¡¾»ã±¨·ÖÏí¡¿¿¨°Í˹»ù - 2018ϰëÄêICSÍþв¾°¹Û
°ä²¼¹¦·ò 2019-04-26Ò»¡¢2018ϰëÄêÖØÒª¹¥»÷ÊÂÎñ
1.1 Õë¶Ô¹¤ÒµÐÐÒµµÄAPT¹¥»÷
1.1.1 ·¸×ïÍÅ»ïLeafminerµÄAPT¹¥»÷
Leafminer¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©
¹¥»÷ÕßʹÓÃÁ˶àÖÖ¹«¿ª»ò¶¨ÔìµÄ¹¤¾ß¡¢exploitÒÔ¼°Ë®¿Ó¹¥»÷ºÍ×ֵ乥»÷£¬ÀýÈçÓÀºãÖ®À¶µÄexploitºÍMimikatz±äÌå¡£
1.1.2 жñÒâÈí¼þGreyEnergy
Eset×êÑÐÈËÔ±»ã±¨ÁËÓë·¸×ïÍÅ»ïBlackEnergyÓйصĶàÆð¹¥»÷ÊÂÎñ£¬ÔÚÕâЩ¹¥»÷Öй¥»÷ÕßʹÓÃÁËÒ»¸öеĶñÒâÈí¼þGreyEnergy¡£BlackEnergyÏÈǰÒÑ´ÓAPT×êÑÐÈËÔ±µÄÀ×´ïÉÏÒþû£¬µ«ÕâÒ»´Î¹¥»÷ÕßÔÙ´ÎÏÖÉí£¬ÖØÒªÕë¶ÔÖÐÅ·ºÍ¶«Å··ÖÆçÒµÒµµÄ¹¤ÒµÍøÂ磬Ô̺¬ÄÜÔ´¹«Ë¾¡¢ÔËÊ乫˾µÈ£¬²¢³Áµã¹Ø×¢ÕƹÜÔËÓª¹Ø¼ü»ù´¡ÉèÊ©µÄÆóÒµ¡£
×êÑÐÈËÔ±·¢ÏÖGreyEnergyÓë2015ÄêBlackEnergyÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄ¶ñÒâÈí¼þ´æÔÚ¸ÅÏëÉϵÄÀàËÆÖ®´¦¡£´Ë±í£¬×êÑÐÈËÔ±»¹·¢ÏÖGreyEnergyÓë·¸×ïÍÅ»ïTeleBotsµÄ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£TeleBotsÒÔ¶àÆð´ó¹æÄ£¹¥»÷ÊÂÎñÎÅÃû£¬ÀýÈç2017ÄêµÄNotPetyaºÍBadRabbit¡£¿¨°Í˹»ù×êÑÐÈËÔ±Ëæºó·¢ÏÖGreyEnergy»¹ÓëSofacy£¨¼´APT28£©µÄ×ÓÍÅ»ïZebrocy´æÔÚ¹ØÁª¡£
GreyEnergyÓµÓÐÄ£¿é»¯µÄϵͳ½á¹¹£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ý¼ÓÔØÓйØDLLÀ´×éºÏ·ÖÆçµÄ¶ñÒâÈí¼þÖ°ÄÜ¡£Ä³Ð©Çé¿öÏ£¬ÕâЩ¶ñÒâÄ£¿é´ÓC&C·þÎñÆ÷ÏÂÔØ²¢Ö±½Ó¼ÓÔØ½øÄڴ棨²»Ð´Èë´ÅÅÌÎļþ£¬¼´ÎÞÎļþ¹¥»÷£©¡£GreyEnergy¿ÉÍøÂçÊܺ¦ÕßµÄÍ´´¦ÒÔÉøÈ빤¿ØÍøÂç¡£¸Ã×éÖ¯µÄ¹¤¾ß°ü»¹Ô̺¬¿ªÔ´¹¤¾ßMimikatz¡¢PsExec¡¢WinExeºÍNmapµÈ¡£
GreyEnergyµÄ³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ¼°ÆóÒµµÄ¹«¹²ÍøÂç×ÊÔ´£¬µ±È»ºÜÓпÉÄÜ»¹Ô̺¬ÆäËü¹¥»÷ÏòÁ¿¡£
ÔÚ֮ǰµÄ¹¥»÷»î¶¯ÖУ¬¸Ã×éÖ¯ÔøÀûÓÃGE CimplicityÖеķì϶£¨CVE-2014-0751£©ÔÚHMI·þÎñÆ÷ÉÏÖ´ÐжñÒâ.cimÎļþ£¬²¢×îÖÕ×°ÖÃBlackEnergy¡£Æ¾¾Ý¿¨°Í˹»ùµÄ×êÑУ¬¸Ã×éÖ¯»¹ÔøÔÚ2014ÄêÀûÓÃÎ÷ÃÅ×ÓWinCCÖеķì϶£¨CVE-2014-8551£©À´ÉøÈëÖ¸±êÍøÂç¡£ÔÚ×î½üµÄ¹¥»÷Öи÷ìÏ¶Ò²Ôø±»ÀûÓá£
´Ë±í£¬´Óǰ¸Ã×éÖ¯ÔøÈëÇÖÖ¸±êÆóÒµµÄ·ÓÉÆ÷²¢×°Öø÷Àà¶ñÒâÄ£¿éºÍ¾ç±¾£¬ÒÔ½øÐкáÏòÒÆ¶¯¡£ÔÚ×î½üµÄGreyEnergy¹¥»÷ÖÐÉÐδ·¢ÏÖÕâÖÖÐÐΪ£¬µ«¸ÃÐÐΪºÜ¿ÉÄÜ´æÔÚ£¬ÓÉÓڸù¥»÷ÏòÁ¿¶Ô¹¥»÷Õß¼«¶ÈÓÐÀû£¬¿ÉÓÃÓÚ¶¨ÆÚÍøÂç¸÷¸ö·ÓÉÆ÷ÐͺŴæÔڵķì϶ÐÅÏ¢£¬Ô̺¬0day¡£
1.1.3 ¹¥»÷»î¶¯Sharpshooter
SharpshooterµÄÖ¸±êÐÐÒµºÍ¹ú¶ÈÉ¢²¼£¨ÆðÔ´£ºMcAfee£©
ϰȾÁ´Ê¼ÓÚÔ̺¬¶ñÒâºêµÄMicrosoft WordÎĵµ¡£¸Ã¶ñÒâºê×÷Ϊһ¸öµäÐ͵Ädownloader£¬ÓÃÓÚ½»¸¶¶ñÒâÖ²ÈëÎï¡£¹¥»÷Õßͨ¹ýDropboxÀ´·Ö·¢ÊÜϰȾµÄÎļþ¡£¸ÃÖ²ÈëÎÃûΪRising Sun£©ÊÇÒ»¸öеÄÄ£¿é»¯ºóÃÅ£¬Ö»ÔÚÄÚ´æÖÐÔËÐУ¬ÖØÒªÍøÂçÓû§Êý¾Ý£¬Ô̺¬ÍÆËã»úÃû³Æ¡¢IPµØÖ·¡¢ÏµÍ³ÐÅÏ¢µÈ¡£ÍøÂçµ½µÄÊý¾Ý±»¼ÓÃÜ´«ÊäÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¿¨°Í˹»ù×êÑÐÈËÔ±ÒÔΪ·¸×ïÍÅ»ïLazarusÓëÕâЩ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£
1.1.4 ¹¥»÷»î¶¯MuddyWater
MuddyWater¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©
1.1.5 ¹¥»÷»î¶¯Cloud Hopper
2018Äê12ÔÂÖÐÑ®£¬µÂ¹úÁª¹úÐÅÏ¢°²È«°ì¹«ÊÒ£¨BSI£©ÏòһЩµÂ¹úÆóÒµ°ä²¼Á˾ݳÆÓëAPT10ÓйصÄCloudHopper¹¥»÷¾¯±¨¡£BSI³Æ¶à¼Ò´óÐ͹¤³ÌÆóÒµÒѾÔâµ½¹¥»÷£¬¹¥»÷Õß»¹¶Ô¹¹ÖþºÍ×ÊÁÏѧÁìÓòµÄÆóÒµ¸ÐÐËÖ¡£
¹¥»÷Õß²¢Ã»ÓÐÖ±½Ó¹¥»÷Ö¸±êÆóÒµ£¬¶øÊÇͨ¹ýÉøÈëÖ¸±êÆóҵʹÓõÄÓ×ÐÍÔÆ·þÎñºÍÍйܷþÎñ¹©¸øÉÌÌáÒé¹¥»÷¡£ÕâÀ๩¸øÉÌͨ³£°²È«ÐԽϲ¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÉøÈëÖ¸±ê¹«Ë¾µÄÆóÒµÍøÂç¡£
1.1.6 ¶ñÒâÈí¼þShamoon v.3
2018Äê12ÔÂ10ÈÕ£¬Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SiapemÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷ÕßÖØÒªÕë¶Ô¸Ã¹«Ë¾Î»ÓÚÖж«¡¢Ó¡¶È¡¢ËÕ¸ñÀ¼ºÍÒâ´óÀûµÄ·þÎñÆ÷£¬Ê¹ÓõĶñÒâÈí¼þÊÇShamoonÈ䳿µÄбäÌåShamoon v.3¡£Ô¼ÓÐ300µ½400̨·þÎñÆ÷¼°100̨¹¤×÷Õ¾ÔÚÕâ´Î¹¥»÷ÊÂÎñÖÐÊܵ½Ó°Ïì¡£
ÔÚSaipem°ä²¼ÉêÃ÷Ö®ºó£¬ÈüÃÅÌú¿Ë·¢ÏÖÏÕЩÔÚͳһ¹¦·ò»¹ÓÐÁ½¼ÒλÓÚÉ³ÌØ°¢À²®ºÍ°¢ÁªÇõµÄʯÓͺÍÌìÈ»Æø¹«Ë¾Ôâµ½ÀàËÆµÄ¹¥»÷¡£
ShamoonÈ䳿³õ´Î³öÏÖÓÚ2012ÄêÕë¶ÔÉ³ÌØ°¢À²®¹ú¶ÈʯÓ͹«Ë¾AramcoºÍ¿¨Ëþ¶ûÌìÈ»Æø¹«Ë¾RasgasµÄ¹¥»÷»î¶¯ÖС£ÔÚ2016-2017ÄêµÄÐÂÒ»ÂÖ¹¥»÷ÖУ¬¹¥»÷ÕßʹÓÃÁËShamoonµÄ±äÖÖ£¨Shamoon v2£©ºÍ¶ñÒâÈí¼þStoneDrill¡£
ÔÚ2018ÄêµÄ¹¥»÷»î¶¯ÖУ¬Åã°é×ÅShamoon v.3³öÏֵϹÓÐÐÂÊý¾Ý²Á³ýÆ÷Filerase¡£Filerase¿É²Á³ý£¨¸²Ð´£©ÊÜϰȾϵͳÉϵÄÎļþ¡£2018ÄêµÄShamoon¹¥»÷»î¶¯ÓÉÓÚʹÓÃÁËFilerase¶ø¸ü¾ß·ÛËéÐÔ¡£ShamoonÄܹ»²Á³ýÊÜϰȾϵͳµÄÖ÷Êèµ¼¼Í¼£¨MBR£©£¬µ«Ó²ÅÌÉϵÄÎļþ¿É±»¸´Ô£¬¶øÊ¹ÓÃÁËFileraseÖ®ºóÈκÎÎļþ¶¼²»³É¸´Ô¡£
FileraseÓµÓÐÄ£¿é»¯½á¹¹£¬Ô̺¬¶à¸öÓÃÓÚÔÚ±¾µØÍøÂçÉϽøÐд«²¼µÄ×é¼þ¡£ÕâÒâζ×ÅFilerase×ÔÉíÄܹ»×÷Ϊһ¸öµ¥¶ÀµÄÍþв¡£FileraseÔÚÊܺ¦Õߵı¾µØÍøÂçÉÏ´«²¼Ê±£¬ÒÀÀµÒ»¸öÖ¸±êÃûµ¥À´°Îȡָ±ê¡£ÔÚ³õʼϰȾ¹ý³ÌÖУ¬¸ÃÃûµ¥ÊÇÓÉOCLC.exe×é¼þ¸´ÔìµÄ£¬²¢·¢Ë͸øSpreader.exe¹¤¾ß£¬ºóÕß½«Filerase¸´Ôìµ½Ãûµ¥ÉϵĻúе¡£¸ÃÃûµ¥ÊÇÒ»¸öÔ̺¬·ÖÆçÊܺ¦ÕßÃû×ÖµÄÎı¾Îļþ£¬ÕâЩÃû×ÖºÜÓпÉÄÜÊǹ¥»÷ÕßÔÚ¹¥»÷µÄÔçÆÚ½×¶ÎÍøÂçµÄ¡£
McAfeeµÄ×êÑÐÈËÔ±ÒÔΪShamoon v3¹¥»÷»î¶¯¿ÉÄÜÓëÒÁÀÊ·¸×ïÍÅ»ïAPT33Óйأ¬»òÊÇÁí±íÒ»¸ö·¸×ïÍÅ»ï¼Ù×°³ÉAPT33¡£ÈüÃÅÌú¿Ë×êÑÐÈËÔ±³ÖÒ»Ñù¶¨¼û¡£
1.2ÍøÂç·¸×ï»î¶¯
1.2.1 ÀÕË÷Èí¼þ¹¥»÷
ƾ¾Ý¿¨°Í˹»ùµÄÊý¾Ý£¬Ôâ·êÀÕË÷Èí¼þ¹¥»÷µÄICSÍÆËã»ú±ÈÀý´Ó1.6%ÉÏÉýÖÁ2%¡£
WannaCryÈÔ¾ÉÊǹ¤ÒµÆóÒµÃæ¶ÔµÄÒ»¸öÕæÊµµÄÍþв£¬Ò²ÊÇÒ»¸ö³£¼ûµÄÍþв¡£Æ¾¾Ý¿¨°Í˹»ùµÄÊý¾Ý£¬WannaCry£¨28.72%£©ÊÇÀÕË÷Èí¼þÍþвÖеÄÁìÍ·Ñò£¨2018ÄêµÚÈý¼¾¶È£©¡£¼´±ãÊÇÔÚ´ó¹æÄ£·¢×÷µÄÒ»ÄêÖ®ºó£¬WannaCryÈԾɳÖÐøÏ°È¾¹¤ÒµÆóÒµµÄICSÍøÂ磬ÀýÈ磬2018Äê8ÔÂ3ÈǪ̃»ýµç£¨TSMC£©µÄ¶à¼Ò¹¤³§Ôâµ½WannaCry¹¥»÷¡£Æ¾¾ÝÏÖÓÐÐÅÏ¢£¬Ï°È¾ÊÇÓÉÒ»¸ö¹©¸øÉÌÔÚгö²ú¹¤¾ßÉÏ×°ÖÃÁËÊÜËðÈí¼þµ¼Öµģº¸Ã¹©¸øÉ̲¢Î´½øÐÐÈκΰ²È«É¨Ãè¾Í½«Èí¼þÁ¬Èë³ö²úÍøÂ磬µ¼Ö¶ñÒâÈí¼þÔŲ́ÄÏ¡¢ÐÂÖñºĮ́ÖеĶà¼Ò¹¤³§Ö®¼äѸ¿ì´«²¼£¬Ì¨Í幤³§µÄ³ö²ú±»ÆÈÖжÏÁË3Ìì¡£
1.2.2 Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷
2018Äê8Ô£¬¿¨°Í˹»ùICS CERT°ä²¼Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷µÄµ÷²éÁ˾֡£¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇ´Ó¹«Ë¾µÄÕË»§ÖÐÇÔÈ¡½ðÇ®¡£
¹¥»÷ʼÓÚ2017Äê11Ô£¬²¢ÇÒÈÔÔÚ³ÖÐø¡£¹¥»÷ÕßÖØÒª·¢ËͼÙ×°³ÉºÏ·¨Ã³Ò×±¨¼ÛµÄ´¹µöÓʼþ£¬ÓʼþÖеĶñÒ⸽¼þÊÜÃÜÂë±£»¤£¬¶øÃÜÂ븽ÔÚÓʼþÄÚÈÝÖС£ÕâÀàÓʼþ×ÔÉí¾¹ý¸ß¶È¼Ù×°£¬ÇкϹ«Ë¾µÄÒµÎñÇé¿ö¡£ÔÚ×î½üµÄÒ»²¨¹¥»÷ÖУ¬´¹µöÓʼþ¼Ù×°³ÉÊܺ¦ÆóÒµµÄºÏ×÷ͬ°é¡£¶ñÒ⸽¼þÖеľ籾½«ÔÚϵͳÉÏ×°ÖöñÒâÈí¼þ£¬¶øºóÏνӵ½¹¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷²¢ÏÂÔØÖ®Ç°ÍµÇԵĺϷ¨Îĵµ¡£
¹¥»÷Õß»áÔÚÊÜϰȾµÄϵͳÉÏ×°ÖúϷ¨µÄÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©- ÈçTeamViewerºÍRMS¡£µ«¶ñÒâÈí¼þ»á°µ²ØÕâЩRATµÄͼÐνçÃæ£¬ÒÔÔÚÓû§²»ÖªÇéµÄÇé¿öϽÚÔìÊÜϰȾµÄ»úе¡£
¹¥»÷Õß½ø¶øËÑË÷ϵͳÉϵIJÆÕþºÍ¹ÜÕÊÈí¼þ£¬²¢²éÕҺͷÖÎöÓë²É¹ºÓйصÄÕÊÄ¿Îĵµ¡¢ºÏ×÷É̵ÄÓʼþµØÖ·ÒÔ¼°ÓëºÏ×÷É̵ÄͨѶÍùÀ´£¬¶øºó½øÒ»²½ÀûÓÃÕâЩ˽º±¼û¾Ý½øÐвÆÕþڲƣ¬ÀýÈçÅú¸Ä¶©µ¥ÖеÄÒøÐп¨Õ˺ŵȡ£
¹¥»÷Á÷³ÌµÄÕûÌåʾÒâͼ
¿¨°Í˹»ùICS CERTÒÔΪÕâЩ¹¥»÷ºÜÓпÉÄÜÊÇÓɶíÓï¹¥»÷ÕßÌáÒéµÄ¡£
1.2.3 Õë¶ÔÈ«ÇòÆóÒµµÄ´¹µö¹¥»÷
2018Äê10ÔÂYoroi CERT¼ì²âµ½¼¸ÆðÕë¶ÔÒâ´óÀûˮʦºÍ¹ú·ÀÆóÒµµÄ¹¥»÷»î¶¯¡£Ö¸±êÆóÒµµÄÔ±¹¤½Ó¹Üµ½Ð¯´ø¶ñÒâExcelÎļþµÄ´¹µöÓʼþ¡£¸Ã¶ñÒâExcelÖ¼±ÉÈËÔØRATľÂíMartyMcFly£¬¹¥»÷Õß¿ÉÀûÓøÃľÂí½ÚÔìÖ¸±ê»úе¼°ÇÔÈ¡Êý¾Ý¡£´Ë±í£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÁíÒ»¸öÔ¶³ÌÖÎÀí¹¤¾ßQuasarRAT£¨Ô´´úÂëÔÚgithubÉÏ¿ÉÓ㩵ıäÌå¡£
´¹µöÓʼþÖжñÒâxlsxÎļþµÄÉ¢²¼£¨ÆðÔ´£ºKSN£©
¿¨°Í˹»ùICS CERTÒÔΪ£¬Õâ´Î¹¥»÷ÊÇÓÉÕë¶Ô¶à¸öÆóÒµ£¨ÓÐʱÔ̺¬¹Ø¼ü»ù´¡ÉèÊ©£©½øÐдó¹æÄ£´¹µö¹¥»÷µÄÒ»Ñù·¸×ïÍÅ»ïÌáÒéµÄ¡£ÕâЩÍÅ»ïרһÓÚÇÔÈ¡½ðÇ®ºÍ²ÆÕþÊý¾Ý¡£
¶þ¡¢2018ÄêICS·ì϶ͳ¼Æ
±¾Ó×½ÚÖеķì϶·ÖÎöÊÇ»ùÓÚ³§É̲¼¸æ¡¢¿ªÔ´·ì϶¿â£¨US ICS-CERT¡¢CVE¡¢Î÷ÃÅ×Ó CERT£©µÄ¹«¿ªÐÅÏ¢ÒÔ¼°¿¨°Í˹»ùICS CERTµÄ×êÑÐÁ˾ֽøÐеġ£US ICS-CERTÍøÕ¾ÉϵÄ2018Äê·ì϶ÐÅÏ¢±»ÓÃ×÷ͳ¼ÆÊý¾ÝµÄÆðÔ´¡£
2.1 ·ì϶ÊýÁ¿
US ICS-CERTÅû¶µÄICS·ì϶ÊýÁ¿
2.2 ÐÐҵɢ²¼
2018ÄêICS·ì϶µÄÐÐҵɢ²¼£¨»ùÓÚUS ICS-CERTµÄ·ÖÀࣩ
2.3 ·ì϶ÑϳÁÐÔÉ¢²¼
ÑϳÁÐÔÆÀ·Ö
9 - 10 (ÑϳÁ)
7 - 8.9 (¸ßΣ)
4 - 6.9 (ÖÐΣ)
0 - 3.9 (µÍΣ)
ICS·ì϶ÊýÁ¿
92
192
128
3
2017 vs 2018£¬ICS·ì϶µÄÑϳÁÐÔÉ¢²¼£¨»ùÓÚCVSS v3ÆÀ·Ö£©
ÒÔϲúÆ·ÖÐÔ̺¬ÆÀ·ÖΪ10·ÖµÄ·ì϶£º
- Siemens TIM 1531 IRC Modules
- Siemens SINUMERIK Controllers
- Circontrol CirCarLife
- NUUO NVRmini2 and NVRsolo
- Emerson AMS Device Manager
- Rockwell Automation RSLinx Classic
- Schneider Electric U.motion Builder
- Martem TELEM-GW6/GWM
´óÎÞÊýÆÀ·ÖΪ10·ÖµÄ·ì϶¶¼ÊÇÉí·ÝÑéÖ¤»ò»º³åÇøÒç³öÎÊÌâ¡£
2.4 ÀàÐÍÉ¢²¼
ÓëǰһÄêÏà±È£¬»º³åÇøÒç¶Âí½ÅµÄ±ÈÀýÏÔÖøÔö³¤¡£ÎÒÃÇÒÔΪÕâÓ밲ȫ×êÑÐÈËÔ±¶ÔICS×é¼þÖеķì϶ԽÀ´Ô½¸ÐÐËÖÂÓйأ¬Ò²ÓëfuzzingµÈ×Ô¶¯»¯²âÊÔ¼¿Á©µÄʹÓÃÓйء£
2017 vs 2018, ICS·ì϶ÀàÐ͵ÄÉ¢²¼
2.5 ÊÜÓ°ÏìµÄICS×é¼þÉ¢²¼
·ì϶ÊýÁ¿×î¶àµÄICS×é¼þÔ̺¬£º
- ¹¤³ÌÈí¼þ£¨143¸ö£©
- SCADA/HMI×é¼þ£¨81¸ö£©
- רΪ¹¤Òµ»·¾³Éè¼ÆµÄÍøÂçÉ豸£¨66¸ö£©
- PLC£¨47¸ö£©
ÊÜÓ°ÏìµÄICS×é¼þ»¹Ô̺¬¹¤ÒµÍÆËã»úºÍ·þÎñ£¨5%£©¡¢¹¤ÒµÊÓÆµ¼à¿ØÏµÍ³£¨4%£©¡¢¸÷Àೡ¼¶É豸ºÍ±£»¤¼ÌµçÆ÷¡£
2.6 ¹¤³ÌÈí¼þÖеķì϶
¹¤³ÌÈí¼þÖеݲȫÎÊÌâͨ³£ÊÇÓɵÚÈý·½Èí¼þµ¼Öµġ£ÓÉÓÚµÚÈý·½×é¼þµÄ¿í·ºÊ¹Óã¬Ò»µ©³öÏÖ·ì϶¾Í»áÓ°Ïì´óÁ¿¹¤Òµ²úÆ·¡£ÀýÈ磬Î÷ÃÅ×ÓÂ¥Óî¿Æ¼¼²úÆ·ºÍÎ÷ÃÅ×ÓSIMATIC WinCC²å¼þÓÉÓÚ¼¯³ÉÁËÔ̺¬·ì϶µÄSentinel LDK RTElicenseÖÎÀíÆ÷¶øÒ×Êܹ¥»÷¡£´Ë±í£¬Î÷ÃÅ×ÓµÄÕû¸ö¹¤Òµ²úÆ·Ïß¶¼Êܵ½OpenSSL·ì϶µÄÓ°Ïì¡£ÀàËÆµØ£¬×÷ΪFloating License ManagerµÄÒ»²¿ÃÅ£¬Flexera PublisherÈí¼þÖеķì϶ͬʱӰÏìÁËÊ©Ä͵µĶà¸öµçÆø²úÆ·¡£
´Ë±í£¬Ó¦³ö¸ñ°ÑÎÈÓÃÓÚ½Ó¼ûICSϵͳµÄÒÆ¶¯APP£¨Android»òiOSƽ̨µÄÖÇÄÜÊÖ»ú¡¢Æ½°åµÈ£©¡£Ò×Êܹ¥»÷µÄ´ËÀà²úÆ·°¸ÀýÔ̺¬SIMATIC WinCC OA iOS App¡¢IGSS Mobile¡¢SIMATIC WinCC OA UIMobile App¡¢General Motors¼°OnStar (SOS) iOS¿Í»§¶Ë¡£´ËÀàÒÆ¶¯APPÔ½À´Ô½¶àµØÀûÓÃÓÚICS»ù´¡ÉèÊ©£¬µ«Æä°²È«Ë®Æ½ÈÔÓдýÌá¸ß£¬Í¨¹ýÈëÇÖÒÆ¶¯APP¿ÉÄܵ¼ÖÂÕû¸öICS»ù´¡ÉèÊ©Ãæ¶Ô±»ÈëÇֵķçÏÕ¡£
ÁíÒ»¸öÀàËÆµÄ°²È«ÎÊÌâÓëICSºÍÔÆ¼¼ÊõµÄ½áºÏÓйء£ÀýÈ磬2018ÄêMindConnect NanoºÍMindConnect IoT2040£¨IoTÓ²¼þÍø¹Ø£¬ÓÃÓÚÏνӹ¤ÒµÉ豸ºÍÎ÷ÃÅ×ÓMindSphereÔÆÆ½Ì¨£©¾Í±»·¢ÏÖÒ×Êܹ¥»÷¡£
2.7 ¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷Öеķì϶
2018Äê¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷ÖеݲȫÎÊÌâÖØÒªÓëÖ÷Á÷¹©¸øÉ̵ÄоƬ·ì϶Óйأ¬ÀýÈçÈۻٺ͹í»ê·ì϶£¬»¹ÓÐSpectre-NG·ì϶¡£ÁíÒ»¸öÓ°Ïì´óÁ¿¹¤ÒµÍÆËã»úµÄ·ì϶ÊÇ¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©ÖеÄRCE·ì϶¡£ÕâÔÙÒ»´ÎÖ¤ÁËÈ»£¬´«Í³¼¼Êõ£¨¼´·ÇICSÌØÓеļ¼Êõ£©Öеķì϶Äܹ»Ó°Ï칤ҵϵͳ¡£
2.8 ¹¤ÒµÍøÂ簲ȫ½â¾ö¹æ»®Öеķì϶
Èý¡¢³£¼ûÍþв
3.1 Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷
Ô̺¬¶ñÒ⸽¼þµÄ´¹µöÓʼþÈÔÊÇÉøÈ빤ҵÆóÒµµÄÖØÒª¹¥»÷ÏòÁ¿¡£ÔÚ´ÓǰÊýÄêÖУ¬ÕâÀàÍþвÒѳÉΪ¹¤Òµ¹¤×÷Õ¾µÄ³£¼ûÍþв¡£

´¹µöÓʼþÑùÀý
ͨ³£Ë·´£¬Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷Æä×îÖÕÖ÷ÕŶ¼ÊÇΪÁËÇÔÈ¡½ðÇ®¡£µ±È»£¬Ò²ÓÐһЩ¼Ù×°³É¡°³ß¶È¡±´¹µö¹¥»÷µÄÕë¶ÔÐÔ¹¥»÷¡£
ƾ¾ÝGA»Æ½ð¼×ͳ¼Æ£¬¹¤Òµ´¹µö¹¥»÷²»½öÕë¶ÔÆóÒµÍøÂçÖеķþÎñÆ÷£¬»¹Õë¶Ô¹¤Òµ»ù´¡ÉèÊ©ÖеÄÒ»Ð©ÍÆËã»ú¡£ÔÚÈ«ÇòÁìÓòÄÚ£¬ÖÁÉÙ4.3%µÄICSÍÆËã»úÔø¼ì³ö¹ý¼äµýÈí¼þ¡¢ºóÃźͼüÅ̼ͼľÂí¡£ÕâЩ¶ñÒâÈí¼þ³£ÓÉ´¹µöÓʼþ½øÐзַ¢¡£ÎÒÃÇÒÔΪÕâЩ¶ñÒâÈí¼þµÄÁìÓò¿ÉÄÜÔ½·¢¿í·º£¬ÓÉÓÚ´¹µö¹¥»÷Õß³£¸üлò¶¨ÆÚת»»Æä¶ñÒ⹤¾ß£¬Ê¹µÃһЩ×îÐÂÑù±¾Î´±»Í³¼Æµ½¡£
ÓÉÓÚ´¹µö¹¥»÷Õß»ý¼«Ê¹Óô¹µöÓʼþ½øÐй¥»÷£¬ÎÒÃǹ۲쵽ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý²»ÐÝÅÊÉý¡££¨ÓëITÍÆËã»úÒ»Ñù£¬OTÍÆËã»úͨ³£Ò²×°ÖÃÁËÓʼþ¿Í»§¶Ë£¬ÒԿ繫˾»¥»»ÐÅÏ¢ ¨C ͨ³£»¹Ê¹ÓÃÁËÒ»ÑùµÄÓʼþÕÊ»§¡£ÎÒÃǺÜÉÙ¿´µ½OTÍøÂçÖÐʹÓÃÁËÓëIT·ÖÆçµÄÓʼþÕÊ»§£©¡£2018ÄêϰëÄêÎÒÃÇÔÚÈ«ÊÀ½çÁìÓòÄÚ¶¼·¢ÏÖÁËÕâÒ»Ôö³¤¡£
ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý
ÈçÉÏͼËùʾ£¬Î÷Å·µØÓòÒâ±íµØÅÅÃûTop3£º¸ÃµØÓòµÄÊý×ÖÔö³¤ÁË2.7¸ö°Ù·Öµã£¬ÆäÖÐÔö³¤·ù¶È×î´óµÄÊǵ¹ú£¬¸ÃµØÓòµÄÊý×ÖÏÕЩ··¬¡£
Î÷Å·µØÓòÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý
ÖµÍ×ÌùÐĵÄÊÇ£¬´¹µöÓʼþÖеĺܶà¶ñÒ⸽¼þ´Ë¿Ì¶¼ÊǼÓÃܵÄѹËõÎļþ£¬ÃÜÂ븽ÔÚÓʼþµÄÕýÎÄÖ®ÖС£´Ë¾ÙÊÇΪÁËÌӱܼì²â£¬Í¨³£Çé¿ö϶ñÒâÈí¼þÖ»ÓÐÔÚÊÕ¼þÈË´ò¿ª¸½¼þʱÄÜÁ¦¼ì²âµ½¡£
ÎÒÃǽ¨Ò飬ËùÓй«Ë¾¶¼ÒªÌáÐÑÔ±¹¤ÕâÒ»ÕæÕýµÄÍþв£¬²¢ÑµÁ·ËûÃǼø±ð¹¥»÷¼£Ï󣬲»Òª´ò¿ª¿ÉÒÉÎļþ»òµã»÷Á´½Ó£¬²¢½«ÈκÎDZÔÚÊÂÎñÍ¨ÖªÍøÂ簲ȫÊýÃÅ¡£
2018ÄêϰëÄ꿨°Í˹»ùµÄ°²È«²úÆ·¹²ÔÚ40.8%µÄICSÍÆËã»úÉϼì²âµ½¶ñÒâÑù±¾¡£
ÕâЩ¶ñÒâÑù±¾¿É¹éÀàÓÚÒÔÏÂÀà±ð£¬ÁбíÖл¹±ê³öÁËÊÜ´ËÀàÑù±¾¹¥»÷µÄICSÍÆËã»úµÄ±ÈÀý¡£Çë°ÑÎÈÓÉÓÚͳ¼ÆÊý¾ÝѡȡÁË»ùÓÚÊðÃûºÍÆô·¢Ê½µÄ¼ì²â²½Ö裬һЩÎÞ·¨·Ö±æµÄ¶ñÒâÈí¼þÑù±¾±»¹éÀàÓÚGeneric£¨Í¨Óã©Àà±ð£¬ÕâÒâζ×ÅijЩÀà´ËÍâ¶ñÒâÈí¼þµÄ±ÈÀýÏÖʵÉÏÒª¸ü¸ß¡£
¼ì²âµ½µÄ¶ñÒâÑù±¾¹éÀ༰Æä±ÈÀý£º
- 15.9% - ÁÐÈëºÚÃûµ¥µÄ»¥ÁªÍø×ÊÔ´
ÕâÀà¶ñÒâÑù±¾Í¨³£ÊÇÓû§ÔÚä¯ÀÀÆ÷Öдò¿ªÒ»¸ö¶ñÒâ»òÊÜϰȾµÄÍøÒ³Ê±ÏÂÔØµÃÀ´¡£ÕâÐ©ÍøÒ³Òѱ»ÁÐÈëºÚÃûµ¥£¬Òò¶ø´óÎÞÊýÇé¿öϰ²È«²úƷͨ¹ý¼ì²âURL¼´¿É·¢ÏÖ¹¥»÷¡£ÕâÀà×ÊÔ´³£ÓÃÓÚ·Ö·¢Ä¾Âí¡¢¼äµýÈí¼þºÍÀÕË÷Èí¼þ£¬ÇÒͨ³£¼Ù×°³É¸÷³§¼Ò½ÚÔìÆ÷µÄÆÆ½â¹¤¾ß»òÃÜÂë³ÁÖù¤¾ß£¬Ò²¿ÉÄÜÊǼÙ×°³É¹¤Òµ/¹¤³ÌÈí¼þµÄÆÆ½â°æ»ò²¹¶¡¡£
- 8.7% - ¶ñÒâ¾ç±¾£¬ÍøÒ³³Á¶¨Ïò£¨JSºÍHTML£©£¬ÒÔ¼°ä¯ÀÀÆ÷·ì϶ÀûÓà ¨C 0.17%
- 6.36% - È䳿£¬Ô̺¬Í¨¹ý¿ÉÒÆ¶¯Ã½ÌåºÍÍøÂç¹²Ïí´«²¼µÄÈ䳿£¨Worm£©¡¢Í¨¹ýµç×ÓÓʼþ´«²¼µÄÈ䳿£¨Email-Worm£©¡¢Í¨¹ýÍøÂç·ì϶´«²¼µÄÈ䳿£¨Net-Worm£©ºÍ¼´Ê±Ì¸ÌìÀûÓÃÖеÄÈ䳿£¨IM-Worm£©¡£´ÓÍøÂç»ù´¡ÉèÊ©µÄ½Ç¶ÈÀ´¿´£¬´óÎÞÊýÈ䳿¶¼ÊǹýÆÚµÄ¡£
ÕâÒ»Àà±ðÖеļÒ×åÔ̺¬£º
- Worm.Win32.VBNA (0.2%)£¬³öÏÖÓÚ2009Äê¡£
- Worm.Win32.Vobfus (0.05%)£¬³öÏÖÓÚ2012Ä꣬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¨Zbot¡¢Fareit¡¢CutwailµÈ£©¡£
- Andromeda/Gamarue (0.69%)£¬¸Ã¶ñÒâÈí¼þ¹¹½¨µÄ¾ÞÐͽ©Ê¬ÍøÂçÓÚ2017Äê±»ÆËÃð¡£
ÓÈÆäÖµÍ×ÌùÐĵÄÊÇÒ»¸ö¹ýÆÚµ«¾¾Ã²»Ë¥µÄ¶ñÒâÈí¼þNetWorm.Win32.Kido(3.14%)¡£×Ô2010ÄêÎÊÊÀÒÔÀ´£¬ËüÒ»ÏòÊÇÅÅÃû×î¸ßµÄ¼ì²âÑù±¾Ö®Ò»¡£
´Ë±í£¬Ò²´æÔÚÏñWorm.Win32.Zombaque (0.02%)ÕâÑùµÄP2PÍøÂç¼Ü¹¹µÄÈ䳿£¬¹¥»÷ÕßÄܹ»ËæÊ±¼¤»îËüÃÇ¡£»¹´æÔÚʹÓÃHTTPºÍ̸µÄ»îÔ¾È䳿£¬ËüÃdz£ÓÉVBS±àд£¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¬ÀýÈçºóÃźͼäµýľÂíµÈ¡£
- 6.35% - ÔËÐÐÔÚä¯ÀÀÆ÷ÖеÄÍÚ¿óľÂí
0.76% - WindowsÍÚ¿óľÂí
- 5.78% - ¶ñÒâLNKÎļþ
ÕâÀàÑù±¾ÖØÒªÔÚ¿ÉÒÆ¶¯Ã½ÌåÉϼì²âµ½£¬³£×÷ΪÆäËü¶ñÒâÈí¼þ¼Ò×åµÄ´«²¼»úÔìµÄÒ»²¿ÃÅ£¬ÀýÈçAndromeda/Gamarue¡¢Dorkbot¡¢Jenxcus/DinihouµÈ¡£ÕâÒ»Àà±ð»¹Ô̺¬CVE-2010-2568£¨¸Ã·ì϶×îÔçÓÃÓÚ·Ö·¢ÕðÍø²¡¶¾£©·ì϶ÀûÓõÄLNKÎļþ£¨0.66%£©¡£¸Ã·ì϶»¹±»ÓÃÓÚ´«²¼Sality¡¢Nimnul/Ramnit¡¢ZeuSºÍVobfusµÈ¼Ò×å¡£
Ŀǰ£¬¼Ù×°³ÉºÏ·¨ÎĵµµÄLNKÎļþ±»ÓÃ×÷¶à½×¶Î´¹µö¹¥»÷µÄÒ»²¿ÃÅ£¬ÓÃÓÚÔËÐÐPowerShell¾ç±¾²¢ÏÂÔØ¶ñÒâpayload¡£ÔÚ¼«ÉÙÊýÇé¿öÏ£¬PowerShell¾ç±¾»áÏÂÔØÒ»¸öMetasploitÄ£¿é£¨MetasploitÖеÄTCPºóÃÅ£©µÄÌØ¶¨±äÌå¡£
- 2.85% - Ô̺¬exploits¡¢¶ñÒâºê»ò¶ñÒâÁ´½ÓµÄ¶ñÒâÎĵµ£¨MSOffice + PDF£©
- 2.31% - ϵͳÆô¶¯Ê±»ò²åÈë¿ÉÒÆ¶¯Ã½Ìåʱ×Ô¶¯ÔËÐеĶñÒâÎļþ£¨¿ÉÖ´ÐÐÎļþ¡¢¾ç±¾¡¢autorun.inf¡¢.LNKÎļþµÈ£©
ÕâÀàÑùÕý±¾×ÔÓÚ¶à¸ö¼Ò×壬µ«¶¼ÓÐÒ»¸ö¹²Í¬µã ¨C ×Ô¶¯ÔËÐС£Óк¦Ë®Æ½×îµÍµÄÑù±¾ÊÇʹÓÃÔ¤Ô¼ÒåµÄÖ÷Ò³×Ô¶¯Æô¶¯ä¯ÀÀÆ÷¡£ºÜ¶àʹÓÃautorun.infµÄ¼Ò×åÔÚÍøÂç»ù´¡ÉèÊ©·½Ãæ¶¼ÒѹýÆÚ£¨Palevo¡¢ SalityºÍ KidoµÈ£©¡£
- 2.28% - ²¡¶¾
ÕâÀ෨ʽÔ̺¬Virus.Win32.Sality (1.22%)¡¢Virus.Win32.Nimnul (0.87%)ºÍVirus.Win32.Virut (0.61%)¼Ò×壨ÒѳÖÐø¶àÄ꣩µÈ¡£Ö»¹ÜÕâЩ¼Ò×åµÄÍøÂç»ù´¡ÉèÊ©¶¼ÒÑʧЧ£¬µ«ÓÉÓÚ×ÔÎÒ´«²¼µÄ¸öÐÔºÍÆëÈ«×èÖ¹ËüÃǵݲȫ´ëÊ©µÄ²»¼°£¬ËüÃÇÈÔÔÚͳ¼ÆÊý¾ÝÖÐÕ¼¾Ý´óÍ·¡£
- 2% - ÀÕË÷Èí¼þ
- 1.26% - ÒøÐÐľÂí
- 0.9% - AutoCad¶ñÒâÈí¼þ
- 0.61% - Õë¶ÔÒÆ¶¯É豸µÄ¶ñÒâÎļþ£¨ÔÚÉ豸Ïνӵ½ÍÆËã»úʱ¼ì²âµ½£©
3.3 Õë¶ÔÆû³µÔì×÷ÒµµÄÍþвTop3
´ÓÕâ·Ý»ã±¨ÆðÍ·£¬ÎÒÃǽ«Ã¿Áù¸öÔ¶ÔÒ»¸öÐÐÒµµÄTop3Íþв½øÐзÖÎö¡£
µ«ÔÚ2018ÄêϰëÄ꣬¿¨°Í˹»ùµÄ²úÆ·×èÖ¹ÁË´óÁ¿Õë¶ÔÆû³µ¹¤³§×°ÅäÏߺÍÉ̵êÒÔ¼°Õë¶ÔÒ»¼¶¹©¸øÉ̹¤³§£¨Ô̺¬ÔËÐÐÆû³µÐÐÒµ¶àÖÖÈí¼þ²úÆ·µÄWindowsÍÆËã»ú£©µÄ¡°Í¨³£¡±¶ñÒâÈí¼þ¡£ÕâЩ¶ñÒâÈí¼þ×ÔÉí²¢²»ÊÇÕë¶ÔICS»·¾³µÄ£¬ËüÃÇÔ̺¬ÒÑÖªµÄ²¡¶¾¡¢ÍÚ¿óÈí¼þ¡¢³£¼ûµÄ¼äµýÈí¼þµÈ¡£Ö»¹ÜÕâЩ¶ñÒâÈí¼þµÄÖ÷ÕÅÊÇÔì³ÉÎïÀíÍøÂçµÄÇÖº¦£¬µ«Æä¸±×÷ÓÿÉÄÜ»á¶ÔICSºÍOTϵͳµÄ¿ÉÓÃÐÔºÍÆëÈ«ÐÔÔì³É³Á´óÓ°Ïì¡£
³ÁÒªµÄÊÇÒª¹Ø×¢½«À´¹¥»÷µÄDZÔÚ·çÏÕ£¬ÕâЩÍþвµÄ½Ã½ÝÐÔºÍÕë¶ÔÐÔ£¨¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷£©¼Ó¾çÁËÕâÒ»µã¡£
3.3.1 Sality½©Ê¬ÍøÂç
ÆäÖÐÒ»¸ö×î³£¼ûµÄÍþвÊÇSality£¬ËüÊÇÒ»¸ö³ÛÃûµÄÄ£¿é»¯¶à̬²¡¶¾/È䳿£¬×îÔç³öÏÖÓÚ2003Ä꣬²¢ÔÚ2015Ä껹ÔÚÊØ»¤¡£
ÔÚ´Óǰ£¬SalityµÄC&C·þÎñÆ÷ÓÃÓÚÏÂÔØÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¼°ÇÔÈ¡Óû§µÄÕË»§Í´´¦¡£µ«´Ë¿ÌÕâЩC&CÒѾ²»ÔÙ¿ÉÓ㬲¢ÇÒËùÓеÄSalityÑù±¾¶¼¿Éͨ¹ý³£¼ûµÄAV¼¼Êõ¼ì²âµ½¡£
Ö»¹ÜÈç´Ë£¬¸Ã¶ñÒâÈí¼þÈÔÔÚÈ«ÇòÍøÂç³ÖÐø´«²¼¡£¿¨°Í˹»ùÔÚÆû³µÐÐÒµµÄ´óÁ¿OTÍÆËã»úÉϼì²âµ½ÁËSality£¬ÎÒÃÇÒÔΪÏÖʵÊܵ½Ï°È¾µÄOTÍÆËã»úÊýÁ¿¸ü¶à¡£
SalityµÄ×ÔÎÒ´«²¼¸öÐÔʹµÃËü³ÉΪOT/ICS»ù´¡ÉèÊ©µÄÑϳÁÍþв£¬ËüÄܹ»´¥·¢»Ø¾ø·þÎñ¼°ÓÉÓÚ¶ñÒâÁ÷Á¿µ¼Ö±¾µØÍøÂçµÄ»úÄܽµÂä¡£
3.3.2 Bladabindi/njRAT½©Ê¬ÍøÂç
Õë¶ÔÆû³µÐÐÒµµÄÁíÒ»¸ö³Á´óÍþвÊÇBladabindi ¨C Ò»¸öÄ£¿é»¯µÄ¶àÖ°Äܽ©Ê¬ÍøÂç´úÀí£¬Æä´ó¾ÖÊDZàÒëºÃµÄÒ»×éAutoIT¾ç±¾¡£ËüµÄºóÃÅ/¼äµýÖ°Äܼ«¶È׳´ó£¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡¶àÖÖÃô¸ÐÐÅÏ¢¡£¸Ã½©Ê¬ÍøÂ绹ӵÓÐÀàËÆÈ䳿µÄÖ°ÄÜ£¬¿Éͨ¹ý¿ÉÒÆ¶¯Ã½Ìå´«²¼¡£
ËüµÄC&C·þÎñÆ÷´¦ÓÚ»îԾ״̬£¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢·Ö·¢ºÅÁîºÍÏÂÔØÏÂÒ»½×¶Î¶ñÒâÈí¼þ£¨¶ñÒâ¿ó¹¤¡¢DDoS´úÀí¡¢ÀÕË÷Èí¼þµÈ£©¡£¹¥»÷ÕßʹÓö¯Ì¬DNS¼¼ÊõÀ´Ìӱܼì²âºÍ¶ñÒâÈí¼þ·ÖÎö¡£ÓÉÓÚÖ°ÄÜ׳´ó£¬Bladabindi¿ÉÄܶÔOTÍøÂç²úÉú³Á´óÓ°Ïì¡£
3.3.3 AutoCAD½©Ê¬ÍøÂç
»ùÓÚAutoCADµÄ½©Ê¬ÍøÂçÊÇÓÉAutoLISP (FAS)ľÂí¹¹½¨µÄ£¬ÆäC&C·þÎñÆ÷³õ´Î³öÏÖÓÚ2013Äê¡£¸Ã½©Ê¬ÍøÂçÒÀÈ»Óɹ¥»÷Õß½øÐÐÊØ»¤¡£
FASľÂí»á´Û¸ÄAutoCADµÄÉèÖã¬Ê¹µÃÿ´ÎÓû§´ò¿ªAutoCAD¹¤³Ìʱ³ÇÊÐÖ´ÐиÃľÂí£¬ÕâÒ²µ¼ÖÂÿһ¸öн¨µÄÏîÄ¿³ÇÊÐÊܵ½Ï°È¾¡£
ÆäC&CÈÔ´¦ÓÚ»îԾ״̬,ÓÃÓÚÏòÊÜϰȾµÄÍÆËã»ú·Ö·¢ÏÂÒ»½×¶Î¶ñÒâÈí¼þ¡£µ±Ç°£¬ÒÑÖªµÄΨÖðÒ»¸öÕâÖÖpayloadµÄÑùÀýÊÇÒ»¸öVB¾ç±¾£¬¸Ã¾ç±¾ÓÃÓÚÅú¸Ää¯ÀÀÆ÷µÄÖ÷Ò³ÉèÖúͽ«ä¯ÀÀÆ÷µ¼º½ÖÁËÁÒâURL¡£
¸ÃľÂíÖØÒªÕë¶ÔÑÇÖÞ£¨ÓÈÆäÊÇÖйú£©µÄ¹¤ÒµºÍ¹¤³ÌÆóÒµ£¬²¢ÇÒ¿ÉÄܶÔOTÍøÂçÔì³ÉÑϳÁÓ°Ïì¡£
- ¸½¼þÖÐÔ̺¬Ä¾ÂíÏÂÔØÆ÷acad.fas£¨°µ²ØÔÚAutoCADÔìͼÖУ©µÄµç×ÓÓʼþ£¬¸ÃÓʼþÓɲ»ÊÜÒÉ»óµÄ³Ð°üÉÌ/·Ö°üÉ̺Ϸ¨¹¤³Ìʦ·¢ËÍ¡£
- ¹¥»÷Õß·¢Ë͵Ĵ¹µöÓʼþ£¬Í¬ÑùЯ´øÔ̺¬acad.fasµÄ¸½¼þ
- Я´øacad.fasµÄ¿ÉÒÆ¶¯Ã½Ì壨ÈçUÅÌ£©
- ±¾µØÍøÂçÉϵĹ²ÏíÎļþ£¨Ô̺¬°µ²ØµÄacad.fas£©
Ææ¹ÖµÄÊÇ£¬C&C·þÎñÆ÷¶ËµÄ´úÂë¶Ô´«ÈëµÄÒªÇó×öÁËһЩ²é³£¨ÀýÈçIPµØÖ·µÄ¹ú¶È¹ýÂË£©£¬ÈôÊDzé³Ê§°Ü£¬Ôò²»»á½»¸¶µÚ¶þºÍµÚÈý½×¶Îpayload£¨ÀýÈçIPµØÖ·µØµãµÄ¹ú¶È²»ÇкϹ¥»÷ÕßµÄÐËÖ£©¡£
µÚÈý½×¶ÎVB ¾ç±¾ÑùÀý
ËÄ¡¢Íþвͳ¼Æ
±¾»ã±¨ÖеÄͳ¼ÆÊý¾Ý¶¼ÊǾ¹ýÐí¿É´ÓKSNÓû§µÄÍÆËã»úÉÏÄäÃûÍøÂçµÃÀ´¡£
4.1 ×êÑв½Öè
¿¨°Í˹»ùICS CERT½«ÆóÒµÖеĹ¤Òµ»ù´¡ÉèÊ©¹éÀàΪICSÍÆËã»ú¡£ÓйØÍ³¼ÆÊý¾Ý´ÓÕâÒ»Àà´ËÍâÍÆËã»úÉÏÍøÂçµÃÀ´¡£ÕâÐ©ÍÆËã»úÔ̺¬ÔËÐÐÒÔÏÂÖ°ÄܵÄWindowsÍÆËã»ú£º
? Êý¾Ý´æ´¢·þÎñÆ÷£¨Historian£©£»
? Êý¾ÝÍø¹Ø£¨OPC£©£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÒÆ¶¯¹¤×÷Õ¾£»
? ÈË»ú½çÃæ£¨HMI£©¡£
»¹Ô̺¬´Ó¹¤¿ØÍøÂçÖÎÀíÔ±ÒÔ¼°¹¤Òµ×Ô¶¯»¯ÏµÍ³¿ª·¢ÈËÔ±µÄÍÆËã»úÉÏÍøÂçµ½µÄÊý¾Ý¡£
ÔÚ±¾»ã±¨ÖУ¬Ôâ·ê¹¥»÷µÄÍÆËã»úÊÇÖ¸Ôڻ㱨ÆÚ¼äGA»Æ½ð¼×°²È«½â¾ö¹æ»®ÖÁÉÙ±»´¥·¢Ò»´ÎµÄÍÆËã»ú¡£Ôâ·ê¹¥»÷µÄÍÆËã»úµÄ±ÈÀýÊÇÖ¸Ôâ·ê¹¥»÷µÄÍÆËã»ú£¨È¥³Á£©Õ¼ËùÓÐÑù±¾ÍÆËã»ú£¨Ôڻ㱨ÆÚ¼äÏòÎÒÃÇ·¢ËÍÁËÄäÃûÊý¾ÝµÄÍÆËã»ú£©µÄ±ÈÀý¡£
ͨ³£Çé¿öÏ£¬ÓÉÓÚ¹¤ÒµÍøÂçµÄÏÞ¶È£¬ICS·þÎñÆ÷ºÍ¹¤³Ìʦ/²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾²»ÊÇ24Ó×ʱÁªÍøµÄ¡£ÕâÀàÍÆËã»ú¿ÉÄÜÖ»ÔÚ£¬ÀýÈçÊØ»¤ÆÚ¼ä£¬ÄÜÁ¦ÁªÍø¡£
ϵͳ/ÍøÂçÖÎÀíÔ±¡¢¹¤³Ìʦ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³µÄ¿ª·¢ÈËÔ±ºÍ¼¯³ÉÈËÔ±µÄ¹¤×÷Õ¾¿ÉÄÜ»áʱʱÁªÍø£¬ÉõÖÁ¿ÉÄÜÊÇ24Ó×ʱÁªÍø¡£
Òò¶ø£¬2018ÄêϰëÄêGA»Æ½ð¼×Ñù±¾ÍÆËã»úÖÐÔ¼ÓÐ40%µÄÍÆËã»úÊǶ¨ÆÚ»òÈ«ÌìÁªÍøµÄ¡£ÆäÓà»úеµÄÁªÍø¹¦·ò²»³¬¹ýÒ»¸öÔ£¬ÆäÖкöàÊÇÔ¶Ô¶ÉÙÓÚÕâ¸ö¹¦·òµÄ¡£
4.2Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý
2017 vs 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý
Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý
2018ÄêÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©
2017 vs 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©
4.3 ¶ñÒâÈí¼þµÄÀà±ðÉ¢²¼
Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©
2017 ¨C 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©
4.4 µØÀíÉ¢²¼
2018ÄêϰëÄ꣬ICS¹¥»÷±ÈÀý×î¸ßµÄ¹ú¶È/µØÓò£¨Top 15£©
Óë2018ÄêÉϰëÄêÏà±È£¬ICS¹¥»÷±ÈÀý¹ú¶ÈÅÅÃûµÄǰÎåÃûûÓиĹۣ¬µ«Morocco£¨´Ë¿Ì´¦ÓÚµÚÈýÃû£©ºÍTunisia£¨µÚËÄÃû£©»¥»»Á˵ØÎ»¡£
2018ÄêϰëÄê¶íÂÞ˹Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÊÇ45.3%£¬ºÍÉϰëÄ꣨44.7%£©´¦ÓÚͳһˮƽ¡£¶íÂÞ˹µÄÅÅÃûÊǵÚ16Ãû¡£
2018ÄêϰëÄêICS¹¥»÷±ÈÀý×îµÍµÄ¹ú¶È/µØÓò
2018ÄêH1ºÍH2£¬ICS¹¥»÷±ÈÀýµÄµØÀíÇøÓòÉ¢²¼
4.5 ϰȾԴ
ICSÍÆËã»ú*µÄÖØÒªÍþвÆðÔ´£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©
* Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý
4.6 ÖØÒªÏ°È¾Ô´µÄµØÓòÉ¢²¼
2018ÄêϰëÄ꣬ICSÍÆËã»úÖØÒªÍþвÆðÔ´µÄµØÀíÉ¢²¼
4.6.1 »¥ÁªÍø
2018ÄêϰëÄ꣬»¥ÁªÍøÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15
4.6.2 ¿ÉÒÆ¶¯Ã½Ìå
2018ÄêϰëÄ꣬¿ÉÒÆ¶¯Ã½ÌåÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15
4.6.3 Óʼþ¿Í»§¶Ë
µÂ¹úÔÚµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄ¹ú¶È/µØÓòTop15ÖÐÉϰñ£¬ÖµÍ×ÌùÐĵÄÊǸùú¶ÈÔÚÆäËü·½Ã涼δÉϰñ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2018/90041/


¾©¹«Íø°²±¸11010802024551ºÅ