ÍþвÇ鱨רÀ¸|2020 ÉϰëÄêÍøÂçÇå¾²Ì¬ÊÆÆÊÎö
2020-07-20
¿ËÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©ÖذõÐû²¼¡¶2020 ÉϰëÄêÍøÂçÇå¾²Ì¬ÊÆÆÊÎö¡·±¨¸æ¡£±¨¸æ¶Ô2020ÄêÉϰëÄêµÄÖÖÖÖÍøÂçÇå¾²Ì¬ÊÆ¾ÙÐÐ×·×ÙºÍÑо¿£¬Í¨¹ý¾Û½¹Îó²î¡¢¶ñÒâÈí¼þ¡¢ÎïÁªÍøÇå¾²¡¢DDoS¹¥»÷ºÍ½©Ê¬ÍøÂç·½ÃæµÄÇå¾²Ì¬ÊÆ£¬ÖÜÈ«ÊÓ²ìÍøÂç¿Õ¼äÇå¾²Ê±ÊÆ£¬×ÊÖúÓû§¸üºÃµØÏàʶºÍÓ¦¶ÔÖÖÖÖÍøÂçÍþв¡£
Ò»¡¢ Îó²îÌ¬ÊÆ×ÛÊö
2020ÄêÉϰëÄê¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼1419¸öÎó²î£¬ÆäÖиßΣÎó²î714¸ö£¬Î¢Èí¸ßΣÎó²î184¸ö¡£¸ßΣÎó²îÖ÷ÒªÂþÑÜÔÚMicrosoft¡¢Orcale¡¢Adobe¡¢Google¡¢Cisco¡¢IBM¡¢Moxa¡¢ApacheµÈ³§É̵ÄÖ÷Òª²úÆ·ÖС£

ͼ 1-1 2020ÉϰëÄêÎó²îÊýĿͳ¼Æ
¶þ¡¢ ¶ñÒâÈí¼þÌ¬ÊÆ×ÛÊö
2020ÄêÉϰëÄêÊý¾ÝÓë2019Äê¶ÈÊý¾ÝÖжñÒâÈí¼þÖÖÖÖÐÍÂþÑÜÈçÏÂͼËùʾ¡£ÉϰëÄê¸÷¶ñÒâÈí¼þÀàÐÍÕ¼±ÈÏà±ÈÈ¥ÄêÕûÄêÇéÐÎÓÐËù²¨¶¯£¬ºóÃÅÈ¡´úÍÚ¿ó¾ÓÓÚÊ×λ£¬Õ¼±È48.05%£»ÍÚ¿óÏà½ÏÓÚÈ¥ÄêÕûÄêµÄÊý¾Ý±ÈÀýÓдó·ùϽµ£¬È䳿»îԾˮƽÓëÈ¥ÄêÕûÄê³Öƽ£¬ºÍºóÃÅÒ»ÆðÕ¼ÓÐÕûÌå¶ñÒâÈí¼þÔ˶¯µÄ87%¡£

ͼ 1-2 ¶ñÒâÈí¼þÀàÐÍ·ÖÀà
Èý¡¢ ÎïÁªÍøÇå¾²Ì¬ÊÆ×ÛÊö
2020ÄêÉϰëÄêÓÐ9¸öÖµµÃÖØµã¹Ø×¢µÄÎïÁªÍøÇå¾²ÊÂÎñ£º
£¨1£© Ripple20 0dayÎó²îÆØ¹â£¬É¨µ´È«Çò¸÷ÐÐÒµÊýÒŲ́ÁªÍø×°±¸
£¨2£© NetgearÊýÊ®¿î·ÓÉÆ÷²úÆ·ÆØ³ö¸ßΣÁãÈÕÎó²î
£¨3£© Ò»×鹤¿ØÃÛ¹ÞÕÐÀ´ËĸöÁãÈÕ¹¥»÷
£¨4£© ÑÏÖØµÄRCEÎó²îÓ°ÏìÁËÊý°ÙÍò»ùÓÚOpenWrtµÄÍøÂç×°±¸
£¨5£© ºÚ¿ÍʹÓÃDrayTek×°±¸ÖеÄ0dayÎó²î¶ÔÆóÒµÍøÂç·¢¶¯¹¥»÷
£¨6£© ºÚ¿ÍÐ®ÖÆÁËÖÇÄÜÃŽûϵͳ£¬²¢¿ÉÒÔ¶ÔÍøÂç¿É´ïµÄ×°±¸ÌᳫDDoS¹¥»÷
£¨7£© Êý°ÙÍòʹÓÃLoRaWANµÄ×°±¸¿ÉÔâºÚ¿Í¹¥»÷£¬LoRaWANÍøÂçÖÐµÄ½Úµã¡¢Íø¹Ø¡¢·þÎñÆ÷¾ù±£´æ½ÏÁ¿ÑÏÖØµÄÎó²î£¬ÆäÇå¾²·À»¤ÄÜÁ¦ÓдýÌá¸ß
£¨8£© ºÚ¿Íй¶Áè¼Ý50Íǫ̀װ±¸µÄTelnetƾ֤
£¨9£© Ñо¿Ö°Ô±·¢Ã÷´øÓÐÍÚ¿ó¹¦Ð§Ð½©Ê¬ÍøÂçLiquorBot
2020ÄêÉϰëÄ꣬Îó²îʹÓÃÆ½Ì¨Exploit-DB¹²¼Æ·ºÆð84¸öÎïÁªÍøÏà¹ØÎó²îʹÓã¬ÒÔNetgearΪÊ×µÄÍøÂç×°±¸³§ÉÌΪÖ÷£¬ÎÒÃÇÒÔΪ·ºÆðÕâÖÖÕ÷ÏóµÄÔµ¹ÊÔÓÉ£¬ÊÇÍøÂç×°±¸µÄÍ·²¿³§ÉÌͨ³£³öÊÛµÄ×°±¸ÊýÄ¿¶à£¬»ùÊý´ó£¬Ñо¿Ö°Ô±¸ü¹Ø×¢ÆäÏà¹Ø×°±¸¡£Îó²îʹÓõÄÀàÐÍÒÔRCEºÍDoSΪÖ÷£¬ÆäÖÐRCEÀàÎó²îÊýÄ¿×î¶à£¬Õ¼×ÜÁ¿µÄ°Ù·ÖÖ®ÈýÊ®ÎåÒÔÉÏ¡£
2020ÄêÉϰëÄ꣬¾ÅÓÎÀϸçÍþв²¶»ñϵͳ²¶»ñµ½À´×Ô266632¸öIPµÄ26998718´Î»á¼ûÇëÇóÈÕÖ¾£¬ÆäÖÐ12.98%µÄ»á¼ûÇëÇóÊǶÔÎïÁªÍøÎó²î¾ÙÐÐʹÓõĶñÒâ¹¥»÷ÐÐΪ¡£¹¥»÷ÕßʹÓõÄÎó²î´ó¶àÔÚExploit-DBÓйûÕæµÄÎó²îʹÓþ籾¡£Êܵ½¹¥»÷ÕßʹÓÃ×î¶àµÄÎó²î°üÀ¨D-Link×°±¸Îó²îCVE-2015-2051ÓëMVPower DVRÎó²î£¬EDB±àºÅ41471¡£¶ÔÔ´IP¾ÙÐÐÆÊÎö£¬ÆäÖÐ159679¸öIPÌᳫ¹ýÎó²îʹÓõȶñÒâÐÐΪ£¬Õ¼×ÜÁ¿µÄ59.89%¡£´Ó¹ØÁªµ½¶ñÒâÐÐΪµÄIPÂþÑÜÔÚÁË201¸ö¹ú¼ÒºÍµØÇø£¬´Ó¹ú¼ÒÂþÑÜÇéÐÎÀ´¿´£¬Öйú×î¶à£¬À´×ÔÖйúµÄ¶ñÒâIPÕ¼ËùÓжñÒâIPµÄ23.6%¡£
ËÄ¡¢ DDOS¹¥»÷Ì¬ÊÆ×ÛÊö
2020ÄêÉϰëÄ꣬ÎÒÃÇ¼à¿Øµ½ DDoS ¹¥»÷´ÎÊýΪ21Íò´Î£¬¹¥»÷×ÜÁ÷Á¿11ÍòTb¡£ÆäÖУ¬¹¥»÷ʱ³¤ÔÚ5·ÖÖÓÒÔÄÚµÄDDoS¹¥»÷Õ¼ÁËËùÓй¥»÷µÄ67%¡£´ÓÒ»Ìì24Сʱ¹¥»÷Õ¼±ÈÀ´¿´£¬Ê²Ã´Ê±¼ä¶¼ÓпÉÄܱ»¹¥»÷¡£´ÓÿÖÜÖÐDDoS ¹¥»÷Ô˶¯µÄÂþÑÜÀ´¿´£¬ÌìÌì¶¼ÓпÉÄܱ»¹¥»÷£¬ÖÜÈý×î³£±»¹¥»÷¡£SYN FloodÊÇÖ÷ÒªµÄ¹¥»÷ÀàÐÍ£¬Õ¼×ܹ¥»÷´ÎÊýµÄ43.17%¡£´ÓÁ÷Á¿Õ¼±ÈÀ´¿´£¬UDP FloodÌᳫµÄ¹¥»÷Á÷Á¿Õ¼±È×î¸ß£¬Õ¼±È75.5%¡£
2020ÉϰëÄêÒ»Á¬¹Ø×¢ÍÅ»ï15¸ö£¬ÆäÖÐIPGang01ÊÇÔÚÎÒÃǼà²â¹æÄ£ÄÚ¹æÄ£×î´óµÄÍŻ°üÀ¨¹¥»÷Ô´21.7Íò¸ö£¬Ô¶ȻîÔ¾×ÊÔ´13Íò£¬ÉϰëÄê»îÔ¾ÌìÊý164Ì죬ʱ´ú¹²¶Ô1366¸öÄ¿µÄIPÌᳫ¹ý5.8ÍòÆð¹¥»÷ÊÂÎñ£¬ÀÛ¼Æ×ܹ¥»÷Á÷Á¿1.3ÍòTbits¡£
Îå¡¢ ½©Ê¬ÍøÂç¼°ÃÛ¹ÞÌ¬ÊÆ×ÛÊö
ÔÚ2020ÄêÉϰëÄêµÄDDoS½©Ê¬ÍøÂçÔ˶¯ÖУ¬Ö÷Òª¹¥»÷À´×ÔMiraiºÍGafgytµÈ¼Ò×å¡£
ÉϰëÄêµÄDDoS¹¥»÷ÊÖ¶ÎÖ÷ҪΪUDP flood¡¢CCºÍTCP flood¡£
ÉϰëÄê½©Ê¬ÍøÂç¿ØÖÆ¶ËÍйܵÄÔÆ·þÎñÉÌÒÔHostwinds¡¢Digital OceanºÍOVHΪÖ÷£¬Ô¤¼ÆÔÚϰëÄê²»»á¸Ä±ä¡£
ÉϰëÄê¼ì²âµ½µÄIoTľÂíÈö²¥Ê¹ÓõÄÖÖÖÖÎó²îÖÖÀàΪ128ÖÖ£¬ÆäÖÐCVE-2017-17215£¨»ªÎªHG532·ÓÉÆ÷£©¡¢CVE-2014-8361£¨Realtek rtl81xx SDKÔ¶³Ì´úÂëÖ´ÐÐÎó²î£©ºÍThinkPHPÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îλ¾ÓǰÏß¡£
ͨ¹ý¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄÍþв²¶»ñϵͳ£¬ÎÒÃǺã¾Ã¼à²âÁËÒ»¸öÃæÏòÃÅÂÞ±ÒÍÚ¿óµÄ½©Ê¬ÍøÂç¡£¸Ã½©Ê¬ÍøÂçͨ¹ýÈõ¿ÚÁî±¬ÆÆÈëÇÖÖ÷»ú£¬ÒÔÖ²È뽩ʬ³ÌÐòµÄ·½·¨»ñÈ¡¿ØÖÆÈ¨ÏÞ£¬Í¬Ê±Ê¹ÓÃÏÂÔØÆ÷ÏÂÔØ²¢Ö´ÐÐÃÅÂÞ±ÒÍڿ󲡶¾¾ç±¾£¬ÊµÏÖ¶ñÒâÍڿ󡣸ÃÍÚ¿ó½©Ê¬ÍøÂçÔÚ2020ÄêÉϰëÄêµÄÕûÌå»îÔ¾ÇéÐγÊÔöÌíÇ÷ÊÆ£¬»îÔ¾È⼦×ÜÁ¿µÖ´ï20830̨£¬ÆäÖÐÔÚÖйúµÄÈ⼦×î¶à£¬µÖ´ï8304̨£¬Õ¼±È40%¡£¿ª·Å22¶Ë¿ÚµÄÈ⼦ÊýÓÐ13664̨£¬Õ¼±È¿¿½üËùÓÐÈ⼦µÄ 66%¡£ÔÚÒÑÖªµÄ×ʲúÇ鱨Êý¾ÝÖУ¬ÕâЩÈ⼦µÄÖ÷Ҫװ±¸ÀàÐÍÊÇ·ÓÉÆ÷ºÍÉãÏñÍ·¡£

¾ÅÓÎÀϸçÔÆ







