《電子技術(shù)應(yīng)用》
您所在的位置:首頁(yè) > 通信与网络 > 设计应用 > 面向攻击面收敛的网络安全风险治理研究
面向攻击面收敛的网络安全风险治理研究
网络安全与数据治理
沈萍
上海市教育委员会财务与资产管理事务中心
摘要: 针对组织网络攻击面动态变化和防御者视角不能有效识别黑客攻击手段的特点,基于多维攻击者视角构建以“资产管理、攻击面识别与风险值计算、攻击面修复与闭环验证、网络流量采集与实时监控分析”为流程的攻击面收敛管理体系,有效实现“安全左移”。对已知资产、影子资产等计入纳管范围,融合风险量化分级与安全漏洞闭环验证,开启持续监控以实时感知资产异动并采取措施。实践结果证明,引入网络流量与威胁情报的协同分析后,威胁情报命中安全事件数量逐步下降;网址及端口非必要暴露面得到有效监控与响应,平均暴露时间显著缩短,从数天减少至1 h以内。攻击面管理技术有效缓解了攻防不对称性问题,提升了组织在网络攻击面的全局可见性与风险控制效率。
中圖分類號(hào):TP393文獻(xiàn)標(biāo)志碼:ADOI:10.19358/j.issn.2097-1788.2026.03.003
中文引用格式:沈萍. 面向攻擊面收斂的網(wǎng)絡(luò)安全風(fēng)險(xiǎn)治理研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2026,45(3):17-23.
英文引用格式:Shen Ping. Research on network security risk governance oriented to attack surface convergence[J].Cyber Security and Data Governance,2026,45(3):17-23.
Research on network security risk governance oriented to attack surface convergence
Shen Ping
Shanghai Municipal Education Commission Finance and Asset Management Affairs Center
Abstract: In view of the dynamic changes of the organization′s network attack surface and the fact that the defender′s perspective can′t effectively identify the hacker′s attack means, based on the multidimensional attacker′s perspective, an attack surface convergence management system with the process of "asset management, attack surface identification and risk value calculation, attack surface repair and closedloop verification, network traffic collection and realtime monitoring and analysis" is constructed to effectively realize the "safe left shift". The known assets and shadow assets are included in the scope of custody, and the risk quantification and classification and closedloop verification of security vulnerabilities are integrated. Continuous monitoring is enabled to detect asset changes in real time and take measures. The practice results show that after introducing the collaborative analysis of network traffic and threat intelligence, the number of security incidents hit by threat intelligence has gradually decreased; the non essential exposure surfaces of websites and ports have been effectively monitored and responded to, and the average exposure time has been significantly shortened from several days to less than one hour. The attack surface management technology effectively alleviates the asymmetry of attack and defense, and improves the overall visibility and risk control efficiency of the organization in the network attack surface.
Key words : attack surface convergence; asset management; calculation of risk value; closed-loop verification

引言

近年來(lái),在數(shù)字化轉(zhuǎn)型驅(qū)動(dòng)下,人工智能、大數(shù)據(jù)、云計(jì)算技術(shù)處于高速發(fā)展階段,廣泛應(yīng)用于專項(xiàng)領(lǐng)域和人們?nèi)粘I?。新技術(shù)革新發(fā)展的過程中,也帶來(lái)了新的安全問題。組織網(wǎng)絡(luò)空間資產(chǎn)能被訪問和利用的網(wǎng)絡(luò)入口越來(lái)越多,攻擊面不斷變得更多、更分散、更動(dòng)態(tài),安全威脅不斷增加,安全事件頻繁發(fā)生,攻擊面識(shí)別和收斂過程中面臨諸多挑戰(zhàn)。云服務(wù)、微服務(wù)架構(gòu)、遠(yuǎn)程辦公等導(dǎo)致資產(chǎn)分散化,形成攻擊面的基礎(chǔ)性擴(kuò)張;員工私自部署的未授權(quán)的應(yīng)用與設(shè)備,形成了難以監(jiān)管的“影子資產(chǎn)”;復(fù)雜供應(yīng)鏈中對(duì)第三方服務(wù)及開源組件依賴增加,相關(guān)漏洞也在不斷暴露;攻擊者利用不斷演變升級(jí)的自動(dòng)化攻擊工具,可以實(shí)現(xiàn)全網(wǎng)暴露資產(chǎn)分鐘級(jí)掃描,從而將各類漏洞高效轉(zhuǎn)化為武器化攻擊入口。這些最終構(gòu)成“資產(chǎn)分散—影子資產(chǎn)滋生—供應(yīng)鏈傳導(dǎo)—攻擊自動(dòng)化”的負(fù)向循環(huán),形成數(shù)字足跡和攻擊面更多、更分散、更動(dòng)態(tài)的發(fā)展趨勢(shì),迫使防御體系向持續(xù)收斂范式演進(jìn)[1]。

攻擊面的識(shí)別和收斂是網(wǎng)絡(luò)安全主動(dòng)防御[2]的發(fā)展趨勢(shì)。在考慮系統(tǒng)安全、系統(tǒng)復(fù)雜性、資源需求和管理成本等因素下[3],傳統(tǒng)的資產(chǎn)發(fā)現(xiàn)、風(fēng)險(xiǎn)評(píng)估、漏洞管理、網(wǎng)絡(luò)空間測(cè)繪等流程在企業(yè)網(wǎng)絡(luò)穩(wěn)定和集中的情況下效果顯著,但無(wú)法響應(yīng)當(dāng)今網(wǎng)絡(luò)中新漏洞和攻擊媒介出現(xiàn)的速度[4]。攻擊面管理作為近些年來(lái)的研究熱點(diǎn),深刻影響到當(dāng)下資產(chǎn)與漏洞管理模式,其持續(xù)工作流程和黑客視角為防御者提供了攻擊者視角下的企業(yè)外部攻擊面數(shù)據(jù),幫助減少攻防信息差,支持安全團(tuán)隊(duì)在不斷增長(zhǎng)和變化的攻擊面背景下建立更主動(dòng)的安全態(tài)勢(shì),促進(jìn)企業(yè)攻擊面的收斂和管理,為安全團(tuán)隊(duì)提供了實(shí)時(shí)可見性的解決方案。


本文詳細(xì)內(nèi)容請(qǐng)下載:

http://ihrv.cn/resource/share/2000007022


作者信息:

沈萍

(上海市教育委員會(huì)財(cái)務(wù)與資產(chǎn)管理事務(wù)中心,上海200003)

2.jpg

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。