• 查询稿件
  • 获取最新论文
  • 知晓行业信息
周游, 赵悠麒. 应对供应链攻击的铁路企业网络SDP部署方案研究[J]. 铁路计算机应用, 2022, 31(11): 41-47. DOI: 10.3969/j.issn.1005-8451.2022.11.10
引用本文: 周游, 赵悠麒. 应对供应链攻击的铁路企业网络SDP部署方案研究[J]. 铁路计算机应用, 2022, 31(11): 41-47. DOI: 10.3969/j.issn.1005-8451.2022.11.10
ZHOU You, ZHAO Youqi. Research on SDP deployment scheme for railway enterprise network against supply chain attack[J]. Railway Computer Application, 2022, 31(11): 41-47. DOI: 10.3969/j.issn.1005-8451.2022.11.10
Citation: ZHOU You, ZHAO Youqi. Research on SDP deployment scheme for railway enterprise network against supply chain attack[J]. Railway Computer Application, 2022, 31(11): 41-47. DOI: 10.3969/j.issn.1005-8451.2022.11.10

应对供应链攻击的铁路企业网络SDP部署方案研究

Research on SDP deployment scheme for railway enterprise network against supply chain attack

  • 摘要: 在铁路企业信息系统日益开放、拓展互联的过程中,供应链攻击成为当前铁路企业网络安全面临的主要挑战之一。而云计算、移动互联的快速发展导致铁路企业网络的传统内外网边界模糊,传统网络安全防护模式越来越难以应对各种复杂多变的攻击手段。文章基于零信任理念,结合铁路企业网络攻防演练实践,探讨将软件定义边界(SDP,Software Defined Perimeter)模型应用于防范供应链攻击;SDP控制器部署在铁路网络安全管理中心区域,主要由流量检测模块、规则控制模块、流量时间特性分析模块构成;SDP控制器通过这3个模块协同工作,辅助统一日志管理平台完成对铁路信息系统与外部系统的细粒度动态访问控制,以有效应对供应链攻击,构建更加安全的铁路企业网络安全防护体系。

     

    Abstract: As the information systems of railway enterprises are becoming more and more open and interconnected, supply chain attack has become one of the main challenges of railway enterprises' network security. However, the rapid development of cloud computing and mobile Internet has led to the blurring of the traditional internal and external boundaries of enterprise networks, and the traditional network security protection mode is increasingly difficult to cope with a variety of complex and changeable attacks. Based on the concept of zero trust and combined with the attack and defense drilling of railway enterprise network, this paper discusses the application of SDP model to guard against supply chain attacks. The SDP controller is deployed within the railway network security management center and mainly consists of the traffic detection module, the rule control module and the traffic time characteristic analysis module. These three modules work together to assist the unified log management platform to complete fine-grained dynamic access control over the interactions between the railway information systems and external systems so as to effectively cope with supply chain attacks, thus building a more secure network security protection system for railway enterprises.

     

/

返回文章
返回