现代防御技术 ›› 2022, Vol. 50 ›› Issue (2): 61-66.DOI: 10.3969/j.issn.1009-086x.2022.02.009

• 指挥控制与通信 • 上一篇    下一篇

装备网络安全靶场架构设计研究

沈斌1, 柳中华1, 杨豪璞1, 武超2   

  1. 1.中国人民解放军92493部队,辽宁 葫芦岛 125001
    2.中国电子科技集团公司 第三十研究所,北京 100042
  • 收稿日期:2021-09-24 修回日期:2021-11-22 出版日期:2022-04-28 发布日期:2022-04-29
  • 作者简介:沈斌(1981-),男,辽宁葫芦岛人。工程师,硕士,研究方向为网络安全。通信地址:125001 辽宁省葫芦岛市龙港区海滨南路 1 号 E-mail:122259649@qq.com

Research on the Architecture Design of Equipment Network Security Range

Bin SHEN1, Zhong-hua LIU1, Hao-pu YANG1, Chao WU2   

  1. 1.PLA,No. 92493 Troop,Liaoning Huludao 125001,China
    2.The 30th of CETC,Beijing 100042,China
  • Received:2021-09-24 Revised:2021-11-22 Online:2022-04-28 Published:2022-04-29

摘要:

借鉴美国网络空间靶场建设思路,分析国内网络靶场建设基本情况,对靶场框架目标和框架能力进行了描述,分析了涉及靶场建设的5项关键技术,按照统一规划、技术先进性、通用性、可扩展性原则进行结构设计和功能设计,根据靶场实际需求和资源现状,采用云平台和虚拟化技术,对装备网络安全靶场进行分层设计,为满足靶场内场试验与外场试验需求,预留目标模拟和实装接入接口。

关键词: 装备网络安全靶场, 网络安全, 架构设计, 能力框架, 安全能力试验, 抗攻击试验, 网络攻防训练

Abstract:

Following the construction experience of the USA cyber range,this paper describes the target and the capacity of the range architecture on the basis of analyzing the current domestic situation on internal cyber range. Five key technologies involving the construction of the range are analyzed. The compositions and functions are designed on principles of unified planning,advanced technology,versatility and extensibility. According to the actual demand and resource status,the technologies of cloud and virtualization are adopted to design for the equipment network security range hierarchically. The interfaces of simulated and real equipment are reserved for the demand of all kinds of tests.

Key words: equipment network security range, network security, architecture design, capacity framework, security capacity test, anti-attack test, network attack and defense training

中图分类号: