Frontiers of Data and Computing ›› 2025, Vol. 7 ›› Issue (4): 208-218.

CSTR: 32002.14.jfdc.CN10-1649/TP.2025.04.017

doi: 10.11871/jfdc.issn.2096-742X.2025.04.017

• Technology and Application • Previous Articles    

Design and Practice of Meteorological Cybersecurity Operations Platform

TIAN Zheng(),DENG Xin,FENG Wei*(),ZHAO Licheng,CHEN Xin,ZHONG Lei,PAN Yuting   

  1. National Meteorological Information Centre, Beijing 100081, China
  • Received:2025-05-29 Online:2025-08-20 Published:2025-08-21
  • Contact: FENG Wei E-mail:tianzh0203@163.com;fengw2012@sohu.com

Abstract:

[Objective] To address issues such as data fragmentation, isolated defenses, and lagging responses in the cybersecurity of meteorological departments, this paper proposes the design and implementation of a collaborative national-provincial meteorological security operations platform. [Methods] The platform enables the aggregation and governance of multi-source security monitoring data and asset information, supports centralized correlation analysis of heterogeneous alerts, and facilitates event investigation and traceability. By utilizing automated orchestration and intelligent risk-aware decision-making technologies, it integrates various notification and response components to enable rapid and automated handling of security risks. Through the cascading architecture of national and provincial platforms, the system achieves real-time sharing of security alerts, asset data, and other critical information across provinces, as well as timely distribution of intelligence, early warnings, and incident notifications, thereby supporting collaborative security operations within the meteorological sector. [Results] The practical application tests show that the automatic interception rate of attack IPs reached 99.3%, with the response time reduced to minutes. [Conclusions] The meteorological cybersecurity operations platform integrates security data and capabilities, significantly improving the efficiency of handling security risks and effectively ensuring the safe and stable operation of meteorological services.

Key words: cybersecurity, security operations, risk detection, automated response