-
Notifications
You must be signed in to change notification settings - Fork 19
/
数据安全架构设计与实现.mm
1150 lines (1150 loc) · 125 KB
/
数据安全架构设计与实现.mm
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
<map version="1.0.1">
<!-- To view this file, download free mind mapping software FreeMind from http://freemind.sourceforge.net -->
<node CREATED="1597631240778" ID="ID_1567335665" MODIFIED="1597635316333" TEXT="数据安全架构设计与实现">
<node CREATED="1597635316302" FOLDED="true" ID="ID_288499756" MODIFIED="1601009249423" POSITION="right" TEXT="介绍">
<node CREATED="1597631253525" FOLDED="true" ID="ID_1607775564" MODIFIED="1597655103905" TEXT="01.架构">
<node CREATED="1597631318420" ID="ID_421768161" MODIFIED="1597631320699" TEXT="含义">
<node CREATED="1597631321511" ID="ID_1378170805" MODIFIED="1597631960299" TEXT="描述系统中组件(逻辑模块)以及之间关系"/>
</node>
<node CREATED="1597631864725" ID="ID_447662348" MODIFIED="1597631866424" TEXT="分类">
<node CREATED="1597631867171" ID="ID_1449209489" MODIFIED="1597631869732" TEXT="概念架构">
<node CREATED="1597631898363" ID="ID_1527739292" MODIFIED="1597631931591" TEXT="包含基本的定义,不涉及接口细节内容"/>
</node>
<node CREATED="1597631869930" ID="ID_1647554140" MODIFIED="1597631872361" TEXT="逻辑架构">
<node CREATED="1597631933187" ID="ID_1715227568" MODIFIED="1597631953950" TEXT="体现业务逻辑模块及之间关系"/>
</node>
<node CREATED="1597631872589" ID="ID_1193290711" MODIFIED="1597631874408" TEXT="物理架构">
<node CREATED="1597631963085" ID="ID_1879998478" MODIFIED="1597631976898" TEXT="体现组件及部署位置"/>
</node>
</node>
<node CREATED="1597632124207" ID="ID_1801847326" MODIFIED="1597632135114" TEXT="软件需求">
<node CREATED="1597632135890" ID="ID_497161514" MODIFIED="1597632138969" TEXT="功能需求"/>
<node CREATED="1597632139160" ID="ID_87473883" MODIFIED="1597632141403" TEXT="质量需求">
<node CREATED="1597632158872" ID="ID_1836541620" MODIFIED="1597632160202" TEXT="性能"/>
<node CREATED="1597632160457" ID="ID_1800757692" MODIFIED="1597632161933" TEXT="安全性"/>
<node CREATED="1597632162174" ID="ID_1282389666" MODIFIED="1597632167247" TEXT="扩展性"/>
<node CREATED="1597632167480" ID="ID_1257255125" MODIFIED="1597632171082" TEXT="可维护性"/>
</node>
</node>
</node>
<node CREATED="1597632214569" FOLDED="true" ID="ID_339652191" MODIFIED="1597655102778" TEXT="02.安全架构">
<node CREATED="1597632240088" ID="ID_630003867" MODIFIED="1597632354800" TEXT="安全三要素">
<node CREATED="1597632245119" ID="ID_1320857587" MODIFIED="1597632249702" TEXT="机密性">
<node CREATED="1597632296972" ID="ID_234174430" MODIFIED="1597632320037" TEXT="Confidentiality"/>
<node CREATED="1597632320809" ID="ID_1146412014" MODIFIED="1597632350703" TEXT="保障信息资产不被未授权的用户访问或泄露"/>
</node>
<node CREATED="1597632255016" ID="ID_1665211725" MODIFIED="1597632257687" TEXT="完整性">
<node CREATED="1597632362924" ID="ID_1031866503" MODIFIED="1597632371868" TEXT="Integrity"/>
<node CREATED="1597632372207" ID="ID_1430511396" MODIFIED="1597632888393" TEXT="保障信息资产不被未授权的用户篡改"/>
</node>
<node CREATED="1597632249926" ID="ID_1439589309" MODIFIED="1597632252047" TEXT="可用性">
<node CREATED="1597632398074" ID="ID_1005426246" MODIFIED="1597632406943" TEXT="Availability"/>
<node CREATED="1597632408203" ID="ID_204154455" MODIFIED="1597632424770" TEXT="保障已授权的用户合法访问信息资产的权力"/>
</node>
</node>
<node CREATED="1597633092447" ID="ID_1465538750" MODIFIED="1597633095632" TEXT="概念">
<node CREATED="1597633096367" ID="ID_1947269417" MODIFIED="1597633098450" TEXT="信息安全">
<node CREATED="1597633106241" ID="ID_707399722" MODIFIED="1597633109908" TEXT="广义">
<node CREATED="1597633110682" ID="ID_602460396" MODIFIED="1597633121931" TEXT="安全体系以信息为中心">
<node CREATED="1597633150622" ID="ID_835484766" MODIFIED="1597633280019" TEXT="侧重于安全管理"/>
</node>
</node>
<node CREATED="1597633283111" ID="ID_962496673" MODIFIED="1597633291078" TEXT="狭义">
<node CREATED="1597633308215" ID="ID_43674960" MODIFIED="1597633310528" TEXT="内容合规"/>
<node CREATED="1597633310760" ID="ID_1263841269" MODIFIED="1597633314221" TEXT="数据防泄漏"/>
<node CREATED="1597633315311" ID="ID_382446254" MODIFIED="1597633316554" TEXT="..."/>
</node>
</node>
<node CREATED="1597633098668" ID="ID_559389834" MODIFIED="1597633101534" TEXT="网络安全">
<node CREATED="1597633110682" ID="ID_1540331045" MODIFIED="1597633130780" TEXT="安全体系以网络为中心">
<node CREATED="1597633330183" ID="ID_334400957" MODIFIED="1597633361505" TEXT="涉及网络安全域、防火墙、网络访问控制、抗D等场景"/>
</node>
<node CREATED="1597633404406" ID="ID_393637171" MODIFIED="1597633409259" TEXT="网络空间安全">
<node CREATED="1597633410049" ID="ID_1668012007" MODIFIED="1597633422001" TEXT="包含云端、网络、终端等环节"/>
</node>
</node>
<node CREATED="1597633101756" ID="ID_718154932" MODIFIED="1597633104857" TEXT="数据安全">
<node CREATED="1597633110682" ID="ID_759131785" MODIFIED="1597633136447" TEXT="安全体系以数据为中心">
<node CREATED="1597633459224" ID="ID_1388504380" MODIFIED="1597633487223" TEXT="侧重于数据分级及敏感数据全生命周期的保护"/>
<node CREATED="1597633511354" ID="ID_787780872" MODIFIED="1597633544927" TEXT="涉及数据的安全收集与生成、安全使用、安全传输、安全存储、安全披露、安全流转与跟踪、安全销毁"/>
<node CREATED="1597633562383" ID="ID_1726102440" MODIFIED="1597633582936" TEXT="包含隐私保护(个人数据安全与法律发规)"/>
</node>
</node>
</node>
<node CREATED="1597633936258" ID="ID_366133032" MODIFIED="1597633943603" TEXT="安全架构三道防线">
<node CREATED="1597633944473" ID="ID_1797038377" MODIFIED="1597633948161" TEXT="产品安全架构">
<node CREATED="1597633948969" ID="ID_703858661" MODIFIED="1597633977065" TEXT="在不依赖外部防御系统情况下打造自身安全的产品"/>
</node>
<node CREATED="1597634004558" ID="ID_979292804" MODIFIED="1597634011159" TEXT="安全技术体系架构">
<node CREATED="1597634012458" ID="ID_146479222" MODIFIED="1597634055415" TEXT="构建通用的安全技术基础设施, 系统性的增强各产品的安全防御能力">
<node CREATED="1597634057058" ID="ID_1333058605" MODIFIED="1597634062863" TEXT="安全基础设施"/>
<node CREATED="1597634063108" ID="ID_1187487733" MODIFIED="1597634069407" TEXT="安全工具和技术"/>
<node CREATED="1597634069687" ID="ID_691017650" MODIFIED="1597634076181" TEXT="安全组件与支持系统"/>
</node>
</node>
<node CREATED="1597634088036" ID="ID_68422737" MODIFIED="1597634091429" TEXT="审计架构">
<node CREATED="1597634105823" ID="ID_1910340463" MODIFIED="1597634160383" TEXT="提供风险发现能力, 审计范围包括所有安全风险"/>
</node>
</node>
<node CREATED="1597634240414" ID="ID_1665787188" MODIFIED="1597634248303" TEXT="5A方法论">
<node CREATED="1597634250991" ID="ID_508234097" MODIFIED="1597634254385" TEXT="身份认证">
<node CREATED="1597634274639" ID="ID_1152821410" MODIFIED="1597634435571" TEXT="验证主体身份"/>
<node CREATED="1597634389609" ID="ID_1096257534" MODIFIED="1597634419558" TEXT="主体包含所有要访问的对象">
<node CREATED="1597634420502" ID="ID_1343732024" MODIFIED="1597634423495" TEXT="用户"/>
<node CREATED="1597634423757" ID="ID_73382527" MODIFIED="1597634428013" TEXT="设备"/>
<node CREATED="1597634428242" ID="ID_363808288" MODIFIED="1597634429159" TEXT="系统"/>
<node CREATED="1597634429818" ID="ID_1591479611" MODIFIED="1597634432487" TEXT="..."/>
</node>
</node>
<node CREATED="1597634254623" ID="ID_459896615" MODIFIED="1597634256234" TEXT="授权">
<node CREATED="1597634293355" ID="ID_57767010" MODIFIED="1597634444557" TEXT="授予主体允许访问的客体权限"/>
</node>
<node CREATED="1597634256483" ID="ID_518739148" MODIFIED="1597634258710" TEXT="访问控制">
<node CREATED="1597634310132" ID="ID_473182759" MODIFIED="1597634467478" TEXT="执行授权以控制是否放行主体访问"/>
<node CREATED="1597634531265" ID="ID_1883699561" MODIFIED="1597634598781" TEXT="覆盖物理和环境层、网络和通信层、设备和主机层、应用和数据层"/>
</node>
<node CREATED="1597634258908" ID="ID_1306219428" MODIFIED="1597634260722" TEXT="可审计">
<node CREATED="1597634346660" ID="ID_696805419" MODIFIED="1597634359146" TEXT="提供可用于追溯的操作日志"/>
<node CREATED="1597634924283" ID="ID_1710663165" MODIFIED="1597634926535" TEXT="阶段">
<node CREATED="1597634927426" ID="ID_541006475" MODIFIED="1597634930943" TEXT="身份认证">
<node CREATED="1597634940932" ID="ID_293361770" MODIFIED="1597635069084" TEXT="记录登录时间、用户名、IP、访问目标等信息"/>
</node>
<node CREATED="1597634931155" ID="ID_1096270396" MODIFIED="1597634937069" TEXT="授权">
<node CREATED="1597634999878" ID="ID_1841618961" MODIFIED="1597635063792" TEXT="记录权限申请流程中每个审批环节的时间、用户、IP、理由、动作等新信息"/>
</node>
<node CREATED="1597634937299" ID="ID_217975870" MODIFIED="1597634939566" TEXT="访问控制">
<node CREATED="1597635076526" ID="ID_1240971564" MODIFIED="1597635168717" TEXT="记录访问控制执行结果,需要记录所有阻断信息及敏感资产的所有执行信息"/>
</node>
<node CREATED="1597635181606" ID="ID_1157378562" MODIFIED="1597635183916" TEXT="资产保护">
<node CREATED="1597635184747" ID="ID_1368526683" MODIFIED="1597635196017" TEXT="记录用户访问目标及其操作"/>
</node>
</node>
</node>
<node CREATED="1597634261004" ID="ID_1752257538" MODIFIED="1597634263610" TEXT="资产保护">
<node CREATED="1597634360431" ID="ID_404777214" MODIFIED="1597634375413" TEXT="保障资产的机密性、完整性、可用性"/>
<node CREATED="1597634628674" ID="ID_1504134319" MODIFIED="1597634643288" TEXT="资产包含数据和资源">
<node CREATED="1597634644200" ID="ID_817911351" MODIFIED="1597634646745" TEXT="数据">
<node CREATED="1597634658398" ID="ID_1107558499" MODIFIED="1597634661417" TEXT="信息数据"/>
<node CREATED="1597634661648" ID="ID_1155511328" MODIFIED="1597634707098" TEXT="包含存储、使用、传输、流转中的数据"/>
</node>
<node CREATED="1597634646964" ID="ID_553178198" MODIFIED="1597634648116" TEXT="资源">
<node CREATED="1597634714347" ID="ID_1546960963" MODIFIED="1597634745738" TEXT="包括网络、计算、存储、进程、产品功能、网络服务、系统文件等"/>
</node>
</node>
</node>
</node>
</node>
</node>
<node CREATED="1597635324117" FOLDED="true" ID="ID_1463760188" MODIFIED="1601009250607" POSITION="right" TEXT="产品安全架构">
<node CREATED="1597635329147" FOLDED="true" ID="ID_40173163" MODIFIED="1597655107401" TEXT="03.产品安全架构简介">
<node CREATED="1597635775582" ID="ID_663584748" MODIFIED="1597635784288" TEXT="构建产品自身安全特性"/>
</node>
<node CREATED="1597637028237" FOLDED="true" ID="ID_188539145" MODIFIED="1597655107402" TEXT="04.身份认证">
<node CREATED="1597637166635" FOLDED="true" ID="ID_1560818864" MODIFIED="1597655107401" TEXT="基于身份的信任思维">
<node CREATED="1597637179540" ID="ID_691117083" MODIFIED="1597637243095" TEXT="任何企业内/外部的任何人、任何系统都是不可信的, 需要基于身份认证和授权执行以身份为中心的访问控制和资产保护"/>
</node>
<node CREATED="1597637442685" FOLDED="true" ID="ID_1619616298" MODIFIED="1597655107401" TEXT="身份认证">
<node CREATED="1597637452136" ID="ID_1891199424" MODIFIED="1597637460055" TEXT="确定访问者身份"/>
</node>
<node CREATED="1597637641064" FOLDED="true" ID="ID_322312530" MODIFIED="1597655107402" TEXT="单点登录">
<node CREATED="1597637647088" ID="ID_61839484" MODIFIED="1597637675801" TEXT="统一身份认证入入口"/>
<node CREATED="1597637680075" FOLDED="true" ID="ID_412102067" MODIFIED="1597655107401" TEXT="优势">
<node CREATED="1597637684105" ID="ID_970663097" MODIFIED="1597637710971" TEXT="避免各业务重复建设, 简化业务工作量"/>
<node CREATED="1597637712432" ID="ID_1704972551" MODIFIED="1597637758924" TEXT="统一强化对用隐私的保护, 避免隐私分散造成信息泄露"/>
<node CREATED="1597637759330" ID="ID_960383116" MODIFIED="1597637802055" TEXT="账号熊实现对其他系统的自动化关联"/>
</node>
<node CREATED="1597637806604" FOLDED="true" ID="ID_425541144" MODIFIED="1597655107401" TEXT="流程">
<node CREATED="1597637808799" ID="ID_176770344" MODIFIED="1597637913511" TEXT="客户端提交用户名/密码到SSO系统, 对用户身份进行验证无误, 颁发Ticket"/>
<node CREATED="1597637857332" ID="ID_944214626" MODIFIED="1597637887718" TEXT="客户端携带Ticket到业务系统进行请求"/>
</node>
<node CREATED="1597637917166" FOLDED="true" ID="ID_1568892072" MODIFIED="1597655107402" TEXT="Ticket使用机制">
<node CREATED="1597637929181" FOLDED="true" ID="ID_234749268" MODIFIED="1597655107401" TEXT="会话机制">
<node CREATED="1597637956032" ID="ID_257869630" MODIFIED="1597638028282" TEXT="业务系统对Ticket进行验证(调用SSO认证接口)无误后建立Session信息, 在session有效期不在访问SSO认证接口"/>
</node>
<node CREATED="1597637939707" FOLDED="true" ID="ID_1212004163" MODIFIED="1597655107401" TEXT="全程Ticket机制">
<node CREATED="1597638036851" ID="ID_1250508091" MODIFIED="1597638077458" TEXT="用户全程携带Ticket, 业务系统针对每次请求对Ticket进行验证(调用SSO认证接口)"/>
</node>
<node CREATED="1597638082513" FOLDED="true" ID="ID_622459558" MODIFIED="1597655107402" TEXT="持续的消息认证机制">
<node CREATED="1597638090085" ID="ID_1207009582" MODIFIED="1597638099839" TEXT="每次请求都需要执行身份认证"/>
</node>
</node>
<node CREATED="1597638726234" FOLDED="true" ID="ID_1857873430" MODIFIED="1597655107402" TEXT="误区">
<node CREATED="1597638728916" ID="ID_111517615" MODIFIED="1597638804926" TEXT="业务认证禁止使用代理方式接收用户名/密码在后端调用SSO进行用户认证, 而应该让用户名/密码信息直接提交给SSO"/>
</node>
</node>
<node CREATED="1597638964177" FOLDED="true" ID="ID_1772270513" MODIFIED="1597655107402" TEXT="口令保护">
<node CREATED="1597638969940" ID="ID_1457484508" MODIFIED="1597639005490" TEXT="使用密文(加盐散列)存储"/>
<node CREATED="1597639006895" ID="ID_1937752596" MODIFIED="1597639034085" TEXT="认证使用HTTPS传输"/>
<node CREATED="1597639026431" FOLDED="true" ID="ID_430028042" MODIFIED="1597655107402" TEXT="客户端不直接发送明文口令">
<node CREATED="1597639056138" ID="ID_954015783" MODIFIED="1597639061842" TEXT="保护用户隐私"/>
</node>
<node CREATED="1597639246676" ID="ID_1598344470" MODIFIED="1597639310869" TEXT="限制用户使用弱口令, 并使用大小写字母、数字、特殊字符组合方式,并限制最小长度"/>
</node>
<node CREATED="1597639520161" FOLDED="true" ID="ID_310761189" MODIFIED="1597655107402" TEXT="前端慢速加盐案列">
<node CREATED="1597639572555" FOLDED="true" ID="ID_1819055112" MODIFIED="1597655107402" TEXT="在客户端侧通过慢速加盐散列算法将密码进行hash运算后提交">
<node CREATED="1597639974217" ID="ID_1543027388" MODIFIED="1597640057011" TEXT="盐值取用户名、口令(不能包含原始口令)和固定字符串拼接"/>
</node>
<node CREATED="1597639928230" ID="ID_1193836313" MODIFIED="1597639972554" TEXT="服务器接受到提交的密文字符串, 再次进行hash运算后与数据库中存储密码进行比较"/>
</node>
<node CREATED="1597645604798" FOLDED="true" ID="ID_37964052" MODIFIED="1597655107402" TEXT="API身份认证">
<node CREATED="1597645666347" ID="ID_754922912" MODIFIED="1597645673656" TEXT="基于用户Ticket"/>
<node CREATED="1597645710656" ID="ID_1935165501" MODIFIED="1597645718214" TEXT="基于AppKey"/>
<node CREATED="1597645741434" ID="ID_919499717" MODIFIED="1597645750024" TEXT="基于非对称加密技术"/>
<node CREATED="1597645857488" ID="ID_1389874516" MODIFIED="1597645861910" TEXT="基于HMAC"/>
<node CREATED="1597646038338" ID="ID_518995783" MODIFIED="1597646046439" TEXT="基于AES-GCM共享密钥"/>
</node>
<node CREATED="1597646067694" FOLDED="true" ID="ID_804295761" MODIFIED="1597655107402" TEXT="双因子认证">
<node CREATED="1597646072137" ID="ID_1801855284" MODIFIED="1597646081579" TEXT="手机验证码"/>
<node CREATED="1597646081923" ID="ID_1917372271" MODIFIED="1597646103733" TEXT="动态令牌"/>
<node CREATED="1597646207784" FOLDED="true" ID="ID_1914624570" MODIFIED="1597655107402" TEXT="U2F">
<node CREATED="1597646212969" ID="ID_1393197840" MODIFIED="1597646220149" TEXT="通用双因子身份认证"/>
<node CREATED="1597646267921" ID="ID_1984884526" MODIFIED="1597646295914" TEXT="与U盾相比可是使用在多个应用中"/>
</node>
</node>
</node>
<node CREATED="1597646405307" FOLDED="true" ID="ID_629258039" MODIFIED="1597655107403" TEXT="05.授权">
<node CREATED="1597646983045" ID="ID_1307681002" MODIFIED="1597647222732" TEXT="向通过身份认证的主体授权或拒绝访问客体的特定权限"/>
<node CREATED="1597647016977" FOLDED="true" ID="ID_1170340324" MODIFIED="1597655107402" TEXT="授权原则">
<node CREATED="1597647041324" ID="ID_1168988789" MODIFIED="1597647047812" TEXT="最小权限原则"/>
</node>
<node CREATED="1597647048463" FOLDED="true" ID="ID_1290249708" MODIFIED="1597655107403" TEXT="授权方式">
<node CREATED="1597647051217" ID="ID_1858675855" MODIFIED="1597647057959" TEXT="基于属性的"/>
<node CREATED="1597647058219" ID="ID_1635252081" MODIFIED="1597647063136" TEXT="基于角色的"/>
<node CREATED="1597648189874" FOLDED="true" ID="ID_60482327" MODIFIED="1597655107403" TEXT="基于任务的">
<node CREATED="1597648223271" ID="ID_38745519" MODIFIED="1597648251772" TEXT="常为保证流程任务顺利完成采用的临时授权"/>
</node>
<node CREATED="1597648283535" ID="ID_1620191903" MODIFIED="1597648290219" TEXT="基于ACL的"/>
<node CREATED="1597648355697" FOLDED="true" ID="ID_398985617" MODIFIED="1597655107403" TEXT="动态授权">
<node CREATED="1597648370971" ID="ID_807396316" MODIFIED="1597648414988" TEXT="基于专家知识或人工智能学习来判断访问者信誉度以决策是否允许"/>
</node>
</node>
<node CREATED="1597648444156" FOLDED="true" ID="ID_764733673" MODIFIED="1597655107403" TEXT="授权风险">
<node CREATED="1597648447369" ID="ID_391524056" MODIFIED="1597648454979" TEXT="未授权"/>
<node CREATED="1597648455230" ID="ID_1976654124" MODIFIED="1597648460480" TEXT="水平越权"/>
<node CREATED="1597648460692" ID="ID_1889983931" MODIFIED="1597648465266" TEXT="垂直越权"/>
<node CREATED="1597648465528" ID="ID_689239080" MODIFIED="1597648471178" TEXT="诱导授权"/>
<node CREATED="1597648471441" ID="ID_1223139617" MODIFIED="1597648476619" TEXT="职责未分离"/>
</node>
</node>
<node CREATED="1597649117512" FOLDED="true" ID="ID_748635281" MODIFIED="1597655107403" TEXT="06.访问控制">
<node CREATED="1597652366272" ID="ID_173440860" MODIFIED="1597652443224" TEXT="为降低攻击面, 按照安全管理政策、业务规则或资源属性、授权表、专家知识, 对主体访问客体行为进行控制"/>
<node CREATED="1597652487068" FOLDED="true" ID="ID_1717101788" MODIFIED="1597655107403" TEXT="三要素">
<node CREATED="1597652495037" ID="ID_551354267" MODIFIED="1597652496439" TEXT="主体"/>
<node CREATED="1597652496648" ID="ID_1217724556" MODIFIED="1597652497928" TEXT="客体"/>
<node CREATED="1597652498177" FOLDED="true" ID="ID_325573302" MODIFIED="1597655107403" TEXT="控制策略">
<node CREATED="1597652532564" ID="ID_1557313520" MODIFIED="1597652535081" TEXT="基于属性的"/>
<node CREATED="1597652535311" ID="ID_862228207" MODIFIED="1597652539984" TEXT="基于角色的"/>
<node CREATED="1597652540182" ID="ID_188364609" MODIFIED="1597652545964" TEXT="基于任务的"/>
<node CREATED="1597652546186" ID="ID_282488148" MODIFIED="1597652548950" TEXT="基于ACL的"/>
<node CREATED="1597652549716" ID="ID_1123874970" MODIFIED="1597652558001" TEXT="基于专家知识的"/>
<node CREATED="1597652558254" FOLDED="true" ID="ID_253918291" MODIFIED="1597655107403" TEXT="基于强制访问控制的">
<node CREATED="1597652909816" ID="ID_1425236842" MODIFIED="1597652937361" TEXT="主体和客体通过分配标签来标识安全等级"/>
</node>
</node>
</node>
<node CREATED="1597654646559" FOLDED="true" ID="ID_1097346850" MODIFIED="1597655107403" TEXT="不信任原则">
<node CREATED="1597653005970" ID="ID_981308909" MODIFIED="1597654688191" TEXT="针对主体提交的数据需要保持不信任原则, 需要对所有提交的数据进行格式检查"/>
<node CREATED="1597654690764" FOLDED="true" ID="ID_578118190" MODIFIED="1597655107403" TEXT="常见漏洞">
<node CREATED="1597654704918" ID="ID_447685721" MODIFIED="1597654711869" TEXT="缓冲区溢出"/>
<node CREATED="1597654712098" ID="ID_790188671" MODIFIED="1597654716368" TEXT="SQL注入"/>
<node CREATED="1597654716608" ID="ID_1486248433" MODIFIED="1597654719406" TEXT="XSS"/>
<node CREATED="1597654719676" ID="ID_888661329" MODIFIED="1597654726562" TEXT="CSRF"/>
<node CREATED="1597654726832" ID="ID_981462810" MODIFIED="1597654728882" TEXT="SSRF"/>
<node CREATED="1597654729165" ID="ID_291126535" MODIFIED="1597654742697" TEXT="路径遍历"/>
<node CREATED="1597654734524" ID="ID_1150969847" MODIFIED="1597654739667" TEXT="上传Webshell"/>
<node CREATED="1597654745429" ID="ID_1739031417" MODIFIED="1597654747053" TEXT="..."/>
</node>
</node>
</node>
<node CREATED="1597654766178" FOLDED="true" ID="ID_1902094356" MODIFIED="1597655107404" TEXT="07.可审计">
<node CREATED="1597654781612" ID="ID_919623425" MODIFIED="1597654795872" TEXT="记录所有敏感操作, 用于事件追溯"/>
<node CREATED="1597654848131" FOLDED="true" ID="ID_272436170" MODIFIED="1597655107404" TEXT="操作日志内容">
<node CREATED="1597654870673" ID="ID_787777966" MODIFIED="1597654881318" TEXT="时间"/>
<node CREATED="1597654873016" ID="ID_170371486" MODIFIED="1597654883877" TEXT="地点"/>
<node CREATED="1597654884484" ID="ID_788575233" MODIFIED="1597654893914" TEXT="人物"/>
<node CREATED="1597654894143" FOLDED="true" ID="ID_259155489" MODIFIED="1597655107403" TEXT="事件">
<node CREATED="1597654926312" ID="ID_1175324670" MODIFIED="1597654933829" TEXT="操作"/>
<node CREATED="1597654928511" ID="ID_310398366" MODIFIED="1597654930961" TEXT="操作对象"/>
</node>
</node>
<node CREATED="1597654980872" FOLDED="true" ID="ID_804535897" MODIFIED="1597655107404" TEXT="存储">
<node CREATED="1597654994815" ID="ID_1991117247" MODIFIED="1597655008931" TEXT="应用自身保存"/>
<node CREATED="1597655009194" ID="ID_262610036" MODIFIED="1597655020342" TEXT="发送到日志管理系统"/>
</node>
<node CREATED="1597655034696" FOLDED="true" ID="ID_1071280500" MODIFIED="1597655107404" TEXT="保留期限">
<node CREATED="1597655038721" FOLDED="true" ID="ID_253936133" MODIFIED="1597655107404" TEXT="大于6个月">
<node CREATED="1597655051830" ID="ID_1319264813" MODIFIED="1597655077575" TEXT="需要自动清理过期日志防止磁盘写满影响可用性"/>
</node>
</node>
<node CREATED="1597654947470" FOLDED="true" ID="ID_1574272133" MODIFIED="1597655107404" TEXT="注意">
<node CREATED="1597654949869" ID="ID_1088739923" MODIFIED="1597654976132" TEXT="需要对敏感数据进行脱敏处理"/>
</node>
</node>
<node CREATED="1597655091344" FOLDED="true" ID="ID_1096666832" MODIFIED="1601009245152" TEXT="08.资产保护">
<node CREATED="1597655395498" ID="ID_443813253" MODIFIED="1597655398437" TEXT="数据存储安全">
<node CREATED="1597655399170" ID="ID_871125217" MODIFIED="1597655449305" TEXT="为防止原始数据窃取后或攻击者直接查看数据等方式导致敏感信息泄露"/>
<node CREATED="1597655460413" ID="ID_497252210" MODIFIED="1597655476921" TEXT="哪些敏感数据需要加密">
<node CREATED="1597655478230" ID="ID_1508833946" MODIFIED="1597655509964" TEXT="敏感个人信息及涉及个人隐私的数据、用户产生的数据"/>
<node CREATED="1597655510616" ID="ID_1545579165" MODIFIED="1597655552110" TEXT="口令、加解密密钥、私钥等需要加密存储(不需要还原的口令使用单向散列)"/>
<node CREATED="1597655556642" ID="ID_1816828303" MODIFIED="1597655573586" TEXT="有明确检索、排序、求和等运算的业务数据不需要加密">
<node CREATED="1597655616136" ID="ID_744004759" MODIFIED="1597655630980" TEXT="针对加密数据检索方案">
<node CREATED="1597655633915" ID="ID_130172997" MODIFIED="1597655687309" TEXT="增加关键词, 用于辅助检索, 缩小范围, 再对相关记录执行解密比较"/>
</node>
</node>
</node>
<node CREATED="1597655748583" ID="ID_1289194438" MODIFIED="1597655751839" TEXT="数据加密方式">
<node CREATED="1597655752635" ID="ID_262952009" MODIFIED="1597655762188" TEXT="字段加密">
<node CREATED="1597655766374" ID="ID_1380940878" MODIFIED="1597655784084" TEXT="应用层对数据进行加解密 "/>
</node>
<node CREATED="1597655762411" ID="ID_138975434" MODIFIED="1597655764971" TEXT="静态加密">
<node CREATED="1597655786077" ID="ID_402922284" MODIFIED="1597655814996" TEXT="在存储侧自动完成底层加密, 开发人员无需关注"/>
</node>
</node>
<node CREATED="1597655835562" ID="ID_1583810640" MODIFIED="1597655837570" TEXT="密钥管理">
<node CREATED="1597655838613" ID="ID_1714368612" MODIFIED="1597655843076" TEXT="自管理密钥"/>
<node CREATED="1597655843704" ID="ID_1860285224" MODIFIED="1597655855397" TEXT="密钥管理系统"/>
</node>
<node CREATED="1597656012636" ID="ID_1232991543" MODIFIED="1597656019314" TEXT="加密系统">
<node CREATED="1597656020115" ID="ID_1049238481" MODIFIED="1597656033620" TEXT="至少需要二级或二级以上加密机制">
<node CREATED="1597656035040" ID="ID_1246675188" MODIFIED="1597656038892" TEXT="对数据加密"/>
<node CREATED="1597656044604" ID="ID_222531679" MODIFIED="1597656050876" TEXT="对加密密钥加密"/>
</node>
<node CREATED="1597656066909" ID="ID_1627751900" MODIFIED="1597656068358" TEXT="原则">
<node CREATED="1597656069130" ID="ID_984307070" MODIFIED="1597656083911" TEXT="数据加密密钥">
<node CREATED="1597656084830" ID="ID_526534129" MODIFIED="1597656097285" TEXT="每条记录使用不同密钥"/>
<node CREATED="1597656098189" ID="ID_230402809" MODIFIED="1597656117671" TEXT="密钥加密后与密文数据一起存储"/>
</node>
<node CREATED="1597656075131" ID="ID_1428966958" MODIFIED="1597656079771" TEXT="密钥加密密钥">
<node CREATED="1597656121839" ID="ID_1323944769" MODIFIED="1597656150193" TEXT="每个应用或每个用户的每个应用使用不同密钥"/>
<node CREATED="1597656154615" ID="ID_757108735" MODIFIED="1597656161145" TEXT="密钥存储与KMS系统中"/>
</node>
</node>
</node>
</node>
<node CREATED="1597655456402" ID="ID_910277609" MODIFIED="1597656175979" TEXT="数据安全传输">
<node CREATED="1597656176672" ID="ID_849501814" MODIFIED="1597656190818" TEXT="保证数据的机密性与完整性"/>
<node CREATED="1597656217877" ID="ID_792912959" MODIFIED="1597656229626" TEXT="方案">
<node CREATED="1597656230412" ID="ID_103235670" MODIFIED="1597656231490" TEXT="web">
<node CREATED="1597656235293" ID="ID_722520380" MODIFIED="1597656245744" TEXT="启用HTTPS协议"/>
</node>
<node CREATED="1597656231804" ID="ID_1364049867" MODIFIED="1597656234111" TEXT="api">
<node CREATED="1597656247429" ID="ID_37742232" MODIFIED="1597656250913" TEXT="启用HTTPS协议"/>
<node CREATED="1597656251166" ID="ID_700209115" MODIFIED="1597656269208" TEXT="基于共享密钥的认证加密机制">
<node CREATED="1597656269985" ID="ID_1603149935" MODIFIED="1597656272485" TEXT="AES-GCM"/>
</node>
</node>
</node>
<node CREATED="1597656929666" ID="ID_1921293854" MODIFIED="1597657266112" TEXT="https证书">
<node CREATED="1597657266090" ID="ID_848937707" MODIFIED="1597657267965" TEXT="分类">
<node CREATED="1597657066916" ID="ID_1961952936" MODIFIED="1597657073242" TEXT="按验证信息">
<node CREATED="1597656936912" ID="ID_249591793" MODIFIED="1597656939921" TEXT="DV证书">
<node CREATED="1597656957687" ID="ID_20550453" MODIFIED="1597656965567" TEXT="域名验证型"/>
<node CREATED="1597656965858" ID="ID_1928942839" MODIFIED="1597656985648" TEXT="只证明域名有效, 不包含组织信息(O)"/>
<node CREATED="1597657001783" ID="ID_1853979" MODIFIED="1597657005268" TEXT="适用于个人"/>
</node>
<node CREATED="1597656940158" ID="ID_1863012109" MODIFIED="1597656942785" TEXT="OV证书">
<node CREATED="1597656957687" ID="ID_585740333" MODIFIED="1597656998148" TEXT="组织验证型"/>
<node CREATED="1597656965858" ID="ID_1716489684" MODIFIED="1597657027390" TEXT="证书包含组织信息(O)"/>
<node CREATED="1597657028859" ID="ID_892828218" MODIFIED="1597657032779" TEXT="适用于企业"/>
</node>
<node CREATED="1597656943015" ID="ID_1214664614" MODIFIED="1597656945729" TEXT="EV证书">
<node CREATED="1597657035286" ID="ID_269760396" MODIFIED="1597657043240" TEXT="扩展验证型"/>
</node>
</node>
<node CREATED="1597657076641" ID="ID_1146622166" MODIFIED="1597657078806" TEXT="按域名">
<node CREATED="1597657079878" ID="ID_84805207" MODIFIED="1597657087208" TEXT="单域名证书"/>
<node CREATED="1597657087502" ID="ID_534661207" MODIFIED="1597657090690" TEXT="多域名证书"/>
<node CREATED="1597657090949" ID="ID_933770760" MODIFIED="1597657097494" TEXT="通配型证书"/>
</node>
</node>
<node CREATED="1597657261561" ID="ID_1159794915" MODIFIED="1597657292871" TEXT="加固配置">
<node CREATED="1597657293589" ID="ID_806127280" MODIFIED="1597657319174" TEXT="禁用SSL及TLS1.0, 建议使用TLS1.2版本及以上"/>
<node CREATED="1597657319478" ID="ID_1461561509" MODIFIED="1597657336978" TEXT="密码算法使用向前安全算法"/>
<node CREATED="1597657337232" ID="ID_372168601" MODIFIED="1597657353645" TEXT="启用HSTS强制浏览器跳转奥HTTPS">
<node CREATED="1597657360779" ID="ID_664875811" MODIFIED="1597657371094" TEXT="Response Header添加">
<node CREATED="1597657373757" ID="ID_1852329543" MODIFIED="1597657412160" TEXT="Strict-Transport-Security: max-age=31536000; includesubDomains"/>
</node>
</node>
</node>
</node>
</node>
<node CREATED="1597657427668" ID="ID_873364463" MODIFIED="1597657433686" TEXT="数据显示与脱敏">
<node CREATED="1597657441697" ID="ID_674899883" MODIFIED="1597657462129" TEXT="按照一定规则对数据进行变形、隐藏或部分隐藏处理"/>
<node CREATED="1597657513158" ID="ID_221765750" MODIFIED="1597657517386" TEXT="注意">
<node CREATED="1597657518120" ID="ID_1592844474" MODIFIED="1597657528779" TEXT="各业务脱敏标准保持一致"/>
<node CREATED="1597657529031" ID="ID_702231563" MODIFIED="1597657547730" TEXT="在数据接口中进行脱敏"/>
<node CREATED="1597657593282" ID="ID_1582832613" MODIFIED="1597657645249" TEXT="针对需要查询明文信息使用受控方式让主体查询获取">
<node CREATED="1597657657060" ID="ID_759386740" MODIFIED="1597657669322" TEXT="查询次数限制"/>
<node CREATED="1597657671721" ID="ID_1387301379" MODIFIED="1597657676186" TEXT="记录查询日志"/>
</node>
</node>
</node>
<node CREATED="1597657682686" ID="ID_1766118867" MODIFIED="1597657687397" TEXT="数据完整性检查">
<node CREATED="1597657767862" ID="ID_1959486175" MODIFIED="1597657774649" TEXT="单向散列"/>
<node CREATED="1597657782893" ID="ID_1127071963" MODIFIED="1597657787330" TEXT="HMAC"/>
<node CREATED="1597657790285" ID="ID_748330339" MODIFIED="1597657796480" TEXT="AES-GCM"/>
<node CREATED="1597657796729" ID="ID_311843168" MODIFIED="1597657801288" TEXT="数字签名"/>
</node>
</node>
<node CREATED="1597657815204" ID="ID_839873489" MODIFIED="1597657819450" TEXT="09.业务安全">
<node CREATED="1597658000187" ID="ID_1201840009" MODIFIED="1597658007257" TEXT="产品自身逻辑安全"/>
<node CREATED="1597658165439" ID="ID_1702821438" MODIFIED="1597658168038" TEXT="账号安全">
<node CREATED="1597658168725" ID="ID_1715587803" MODIFIED="1597658332599" TEXT="防弱口令及撞库">
<node CREATED="1597658332592" ID="ID_1694073301" MODIFIED="1597658402815" TEXT="防御手段">
<node CREATED="1597658287024" ID="ID_743327942" MODIFIED="1597658304958" TEXT="前端慢速加盐散列"/>
<node CREATED="1597658305207" ID="ID_681895651" MODIFIED="1597658318778" TEXT="频率限制"/>
<node CREATED="1597658319058" ID="ID_785121045" MODIFIED="1597658322967" TEXT="总量限制"/>
<node CREATED="1597658323240" ID="ID_834224479" MODIFIED="1597658410665" TEXT="IP锁定"/>
<node CREATED="1597658327254" ID="ID_1370898488" MODIFIED="1597658329263" TEXT="验证码"/>
</node>
</node>
<node CREATED="1597658183582" ID="ID_584332289" MODIFIED="1597658195240" TEXT="防账号数据库泄露">
<node CREATED="1597658488632" ID="ID_745837803" MODIFIED="1597658491323" TEXT="防御手段">
<node CREATED="1597658492204" ID="ID_1952264755" MODIFIED="1597658500973" TEXT="对口令进行hash运算">
<node CREATED="1597658502486" ID="ID_84499062" MODIFIED="1597658516912" TEXT="至少采用sha256"/>
</node>
</node>
</node>
<node CREATED="1597658195519" ID="ID_175578258" MODIFIED="1597658202359" TEXT="防垃圾账号">
<node CREATED="1597658556303" ID="ID_1626484355" MODIFIED="1597658558798" TEXT="防御手段">
<node CREATED="1597658559709" ID="ID_1321543937" MODIFIED="1597658587276" TEXT="借助实名验证、手机认证、邮箱认证、验证码等手段防止批量注册"/>
<node CREATED="1597658587572" ID="ID_1057475086" MODIFIED="1597658593119" TEXT="借助风控系统">
<node CREATED="1597658594532" ID="ID_222387603" MODIFIED="1597658632828" TEXT="针对有大量实名认证账号、短信发送设备等情况"/>
</node>
</node>
</node>
<node CREATED="1597658202609" ID="ID_278226543" MODIFIED="1597658211491" TEXT="防账号找回逻辑缺陷"/>
</node>
<node CREATED="1597659389021" ID="ID_1606583808" MODIFIED="1597659481489" TEXT="B2B交易安全">
<node CREATED="1597659481481" ID="ID_1089622299" MODIFIED="1597659490199" TEXT="双方身份确认">
<node CREATED="1597659429101" ID="ID_1834774793" MODIFIED="1597659479278" TEXT="交易数据->甲方数据签名->乙方公钥加密--https传输-->乙方私钥解密->甲方公钥解密->交易数据"/>
</node>
<node CREATED="1597659509456" ID="ID_971341341" MODIFIED="1597659514802" TEXT="详细日志"/>
</node>
<node CREATED="1597659736833" ID="ID_1357568038" MODIFIED="1597659746222" TEXT="产品防攻击能力">
<node CREATED="1597659746947" ID="ID_866977356" MODIFIED="1597659755501" TEXT="网页静态化与缓存"/>
<node CREATED="1597659755745" ID="ID_1082069157" MODIFIED="1597659763231" TEXT="消息队列与异步机制"/>
<node CREATED="1597659763471" ID="ID_413406403" MODIFIED="1597659769356" TEXT="负载均衡"/>
</node>
</node>
</node>
<node CREATED="1597659776949" FOLDED="true" ID="ID_32805191" MODIFIED="1601009254183" POSITION="right" TEXT="安全技术体系架构">
<node CREATED="1597720227881" FOLDED="true" ID="ID_137355387" MODIFIED="1597799763035" TEXT="10.简介">
<node CREATED="1597714156706" FOLDED="true" ID="ID_720282126" MODIFIED="1597799763031" TEXT="基础设施">
<node CREATED="1597714165617" FOLDED="true" ID="ID_1007965792" MODIFIED="1597799763031" TEXT="通用基础设施">
<node CREATED="1597714198737" ID="ID_661364500" MODIFIED="1597714205474" TEXT="基础网络架构"/>
<node CREATED="1597714205856" ID="ID_1509743308" MODIFIED="1597714207407" TEXT="DNS"/>
<node CREATED="1597714207742" ID="ID_1907431677" MODIFIED="1597714220837" TEXT="资产及配置管理数据库CMDB"/>
<node CREATED="1597714223959" ID="ID_1923762653" MODIFIED="1597714226432" TEXT="..."/>
</node>
<node CREATED="1597714170658" FOLDED="true" ID="ID_1914451278" MODIFIED="1597799763031" TEXT="安全组件与支撑系统">
<node CREATED="1597714227894" ID="ID_358267075" MODIFIED="1597714230053" TEXT="SSO"/>
<node CREATED="1597714230304" ID="ID_1442058269" MODIFIED="1597714231445" TEXT="KMS"/>
<node CREATED="1597714231882" ID="ID_1977242842" MODIFIED="1597714241615" TEXT="权限管理系统"/>
<node CREATED="1597714241886" ID="ID_1204181232" MODIFIED="1597714246434" TEXT="统一日志平台"/>
<node CREATED="1597714246892" ID="ID_1842595536" MODIFIED="1597714252264" TEXT="数据服务"/>
<node CREATED="1597714252792" ID="ID_1815725862" MODIFIED="1597714255838" TEXT="..."/>
</node>
<node CREATED="1597714186002" FOLDED="true" ID="ID_78380777" MODIFIED="1597799763031" TEXT="安全防御基础设施">
<node CREATED="1597714257874" ID="ID_1541451027" MODIFIED="1597714267525" TEXT="抗DDos"/>
<node CREATED="1597714268031" ID="ID_1657906258" MODIFIED="1597714273663" TEXT="H/NIDS"/>
<node CREATED="1597714273983" ID="ID_712582938" MODIFIED="1597714282774" TEXT="WAF防御"/>
<node CREATED="1597714283702" ID="ID_1855568632" MODIFIED="1597714285964" TEXT="CC防御"/>
<node CREATED="1597714286298" ID="ID_1096410478" MODIFIED="1597714287347" TEXT="..."/>
</node>
<node CREATED="1597714190763" FOLDED="true" ID="ID_529594636" MODIFIED="1597799763031" TEXT="安全运维基础设施">
<node CREATED="1597714289350" ID="ID_241593244" MODIFIED="1597714292381" TEXT="跳板机"/>
<node CREATED="1597714292654" ID="ID_1496456180" MODIFIED="1597714297160" TEXT="自动化运维平台"/>
<node CREATED="1597714297423" ID="ID_796261424" MODIFIED="1597714301418" TEXT="数据传输熊"/>
<node CREATED="1597714302264" ID="ID_1780110881" MODIFIED="1597714303333" TEXT="..."/>
</node>
</node>
<node CREATED="1597714315605" FOLDED="true" ID="ID_840787155" MODIFIED="1597799763032" TEXT="安全建设">
<node CREATED="1597714324784" ID="ID_251152480" MODIFIED="1597714364364" TEXT="安全建设没有捷径,需要从最基础的地方开始建设, 做好基本功, 步步为营, 层层设防"/>
<node CREATED="1597714366042" FOLDED="true" ID="ID_1617835470" MODIFIED="1597799763032" TEXT="思路">
<node CREATED="1597714371146" FOLDED="true" ID="ID_1609423155" MODIFIED="1597799763031" TEXT="以检测为主的防御性建设">
<node CREATED="1597714402720" FOLDED="true" ID="ID_711794014" MODIFIED="1597799763031" TEXT="模型">
<node CREATED="1597714406368" ID="ID_1680821913" MODIFIED="1597714413555" TEXT="检测-响应-恢复"/>
</node>
<node CREATED="1597714425761" ID="ID_1914863927" MODIFIED="1597714463889" TEXT="建设入侵检测系统, 要求出问题及时修复, 检测系统告警触发应急响应"/>
</node>
<node CREATED="1597714381742" FOLDED="true" ID="ID_1097060095" MODIFIED="1597799763032" TEXT="以预防为主的安全生命周期建设">
<node CREATED="1597714467703" FOLDED="true" ID="ID_1681254839" MODIFIED="1597799763031" TEXT="模型">
<node CREATED="1597714469832" ID="ID_1974122818" MODIFIED="1597714473135" TEXT="SDL"/>
</node>
<node CREATED="1597714479217" ID="ID_684658412" MODIFIED="1597714505733" TEXT="将安全要素与检查点嵌入到产品的项目管理中, 将风险控制在发布前"/>
</node>
</node>
<node CREATED="1597716382445" FOLDED="true" ID="ID_1633075585" MODIFIED="1597799763032" TEXT="维度">
<node CREATED="1597716403605" FOLDED="true" ID="ID_75508112" MODIFIED="1597799763032" TEXT="安全架构">
<node CREATED="1597716413021" ID="ID_544654382" MODIFIED="1597716416360" TEXT="身份认证"/>
<node CREATED="1597716416591" ID="ID_259564825" MODIFIED="1597716417996" TEXT="授权"/>
<node CREATED="1597716418215" ID="ID_205457696" MODIFIED="1597716420224" TEXT="访问控制"/>
<node CREATED="1597716420466" ID="ID_567533721" MODIFIED="1597716422843" TEXT="审计"/>
<node CREATED="1597716423092" ID="ID_1717199338" MODIFIED="1597716428351" TEXT="资产保护"/>
</node>
<node CREATED="1597716406673" FOLDED="true" ID="ID_1802925269" MODIFIED="1597799763032" TEXT="网络分层">
<node CREATED="1597716429969" ID="ID_1421099723" MODIFIED="1597716432549" TEXT="应用与数据"/>
<node CREATED="1597716432773" ID="ID_1743167661" MODIFIED="1597716440921" TEXT="设备与主机"/>
<node CREATED="1597716441196" ID="ID_521868330" MODIFIED="1597716445237" TEXT="网络与通信"/>
<node CREATED="1597716445496" ID="ID_786586250" MODIFIED="1597716450716" TEXT="物理与环境"/>
</node>
</node>
</node>
<node CREATED="1597719111289" FOLDED="true" ID="ID_1903435867" MODIFIED="1597799763033" TEXT="三道防线">
<node CREATED="1597719118067" FOLDED="true" ID="ID_935579255" MODIFIED="1597799763032" TEXT="业务部门">
<node CREATED="1597719132144" ID="ID_1414015554" MODIFIED="1597719150950" TEXT="对风险负责主要责任, 需要考虑从源头控制风险"/>
</node>
<node CREATED="1597719123554" FOLDED="true" ID="ID_265246422" MODIFIED="1597799763033" TEXT="风险管理部门">
<node CREATED="1597719152567" ID="ID_392980996" MODIFIED="1597719168814" TEXT="提供整体风险控制方案"/>
<node CREATED="1597719415438" FOLDED="true" ID="ID_192879315" MODIFIED="1597799763032" TEXT="安全技术体系">
<node CREATED="1597719464995" ID="ID_1931273466" MODIFIED="1597719464995" TEXT="构建安全的基础设施、工具和技术以及各种支撑系统, 为产品的安全能力提供加持"/>
<node CREATED="1597719476462" FOLDED="true" ID="ID_1658834135" MODIFIED="1597799763032" TEXT="主要工作">
<node CREATED="1597719483018" ID="ID_1041948959" MODIFIED="1597719495626" TEXT="建立和完善数据安全政策文件体系"/>
<node CREATED="1597719505199" ID="ID_346360867" MODIFIED="1597719519597" TEXT="管理内外安全合规、认证评测、渗透测试"/>
<node CREATED="1597719519860" ID="ID_912584140" MODIFIED="1597719529671" TEXT="协助建立/完善通用的基础设施"/>
<node CREATED="1597719530282" ID="ID_1140254353" MODIFIED="1597719582681" TEXT="协助并完善相关的安全防御基础设施、安全运维基础设施、安全支撑系统、风险识别工具、运维工具等"/>
<node CREATED="1597719639507" ID="ID_82811633" MODIFIED="1597719653180" TEXT="建立完善的安全组件与支撑系统"/>
<node CREATED="1597719654107" ID="ID_698109876" MODIFIED="1597719664724" TEXT="完善各种安全工具与技术"/>
<node CREATED="1597719664954" ID="ID_199434847" MODIFIED="1597719702788" TEXT="考虑建设数据中台, 将数据作为生产力, 并统一执行安全管理"/>
<node CREATED="1597719704891" ID="ID_1352024368" MODIFIED="1597719752718" TEXT="例行开展扫描、检测活动,为风险数据化运营提供数据,执行风险规避措施"/>
<node CREATED="1597719753686" ID="ID_1088274572" MODIFIED="1597719762356" TEXT="风险管理、事件管理与应急响应"/>
</node>
</node>
</node>
<node CREATED="1597719127739" FOLDED="true" ID="ID_129048529" MODIFIED="1597799763033" TEXT="审计部门">
<node CREATED="1597719809630" ID="ID_658518108" MODIFIED="1597719846597" TEXT="识别风险并提出改进建议"/>
</node>
</node>
<node CREATED="1597720251146" FOLDED="true" ID="ID_1527953984" MODIFIED="1597799763035" TEXT="强化产品安全">
<node CREATED="1597720711196" FOLDED="true" ID="ID_1138847537" MODIFIED="1597799763033" TEXT="网络部署架构">
<node CREATED="1597720724038" ID="ID_904520252" MODIFIED="1597720885333" TEXT="服务器不配置外网网卡, 统一接入网关反向代理, 减少安全域和防火墙使用, 接入网关可与安全基础设施集成"/>
</node>
<node CREATED="1597720716092" FOLDED="true" ID="ID_382093298" MODIFIED="1597799763033" TEXT="主机层安全">
<node CREATED="1597720912224" FOLDED="true" ID="ID_1809665098" MODIFIED="1597799763033" TEXT="端口扫描">
<node CREATED="1597720937211" ID="ID_917646539" MODIFIED="1597720948844" TEXT="发现不必要的开发端口和服务"/>
<node CREATED="1597722164616" ID="ID_1415627134" MODIFIED="1597722171601" TEXT="只开放web服务"/>
</node>
<node CREATED="1597721008326" FOLDED="true" ID="ID_1634650227" MODIFIED="1597799763033" TEXT="内部组件源">
<node CREATED="1597721028991" ID="ID_781341367" MODIFIED="1597721057583" TEXT="使用来源可信、版本安全、经过评估的开源组件"/>
</node>
<node CREATED="1597721067768" ID="ID_77399428" MODIFIED="1597721100196" TEXT="组件云化&部署自动化"/>
<node CREATED="1597721124976" FOLDED="true" ID="ID_1116950300" MODIFIED="1597799763033" TEXT="HIDS">
<node CREATED="1597721128306" ID="ID_874489743" MODIFIED="1597721133321" TEXT="检测恶意文件"/>
<node CREATED="1597721133573" ID="ID_795762237" MODIFIED="1597721136595" TEXT="暴力破解"/>
<node CREATED="1597721136850" FOLDED="true" ID="ID_602799635" MODIFIED="1597799763033" TEXT="弱口令检测">
<node CREATED="1597721145486" ID="ID_540631670" MODIFIED="1597721150522" TEXT="通过彩虹表比对"/>
</node>
</node>
</node>
<node CREATED="1597721156211" FOLDED="true" ID="ID_532858705" MODIFIED="1597799763034" TEXT="应用层安全">
<node CREATED="1597722480142" FOLDED="true" ID="ID_1509648745" MODIFIED="1597799763033" TEXT="认证">
<node CREATED="1597722156078" ID="ID_424564713" MODIFIED="1597722183250" TEXT="非公开web服务必须有认证"/>
<node CREATED="1597722147319" FOLDED="true" ID="ID_1875898065" MODIFIED="1597799763033" TEXT="统一认证">
<node CREATED="1597722574060" ID="ID_1891906163" MODIFIED="1597722575340" TEXT="SSO"/>
<node CREATED="1597722435707" ID="ID_55266046" MODIFIED="1597722443532" TEXT="前端慢速加盐散列"/>
<node CREATED="1597722549267" ID="ID_790664626" MODIFIED="1597722568509" TEXT="接入网关统一认证"/>
</node>
</node>
<node CREATED="1597722484132" FOLDED="true" ID="ID_1589769618" MODIFIED="1597799763034" TEXT="授权">
<node CREATED="1597722492805" ID="ID_1863267441" MODIFIED="1597722496318" TEXT="最小权限控制"/>
<node CREATED="1597722496548" ID="ID_1519017862" MODIFIED="1597722499061" TEXT="职责分离"/>
<node CREATED="1597722503113" ID="ID_1050371392" MODIFIED="1597722510697" TEXT="外部权限管理系统"/>
</node>
<node CREATED="1597722649424" FOLDED="true" ID="ID_1913677892" MODIFIED="1597799763034" TEXT="上传文件">
<node CREATED="1597722652619" ID="ID_1728750643" MODIFIED="1597722663728" TEXT="可写目录不执行,执行目录不可写"/>
</node>
<node CREATED="1597722584320" FOLDED="true" ID="ID_890529952" MODIFIED="1597799763034" TEXT="审计">
<node CREATED="1597722604803" ID="ID_1997748604" MODIFIED="1597722622676" TEXT="操作日志实时上传日志系统"/>
</node>
</node>
<node CREATED="1597722643388" FOLDED="true" ID="ID_1159301079" MODIFIED="1597799763035" TEXT="数据安全">
<node CREATED="1597723324280" FOLDED="true" ID="ID_114724973" MODIFIED="1597799763034" TEXT="数据层">
<node CREATED="1597723314976" FOLDED="true" ID="ID_1257061678" MODIFIED="1597799763034" TEXT="封装数据服务构建数据中台">
<node CREATED="1597723352412" ID="ID_417050191" MODIFIED="1597723359999" TEXT="构建API访问数据"/>
<node CREATED="1597723367203" ID="ID_221473157" MODIFIED="1597723377061" TEXT="消除数据库账号使用"/>
</node>
</node>
<node CREATED="1597723388868" FOLDED="true" ID="ID_520594072" MODIFIED="1597799763034" TEXT="密钥管理系统">
<node CREATED="1597723399911" ID="ID_1758220669" MODIFIED="1597723409178" TEXT="应用层使用KMS系统管理密钥"/>
</node>
<node CREATED="1597723427537" FOLDED="true" ID="ID_1911950344" MODIFIED="1597799763034" TEXT="全站HTTPS">
<node CREATED="1597723574236" ID="ID_235853440" MODIFIED="1597723577889" TEXT="统一管理证书"/>
<node CREATED="1597723607570" ID="ID_1156902888" MODIFIED="1597723611246" TEXT="禁用不安全协议"/>
<node CREATED="1597723618322" ID="ID_591362181" MODIFIED="1597723626211" TEXT="在接入网关集中管理"/>
</node>
<node CREATED="1597723692064" FOLDED="true" ID="ID_1956409975" MODIFIED="1597799763035" TEXT="数据脱敏">
<node CREATED="1597723696076" ID="ID_319367691" MODIFIED="1597723701875" TEXT="应用自身完成脱敏"/>
<node CREATED="1597723702095" ID="ID_711060019" MODIFIED="1597723713905" TEXT="API网关爱用定制化脱敏"/>
</node>
<node CREATED="1597723731903" FOLDED="true" ID="ID_770232909" MODIFIED="1597799763035" TEXT="个人隐私数据">
<node CREATED="1597723738951" ID="ID_797721695" MODIFIED="1597723761513" TEXT="不能直接对第三方提供用户个人隐私数据集"/>
<node CREATED="1597723806540" ID="ID_1651689064" MODIFIED="1597724279724" TEXT="针对不同隐私数据及时征求用户统一, 并由用户主动勾选同意选项"/>
<node CREATED="1597724592750" FOLDED="true" ID="ID_1529866281" MODIFIED="1597799763035" TEXT="增强隐私技术">
<node CREATED="1597724598114" ID="ID_807295027" MODIFIED="1597724602656" TEXT="K-匿名"/>
<node CREATED="1597724602908" ID="ID_831534777" MODIFIED="1597724608076" TEXT="差分隐私"/>
</node>
</node>
</node>
<node CREATED="1597724917735" FOLDED="true" ID="ID_1251855429" MODIFIED="1597799763035" TEXT="物理&环境层">
<node CREATED="1597724927583" ID="ID_1278848565" MODIFIED="1597724945107" TEXT="门禁&出入等级"/>
<node CREATED="1597724945347" ID="ID_186600576" MODIFIED="1597724949755" TEXT="监控摄像"/>
<node CREATED="1597724949984" ID="ID_1579274151" MODIFIED="1597724952784" TEXT="红外告警"/>
</node>
</node>
</node>
<node CREATED="1597724961813" FOLDED="true" ID="ID_289615015" MODIFIED="1597811833681" TEXT="11.网络和通信层安全架构">
<node CREATED="1597725420129" FOLDED="true" ID="ID_842161265" MODIFIED="1597799763036" TEXT="基础设施">
<node CREATED="1597725291017" FOLDED="true" ID="ID_1412456025" MODIFIED="1597799763035" TEXT="通用基础设施">
<node CREATED="1597725296624" ID="ID_476286878" MODIFIED="1597725299706" TEXT="网络安全域"/>
<node CREATED="1597725299939" ID="ID_848929780" MODIFIED="1597725312109" TEXT="防火墙及配套防火墙管理系统"/>
<node CREATED="1597725312760" FOLDED="true" ID="ID_1064399060" MODIFIED="1597799763035" TEXT="四层网关">
<node CREATED="1597725329763" ID="ID_1629181640" MODIFIED="1597725362697" TEXT="用于受控任意协议的NAT转发"/>
</node>
</node>
<node CREATED="1597725366727" FOLDED="true" ID="ID_1257591908" MODIFIED="1597799763035" TEXT="防御基础设施">
<node CREATED="1597725371384" ID="ID_975117986" MODIFIED="1597725374418" TEXT="抗D"/>
<node CREATED="1597725440955" FOLDED="true" ID="ID_988920298" MODIFIED="1597799763035" TEXT="NIPS">
<node CREATED="1597725449714" ID="ID_1995470653" MODIFIED="1597725462289" TEXT="不适用与HTTPS或加密传输协议"/>
</node>
<node CREATED="1597725376441" ID="ID_860290692" MODIFIED="1597725380295" TEXT="网络准入控制"/>
</node>
<node CREATED="1597725387440" FOLDED="true" ID="ID_948476315" MODIFIED="1597799763035" TEXT="其他">
<node CREATED="1597725393571" ID="ID_1702695884" MODIFIED="1597725396682" TEXT="运维通道"/>
<node CREATED="1597725396935" ID="ID_849473111" MODIFIED="1597725403037" TEXT="网络流量审计"/>
</node>
</node>
<node CREATED="1597725490656" FOLDED="true" ID="ID_1896518629" MODIFIED="1597744060483" TEXT="安全域">
<node CREATED="1597725493377" ID="ID_725939393" MODIFIED="1597725515879" TEXT="相同安全等级的主机组成的逻辑区域"/>
<node CREATED="1597725535203" FOLDED="true" ID="ID_494721387" MODIFIED="1597799763036" TEXT="由路由、交换机ACL、防火墙等进行实施隔离访问控制">
<node CREATED="1597725682456" ID="ID_1544156181" MODIFIED="1597725699868" TEXT="路由、交换机ACL变更频率低"/>
</node>
<node CREATED="1597725799367" FOLDED="true" ID="ID_945288019" MODIFIED="1597799763036" TEXT="安全域数量在满足合规情况下越少越好">
<node CREATED="1597725758507" ID="ID_1047928168" MODIFIED="1597725794237" TEXT="规则集数量 = 安全域数量 * (安全域数量 - 1)"/>
</node>
<node CREATED="1597725839027" FOLDED="true" ID="ID_1710053468" MODIFIED="1597799763036" TEXT="安全域划分">
<node CREATED="1597726123095" ID="ID_1016021470" MODIFIED="1597726126435" TEXT="外部网络"/>
<node CREATED="1597726126665" ID="ID_195107286" MODIFIED="1597726129688" TEXT="办公网络"/>
<node CREATED="1597726129931" FOLDED="true" ID="ID_1121341825" MODIFIED="1597799763036" TEXT="生产网络">
<node CREATED="1597726141266" FOLDED="true" ID="ID_254800706" MODIFIED="1597799763036" TEXT="普通区">
<node CREATED="1597726195678" ID="ID_590713131" MODIFIED="1597726223101" TEXT="针对业务服务器仅保留内网IP地址"/>
<node CREATED="1597726168745" ID="ID_1042902900" MODIFIED="1597726190218" TEXT="由内/外部接入网关代理所有业务请求"/>
</node>
<node CREATED="1597726143567" FOLDED="true" ID="ID_1391349239" MODIFIED="1597799763036" TEXT="敏感区">
<node CREATED="1597726231973" ID="ID_1643144142" MODIFIED="1597726237504" TEXT="仅保留内网IP地址"/>
<node CREATED="1597726252653" ID="ID_414547260" MODIFIED="1597726271640" TEXT="使用防火墙限制业务服务器访问"/>
<node CREATED="1597726141266" ID="ID_21254228" MODIFIED="1597726781257" TEXT="使用数据服务,通过API对外提供数据操作"/>
</node>
</node>
</node>
</node>
<node CREATED="1597726954063" FOLDED="true" ID="ID_1430722603" MODIFIED="1597744058011" TEXT="网络接入身份认证">
<node CREATED="1597732541389" FOLDED="true" ID="ID_1123074519" MODIFIED="1597799763036" TEXT="认证对象">
<node CREATED="1597732544539" FOLDED="true" ID="ID_1187952529" MODIFIED="1597799763036" TEXT="人">
<node CREATED="1597732576147" ID="ID_1904126303" MODIFIED="1597732585906" TEXT="Windows操作系统域认证"/>
<node CREATED="1597732586166" ID="ID_1167262718" MODIFIED="1597732616445" TEXT="安全客户端配合统一的SSO系统"/>
<node CREATED="1597732621143" ID="ID_1201725483" MODIFIED="1597732628222" TEXT="无线使用WebAuth认证"/>
</node>
<node CREATED="1597732545991" FOLDED="true" ID="ID_2581525" MODIFIED="1597799763036" TEXT="设备">
<node CREATED="1597732557947" ID="ID_241277993" MODIFIED="1597732574627" TEXT="配合NAC"/>
<node CREATED="1597732635239" ID="ID_1802359358" MODIFIED="1597732651207" TEXT="设备ID与MAC地址比对"/>
<node CREATED="1597732652197" ID="ID_1163723189" MODIFIED="1597732657235" TEXT="设备数字证书"/>
</node>
</node>
<node CREATED="1597732678281" FOLDED="true" ID="ID_1471850942" MODIFIED="1597799763036" TEXT="实施计划">
<node CREATED="1597732699873" FOLDED="true" ID="ID_741625413" MODIFIED="1597799763036" TEXT="创业公司">
<node CREATED="1597732705870" ID="ID_1424463773" MODIFIED="1597732710356" TEXT="忽略"/>
</node>
<node CREATED="1597732711077" FOLDED="true" ID="ID_96898487" MODIFIED="1597799763036" TEXT="中等规模公司">
<node CREATED="1597732717799" ID="ID_996107771" MODIFIED="1597732752213" TEXT="无线网络接入实现对人的身份认证, 识别员工与访客"/>
</node>
<node CREATED="1597732755524" FOLDED="true" ID="ID_710746367" MODIFIED="1597799763036" TEXT="大型公司">
<node CREATED="1597732759597" ID="ID_1131427114" MODIFIED="1597732817468" TEXT="针对有线和无线需要对人和办公设备进行认证, 检查接入设备是公司资产还是个人设备"/>
</node>
<node CREATED="1597732818958" FOLDED="true" ID="ID_1494412215" MODIFIED="1597799763036" TEXT="领先企业">
<node CREATED="1597732824555" ID="ID_1913725732" MODIFIED="1597732842811" TEXT="对人、办公设备、服务器设备均实现认证"/>
</node>
</node>
</node>
<node CREATED="1597733261967" FOLDED="true" ID="ID_1579974197" MODIFIED="1597744056787" TEXT="网络接入授权">
<node CREATED="1597732941360" FOLDED="true" ID="ID_1261228925" MODIFIED="1597799763037" TEXT="员工">
<node CREATED="1597732949332" FOLDED="true" ID="ID_719339714" MODIFIED="1597799763037" TEXT="公司电脑">
<node CREATED="1597732962652" FOLDED="true" ID="ID_234535068" MODIFIED="1597799763036" TEXT="合规">
<node CREATED="1597732995041" ID="ID_236500226" MODIFIED="1597732997573" TEXT="办公网络"/>
</node>
<node CREATED="1597732966836" FOLDED="true" ID="ID_41237005" MODIFIED="1597799763036" TEXT="不合规">
<node CREATED="1597732971261" FOLDED="true" ID="ID_1972594933" MODIFIED="1597799763036" TEXT="条件">
<node CREATED="1597732974013" ID="ID_1406194059" MODIFIED="1597732982656" TEXT="未打补丁"/>
<node CREATED="1597732982889" ID="ID_458342042" MODIFIED="1597732988422" TEXT="病毒库未更新"/>
</node>
<node CREATED="1597732999195" ID="ID_1408011500" MODIFIED="1597733005224" TEXT="修复区"/>
</node>
</node>
<node CREATED="1597732954778" FOLDED="true" ID="ID_1446470281" MODIFIED="1597799763037" TEXT="个人电脑">
<node CREATED="1597733008319" FOLDED="true" ID="ID_1901270859" MODIFIED="1597799763037" TEXT="已登记">
<node CREATED="1597733022728" FOLDED="true" ID="ID_1217784520" MODIFIED="1597799763037" TEXT="合规">
<node CREATED="1597733043885" ID="ID_233939097" MODIFIED="1597733048684" TEXT="办公网络"/>
</node>
<node CREATED="1597733024561" FOLDED="true" ID="ID_1518597743" MODIFIED="1597799763037" TEXT="不合规">
<node CREATED="1597733040720" ID="ID_457601285" MODIFIED="1597733042353" TEXT="修复区"/>
</node>
</node>
<node CREATED="1597733012543" FOLDED="true" ID="ID_170676826" MODIFIED="1597799763037" TEXT="未登记">
<node CREATED="1597733033471" ID="ID_1640350462" MODIFIED="1597733035682" TEXT="修复区"/>
</node>
</node>
</node>
<node CREATED="1597732943506" FOLDED="true" ID="ID_544872410" MODIFIED="1597799763037" TEXT="访客">
<node CREATED="1597733055414" FOLDED="true" ID="ID_1947040075" MODIFIED="1597799763037" TEXT="个人电脑">
<node CREATED="1597733059353" FOLDED="true" ID="ID_813733417" MODIFIED="1597799763037" TEXT="不信任">
<node CREATED="1597733070569" ID="ID_985927379" MODIFIED="1597733074483" TEXT="访客网络"/>
</node>
</node>
</node>
</node>
<node CREATED="1597733252086" FOLDED="true" ID="ID_1164809907" MODIFIED="1597744082188" TEXT="网络层访问控制">
<node CREATED="1597733364084" FOLDED="true" ID="ID_1662504925" MODIFIED="1597799763037" TEXT="原理">
<node CREATED="1597733366888" ID="ID_1738624668" MODIFIED="1597733423336" TEXT="在网络层控制用户和设备接入, 确保只有符合企业要求的人员和设备才能访问对应的网络资源"/>
<node CREATED="1597733453022" ID="ID_107318069" MODIFIED="1597733538827" TEXT="网络接入策略中心提供身份认证、安全检查与授权、记账等服务,若策略检查失败则通过网络接入设备将终端接入到修复区"/>
</node>
<node CREATED="1597733545851" FOLDED="true" ID="ID_1201474486" MODIFIED="1597799763038" TEXT="主要技术">
<node CREATED="1597733549980" FOLDED="true" ID="ID_918778104" MODIFIED="1597799763037" TEXT="802.1X">
<node CREATED="1597733559162" ID="ID_1873136283" MODIFIED="1597733568613" TEXT="需要交换机支持"/>
<node CREATED="1597733568816" ID="ID_223705338" MODIFIED="1597733590669" TEXT="为网络接入控制协议, 可对所接入的用户设备进行认证和控制"/>
</node>
<node CREATED="1597733555870" FOLDED="true" ID="ID_1088261423" MODIFIED="1597799763038" TEXT="DHCP">
<node CREATED="1597733592735" ID="ID_256155798" MODIFIED="1597733628661" TEXT="先分配临时IP只能访问修复区, 待策略检查成功则正式分配IP"/>
</node>
</node>
<node CREATED="1597733668155" FOLDED="true" ID="ID_894419531" MODIFIED="1597799763038" TEXT="办公终端管理">
<node CREATED="1597733674272" FOLDED="true" ID="ID_1235935515" MODIFIED="1597799763038" TEXT="状态">
<node CREATED="1597733676579" FOLDED="true" ID="ID_537584827" MODIFIED="1597799763038" TEXT="未注册">
<node CREATED="1597733786431" ID="ID_1952088537" MODIFIED="1597733796676" TEXT="未在系统中登记的资产"/>
<node CREATED="1597733803217" ID="ID_64586555" MODIFIED="1597733809196" TEXT="不具有任何权限"/>
</node>
<node CREATED="1597733683155" FOLDED="true" ID="ID_1290861884" MODIFIED="1597799763038" TEXT="已注册">
<node CREATED="1597733810759" ID="ID_1517343948" MODIFIED="1597733841725" TEXT="使用规定的注册工具在资产库中登记相应信息"/>
<node CREATED="1597733857158" ID="ID_1445780310" MODIFIED="1597733871276" TEXT="仅允许公司配发电脑可进行注册"/>
</node>
<node CREATED="1597733686404" FOLDED="true" ID="ID_1874811047" MODIFIED="1597799763038" TEXT="不可信">
<node CREATED="1597733882336" ID="ID_192357964" MODIFIED="1597733969622" TEXT="已完成注册但未通过人员认证、未通过设备认证或检查策略不满足的"/>
<node CREATED="1597733972345" ID="ID_1408177129" MODIFIED="1597733980752" TEXT="允许接入到修复区"/>
</node>
<node CREATED="1597733689750" FOLDED="true" ID="ID_1712200480" MODIFIED="1597799763038" TEXT="可信任">
<node CREATED="1597733985245" ID="ID_640151014" MODIFIED="1597734018512" TEXT="通过设备认证、人员认证及安全检查的已注册终端"/>
<node CREATED="1597734020818" FOLDED="true" ID="ID_1934326218" MODIFIED="1597799763038" TEXT="设备">
<node CREATED="1597734032940" ID="ID_1099175328" MODIFIED="1597734035621" TEXT="设备证书"/>
<node CREATED="1597734035915" ID="ID_448362563" MODIFIED="1597734047546" TEXT="登记ID及MAC地址"/>
</node>
<node CREATED="1597734023320" FOLDED="true" ID="ID_813112935" MODIFIED="1597799763038" TEXT="人员">
<node CREATED="1597734050491" ID="ID_414136744" MODIFIED="1597734056246" TEXT="AD"/>
</node>
<node CREATED="1597734025232" FOLDED="true" ID="ID_547107850" MODIFIED="1597799763038" TEXT="安全检查">
<node CREATED="1597734058351" ID="ID_517749262" MODIFIED="1597734059970" TEXT="补丁"/>
<node CREATED="1597734060218" ID="ID_87683289" MODIFIED="1597734064179" TEXT="病毒库"/>
<node CREATED="1597734064410" ID="ID_948446461" MODIFIED="1597734071386" TEXT="规定安装软件"/>
</node>
</node>
</node>
<node CREATED="1597734091532" FOLDED="true" ID="ID_1185845373" MODIFIED="1597799763038" TEXT="控制">
<node CREATED="1597734107937" ID="ID_311262607" MODIFIED="1597734159217" TEXT="只允许公司配发电脑进行登记并通过设备身份认证"/>
<node CREATED="1597734160045" ID="ID_169086958" MODIFIED="1597734175610" TEXT="只允许可信任终端接入办公网络"/>
<node CREATED="1597734216750" ID="ID_1629182787" MODIFIED="1597734241692" TEXT="其他均接入到修复区, 用于执行修复动作"/>
</node>
</node>
<node CREATED="1597734193281" ID="ID_716890747" MODIFIED="1597734196494" TEXT="服务器NAC"/>
<node CREATED="1597735497754" FOLDED="true" ID="ID_1965601118" MODIFIED="1597799763038" TEXT="生产网络访问互联网行为控制">
<node CREATED="1597735554828" FOLDED="true" ID="ID_1946483153" MODIFIED="1597799763038" TEXT="策略">
<node CREATED="1597735556795" ID="ID_822452877" MODIFIED="1597735561645" TEXT="自由访问"/>
<node CREATED="1597735561925" ID="ID_1202499273" MODIFIED="1597735664257" TEXT="通过指定代理服务器&内部软件源"/>
</node>
</node>
<node CREATED="1597740724740" FOLDED="true" ID="ID_1511339936" MODIFIED="1597799763039" TEXT="防火墙管理">
<node CREATED="1597740728695" FOLDED="true" ID="ID_504851740" MODIFIED="1597799763039" TEXT="策略条件&动作">
<node CREATED="1597740737678" FOLDED="true" ID="ID_1836981632" MODIFIED="1597799763038" TEXT="策略条件">
<node CREATED="1597740749420" ID="ID_1233711575" MODIFIED="1597740756096" TEXT="源IP"/>
<node CREATED="1597740756306" ID="ID_694336532" MODIFIED="1597740758817" TEXT="目的IP"/>
<node CREATED="1597740759045" ID="ID_1519768469" MODIFIED="1597740765516" TEXT="源端口"/>
<node CREATED="1597740765758" ID="ID_430364482" MODIFIED="1597740768494" TEXT="目的端口"/>
<node CREATED="1597740768736" ID="ID_721686791" MODIFIED="1597740770150" TEXT="协议"/>
</node>
<node CREATED="1597740770875" FOLDED="true" ID="ID_265192381" MODIFIED="1597799763039" TEXT="动作">
<node CREATED="1597740774939" ID="ID_277154008" MODIFIED="1597740777650" TEXT="阻断"/>
<node CREATED="1597740777892" ID="ID_1207361495" MODIFIED="1597740779310" TEXT="允许"/>
</node>
</node>
<node CREATED="1597740785157" FOLDED="true" ID="ID_1332277814" MODIFIED="1597799763039" TEXT="问题">
<node CREATED="1597740792195" ID="ID_788002579" MODIFIED="1597740807564" TEXT="策略多臃肿,达到防火墙极限"/>
<node CREATED="1597740808276" ID="ID_1121890167" MODIFIED="1597740823711" TEXT="业务变迁,旧策略失效"/>
<node CREATED="1597740823972" ID="ID_1468309197" MODIFIED="1597740834788" TEXT="随业务扩张,策略复杂"/>
</node>
<node CREATED="1597740835610" FOLDED="true" ID="ID_1274655603" MODIFIED="1597799763039" TEXT="解决方案">
<node CREATED="1597740842767" ID="ID_1344330519" MODIFIED="1597740867813" TEXT="控制安全域在一定范围内, 满足合规要求及敏感性业务的保密"/>
<node CREATED="1597740875619" ID="ID_551581243" MODIFIED="1597740919868" TEXT="与基础设施相关只在建设时一次性开通,由安全团队和网络维护团队定期审查"/>
<node CREATED="1597740920581" FOLDED="true" ID="ID_852991064" MODIFIED="1597799763039" TEXT="业务申请防火墙在流程上具有清理机制, 指定负责人和有效期, 并在到期时进行提醒">
<node CREATED="1597741016220" FOLDED="true" ID="ID_198430968" MODIFIED="1597799763039" TEXT="服务器之间">
<node CREATED="1597741038217" ID="ID_747300443" MODIFIED="1597741041239" TEXT="有效期1年"/>
</node>
<node CREATED="1597741019716" FOLDED="true" ID="ID_458960777" MODIFIED="1597799763039" TEXT="办公网之间">
<node CREATED="1597741033310" ID="ID_1869463265" MODIFIED="1597741036363" TEXT="有效期1月"/>
</node>
</node>
<node CREATED="1597740980698" ID="ID_300394259" MODIFIED="1597741002691" TEXT="具有临时策略,满足应急和测评需求,短时间开放并到期销毁"/>
</node>
</node>
<node CREATED="1597741157798" ID="ID_670575919" MODIFIED="1597741164939" TEXT="内网访问控制"/>
<node CREATED="1597741165406" FOLDED="true" ID="ID_452016242" MODIFIED="1597799763039" TEXT="运维通道访问控制">
<node CREATED="1597741210277" ID="ID_1040359499" MODIFIED="1597741223615" TEXT="通过跳板机或运维平台"/>
<node CREATED="1597741223877" ID="ID_1084092543" MODIFIED="1597741272111" TEXT="设置防火墙只允许办公网到跳板机及运维平台网络请求"/>
</node>
</node>
<node CREATED="1597744048494" FOLDED="true" ID="ID_646335690" MODIFIED="1597799763039" TEXT="网络层流量审计">
<node CREATED="1597744323711" ID="ID_1278704791" MODIFIED="1597744395842" TEXT="以网络层流量为分析对象,构建基于大数据的流量分析及事件挖系统,发现DDos攻击、入侵、数据泄露、明文传输敏感信息等风险"/>
<node CREATED="1597744399206" ID="ID_151161533" MODIFIED="1597744436687" TEXT="针对明文数据可使用在链路层、网络层使用分光器、IDS等各种网络设备"/>
<node CREATED="1597744437416" ID="ID_83732260" MODIFIED="1597744460666" TEXT="针对加密数据需要通过应用层网关或WAF获取流量镜像"/>
</node>
<node CREATED="1597744495037" FOLDED="true" ID="ID_1479910696" MODIFIED="1597799763046" TEXT="网络层资产保护">
<node CREATED="1597744595024" FOLDED="true" ID="ID_1283277805" MODIFIED="1597799763045" TEXT="抗D">
<node CREATED="1597744599670" FOLDED="true" ID="ID_178976446" MODIFIED="1597799763040" TEXT="缓解方案">
<node CREATED="1597744608619" FOLDED="true" ID="ID_1564769262" MODIFIED="1597799763039" TEXT="产品自身">
<node CREATED="1597744614360" ID="ID_1589228319" MODIFIED="1597744622227" TEXT="优化代码,降低系统资源占用"/>
<node CREATED="1597744622491" ID="ID_1168781966" MODIFIED="1597744635877" TEXT="启用缓存,降低对数据库资源频繁操作"/>
</node>
<node CREATED="1597744638981" FOLDED="true" ID="ID_597203044" MODIFIED="1597799763039" TEXT="基础设施">
<node CREATED="1597744648446" ID="ID_511903974" MODIFIED="1597744662034" TEXT="增加服务器前带宽"/>
<node CREATED="1597744663253" ID="ID_740113642" MODIFIED="1597744682821" TEXT="启用负载均衡或CDN进行分流"/>
</node>
</node>
<node CREATED="1597744842932" FOLDED="true" ID="ID_1327897709" MODIFIED="1597799763040" TEXT="专业方案">
<node CREATED="1597744846716" FOLDED="true" ID="ID_253706894" MODIFIED="1597799763040" TEXT="流量清洗">
<node CREATED="1597744855017" ID="ID_61300368" MODIFIED="1597744902746" TEXT="镜像流量到检测集群"/>
<node CREATED="1597744930482" FOLDED="true" ID="ID_281102256" MODIFIED="1597799763040" TEXT="检测集群通过更新策略应用到防护集群">
<node CREATED="1597745038575" FOLDED="true" ID="ID_1332865857" MODIFIED="1597799763040" TEXT="策略">
<node CREATED="1597745047442" ID="ID_1046474789" MODIFIED="1597745054733" TEXT="应用端口登记"/>
<node CREATED="1597745055252" ID="ID_928945381" MODIFIED="1597745064087" TEXT="访问来源注册"/>
</node>
</node>
<node CREATED="1597744960997" ID="ID_1994634719" MODIFIED="1597744998967" TEXT="防护集群对流量进行清洗并通过路由回注等方式将正常流量投递到目标站点"/>
</node>
</node>
</node>
</node>
</node>
<node CREATED="1597745076224" FOLDED="true" ID="ID_972337949" MODIFIED="1597915172800" TEXT="12.设备和主机层安全架构">
<node CREATED="1597800866529" FOLDED="true" ID="ID_1896259193" MODIFIED="1597800994885" TEXT="基础设施">
<node CREATED="1597800877563" ID="ID_1859216222" MODIFIED="1597800884105" TEXT="主机统一认证管理"/>
<node CREATED="1597800884368" ID="ID_1721020440" MODIFIED="1597800894722" TEXT="跳板机、运维平台、数据传输平台"/>
<node CREATED="1597800894975" ID="ID_599260923" MODIFIED="1597800909114" TEXT="操作系统母盘镜像"/>
<node CREATED="1597800909484" ID="ID_682350558" MODIFIED="1597800917761" TEXT="Docker容器基础镜像"/>
<node CREATED="1597800918103" ID="ID_764022525" MODIFIED="1597800934639" TEXT="补丁管理,保障主机操作系统及组件完整性"/>
<node CREATED="1597800934910" ID="ID_1286712236" MODIFIED="1597800954964" TEXT="防病毒管理,防止病毒、木马、webshell等有害程序危害安全"/>
<node CREATED="1597800955265" ID="ID_1810661759" MODIFIED="1597800983951" TEXT="响应HIDS,监测主机入侵行为并触发告警及响应"/>
</node>
<node CREATED="1597800986953" FOLDED="true" ID="ID_1056300393" MODIFIED="1597915172792" TEXT="身份认证与账号安全">
<node CREATED="1597801029566" FOLDED="true" ID="ID_299310535" MODIFIED="1597915172791" TEXT="登录方式">
<node CREATED="1597801032357" FOLDED="true" ID="ID_970367316" MODIFIED="1597915172790" TEXT="linux">
<node CREATED="1597801034262" ID="ID_1220164716" MODIFIED="1597801035644" TEXT="ssh"/>
</node>
<node CREATED="1597801036507" FOLDED="true" ID="ID_687596064" MODIFIED="1597915172791" TEXT="window">
<node CREATED="1597801038534" ID="ID_1851696927" MODIFIED="1597801039899" TEXT="rdp"/>
</node>
<node CREATED="1597801040526" FOLDED="true" ID="ID_430344094" MODIFIED="1597915172791" TEXT="网络设备">
<node CREATED="1597801047431" ID="ID_1352427116" MODIFIED="1597801048816" TEXT="ssh"/>
<node CREATED="1597801049066" ID="ID_69554941" MODIFIED="1597801051785" TEXT="telnet"/>
</node>
</node>
<node CREATED="1597801149984" FOLDED="true" ID="ID_1458861889" MODIFIED="1597915172791" TEXT="主要风险">
<node CREATED="1597801157040" ID="ID_205115096" MODIFIED="1597801172370" TEXT="非实名账号难以定位具体使用人员"/>
<node CREATED="1597801172620" ID="ID_1126944749" MODIFIED="1597801185941" TEXT="冗余账号"/>
<node CREATED="1597801186283" FOLDED="true" ID="ID_1752192491" MODIFIED="1597915172791" TEXT="通用口令">
<node CREATED="1597801190750" ID="ID_553415412" MODIFIED="1597801196983" TEXT="多个服务器使用同一口令"/>
</node>
<node CREATED="1597801197734" ID="ID_1605145531" MODIFIED="1597801200367" TEXT="弱口令"/>
<node CREATED="1597801201110" ID="ID_1540189502" MODIFIED="1597801208629" TEXT="已泄露口令"/>
</node>
<node CREATED="1597802547103" FOLDED="true" ID="ID_1053153010" MODIFIED="1597915172792" TEXT="解决方案">
<node CREATED="1597802550234" FOLDED="true" ID="ID_1659578221" MODIFIED="1597915172792" TEXT="动态口令">
<node CREATED="1597803252870" FOLDED="true" ID="ID_653921674" MODIFIED="1597915172792" TEXT="linux">
<node CREATED="1597803257023" ID="ID_331395798" MODIFIED="1597803290585" TEXT="自动开发PAM模块与企业SSO关联,统一身份认证机制"/>
<node CREATED="1597803293754" FOLDED="true" ID="ID_777532320" MODIFIED="1597915172791" TEXT="常见解决方案">
<node CREATED="1597803299927" ID="ID_1688528609" MODIFIED="1597803306832" TEXT="Google Authenticator"/>
<node CREATED="1597803307092" ID="ID_853372083" MODIFIED="1597803310811" TEXT="TOTP"/>
</node>
</node>
</node>
<node CREATED="1597804806432" FOLDED="true" ID="ID_58340684" MODIFIED="1597915172792" TEXT="一次一密">
<node CREATED="1597804939698" ID="ID_1496037877" MODIFIED="1597805402288" TEXT="服务器安装agent与运维平台使用私有协议进行认证并通信获取登录口令并修改"/>
</node>
</node>
</node>
<node CREATED="1597805423695" FOLDED="true" ID="ID_658313133" MODIFIED="1597915172794" TEXT="授权与访问控制">
<node CREATED="1597805749200" FOLDED="true" ID="ID_1034417971" MODIFIED="1597915172792" TEXT="主机授权与账号访问控制">
<node CREATED="1597805970552" ID="ID_1968550231" MODIFIED="1597805991909" TEXT="只允许主机负责人远程登录"/>
</node>
<node CREATED="1597805997155" FOLDED="true" ID="ID_735440453" MODIFIED="1597915172793" TEXT="主机服务监听地址">
<node CREATED="1597806036532" ID="ID_959938208" MODIFIED="1597806063710" TEXT="业务服务器只配置内网iP"/>
<node CREATED="1597806068325" ID="ID_929422959" MODIFIED="1597806088966" TEXT="所有服务器登录只监听内网IP"/>
<node CREATED="1597806131113" ID="ID_433995748" MODIFIED="1597806139109" TEXT="限制访问IP为跳板机"/>
</node>
<node CREATED="1597806839638" FOLDED="true" ID="ID_634709498" MODIFIED="1597915172793" TEXT="运维平台">
<node CREATED="1597806869827" FOLDED="true" ID="ID_1699437330" MODIFIED="1597915172793" TEXT="跳板机">
<node CREATED="1597806872414" ID="ID_1307531528" MODIFIED="1597806877098" TEXT="限制访问来源"/>
<node CREATED="1597806883003" ID="ID_1798923480" MODIFIED="1597806908340" TEXT="与操作者真实身份关联"/>
<node CREATED="1597806908880" FOLDED="true" ID="ID_1935113215" MODIFIED="1597915172793" TEXT="自动化操作(脚本化)">
<node CREATED="1597809562516" FOLDED="true" ID="ID_1159384567" MODIFIED="1597915172793" TEXT="web console">
<node CREATED="1597809567542" FOLDED="true" ID="ID_1721526347" MODIFIED="1597915172793" TEXT="gateone">
<node CREATED="1597809581267" LINK="https://github.com/liftoff/GateOne" MODIFIED="1597809581267" TEXT="https://github.com/liftoff/GateOne"/>
</node>
</node>
<node CREATED="1597809709101" ID="ID_1602409797" MODIFIED="1597809781066" TEXT="文件发布(上传/下载)、脚本发布、批量执行、内容发布等通过运维操作"/>
</node>
</node>
<node CREATED="1597809687946" FOLDED="true" ID="ID_1554020132" MODIFIED="1597915172793" TEXT="云端运维">
<node CREATED="1597809696788" ID="ID_97570402" MODIFIED="1597809704282" TEXT="防止数据泄露"/>
</node>
</node>
<node CREATED="1597809851457" FOLDED="true" ID="ID_1622845604" MODIFIED="1597915172794" TEXT="数据传输">
<node CREATED="1597809874098" FOLDED="true" ID="ID_1207723675" MODIFIED="1597915172793" TEXT="网关">
<node CREATED="1597809944801" ID="ID_392684725" MODIFIED="1597809949092" TEXT="统一认证"/>
<node CREATED="1597809879051" ID="ID_936020841" MODIFIED="1597809937955" TEXT="通过TCP端口转发实现文件上传功能"/>
<node CREATED="1597810077132" ID="ID_788801169" MODIFIED="1597810086307" TEXT="后端使用独立SFTP服务器"/>
</node>
</node>
<node CREATED="1597810147601" FOLDED="true" ID="ID_1764700408" MODIFIED="1597915172794" TEXT="网络设备">
<node CREATED="1597810153747" FOLDED="true" ID="ID_1833347981" MODIFIED="1597915172794" TEXT="常见风险">
<node CREATED="1597810161396" FOLDED="true" ID="ID_63519313" MODIFIED="1597915172794" TEXT="不正确的开放端口">
<node CREATED="1597810186275" ID="ID_1793224587" MODIFIED="1597810213429" TEXT="可通过业务网或外网访问运维端口和后台管理系统"/>
</node>
<node CREATED="1597810216154" FOLDED="true" ID="ID_1996723841" MODIFIED="1597915172794" TEXT="不安全的协议">
<node CREATED="1597810220771" ID="ID_1570643278" MODIFIED="1597810229792" TEXT="无认证"/>
<node CREATED="1597810225017" ID="ID_867641005" MODIFIED="1597810226805" TEXT="明文"/>
</node>
<node CREATED="1597810230613" ID="ID_1591315790" MODIFIED="1597810234076" TEXT="固件漏洞"/>
</node>
<node CREATED="1597810239435" FOLDED="true" ID="ID_1189777543" MODIFIED="1597915172794" TEXT="修复建议">
<node CREATED="1597810242243" ID="ID_1482508358" MODIFIED="1597810263561" TEXT="淘汰不安全协议的网络设备"/>
<node CREATED="1597810263925" ID="ID_578780132" MODIFIED="1597810271609" TEXT="管理网与业务网分离"/>
<node CREATED="1597810276624" ID="ID_1903494051" MODIFIED="1597810313930" TEXT="关注网络设备厂商补丁信息, 及时升级存在漏洞固件"/>
</node>
</node>
</node>
<node CREATED="1597810394619" FOLDED="true" ID="ID_376146889" MODIFIED="1597915172800" TEXT="运维审计&主机资产保护">
<node CREATED="1597810403924" FOLDED="true" ID="ID_816610209" MODIFIED="1597915172794" TEXT="对运维操作进行记录、分析,从中找出恶意行为和攻击线索">
<node CREATED="1597810448522" ID="ID_1336868758" MODIFIED="1597810480732" TEXT="包含正常的运维操及通过脚本发起的命令执行操作"/>
</node>
<node CREATED="1597810490439" FOLDED="true" ID="ID_558896703" MODIFIED="1597915172795" TEXT="保护主机层面的数据和资产安全">
<node CREATED="1597810502879" ID="ID_14061192" MODIFIED="1597810530945" TEXT="除业务数据外海包括网络资源、计算资源、存储资源、进程、产品功能、网络服务、系统文件等"/>
</node>
<node CREATED="1597810556225" FOLDED="true" ID="ID_1413276560" MODIFIED="1597915172795" TEXT="补丁包&防病毒管理">
<node CREATED="1597810700969" ID="ID_1247820703" MODIFIED="1597810753902" TEXT="与NAC关联,强制打补丁、防病毒软件安装、病毒库更新等策略"/>
</node>
<node CREATED="1597810825468" FOLDED="true" ID="ID_1582354891" MODIFIED="1597915172795" TEXT="母盘镜像与容器镜像">
<node CREATED="1597810835670" ID="ID_460828361" MODIFIED="1597810842270" TEXT="高危功能裁剪"/>
<node CREATED="1597810842473" ID="ID_1298401132" MODIFIED="1597810846978" TEXT="安全配置"/>
<node CREATED="1597810847247" ID="ID_830749473" MODIFIED="1597810860218" TEXT="预置安全防御能力"/>
</node>
<node CREATED="1597810872118" FOLDED="true" ID="ID_663032321" MODIFIED="1597915172795" TEXT="开源镜像&软件供应链攻击防范">
<node CREATED="1597810945560" FOLDED="true" ID="ID_828574659" MODIFIED="1597915172795" TEXT="软件供应链攻击">
<node CREATED="1597810956191" ID="ID_84585466" MODIFIED="1597810987715" TEXT="在软件开发的开发、编译、测试、发布、部署阶段污染软件行为"/>
</node>
<node CREATED="1597811102151" FOLDED="true" ID="ID_1617106749" MODIFIED="1597915172795" TEXT="建立经过过滤的企业内部开源镜像">
<node CREATED="1597811131897" ID="ID_1412633349" MODIFIED="1597811146556" TEXT="提供各种官方开发工具、软件的下载"/>
<node CREATED="1597811146847" FOLDED="true" ID="ID_205079234" MODIFIED="1597915172795" TEXT="提供经过过滤的各种开源组件">
<node CREATED="1597811158593" ID="ID_1080022467" MODIFIED="1597811170867" TEXT="对组件、版本进行控制"/>
</node>
</node>
</node>
<node CREATED="1597811223591" FOLDED="true" ID="ID_1180643277" MODIFIED="1597915172800" TEXT="HIDS">
<node CREATED="1597811296541" FOLDED="true" ID="ID_1414525313" MODIFIED="1597915172796" TEXT="账号风险检测">
<node CREATED="1597811322535" ID="ID_890437584" MODIFIED="1597811330270" TEXT="异常账号名称"/>
<node CREATED="1597811330604" ID="ID_1731243626" MODIFIED="1597811334476" TEXT="弱口令"/>
<node CREATED="1597811392265" ID="ID_611042233" MODIFIED="1597811394796" TEXT="暴力破解"/>
</node>
<node CREATED="1597811423803" ID="ID_1501708191" MODIFIED="1597811428581" TEXT="授权风险检测"/>
<node CREATED="1597811485033" ID="ID_1728816513" MODIFIED="1597811491088" TEXT="访问控制风险检测"/>
<node CREATED="1597811534916" FOLDED="true" ID="ID_710470037" MODIFIED="1597915172798" TEXT="主机资源完整性检测">
<node CREATED="1597811571172" ID="ID_1140384207" MODIFIED="1597811574698" TEXT="webshell"/>
<node CREATED="1597811574938" ID="ID_1157983879" MODIFIED="1597811580368" TEXT="病毒、木马"/>
<node CREATED="1597811580652" ID="ID_1501500918" MODIFIED="1597811584388" TEXT="系统漏洞"/>
</node>
<node CREATED="1597811659548" FOLDED="true" ID="ID_699111152" MODIFIED="1597915172799" TEXT="常用检测输入与输出">
<node CREATED="1597811671110" FOLDED="true" ID="ID_1268516450" MODIFIED="1597915172798" TEXT="账号">
<node CREATED="1597811720564" ID="ID_489264657" MODIFIED="1597811727113" TEXT="异常账号"/>
</node>
<node CREATED="1597811673438" FOLDED="true" ID="ID_944441925" MODIFIED="1597915172799" TEXT="口令Hash">
<node CREATED="1597811728808" ID="ID_1131573379" MODIFIED="1597811730775" TEXT="弱口令"/>
</node>
<node CREATED="1597811679539" FOLDED="true" ID="ID_35331298" MODIFIED="1597915172799" TEXT="登录行为">
<node CREATED="1597811732670" ID="ID_919401319" MODIFIED="1597811735382" TEXT="暴力破解"/>
<node CREATED="1597811737932" ID="ID_454324709" MODIFIED="1597811742015" TEXT="越权登录"/>
<node CREATED="1597811742305" ID="ID_496720329" MODIFIED="1597811754932" TEXT="高危服务开放"/>
</node>
<node CREATED="1597811683245" FOLDED="true" ID="ID_1270700199" MODIFIED="1597915172799" TEXT="端口">
<node CREATED="1597811742305" ID="ID_673512082" MODIFIED="1597811754932" TEXT="高危服务开放"/>
</node>
<node CREATED="1597811686441" FOLDED="true" ID="ID_431581792" MODIFIED="1597915172799" TEXT="文件">
<node CREATED="1597811764105" ID="ID_593343735" MODIFIED="1597811772496" TEXT="webshell"/>
<node CREATED="1597811772735" ID="ID_415843865" MODIFIED="1597811778376" TEXT="病毒&木马"/>
</node>
<node CREATED="1597811687945" FOLDED="true" ID="ID_94309886" MODIFIED="1597915172799" TEXT="身份/命令序列">
<node CREATED="1597811764105" ID="ID_424884163" MODIFIED="1597811772496" TEXT="webshell"/>
<node CREATED="1597811772735" ID="ID_1174020338" MODIFIED="1597811778376" TEXT="病毒&木马"/>
</node>
<node CREATED="1597811692479" FOLDED="true" ID="ID_1704535673" MODIFIED="1597915172799" TEXT="进程">
<node CREATED="1597811764105" ID="ID_1648838949" MODIFIED="1597811772496" TEXT="webshell"/>
<node CREATED="1597811772735" ID="ID_1448047161" MODIFIED="1597811778376" TEXT="病毒&木马"/>
</node>
<node CREATED="1597811694107" FOLDED="true" ID="ID_535656313" MODIFIED="1597915172799" TEXT="补丁">
<node CREATED="1597811786529" ID="ID_1388693180" MODIFIED="1597811795311" TEXT="系统漏洞"/>
<node CREATED="1597811789401" ID="ID_1065486160" MODIFIED="1597811792423" TEXT="开源漏洞"/>
</node>