¡¶Îó²îÉú³¤Ç÷ÊÆ±¨¸æ¡·Ðû²¼
2020-05-21
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼Ðû²¼¡¶Îó²îÉú³¤Ç÷ÊÆ±¨¸æ¡·£¬ÒÔNVDΪÊý¾ÝÔ´£¬¶Ô1999-2019ÄêµÄÎó²îÊý¾Ý¾ÙÐлØÊׯÊÎö£¬ÍŽáAG¹«Ë¾ÍþвÇ鱨ÖÐÐļà²âµ½µÄÎó²îʹÓù¥»÷ÊÂÎñ£¬´ÓͨÓÃϵͳ¡¢Èí¼þµÄÎó²î·ºÆðÇéÐΣ¬×ܽáÁË20ÄêÀ´Îó²îÑо¿¼°Ê¹ÓõÄÇ÷ÊÆ£¬²¢¶Ô½ü¼¸ÄêÐÂÐ˵ÄÒÆ¶¯¡¢ÎïÁªÍø×°±¸µÈÁìÓòµÄÎó²îÉú³¤¾ÙÐлØÊ׺ÍÕ¹Íû¡£

ÈýÕÅͼ£¬½â¶ÁÎó²îÉú³¤Ç÷ÊÆ

ÀúÄêÎó²îÊýĿͳ¼Æ
×èÖ¹2019Äêµ×£¬NVDÊý¾Ý¿â¹²ÊÕ¼Îó²îÐÅÏ¢138909Ìõ¡£2019ÄêµÄÎó²îÊýĿͬ±È1999Ä꣬ÔöÌíÁË9.62±¶¡£

Îó²îµÄ CVSS V2.0 ÂþÑÜ
×èÖ¹ 2019 Äêµ×¹²ÓÐ 130937 ÌõÎó²î·ÖÅÉÁË CVSS V2.0 Æ·¼¶£¬ÖÐΣÎó²îÕ¼ 56.06%£¬¸ßΣÎó²îÕ¼ÓÐ 35.22%¡£

TOP20 CWE Îó²îÀàÐÍ
¿çÕ¾¾ç±¾ (CWE-79) ÀàÐ͵ÄÎó²îÊýÄ¿ÒÔ 12911 ÌõÕ¼ÓеÚÒ»¡£
¹¥»÷ÕßÑÛÖУ¬Ê®ÄêÒÔÉÏ“¸ßÁä”Îó²îÒÀ¾É“ºÃʹ”

¹¥»÷ÊÂÎñʹÓõ½µÄÎó²î°´ÄêÂþÑÜ
¹¥»÷Õß¹Ø×¢Îȹ̡¢¸ßЧµÄÎó²îʹÓÃÊÖÒÕ£¬ÔÚÎó²îµÄÑ¡ÔñÉÏ×·ÇóÒ×ÓÃÐÔ¡¢Ê±Ð§ÐÔÒÔ¼°ÊÇ·ñÄÜ»ñȡĿµÄ¿ØÖÆÈ¨Ï޵Ĺ¥»÷ÄÜÁ¦¡£¿ÉÒÔ¿´µ½£¬×ÝÈ»ÊÇÔÚ 2019 Ä꣬ʮÄêÒÔÉϵĸßÁäÎó²îÈÔȻռÓÐÁËÏ൱´óµÄ±ÈÀý£¬ËµÃ÷»¥ÁªÍøÉÏÒÀÈ»±£´æ×Å´ó×Úºã¾Ãδ¸üеÄÈí¼þºÍϵͳ¡£
СÐÄ£¡Ê¹ÓÃÎļþÃûÌÃÎó²îµÄÓã²æÊ½´¹ÂÚ¹¥»÷

ÎĵµÀàÐÍÎó²îÂþÑÜ
ͨ¹ý¶ÔAPT¹¥»÷µÄÑо¿·¢Ã÷£¬Ê¹ÓÃÎļþÃûÌÃÎó²îµÄÓã²æÊ½´¹ÂÚ¹¥»÷ÒѳÉÎªÍøÂçÇå¾²µÄÖ÷ÒªÍþв֮һ¡£PDF¡¢doc(x)¡¢xls(x)¡¢ppt(x) µÈÎļþÃûÌþßÓÐ¿çÆ½Ì¨¡¢Ó¦ÓùæÄ£¹ã¡¢Óû§»ùÊý´óµÄÌØµã£¬Êܵ½Á˹¥»÷ÕßµÄÒ»Á¬¹Ø×¢£¬Ä¿µÄÖ÷»úÉϵÄÏìÓ¦³ÌÐòÒ»µ©±£´æÇå¾²Îó²î¾Í»á±»ÈÝÒ×¹¥ÆÆ¡£
¿ªÔ´Èí¼þÃæÁÙÎó²îʹÓúÍÈí¼þ¹©Ó¦Á´µÄË«ÖØ¹¥»÷

³£¼û¿ªÔ´Èí¼þµÄÎó²îÊýÄ¿
¿ªÔ´Èí¼þ¾ßÓпª·Å¡¢Ãâ·Ñ¡¢¹¦Ð§ÎÞаµÈÌØµã£¬»ñµÃÁËÔ½À´Ô½ÆÕ±éµÄÓ¦Ó㬿ÉÊÇÇå¾²ÎÊÌâÈÔÈ»ÆÕ±é±£´æ¡£¹ûÕæµÄʹÓôúÂëÔÚ¶Ìʱ¼äÄÚ±»¼¯³Éµ½³ÉÊìµÄ¹¥»÷¿ò¼Ü»òľÂí³ÌÐòÖУ¬½øÒ»²½½µµÍÁËÎó²îʹÓõÄÃż÷£¬¶ø´ÓÎó²îÐû²¼µ½±»¹¥»÷Õß´ó¹æÄ£Ê¹ÓõÄʱ¼ä´°¿ÚÒ²ÔÚ½øÒ»²½Ëõ¶Ì£¬¸øÇå¾²³§ÉÌ·À»¤ÄÜÁ¦´øÀ´Á˸ü´óµÄÌôÕ½¡£
Õë¶ÔÈí¼þ¹©Ó¦Á´µÄ¹¥»÷£¬³ÉÎªÃæÏòÈí¼þ¿ª·¢Ö°Ô±ºÍ¹©Ó¦É̵ÄÒ»ÖÖÐÂÐËÍþв¡£Õë¶ÔÈí¼þ¹©Ó¦Á´µÄ¹¥»÷ÔÚÈö²¥ËÙÂÊÉϸü¿ì¡¢Ó°Ïì¹æÄ£¸ü¹ã¡¢Î£º¦¸ü´ó£¬Í¬Ê±Ò²¸üÒþ²Ø¡£Èí¼þ¿ª·¢ÉÌÓ¦¸ÃÖÆ¶©Èí¼þ¹©Ó¦Á´±ê×¼¡¢¹æ·¶£¬×ñÕÕÇå¾²µÄ¿ª·¢Á÷³Ì£¬°´ÆÚ×éÖ¯Èí¼þ¹©Ó¦Á´¹¥·ÀÑÝÁ·¾ºÈü£¬°´ÆÚ¶Ô×ÔÉíÍøÕ¾¡¢Èí¼þµÈ¾ÙÐмì²âÓë¼Ó¹Ì£¬ÒÔïÔÌÊܵ½´ËÀ๥»÷µÄΣº¦¡£
ÎïÁªÍøÇå¾²µÄ¼ÛÖµ²»Ó¦Ö»ÔÚÊܵ½Íþвʱ²Å±»ÖØÊÓ
¾ÝÊг¡Ñо¿¹«Ë¾ Gartner ³Æ£¬ 2016 ÄêÈ«ÇòÎïÁªÍø×°±¸ÊýĿΪ 64 ÒÚ£¬2020 Ä꽫µÖ´ï 204 ÒÚ £¬ÔöÌí 218.75%£¬¿ÉÊÇÏÖÔÚÎïÁªÍø½¨ÉèÀú³ÌÖÐ˼Á¿µ½ÐÅÏ¢Çå¾²µÄ²úÆ·ÉÙÉÙ£¬¾ø´ó²¿·ÖÊÇ“Âã±¼”״̬¡£

2019Äê TOP10 ÎïÁªÍøÎó²îʹÓÃÊýÄ¿
ÃæÁÙÎïÁªÍøµÄÍþв£¬×°±¸ÖÆÔìÉÌÓ¦µ±ÖØÊÓ×°±¸µÄÇå¾²£¬Ö¸¶¨Çå¾²µÄ¿ª·¢Á÷³Ì£¬¶Ô×°±¸¾ÙÐÐÖÜÈ«µÄÇå¾²²âÊÔ¡£¹ØÓÚĬÈÏÃÜÂëµÄÎÊÌ⣬Ӧµ±ÔÚÓû§µÚÒ»´ÎʹÓõÄʱ¼ä£¬Ç¿ÖÆÈÃÓû§ÐÞ¸ÄÃÜÂ룬²¢¼ì²éÓû§ÃÜÂëµÄÇå¾²ÐÔ£¬Õ¥È¡ÉèÖÃÈõÃÜÂë¡£¶ÔʹÓÃÖÜÆÚ½Ï³¤µÄ×°±¸£¬°´ÆÚÌṩ¿É¸üеĹ̼þ£¬ÒÔÈ·±£×°±¸µÄÇå¾²ÐÔ¡£
×ܽ᣺“Çå¾²×óÒÆ”£¬´ÓÔ´Í·ÉÏïÔÌÎó²îµÄ±¬·¢
Çå¾²ÊÇÒ»¸ö¹¥Óë·ÀµÄÀú³Ì£¬Î´Öª¹¥ÑÉÖª·À£¬Ö»ÓÐÔÚÏàʶÖÖÖÖ¹¥»÷ÊÖÒÕºÍÊֶκó²Å»ª½ÓÄÉÔ½·¢ÓÐÓõķÀÓùÕ½ÂÔ£¬´Ó¶ø×èÖ¹Çå¾²ÊÂÎñµÄ±¬·¢¡£Èí¼þ¿ª·¢Ö°Ô±²»µ«ÐèÒªÊìÁ·µÄ±à³Ì¼¼ÇÉ£¬»¹ÐèÒªÖØÊÓ“Çå¾²×óÒÆ”£¬¼´ÔÚ¿ª·¢½×¶Î¾ÙÐÐÇå¾²¼Ó¹Ì¡¢´úÂëÉ󼯣¬½«Çå¾²ÊôÐÔÈÚÈëµ½Èí¼þµÄ¿ª·¢Àú³ÌÖУ¬´ÓÔ´Í·ÉÏïÔÌÎó²îµÄ±¬·¢¡£
Çå¾²Ñо¿Ö°Ô±ÐèÒªÔöǿϵͳÎó²î¼°·À»¤ÊÖÒյȷ½ÃæµÄѧϰ£¬Ò»Ö±ÉîÈëÑо¿ÐµÄÎó²îÍÚ¾òºÍʹÓÃÊÖÒÕ£¬ÌôÕ½ÖÖÖÖÎó²îµÄ»º½â²½·¥£¬Ïȹ¥»÷ÕßÒ»²½ÕÆÎÕ×îÐµĹ¥»÷ÊÖÒÕ£¬²Å»ªÓëÇå¾²³§ÉÌЯÊÖ£¬½øÒ»²½Ìá¸ßϵͳºÍÓ¦ÓõÄÇå¾²·À»¤Ë®Æ½¡£
ÏÂÔØÁ´½Ó£º
http://blog.nsfocus.net/wp-content/uploads/2020/05/Vulnerability-Development-Trend.pdf

AG¹«Ë¾ÔÆ







