首页 | 官方网站   微博 | 高级检索  
     

铁路网络安全态势感知平台方案研究
引用本文:董鹏,马小宁,高明星.铁路网络安全态势感知平台方案研究[J].铁路计算机应用,2020,29(4):50-54.
作者姓名:董鹏  马小宁  高明星
作者单位:1. 中国铁路信息科技有限责任公司, 北京 100038;
基金项目:铁路总公司科技研究开发计划课题(2017X004-B,J2018X005)
摘    要:研究基于大数据的网络安全态势感知技术在铁路行业的应用,使铁路信息网络具有全面感知、主动预警的能力是当前铁路网络安全建设的重点任务之一。为此,需要解决目前由于无法及时监测和感知信息网络中所存在的安全风险而导致的应用系统发展受限问题;解决传统网络安全态势感知平台由于实际网络环境中数据处理量巨大、业务复杂、层次套叠所导致的误报警率高、易遗漏报警等问题。以大数据高速存取为基础,利用人工智能和并行处理等技术优化感知预测算法,提出适于铁路行业应用的网络安全态势感知平台解决方案,并在测试环境中进行测试验证。结果表明:在具有高通量、复杂化特点的铁路信息网络环境中,该解决方案对潜在安全风险的感知和发现能力优于传统网络安全态势感知平台,满足铁路信息网络高通量、高实时性响应要求,有效地降低误报警率,提升了报警质量和水平。

关 键 词:网络安全    态势感知    铁路信息系统
收稿时间:2019-09-30

Research on railway network security situation awareness platform
Affiliation:1. China Railway Information Technology Co. Ltd., Beijing 100038, China;2. Research and Application Innovation Center for Big Data Technology in Railway, China Academy of Railway Sciences Corporation Limited, Beijing 100081, China
Abstract:It is one of the key tasks of current railway network security construction to study the application of network security situation awareness technology based on big data in railway so as to endow the railway information network with the ability of comprehensive awareness and proactive early warning. Therefore, it was aimed to solve the lack of timely surveillance and awareness over potential threats that might impose limitations on the development of application systems. Meanwhile, the problems of high false alarm rate and missing alarms due to huge amount of data, complexity of business, hierarchical overlapping existing in traditional situation awareness platform were also dealt with. Based on high-speed access of big data, artificial intelligence and parallel processing technology were used to optimize the perception and prediction algorithm and a solution of network security situation awareness platform suitable for Chinese railways was also put forward. Furthermore, the solution had been tested and verified in a test environment for a month and the results show that this solution is superior to traditional network security situation awareness platform in perceiving and discovering potential security threats in a railway information network environment with the characteristics of high throughput and high complexity, and can effectively reduce the rate of false alarm and improve the quality and level of alarming of the Chinese railway information network with the characteristics of high throughput and rapid real-time response.
Keywords:
点击此处可从《铁路计算机应用》浏览原始摘要信息
点击此处可从《铁路计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号