高级检索+

基于威努特的水电厂网络安全架构

Water Power Plant Network Security Architecture Based on Winute

  • 摘要: 为了保证水电厂网络运行安全,针对现有水电厂网络入侵检测系统存在的检测功能和运行性能差的问题,利用威努特网络威胁感知技术,从硬件、数据库和软件功能3个方面实现系统的优化设计。在系统硬件方面,以改装网络流量采集器、网络数据处理器,加设威努特网络威胁感知器作为网络威胁感知技术的运行环境,完成系统硬件设备的优化。再从攻击规则库、应用识别规则库、URL过滤库、病毒库四个方面构建系统数据库表,根据数据之间的内部关系实现数据库表之间的连接。设置水电厂网络入侵检测标准,利用采集器设备捕获水电厂网络流量数据。提取水电厂网络流量数据中的密度、增益等特征,利用威努特网络威胁感知技术识别网络入侵事件。结合入侵事件识别结果,通过特征的匹配,输出包含网络入侵状态、入侵类型等信息的检测结果。系统测试结果表明:优化设计系统比传统网络入侵检测系统的入侵次数检测误差低2.8,类型检测错误率低2.3%;且系统的最大并发连接数和吞吐率更高,即设计系统的入侵检测功能和运行性能更加具有优势。

     

    Abstract: In order to ensure the safety of hydropower plant network operation and aiming at the problems of poor detection function and operation performance of the existing hydropower plant network intrusion detection system,this paper uses Winute network threat perception technology to realize the optimal design of the system from three aspects of hardware,database and software function. In terms of system hardware,the optimization of system hardware equipment is completed by refitting network traffic collector and network data processor,and adding Winute network threat sensor as the operation environment of network threat perception technology. Then the system database tables are built from the four aspects of attack rule base,application identification rule base,URL filter base and virus base,and the connection between database tables is realized according to the internal relationship between data. The network intrusion detection standard of hydropower plant is set,and the collector equipment is used to capture the network traffic data of hydropower plant. The characteristics of density and gain in the network flow data of hydropower plants are extracted,and the network intrusion events are identified by using Winute network threat perception technology. Combined with the intrusion event identification results,the detection results including network intrusion status,intrusion type and other information are output through feature matching. The system test results show that compared with the traditional network intrusion detection system,the intrusion detection error and type detection error rate of the optimized design system are 2.8 and2.3% lower,respectively,and the maximum number of concurrent connections and the throughput rate of the system are higher,that is,the intrusion detection function and operation performance of the designed system have more advantages.

     

/

返回文章
返回