电信科学 ›› 2013, Vol. 29 ›› Issue (8): 49-55.doi: 10.3969/j.issn.1000-0801.2013.08.008

• 专题:业务平台安全 • 上一篇    下一篇

电信系统业务安全架构研究

李洪,渠凯   

  1. 中国电信集团公司网络运行维护事业部 北京 100032
  • 出版日期:2013-08-15 发布日期:2017-06-21

Research on Telecommunication System Business Security Architecture

Hong Li,Kai Qu   

  1. Network Operation & Maintenance Division,China Telecom Corporation,Beijing 100032,China
  • Online:2013-08-15 Published:2017-06-21

摘要:

对业务安全的概念进行了深入分析与研究,提出了广义和狭义业务安全的概念。广义业务安全将业务安全系统分为五大层次并定义各层网络安全要素和安全要求,狭义业务安全则聚焦于业务系统应用层的安全,是研究重点,主要包括应用层通用安全漏洞和业务逻辑漏洞两方面,并对这两方面进行定义和深入分析。针对狭义业务安全,首次提出了面向业务系统全生命安全周期的安全架构,该安全架构对业务系统的设计和实现具有很好的指导意义。

关键词: 电信系统业务安全, 狭义业务安全, 安全架构

Abstract:

The concept of service security was thoroughly analyzed,and the generalized and narrow business security was proposed.The generalized business safety system was divided into five layers,and network security and safety requirements were defined,meanwhile the narrow business security was focused on the security of application layer,which was the concentration of the research.The security of application layer mainly includes two aspects:common vulnerabilities and loopholes in the service logic,which are defined and researched intensively.A security architecture against the security problem of the business-oriented system,and the security architecture taken as a better guideline for the design and implementation of business systems were proposed.

Key words: telecom system business security, narrow business security, security architecture

No Suggested Reading articles found!