《电子技术应用》
您所在的位置:首页 > 通信与网络 > 设计应用 > 面向攻击面收敛的网络安全风险治理研究
面向攻击面收敛的网络安全风险治理研究
网络安全与数据治理
沈萍
上海市教育委员会财务与资产管理事务中心
摘要: 针对组织网络攻击面动态变化和防御者视角不能有效识别黑客攻击手段的特点,基于多维攻击者视角构建以“资产管理、攻击面识别与风险值计算、攻击面修复与闭环验证、网络流量采集与实时监控分析”为流程的攻击面收敛管理体系,有效实现“安全左移”。对已知资产、影子资产等计入纳管范围,融合风险量化分级与安全漏洞闭环验证,开启持续监控以实时感知资产异动并采取措施。实践结果证明,引入网络流量与威胁情报的协同分析后,威胁情报命中安全事件数量逐步下降;网址及端口非必要暴露面得到有效监控与响应,平均暴露时间显著缩短,从数天减少至1 h以内。攻击面管理技术有效缓解了攻防不对称性问题,提升了组织在网络攻击面的全局可见性与风险控制效率。
中图分类号:TP393文献标志码:ADOI:10.19358/j.issn.2097-1788.2026.03.003
中文引用格式:沈萍. 面向攻击面收敛的网络安全风险治理研究[J].网络安全与数据治理,2026,45(3):17-23.
英文引用格式:Shen Ping. Research on network security risk governance oriented to attack surface convergence[J].Cyber Security and Data Governance,2026,45(3):17-23.
Research on network security risk governance oriented to attack surface convergence
Shen Ping
Shanghai Municipal Education Commission Finance and Asset Management Affairs Center
Abstract: In view of the dynamic changes of the organization′s network attack surface and the fact that the defender′s perspective can′t effectively identify the hacker′s attack means, based on the multidimensional attacker′s perspective, an attack surface convergence management system with the process of "asset management, attack surface identification and risk value calculation, attack surface repair and closedloop verification, network traffic collection and realtime monitoring and analysis" is constructed to effectively realize the "safe left shift". The known assets and shadow assets are included in the scope of custody, and the risk quantification and classification and closedloop verification of security vulnerabilities are integrated. Continuous monitoring is enabled to detect asset changes in real time and take measures. The practice results show that after introducing the collaborative analysis of network traffic and threat intelligence, the number of security incidents hit by threat intelligence has gradually decreased; the non essential exposure surfaces of websites and ports have been effectively monitored and responded to, and the average exposure time has been significantly shortened from several days to less than one hour. The attack surface management technology effectively alleviates the asymmetry of attack and defense, and improves the overall visibility and risk control efficiency of the organization in the network attack surface.
Key words : attack surface convergence; asset management; calculation of risk value; closed-loop verification

引言

近年来,在数字化转型驱动下,人工智能、大数据、云计算技术处于高速发展阶段,广泛应用于专项领域和人们日常生活。新技术革新发展的过程中,也带来了新的安全问题。组织网络空间资产能被访问和利用的网络入口越来越多,攻击面不断变得更多、更分散、更动态,安全威胁不断增加,安全事件频繁发生,攻击面识别和收敛过程中面临诸多挑战。云服务、微服务架构、远程办公等导致资产分散化,形成攻击面的基础性扩张;员工私自部署的未授权的应用与设备,形成了难以监管的“影子资产”;复杂供应链中对第三方服务及开源组件依赖增加,相关漏洞也在不断暴露;攻击者利用不断演变升级的自动化攻击工具,可以实现全网暴露资产分钟级扫描,从而将各类漏洞高效转化为武器化攻击入口。这些最终构成“资产分散—影子资产滋生—供应链传导—攻击自动化”的负向循环,形成数字足迹和攻击面更多、更分散、更动态的发展趋势,迫使防御体系向持续收敛范式演进[1]。

攻击面的识别和收敛是网络安全主动防御[2]的发展趋势。在考虑系统安全、系统复杂性、资源需求和管理成本等因素下[3],传统的资产发现、风险评估、漏洞管理、网络空间测绘等流程在企业网络稳定和集中的情况下效果显著,但无法响应当今网络中新漏洞和攻击媒介出现的速度[4]。攻击面管理作为近些年来的研究热点,深刻影响到当下资产与漏洞管理模式,其持续工作流程和黑客视角为防御者提供了攻击者视角下的企业外部攻击面数据,帮助减少攻防信息差,支持安全团队在不断增长和变化的攻击面背景下建立更主动的安全态势,促进企业攻击面的收敛和管理,为安全团队提供了实时可见性的解决方案。


本文详细内容请下载:

http://www.chinaaet.com/resource/share/2000007022


作者信息:

沈萍

(上海市教育委员会财务与资产管理事务中心,上海200003)

2.jpg

此内容为AET网站原创,未经授权禁止转载。