Analysis of data security measures in the era of big data

Release time:2023-01-16

The era of big data has come. Big data technology and application are booming, and the number and value of big data are rising rapidly. In addition to the rich value contained in the data resources themselves, metadata resources can create greater economic and social value through mining and analysis. With the further implementation of the Internet plus action plan, big data will accelerate its penetration from the Internet to a wider range of fields. At the same time, big data security threats will also spread to all walks of life. In the first year of 2015, the 12306 website user information leakage and other data leakage events have once again sounded an alarm to us, and the data resource security is facing serious challenges.
1、 Main challenges to data security in the era of big data
1. Data infrastructure is frequently attacked, and the risk of data loss and disclosure is increased
Data centers and mobile intelligent terminals carry a large number of important business data and user personal information, and their security status is increasingly prominent. However, attacks against IDC have increased in recent years. In December 2014, Alibaba Cloud said that it had suffered the largest DDoS attack in the world. In early 2015, an Asian network operator's data center suffered a 334Gbps spam data stream attack. At the same time, the number of malicious applications and trojans that violate data security is increasing, which poses a great threat to user privacy and property security. In 2014, the number of Android users infected with malicious programs monitored by security enterprises reached 319 million, and the average number of malicious program infections per day reached 875000.
2. New network threats emerge in endlessly, forcing data protection technology innovation
The technical complexity and concealment of new network threats are getting higher and higher, and the scope of harm is expanding. In 2014, the heart bleeding vulnerability threatened the security of user names, passwords, server certificates, private keys and other sensitive data stored in about 2/3 of the world's network servers; In the same year, Sony was attacked by ATP, and a large number of employee information and film and television copies were leaked. The endless emergence of new network threats forces breakthroughs in network data protection technology.
3. The underground industrial chain of data trading is rampant, and governance still needs to be carried out for a long time
Driven by interests, illegal collection, theft, trafficking and utilization of user information are increasingly rampant, and the total scale of the domestic underground industrial chain that resells user information has exceeded 10 billion. In order to prevent and control the underground industrial chain of hackers, the Ministry of Industry and Information Technology carried out a special action in 2014 and achieved some results. However, it also faced law enforcement challenges such as diverse technical means, multiple links involved, and strong concealment. There is a long way to go for long-term governance.
4. Cross-border data flow has become a focus of attention, and the regulatory mechanism is facing challenges
The free flow of Internet and mobile data around the world has become an important driving force for economic growth, employment creation and social welfare, but also an important threat to information sovereignty, intellectual property rights and citizens' privacy. Since cross-border data flow may lead to the loss of national key data resources, countries attach great importance to the international problem of data cross-border flow supervision, but there is still a lack of uniform norms and international rules to guide the supervision of data cross-border flow.
5. The demand for data resources is strong, and the contradiction between open sharing and security protection is prominent
With the construction and development of smart cities and the continuous deepening of the integration of urbanization and urbanization, the demand for data open and sharing based on economic and people's needs is increasingly strong. Transportation, tourism and other institutions put forward demands on population distribution and flow data in order to optimize services; Commercial customers need user behavior characteristic data for decision support in product customization and precision marketing. At present, the open sharing of data resources lacks comprehensive and effective management and security protection, and the open sharing and security protection of national data resources has become a long-standing problem.
2、 International data security practice
With the deepening understanding of the importance of data security in various countries, major international countries have carried out data security assurance practices from laws and regulations, strategic policies, technical means, standard evaluation and other aspects.
1. Focus on information sharing and cross-border flow, and improve the legal system of data protection
The United States promulgated the National Network Security Protection Act of 2014, actively promoted the issuance of the Network Security Information Sharing Act, and urged private enterprises to share network security information with the government. The EU has adopted a new version of the Data Protection Law to emphasize local storage and prohibit cross-border sharing. Russia has implemented a new law since 2015, stipulating that Internet enterprises need to store the collected information of Russian citizens in Russia.
2. Pay equal attention to top-level design and policy implementation, and deepen data security policy guidance
Countries have taken data security as an important part of their national strategies, and separately explained data security policies. Japan's 2013 "Creating the most cutting-edge IT strategy" clearly states the national strategy of open public data and big data protection; India's 2014 draft national telecommunication security policy guidance provides for mobile data protection. At the same time, we should innovate the implementation of policies and guide the implementation of policies through the project model. France's "Future Investment Plan" strongly promotes the implementation of cloud computing data security protection policy; The UK "Data. Gov. uk" project measured the application effect of the open government data protection policy.
3. Strengthen security technical means from the key links of key data protection
Data security assurance technology in the world has covered key links such as data collection, storage, mining and publishing, and has provided universal technical means to protect data security, such as transmission security and SSL/VPN technology, digital encryption and data recovery technology, biometric-based identity authentication and mandatory access control technology, journal-based security audit, digital watermarking and other traceability technologies. In addition, the R&D and application of data security protection special technologies such as data leakage prevention (DLP) technology and cloud platform data security are accelerating.
4. Improve the data security standard system and carry out data security assessment and certification practice
Countries and international standards organizations have issued standards and guidelines related to data security. The National Institute of Standards and Technology (NIST) of the United States has issued a user identification guide; ISO/IEC has formulated practical rules for data protection control measures of public cloud computing services. At the same time, the evaluation of data security and related authentication systems are becoming mature. TRUSTe privacy certification in the United States has been recognized and trusted by consumers in many countries around the world; The European Commission has carried out the security assessment of data cross-border flow, which has become an important basis for judging whether data can be transferred. In addition, practices such as international safe harbor certification, contract model and company binding rules have promoted the improvement of data security protection level.
3、 Thoughts on China's data security
In recent years, China has attached great importance to data security, and has successively issued laws and regulations such as the Decision on Strengthening the Protection of Network Information, the Provisions on the Protection of Personal Information of Telecom and Internet Users, as well as a number of departmental rules and regulations related to data protection, issued national and industrial standards for the protection of network personal information, and carried out security protection inspections focusing on data security at the national and industrial levels, with certain results. However, in general, China's lack of data security legislation, lack of dedicated protection technology, inadequate data security assessment and other issues are prominent, and the data security guarantee capacity needs to be further improved. Therefore, from the current data security challenges, we should take multiple measures to build a comprehensive data security protection system and focus on improving the data security guarantee capability.
First, promote the legislative process of data security protection. Accelerate the process of data security legislation, clarify the object, scope and liability of data protection, and formulate legal provisions on data open sharing and cross-border flow supervision. At the same time, the scope of adjustment of existing laws should be broadened to include data protection under new technology and application scenarios such as industrial internet and cloud computing into the scope of legal adjustment.
The second is to introduce the national data security protection strategy. Position data security from the perspective of national security and national strategic resources, and strengthen data strategic planning. Formulate regulatory policies on the cross-border flow of key data and user information in key industries such as communications and finance, and promote legislation to regulate the domestic storage of personal information of Chinese citizens. Actively participate in the formulation of international rules, enhance China's voice in the field of data protection, and create a good international environment for China's data security protection.
The third is to strengthen the technical breakthrough of data security protection. Strengthen the construction of key technical means for data protection, and accelerate the research and development of key technologies such as identity management, APT attack defense, DDoS attack traceability, etc. Accelerate the research on data security supervision and support technology, and improve the monitoring, discovery and disposal capabilities for security risks such as sensitive data leakage and illegal cross-border data flow.
Fourth, improve the data security standard system and evaluation system. Make overall plans for the development of data security-related standards, and actively carry out the research and development of general and special data security standards. We will strengthen the detection and assessment of data security and promote the security assessment of cross-border data flows.
4、 Conclusion
In the era of big data, opportunities and challenges coexist. In the face of the new situation and new problems, we should pay equal attention to security and development, build up the defense line of big data security management in China, and guard the information sovereignty and user privacy of our country, so as to prevent large and disorderly, large and insecure, and truly achieve great advantages and great use.

key word: Analysis of data security measures in the era of big data

其他技术