CN109934011A - A data security partition method applied to operation and maintenance audit system - Google Patents
A data security partition method applied to operation and maintenance audit system Download PDFInfo
- Publication number
- CN109934011A CN109934011A CN201910201683.XA CN201910201683A CN109934011A CN 109934011 A CN109934011 A CN 109934011A CN 201910201683 A CN201910201683 A CN 201910201683A CN 109934011 A CN109934011 A CN 109934011A
- Authority
- CN
- China
- Prior art keywords
- data
- server
- file
- maintenance
- database
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Landscapes
- Computer And Data Communications (AREA)
Abstract
Description
技术领域technical field
本发明涉及一种应用于运维审计系统的数据安全分区方法。The invention relates to a data security partition method applied to an operation and maintenance audit system.
背景技术Background technique
大数据已经成为国家战略,当今国网公司信息化建设方兴未艾,同时伴随灾备数据中心、云计算、大数据、移动办公和智能设备等数字化智能化建设的持续升温,信息安全正面临新的挑战。大数据平台整体安全建设,从数据采集到数据资产的梳理,再到平台的访问安全管控和数据存储安全,以及数据共享分发过程中的版权保护,整个安全方案如何形成数据访问和使用过程的闭环,并且能够实现安全策略的统一下发和协同配合,是摆在平台建设方面前的棘手问题。Big data has become a national strategy, and the informatization construction of State Grid Corporation is in the ascendant. At the same time, with the continuous increase of digital and intelligent construction of disaster recovery data centers, cloud computing, big data, mobile office and smart devices, information security is facing new challenges. . The overall security construction of the big data platform, from data collection to the sorting of data assets, to the access security control and data storage security of the platform, as well as the copyright protection in the process of data sharing and distribution, how does the entire security scheme form a closed loop of data access and use process , and can realize the unified issuance and coordination of security policies, which is a thorny issue before platform construction.
现有运维审计系统的业务功能主要包括五方面:(1)参数、策略配置功能;(2)资源管理功能;(3)安全管理功能;(4)日志管理功能;(5)安全审计功能。其中,参数、策略配置功能为系统提供参数、功能及安全策略配置;资源管理功能实现对人员、设备等资源的管理;安全管理功能实现系统的安全认证、控制功能;日志管理功能实现系统各种日志的分析、统计、展示;安全审计功能实现运维操作的记录、分析、控制、监测和回放。The business functions of the existing operation and maintenance audit system mainly include five aspects: (1) parameter and policy configuration function; (2) resource management function; (3) security management function; (4) log management function; (5) security audit function . Among them, the parameter and policy configuration function provides parameters, functions and security policy configuration for the system; the resource management function realizes the management of resources such as personnel and equipment; the security management function realizes the security authentication and control functions of the system; the log management function realizes various system functions Log analysis, statistics and display; the security audit function realizes the recording, analysis, control, monitoring and playback of operation and maintenance operations.
在日常运维中针对数据的存在如下高危操作:In daily operation and maintenance, the following high-risk operations are performed for the existence of data:
在日常运维中,运维人员能直接访问某些数据甚至导出到本地,这些数据没有相应的安全措施来保护,存在被非法利用的风险。In daily operation and maintenance, operation and maintenance personnel can directly access some data or even export it locally. These data are not protected by corresponding security measures, and there is a risk of being illegally used.
在系统实施、上线、测试等过程中,存在需要导出真实数据来进行使用的情况,加大了数据被泄露的风险。In the process of system implementation, launch, and testing, it is necessary to export real data for use, which increases the risk of data leakage.
在系统下线或者硬盘出现问题时,硬盘中留存的大量数据往往容易被忽视,即使经过删除、格式话等操作后也极易被恢复,在硬盘维修销毁过程中极易泄露数据造成严重后果。When the system goes offline or there is a problem with the hard disk, a large amount of data retained in the hard disk is often easily overlooked. Even after deletion, formatting, etc., it is very easy to recover. In the process of hard disk repair and destruction, it is easy to leak data and cause serious consequences.
普通运维审计系统只管理了存储和访问,安全防护全面性不足;只是针对特定的风险点进行防护,没有形成整体联动的安全防护体系。The ordinary operation and maintenance audit system only manages storage and access, and the security protection is not comprehensive enough; it only protects specific risk points, and does not form an overall linked security protection system.
发明内容SUMMARY OF THE INVENTION
本发明的目的是提供一种应用于运维审计系统的数据安全分区方法,解决现有的运维审计系统在日常运维中,运维人员能直接访问某些数据甚至导出到本地,这些数据没有相应的安全措施来保护,存在被非法利用的风险;在系统实施、上线、测试等过程中,存在需要导出真实数据来进行使用的情况,加大了数据被泄露的风险;在系统下线或者硬盘出现问题时,硬盘中留存的大量数据往往容易被忽视,即使经过删除、格式话等操作后也极易被恢复,在硬盘维修销毁过程中极易泄露数据造成严重后果。The purpose of the present invention is to provide a data security partitioning method applied to the operation and maintenance audit system, so as to solve the problem that in the daily operation and maintenance of the existing operation and maintenance audit system, the operation and maintenance personnel can directly access some data or even export the data locally. Without corresponding security measures to protect, there is a risk of illegal use; in the process of system implementation, launch, testing, etc., it is necessary to export real data for use, which increases the risk of data leakage; when the system is offline Or when there is a problem with the hard disk, the large amount of data retained in the hard disk is often easily overlooked, and even after deletion, formatting, etc., it is easy to recover, and it is easy to leak data during the process of hard disk repair and destruction. Serious consequences.
普通运维审计系统只管理了存储和访问,安全防护全面性不足;只是针对特定的风险点进行防护,没有形成整体联动的安全防护体系The general operation and maintenance audit system only manages storage and access, and the security protection is not comprehensive enough; it only protects specific risk points, and does not form an overall linked security protection system
本发明解决其技术问题所采用的技术方案是:一种应用于运维审计系统的数据安全分区方法,The technical solution adopted by the present invention to solve the technical problem is: a data security partition method applied to an operation and maintenance audit system,
将运维审计系统划分为运维目标、运维接入区和操作区三个部分,其中操作区包括监控管理区,运维办公区和业务办公区;The operation and maintenance audit system is divided into three parts: the operation and maintenance target, the operation and maintenance access area and the operation area. The operation area includes the monitoring and management area, the operation and maintenance office area and the business office area;
数据库客户端运行在运维审计系统的应用虚拟化服务器上,运维人员在个人操作机上无法通过数据库客户端直接将数据保存至本地;The database client runs on the application virtualization server of the operation and maintenance audit system, and the operation and maintenance personnel cannot directly save the data locally through the database client on the personal operating machine;
切断运维操作机与应用虚拟化服务器之间的文件按传输、数据拷贝通道,防止运维人员将数据库文件导出到虚拟化服务器上后再上传到运维操作机上;Cut off the file transfer and data copy channels between the operation and maintenance operation machine and the application virtualization server, so as to prevent the operation and maintenance personnel from exporting the database files to the virtualized server and then uploading them to the operation and maintenance operation machine;
将特定服务器文件传输功能关闭,在需要时再打开;可以避免运维人员在特定服务器上导出文件;Turn off the file transfer function of a specific server and turn it on again when needed; it can prevent operation and maintenance personnel from exporting files on a specific server;
根据需求对各服务器之间的网络访问策略进行精细化管理,避免运维人员在服务器之间做跳板访问、传输文件,再通过跳板服务器取走数据;Perform refined management of network access policies between servers according to requirements, to avoid operation and maintenance personnel from making springboard access between servers, transferring files, and then fetching data through the springboard server;
数据库运维过程中的文件传输步骤如下:The file transfer steps in the database operation and maintenance process are as follows:
步骤(1)、运维专区管理员新建运维任务,并将运维过程中所需的运维脚本一并上传至堡垒机;Step (1), the administrator of the operation and maintenance area creates a new operation and maintenance task, and uploads the operation and maintenance scripts required in the operation and maintenance process to the bastion host;
步骤(2)、进行运维工作时,运维人员通过虚拟化连接到应用虚拟化服务器;In step (2), during operation and maintenance work, the operation and maintenance personnel are connected to the application virtualization server through virtualization;
步骤(3)、系统自动将运维所需脚本文件同步至应用虚拟化服务器上,使文件在该用户的会话中有效;Step (3), the system automatically synchronizes the script file required for operation and maintenance to the application virtualization server, so that the file is valid in the user's session;
步骤(4)、数据库运维工作正常进行,过程中有可能会导出数据文件到应用虚拟化服务器上,;Step (4), the database operation and maintenance work is carried out normally, and the data file may be exported to the application virtualization server in the process;
步骤(5)、系统自动将运维导出数据文件同步至运维数据文件服务器上;Step (5), the system automatically synchronizes the operation and maintenance export data file to the operation and maintenance data file server;
步骤(6)、业务人员获取所需数据文件。In step (6), the business personnel obtain the required data files.
本发明的有益效果:本应用于运维审计系统的数据安全分区方法实现对运维专区中各要素的管理,如专区、专机、人员等;实现对运维专区中所发生的运维工作进行全面的审计,做到对运维专机的有序分配、对运维专机操作的实时监控和事后审计、对运维人员的严格认证、对运维专机的远程管理等,从而实现远程运维操作安全可控,确保信息系统安全稳定运行。解决了以往运维审计系统只管理了存储和访问,安全防护全面性不足;只是针对特定的风险点进行防护,没有形成整体联动的安全防护体系的问题。通过将文件分区管理,切断文件传输通道解决了以往运维审计系统无法有效控制数据流动,数据容易通过各种途径被导出的问题。通过精细化处理服务器间网络访问策略设置,避免了运维人员在服务器之间做跳板访问、传输文件,再通过跳板服务器取走数据的问题。Beneficial effects of the present invention: The data security partition method applied to the operation and maintenance audit system realizes the management of various elements in the operation and maintenance area, such as special areas, special planes, personnel, etc.; realizes the operation and maintenance work occurring in the operation and maintenance area. Comprehensive audit, to achieve orderly allocation of special operation and maintenance planes, real-time monitoring and post-audit of the operation of special operation and maintenance planes, strict certification of operation and maintenance personnel, remote management of special operation and maintenance planes, etc., so as to realize remote operation and maintenance operations Safe and controllable to ensure the safe and stable operation of the information system. It solves the problem that the previous operation and maintenance audit system only manages storage and access, and the security protection is insufficient; it only protects specific risk points, and does not form an overall linked security protection system. By partitioning the file management and cutting off the file transmission channel, the problem that the previous operation and maintenance audit system could not effectively control the data flow and the data was easily exported through various channels was solved. Through refined processing of network access policy settings between servers, the problem of operation and maintenance personnel doing springboard access between servers, transferring files, and then retrieving data through the springboard server is avoided.
以下将结合附图和实施例,对本发明进行较为详细的说明。The present invention will be described in more detail below with reference to the accompanying drawings and embodiments.
附图说明Description of drawings
图1为本发明的示意图。Figure 1 is a schematic diagram of the present invention.
具体实施方式Detailed ways
实施例1,如图1所示的一种应用于运维审计系统的数据安全分区方法,将运维审计系统划分为运维目标、运维接入区和操作区三个部分,其中操作区包括监控管理区,运维办公区和业务办公区;Embodiment 1, as shown in FIG. 1, is a data security partitioning method applied to an operation and maintenance audit system. The operation and maintenance audit system is divided into three parts: an operation and maintenance target, an operation and maintenance access area, and an operation area. Including monitoring and management area, operation and maintenance office area and business office area;
数据库客户端运行在运维审计系统的应用虚拟化服务器上,运维人员在个人操作机上无法通过数据库客户端直接将数据保存至本地;The database client runs on the application virtualization server of the operation and maintenance audit system, and the operation and maintenance personnel cannot directly save the data locally through the database client on the personal operating machine;
切断运维操作机与应用虚拟化服务器之间的文件按传输、数据拷贝通道,防止运维人员将数据库文件导出到虚拟化服务器上后再上传到运维操作机上;Cut off the file transfer and data copy channels between the operation and maintenance operation machine and the application virtualization server, so as to prevent the operation and maintenance personnel from exporting the database files to the virtualized server and then uploading them to the operation and maintenance operation machine;
将特定服务器文件传输功能关闭,在需要时再打开;可以避免运维人员在特定服务器(如数据库服务器)上上导出文件;Turn off the file transfer function of a specific server and turn it on again when needed; it can prevent operation and maintenance personnel from exporting files on a specific server (such as a database server) ;
根据需求对各服务器之间(如管理信息大区里的服务器之间)的网络访问策略进行精细化管理,避免运维人员在服务器之间做跳板访问、传输文件,再通过跳板服务器取走数据;Perform refined management of network access policies between servers (such as between servers in the management information area) according to requirements, so as to avoid operation and maintenance personnel from making springboard access, transferring files between servers, and then retrieving data through the springboard server ;
数据库运维过程中的文件传输步骤如下:The file transfer steps in the database operation and maintenance process are as follows:
步骤(1)、运维专区管理员新建运维任务,并将运维过程中所需的运维脚本一并上传至堡垒机;Step (1), the administrator of the operation and maintenance area creates a new operation and maintenance task, and uploads the operation and maintenance scripts required in the operation and maintenance process to the bastion host;
步骤(2)、进行运维工作时,运维人员通过虚拟化连接到应用虚拟化服务器;In step (2), during operation and maintenance work, the operation and maintenance personnel are connected to the application virtualization server through virtualization;
步骤(3)、系统自动将运维所需脚本文件同步至应用虚拟化服务器上,使文件在该用户的会话中有效;Step (3), the system automatically synchronizes the script file required for operation and maintenance to the application virtualization server, so that the file is valid in the user's session;
步骤(4)、数据库运维工作正常进行,过程中有可能会导出数据文件到应用虚拟化服务器上,;Step (4), the database operation and maintenance work is carried out normally, and the data file may be exported to the application virtualization server in the process;
步骤(5)、系统自动将运维导出数据文件同步至运维数据文件服务器上;Step (5), the system automatically synchronizes the operation and maintenance export data file to the operation and maintenance data file server;
步骤(6)、业务人员获取所需数据文件。In step (6), the business personnel obtain the required data files.
以上结合附图对本发明进行了示例性描述。显然,本发明具体实现并不受上述方式的限制。只要是采用了本发明的方法构思和技术方案进行的各种非实质性的改进;或未经改进,将本发明的上述构思和技术方案直接应用于其它场合的,均在本发明的保护范围之内。The present invention has been exemplarily described above with reference to the accompanying drawings. Obviously, the specific implementation of the present invention is not limited by the above manner. As long as the method concept and technical solution of the present invention are adopted for various non-substantial improvements; or the above-mentioned concept and technical solution of the present invention are directly applied to other occasions without improvement, they are all within the protection scope of the present invention. within.
Claims (1)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910201683.XA CN109934011A (en) | 2019-03-18 | 2019-03-18 | A data security partition method applied to operation and maintenance audit system |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910201683.XA CN109934011A (en) | 2019-03-18 | 2019-03-18 | A data security partition method applied to operation and maintenance audit system |
Publications (1)
Publication Number | Publication Date |
---|---|
CN109934011A true CN109934011A (en) | 2019-06-25 |
Family
ID=66987460
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201910201683.XA Pending CN109934011A (en) | 2019-03-18 | 2019-03-18 | A data security partition method applied to operation and maintenance audit system |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN109934011A (en) |
Citations (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20040268151A1 (en) * | 2003-04-07 | 2004-12-30 | Tokyo Electron Limited | Maintenance/diagnosis data storage server |
CN1858738A (en) * | 2006-02-15 | 2006-11-08 | 华为技术有限公司 | Method and device for access data bank |
CN201733328U (en) * | 2010-07-09 | 2011-02-02 | 中国工商银行股份有限公司 | Enterprise data maintaining device and system based on bank system |
CN102215133A (en) * | 2011-06-21 | 2011-10-12 | 德讯科技股份有限公司 | Audit data positioning playback system and method based on RDP remote protocol board-jumping machine |
WO2012142854A1 (en) * | 2011-04-18 | 2012-10-26 | 北京新媒传信科技有限公司 | Application service platform system and implementation method thereof |
CN103188336A (en) * | 2011-12-31 | 2013-07-03 | 北京市国路安信息技术有限公司 | Virtual desktop-based operation and maintenance management method |
CN103475727A (en) * | 2013-09-18 | 2013-12-25 | 浪潮电子信息产业股份有限公司 | Database auditing method based on bridged mode |
CN103685215A (en) * | 2013-04-28 | 2014-03-26 | 中国南方电网有限责任公司 | Power communication operation and maintenance mobile system and power communication operation and maintenance method |
CN103685242A (en) * | 2013-11-27 | 2014-03-26 | 国家电网公司 | Electric power operation and maintenance security defending system |
CN103841114A (en) * | 2014-03-20 | 2014-06-04 | 北京中电普华信息技术有限公司 | Intelligent operation and maintenance safety audit method and system |
CN104065731A (en) * | 2014-06-30 | 2014-09-24 | 江苏华大天益电力科技有限公司 | FTP file transfer system and transfer method |
CN104732160A (en) * | 2015-02-03 | 2015-06-24 | 武汉风奥软件技术有限公司 | Control method for preventing database information from being leaked internally |
CN105847021A (en) * | 2015-01-13 | 2016-08-10 | 国家电网公司 | Concentrated operation and maintenance safety audit system in intelligent power grid dispatching control system |
CN107733901A (en) * | 2017-10-23 | 2018-02-23 | 成都安恒信息技术有限公司 | A kind of Windows remote desktops file for O&M auditing system transmits auditing method |
CN107770160A (en) * | 2017-09-30 | 2018-03-06 | 深信服科技股份有限公司 | Data security protection method, equipment and computer-readable recording medium |
CN108965388A (en) * | 2018-06-13 | 2018-12-07 | 新华三信息安全技术有限公司 | A kind of operation audit method and device |
CN109447876A (en) * | 2018-10-16 | 2019-03-08 | 湖北三峡云计算中心有限责任公司 | A kind of burgher card system |
-
2019
- 2019-03-18 CN CN201910201683.XA patent/CN109934011A/en active Pending
Patent Citations (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20040268151A1 (en) * | 2003-04-07 | 2004-12-30 | Tokyo Electron Limited | Maintenance/diagnosis data storage server |
CN1858738A (en) * | 2006-02-15 | 2006-11-08 | 华为技术有限公司 | Method and device for access data bank |
CN201733328U (en) * | 2010-07-09 | 2011-02-02 | 中国工商银行股份有限公司 | Enterprise data maintaining device and system based on bank system |
WO2012142854A1 (en) * | 2011-04-18 | 2012-10-26 | 北京新媒传信科技有限公司 | Application service platform system and implementation method thereof |
CN102215133A (en) * | 2011-06-21 | 2011-10-12 | 德讯科技股份有限公司 | Audit data positioning playback system and method based on RDP remote protocol board-jumping machine |
CN103188336A (en) * | 2011-12-31 | 2013-07-03 | 北京市国路安信息技术有限公司 | Virtual desktop-based operation and maintenance management method |
CN103685215A (en) * | 2013-04-28 | 2014-03-26 | 中国南方电网有限责任公司 | Power communication operation and maintenance mobile system and power communication operation and maintenance method |
CN103475727A (en) * | 2013-09-18 | 2013-12-25 | 浪潮电子信息产业股份有限公司 | Database auditing method based on bridged mode |
CN103685242A (en) * | 2013-11-27 | 2014-03-26 | 国家电网公司 | Electric power operation and maintenance security defending system |
CN103841114A (en) * | 2014-03-20 | 2014-06-04 | 北京中电普华信息技术有限公司 | Intelligent operation and maintenance safety audit method and system |
CN104065731A (en) * | 2014-06-30 | 2014-09-24 | 江苏华大天益电力科技有限公司 | FTP file transfer system and transfer method |
CN105847021A (en) * | 2015-01-13 | 2016-08-10 | 国家电网公司 | Concentrated operation and maintenance safety audit system in intelligent power grid dispatching control system |
CN104732160A (en) * | 2015-02-03 | 2015-06-24 | 武汉风奥软件技术有限公司 | Control method for preventing database information from being leaked internally |
CN107770160A (en) * | 2017-09-30 | 2018-03-06 | 深信服科技股份有限公司 | Data security protection method, equipment and computer-readable recording medium |
CN107733901A (en) * | 2017-10-23 | 2018-02-23 | 成都安恒信息技术有限公司 | A kind of Windows remote desktops file for O&M auditing system transmits auditing method |
CN108965388A (en) * | 2018-06-13 | 2018-12-07 | 新华三信息安全技术有限公司 | A kind of operation audit method and device |
CN109447876A (en) * | 2018-10-16 | 2019-03-08 | 湖北三峡云计算中心有限责任公司 | A kind of burgher card system |
Non-Patent Citations (2)
Title |
---|
叶水勇等: ""利用安全审计网关技术实现应用系统运维安全防护"", 《电力信息与通信技术》 * |
朱兵等: ""基于安全分区技术的数据安全防护策略及实现"", 《国网技术学院学报》 * |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
Zhe et al. | Study on data security policy based on cloud storage | |
KR102542720B1 (en) | System for providing internet of behavior based intelligent data security platform service for zero trust security | |
CN112329031A (en) | Data authority control system based on data center | |
CN104378387A (en) | Method for protecting information security under virtualization platform | |
CN103413088A (en) | Computer document operational safety audit system | |
CN103763369B (en) | A kind of multiple authority distributing method based on SAN storage system | |
CN105337971A (en) | Electric power information system cloud safety guarantee system and implementation method thereof | |
US20240045964A1 (en) | Cybersecurity Active Defense and Rapid Bulk Recovery in a Data Storage System | |
CN101520833A (en) | Anti-data-leakage system and method based on virtual machine | |
CN102202052A (en) | Virtual-machine-technology-based information system password management method | |
CN110222498A (en) | A kind of supervision management system and method based on mobile interchange cloud | |
CN113132318A (en) | Active defense method and system for information safety of power distribution automation system master station | |
CN201854302U (en) | Active anti-disclosure based network security system | |
US20140236898A1 (en) | System and method for facilitating electronic discovery | |
CN118484267B (en) | Cloud computing-based online service computing power optimization method and system | |
CN109934011A (en) | A data security partition method applied to operation and maintenance audit system | |
CN113672479A (en) | Data sharing method and device and computer equipment | |
CN108092808A (en) | A kind of method for managing security of data center's total management system | |
CN103942502B (en) | Ferry-boat formula secure data exchange method and device | |
CN106295341A (en) | Enterprise data center security solution method based on virtualization | |
CN113709140B (en) | Cloud big data intelligent safety management and control system based on comprehensive audit | |
CN109754149A (en) | Power communication trusted background management system, terminal and power communication trusted system | |
CN116257864A (en) | Data protection method, virtual device, electronic equipment and computer storage medium | |
CN113760449A (en) | 3D design data sharing system for power transmission and transformation based on desktop cloud xView | |
Fan et al. | Research on cloud computing security problems and protection countermeasures |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
RJ01 | Rejection of invention patent application after publication | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20190625 |