计算机与现代化 ›› 2017, Vol. 0 ›› Issue (3): 65-.doi: 10.3969/j.issn.1006-2475.2017.03.014

• 信息安全 • 上一篇    下一篇

#br# 基于威胁情报共享的安全态势感知#br# 和入侵意图识别技术研究

  

  1. 南瑞集团公司,江苏南京210003
  • 收稿日期:2016-07-13 出版日期:2017-03-29 发布日期:2017-03-30
  • 作者简介:李炜键(1984-),男,江苏武进人,南瑞集团公司工程师,本科,研究方向:网络安全,数据安全,监控预警; 金倩倩(1986-),女,浙江宁波人,工程师,硕士,研究方向:工控安全, 数据安全,监控预警; 郭靓(1985-),男,江苏淮安人,工程师,研究方向:网络空间安全,威胁情报,监控预警。

Research on Security Situation Awareness and Intrusion Intention#br# Recognition Based on Threat Intelligence Sharing

  1. NARI Group Corporation, Nanjing 210003, China
  • Received:2016-07-13 Online:2017-03-29 Published:2017-03-30

摘要:

随着以云计算、物联网、大数据为代表的“互联网+”技术大量引入,电网的信息安全暴露面在迅速增加,为了应对电网安全防护的严峻挑战,以威胁情报为切入点,通过共享重要的第三方情报数
据对电网安全的安全态势进行评估是及时发现异常行为,识别入侵意图的重要手段之一。本文提出威胁情报共享方法,实现安全威胁情报共享系统的设计,并提出基于威胁情报共享的安全态势感知和入
侵意图识别方法和应用实例。

关键词: 数据挖掘, 流量分析, 威胁情报, 安全态势, 入侵意图识别

Abstract:

With large scale introduction of “Internet +” technology represented by cloud computing, Internet of things, and big data, information security exposure surface of
power grid is rapidly increasing. In order to cope with the severe challenges of security protection of power grid, one of the important means is using the threat intelligence
as the starting point, through sharing important thirdparty security intelligence data on the security situation assessment of power grid to timely detect abnormal behavior,
and finally identify intrusion intention. This paper presents a method for sharing threat intelligence, realizes the design of security threat intelligence sharing system, and
puts forward the security situation awareness and intrusion intention identification method based on threat intelligence sharing.

Key words: data mining, traffic analysis, threat intelligence, security situation, intrusion intention recognition

中图分类号: