中国安全科学学报 ›› 2019, Vol. 29 ›› Issue (S2): 88-92.doi: 10.16265/j.cnki.issn1003-3033.2019.S2.015

• 安全社会工程 • 上一篇    下一篇

铁路通信网络安全管理中心技术方案研究*

张卫军 高级工程师   

  1. 北京铁路局集团公司 北京铁路通信技术中心,北京 100038
  • 收稿日期:2019-08-10 修回日期:2019-10-25 出版日期:2019-12-30 发布日期:2020-10-28
  • 作者简介:张卫军 (1972—),男,北京人,本科,高级工程师,主要从事铁路通信专业管理、运用维护管理等方面的工作。

Research on technical scheme of railway communication network security management center

ZHANG Weijun   

  1. Beijing Railway Communication Technology Center, China Railway Beijing Group Co., Ltd., Beijing 100038, China
  • Received:2019-08-10 Revised:2019-10-25 Online:2019-12-30 Published:2020-10-28

摘要: 为全面提升铁路通信网网络安全防护能力,通过梳理分析铁路通信网络运用现状和存在的网络安全风险问题,以《国家网络安全法》《网络安全等级保护基本要求》为指引,结合铁路运行管理体制,围绕铁路通信网网络安全集中监控、安全事件预警、安全态势感知、安全合规检测及安全业务统一运维等管理需求,开展了系统架构、核心能力、关键技术等方面的研究,提出网络安全中心总体技术架构和部署方案建议。结果表明:该技术方案可为构建和实现铁路通信网“一个中心、三重防护”的网络安全防护技术体系提供技术支撑。

关键词: 铁路通信, 网络安全, 主动防御, 态势感知, 技术架构

Abstract: In order to improve the ability of network security protection of railway communication network, the current situation of application of railway communication network and the existing network security risks were summarized and analyzed. Guided by Cybersecurity Law of the People's Republic of China and Baseline for Classified Protection of Cybersecurity, research on system architecture, core capabilities and key technologies was carried out. The railway operation management system was taken into consideration, and the management requirements of centralized monitoring of network security, early warning of events, security situation awareness, security compliance detection and unified operation and maintenance of security business were discussed. The overall technical framework and deployment proposal of network security center were proposed. The results show that the proposed technology scheme can provide technical support for the construction and implementation of ″one center, three protection″ network security protection system of railway communication network.

Key words: railway communication, network security, active defense, situational awareness, technical architecture

中图分类号: