段炼, 王黎迪. Research on the evolution of critical information infrastructures defense system in actual combat[J]. 2021, 34(11): 26-31. DOI: 10.13992/j.cnki.tetas.2021.11.006.
面向实战的关键信息基础设施防御体系演进研究
摘要
本文基于攻击链模型提出了一种关键信息基础设施防御体系演进思路和实现方式
在骨干网、城域网和企业内网3个层面对网络入侵流量进行监测、分析和处置
进一步扩大关键信息基础设施的防御纵深。通过综合运用DPI、欺骗防御、大数据和旁路阻断等技术
逐层收敛告警
并以可视化的界面展示给网络安全运营人员
提升攻击事件的监测准确率
极大提升了系统整体防护效果和安全运营工作效率。
Abstract
Based on the cyber kill chain model
this paper proposes an evolutionary idea and implementation method for critical information infrastructures defense system. It monitors
analyzes and disposes of network intrusion traffic at the backbone network
metropolitan area network
and corporate intranet
which further expands the defense depth of critical information infrastructures. Through the comprehensive use of DPI
deception defense
big data
bypass blocking and other technologies
the alarms are converged layer by layer
and displayed to network security operators with a visual interface
which improves the accuracy of the monitoring of attack events
system protection effect and the effi ciency of network security operation.