电信科学 ›› 2022, Vol. 38 ›› Issue (7): 184-189.doi: 10.11959/j.issn.1000-0801.2022133

• 工程与应用 • 上一篇    

电力企业网络安全威胁情报管理体系的研究与实践

陈伟雄1, 杨晓晨2, 春增军1, 李若兰3, 张华1   

  1. 1 中广核智能科技(深圳)有限责任公司,广东 深圳 518026
    2 上海中广核工程科技有限公司,上海 200241
    3 中国广核集团有限公司,广东 深圳 518026
  • 修回日期:2022-03-14 出版日期:2022-07-20 发布日期:2022-07-01
  • 作者简介:陈伟雄(1974- ),男,中广核智能科技(深圳)有限责任公司高级工程师,主要从事网络安全情报、网络安全态势感知研究等工作
    杨晓晨(1963- ),男,上海中广核工程科技有限公司高级工程师、副总工程师,主要从事网络安全与数字化转型规划、网络安全演习技术研究工作
    春增军(1973- ),男,博士,中广核智能科技(深圳)有限责任公司研究员级高级工程师,主要从事网络安全架构与网络安全技术研究工作
    李若兰(1982- ),女,中国广核集团有限公司高级工程师,主要从事网络安全等保测评、应急演练等工作
    张华(1980- ),女,中广核智能科技(深圳)有限责任公司工程师,主要从事网络安全管理、网络安全管理平台设计开发等工作

Research and practice of network security threat intelligence management system for power enterprise

Weixiong CHEN1, Xiaochen YANG2, Zengjun CHUN1, Ruolan LI3, Hua ZHANG1   

  1. 1 CGN Intellgent Technology Co., Ltd., Shenzhen 518026, China
    2 Shanghai Engineering Science &Technology Co., Ltd., Shanghai 200241, China
    3 China General Nuclear Power Corporation, Shenzhen 518026, China
  • Revised:2022-03-14 Online:2022-07-20 Published:2022-07-01

摘要:

网络安全是国家安全的重要组成部分,网络安全威胁情报工作成为网络安全防护工作重要内容,针对电力企业开展网络安全威胁情报来源多、种类多、范围广、漏洞风险多、涉及部门和人员多等问题,提出了电力企业网络安全威胁情报工作方案,方案包括情报来源、情报研判、情报处置、情报平台、情报绩效 5 个方面,设计了网络安全漏洞评估方法、情报标准化处理流程、情报绩效评价方法。初步应用结果表明该方案对提升电力企业网络安全情报应急处置能力、网络安全防护能力水平具有重要参考价值。

关键词: 网络安全, 威胁情报, 漏洞评估, 绩效评价

Abstract:

Network security is an important part of the national security, and network security threat intelligence work has become an important part of the network security protection.Aiming at the problems of power enterprise carrying out network security threat intelligence, such as many sources, many types, wide range, many vulnerability risks, many subordinate departments and personnel, the network security threat intelligence work plan of power enterprise was put forward.The scheme includes five aspects: information source, information research and judgment, information disposal, information platform and information performance.The evaluation method of network security vulnerabilities, information emergency disposal process and information performance evaluation method were puts forward.The preliminary application results show that the proposed scheme has important reference value for power enterprise to improve the emergency response ability of network security information and the level of network security protection ability.

Key words: network security, threat intelligence, vulnerability assessment, performance evaluation

中图分类号: 

No Suggested Reading articles found!