基于零信任的网络安全模型架构与应用研究
2021-09-29李欢欢徐小云王红蕾
李欢欢 徐小云 王红蕾
DOI:10.16661/j.cnki.1672-3791.2107-5042-9133
摘 要:随着新技术的快速发展,传统的网络安全模型无法满足企业信息安全防护要求,基于零信任的网络安全模型应运而生,被众多企业选择。该文阐述并分析了传统网络安全模型的优缺点,并对零信任网络安全模型的架构进行了详细阐述,在此基础上以零信任网络安全模型在某网信息安全支撑技术平台上的实践为例,提出了基于零信任架构的安全应用解决方案。
关键词:零信任 信任评估 动态访问 网络安全
中图分类号:TP393.8 文献标识码:A 文章编号:1672-3791(2021)06(b)-0007-03
Research on the Architecture and Application of Network Security Model Based on Zero Trust
LI Huanhuan XU Xiaoyun WANG Honglei
(Aostar Information Technology Co., Ltd., Chengdu, Sichuan Province,610041 China)
Abstract: With the rapid development of new technology, the traditional network security model can not meet the requirements of enterprise information security protection, the network security model based on zero trust arises at the historic moment, has been chosen by many enterprises. This paper first analyzes the advantages and disadvantages of the traditional network security model, and elaborates on the architecture of the zero trust network security model. On this basis, taking the practice of the zero trust network security model on a network information security support technology platform as an example, this paper proposes a security application solution based on the zero trust architecture.
Key Words: Zero trust; Trust assessment; Dynamic access; Cyber security
多数企业当前主要采用传统的网络安全模型,即对网络进行分区并设置网络隔离的模型,企业使用边界防护设备将企业网络设置为企业内网与企业外网,从而构建出企业自身的网络安全防护体系。随着云计算、大数据、物联网、移动互联网等新兴技术的发展,企业的业务架构与网络应用环境已发生较大变化。从而导致基于边界防护的传统网络安全模型不足以满足新环境下的网络安全要求,在一些进化的持续性威胁攻击面前无法有效防护网络与系统安全,内网安全事故也因此频繁发生。
针对传统的网络安全模型无法满足当前企业在数字化转型阶段对网络安全的需求,基于零信任的网络安全模型应运而生。对任一访问企业网络的主体,包括发起访问的人员、发起访问的设备以及被访问的应用,在每次访问时都默认为不可信状态,需要通过持续的身份验证以及访问授权来构建动态访问的信任。……
