·À»¤¼Æ»®£ºHacking TeamÊý¾Ýй¶ÊÂÎñ
2015-07-10
Content
-
¹¥»÷£ºËÔÚ¹¥»÷£¿
- Hacking Team¼°Gamma Group
- й¶Êý¾Ý
- Ó°Ïìˮƽ
-
·À»¤Ë¼Ð÷
- Detect
- Deny
-
½â¾ö¼Æ»®
- Ó¦¶Ô0Day
- ¼Æ»®ÓÅÊÆ
-
ÍþвÇ鱨
-
¹ØÓÚAG¹«Ë¾¿Æ¼¼
7ÔÂ5ÈÕÍí£¬Ò»¼ÒÒâ´óÀûÔ¶³Ì¿ØÖÆÈí¼þ³§ÉÌHacking TeamµÄÄÚ²¿Êý¾Ý±»Ð¹Â¶³öÀ´£¬ÆäÓ°ÏìÁ¦²»ÑÇÓÚ˹ÂåµÇÊÂÎñ¼°Î¬»ù½âÃÜÊÂÎñ£¬AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄËæ¼´Æô¶¯Ó¦¼±ÏìÓ¦ÊÂÇé¡£
-
- 6ÈÕ£¬ÍþвÏìÓ¦ÖÐÐÄÆô¶¯Ó¦¼±ÆÊÎöÊÂÇ飬AG¹«Ë¾TAC²úÆ·×èµ²µ½Flash 0DayÎó²î¹¥»÷£»
-
- 6ÈÕÒ¹£¬Ïà¹ØÐÅÏ¢¼°ÆðÔ´½¨Ò飬µÚһʱ¼ä¼û¸æ¿Í»§¹Ø×¢£»
-
- 7ÈÕ£¬ÔÚ¹ÙÍøÍøÕ¾Ðû²¼½ôÆÈͨ¸æ£¬½¨Òé¿í´óÓû§¹Ø×¢ÊÂÎñÏ£Íû¡£ÆÊÎöÊÂÇéÏ£ÍûÏ£ÍûÖУ»
-
- 9ÈÕ£¬Ðû²¼Hacking TeamÔ¶³Ì¿ØÖÆÏµÍ³¼òÒªÆÊÎö±¨¸æ£¬Í¬Ê±Ðû²¼·À»¤¼Æ»®£»
±¾±¨¸æÒÔºó´ÎÊÂÎñÖлñÈ¡µÄÑù±¾ÈëÊÖ£¬ÆÊÎöÆä°üÀ¨µÄÊý¾Ý¼°Ó°Ï죬ΪÓû§Ë¼Ë÷ÏÂÒ»²½µÄÓ¦¶Ô¼Æ»®£¬¸ø³öÁË·À»¤Ë¼Ð÷¼°½â¾ö¼Æ»®¡£
¹¥»÷£ºËÔÚ¹¥»÷£¿
7ÔÂ5ÈÕÍí£¬Ò»¼ÒÒâ´óÀûÈí¼þ³§É̱»¹¥»÷£¬ÆäÕÆÎÕµÄ400GBÊý¾Ýй¶³öÀ´£¬ÓÉ´Ë¿ÉÄÜÒý·¢µÄ¶¯µ´£¬ÒýÆðÁËÒµ½çһƬ»©È»¡£×èÖ¹·¢¸åʱֹ£¬Óжà¸ö×éÖ¯Éù³Æ¶Ô´ËÐÐΪÈÏÕæ£¬°üÀ¨Gamma Group Hacker¡£ËäÈ»ÏÖÔÚûÓÐÊÂʵÅú×¢¸ÃÉù³ÆÈ·Êµ¿ÉÐÅ£¬µ«ÓÉ´ËÈÃÐþÉ«¹¤ÒµÁ´ÌõÖеÄÒ»ÖÖ¡±Ð¡±ÐÎ̬̻¶³öÀ´£¬¼´´Ó¹¥»÷×îÖÕÓû§ÑݱäΪ¹¥»÷ÖÐÐÄÁ´ÌõÒÔÖ¹¥»÷Õß×éÖ¯Ö®¼äµÄÏ໥ØËɱ£¬ÕâÖÖÐÎ̬ÒѾ´ÓºÚ²úÉÏÉýµ½¹©Ó¦ÉÌ¡¢Õþ¸®»ú¹¹Ö®¼äµÄÎÊÌ⣬Õâ²»µÃ²»Ëµ£¬¶ÔÉæ¼°ÖÐÐÄÁ´ÌõµÄ×éÖ¯£¬ÇÃÏìÁ˾¯ÖÓ¡£
Hacking Team¼°Gamma Group
Hacking TeamÔÚÒâ´óÀûÃ×À¼×¢²áÁËÒ»¼ÒÈí¼þ¹«Ë¾£¬Ö÷ÒªÏò¸÷¹úÕþ¸®¼°Ö´·¨»ú¹¹ÏúÊÛÈëÇÖ¼°¼àÊÓ¹¦Ð§µÄÈí¼þ¡£ÆäÔ¶³Ì¿ØÖÆÏµÍ³¿ÉÒÔ¼à²â»¥ÁªÍøÓû§µÄͨѶ¡¢½âÃÜÓû§µÄ¼ÓÃÜÎļþ¼°µç×ÓÓʼþ£¬¼Í¼Skype¼°ÆäËûVoIPͨѶ£¬Ò²¿ÉÒÔÔ¶³Ì¼¤»îÓû§µÄÂó¿Ë·ç¼°ÉãÏñÍ·¡£Æä×ܲ¿ÔÚÒâ´óÀû£¬¹ÍÔ±40¶àÈË£¬²¢ÔÚ°²Äɲ¨Àû˹ºÍÐÂ¼ÓÆÂÓµÓзÖÖ§»ú¹¹£¬Æä²úÆ·ÔÚ¼¸Ê®¸ö¹ú¼ÒʹÓá£
ÎÞ¶ÀÍÌż£¬Õâ´ÎÉù³Æ¶Ô´Ë´ÎÊÂÎñÈÏÕæµÄ×éÖ¯£¬Gamma Group InternationalÒ²Ò»¾ÔÚ2014ÄêµÄ8Ô±»ÈËÈëÇÖ¹ý£¬ÔÚÄǴεÄÊÂÎñÖУ¬¸Ã×éÖ¯±»Ð¹Â¶ÁË40GBµÄÄÚ²¿ÎĵµºÍ¶ñÒâ³ÌÐò´úÂë¡£Õâ¸ö×éÖ¯ÎÞÂÛ´ÓÅä¾°ÕÕ¾ÉÓªÒµ¶¼ÓëHacking TeamÀàËÆ£¬¿ÉÊÇÒ»¼ÒÓ¢¹úµÄ¹«Ë¾¡£µØÏ¹¤ÒµÁ´¸÷·½µÄÏ໥ØËɱÓɴ˿ɼûÒ»°ß£¬ÕâÀï¼òÆÓÓÃÒ»ÕÅͼÀ´¼òÆÓչʾһÏÂÆäÖеÄÒ»¸ö²¿·Ö¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Õâ´Îͨ¹ý¹¥»÷¹©Ó¦É̵ÈÖÐÐÄÁ´Ìõ»ñµÃ¹¥»÷Êý¾ÝµÄ¶¯Ì¬¡£
й¶Êý¾Ý
´Ë´ÎÊÂÎñÖÐй¶µÄÊý¾Ý¶à´ï400GB£¬Êý¾Ý°üÖÐÖ÷Òª°üÀ¨¼¸¸ö´óµÄ²¿·Ö£º
- Ô¶³Ì¿ØÖÆÈí¼þÔ´Â룬ҲÊÇÆä½¹µã£¬ÔÝÇÒ³ÆÖ®ÎªHacking Team RCS£¨Remote Control System£©
- ·´²éɱÆÊÎö¹¤¾ß¼°Ïà¹ØÌÖÂÛÎĵµ
- 0Day¡¢Îó²î¼°Ïà¹ØÈëÇÖ¹¤¾ß
- ÈëÇÖÏîÄ¿Ïà¹ØÐÅÏ¢£¬°üÀ¨ÕË»§ÃÜÂë¡¢Êý¾Ý¼°ÒôÏñ×ÊÁÏ
- °ì¹«ë¹µµ¡¢Óʼþ¼°Í¼Æ¬
- ÆäËû
Ó°Ïìˮƽ
ÔÚÕâЩÊý¾ÝÖУ¬ÂÌÉ«±ê×¢µÄ3Àà½ÏÁ¿ÒýÈ˹Ø×¢£¬Õâ3ÀàÊý¾Ý½«¶Ô¸÷¸ö²î±ðµÄÁìÓòÔì³ÉÓ°Ïì
-
¸üƵÈÔ£º0Day¡¢Îó²î¼°Ïà¹ØÈëÇÖ¹¤¾ß£¬´ÓÏÖÔÚ»ñÈ¡µÄÐÅÏ¢À´¿´
- Flash Ïà¹ØµÄÓ¦Óü°Èí¼þʹÓÃÁ¿ºÜÊÇÖØ´ó£¬Windowsƽ̨ÉÏÏÕЩÊÇËùÓеÄÓû§¶¼»áÓõ½£»
- ÕâЩÎó²îµÄÁ÷ÈëÐþÉ«¹¤ÒµÁ´£¬»áÈù¥»÷Ô½·¢¿ìËÙºÍÖØ´ó»¯
-
Ãż÷µÍ£ºHacking Team RCS£¬ÊǸÃ×éÖ¯Ö÷ÒªÊä³öµÄÈí¼þ£¬´ÓÏÖÔÚ»ñÈ¡µÄÐÅÏ¢À´¿´
- ¿ÉÒÔ»ñȡĿµÄÓû§µÄµç»°¡¢µçÄÔµÄËùÓÐÐÅÏ¢¼°Ó°Òô×ÊÁÏ£»
- Éæ¼°µÄ×ÀÃæOS´ÓWindowsµ½MacOs X£¬ÊÖ»úOS»ù±¾ÁýÕÖÁËÊг¡ÉÏÊ¢ÐеÄϵͳ£»
- Êܸù¤¾ß¼°ÆäÒѾѬȾµÄ¿Í»§¶ËÊýÄ¿µÄÓ°Ï죬»áÈù¥»÷Ãż÷½µµÍ
- Ó°Ïì´ó£ºÈëÇÖÏîÄ¿Ïà¹ØÐÅÏ¢£¬ÕâÄÚÀï°üÀ¨ÁËÖÖÖÖÈëÇÖÀú³Ì×ÊÁÏ£¬ÉõÖÁ°üÀ¨ÁËÒѾÀֳɻñÈ¡µÄÕË»§ÃÜÂë¼°Ïà¹Ø×ÊÁÏ£¬Ò»µ©±»¶ñÒâ¹¥»÷Õß»ñÈ¡²¢Ê¹Ó㬽«»áÔÚÐþÉ«¹¤ÒµÁ´ÖнøÒ»²½·¢½Í¡£
ͼע£ºHacking TeamÔ¶³Ì¿ØÖÆÏµÍ³
·À»¤Ë¼Ð÷
AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ³¤Äê¶ÔºÚ¿Í×éÖ¯ÊÂÎñµÄ×·×Ù¼°ÆÊÎöÖУ¬»ñµÃÁ˸»ºñµÄÂÄÀú»ýÀÛ£¬½è¼ø¼°½¨ÉèÁËһЩģ×ÓÈ¥Ã÷È·ËüÃÇ£¬ÊÔͼ´ÓÖÐÕÒµ½¼ÍÂÉ£¬ÒÔ±ãΪӦ¶ÔδÀ´µÄδ֪ÍþвÌṩÂÄÀú½è¼ø¡£Õë¶Ô´Ë´ÎÊÂÎñ£¬ÕâÀïʹÓÃIntrusion Kill ChainÄ£×Ó¸ú¸÷È˾ÙÐÐ̽ÌÖ£¬ËäÈ»·×Æç¶¨ÊʺÏËùÓÐÓªÒµÇéÐΣ¬µ«Ï£Íû¿ÉÒÔ×ÊÖú¸÷ÈËÕÒµ½Ö¸¶¨×ÔÉí·À»¤¼Æ»®µÄÒ»µãÁé¸Ð¡£
Intrusion Kill ChainÄ£×Ó¾«ËèÔÚÓÚÃ÷È·Ìá³öÍøÂç¹¥·ÀÀú³ÌÖй¥·ÀË«·½»¥ÓÐÓÅÊÆ£¬·ÀÊØ·½ÈôÄÜ×è¶Ï/Í߽⹥»÷·½µÄ½ø¹¥×éÖ¯»·½Ú£¬¼´ÊÇÀֳɵشì°ÜµÐÊֵĹ¥»÷ÍýÏ롣ģ×ÓÊǽ«¹¥»÷ÕߵĹ¥»÷Àú³ÌÆÊÎöΪÈçÏÂÆß¸ö°ì·¨: Reconnaissance£¨²Èµã£©¡¢Weaponization£¨×é×°£©¡¢Delivery£¨Í¶ËÍ£©¡¢Exploitation£¨¹¥»÷£©¡¢Installation£¨Ö²È룩¡¢C2£¨¿ØÖÆ£©¡¢Actions on Objectives£¨Êո£¬ÈçÏÂͼ£º
ͨ¹ýÏÖÔÚ¶ÔHacking Team RCSÈí¼þµÄÆÊÎöÇéÐÎÀ´¿´£¬Ö÷Ҫͨ¹ýÈçÏÂÈýÖÖ·½·¨ÈëÇÖÄ¿µÄ£º
- Ñ¬È¾ÒÆ¶¯½éÖÊ£ºÓëÐí¶àľÂí¡¢²¡¶¾¼°Á÷Ã¥Èí¼þµÄÈö²¥·½·¨Ò»Ñù£¬¸ÃÈí¼þÊ×ÏÈÕվɽÓÄÉÕâÖֵͱ¾Ç®µÄ·½·¨¾ÙÐУ¬Ñ¬È¾Ò»Ð©Äܹ»½Ó´¥Ä¿µÄµÄÒÆ¶¯Ã½Ì壬ºÃ±ÈCD-ROM¡¢USBµÈ£¬¼´¼´ÊÇOS »òÕßBIOSÉèÖÃÁËÃÜÂëÒ²Ò»Ñù¿ÉÒÔѬȾ£¬´Ó¶ø»ñȡһЩÇéÐÎÊý¾Ý£¬ºÃ±ÈµçÄÔÊÇ·ñ¿ÉÒÔÉÏÍøµÈ£¬ÎªºóÐøµÄÐж¯Ìṩ²Î¿¼ÒÀ¾Ý¡£
- ÊðÀí¹¥»÷£º½ÓÄÉÈí¼þ»òÓ²¼þµÄϵͳ£¬Äܹ»ÔÚÍøÂç»á»°Àú³ÌÖÐÐ޸ĺÍ×¢ÈëÊý¾Ý£¬ÔÚijЩÇéÐÎÏ£¬¿ÉÒÔ×¢È뵽ϵͳ²¢ÄÑÒÔ±»¼ì²âµ½¡£Í¬Ê±£¬Ò²Äܹ»Ñ¬È¾Windowsƽ̨ÉϵĿÉÖ´ÐÐÎļþ£¬ÈôÊÇÄ¿µÄµçÄÔ´ÓÍøÕ¾ÉÏÏÂÔØ²¢Ö´ÐÐÕâЩ¿ÉÖ´ÐÐÎļþʱ£¬Agent½«ÔÚºǫ́×Ô¶¯×°Öã¬Óû§²»»áÖªÏþ¡£
- APT£ºÈçÉÏÁ½ÖÖ·½·¨¶¼ÎÞ·¨×àЧµÄʱ¼ä£¬¾Í»á½ÓÄɶàÖÖÐÎʽ×éºÏÈëÇÖ£¬½ÓÄÉÏà¹ØµÄÎó²î¡¢ÈëÇÖ¹¤¾ß¼°¸ü¶àʹÓÃÊֶΡ£Õë¶ÔÕâЩÈëÇÖ·½·¨£¬ÏÂÃæÀ´·Ö½×¶ÎÌÖÂÛ·À»¤Ë¼Ð÷¡£
Detect
ÔÚÕâ¸ö½×¶Î£¬½¨ÒéÄú½«Ä¿½ñITÇéÐÎÖеÄÎó²îɨÃèϵͳÉý¼¶µ½×îа汾ºó£¬¾¡¿ì×îÏȶÔӪҵϵͳ¾ÙÐÐɨÃ裬ÓÈÆäÊÇÊÜ´Ë´ÎFlash 0DayÎó²îÓ°ÏìµÄӪҵϵͳƽ̨¾ÙÐÐÒ»´ÎÍêÕûµÄÎó²îɨÃè¡£
´Ë´ÎÊÂÎñÖУ¬AG¹«Ë¾ÍþвÆÊÎöϵͳ£¨NSFOCUS Threat Analyze Center£¬TAC£©¼´ÌåÏÖ³öÓÅÔ½ÐÔ£¬¼´Í¨¹ý¶À´´µÄ¾²Ì¬¼ì²âºÍ¶¯Ì¬¼ì²âÒýÇæ£¬Äܹ»²»ÒÀÀµÓÚ¹¥»÷ÌØÕ÷ʶ±ð¶ñÒâÈí¼þ¼°ÆäΣº¦Ë®Æ½£¬ÂÊÏÈÕì²âµ½Flash 0DayÎó²î¡£
AG¹«Ë¾TAC¿ÉÓÐÓüì²âͨ¹ýÍøÒ³¡¢µç×ÓÓʼþ»òÆäËûÔÚÏßÎļþ¹²Ïí·½·¨½øÈëÍøÂçµÄÒÑÖªºÍδ֪¶ñÒâÈí¼þ£¬·¢Ã÷ʹÓÃ0dayÎó²îµÄAPT¹¥»÷ÐÐΪ£¬±£»¤¿Í»§ÍøÂçÃâÔâʹÓÃ0dayÎó²îµÈ¹¥»÷Ôì³ÉµÄÖÖÖÖΣº¦£¬ÈçÃô¸ÐÐÅϢй¶¡¢»ù´¡ÉèÊ©ÆÆËðµÈ¡£
AG¹«Ë¾TACÄܹ»ÔÚÈçÏÂÁ½¸ö½×¶Î¶Ô´Ë´ÎÊÂÎñËù´øÀ´µÄ¿ÉÄܹ¥»÷¾ÙÐмì²â
- Delivery½×¶Î£º·¢Ã÷£¨detect£©ÊÔͼ´«Êäµ½ÄÚÍøµÄ¶ñÒâÈí¼þ£¨Îļþ£©£¬°üÀ¨ÒÑÖªºÍδ֪µÄ¸ß¼¶¶ñÒâÈí¼þ£»
- Installation½×¶Î£º·¢Ã÷¸ß¼¶¶ñÒâÈí¼þÀÖ³ÉʹÓúó£¬ÊÔͼ´Ó¿ØÖƶËÏÂÔØ¸ü¶à¶ñÒâ³ÌÐò¡£
Deny
ÈôÊÇÄúÒѾ°²ÅÅÁËAG¹«Ë¾ÍøÂçÈëÇÖ·À»¤ÏµÍ³£¨Network Intrusion Prevention System£¬¼ò³ÆNIPS£©£¬ÔÚÉý¼¶×îеÄÉý¼¶°üºó£¬¼´¿É×è¶ÏFlash 0DayÎó²îËù´øÀ´µÄ¹¥»÷£¬²¢Ò»Á¬»ñµÃÃô¸ÐÊý¾Ý±£»¤¡¢¿Í»§¶Ë·À»¤¡¢·þÎñÆ÷²»·¨ÍâÁª·À»¤¡¢½©Ê¬ÍøÂç·À»¤µÈ¶àÏî·À»¤¡£
ÇëËùÓÐʹÓÃAG¹«Ë¾²úÆ·µÄÓû§¾¡¿ìÉý¼¶¡£AG¹«Ë¾¿Æ¼¼ÒÑÔÚÈí¼þÉý¼¶Í¨¸æÖÐÌṩ¹æÔòÉý¼¶°ü£¬¹æÔò¿ÉÒÔͨ¹ý²úÆ·½çÃæµÄÔÚÏßÉý¼¶¾ÙÐС£ÈôÊÇÄúµÄӪҵϵͳÔÝʱ»¹ÎÞ·¨Éý¼¶¹æÔò°ü£¬ÄÇô¿ÉÒÔÔÚÈí¼þÉý¼¶Ò³ÃæÖУ¬ÕÒµ½¶ÔÓ¦µÄ²úÆ·£¬Í¨¹ýÏÂÔØÉý¼¶°ü£¬ÒÔÀëÏß·½·¨¾ÙÐÐÉý¼¶¡£Ïà¹ØÐÅÏ¢Çë»á¼û²úÆ·Éý¼¶Í¨¸æ http://update.nsfocus.com/
ÁíÍ⣬Óû§ÈôÊÇÒѰ²ÅÅAG¹«Ë¾NIPS²úÆ·£¬¿ÉÒÔͨ¹ýÔöÌíTAC·À»¤×é¼þµÄ·½·¨£¬Ê¹ÆóÒµÍâµØÍøÂç¾ß±¸Î´ÖªÍþв·¢Ã÷ÄÜÁ¦£¬²¢ÓëAG¹«Ë¾NIPSÐγÉÁª¶¯£¬ÔÚµÚһʱ¼ä×öµ½Î´ÖªÍþв¼ì²â¡¢×èµ²¡£
Patch
ÔÚÕâ¸ö½×¶Î£¬½¨ÒéÄú¾¡¿ìµÄ×°Öþʹ˴Îй¶³öÀ´µÄ×ÊÁÏ¿âÖÐËù°üÀ¨µÄFlash 0DayÎó²î£¬Adobe¹Ù·½ÒѾÐÞ¸´ÁËÎó²î£¬²¢ÌṩÁËÉý¼¶°æ±¾£¬Çë¿í´óÓû§¾¡¿ìÉý¼¶µ½×îа汾¡£FLASH¸üа취ÈçÏ£º
- ·¿ª https://get.adobe.com/flashplayer/?loc=cn
-
µã»÷Á¬Ã¦×°Öã¬ÉúÑÄ×°Öðü£¬ÏÂÔØÍê³ÉºóÖ´ÐÐ×°ÖÃÎļþ0DayÎó²îÒ»µ©±»¹ûÕæ£¬ÍùÍùÒ²ÊDZ»¹¥»÷ÕßʹÓÃ×îΪ·Å×ݵÄʱ¼ä¡£ÔÚ´Ë Ç徲ר¼Ò½¨Òé:
- ×°Ö÷´²¡¶¾Èí¼þ¾ÙÐÐͨÅÌÎÊɱ ²¢µÚһʱ¼ä¸üÐÂϵͳºÍFlash²¹¶¡
-
ÍÆ¼öʹÓÃÇå¾²¼¶±ð¸ü¸ßµÄÁÔ±ª FireFoxä¯ÀÀÆ÷
- ChromeÓû§ÇëÉý¼¶ÖÁ×îа汾(>=43)
- IE ChromeÓû§ÇëÊÖ¶¯Éý¼¶FlashÖÁ×îа汾
-
Ñø³ÉÓÅÒìµÄÉÏÍøÏ°¹ßºÍÇå¾²Òâʶ
- Ìá¸ßÄÚ²¿Ô±¹¤µÄÇå¾²ÒâʶºÍ½¨ÉèÍêÕûµÄ¼à¿ØÏµÍ³ÊÇÌá·ÀAPTµÄÖ÷ÒªÊֶΡ£
- ½¨Òé¶ÔÄÚ²¿Ô±¹¤¿ªÕ¹ÆÕ±éµÄÇå¾²ÒâʶÅàѵ£¬×èÖ¹·ºÆðʹÓÃÈõ¿ÚÁî¡¢µã»÷²»Ã÷ȪԴÓʼþ¸½¼þ¡¢»á¼û¶ñÒâÍøÕ¾µÈΣÏÕÐÐΪ¡£²»ËæÒâ·¿ªÉúÊèÈËͨ¹ýQQµÈ·¢Ë͵ÄÍøÒ³Á´½Ó ²»ËæÒâ·¿ªÀ¬»øÓʼþ
½â¾ö¼Æ»®
AG¹«Ë¾ÏÂÒ»´úÍþв½â¾ö¼Æ»®£¨NGTP½â¾ö½â¾ö¼Æ»®£©£¬ÊÇÕë¶ÔAPTÍþв¾ÙÐмì²âºÍ·ÀÓùµÄ½â¾ö¼Æ»®¡£NGTP½â¾ö¼Æ»®¾Û½¹APT¹¥»÷Á´Ìõ£¬¼ì²âºÍ·ÀÓùAPT¹¥»÷Á´Öй¥»÷£¬Ç±ÔÚºÍ͵ȡÈý¸öÖ÷Òª»·½Ú¡£Öصã¼ì²âºÍ·ÀÓùÔÚ¹¥»÷ʵÑé½×¶Î£¬½øÈëºóµÄDZÔÚºÍÀ©Õ¹¹¥»÷½×¶Î£¬ÒÔ¼°×îÖÕ͵ȡÊý¾ÝÄ¿µÄ½×¶Î¡£
NGTP½â¾ö¼Æ»®ÒÔÈ«ÇòÍþвÇé±¨ÔÆÎªÅ¦´ø£¬ÒÔδ֪Íþв¼ì²âΪ½¹µã£¬Í¨¹ýÓë¹Å°åÖÕ¶Ë¡¢Íø¹Ø×°±¸Áª¶¯£¬ÊµÏÖ¿ç³§É̵ÄÍþвÇ鱨µÄ¹²Ïí£¬ÒÔ¼°ÆóÒµÍþÐ²Ì¬ÊÆ¿ÉÊÓ»¯£¬×îÖÕµÖ´ïÌáÉýÆóÒµAPTÍþв·À»¤µÄÄÜÁ¦µÄÄ¿µÄ¡£
Ó¦¶Ô0Day
NGTPÕë¶Ô0DayÎó²î¹¥»÷µÄ½â¾ö¼Æ»®£¬ÓÉÍâµØÉ³ÏäTAC£¬Íþв·ÀÓùÄ£¿éIPS£¬AG¹«Ë¾Çå¾²ÐÅÓþºÍESPCÖÎÀíµÈϵͳ×é³É¡£NGTP¼Æ»®·ÀÓù0DayÎó²î¹¥»÷µÄÁ÷³Ì£º
- µÚÒ»²½£ºÒª¾ÓÉÍâµØÉ³ÏäϵͳTACµÄ¼ì²â£¬TACÌṩ¾²Ì¬¼ì²âÒýÇæºÍÐéÄâÖ´ÐÐÒýÇæ£¬¶Ô¶ñÒâÈí¼þ¾ÙÐÐShellcode¾²Ì¬ÆÊÎö£¬È»ºóÔÙ¾ÙÐÐÐéÄâÖ´ÐС£Í¨¹ýÕâÁ½²½ÆÊÎö£¬´ÓHacking Team×é֯й¶µÄ0Day¹¥»÷Èí¼þ±»Ê¶±ð³öÀ´£»
- µÚ¶þ²½£ºTAC¼ì²â³ö¶ñÒâÈí¼þµÄȪԴ£¬ÌìÉúÐÅÓþÐÅÏ¢£¬°üÀ¨ÎļþµÄÐÅÓþºÍ¹¥»÷Ô´IPµÈÐÅÏ¢£¬Í¬²½µ½ÍâµØµÄÇå¾²ÖÎÀíÖÐÐÄESPC£¬ÐγÉÍâµØµÄÐÅÓþ¿â£»
- µÚÈý²½£ºNIPS´ÓÍâµØÐÅÓþ¿âÎüÊÕµ½¶ñÒâÈí¼þµÄÐÅÓþÐÅÏ¢£¬¶ÔÌᳫ¹¥»÷µÄÔ´IPʵÏÖ×è¶Ï£¬²¢ÌìÉú¸æ¾¯ÈÕÖ¾¡£
¼Æ»®ÓÅÊÆ
- APTÍþв¼ì²âºÍ·ÀÓùµÄÖÜÈ«ÐÔ£ºAG¹«Ë¾ÏÂÒ»´úÍþв½â¾ö¼Æ»®£¬Äܹ»ÖÜÈ«µÄ¶ÔAPTÍþв¼ì²âºÍ·ÀÓù¡£ÎÞÂÛÊÇÍøÂ磬WebÕÕ¾ÉÓʼþ£¬ÖÕ¶ËÖÚ¶àͨµÀ£¬¶¼ÊÇAPTÍþв¿ÉÄÜʹÓõÄͨµÀ£¬NGTP½â¾ö¼Æ»®£¬²»µ«ÔÚÍøÂç½çÏß½ø¼ì²âºÍ·ÀÓù£¬»¹ÔÚÆóÒµÄÚÍø£¬Óʼþ·þÎñÆ÷£¬Öն˵ȶà¸ö²ãÃæ¾ÙÐмì²âºÍ·ÀÓù¡£¼ÈÄܹ»ÊµÊ±¾ÙÐмì²âºÍ×è¶Ï£¬»¹Ê¹ÓôóÊý¾ÝÆÊÎöƽ̨£¬¾ÙÐÐʺóµÄÆÊÎöºÍÊӲ졣
- APT¼ì²âµÄ׼ȷÐÔ£ºAG¹«Ë¾ÏÂÒ»´úÍþв½â¾ö¼Æ»®£¬Ê¹ÓÃÍâµØÉ³ÏäºÍÔÆ¶ËÇå¾²ÐÅÓþ£¬×¼È·µØ¶ÔAPTÍþв¼ì²âºÍ·ÀÓù¡£ÍâµØÉ³ÏäÌṩÁ˶ñÒâÈí¼þ¾²Ì¬¼ì²âºÍÐéÄâÖ´ÐÐÊֶΣ¬¼ì²é¶ñÒâÈí¼þShellcode£¬²¢ÇÒÄ£ÄâÕæÊµµÄPCÇéÐξÙÐÐÑéÖ¤£¬¼«´óÌá¸ß¶ñÒâÈí¼þµÄ׼ȷÐÔ£»Í¬Ê±£¬ÔƶËÐÅÓþÌṩ×îеÄÍþвÇ鱨ÐÅÏ¢£¬½øÒ»²½ÌṩNGTP¼Æ»®¶ÔAPTÍþв¼ì²âµÄ׼ȷÐÔ¡£
- ½â¾ö¼Æ»®ÊÖÒÕÁìÏÈ£º×é³ÉNGTP½â¾ö¼Æ»®µÄ¸÷¸öÄ£¿éÊÖÒÕÏȽø¡£TAC²úÆ·£¬ÊǺ£ÄÚ×îÔçÍÆÏòÊг¡µÄAPT¼ì²â×°±¸£¬¾Óɼ¸ÄêµÄÒ»Ö±ÓÅ»¯£¬¹¦Ð§ºÍÐÔÄÜ»ñµÃ¼«´óÌá¸ß£¬ÓÈÆäÊÇ»ñµÃרÀûÊÖÒյľ²Ì¬Shellcode¼ì²âÊÖÒÕºÍÐéÄâÖ´Ðмì²âÊÖÒÕ£¬¸üÊÇΪAPTÍþв¼ì²âµÄ׼ȷÐÔÌṩǿÁ¦Ö§³Ö¡£AG¹«Ë¾NIPS²úÆ·Ò²ÊǾøºÊ¢Óþ£¬²»µ«ÔÚº£ÄÚÊг¡ÉÏÒ£Ò£ÁìÏÈ£¬»¹¶à´ÎÓÚ¹ú¼ÊȨÍþ¼ì²â»ú¹¹»ñµÃÈϿɡ£AG¹«Ë¾Çå¾²ÍþвÐÅÓþϵͳ£¬Ìṩ×îÐÂ×îÈ«µÄÇå¾²ÐÅÓþ£¬ÈÃNGTP¼Æ»®Ê©Õ¹×î´óЧÄÜ¡£
AG¹«Ë¾ÍþвÆÊÎöϵͳTAC£¬ http://www.nsfocus.com.cn/products/details_22_1.html
AG¹«Ë¾ÍøÂçÈëÇÖ·À»¤ÏµÍ³NIPS£¬ http://www.nsfocus.com.cn/products/details_22_3.html

AG¹«Ë¾ÔÆ












