微软的SOC设计

本文介绍了微软全球安全高级项目经理Johnny Walker关于SOC(安全运营中心)的设计思路。SOC旨在提供全局态势感知,实现精确响应及支持历史调查取证。文章还详细阐述了SOC设计的四个关键层面:技术投资、监测模型、通讯机制及行政管理。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

在2008年1月, 有篇文章提及了微软对SOC的设计的思路:Johnny Walker, senior program manager for Microsoft Global security, explains that the role of the technology design and concept of operations for a SOC is to provide situation awareness that enables precision response and supports forensics investigations.SOC的目标就是为使用者提供全局的态势感知,使得使用者能够进行精确响应并支持其进行历史的调查取证分析。
他还说到了SOC设计的4个层次,技术、监测、沟通和管理。
"We kind of bucket it in four zones: technology, monitoring, communication and administration. First is the technology investment that is really built on your risk drivers. Next, you have to have an effective, sustainable and predictable monitoring model that goes on the total cost of ownership."Once you have heard an alarm and you understand the alarm, you have to be able to communicate it quickly to a response mechanism - whether that's your proprietary forces or a public safety response mechanism - it still has to work," Walker continued. "So you have to invest in that third tier (communications). And then finally you have to have this administrative module that says, 'Do I have the right design, is it working?' So you have this process improvement piece going on so you can evolve the lifecycle of the system and know its readiness."
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值