| The conventional cybersecurity measures taken by the courts rely only on security equipment such as the firewall or the passive cybersecurity techniques.In this way,the measures can only be taken after the security breach occurs.This is actually a passive defense that is slow in response due to the fact that it has to be operated manually.The study of the thesis is based on the actual cybersecurity needs of a court in Tianjin and aims at solving the problems in the passive defense.It is proposed that the big data technology should be integrated into the cybersecurity technology to avoid the conventional passive defense and manual inspection.Such integration will be equipped with automatic sensing function,which will present the real-time cybersecurity condition to the cybersecurity staff for the sake of running precise and highly-effective management.Based on the research and analysis on the actual needs,a threat-detecting-and-handling platform for cybersecurity can be established by applying Asp.Net technology to the specific technological routes.The platform consists of the sub-systems of back-up management,threat monitoring,inspection and rectification,communication and interaction,knowledge base,statistical analysis and system maintenance.The platform has the features of mass storage,parallel computing and efficient searching function.It integrates various data and technologies and automatically analyzes,handles and deeply processes the kinds of security information such as mass equipment logs and system logs;it proactively assesses and analyzes the cybersecurity condition through the techniques of feature extraction and trend prediction;it senses the abnormal incidents in the Internet system and makes the prediction on the overall cybersecurity condition;it clearly presents the results of the prediction and analysis through visualized technology.Once completed,the results of the study will help transform how that court in Tianjin ensures its cybersecurity and improve the efficiency,precision and effectiveness of the cybersecurity protection.The platform will help improve greatly the level of management and the application of information technology as well as the working efficiency.It will shift the focus of cybersecurity staff away from the previous middle-incident and post-incident handling to automatic prediction and assessment before the security incident happens.This transformation will drasticallylower the cybersecurity risk.In the meantime,efficient communication channels should be set up among its subsidiary courts,so that the advantages of information technology on the aspects of security information management,incident reporting and handling and vulnerability warning can be utilized to the fullest.The level of recognition and cooperation on the work of cybersecurity needs to be improved.The new working model of proactively warning,coordinating work,reporting data,dispatching and directing ought to be established. |