APP下载

浅析网络内部威胁

2019-07-08吴良秋

计算机时代 2019年6期
关键词:网络安全

吴良秋

摘  要: 网络安全的一个严峻考验是内部威胁,如信息泄露,其危害远远大于外部攻击。文章概述了内部威胁的产生及特点,介绍了内部威胁的相关检测技术在国内外研究的现状,列举了当前用于内部威胁的主流检测模型,并从数据量、数据特征、攻击种类、公布时间、优缺点和应用领域等六个方面,简单对比了国内外专家在内部威胁检测领域所选用的数据集,最后分别从人工智能和云平台方面展望了内部威胁检测领域的研究方向。

关键词: 内部威胁; 检测模型; 信息泄露; 网络安全

中图分类号:TP311          文献标志码:A      文章编号:1006-8228(2019)06-41-05

Abstract: A severe test of network security is insider threat, such as information leakage, its harm is far greater than outsider attack. This paper summarizes the generation and characteristics of insider threat, introduces the current research status of insider threat detection technology at home and abroad, and makes a simple comparison between domestic and foreign experts in the field of insider threat detection from six aspects of the amount of data, data characteristics, the types of attacks, timing, advantages, disadvantages and application fields. Finally, puts forward  the research directions in the field of insider threat detection from the aspects of artificial intelligence and cloud platform respectively.

Key words: insider threat; detection model; information leakage; network security

0 引言

随着大数据、云计算蓬勃发展,计算机相关产品在我们生活中扮演着重要角色,我们在享受的同时,信息安全成了不可忽视的安全隐患,数据的非法获取成了互联网环境下的巨大威胁,特别是内部威胁,具有一定的透明性,发生在安全边界之内,相对于外部攻击更隐蔽,对整个网络安全环境提出了严峻挑战。

美国防部海量数据库[1]监测、分析和识别单位雇员的行为是否给国防部带来危险;2013年斯诺登事件中内部人员通过私人渠道公开内部数据引起媒体广泛关注;2017年3月,Dun&Bradstreet(邓白氏)的52GB数据库遭到泄露,这个数据库中包括了美国一些大型企业和政府组织(包括AT&T,沃尔玛、Wells Fargo,美国邮政甚至美国国防部)的3300多万员工的信息和联系方式等;2014年1月,韩国信用局内部员工窃取了2000万银行和信用卡用户的个人数据,造成韩国历史上最严重的数据泄露事件,但这只是内部威胁安全的冰山一角。……

登录APP查看全文

猜你喜欢

网络安全
网络安全(上)
网络安全知多少?
新量子通信线路保障网络安全
网络安全
网络安全人才培养应“实战化”
上网时如何注意网络安全?
网络安全与执法专业人才培养探索与思考
设立网络安全专项基金 促进人才培养
网络安全监测数据分析——2015年11月
打造信息网络安全的铜墙铁壁