RSA Á¢ÒìɳºÐÅÌ»õ| INKY¡ª¡ª»ùÓÚ»úеѧϰµÄ¶ñÒâÓʼþʶ±ðϵͳ
2020-02-20
2020Äê2ÔÂ24ÈÕ-28ÈÕ£¬ÍøÂçÇå¾²ÐÐҵʢ»áRSA Conference½«ÔھɽðɽÀ¿ªá¡Ä»¡£¾ÅÓÎÀϸç¾ýÒѾΪ¸÷ÈËÏÈÈݹýÈëÑ¡½ñÄêÁ¢ÒìɳºÐµÄʮǿÊ×´´¹«Ë¾£ºElevate Security ¡¢Sqreen¡¢Tala SecurityºÍAppOmniËļҳ§ÉÌÁË£¬½ñÌ콫Ϊ¸÷ÈËÏÈÈݵÄÊÇ£ºINKY¡£
Ò»¡¢¹«Ë¾ÏÈÈÝ
INKY¹«Ë¾µÄ×ܲ¿Î»ÓÚÂíÀïÀ¼´óѧ¹«Ô°£¬ÒÀ¸½ÆæÒìµÄÅÌËã»úÊÓ¾õ¡¢È˹¤ÖÇÄܺͻúеѧϰÊÖÒÕ£¬INKYÔÚµç×ÓÓʼþ·À»¤ÁìÓò´¦ÓÚÐÐÒµÁìÏȵÄְλ¡£ÏÖÔÚ£¬¸Ã¹«Ë¾ÒѾÍê³ÉÁËÈýÂÖÈÚ×Ê£¬¹²³ï¼¯ÁË1183.5ÍòÃÀÔª¡£Æä×î½üµÄÒ»´ÎAÂÖÈÚ×ÊÔÚ2019Äê11Ô£¬ÈÚ×ʽð¶îΪ600ÍòÃÀÔª¡£¹«Ë¾Ê×´´ÈËDave Baggett»¹ÓëËûÈËÅäºÏ½¨ÉèÁËITA Software¹«Ë¾(ITA Software¹«Ë¾ÊÇÒµÄÚÁìÏȵĻúƱËÑË÷¹«Ë¾£¬ÓÚ2011Äê±»¹È¸èÒÔ7.3ÒÚÃÀÔªÊÕ¹º£¬ÏÖÔÚΪ¹È¸èFlights®Ìṩ֧³Ö)¡£
INKY Phish FenceÊǸù«Ë¾µÄÆì½¢²úÆ·£¬¸Ã²úÆ·ÊÇÒ»¸ö»ùÓÚÔÆÅÌËãµÄµç×ÓÓʼþÇ徲ƽ̨¡£¸Ãƽ̨Äܹ»ÏñÈËÒ»ÑùÃ÷È·µç×ÓÓʼþ£¬ÆÊÎöÆäÖеÄڲơ¢´¹ÂڵȶñÒâÐÐΪ£¬ÒÔ±ÜÃâÆóÒµ±»¶ñÒâÓʼþ¹¥»÷¡£
¶þ¡¢Åä¾°ÏÈÈÝ
´¹ÂÚÓʼþÊÇ×î³£¼ûµÄÍøÂçÍþв֮һ¡£´ó²¿·ÖÍøÂç¹¥»÷¶¼ÊÇÒÔ´¹ÂÚÓʼþΪÇÐÈëµã¡£GartnerµÄÊý¾ÝÏÔʾ78%µÄÍøÂçÇå¾²ÊÂÎñÖÐÉæ¼°µ½´¹ÂÚÓʼþ¡£¹Å°å´¹ÂÚÓʼþµÄÔÀíÈçͼËùʾ¡£

¹¥»÷ÕßÊ×ÏÈαװ³ÉÒ»¸ö¿ÉÐŵÄʵÌ司Êܺ¦Õß·¢ËÍÓʼþ£¬²¢ÓÕÆÊܺ¦Õßµã»÷µç×ÓÓʼþÖеĶñÒâÁ´½Ó»òÕßÏÂÔØ¶ñÒ⸽¼þ£¬´Ó¶øµ¼ÖÂÊܺ¦ÕßµÄÖ÷»ú±»×°ÖöñÒâÈí¼þ£¬½ø¶øµ¼ÖÂÊܺ¦Ö÷»ú±»ÀÕË÷Èí¼þ¹¥»÷»òÕßÊý¾Ýй¶¡£
È»¶ø£¬µ±½ñÍøÂç´¹ÂÚÓʼþÕý±äµÃÔ½À´Ô½¾ßÓÐÒÉ»óÐÔ£¬ÒÔÊÇ×ÝÈ»ÂÄÀú¸»ºñµÄÇå¾²Ö°Ô±Ò²ÎÞ·¨ÓÐÓÃµÄ¶ÔÆä¾ÙÐÐÇø·Ö¡£ÆäÖУ¬ÉÌÒµÓʼþʧÏÝ£¨Business Email Compromise £¬BEC£©Ã¿ÄêÔì³É12ÒÚÃÀ½ðµÄËðʧ¡£BEC¹¥»÷ͨ³£Í¨¹ýÕý³£µÄÉÌÎñÁ÷³Ì£¬µ«»áαװ³ÉÆóÒµµÄÔ±¹¤¡¢ÉÌҵͬ°é»ò¹©Ó¦ÉÌ£¬Í¨¹ýÉ繤ÊÖ¶ÎÇÔÈ¡ÆóÒµµÄ×ʽð»òÃô¸ÐÊý¾Ý¡£Óë¹Å°åµÄ´¹ÂÚÓʼþ°üÀ¨¶ñÒâÁ´½Ó»ò¸½¼þ²î±ð£¬BEC¹¥»÷ÕßµÄÓʼþÄÚÈݵÈÊÇÕý³£µÄ£¬ÒÔÊÇÍøÂçÇå¾²²ãÃæµÄ¼ì²éÎÞЧ¡£ÓÉÓÚÓʼþÇå¾²ÒýÆðµÄÓªÒµËðʧ½Ï¸ß£¬Ó¦¶ÔBECÏà¹ØµÄÇå¾²²úÆ·³ÉΪGartner 2019ÄêÊ®´óÏîĿ֮һ¡£ÔÚÏà¹ØµÄ²úÆ·ÖУ¬»úеѧϰÊÖÒÕÔ½À´Ô½¶àµÄ±»ÓÃÀ´Ê¶±ð¶ñÒâÓʼþ£¬²¢È¡µÃÁ˽ϺõÄЧ¹û¡£
Èý¡¢²úÆ·ÏÈÈÝ
INKY Phish FenceÊǸù«Ë¾µÄÖ÷´ò²úÆ·¡£¸Ã²úÆ·ÊÇ»ùÓÚÔÆµÄµç×ÓÓʼþ·À»¤Èí¼þ¡£»ùÓÚÌØ¶¨ÁìÓòµÄ»úеѧϰºÍÅÌËã»úÊÓ¾õÊÖÒÕ£¬¸Ã²úÆ·¿ÉÒÔʶ±ð²¢×èÖ¹¶àÖÖ¶ñÒâÓʼþ£¬°üÀ¨´¹ÂÚÓʼþ£¬Õ©ÆÓʼþµÈ¡£Í¬Ê±£¬¸Ã²úÆ·¿ÉÒԺͶàÖÖµç×ÓÓʼþ·þÎñ×é¼þÏàÍŽᣬ°üÀ¨Exchange¡¢Office 365¡¢G Suite£¬ÎªÆäÌṩȫ·½Î»µÄ·À»¤¡£
1¡¢Exchange£ºExchange ÊÇ΢Èí¹«Ë¾µÄµç×ÓÓʼþ·þÎñ×é¼þ¡£INKY¿ÉÒÔÓëExchangeÎ޷켯³É¡£INKYͨ¹ý×Ô¶¯É¨ÃèËùÓÐÄÚ²¿ºÍÍⲿµÄµç×ÓÓʼþ£¬Ñ°ÕÒÆäÖеĴ¹ÂÚÓʼþ¡¢¶ñÒâÓʼþ¡¢À¬»øÓʼþµÈ¡£¶ñÒâµç×ÓÓʼþ»á±»¸ôÀë¡£
2¡¢Office 365£ºOffice 365 ÊÇÒ»ÖÖ¶©ÔÄʽµÄ¿çƽ̨°ì¹«Èí¼þ£¬»ùÓÚÔÆÆ½Ì¨Ìṩ¶àÖÖ·þÎñ¡£Office 365ÊÇÐí¶à´¹ÂÚÓʼþ¹¥»÷µÄÖ÷ҪĿµÄ¡£ÓÉÓÚ´¹ÂÚÊֶεÄÇÉÃîºÍ½ÆÕ©£¬Office 365×Ô¼ººÍ¹Å°åµÄµÚÈý·½Ç徲ϵͳ²¢²»¿ÉÓÐÓõļì²âµ½¡£INKY¿ÉÒÔÓëOffice 365Î޷켯³É£¬¾ßÓÐÕë¶ÔOffice 365ƽ̨µÄ×Ô½ç˵ʵÏÖ¡£Ëü¼¯³ÉÆðÀ´ÓÖ¿ìÓÖÈÝÒס£INKY»¹¿ÉÒԷֽ׶ΰ²ÅÅ£¬Ò×ÓÚʵÑé¡£
3¡¢G Suite£ºG SuiteÊÇGoogle ÔÚ¶©ÔÄ»ù´¡ÉÏÌṩµÄÒ»Ì×Ð×÷Èí¼þ¹¤¾ß¡£INKY¿ÉÒÔÓëG SuiteÎ޷켯³É£¬ÊµÏÖ¶Ô¶ñÒâÓʼþ£¬´¹ÂÚÓʼþµÄ׼ȷ¼ì²â¡£
INKY Phish Fence¹ýÂËÿһ·âµç×ÓÓʼþ¡£ÔÚ×îÖÕ·ºÆð¸øÓû§µÄÓʼþÖУ¬¸Ãϵͳ»áÔÚÿһ·âÓʼþµÄ¶¥²¿¼ÓÉÏÒ»¸öºá·ù£¨banner£©£¬À´¶ÔÓʼþµÄÇå¾²ÐÔ¾ÙÐÐ˵Ã÷¡£
ºá·ùÊÇINKY Phish FenceµÄÒ»´óÌØÉ«£¬ÈçͼËùʾ¡£



²î±ðΣº¦Ë®Æ½µÄÓʼþÓòî±ðµÄÑÕÉ«±êʶ¡£ÆäÖУ¬»ÒÉ«ºá·ùÓÃÓÚ±êʶÇå¾²µÄÓʼþ£¬»ÆÉ«ºá·ùÓÃÓÚ±êʶÉóÉ÷·¿ªµÄÓʼþ£¬ºìÉ«ºá·ùÓÃÓÚ±êʶΣÏÕÓʼþ¡£ÔÚ»ÆÉ«ºÍºìÉ«±êʶÖеã»÷“Details”Á´½Ó¿ÉÒÔ½øÒ»²½Éó²é¶ÔÓʼþµÄÐÎò¡£ÕâЩÐÅÏ¢¿ÉÒÔÈÃÓû§ÏàʶËûÃǵÄÊÕ¼þÏäÖб£´æµÄÍþв¡£ÁíÍ⣬ÕâЩÐÅÏ¢¿ÉÒÔÈÃÓû§Ñ§Ï°µ½¸ü¶àµÄ´¹ÂÚÓʼþÏà¹ØµÄ֪ʶ£¬ÕâÍùÍù±È´¹ÂÚÓʼþÄ£Äâ²âÊÔÔ½·¢ÓÐÓ᣺á·ùÖеēReport This Email”Á´½ÓÔÊÐíÖÕ¶ËÓû§±¨¸æÀ´×ÔÈκÎÖÕ¶Ë×°±¸µÄÓÐÎÊÌâµÄµç×ÓÓʼþ£¬¶ø²»ÐèÒªÌØÊâµÄ¿Í»§¶ËÈí¼þ¡£INKYÉõÖÁÕûºÏÁË×ÔÈ»ÓïÑÔ´¦Öóͷ£(NLP)Ëã·¨À´Ê¶±ðÃô¸ÐÄÚÈÝ£¬Èçµç»ã»ò·¢Æ±¸¶¿îÇëÇó¡¢ÃÜÂëÏà¹ØµÄµç×ÓÓʼþµÈ£¬²¢ÔÚºá·ùÖбê×¢¿Í»§¿ÉÉèÖõÄÕ½ÂÔÀ´¶ÔÓû§¾ÙÐÐÖ¸µ¼¡£
ËÄ¡¢½¹µãÊÖÒÕ
¹Å°åµÄµç×ÓÓʼþÇå¾²½â¾ö¼Æ»®Í¨³£Ö»ÒÀÀµÓÚÒÑÖªµÄ¹¥»÷ÕßÊý¾Ý¿â¡£INKY³ýÁËʹÓÃ×îеÄÊý¾Ý¿âÍ⣬»¹Ê¹ÓûúеѧϰºÍÅÌËã»úÊÓ¾õÊÖÒÕÀ´¼ì²â´¹ÂÚÓʼþ£¬ÉõÖÁ²¶»ñÁãÈÕµÄBEC´¹ÂÚÕ©Æ¡£Áè¼Ý24¸öÅÌËã»úÊÓ¾õºÍÎÄÌìÖ°ÎöÄ£×ÓÄܹ»ÏñÈËÒ»Ñù“¿´µ½”ÓʼþÐÅÏ¢£¬²¢²¶»ñÈËÀà¿ÉÄÜ»áºöÂÔµÄÎı¾¡¢ÀàÐͺÍͼÏñµÄÒì³£¡£Í¨¹ýÖÇÄÜÆÊÎö£¬¿ÉÒÔ¼ì²â³öÓÐÎÊÌâµÄµç×ÓÓʼþ¡£

´¹ÂÚÓʼþ¼ì²â£º´¹ÂÚÓʼþÖÐÍùÍù°üÀ¨ÓжñÒâÁ´½Ó¡£INKY¶ÔÊÕµ½µÄµç×ÓÓʼþÖаüÀ¨µÄÿ¸öÁ´½Ó¾ÙÐÐÄ£Äâµã»÷£¬²¢¼ì²éÏà¹ØµÄÍøÒ³ÊÇ·ñÓд¹ÂÚ»òÆäËû¶ñÒâÄÚÈݵÄÌØÕ÷¡£º¬ÓжñÒâÍøÕ¾Á´½ÓµÄµç×ÓÓʼþ»á±»±ê¼Ç¸æ¾¯»ò¸ôÀë¡£
¶ñÒâ´úÂë¼ì²â£ºHTMLΪµç×ÓÓʼþÌṩÁ˸ü¸ß¼¶±ðµÄ¿ÉÉèÖÃÐÔ£¬µ«Ò²Ê¹µÃÔÚµç×ÓÓʼþÖÐǶÈë¶ñÒâ¿ÉÖ´ÐдúÂë³ÉΪ¿ÉÄÜ¡£Ä¬ÈÏÇéÐÎÏ£¬INKYÄܹ»±êʶ²¢×èÖ¹Ö´ÐпçÕ¾µã¾ç±¾¹¥»÷£¨XSS£©¡¢JavaScriptºÍCSS¹¥»÷µÄ´úÂë¡£
¿ÉÒÉ·¢¼þÈ˼ì²â£ºINKYµÄ»úеѧϰÒýÇæ¿ÉÒÔͨ¹ýÐÐÎªÌØÕ÷ºÍÉç½»ÍøÂçͼÆ×À´Ê¶±ð¿ÉÒɵÄÐÐΪ»òÉí·Ý¡£Í¨¹ýÊÓ²ìÓʼþÔÚ×éÖ¯ÖеÄÁ÷¶¯ÇéÐΣ¬INKY¿ÉÒÔΪËùÓеÄÈ˽¨ÉèÐÐΪµµ°¸¡£µ±INKY¿´µ½Ò»·âµç×ÓÓʼþµÄ·¢¼þÈ˵ÄÌØÕ÷Óëѧϰµ½µÄÌØÕ÷²»Æ¥Åäʱ£¬Ëü»á·¢³ö¸æ¾¯£¬ÈçͼËùʾ¡£

Ч¹ûÉϱ¨£ºINKY²úÆ·µÄÒ»¸öÆæÒìµÄ¹¦Ð§ÊÇ¿ÉÒÔÔÚÿ·âµç×ÓÓʼþÖеã»÷“Report this Email”Á´½Ó¡£ÕâÒâζ×ÅÓû§¿ÉÒÔÔÚ²»ÐèҪװÖÃÌØ¶¨Èí¼þµÄÇéÐÎϱ¨¸æÀ´×ÔÈκÎ×°±¸£¨web¡¢ÊÖ»ú¡¢Èκεç×ÓÓʼþ¿Í»§¶Ë£©µÄÓÐÎÊÌâµÄÓʼþ¡£¶ø´ó´ó¶¼µç×ÓÓʼþ±£»¤Èí¼þÖ»ÄÜÔÚÒÑ×°ÖÃÌØ¶¨Èí¼þµÄϵͳÉÏÊÂÇé¡£ÕâÑù£¬INKY¿ÉÒÔËæÊ±ÊÕµ½Óû§¶Ô¼ì²âЧ¹ûµÄ·´Ï죬½øÒ»²½ÍêÉÆÆä¼ì²âÄ£×Ó¡£
ËÄ¡¢×ܽá
Ëæ×Å´¹ÂÚÓʼþÔ½À´Ô½¾ßÓÐÒÉ»óÐÔ£¬¹Å°åµÄ»ùÓÚ¹æÔòµÄ¼ì²âÒªÁìÒѾÎÞ·¨ÓÐÓõľÙÐмì²â¡£INKY¹«Ë¾µÄ²úÆ·INKY Phish Fence½ÓÄÉ»úеѧϰÊÖÒÕ¶ÔÓʼþ¾ÙÐÐÖÇÄÜÆÊÎö£¬¿ÉÒÔÔ½·¢ÓÐÓõØÊ¶±ð´¹ÂÚÓʼþ¡£¶ø°²ÅÅÔÚÔÆ¶ËµÄ¼ì²âϵͳʹµÃÆóÒµ°²ÅÅÔ½·¢ÎÞа¡£Í¬Ê±£¬¸Ã²úÆ·¿ÉÒÔÓëExchange£¬Office 365ºÍG SuiteµÈ°ì¹«Èí¼þÎ޷켯³É£¬Äܹ»ÎªÆóÒµÌṩԽ·¢ÖÜÈ«µÄ·À»¤¡£
· ²Î¿¼Á´½Ó ·
[1] Gartner 2019Ê®´óÇå¾²ÏîÄ¿£ºhttps://www.gartner.com/smarterwithgartner/gartner-top-10-security-projects-for-2019/
[2]https://www.crunchbase.com/search/funding_rounds/field/organizations/num_funding_rounds/arcode
[3] https://www.inky.com/
[4] Gartner Security & Risk Management Summit 2019

¾ÅÓÎÀϸçÔÆ







