首页|面向零信任架构的访问安全态势评估

面向零信任架构的访问安全态势评估

Situation Assessment of Access Security for Zero-Trust Architecture

扫码查看
传统网络安全态势评估为企业安全风险管理提供决策依据.结合零信任安全的基本原则,分析了零信任安全态势评估的内涵、目标和意义,提出了一个基于持续风险评估的零信任安全访问架构,围绕该架构研究了零信任安全态势评估的关键技术,针对用户访问的上下文安全评估,构建并设计了一个可扩展的态势评估指标体系和量化评估算法,为实现零信任动态细粒度访问控制提供了持续评估能力,最后对零信任态势评估的未来发展进行了总结.
Conventional network security situation assessment provides a decision-making basis for enterprise security risk management.According to the basic principles of zero-trust security,this paper first analyzes the connotation,goal and significance of zero-trust security situation assessment,and then puts forward a zero-trust security access architecture based on continuous risk assessment.Around this architecture,it studies key technologies of zero-trust security situation assessment,focuses on context security assessment for user access,constructs and designs an extensible situation assessment index system as well as a quantitative assessment algorithm,provides continuous assessment capabilities for achieving dynamic fine-grained access control under the zero-trust paradigm,and finally summarizes the future development trend of zero-trust situation assessment.

zero-trustrisk analysisendpoint securitysituation assessment

段炼、张智森、秦益飞、于振伟

展开 >

江苏第二师范学院 物理与信息工程学院,江苏 南京 211200

南京邮电大学 管理学院,江苏 南京 210003

江苏易安联网络技术有限公司,江苏 南京 210012

零信任 风险分析 终端安全 态势评估

2023

信息安全与通信保密
中国电子科技集团公司第三十研究所

信息安全与通信保密

影响因子:0.374
ISSN:1009-8054
年,卷(期):2023.(10)
  • 2
  • 1