湖北农业科学 ›› 2020, Vol. 59 ›› Issue (24): 9-15.doi: 10.14088/j.cnki.issn0439-8114.2020.24.002

• 综述 • 上一篇    下一篇

关键信息基础设施安全策略应用研究

邢丽平1, 陈侃2, 汪璠1   

  1. 1.湖北省气象信息与技术保障中心,武汉 430074;
    2.湖北省税务局,武汉 430071
  • 收稿日期:2020-08-20 出版日期:2020-12-25 发布日期:2021-01-21
  • 作者简介:邢丽平(1962-),女,湖北黄冈人,高级工程师,主要从事信息技术、信息安全研究,(电话)13886173562(电子信箱)chenxing6621@sohu.com
  • 基金资助:
    湖北省气象局科技发展基金重点项目(2019Z06)

Research on the application of key information infrastructure security strategy

XING Li-ping1, CHEN Kan2, WANG Fan1   

  1. 1. Hubei Meteorological Information and Technical Support Center,Wuhan 430074,China;
    2. Hubei Tax Bureau, Wuhan 430071,China
  • Received:2020-08-20 Online:2020-12-25 Published:2021-01-21

摘要: 在梳理湖北省关键信息基础设施安全问题的基础上,结合等级测评报告反映主要问题和整改建议,按照构建安全体系结构的研究思路,采用包括加固线上安全产品防护策略、新增冗余网络关键节点及安全产品无缝接入现网等技术策略,逐步开展分期整改。结果表明,多种技术方法的融合应用解决了目前湖北省关键信息基础设施中广域网节点冗余设计缺失的问题;缓解核心网络设备和服务器登录地址不统一、口令复杂度及定期更换难以实施的不合规局面。经测评机构的等级测评和风险评估,湖北省关键信息基础设施逐步达到相关的安全保护等级要求及标准,安全防护能力逐年提高。

关键词: 安全等级保护测评, 关键信息基础设施, IRF, HSRP, VPC

Abstract: On the basis of combing the security problems of key information infrastructure in Hubei province, combining the grade evaluation report to reflect the main problems and suggestions for rectification, and according to the research ideas of constructing security architecture, the technical strategies including strengthening online security product protection strategy, adding redundant network key nodes and seamless access of security products to the current network are adopted to carry out phased rectification step by step. The results show that the application of various techniques solves the problem of missing redundant design of WAN nodes in the key information infrastructure of Hubei province, and alleviates the irregular situation that the login address of core network equipment and server is not uniform, the password complexity and the periodic replacement are difficult to implement. Through the grade evaluation and risk assessment of the evaluation organization, the safety protection grade requirements and standards of the key information infrastructure in Hubei province are gradually related, and the safety protection ability is improved year by year.

Key words: security level protection assessment, critical information infrastructure, IRF, HRSP, VPC

中图分类号: