文档介绍:摘要Summary脆弱性安全Vulnerability-orientedsecurity结构性安全Structuralsecurity结构性安全中的脆弱性 Vulnerabilitiesinstructures结构性威胁Structuralthreats1脆弱性安全Vulnerability-orientedsecurity2脆弱性Vulnerabilities弱口令simplepassword病毒virus操作系统漏洞OSflaw协议漏洞protocolflaw造成拒绝服务攻击的性能限制 performancelimitation防火墙配置不当badconfigurationoffirewalls……3面向脆弱性的安全Vulnerability-orientedsecurity防病毒系统anti-virussystem漏洞扫描系统vulnerabilityscanner补丁管理系统patchmanagementsystem入侵检测系统IDS防拒绝服务攻击系统anti-DoS防火墙Firewall多功能安全网关UTM……4PSPC需求驱动筐架 Vulnerability-orientedriskmanagement6国家标准中的风险管理关系图RiskmanagementelementsinChinesestandard7最精简的风险管理3要素模型3-elementriskmanagementmodel82006SCAwardsBestanti-malwaresolutionBestAnti-spywareBestAnti-trojanBestAnti-virusBestAnti-wormBestContentSecuritySolutionBestAnti-essBestVPN-SSLBestVPN-IpsecBestEndpointSecuritySolutionBestWebFilteringBestEncryptionBestIdentityManagementSolutionBestPasswordManagementBestAuthenticationBestSingleSign-onBestTwo-puterForensicsBestPolicyManagementBestSecurityAuditBestSecurityManagementToolBestVulnerabilityAssessmentandRemediationBestPatchManagementBestVulnerabilityAssessmentSourcefrom:/awards/previous/26104/year/2006/9脆弱性安全的产业环境Vulnerability-orientedsecurityindustrialenvironment威胁方Threatagents厂商Provider用户User10