《電子技術應用》
您所在的位置:首頁 > 通信与网络 > 设计应用 > 面向攻击面收敛的网络安全风险治理研究
面向攻击面收敛的网络安全风险治理研究
网络安全与数据治理
沈萍
上海市教育委员会财务与资产管理事务中心
摘要: 针对组织网络攻击面动态变化和防御者视角不能有效识别黑客攻击手段的特点,基于多维攻击者视角构建以“资产管理、攻击面识别与风险值计算、攻击面修复与闭环验证、网络流量采集与实时监控分析”为流程的攻击面收敛管理体系,有效实现“安全左移”。对已知资产、影子资产等计入纳管范围,融合风险量化分级与安全漏洞闭环验证,开启持续监控以实时感知资产异动并采取措施。实践结果证明,引入网络流量与威胁情报的协同分析后,威胁情报命中安全事件数量逐步下降;网址及端口非必要暴露面得到有效监控与响应,平均暴露时间显著缩短,从数天减少至1 h以内。攻击面管理技术有效缓解了攻防不对称性问题,提升了组织在网络攻击面的全局可见性与风险控制效率。
中圖分類號:TP393文獻標志碼:ADOI:10.19358/j.issn.2097-1788.2026.03.003
中文引用格式:沈萍. 面向攻擊面收斂的網絡安全風險治理研究[J].網絡安全與數據治理,2026,45(3):17-23.
英文引用格式:Shen Ping. Research on network security risk governance oriented to attack surface convergence[J].Cyber Security and Data Governance,2026,45(3):17-23.
Research on network security risk governance oriented to attack surface convergence
Shen Ping
Shanghai Municipal Education Commission Finance and Asset Management Affairs Center
Abstract: In view of the dynamic changes of the organization′s network attack surface and the fact that the defender′s perspective can′t effectively identify the hacker′s attack means, based on the multidimensional attacker′s perspective, an attack surface convergence management system with the process of "asset management, attack surface identification and risk value calculation, attack surface repair and closedloop verification, network traffic collection and realtime monitoring and analysis" is constructed to effectively realize the "safe left shift". The known assets and shadow assets are included in the scope of custody, and the risk quantification and classification and closedloop verification of security vulnerabilities are integrated. Continuous monitoring is enabled to detect asset changes in real time and take measures. The practice results show that after introducing the collaborative analysis of network traffic and threat intelligence, the number of security incidents hit by threat intelligence has gradually decreased; the non essential exposure surfaces of websites and ports have been effectively monitored and responded to, and the average exposure time has been significantly shortened from several days to less than one hour. The attack surface management technology effectively alleviates the asymmetry of attack and defense, and improves the overall visibility and risk control efficiency of the organization in the network attack surface.
Key words : attack surface convergence; asset management; calculation of risk value; closed-loop verification

引言

近年來,在數字化轉型驅動下,人工智能、大數據、云計算技術處于高速發(fā)展階段,廣泛應用于專項領域和人們日常生活。新技術革新發(fā)展的過程中,也帶來了新的安全問題。組織網絡空間資產能被訪問和利用的網絡入口越來越多,攻擊面不斷變得更多、更分散、更動態(tài),安全威脅不斷增加,安全事件頻繁發(fā)生,攻擊面識別和收斂過程中面臨諸多挑戰(zhàn)。云服務、微服務架構、遠程辦公等導致資產分散化,形成攻擊面的基礎性擴張;員工私自部署的未授權的應用與設備,形成了難以監(jiān)管的“影子資產”;復雜供應鏈中對第三方服務及開源組件依賴增加,相關漏洞也在不斷暴露;攻擊者利用不斷演變升級的自動化攻擊工具,可以實現全網暴露資產分鐘級掃描,從而將各類漏洞高效轉化為武器化攻擊入口。這些最終構成“資產分散—影子資產滋生—供應鏈傳導—攻擊自動化”的負向循環(huán),形成數字足跡和攻擊面更多、更分散、更動態(tài)的發(fā)展趨勢,迫使防御體系向持續(xù)收斂范式演進[1]。

攻擊面的識別和收斂是網絡安全主動防御[2]的發(fā)展趨勢。在考慮系統(tǒng)安全、系統(tǒng)復雜性、資源需求和管理成本等因素下[3],傳統(tǒng)的資產發(fā)現、風險評估、漏洞管理、網絡空間測繪等流程在企業(yè)網絡穩(wěn)定和集中的情況下效果顯著,但無法響應當今網絡中新漏洞和攻擊媒介出現的速度[4]。攻擊面管理作為近些年來的研究熱點,深刻影響到當下資產與漏洞管理模式,其持續(xù)工作流程和黑客視角為防御者提供了攻擊者視角下的企業(yè)外部攻擊面數據,幫助減少攻防信息差,支持安全團隊在不斷增長和變化的攻擊面背景下建立更主動的安全態(tài)勢,促進企業(yè)攻擊面的收斂和管理,為安全團隊提供了實時可見性的解決方案。


本文詳細內容請下載:

http://ihrv.cn/resource/share/2000007022


作者信息:

沈萍

(上海市教育委員會財務與資產管理事務中心,上海200003)

2.jpg

此內容為AET網站原創(chuàng),未經授權禁止轉載。