首页 | 本学科首页   官方微博 | 高级检索  
     

面向漏洞管理的工作流技术应用研究
引用本文:杨诗雨,苏丽丽,侯元伟,郝永乐,李伟平. 面向漏洞管理的工作流技术应用研究[J]. 北京理工大学学报, 2019, 39(9): 967-973. DOI: 10.15918/j.tbit1001-0645.2019.09.014
作者姓名:杨诗雨  苏丽丽  侯元伟  郝永乐  李伟平
作者单位:中国信息安全测评中心,北京,100085;北京大学软件与微电子学院,北京,100871
摘    要:随着网络安全漏洞威胁日益加深,网络空间安全形势愈加严峻,掌控漏洞威胁信息、负责漏洞风险管理的漏洞管理机构发挥着越来越重要的作用,对漏洞数据的制度化、规范化、流程化管理是有效开展漏洞威胁消控的重要基石.研究了目前管理机制较为完善的漏洞管理机构,提出了一套普适性的漏洞管理流程,并结合工作流技术进行业务建模和系统实现.实践表明,将工作流技术应用于漏洞管理工作中,可以协助漏洞管理机构提高漏洞管理效率,有效开展漏洞威胁消控工作. 

关 键 词:漏洞管理  工作流  工作流建模
收稿时间:2018-11-03

Research on Workflow Technology for Vulnerability Management
YANG Shi-yu,SU Li-li,HOU Yuan-wei,HAO Yong-le and LI Wei-ping. Research on Workflow Technology for Vulnerability Management[J]. Journal of Beijing Institute of Technology(Natural Science Edition), 2019, 39(9): 967-973. DOI: 10.15918/j.tbit1001-0645.2019.09.014
Authors:YANG Shi-yu  SU Li-li  HOU Yuan-wei  HAO Yong-le  LI Wei-ping
Affiliation:1. China Information Technology Security Evaluation Center, Beijing 100085, China;2. School of Software and Microelectronics, Peking University, Beijing 100871, China
Abstract:With the growing threat of network vulnerability, cyberspace is confronted with numerous dangers and the vulnerability management agencies play an increasingly significant role therefore. Vulnerability management is supposed to be institutionalized, standardized, and streamlined, which is an indispensable cornerstone for effectively reducing vulnerability risk. To improve the efficiency of vulnerability management, general vulnerability management processes were proposed, and a workflow technology was used to model and run these processes. BPMN (business process model and notation) was used to model the management processes and a workflow management system was built to run them. Practices show that, the workflow technology based vulnerability management can improve the efficiency of vulnerability management and effectively remove and control the vulnerability threat.
Keywords:vulnerability management  workflow  workflow modeling
本文献已被 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号