首页> 中文期刊> 《计算机科学》 >基于开源工具集的大数据网络安全态势感知及预警架构

基于开源工具集的大数据网络安全态势感知及预警架构

         

摘要

对信息系统安全防护而言,大数据是一把双刃剑.信息量的巨增使得数据价值密度更小,给APT等攻击行为提供了更好的藏身环境;但大数据处理技术对海量数据的聚合、挖掘和分析又使得准确检测及预测攻击威胁成为可能.为增强信息系统的威胁感知与攻击预警能力,构建大数据威胁处理平台势在必行.基于最新的开源大数据组件集,构建了集数据收集整理、数据存储、离线分析发现、实时关联检测、威胁预警和态势呈现等功能于一体的、支持全流程安全事件处理过程的、完整的网络安全态势感知及预警架构,与现有同类平台架构相比,其具有高可用、可扩展、易部署等特点,且能较好地支持威胁情报的引入.%Big data is a double-edged sword for information system security protection.On the one hand,data value density decreased because of the dramatic increase in the amount of information,which provides a better shelter for attacks like APT.On the other hand,its processing technology in aggregation,mining and analysis of huge amounts of data makes it possible to identify security threats accurately.In order to strengthen the perceiving threat ability of information system,it is imperative to build a big data threat analyzing platform.Based on open source big data components,we proposed a situational awareness and threat warning platform for data collection and reduction,data storage,off-line analysis,real-time correlation,threat warning and situation awareness.Compared with existing platforms,this architecture has the advantages of high availability,scalability,and it is easy to deploy and is suitable for introducing threat intelligence.

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号