基于SIEM的APT检测与防御体系研究  被引量:4

Research on APT detection and defense system based on SIEM

在线阅读下载全文

作  者:李艳斐 李斯祺 Li Yanfei;Li Siqi(The First Research Institute of the Ministry of Public Security,Beijing 100046)

机构地区:[1]公安部第一研究所,北京100048

出  处:《网络空间安全》2018年第6期16-19,25,共5页Cyberspace Security

摘  要:高级持续性威胁(简称APT)是目前面临的最严重的安全威胁,在整个攻击过程中,攻击者会投入大量的人力、财力以及时间,同时还会运用社工以及大量的0day,执行目的明确地针对型攻击,尤其是利用恶意代码,建立加密控制通道,窃取或篡改关键数据。如果被攻击者不具备实时检测与防御的能力,一旦业务系统被成功入侵,将遭受非常严重的经济和业务损失。论文阐述了APT攻击的典型特点和生命周期,以及对企业和组织可能造成的威胁,介绍了APT常见的攻击渠道和技术环节,以及抵御APT攻击面临的技术难题和挑战。为解决这些问题,提出了基于下一代SIEM(安全信息和事件管理)的APT检测与防御体系,将所有安全设备、终端和应用中的日志事件和网络流数据整合起来,实施规范化和关联处理,识别APT攻击特征,从而实时检测和抵御APT攻击,保障业务系统的网络安全,降低业务数据被盗取和篡改的风险。Nowadays, Advanced Persistent Threat is the most serious security threat. In APT attacks, attackers will invest a lot of manpower, financial resources and time. At the same time, they will use social engineering methods and a large number of zero-day vulnerability attacks, which aims specifically at targeted attacks, especially using malicious code and establishing an encrypted control channel, stealing or tampering key data. If the attacked targets does not have the ability of real-time attack detection and defense, once the business system is successfully intruded, it will suffer very serious economic and business losses. This paper describes the typical characteristics and life cycle of APT attacks, as well as the possible threats to enterprises and organizations, and introduces the common attack channels and technical links of APT, as well as the technical difficulties and challenges in resisting APT attacks. To solve the above problems, an APT detection and defense system based on next generation SIEM (Security Information and Event Management) is proposed, which integrates log events and network flow data of all security devices, terminals and applications, to implement normalization and association processing. Finally the characteristics of APT attacks need to be identified, which can help detecting and resisting APT attacks in real time to ensure the network Security of business systems, and reducing the risk of theft and tampering of business data

关 键 词:APT攻击 下一代SIEM 分层防御 端到端策略 动态数据模型 

分 类 号:TP393.0[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象