摘要
论文研究分析了"震网"对网络空间的攻击行为,为实现网络空间安全,引入了可信计算技术,以可信密码模块为信任根,在安全操作系统之上,配置密钥协商和进程预期值匹配等防御策略,建立安全可信的终端运行环境和传输通道,杜绝各种外部攻击引入的病毒、木马和其他非法程序以及非授权访问。
This paper researches and analysis the attacking behavior to cyberspace by Stuxnet. For the security of cyberspace, the trusted-computing is referenced. The trusted cipher module is the trusted root; the defense policies like key association and matching process' s expected value are valid on security operation system. The safe and trusted terminal and date channel can be constructed by this way, the external virus, troy, il egal progress and access without authorization wil be denied.
关键词
网络空间
可信计算
防御策略
cyberspace
trusted-computing
defense policy