ÍøÂçÍþв¹¥Êز©ÞÄ×ݺá¶þÊ®Äê
2020-05-10
¾ÅÓÎÀÏ¸ç¿Æ¼¼½¨ÉèÖ®³õ£¬º£ÄÚÐÅÏ¢ÊÖÒÕ¸Õ¸ÕÆð²½£¬¸÷´ó¸ßУ»¹Ã»ÓÐÉèÁ¢Ç徲רҵ£¬2001ÄêµÄÖÐÃÀºÚ¿Í´óÕ½Èç»ðÈçݱ£¬°×¹¬ÍøÕ¾ÉÏÆ®ÑïµÄºìÉ«ìºÆìʹ“ÍøÂç¹¥»÷”Õâ¸öÃû´Ê½øÈ뺣ÄÚ¹«¹²ÊÓÒ°¡£Ëæºó£¬2003Äê·ºÆðµÄ¹¥»÷²¨£¨Worm.Blaster£©²¡¶¾Í¨¹ýÒ»¸ö×îеÄRPCÎó²î¾ÙÐÐÈö²¥£¬²¡¶¾Ï¯¾íÈ«Çò£¬ÈÃÎÞÊýµçÄÔÖØ¸´ÖØÆô£¬²¢Í¬Ê±¶Ô΢ÈíÒ»¸öÉý¼¶ÍøÕ¾¾ÙÐоܾø·þÎñ¹¥»÷£¬µ¼ÖÂÍøÕ¾¹£Èû£¬Óû§ÎÞ·¨Í¨¹ý¸ÃÍøÕ¾Éý¼¶ÏµÍ³¡£´Ë´ÎÍøÂç¹¥»÷ÈÃÕýÔÚ¾ÙÐÐÐÅÏ¢»¯½¨ÉèµÄÆóÒµºÍСÎÒ˽¼ÒÓû§ÕæÕýÒâʶµ½ÍøÂçÇå¾²·ÀÓùµÄÖ÷ÒªÐÔ¡£
“Íþв”Õâ¸ö¿´·¨¿ÉÒÔ×·Ëݵ½20ÊÀ¼Í80ÄêÔ£¬AdenrsonÓÃÁË“Íþв”ÕâÒ»¿´·¨ÊõÓÆä½ç˵ÓëÈëÇÖÏàͬ£¬½«ÈëÇÖÍýÏë»òÍþв½ç˵Ϊδ¾ÊÚȨÐîÒâʵÑé»á¼ûÐÅÏ¢¡¢¸Ä¶¯ÐÅÏ¢¡¢Ê¹ÏµÍ³²»¿É¿¿»ò²»¿ÉʹÓá£Heady¸ø³öÁíÍâµÄÈëÇÖ½ç˵£¬ÈëÇÖÊÇÖ¸ÓйØÊÔÍ¼ÆÆËð×ÊÔ´µÄÍêÕûÐÔ¡¢ÉñÃØÐÔ¼°¿ÉÓÃÐÔµÄÔ˶¯ÜöÝÍ¡£Smaba´Ó·ÖÀà½Ç¶ÈÖ¸ÊÕÖ§ÇÖ°üÀ¨ÊµÑéÐÔÍ»È롢αװ¹¥»÷¡¢Çå¾²¿ØÖÆÏµÍ³ÉøÍ¸¡¢Ð¹Â¶¡¢¾Ü¾ø·þÎñ¡¢¶ñÒâʹÓÃ6ÖÖÀàÐÍ¡£ÔçÆÚÍøÂçºÚ¿ÍÓëÇ徲ר¼ÒÕýÊÇÎ§ÈÆÕâЩÈëÇÖµÄÒªÁ켰ʹÓõÄÊÖÒÕÊֶξÙÐй¥Êز©ÞÄ¡£
·À»ðǽ¡¢ÈëÇÖ¼ì²âϵͳÏòÈëÇÖ·ÀÓùϵͳµÄת±ä
×îÔçµÄÍøÂçÇå¾²·ÀÓùϵͳÊÇ·À»ðǽ£¬ÆäÔÚÍâµØÍøÂçÓëÍâ½çÍøÂçÖ®¼äÖ´ÐпØÖÆÕ½ÂÔ£¬¶ÔÍøÂç¼ä´«ÊäµÄÊý¾Ý°ü×ñÕÕÖÆ¶©µÄÇå¾²Õ½ÂÔ¾ÙÐмì²â£¬ÒÔ¾öÒéͨѶÊÇ·ñ±»ÔÊÐí¡£·À»ðǽ±£´æ¾ÖÏÞÐÔºÍȱ·¦£¬Æäͨ³£×÷ÓÃÓÚÒÑÖªÐÒéµÄ»á¼û¿ØÖÆ£¬Èç¹¥»÷Õß½«¶ñÒâ´úÂë»ò¹¥»÷Ö¸Áî¾ÙÐÐÐÒéÒþ²Ø¾Í¿ÉÄÜÌÓÒÝ·ÀÓù¡£
ͬÆÚ·ºÆðµÄÍøÂçÍþв¼ì²âϵͳÊÇÈëÇÖ¼ì²âϵͳ£¬Ëüͨ³£Î»ÓÚ·À»ðǽ֮ºó£¬±»ÒÔΪÊǵڶþµÀÇå¾²Õ¢ÃÅ¡£ÈëÇÖ¼ì²âÊÖÒÕÖ÷Òª·ÖΪÁ½´óÀࣺÒì³£ÈëÇÖ¼ì²âºÍÎóÓÃÈëÇÖ¼ì²â£¬ÆäÌṩÁ˶ÔÄÚ¡¢Íⲿ¹¥»÷µÄʵʱ¼ì²â£¬°üÀ¨ÔÚÍøÂçÊܵ½Íþв֮³õµÄ×èµ²ºÍÏìÓ¦ÈëÇÖ¡£ÈëÇÖ¼ì²âϵͳµÄȱ·¦ÔÚÓÚ£¬ËüÖ»Äܼì²â¹¥»÷£¬¶ø²»¿É×èÖ¹¹¥»÷¡£
Ëæ×ÅÊÖÒÕµÄÉú³¤£¬ÍŽáÉÏÊöÁ½ÖÖϵͳµÄÁªÏÂÊÖÒÕÓ¦Ô˶øÉú£¬·À»ðǽ¿ÉÒÔͨ¹ýÈëÇÖ¼ì²âϵͳʵʱ·¢Ã÷Õ½ÂÔÖ®ÍâµÄ¹¥»÷ÐÐΪ£¬ÈëÇÖ¼ì²âÒ²¿ÉÒÔͨ¹ý·À»ðǽ¶ÔÀ´×ÔÍⲿµÄÍøÂç¹¥»÷ÐÐΪ¾ÙÐÐ×è¶Ï¡£
¶øÍê³ÉÕâÁ½ÖÖϵͳµÄÈںϡ¢ÊµÏÖ1+1>2µÄÊÇѸËÙո¶ͷ½ÇµÄÍøÂçÈëÇÖ·À»¤ÏµÍ³¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍƳöµÄ“±ùÖ®ÑÛ”ÍøÂçÈëÇÖ·À»¤ÏµÍ³£¬ÄÜÌṩ´ÓÍøÂç²ã¡¢Ó¦Óò㵽ÄÚÈݲãµÄÉî¶ÈÇå¾²·À»¤£¬¾ß±¸ÊµÊ±¡¢×Ô¶¯µÄ·À»¤ÄÜÁ¦£¬×¼È·Ê¶±ðÖÖÖֺڿ͹¥»÷£¬²¢ÓÐÓÃ×è¶Ï¹¥»÷¶ø²»Ó°ÏìÕý³£ÓªÒµÁ÷Á¿¡£
Îó²îÍÚ¾òÊÖÒÕÔö½øÇå¾²·ÀÓù
Ç徲ר¼ÒÔÚ²©ÞÄÀú³ÌÖÐʵÑé×Ô¶¯³ö»÷£¬È¥ÍÚ¾ò±£´æµÄÍþвÒþ»¼£¬ÃãÀøÐû²¼¡¢¹²ÏíÕâЩÍþвÒþ»¼µÄÐÅÏ¢£¬´Ùʹ´ÓÒµÖ°Ô±ÄܸüºÃµØ±£»¤Óû§¡£Îó²îÍÚ¾òÊÇÒ»¸ö¶àÖÖÎó²îÍÚ¾òÆÊÎöÊÖÒÕÏàÍŽᡢÅäºÏʹÓúÍÓÅÊÆ»¥²¹µÄÀú³Ì¡£³£ÓõÄÎó²îÍÚ¾òÊÖÒÕ°üÀ¨ÊÖ¹¤²âÊÔÊÖÒÕ¡¢FuzzingÊÖÒÕ¡¢±ÈÕպͶþ½øÖƱÈÕÕÊÖÒÕ¡¢¾²Ì¬ÆÊÎöÊÖÒÕ¡¢¶¯Ì¬ÆÊÎöÊÖÒյȡ£
Ëæ×ÅÔ½À´Ô½¶àר¼ÒͶÈëÆäÖУ¬Îª¹«¹²ËùÖªµÄÎó²îÊý¾ÝÖðÄêÔöÌí£¬´Ó2000ÄêµÄ1243ÌõÔöÌíµ½2019ÄêµÄ20827Ìõ£¬ÎªÍøÂç·ÀÓùÊÖÒÕÌṩÁ˼áʵµÄ֪ʶ´¢±¸¡£
Îó²î¿â
ÔçÆÚ×öÍøÂçÇå¾²²úÆ·£¬Çå¾²Ñо¿Ô±·¢Ã÷Îó²îºó¶ÔÆä¾ÙÐÐÃüÃû£¬Ëæ×ÅÎó²îÑо¿µÄÉîÈ룬һЩÎó²îÒѾºÜÄÑÒÀÀµÃû³ÆÇø·Ö£¬ÔçÆÚµÄÇå¾²Ñо¿»ú¹¹ºÍ´óÐͳ§ÉÌ×îÏÈʹÓÃÎó²î¿âÖÎÀíÖÚ¶àÎó²î¡£Îó²î¿âÊǾÙÐÐÍøÂçÇå¾²Òþ»¼ÆÊÎöµÄ»ù´¡£¬½¨ÉèÎó²î¿âÓÐÊ®·ÖÖ÷ÒªµÄÒâÒå¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔçÔÚ2000Äê¾ÍÍÆ³öÁËÎó²î¿â£¬Àú¾20ÄêµÄËêÔ£¬ÈÔÒ»Á¬Î¬»¤×ÅÎó²î¿âµÄ¸üУ¬ÖÁ½ñÒÑÊÕ¼45689ÌõÎó²î£¬°üÀ¨Ö÷Á÷Îó²îÐÅÏ¢ÒÔ¼°¹«Ë¾Ñо¿Ô±×ÔÖ÷·¢Ã÷µÄÎó²îÐÅÏ¢¡£
Îó²î¿â¶ÔÇå¾²·À»¤²úÆ·Ò²ºÜÊÇÖ÷Òª£¬ÔÚ¸÷¸ö³§É̵ÄÇå¾²·À»¤²úƷչʾ×ÔÉí·À»¤ÄÜÁ¦µÄʱ¼ä£¬Ê¹ÓÃͳһÎó²î¿âµÄÐÎò½«Ö±¹ÛµØÈÃÓû§Ïàʶ·À»¤Ð§¹û¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼Îó²î¿â¼æÈݹú¼ÒÐÅÏ¢Çå¾²Îó²î¿â£¨ChinaNationalVulnerabilityDatabaseofInformationSecurity£¬¼ò³ÆCNNVD£©ÒÔ¼°¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨ChinaNationalVulnerabilityDatabase£¬¼ò³ÆCNVD£©£¬±ðµÄ»¹¼æÈÝÍâÑóµÄͨÓÃÎó²îÅû¶CVE£¬Îªº£ÄÚÍâÓû§Ê¹ÓÃÌṩÁ˱㵱¡£
WebÇå¾²µÄÐËÆð
Ëæ×ÅInternetÊÖÒÕµÄÐËÆð£¬±ã½ÝµÄ¿çÇøÓòÊÂÎñ´¦Öóͷ£ÏÔµÃÓÈΪÖ÷Òª£¬ÎªÁËʵÏÖÓû§ÍÑÀë³ÌÐòµÄÖØ´ó×°ÖöøÊ¹ÓÃWWWä¯ÀÀÆ÷¾ÙÐÐ¿çµØÇøµÄÓ¦ÓòÙ×÷£¬Ïà¹ØµÄÓ¦Óÿª·¢Öð²½´ÓClient/Server¼Ü¹¹×ªÏòÁËBrowser/Server¼Ü¹¹£¬Óû§¶Ë½öÐèҪʵÏÖÉÙÁ¿µÄÊÂÎñÂß¼£¬¶øÖ÷ÒªµÄÊÂÎñÂß¼ÔÚ·þÎñÆ÷¶Ë¾ÙÐÐʵÏÖ¡£Browser/Server¼Ü¹¹¿ÉÒÔ´ó´ó¼ò»¯¿Í»§¶ËµçÄÔ¸ºÔØ£¬¼õÇáϵͳά»¤ºÍÉý¼¶µÄ±¾Ç®ºÍÊÂÇéÁ¿£¬´Ó¶ø½µµÍ×ܱ¾Ç®¡£Ú¹ÊÍÐÍÓïÑԵIJ»Ç徲ʹÓ㨶ÔÓû§ÊäÈëµÄÄÚÈÝûÓÐ×öÑÏ¿á¼ì²é£©´ßÉúÁË»ùÓÚWebµÄ¹¥»÷ÊÖÒÕ£¬ÀýÈçSQL×¢Èë¡¢¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©¡¢Ô¶³ÌÏÂÁî×¢Èë¡¢¿çÕ¾µãÇëÇóαÔ죨CSRF£©¡¢CC¹¥»÷µÈ£¬ÕâЩ¹¥»÷µ¼ÖÂÆóÒµ»òÕßСÎÒ˽¼ÒÃô¸ÐÊý¾Ý×ß©¡¢·þÎñÆ÷¾Ü¾ø·þÎñ»òÕßÓªÒµ±»½ÓÊÜ£¬ÉõÖÁÓпÉÄÜÓÉÓÚÊܵ½µÄ¹¥»÷¶ø±³ÉÏÖ´·¨ÔðÈΡ£
Õë¶ÔWeb¹¥»÷ÊÖÒÕ¶ÔÍøÕ¾Çå¾²ÍþвԽÀ´Ô½ÑÏÖØ£¬Çå¾²¹«Ë¾ÏìÓ¦ÍÆ³öÁËWAFÍøÕ¾Çå¾²·À»¤¹¤¾ßºÍWebÇå¾²ÆÀ¹À¹¤¾ß¡£
¹¤¿ØÇå¾²ÒýÆð¸÷È˹Ø×¢
2010ÄêµÄÕðÍøÈ䳿²¡¶¾£¨ÓÖÃûStuxnet²¡¶¾£©£¬Ò»¸öϯ¾íÈ«Çò¹¤Òµ½çµÄ²¡¶¾£¬ÊÇÒ»ÖÖÈ«ÐĽṹµÄ¶ñÒâ´úÂ룬ÆäÖаüÀ¨Á˶à¸ö¿ÉʹÓõÄÎó²î£¬Í¨¹ýÒ»Ì×ÍêÉÆµÄÈëÇÖºÍÈö²¥Á÷³Ì£¬Í»ÆÆ¹¤Òµ×¨ÓþÖÓòÍøµÄÎïÀíÏÞÖÆ£¬Õë¶ÔÏÖʵÌìÏÂÖеĹ¤Òµ»ù´¡ÉèÊ©Õö¿ª¹¥»÷¡£Í¨¹ýÖÜÆÚÐÔÐÞ¸ÄPLCµÄÊÂÇ鯵ÂÊ£¬Ôì³ÉPLC¿ØÖƵÄÀëÐÄ»úתËÙͻȻÉý¸ßºÍ½µµÍ£¬µ¼ÖÂÀëÐÄ»ú±¬·¢Òì³£Õ𾪺ÍÓ¦Á¦»û±ä£¬×îÖÕÆÆËðÀëÐÄ»ú¡£
Õë¶ÔÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷Ôì³ÉµÄËðʧ¸øÕû¸ö¹¤Òµ½çÇÃÏìÁ˾¯ÖÓ£¬¸÷¹ú×îÏÈÃ÷È·Ö¸³ö¹¤Òµ¿ØÖÆÏµÍ³ÐÅÏ¢Çå¾²ÃæÁÙ×ÅÑÏËàµÄÐÎÊÆ£¬²¢ÒªÇóÇÐʵÔöÇ¿¹¤Òµ¿ØÖÆÏµÍ³µÄÐÅÏ¢Çå¾²ÖÎÀí¡£Çå¾²¹«Ë¾·×·××Ô¶¯¼ç¸ºÆðÊØÎÀÖ®Ô𣬽«¹¤¿ØÇå¾²¶¨Î»ÎªÕ½ÂÔÉú³¤Æ«Ïò£¬Ê¹ÓùŰ幥·ÀÓÅÊÆ£¬×¤×ã“δ֪¹¥¡¢ÑÉÖª·À”µÄÍ·ÄÔ£¬µ÷ÑÐÀúÊ·ÊÂÎñ£¬ÆÊÎöÍøÂç¹¥»÷·½·¨£¬ÒÔųÈõÐÔΪÈë¿Úµã£¬·×·×Ðû²¼ÁËÕë¶Ô¹¤Òµ¿ØÖÆÏµÍ³µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¬ÏÈÓÚ¹¥»÷Õß·¢Ã÷¹¤¿ØÓªÒµÏµÍ³±£´æµÄųÈõÐÔ£¬²¢Ìṩ»º½â¼Æ»®£¬ÆäÖоÅÓÎÀϸ繤¿ØÎó²îɨÃèϵͳICSScanÊÇÑÇÌ«µØÇøµÚÒ»¸ö½øÈëGartnerÊÓÒ°µÄ¹¤¿ØÇ徲רÓüì²â²úÆ·¡£ÔÚÒÑÖªÍþвµÄ»ù´¡ÉÏ£¬ÎªÁ˸üºÃµØÊµÏÖϵͳ·À»¤£¬ÇÐʵ°ü¹Ü¹¤¿ØÓªÒµµÄ˳³©ÔËÐУ¬Çå¾²·À»¤²úÆ·ÈçÓêºó´ºËñ°ã¸¡ÏÖÓÚ¹¤¿ØÓªÒµÊг¡£¬ÀýÈ繤ҵ·À»ðǽ¡¢¹¤ÒµÇå¾²Íø¹Ø¡¢¹¤ÒµÇå¾²¸ôÀë×°ÖÃÒÔ¼°×ÝÏò¼ÓÃÜ×°Öõȡ£
Ëæ×Ź¥»÷ÈÕÒæ¶àÑù»¯¡¢Öش󻯺͹¥»÷Ä¿µÄÃ÷È·»¯£¬Çå¾²¹«Ë¾ÐèÒª¹¹½¨´Óƽ̨µ½×°±¸µÄ·Ö²ãÇå¾²¼Ü¹¹£¬ÁýÕÖÆÀ¹À¡¢·À»¤¡¢¼ì²â¡¢ÏìÓ¦µÄÇ徲ϵͳ£¬ÌṩȫÉúÃüÖÜÆÚµÄÇå¾²·À»¤¡£
¹¤¿ØÇå¾²·ÀÓùϵͳµÄ½¨ÉèÐèÒªÏû³ýIT¡¢OT¡¢¹¤³Ì¡¢²ÆÎñ¡¢ÖÎÀíºÍÖ´ÐÐÏòµ¼µÄ½çÏߣ¬ÍŽá¶à·½ÊµÁ¦²Å¿ÉÒÔÍê³É£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼×÷ΪÌᳫµ¥Î»£¬ÂÊÏȼÓÈ빤ҵ¿ØÖÆÏµÍ³ÐÅÏ¢Çå¾²¹¤ÒµÍ¬ÃË£¬Ï£ÍûÄÜȺ¼¯¶à¼ÒÖ®³¤£¬ÅäºÏµÖÓùÕë¶Ô¹¤Òµ¿ØÖÆÇéÐεÄÍøÂç¹¥»÷£¬Îª¹¤ÒµÍøÂçÇå¾²±£¼Ý»¤º½¡£
ÎïÁªÍø
µ±½ñÉç»áÎïÁªÍø×°±¸ÒѾÖð²½ÉøÍ¸µ½ÈËÃÇÉú²ú¡¢ÉúÑĵķ½·½ÃæÃ棬ΪÈËÃÇʵʱÏàʶ×Ô¼ºÖÜΧÇéÐÎÒÔ¼°¸¨ÖúÒ»Ñùƽ³£ÊÂÇé´øÀ´±ãµ±¡£µ«Ëæ×Å»¥ÁªÏ¸ÃܶȵÄÔö¸ß£¬ÎïÁªÍø×°±¸µÄÇå¾²ÐÔÎÊÌâÒ²Öð½¥Ó°Ïìµ½ÈËÃǵÄÕý³£ÉúÑÄ£¬ÉõÖÁÉúÃüÇå¾²¡£
Ä¿½ñÎïÁªÍøÖб£´æµÄÍþвÊÇÏÔ¶øÒ×¼ûµÄ£¬´Ó2014ÄêÆØ¹âµÄNetcore·ÓÉÆ÷ºóÃŵ½2016Äê´ó¹æÄ£±¬·¢µÄMirai¶ñÒâ´úÂëÊÂÎñ£¬´Ó2017ÄêµÄÎÞÈË»ú¶à´ÎÈëÇÖ»ú³¡µ½2019ÄêÂùÝ͵ÅÄÉãÏñÍ·Òý·¢È«Ãñ¿Ö»Å£¬²»µ«“ÎïÁªÍø³ÉÎªÍøÂç¹¥»÷ÖеÄÖ÷Òª»·½Ú”´ÓÔ¤ÑÔ±äÏÖʵ£¬²¢ÇÒÎïÁªÍøÇå¾²ÊÂÎñÊýÄ¿·ºÆð³öѸÃÍÔöÌíµÄÇ÷ÊÆ¡£Áè¼Ý°ÙGbpsÔ´ÓÚÎïÁªÍøµÄ¹¥»÷ÒѾ³ÉΪÏÖʵ£¬ÎïÁªÍø³¡¾°ÏµÄÇå¾²¶Ô¿¹ÒѾ·ºÆðÔÚÕâ´ÎÀå¸ïµÄÀ˳±ÖУ¬Ó°Ïì×ÅÍòÍòÆóÒµ»òÕßͨË×СÎÒ˽¼Ò¡£ÎÞÂÛÎÒÃÇÊÇ·ñÒâʶµ½£¬ÕⳡսÕùÒѾ´òÏì¡£
ÎïÁªÍøÓ¦ÓÃÖÐÉæ¼°¶à¸ö¼ÓÈë·½£ºÎïÁªÍø×°±¸ÌṩÉÌ¡¢ÎïÁªÍøÆ½Ì¨ÌṩÉÌ¡¢ÎïÁªÍøÍøÂçÌṩÉÌ¡¢ÎïÁªÍøÓ¦ÓÃÌṩÉÌ¡¢Í¨Ë×Óû§¡¢ÎïÁªÍøÇå¾²ÌṩÉÌ£¬Ã¿¸ö¼ÓÈë·½ÔÚ˼Á¿Çå¾²ÎÊÌâʱ×ÅÖØµãÒ²»áÓÐËù²î±ð£¬Ò»¸öÉè¼ÆºÏÀíµÄÎïÁªÍøÇå¾²·À»¤¼Æ»®Ðè׽ס¸÷ÐèÇóµã£¬²Å»ªÇÐʵ½«ÎïÁªÍøÇå¾²Âäʵµ½Î»¡£
Ëæ×ÅÇéÐκÍÍþвµÄת±ä£¬Çå¾²·À»¤Ë¼Ð÷Ò²ÔÚÖð½¥×ª±ä¡£ÎïÁªÍøµÄË鯬»¯¡¢¶¯Ì¬ÐÔÌØµã£¬Ôì³É´¿´âµÄÒÀÀµÇå¾²³§É̾ÙÐÐͨÀýµÄ·À»¤ÒÑÈ»²»·ó£¬Ö»ÓÐÈں϶෽ʵÁ¦£¬²Å»ªÕæÕý½â¾öÎïÁªÍøÇå¾²ÎÊÌ⣬·À»¤ÊýÒÔ°ÙÒڼƵÄÎïÁªÍø×°±¸Çå¾²£¬±£»¤¿í´óÈËÃñȺÖÚµÄÈËÉí¹¤ÒµÇå¾²¡£
APT¹¥»÷
2009Äê¸ß¼¶¿ÉÒ»Á¬Íþв£¨APT£ºAdvancedPersistentThreat£©½øÈëÈËÃǵÄÊÓÒ°£¬ÌØÊâÊÇ“¼«¹â£¨Aurora£©”¹¥»÷¡¢“ÕðÍø£¨Stuxnet£©”²¡¶¾¡¢“Ò¹Áú”¹¥»÷£¬ÈÃAPT¸ß¼¶Ò»Á¬ÐÔÍþв³ÉΪÐÅÏ¢Çå¾²ÐÐÒµÖõÄ¿µÄ½¹µã¡£APT×÷ΪһÖÖ¾«×¼¡¢¸ßЧµÄÐÂÐÍÍøÂç¹¥»÷·½·¨£¬±»ÆµÈÔÓÃÓÚÖÖÖÖÖ÷ÒªÍøÂç¹¥»÷ÊÂÎñÖ®ÖУ¬ÔÚÕþÖÎÇå¾²¡¢¹ú·ÀÇå¾²¡¢ÆóÒµÇå¾²µÈ¶à¸öÖ÷ÒªÁìÓò±»¸ß¶È¹Ø×¢£¬²¢Ñ¸ËÙ³ÉΪÐÅÏ¢Çå¾²×î´óµÄÍþв֮һ¡£ÓÉÓÚºÚ¿ÍÆÕ±éʹÓÃ0Day¡¢Î´ÖªÄ¾Âí¾ÙÐÐÔ¶³Ì¿ØÖÆ£¬Ä¾Âí¹¥»÷ÐÐÎªÌØÕ÷ÄÑÒÔÌáÈ¡£¬¸ø¹Å°åµÄÈëÇÖ¼ì²âÊÖÒÕ´øÀ´ÁËÖØ´óµÄÌôÕ½¡£ÔõÑù׼ȷµØ¼ì²âÃæÏòδ֪ľÂíµÄAPT¹¥»÷£¬Ìá¸ßAPTµÄ¼ì²âÄÜÁ¦£¬ÊµÊ±·¢Ã÷ÍøÂçÖпÉÄܱ£´æµÄAPT¹¥»÷Íþв£¬ÊÇÍøÂçÇå¾²¹«Ë¾Î¬»¤ÍøÂçÖÈÐò£¬°ü¹ÜÉç»áÇå¾²µÄʹÃüËùÔÚ¡£¶ÔAPTµÄÑо¿ÆÊÎö·¢Ã÷£¬APT¹¥»÷Ö÷ÒªÌåÏÖÔÚÈý¸ö·½Ã棺
•ÒÔʱ¼ä»»¿Õ¼ä¡£ÒÔºã¾ÃDZÔڵĹ¥»÷Àú³ÌΪ¼ÛÇ®£¬ÒþÄä¹¥»÷ÐÐΪµÄÒì³££¬Í¬Ê±Ò»Ö±²Á³ý¹¥»÷ºÛ¼££¬Ê¹µÃ¹¥»÷Ч¹ûÏÔÖøÌáÉý¡£Ò»Ð©APT¹¥»÷DZÔÚÆÚ³¤´ï3¸öÔÂÖ®¾Ã£¬ÔÚ´Ëʱ´ú£¬¹¥»÷ÕßÓÐ×ã¹»µÄʱ¼äÇÔÈ¡Ö÷Òª¼ÛÖµÇ鱨¡£
•¹¥»÷¼Æ»®È«Ð͍֯£¬¾ø²»ÀàËÆ¡£´Ó¶à¸öAPT°¸ÀýÖлñÖª£¬APT¹¥»÷ºÍͨË×¹¥»÷ÌåÏÖåÄÒ죬×ÝÈ»¸÷¸öAPT¹¥»÷Ö®¼äÑ¡ÔñµÄ¹¥»÷ÊÖÒÕÊֶζ¼¾ßÓÐÆæÒìÐÔ£¬¼´±ã¹¥»÷µÄÕûÌå½×¶Î»ò˼Ð÷Éϱ£´æÏàËÆÐÔ£¬µ«ÔÚÏêϸµÄ¹¥»÷ÐÐΪ»òÊý¾ÝÖвî±ðÖØ´ó¡£
•ÏÈÈëΪÖ÷£¬ÕÆÎÕ¹¥»÷Ö÷µ¼È¨¡£ÕÆÎÕ¹¥·À²©ÞÄÏÈ»ú£¬Í¨¹ýºã¾ÃµÄǰÆÚ×¼±¸£¬Ê¹ÓöàÖÖÊÖ¶ÎÍøÂçÐÅÏ¢£¬À¿ª¹¥»÷ºÍ·ÀÓùµÄÐÅÏ¢²î³Ø³ÆÐÔ£¬»ñµÃÖ÷µ¼È¨¡£¹¥»÷ÕßÍùÍùÓµÓнÏÇ¿µÄºÚ¿ÍÄÜÁ¦ºÍÍøÂç¹¥»÷ÊÖÒÕ£¬ÕÆÎÕןßÃ÷µÄÎó²îÍÚ¾òºÍʹÓÃÊÖÒÕ£¬Ïàʶ¹¥·ÀÐÄÀí£¬ÔËÓÃÉç»á¹¤³Ìѧ»ñµÃÓÐÓÃÐÅÏ¢¡£
APT¹¥»÷Ä¿µÄºÜÊÇÃ÷È·——ÇÔÈ¡ÌØ¶¨Ä¿µÄ½¹µãÉñÃØ×ÊÁÏ¡£¹¥»÷Õßͨ³£»á×ÛºÏʹÓô¹ÂÚÓʼþ£¨±»90£¥µÄ»îÔ¾APT×éÔÚ³õʼ»á¼û½×¶ÎʹÓã©¡¢Ë®¿ÓÕ¾µã¡¢Éç»á¹¤³Ìѧ£¬Ê¹ÓÃÎĵµÐÍÎó²îÖÆ×÷ÓÕ¶üÎĵµ£¬Òþ²ØËíµÀµÈ¶àÖÖÊÖÒÕÊÖ¶ÎÈÆ¹ýÄ¿µÄÍøÂçµÄ²ã²ã·ÀµØ£¬´ÓÍâΧµ½½¹µãÇøÓòÖð²½¹¥¿ËÄ¿µÄ¡£ÔÚ¹¥»÷¹¤¾ßºÍ¹¥»÷ÊÖÒÕÉÏ×ÅÖØÊÊÓÃÐÔ£¬ÓеÄʹÓÃÕýµ±¹¤¾ß£¨Ô¼ÄªÒ»°ëµÄAPT×é֯ʹÓÃÕýµ±µÄÖÎÀí¹¤¾ßºÍÉÌÒµÉøÍ¸²âÊÔÈí¼þ£©Ìӱܼì²â£¬Ò²ÓеÄ×ÔÑз¢³ÌÐòÇÒʵÏÖ¹¥»÷¹¤¾ßµÄÓïÑÔ¶àÑù£¬³ÌÐòʵÏÖ²»¿¼¾¿¸´ÓÃÐÔ¡£
Ëæ×ÅÇå¾²¹«Ë¾¶ÔAPT¹¥»÷µÄ×ܽáºÍÉîÈëÆÊÎö£¬APT¼ì²âÏµÍ³Ò²ËæÖ®½øÈëÊг¡¡£Ô¤¼ÆAPT±£»¤½â¾ö¼Æ»®µÄÈ«ÇòÊг¡ÊÕÈ뽫´Ó2019ÄêµÄÁè¼Ý43ÒÚÃÀÔªÔöÌíµ½2023ÄêµÄÁè¼Ý94ÒÚÃÀÔª¡£ÏÖÓÐAPT¼ì²âϵͳ½¨É軹´¦ÓÚ³õ¼¶½×¶Î¡£APT·À»¤½â¾ö¼Æ»®ÊÇÒ»Ì×¼¯³ÉµÄ½â¾ö¼Æ»®£¬ÓÃÓÚ¼ì²â¡¢Ô¤·À¡¢¶Ô¿¹³¤ÆÚÐÔ¶ñÒâ¹¥»÷¡£Ëü¿ÉÄܰüÀ¨µ«²»ÏÞÓÚ£ºÉ³Ïä¡¢EDR¡¢CASB£¨CloudAccessSecurityBroker£©¡¢ÐÅÓþÍøÂ磬ÍþвÇ鱨ÖÎÀíºÍ±¨¸æ¡¢È¡Ö¤ÆÊÎöµÈ¡£Òò´Ë£¬¹ØÓÚÇå¾²²úÆ·¹©Ó¦ÉÌÀ´Ëµ£¬ÖÁ¹ØÖ÷ÒªµÄÊÇÌṩÄܹ»ÖÇÄܵØÊ¶±ðºÍ¹ØÁª¿ç¶à¸öȪԴºÍÇþµÀµÄDZÔÚ¹¥»÷ÐÅÏ¢µÄ½â¾ö¼Æ»®¡£
Ó¦¼±ÏìӦϵͳºÍÍþвÇ鱨µÄ·ºÆð
ÍþвÇ鱨µÄ½µÉúÔ´ÓÚ¹¥·ÀµÄ²î³ØµÈ¡£Ëæ×źڿ͹¥»÷µÄ¹æÄ£»¯¡¢×Ô¶¯»¯¡¢¶àÑù»¯¡¢ÎÞа»¯£¬¹Å°åµÄ»ùÓÚÊðÃûºÍ¹æÔòµÄ¹¥»÷¼ì²âºÍ·ÀÓùϵͳÏÔµÃ×óÖ§ÓÒç©¡£ÓÉÓÚÎÞ·¨Ìáǰ»ñÈ¡ÊðÃûºÍ¹æÔòÐÅÏ¢£¬¹Å°åµÄ»ùÓÚ“ÒÑÖª”¹æÔòµÄ¼ì²âÔÚÓöµ½0Day¡¢APTµÈ“δ֪”Íþвʱ£¬ÍêÈ«ÎÞ·¨¸ÐÖªºÍ·ÀÓù¡£
2013Ä꣬GartnerÐû²¼¡¶Defifinition:ThreatIntelligence¡·£¬ÆäÖиø³öÁËÍþвÇ鱨µÄ½ç˵£ºÍþвÇ鱨ÊǹØÓÚ×ʲúËùÃæÁÙµÄÏÖÓлòDZÔÚÍþвµÄÑ֤֪ʶ£¬°üÀ¨Çé¾³£¨ÉÏÏÂÎÄ£©¡¢»úÖÆ¡¢Ö¸±ê¡¢ÍÆÂÛÓë¿ÉÐÐÐÔ½¨Ò飬ÕâЩ֪ʶ¿ÉΪÍþвÏìÓ¦Ìṩ¾öÒéÒÀ¾Ý¡£
Ëæºó£¬2015Ä꣬SANSÌá³ö“ÍøÂçÇå¾²µÄ»¬¶¯±ê³ßÄ£×Ó”£¬ÎªÆóÒµÇå¾²½¨ÉèÌṩÁ˺ê¹ÛÉϵÄÖ¸µ¼ºÍ½¨Òé¡£»¬¶¯±ê³ßÄ£×Ó´Ó×óµ½ÓÒ£¬ÊÇÆóÒµÖð²½Ó¦¶Ô¸ü¸ß¼¶ÍøÂçÍþвµÄÀú³Ì£¬ÆäÖÐÇ鱨ÊǼ̼ܹ¹Çå¾²¡¢±»¶¯·ÀÓù¡¢×Ô¶¯·ÀÓùÖ®ºóµÄ½ø½×½×¶Î¡£

ͼƬȪԴÓÚSANS
ÍþвÇ鱨µÄ·ºÆðÇý¶¯ÁËÓ¦¼±ÏìӦϵͳÉõÖÁÊÇÍøÂçÇå¾²·ÀÓùϵͳµÄתÐÍ£¬¼´´Ó¾²Ì¬µÄ¡¢»ùÓÚ¹æÔò±»¶¯·ÀÓù£¬×ª±äΪ¶¯Ì¬µÄ¡¢×Ô˳ӦµÄ×Ô¶¯·À»¤ÏµÍ³£¬ÎªÏÂÒ»´úÇå¾²µÓÚ¨ÁË»ù´¡¡£Ëï×ÓÔ»“Öª¼ºÖª±Ë£¬°ÙÕ½²»´ù”£¬ÍþвÇ鱨ÕýÊÇÍøÂç¹¥·ÀÕ½³¡Éϓ֪¼ºÖª±Ë”µÄÒªº¦¡£ÍþвÇ鱨×î´óµÄ¼ÛÖµÔÚÓÚ×ÊÖú·ÀÊØ·½ÏàʶËûÃǵĵÐÊÖ£¨¹¥»÷Õߣ©£¬°üÀ¨¹¥»÷ÕßµÄÅä¾°¡¢Í·ÄÔ·½·¨¡¢ÄÜÁ¦¡¢ÄîÍ·¡¢Ê¹ÓõĹ¥»÷¹¤¾ß¡¢¹¥»÷ÊÖ·¨¡¢¹¥»÷ģʽµÈ¡£¶Ô¹¥»÷ÕßÏàʶԽ¶à£¬¾ÍÄÜÔ½ºÃµØÊ¶±ðÍþвÒÔ±ã¿ìËÙµØ×ö³öÏìÓ¦¡£×¼È·ÖÜÈ«µÄÍþвÇ鱨Äܹ»¼«´óµØÀ©Õ¹Íþв·ÀÓùµÄʱ¿Õ½çÏߣ¬ÊÇʵÑé×Ô¶¯·ÀÓùÕ½ÂÔµÄÒªº¦¡£»ùÓÚ¶Ô“µÐÊÖ”µÄÏàʶ£¬ÍþвÇ鱨¹¹½¨ÁËÍþвԤ¾¯¡¢¹¥»÷¼ì²â¡¢ÏìÓ¦´¦Öóͷ£¡¢ËÝԴȡ֤¡¢Ä¿µÄÑÐÅС¢Çé±¨ÍØÕ¹µÄ·ÀÓù·½“Éú»·”¡£ÔÚÓ¦¼±ÏìÓ¦ÖУ¬ÍþвÇ鱨ͨ¹ýΪÇå¾²·ÀÓù×°±¸¾ÙÐи³ÄÜ£¬¿ÉÒÔ´ó´óËõ¶ÌÇå¾²×°±¸¶Ô×îÐÂÍþвµÄÏìÓ¦ºÍ´¦Öóͷ£Ê±¼ä£¬µÖ´ï“µ¥µã¸ÐÖª£¬È«Íø·ÀÓù”µÄЧ¹û¡£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓÚ2015Äê×齨ÁËÍþвÇ鱨ÖÐÐÄ£¬²¢ÍƳöÁ˾ÅÓÎÀϸçÍþвÇ鱨ÆÊÎöÓë¹²ÏíÆ½Ì¨£¨NTI£©¡£ÒÀÍоÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÇå¾²ÁìÓòµÄºã¾Ã»ýÀÛ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄÇ鱨ȪԴ²»µ«°üÀ¨Ô´´Îó²î¿â¡¢Ñù±¾¿â¡¢Çå¾²ÆÊÎöÊý¾Ý¡¢²úÆ·ÔËÓª·´ÏìÊý¾ÝµÈ¾ÅÓÎÀÏ¸ç¿Æ¼¼ÌØÓеÄÊý¾ÝÔ´£¬Í¬Ê±Ò²º¸ÇÁËÖÜÈ«µÄ»¥ÁªÍøÇ鱨ÊÕÂÞºÍÆÕ±éµÄµÚÈý·½Ç鱨ÏàÖú»ú¹¹¡£»ùÓÚ¾ÅÓÎÀϸç´óÊý¾ÝÆÊÎöƽ̨£¬ÍŽáÇå¾²Ç鱨ר¼Ò¶ÔÇ鱨Êý¾Ý¾ÙÐÐÉî¶ÈÍÚ¾òÆÊÎö£¬»ñµÃ¸ßÖÊÁ¿µÄ¶àά¶ÈÍþвÇ鱨£¬ÁýÕÖÍøÂç×ʲú»ù´¡ÐÅÏ¢¡¢Ö¸ÎÆ¡¢Îó²î¡¢TTP¡¢¸ß¼¶ÍþвÆÊÎöЧ¹ûµÈ²î±ð²ãÃæ£»Í¨¹ýNTIportal½çÃæ¡¢API½Ó¿Ú¡¢¶©ÔÄÍÆË͵Ȳî±ðÊä³ö·½·¨½«ÍþвÇ鱨ÓëÇå¾²×°±¸¡¢¿Í»§ºÍÇå¾²³§É̾ÙÐй²Ïí£¬ÓÐÓñ£»¤Á˿ͻ§µÄÇå¾²¡£

¾ÅÓÎÀϸçÔÆ







