检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
出 处:《电力信息与通信技术》2016年第1期28-32,共5页Electric Power Information and Communication Technology
摘 要:为改变传统的事后防御的不利局面,企业信息安全防护体系建设思路已从被动防御逐步发展为主动防御,通过先验知识检测未知威胁,能够对未来的攻击趋势进行预测。针对更加定向、持久化和多样化的攻击模式以及更高的预测难度,文章基于情景感知理念建设了信息安全主动防御体系,结合内部和外部情报,通过攻击特征、异常业务行为匹配来感知和预测未知威胁,能够更精准地发现高级持续威胁,从而保证预警的前瞻性和准确性。To change the adverse situation of the traditional passive defense, the construction of enterprise information security protect system has been gradually developed from passive defense to active defense, which can use future knowledge to detect unknown threats and predict future attacks. For a more targeted, persistence and a variety of attack patterns and greater difficulty to forecast, this paper introduces an approach using context-aware technology to construct active defense system of information security. Considering the internal and external intelligence, matching the attack characteristics and abnormal business behavior to percept and predict unknown threats, more precisely find advanced persistent threat, this approach can ensure the prospective and accurate ability of early warning.
关 键 词:信息安全 情景感知 威胁情报 主动防御 安全事件管理
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.68