摘要
[目的/意义]旨在应对日益突出的互联网资产暴露和漏洞爆发情况,全面掌握企业的网络空间资产信息以及资产的漏洞信息,实现网络空间资产安全测绘,增强对安全突发事件的数据储备及应急处置能力。[方法/过程]通过研究互联网资产情报的背景、意义及技术体系组成,阐述了资产情报定义及组成,包括资产暴露情报、资产指纹情报、资产漏洞情报、资产失陷情报等四大部分。同时,通过搭建互联网资产情报系统,验证了互联网资产情报的实用性。[结果/结论]互联网资产情报系统为网络空间的风险感知提供了有利的手段和工具,可应用在网络监管、安全运营管理以及网络攻防演练中。自动探测整个网络空间资产信息及漏洞信息,在爆发大规模的互联网组件漏洞时,通过系统的预警关联机制,获得区域的受灾情况,督促漏洞整改和修复。
[Purpose/significance]The paper aims to cope with Internet assets exposure and bug outbreak,overall understand the assets information of enterprises’cyberspace and the bug information of Internet assets,realize the security mapping of cyberspace assets,and enhance the ability of data storage and emergency response for security emergencies.[Method/process]The paper studies the background and significance of Internet asset intelligence,and expounds the definition and composition of asset information which include asset exposure information,asset fingerprint information,asset bug information and asset loss information.Meanwhile,the Internet Asset Intelligence System is designed and established for verifying the practicability of Internet asset intelligence.[Result/conclusion]The Internet Asset Intelligence System is a useful tool for detecting risk perception of cyberspace.It can be applied in many situations,like network supervision,security operation management and network attack and defense drilling.It can automatically detect the information of assets and bugs in the whole cyberspace.When large-scale Internet component bugs occur,the system can obtain the disaster situation in the area by the early warning correlation mechanism,and supervise the bug fixes.
作者
赖建华
唐敏
Lai Jianhua;Tang Min(Fujian Institute of Scientific and Technological Information,Fuzhou Fujian 350003;Fujian Key Laboratory of Information and Network,Fuzhou Fujian 350003;Fujian Strait Information Corporation,Fuzhou Fujian 350003)
出处
《情报探索》
2019年第7期39-45,共7页
Information Research
基金
福建省科技计划项目“互联网网络空间资产探测云平台”(项目编号:2017R1008-1)和福建省科技计划项目“多网隔离安全接入网关的关键技术研究与开发”(项目编号:2018R1008-9)研究成果
关键词
资产情报
资产暴露
资产指纹
资产漏洞
失陷主机
asset intelligence
asset exposure
asset fingerprint
asset bug
compromised hosts