摘要
随着政务云平台的建设和政务监测范围的不断扩展,采集的数据类型和数量大幅增加,如何有效地从海量数据中提取有价值的信息是重中之重.分析了政务网站监测中存在的问题,提出了网站流量数据分类方法,并基于网站流量基线分析进行网络监测预警体系建设,可以提升安全监测和运维服务体系能力,及时发现流量中存在的异常情况,提高威胁分析能力,确保监测预警的持续、有效运行.
With the construction of the government cloud platform and the continuous expansion of the scope of government monitoring,the type and quantity of data collected has increased significantly.How to extract valuable information from the massive data effectively is the most important.This paper analyzes the problems existing in the monitoring of government websites,puts forward the classification method of website traffic data,and builds the network monitoring and early warning system based on the analysis of website traffic baseline.The web traffic baseline will improve the ability of security monitoring and operation and maintenance service system,discover the abnormal situation in the website traffic in time,improve the ability of threat analysis,and ensure the continuous and effective operation of monitoring and warning.
作者
蔡国庆
刘鹏
李憧
Cai Guoqing;Liu Peng;Li Chong(Beijing Government Computer Emergency Response Center,Beijing100101)
出处
《信息安全研究》
2020年第6期537-542,共6页
Journal of Information Security Research
关键词
监测预警
网络安全
基线分析
流量分析
政务网站
monitoring and early warning
network security
baseline analysis
network traffic analysis
government website