从自卫到护卫:新时期网络安全保障体系构建与发展建议

田志宏 , 方滨兴 , 廖清 , 孙彦斌 , 王晔 , 杨旭 , 冯纪元

中国工程科学 ›› 2023, Vol. 25 ›› Issue (6) : 96 -105.

PDF (968KB)
中国工程科学 ›› 2023, Vol. 25 ›› Issue (6) : 96 -105. DOI: 10.15302/J-SSCAE-2023.06.007
网络空间安全技术体系与风险应对

从自卫到护卫:新时期网络安全保障体系构建与发展建议

作者信息 +

Cybersecurity Assurance System in the New Era and Development Suggestions Thereof: From Self-Defense to Guard

Author information +
文章历史 +
PDF (990K)

摘要

随着网络攻防技术的快速发展,网络安全保障体系面临诸多挑战,研究新型网络安全保障体系成为推进我国信息化发展的迫切需要,对进一步提升网络安全性、可用性具有重要意义。本文梳理了我国以“自卫模式”为主的网络安全保障体系的运行现状;分析了当前体系面临的“捕不全”“拦不住”“看不清”和“抓不住”四大安全问题;提出了以近身蜜点、前置蜜庭、网关蜜阵、外溢蜜洞的“四蜜”威胁感知体系为代表的“护卫模式”网络安全保障体系,包括纵深威胁感知的蜜点技术、攻击观测和判别的蜜庭技术、协同联动的蜜阵技术和网络威慑与攻击绘制的蜜洞技术等重点发展的技术任务,以及“蜜点”加持的网络安全保险产业任务。研究建议,探索“护卫模式”网络安全保障机制,全面提升国家网络安全防护水平;探索“护卫模式”安全防护技术研究和应用,实现新旧安全防护技术的融合统一;探索面向“护卫模式”的网络安全人才培养新模式,培育创新实践型网络人才,为新时期我国网络安全保障体系研究提供参考。

Abstract

The rapid development of network attack and defense technologies has posed various challenges to current cybersecurity assurance systems. Therefore, studying a new cybersecurity assurance system has become an urgent need to promote the development of information technologies and is of strategic significance for strengthening the network security and availability in China. This study summarizes the operation status of and major security challenges faced by China's current cybersecurity guarantee system that features a self-defense mode. A cybersecurity guarantee system based on a guard mode and its key technical tasks are proposed. Specifically, the tasks include honey point technology based on deep threat perception, honey court technology based on attack observation and discrimination, honey matrix technology based on collaborative linkage, and honey hole technology based on attack deterrence and mapping. Furthermore, we propose the following suggestions: (1) exploring the cybersecurity assurance mechanisms based on the guard mode to comprehensively improving the cybersecurity protection level of China; (2) exploring the research and application of security protection technologies based on the guard mode and achieving the integration of existing and new security protection technologies; (3) exploring a new talent-training model to cultivate innovative and practical professionals in the cybersecurity field.

Graphical abstract

关键词

网络安全 / 保障体系 / 威胁攻击 / 主动防御 / 护卫模式

Key words

cybersecurity / assurance system / threat / active defense / guard mode

引用本文

引用格式 ▾
田志宏, 方滨兴, 廖清, 孙彦斌, 王晔, 杨旭, 冯纪元 从自卫到护卫:新时期网络安全保障体系构建与发展建议[J]. 中国工程科学, 2023, 25(6): 96-105 DOI:10.15302/J-SSCAE-2023.06.007

登录浏览全文

4963

注册一个新账户 忘记密码

参考文献

基金资助

中国工程院咨询项目“网络安全保障体系战略研究”(2022-JB-04)

AI Summary AI Mindmap
PDF (968KB)

2933

访问

0

被引

详细

导航
相关文章

AI思维导图

/