摘要
介绍移动支付业务的发展现状和移动支付系统安全合规性检测的重要性,研究相关安全标准对信息系统安全合规性检测的要求,重点从基于系统日志信息、基于网络通信信息和基于系统配置三个方面描述合规性检测分析方法。在此基础上设计移动支付系统安全合规性分析与自动化检测模型,提高检查结果的准确性和合规性,有利于移动支付系统的持续安全运维。
In this paper the status quo of the development of mobile payment business and the importance of security compliance detection of mobile payment system are introduced. Corresponding security standards on the requirements to infbrmation system security compliance detection are studied. The emphasis of the paper is to describe the compliance detection and analysis methods from three aspects : the system logs-based, the network communication information-based and the system configuration-based. According to these, a security compliance analysis and automatic detection model for mobile payment system is designed, which improves the accuracy and compliance of the detection outcomes, and this helps the sustained secure operation of the mobile payment system.
出处
《计算机应用与软件》
CSCD
北大核心
2012年第10期294-299,共6页
Computer Applications and Software
关键词
移动支付
安全标准
合规性检测
系统日志信息
网络通信信息
系统配置
Mobile payment Security standards Compliance detection System log information Network communication informationSystem configuration