农业大数据学报 ›› 2023, Vol. 5 ›› Issue (1): 68-75.doi: 10.19788/j.issn.2096-6369.230115

• 研究论文 • 上一篇    下一篇

农业农村部网络安全态势感知监测分析平台设计与实现

呼亚杰()   

  1. 农业农村部信息中心,北京 100125
  • 收稿日期:2023-03-21 出版日期:2023-03-26 发布日期:2023-05-16
  • 作者简介:呼亚杰,男,硕士,研究方向:网络安全、农业大数据;E-mail: huyajie@agri.gov.cn

Design and Implementation of Ministry Agriculture and Rural Affairs Network Security Situation Awareness Monitoring and Analysis Platform

HU Yajie()   

  1. Information Center of Ministry Agriculture and Rural Affairs, Beijing 100125,China
  • Received:2023-03-21 Online:2023-03-26 Published:2023-05-16

摘要:

为了做好网络安全防护,消除潜在风险隐患,保障网络基础设施和信息系统安全稳定运行,文章作者探索通过建设农业农村部网络安全态势感知监测分析平台,实现农业农村部网络安全态势感知、流量异常监测、事件安全预警、攻击追踪溯源、全景可视化展示等,有效应对各类网络安全挑战。农业农村部网络安全态势感知监测分析平台依托大数据技术、机器学习算法,进行全局网络安全态势评估、威胁异常排除、攻击事件处置,从而提升网络安全防护能力,实现了安全设备告警、网络及服务器日志、全网关键节点流量数据、管理数据等多源异构网络安全数据标准化;实现了集网络入侵、横向威胁、攻击者追踪溯源、资产威胁和应用安全等为一体的全局网络安全态势感知;实现了网络安全状况、攻击监测处置等全流程安全防御可视化展示;实现了全网络安全防御一体化,有力保障了业务系统的正常运行,有效防范了病毒木马等造成的破坏活动,极大提高了重大网络安全事件的快速发现和应急处置能力,为网络安全防护提供了高效的防护手段。通过农业农村部网络安全态势感知监测分析平台建设,为网络安全数据治理、一体化安全监测防御探索出了一条可复制可推广的有效路径,其建设思路为省级农业农村部门提供了实践参考。

关键词: 网络安全, 态势感知, 数据治理, 网络安全防护

Abstract:

In order to protect network security, eliminate potential risks, ensure the safe and stable operation of network infrastructure and information systems, this paper aims to build a network security situation awareness monitoring and analysis platform for the Ministry of Agriculture and Rural Affairs, to realize network security situation awareness, traffic anomaly monitoring, incident safety warning, attack tracking, panoramic visual display, effectively responding various network security threats and challenges. The platform relies on big data technology and machine learning algorithms to conduct global network security situation assessment, eliminate threat anomalies, and handle attack events, thereby improving network security protection capabilities, it has achieved standardization of multi-source heterogeneous network security data, network server logs, traffic data of key nodes, management data, implemented global network security situational awareness that integrates network intrusion, horizontal threats, attacker tracing, asset threats, and application security, realized the visualization display of the entire process of security defense, including network security status, attack monitoring and disposal, realized the integration of network security defense, effectively ensuring the normal operation of business systems, effectively preventing destructive activities caused by viruses and Trojans, greatly improving the ability to quickly detect and respond to major network security incidents, and providing efficient protection measures for network security protection. Through the construction of the network security situational awareness monitoring and analysis platform of the Ministry of Agriculture and Rural Affairs, an effective path that can be replicated and promoted for network security data governance and integrated security monitoring and defense has been explored, and its construction ideas provide practical reference for provincial agricultural and rural departments.

Key words: network security, situation awareness, data governance, network security protection