天津科技 ›› 2025, Vol. 52 ›› Issue (11): 48-52.

• 应用技术 • 上一篇    下一篇

安全编排、自动化与响应技术在省级气象网络安全防护和自动化运行管理中的应用

张萧, 王华, 韩书倩   

  1. 湖北省气象信息与技术保障中心 湖北武汉 430000
  • 收稿日期:2025-10-09 发布日期:2026-01-05

Application of SOAR technology in provincial meteorological network security protection and automated operation management

ZHANG Xiao, WANG Hua, HAN Shuqian   

  1. Hubei Meteorological Information and Technology Support Center,Wuhan 430000,China
  • Received:2025-10-09 Published:2026-01-05

摘要: 气象业务不断发展,气象网络的架构越来越复杂,网络安全的威胁也更加多样化。当前省级气象网络安全防护存在安全设备之间联动性较差、自动化程度不高、事件处置经验难以借鉴利用等问题。从业务的实际需求出发,探索高效、快速且可复用的网络防护手段非常必要。基于安全编排、自动化与响应(SOAR)技术的网络安全自动化运行管理平台能够实现各类安全设备联动,提取的告警、安全威胁等信息,均可通过预设场景脚本实现自动化处置,以工单方式发给运维人员交互,最终形成一整套闭环管理机制,能够有效提高省级气象部门防护设备之间的联动能力,加快事件响应与处置速度。

关键词: 气象网络安全, 安全自动化运营, 安全编排, 自动化处置

Abstract: With the continuous development of meteorological services and operations,the architecture of meteorological networks is becoming more and more complex,and the threats to network security are also more diverse. At present,there are some problems in the provincial meteorological network security protection,such as low linkage of security devices,lack of automation,and difficulty in regularizing the experience of event disposal,etc. Therefore,it is necessary to explore the efficient,fast and reusable network protection methods from the actual needs of business. The network security automated operation and management platform based on security orchestration,automation and response (SOAR) technology can realize the linkage of various security devices,extract information such as alarms and security threats. All these can be automated according to preset scenario scripts and sent to operation and maintenance personnel for interaction in the form of work orders,ultimately forming a complete set of closed-loop management mechanisms. This platform can effectively improve the linkage capability between protection devices of provincial meteorological departments and accelerate the speed of incident response and disposal.

Key words: meteorological network security, safety automation operation, security orchestration, automated disposal

中图分类号: