基于分布式安全运营中心的威胁情报数据
收藏资源简介:
通过海量的数据、商业情报以及国家情报,建立了政务云上的威胁情报库,不仅如此,威胁情报库还与公安进行了情报共享,建立了联防联控机制。主要用于安全防护、风险管理和安全运维与运营,具体应用场景包括攻击检测与防御、攻击团伙追踪、威胁狩猎、事件监测与响应、基于情报驱动的漏洞管理以及暗网情报发现等。这些应用场景可以全面提升企业网络安全性,防范网络攻击并降低安全风险。
A threat intelligence repository on the government cloud was constructed using massive volumes of data, commercial intelligence, and national intelligence. Furthermore, this repository has established intelligence sharing with public security authorities and built a joint prevention and control mechanism. It is primarily utilized for security protection, risk management, as well as security operations and maintenance. Its specific application scenarios include attack detection and defense, attack group tracking, threat hunting, incident monitoring and response, intelligence-driven vulnerability management, dark web intelligence discovery, and more. These application scenarios can comprehensively enhance enterprise network security, prevent cyber attacks, and mitigate security risks.




