing. Individual technology isn’t able to protect service security. Service systems face a lot of serious problem such as plug-in cheating
identity counterfeiting
trojan virus
system intrusion and so on. So service security must be protected covering terminals
pipe
and cloud. service security system covering "terminal
pipe
and cloud" is designed and put forward in this paper. Based on the framework including security component deployed in the terminal side and the security gateway deployed in the cloud side
the security mechanisms such as application security
channel security
data security
host and system security and so on are provided to the consumers’ service systems
in order to protect the full cycle security of mobile internet services
Io T services and other areas of service and so on.