CN101789948B - Hierarchical type mobile internet security monitoring and protecting system - Google Patents

Hierarchical type mobile internet security monitoring and protecting system Download PDF

Info

Publication number
CN101789948B
CN101789948B CN201010111075.9A CN201010111075A CN101789948B CN 101789948 B CN101789948 B CN 101789948B CN 201010111075 A CN201010111075 A CN 201010111075A CN 101789948 B CN101789948 B CN 101789948B
Authority
CN
China
Prior art keywords
security
monitoring
sae
safety
soc
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201010111075.9A
Other languages
Chinese (zh)
Other versions
CN101789948A (en
Inventor
苗再良
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur Communication Information System Co Ltd
Original Assignee
Inspur Communication Information System Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur Communication Information System Co Ltd filed Critical Inspur Communication Information System Co Ltd
Priority to CN201010111075.9A priority Critical patent/CN101789948B/en
Publication of CN101789948A publication Critical patent/CN101789948A/en
Application granted granted Critical
Publication of CN101789948B publication Critical patent/CN101789948B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Mobile Radio Communication Systems (AREA)

Abstract

The invention provides a hierarchical type mobile internet security monitoring and protecting system. A set of complete mobile internet security monitoring and protecting system is provided by adopting an active security monitoring and protecting technology, an intelligent detecting and analyzing technology and a customer service-oriented quality assurance policy on the basis of the further research on the characteristics of performability and maintainability of the mobile internet. The system comprises three layers of functional groups including a security operation center (SOC), a security gateway (SGW), a security access entity (SAE), and defines the basic attribute of each functional entity and the interoperability relation among the functional entities. The SOC is in charge of overall security operation monitoring management, the SGW is in charge of the flux security detection from common internet to the mobile internet, a security agent (SA) is in charge of the security monitor of in-out flux of network nodes or domestic area networks, and the SAE is in charge of monitoring the safe access and the safe operation of various types of terminals.

Description

Hierarchical type mobile internet security monitoring and guard system
Technical field
The present invention relates to a kind of mobile Internet security fields, specifically adopt multi-C stereo prevention policies and intelligent safety monitoring technology, innovative design a kind of hierarchical type mobile internet security monitoring and protection system.
Background technology
Mobile communication enters the mobile Internet epoch just on a large scale, and the intelligent terminals such as mobile phone become most important communication and information carrying platform day by day, becomes the main access main body of information interchange, ecommerce, mobile office, consumption and payment, amusement.Yet, because directly interconnecting of mobile Internet and general internet, originally wreaked havoc the malicious attacks such as virus on the Internet, wooden horse, hacker, illegal invasion also pours in thereupon, present virus for mobile Internet, smart mobile phone, wooden horse, vicious attack software etc. have had been found that several thousand kinds, and with hundreds of speed increase per month, cause very serious harm for terminal client and mobile network operation.Particularly directly access the portable terminal (smart mobile phone, PDA etc.) of the Internet for those, can introduce mobile data network inside to the virus on all the Internets, hacker, rogue attacks.These harmful softwares or reside on the mobile phone, perhaps reside on the server, perhaps be hidden in webpage or the file, all unlawful activities such as enforcement Communication Jamming, service denial, professional swindle, information are stolen, account is usurped, fund is moved steathily, device resource takies, if there are not strong safeguard procedures, inevitable Network is chaotic, brings loss difficult to the appraisal and disaster for operator and numerous clients.
It should be noted that simultaneously the data service of mobile communications network never is same as general Internet service, the former requires to provide the secure business that business is controlled, safety is controlled, satisfy SLA, and the latter is at present also without any controlled guarantee; The user will quantitatively pay when the former provided business, and the latter is free in principle.Causing thus the former ISP, service user all must be carrier-class to the requirement of network and quality of service level---this also is the Value Realization basis of mobile network data service, so the safety guarantee of mobile Internet is the great core operation support problem that must solve.
Yet, even if general internet, the satisfied solution that also is far from obtaining of most network securitys and information security issue---there is not the real-time effective end-by-end security counter-measure of the complete safety monitoring and preventing system of a cover/yet do not have, so especially stern challenge of safety problem for mobile Internet, not only lack complete efficient total solution, even do not have the special supporting technology for mobile Internet safety.At present, in the core research topic has been included the mobile data network service security in all International Telecommunications Union, standardization body, mobile communication carrier, network and IT service commercial city, attempts effectively to solve business and the information security issue of mobile Internet.
Summary of the invention
The purpose of this invention is to provide a kind of hierarchical type mobile internet security monitoring and protection system.
The objective of the invention is to realize in the following manner, can move on the basis of maintainable characteristics and latest network safe practice at the further investigation mobile Internet, adopt the quality assurance strategy of initiatively monitoring guard technology, intellectualized technology and curstomer-oriented service, proposed complete mobile internet security monitoring and the protection system of a cover.This system is divided into three layers: safe operation center SOC (Security Operation Center), TSM Security Agent SA (Security Agent) and gateway SGW (Security Gateway), safety access entity SAE (SecurityAccess Entity).SOC is responsible for the management of overall safety monitoring operation, SGW is responsible for general internet to the flow safety detection of mobile Internet, and SA is responsible for the safety detection of network main node (or net territory) turnover flow and safety access and the safe operation that management, SAE are responsible for terminal.
Particular content comprises
(1) SOC of security centre
Be responsible for overall safety monitoring and protection, formed by functional entitys such as security monitoring management system (SOM), operation protection server (OPS), Security Policy Servers (SPS).SOM is responsible for monitoring the safety significant incident of the whole network, analyzes various unusual and dangerous trends, and implements control according to the characteristic of event and process.SPS issues SOM with corresponding strategies and carries out according to the full monitoring in dynamic system Dingan County of security status and great security incident and prevention policies.OPS implements safety prevention measure according to the requirement of SOM to objects such as certain network element, terminal, flow, contents, such as depth recognition control, scanning, virus killing, connection control etc., also offer the functions such as the corresponding security tool downloading-running of terminal use and on-line operation.
(2) security gateway SGW
Security gateway SGW is arranged on the junction of mobile Internet and general internet, the main flow safety of being responsible for from the general internet to the mobile Internet comprises flow detection, network attack identification, the identification of virus extension horse, harmful content discriminating, abnormal operation and Malware early warning etc.For detecting armful traffic or operation, can take to forbid manufacture according to the prevention and control strategy, abandon, the measure such as alarm, and the warning information of in time will being correlated with sends to SOC and does further control and process.
SGW also can be arranged in the large-scale TSM Security Agent node, carries out security monitoring for the net stream that passes in and out the region within the jurisdiction network.
(3) TSM Security Agent SA
TSM Security Agent is arranged on the main node place in the mobile Internet, such as mobile switching centre, base station controller, important edge router or switch, main business node (such as mobile commerce platform) etc.Be responsible for the flow safety of a certain cohort of turnover or Local Area Network.Mainly contain three kinds of functions, the one, operation exception, operation exception and the warning information of responsible detecting collection network terminal report the SOC of security centre; The 2nd, according to the instruction of security centre, the network terminal (or subnet) is carried out specific safety detection, control; Three provide the function (generally only having large-scale TSM Security Agent node just to dispose) of security gateway, and flow and the abnormal operation that passes in and out the region within the jurisdiction network carried out security monitoring.
(4) safety access entity SAE
Safety access entity generally is configured on the network terminal, such as mobile phone, net book, value-added service server etc.SAE is security monitoring plug-in unit or the code packages of a compactness, and the operation situation of monitoring terminal notes abnormalities and then sends in real time alarm, reports terminal main interface, SA and SOC.SAE implements corresponding control operation according to instruction or alarm signal that SA/SOC sends, as send security warning, block some abnormal operation, the special safety detection code of downloading-running SOC etc.
The invention has the beneficial effects as follows: the present invention is adapted to be built into complete mobile internet security monitoring and guard system.By the layered modular architecture, contained the structure at all levels of mobile Internet from terminal, Access Network, core net to service network, can guarantee to monitor guard system the deployment flexibility, cover integrality, function expansibility, upgrading convenience and defense-in-depth ability.Active integral intelligent operating mechanism can guarantee that each function cohort under the unified regulation and control of SOC, finishes end-by-end security fast synergistic and monitor and safeguard function.Therefore the present invention is as a kind of security monitoring and protection system framework of innovation, be suitable for telecom operators and Virtual network operator and make up unified complete intelligent safety monitoring and preventing system, the safety of Effective Raise mobile Internet is transported management ability, guarantees numerous clients' service security and information security.
Description of drawings:
Fig. 1 is position and the relation of each safety function entity in network;
Fig. 2 is the configuration diagram of safety monitoring and preventing system.
Embodiment
Explain to hierarchical type mobile internet security monitoring of the present invention and below the protection system work with reference to Figure of description.
Hierarchical type mobile internet security monitoring of the present invention and protection system, the modular architecture that comprises four basic function groups of three aspects is so that whole monitoring protection system has the characteristics such as end-to-end deep layer protection flexible, that autgmentability is strong, upgrading is convenient, complete of disposing.The structure at all levels of mobile Internet from terminal, Access Network, core net to service network can be adapted to, complete security monitoring and guard system can be built into whereby;
The intelligent behaviour of each module guarantees that it has very strong security monitoring autonomy function, can be according to the configuration of self, and running and the resource object of administrative area protected in monitoring.Guarantee that when other safety systems break down the local security monitoring keeps basic function, when other system is normal, can realize collaborative work, realize more senior more powerful safety custody guarantee;
The functional structure of the SOC of security centre, comprise security monitoring management system SOM, operation protection server OPS, Security Policy Server SPS functional entity, intelligent and the cooperative mechanism of each functional entity guarantees security of system monitoring autonomy function, and function comprises:
A) according to the configuration of self, running and the resource object of administrative area protected in monitoring;
B) guarantee that when other safety systems break down the local security monitoring keeps basic function, collaborative work when other system is normal realizes the safety custody guarantee.
Attribute regulation and the matching relationship thereof of each function cohort provide as follows:
A) SOC monitors the abnormality alarming information that SGW, SA, SAE send as overall monitoring management person, determines corresponding processing policy according to analysis result, in time controls SGW, SA, SAE makes concrete reply operation;
B) SGW, SA, SAE according to the unified regulation and control of SOC, finish collaborative work on the basis that Each performs its own functions;
C) SA, SAE work in cooperation: SA act on behalf of SOC and manage many SAE when institute's pipe node or Local Area Network flow safety are come in and gone out in monitoring, and SAE is then when possessing the inherently safe monitoring function, from controlling in SA.The major technique innovative point
Main innovate point of the present invention is the intelligent characteristic of delamination modularization architecture, each module, active integration operating mechanism.
Active integration operating mechanism is mainly stipulated and matching relationship based on the attribute of each function cohort.SOC monitors the abnormality alarming information that SGW, SA, SAE send as overall monitoring management person, determines corresponding processing policy according to analysis result, in time controls SGW, SA, SAE makes concrete reply operation.SGW, SA, SAE according to the unified regulation and control of SOC, finish collaborative work on the basis that Each performs its own functions.Such as, when SGW detects one when importing into the web webpage of hanging horse, then according to predetermined strategy or stop voluntarily or report immediately that SOC, SOC then notify corresponding SA and SAE to make the prevention and control operation immediately, thereby realize effective end-by-end security monitoring protection.

Claims (3)

1. hierarchical type mobile internet security monitoring and guard system is characterized in that, comprise the function group of safe operation center SOC, TSM Security Agent SA, security gateway SGW, three aspects of safety access entity SAE, wherein:
(1) safe operation center SOC
Be responsible for overall safety monitoring and protection, by security monitoring management system SOM, operation protection server OPS, Security Policy Server SPS functional entity forms, SOM is responsible for monitoring the safety significant incident of the whole network, analyze various unusual and dangerous trends, and implement control according to the characteristic of event and process, SPS is according to the full monitoring in dynamic system Dingan County of security status and great security incident and prevention policies, corresponding strategies is issued SOM to be carried out, OPS according to the requirement of SOM to certain network element, terminal, flow, the object of content is implemented safety prevention measure, comprise depth recognition control, scanning, virus killing, connect control, also offer the corresponding security tool downloading-running of terminal use and on-line operation function;
(2) security gateway SGW
Security gateway SGW is arranged on the junction of mobile Internet and general internet, the main flow safety of being responsible for from the general internet to the mobile Internet, comprise flow detection, network attack identification, the identification of virus extension horse, harmful content discriminating, abnormal operation and Malware early warning, for the armful traffic that detects or operation, according to the prevention and control strategy take to forbid manufacture, abandon, the alarm measure, and the warning information of in time will being correlated with sends to safe operation center SOC and does further control and process; Security gateway SGW also is arranged in the large-scale TSM Security Agent node, carries out security monitoring for the net stream that passes in and out the region within the jurisdiction network;
(3) TSM Security Agent SA
TSM Security Agent SA is arranged on the main node place in the mobile Internet, comprise mobile switching centre, base station controller, important edge router or switch, main business node, mobile commerce platform, be responsible for the flow safety of a certain cohort of turnover or Local Area Network, mainly contain three kinds of functions, the one, operation exception, operation exception and the warning information of responsible detecting collection network terminal report safe operation center SOC; The 2nd, according to the instruction of security centre, the network terminal or subnet are carried out specific safety detection, control; Three provide the function of security gateway, and flow and the abnormal operation that passes in and out the region within the jurisdiction network carried out security monitoring;
(4) safety access entity SAE
Safety access physical arrangements is on the network terminal, comprise mobile phone, net book, value-added service server, SAE is security monitoring plug-in unit or the code packages of a compactness, the operation situation of monitoring terminal, note abnormalities and then send in real time alarm, report terminal main interface, SA and SOC, SAE implements corresponding control operation according to instruction or alarm signal that SA/SOC sends, comprise send security warning, block some abnormal operation, the special safety detection code of downloading-running SOC.
2. hierarchical type mobile internet security monitoring according to claim 1 and guard system, it is characterized in that, the functional structure of safe operation center SOC, comprise security monitoring management system SOM, operation protection server OPS, Security Policy Server SPS functional entity, intelligent and the cooperative mechanism of each functional entity, guarantee security of system monitoring autonomy function, described security monitoring autonomy function comprises:
A) according to the configuration of self, running and the resource object of administrative area protected in monitoring;
B) when other safety systems break down, guarantee that the local security monitoring ensures basic function, collaborative work when other system is normal realizes the safety custody guarantee.
3. hierarchical type mobile internet security monitoring according to claim 2 and guard system is characterized in that, attribute regulation and the matching relationship thereof of each function cohort provide as follows:
A) SOC monitors the abnormality alarming information that SGW, SA, SAE send as overall monitoring management person, determines corresponding processing policy according to analysis result, in time controls SGW, SA, SAE makes concrete reply operation;
B) SGW, SA, SAE according to the unified regulation and control of SOC, finish collaborative work on the basis that Each performs its own functions;
C) SA, SAE work in cooperation: SA act on behalf of SOC and manage SAE when institute's pipe node or Local Area Network flow safety are come in and gone out in monitoring, and SAE is then when possessing the inherently safe monitoring function, from controlling in SA.
CN201010111075.9A 2010-02-21 2010-02-21 Hierarchical type mobile internet security monitoring and protecting system Active CN101789948B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201010111075.9A CN101789948B (en) 2010-02-21 2010-02-21 Hierarchical type mobile internet security monitoring and protecting system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201010111075.9A CN101789948B (en) 2010-02-21 2010-02-21 Hierarchical type mobile internet security monitoring and protecting system

Publications (2)

Publication Number Publication Date
CN101789948A CN101789948A (en) 2010-07-28
CN101789948B true CN101789948B (en) 2013-03-20

Family

ID=42533001

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201010111075.9A Active CN101789948B (en) 2010-02-21 2010-02-21 Hierarchical type mobile internet security monitoring and protecting system

Country Status (1)

Country Link
CN (1) CN101789948B (en)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102035734B (en) * 2010-12-03 2012-11-28 成都飞鱼星科技开发有限公司 Multiple wide area network (WAN) broadband router with internet surfing behavior management function and realizing method thereof
CN102882728B (en) * 2012-10-08 2017-04-05 北京星网锐捷网络技术有限公司 Traffic Anomaly cause notifying method, device and the network equipment
EP3084674B1 (en) * 2013-12-18 2018-10-17 Intel Corporation Techniques for integrated endpoint and network detection and eradication of attacks
CN103716785B (en) * 2013-12-26 2017-09-22 中国科学院信息工程研究所 A kind of mobile Internet safety service system
CN106559399A (en) * 2015-09-30 2017-04-05 北京军地联合网络技术中心 A kind of the Internet mobile terminal synthesis managing and control system
US10560840B2 (en) * 2016-03-18 2020-02-11 Wipro Limited System and method for providing dynamic, adaptive and composite privacy and security for IoT communication
CN107889108A (en) * 2016-09-29 2018-04-06 北京军地联合网络技术中心 A kind of Distributed Area internet security guard system
CN107368582B (en) * 2017-07-21 2020-12-22 深信服科技股份有限公司 SQL statement detection method and system
CN108600252A (en) * 2018-04-28 2018-09-28 丙申南京网络技术有限公司 A kind of Network anti-virus system
CN111787038B (en) * 2019-04-04 2022-05-17 华为云计算技术有限公司 Method, system and computing device for providing edge service
CN111049851B (en) * 2019-12-24 2021-10-01 中国电子科技集团公司第五十四研究所 Multi-level and multi-dimensional linkage management and control system for cross-domain transmission service

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1937565A (en) * 2006-09-27 2007-03-28 深圳市皓峰通讯技术有限公司 Service gateway system
CN101056198A (en) * 2006-04-10 2007-10-17 华为技术有限公司 An information security management platform
CN101174973A (en) * 2006-10-31 2008-05-07 华为技术有限公司 Network safety control construction
CN101605065A (en) * 2009-04-22 2009-12-16 网经科技(苏州)有限公司 The implementation method of security incident monitoring in the system of security centre

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101399698A (en) * 2007-09-30 2009-04-01 华为技术有限公司 Safety management system, device and method

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101056198A (en) * 2006-04-10 2007-10-17 华为技术有限公司 An information security management platform
CN1937565A (en) * 2006-09-27 2007-03-28 深圳市皓峰通讯技术有限公司 Service gateway system
CN101174973A (en) * 2006-10-31 2008-05-07 华为技术有限公司 Network safety control construction
CN101605065A (en) * 2009-04-22 2009-12-16 网经科技(苏州)有限公司 The implementation method of security incident monitoring in the system of security centre

Also Published As

Publication number Publication date
CN101789948A (en) 2010-07-28

Similar Documents

Publication Publication Date Title
CN101789948B (en) Hierarchical type mobile internet security monitoring and protecting system
Karie et al. IoT threat detection advances, challenges and future directions
US10700976B2 (en) System and method for an automated system for continuous observation, audit and control of user activities as they occur within a mobile network
CN103875222B (en) System and method for the threat protection of real-time customization
US8209759B2 (en) Security incident manager
US20100122345A1 (en) Control system and protection method for integrated information security services
CN104509034A (en) Pattern consolidation to identify malicious activity
CN106537406A (en) A cyber-security system and methods thereof
CN110493195A (en) A kind of network access control method and system
US20170208092A1 (en) Method for detecting an attack on a working environment connected to a communication network
CN102106167A (en) Security message processing
CN101242658A (en) Mobile information multi-layer network secure auditing system
CN109165508A (en) A kind of external device access safety control system and its control method
Choi et al. Study on information security sharing system among the industrial IoT service and product provider
US20120137362A1 (en) Collaborative security system for residential users
Haggerty et al. DiDDeM: a system for early detection of TCP SYN flood attacks
Haggerty et al. Early detection and prevention of denial-of-service attacks: a novel mechanism with propagated traced-back attack blocking
CN102217248A (en) Distributed packet flow inspection and processing
CN101453363A (en) Network intrusion detection system
CN101277302A (en) Apparatus and method for safety centralized protection of distributed network equipment
WO2016191369A1 (en) Automated system for continuous observation, audit and control of user activities within a mobile network
Krebs Host of Internet spam groups is cut off
CN112417434A (en) Program white list protection method combined with UEBA mechanism
Khobragade et al. Distributed intrusion detection system using mobile agent
Priyadarshini et al. An Introduction to Security in Internet of Things (IoT) and Big Data

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address

Address after: 250100 Ji'nan high tech Zone, Shandong, No. 1036 wave road

Patentee after: Tianyuan Communication Information System Co., Ltd.

Address before: 250014 No. 224 mountain road, Lixia District, Shandong, Ji'nan

Patentee before: Langchao Communication Information System Co., Ltd.

CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 250100 S06 tower, 1036, Chao Lu Road, hi tech Zone, Ji'nan, Shandong.

Patentee after: INSPUR COMMUNICATION AND INFORMATION SYSTEM Co.,Ltd.

Address before: No. 1036, Shandong high tech Zone wave road, Ji'nan, Shandong

Patentee before: INSPUR TIANYUAN COMMUNICATION INFORMATION SYSTEM Co.,Ltd.

CP03 Change of name, title or address