¡¾»ã±¨·ÖÏí¡¿¿¨°Í˹»ù - 2018ϰëÄêICSÍþв¾°¹Û

°ä²¼¹¦·ò 2019-04-26

Ò»¡¢2018ϰëÄêÖØÒª¹¥»÷ÊÂÎñ



1.1 Õë¶Ô¹¤ÒµÐÐÒµµÄAPT¹¥»÷


1.1.1 ·¸×ïÍÅ»ïLeafminerµÄAPT¹¥»÷


2018Äê8ÔÂÒ»·Ýл㱨Åû¶ÁË·¸×ïÍÅ»ïLeafminer£¨ÓÖ³ÆRASPITE£©µÄÍøÂç¼äµý»î¶¯¡£¸Ã×éÖ¯ÖØÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢Öж«ºÍ¶«ÑǵØÓòÈ·µ±¾Ö»ú¹¹ÒÔ¼°Ã³Ò׺͹¤Òµ¹«Ë¾ £¬ÆäÖ¸±êÐÐÒµÔ̺¬ÄÜÔ´¡¢µ±¾Ö¡¢½ðÈÚ¡¢º½Ô˺ÍÔËÊäµÈ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Leafminer¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©


¹¥»÷ÕßʹÓÃÁ˶àÖÖ¹«¿ª»ò¶¨ÔìµÄ¹¤¾ß¡¢exploitÒÔ¼°Ë®¿Ó¹¥»÷ºÍ×ֵ乥»÷ £¬ÀýÈçÓÀºãÖ®À¶µÄexploitºÍMimikatz±äÌå¡£


1.1.2 жñÒâÈí¼þGreyEnergy


Eset×êÑÐÈËÔ±»ã±¨ÁËÓë·¸×ïÍÅ»ïBlackEnergyÓйصĶàÆð¹¥»÷ÊÂÎñ £¬ÔÚÕâЩ¹¥»÷Öй¥»÷ÕßʹÓÃÁËÒ»¸öеĶñÒâÈí¼þGreyEnergy¡£BlackEnergyÏÈǰÒÑ´ÓAPT×êÑÐÈËÔ±µÄÀ×´ïÉÏÒþû £¬µ«ÕâÒ»´Î¹¥»÷ÕßÔÙ´ÎÏÖÉí £¬ÖØÒªÕë¶ÔÖÐÅ·ºÍ¶«Å··ÖÆçÒµÒµµÄ¹¤ÒµÍøÂç £¬Ô̺¬ÄÜÔ´¹«Ë¾¡¢ÔËÊ乫˾µÈ £¬²¢³Áµã¹Ø×¢ÕƹÜÔËÓª¹Ø¼ü»ù´¡ÉèÊ©µÄÆóÒµ¡£


×êÑÐÈËÔ±·¢ÏÖGreyEnergyÓë2015ÄêBlackEnergyÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄ¶ñÒâÈí¼þ´æÔÚ¸ÅÏëÉϵÄÀàËÆÖ®´¦¡£´Ë±í £¬×êÑÐÈËÔ±»¹·¢ÏÖGreyEnergyÓë·¸×ïÍÅ»ïTeleBotsµÄ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£TeleBotsÒÔ¶àÆð´ó¹æÄ£¹¥»÷ÊÂÎñÎÅÃû £¬ÀýÈç2017ÄêµÄNotPetyaºÍBadRabbit¡£¿¨°Í˹»ù×êÑÐÈËÔ±Ëæºó·¢ÏÖGreyEnergy»¹ÓëSofacy£¨¼´APT28£©µÄ×ÓÍÅ»ïZebrocy´æÔÚ¹ØÁª¡£


GreyEnergyÓµÓÐÄ£¿é»¯µÄϵͳ½á¹¹ £¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ý¼ÓÔØÓйØDLLÀ´×éºÏ·ÖÆçµÄ¶ñÒâÈí¼þÖ°ÄÜ¡£Ä³Ð©Çé¿öÏ £¬ÕâЩ¶ñÒâÄ£¿é´ÓC&C·þÎñÆ÷ÏÂÔØ²¢Ö±½Ó¼ÓÔØ½øÄڴ棨²»Ð´Èë´ÅÅÌÎļþ £¬¼´ÎÞÎļþ¹¥»÷£©¡£GreyEnergy¿ÉÍøÂçÊܺ¦ÕßµÄÍ´´¦ÒÔÉøÈ빤¿ØÍøÂç¡£¸Ã×éÖ¯µÄ¹¤¾ß°ü»¹Ô̺¬¿ªÔ´¹¤¾ßMimikatz¡¢PsExec¡¢WinExeºÍNmapµÈ¡£


GreyEnergyµÄ³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ¼°ÆóÒµµÄ¹«¹²ÍøÂç×ÊÔ´ £¬µ±È»ºÜÓпÉÄÜ»¹Ô̺¬ÆäËü¹¥»÷ÏòÁ¿¡£


ÔÚ֮ǰµÄ¹¥»÷»î¶¯ÖÐ £¬¸Ã×éÖ¯ÔøÀûÓÃGE CimplicityÖеķì϶£¨CVE-2014-0751£©ÔÚHMI·þÎñÆ÷ÉÏÖ´ÐжñÒâ.cimÎļþ £¬²¢×îÖÕ×°ÖÃBlackEnergy¡£Æ¾¾Ý¿¨°Í˹»ùµÄ×êÑÐ £¬¸Ã×éÖ¯»¹ÔøÔÚ2014ÄêÀûÓÃÎ÷ÃÅ×ÓWinCCÖеķì϶£¨CVE-2014-8551£©À´ÉøÈëÖ¸±êÍøÂç¡£ÔÚ×î½üµÄ¹¥»÷Öи÷ìÏ¶Ò²Ôø±»ÀûÓá£


´Ë±í £¬´Óǰ¸Ã×éÖ¯ÔøÈëÇÖÖ¸±êÆóÒµµÄ·ÓÉÆ÷²¢×°Öø÷Àà¶ñÒâÄ£¿éºÍ¾ç±¾ £¬ÒÔ½øÐкáÏòÒÆ¶¯¡£ÔÚ×î½üµÄGreyEnergy¹¥»÷ÖÐÉÐδ·¢ÏÖÕâÖÖÐÐΪ £¬µ«¸ÃÐÐΪºÜ¿ÉÄÜ´æÔÚ £¬ÓÉÓڸù¥»÷ÏòÁ¿¶Ô¹¥»÷Õß¼«¶ÈÓÐÀû £¬¿ÉÓÃÓÚ¶¨ÆÚÍøÂç¸÷¸ö·ÓÉÆ÷ÐͺŴæÔڵķì϶ÐÅÏ¢ £¬Ô̺¬0day¡£


1.1.3 ¹¥»÷»î¶¯Sharpshooter


2018Äê12ÔÂMcAfee¼ì²âµ½Ò»¸öÕë¶ÔÈ«Çò¹ú·À³Ð°üÉÌ¡¢ºËÄÜÐÐÒµÒÔ¼°½ðÈÚÐÐÒµµÄ¹¥»÷»î¶¯Sharpshooter¡£×êÑÐÈËÔ±³ÆSharpshooterµÄÖØÒªÖ÷ÕÅÊǽøÐмäµý»î¶¯¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SharpshooterµÄÖ¸±êÐÐÒµºÍ¹ú¶ÈÉ¢²¼£¨ÆðÔ´£ºMcAfee£©


ϰȾÁ´Ê¼ÓÚÔ̺¬¶ñÒâºêµÄMicrosoft WordÎĵµ¡£¸Ã¶ñÒâºê×÷Ϊһ¸öµäÐ͵Ädownloader £¬ÓÃÓÚ½»¸¶¶ñÒâÖ²ÈëÎï¡£¹¥»÷Õßͨ¹ýDropboxÀ´·Ö·¢ÊÜϰȾµÄÎļþ¡£¸ÃÖ²ÈëÎÃûΪRising Sun£©ÊÇÒ»¸öеÄÄ£¿é»¯ºóÃÅ £¬Ö»ÔÚÄÚ´æÖÐÔËÐÐ £¬ÖØÒªÍøÂçÓû§Êý¾Ý £¬Ô̺¬ÍÆËã»úÃû³Æ¡¢IPµØÖ·¡¢ÏµÍ³ÐÅÏ¢µÈ¡£ÍøÂçµ½µÄÊý¾Ý±»¼ÓÃÜ´«ÊäÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¿¨°Í˹»ù×êÑÐÈËÔ±ÒÔΪ·¸×ïÍÅ»ïLazarusÓëÕâЩ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£


1.1.4 ¹¥»÷»î¶¯MuddyWater


2018Äê12Ô³õÈüÃÅÌú¿Ë»ã±¨ÁË·¸×ïÍÅ»ïMuddyWater£¨ÓÖ³ÆSeedÈ䳿£©µÄ¼äµý¹¥»÷»î¶¯¡£¹¥»÷ÕßÖØÒªÕë¶ÔÖж«¡¢Å·Ö޺ͱ±ÃÀµØÓòµÄÆóÒµ¡£Æ¾¾ÝÕâÏî×êÑÐ £¬2018Äê9ÔÂÄ©ÖÁ11ÔÂÖÐÑ®ÆÚ¼ä¹²ÓÐ30¼ÒÆóÒµµÄ130ÃûÔ±¹¤Êܵ½¹¥»÷ £¬´óÎÞÊýÊܺ¦ÕßλÓÚ°Í»ù˹̹ºÍÍÁ¶úÆä £¬»¹ÓÐÉÙÊýÊܺ¦ÕßλÓÚ¶íÂÞ˹¡¢É³Ìذ¢À­²®¡¢°¢¸»º¹¡¢Ô¼µ©µÈ¹ú¶È¡£¹¥»÷ÕßÖØÒª¶Ô×¼µÄÖ¸±êÖ®Ò»ÊÇÓÍÆøÐÐÒµ¡£Öж«µØÓòµÄ´óѧºÍÅ·ÖÞµÄÖж«´óʹ¹ÝͬÑùÔâµ½¹¥»÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MuddyWater¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©


1.1.5 ¹¥»÷»î¶¯Cloud Hopper


2018Äê12ÔÂÖÐÑ® £¬µÂ¹úÁª¹úÐÅÏ¢°²È«°ì¹«ÊÒ£¨BSI£©ÏòһЩµÂ¹úÆóÒµ°ä²¼Á˾ݳÆÓëAPT10ÓйصÄCloudHopper¹¥»÷¾¯±¨¡£BSI³Æ¶à¼Ò´óÐ͹¤³ÌÆóÒµÒѾ­Ôâµ½¹¥»÷ £¬¹¥»÷Õß»¹¶Ô¹¹ÖþºÍ×ÊÁÏѧÁìÓòµÄÆóÒµ¸ÐÐËÖ¡£


¹¥»÷Õß²¢Ã»ÓÐÖ±½Ó¹¥»÷Ö¸±êÆóÒµ £¬¶øÊÇͨ¹ýÉøÈëÖ¸±êÆóҵʹÓõÄÓ×ÐÍÔÆ·þÎñºÍÍйܷþÎñ¹©¸øÉÌÌáÒé¹¥»÷¡£ÕâÀ๩¸øÉÌͨ³£°²È«ÐԽϲî £¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÉøÈëÖ¸±ê¹«Ë¾µÄÆóÒµÍøÂç¡£


1.1.6 ¶ñÒâÈí¼þShamoon v.3


2018Äê12ÔÂ10ÈÕ £¬Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SiapemÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷ÕßÖØÒªÕë¶Ô¸Ã¹«Ë¾Î»ÓÚÖж«¡¢Ó¡¶È¡¢ËÕ¸ñÀ¼ºÍÒâ´óÀûµÄ·þÎñÆ÷ £¬Ê¹ÓõĶñÒâÈí¼þÊÇShamoonÈ䳿µÄбäÌåShamoon v.3¡£Ô¼ÓÐ300µ½400̨·þÎñÆ÷¼°100̨¹¤×÷Õ¾ÔÚÕâ´Î¹¥»÷ÊÂÎñÖÐÊܵ½Ó°Ïì¡£


ÔÚSaipem°ä²¼ÉêÃ÷Ö®ºó £¬ÈüÃÅÌú¿Ë·¢ÏÖÏÕЩÔÚͳһ¹¦·ò»¹ÓÐÁ½¼ÒλÓÚÉ³ÌØ°¢À­²®ºÍ°¢ÁªÇõµÄʯÓͺÍÌìÈ»Æø¹«Ë¾Ôâµ½ÀàËÆµÄ¹¥»÷¡£


ShamoonÈ䳿³õ´Î³öÏÖÓÚ2012ÄêÕë¶ÔÉ³ÌØ°¢À­²®¹ú¶ÈʯÓ͹«Ë¾AramcoºÍ¿¨Ëþ¶ûÌìÈ»Æø¹«Ë¾RasgasµÄ¹¥»÷»î¶¯ÖС£ÔÚ2016-2017ÄêµÄÐÂÒ»ÂÖ¹¥»÷ÖÐ £¬¹¥»÷ÕßʹÓÃÁËShamoonµÄ±äÖÖ£¨Shamoon v2£©ºÍ¶ñÒâÈí¼þStoneDrill¡£


ÔÚ2018ÄêµÄ¹¥»÷»î¶¯ÖÐ £¬Åã°é×ÅShamoon v.3³öÏֵϹÓÐÐÂÊý¾Ý²Á³ýÆ÷Filerase¡£Filerase¿É²Á³ý£¨¸²Ð´£©ÊÜϰȾϵͳÉϵÄÎļþ¡£2018ÄêµÄShamoon¹¥»÷»î¶¯ÓÉÓÚʹÓÃÁËFilerase¶ø¸ü¾ß·ÛËéÐÔ¡£ShamoonÄܹ»²Á³ýÊÜϰȾϵͳµÄÖ÷Êèµ¼¼Í¼£¨MBR£© £¬µ«Ó²ÅÌÉϵÄÎļþ¿É±»¸´Ô­ £¬¶øÊ¹ÓÃÁËFileraseÖ®ºóÈκÎÎļþ¶¼²»³É¸´Ô­¡£


FileraseÓµÓÐÄ£¿é»¯½á¹¹ £¬Ô̺¬¶à¸öÓÃÓÚÔÚ±¾µØÍøÂçÉϽøÐд«²¼µÄ×é¼þ¡£ÕâÒâζ×ÅFilerase×ÔÉíÄܹ»×÷Ϊһ¸öµ¥¶ÀµÄÍþв¡£FileraseÔÚÊܺ¦Õߵı¾µØÍøÂçÉÏ´«²¼Ê± £¬ÒÀÀµÒ»¸öÖ¸±êÃûµ¥À´°Îȡָ±ê¡£ÔÚ³õʼϰȾ¹ý³ÌÖÐ £¬¸ÃÃûµ¥ÊÇÓÉOCLC.exe×é¼þ¸´ÔìµÄ £¬²¢·¢Ë͸øSpreader.exe¹¤¾ß £¬ºóÕß½«Filerase¸´Ôìµ½Ãûµ¥ÉϵĻúе¡£¸ÃÃûµ¥ÊÇÒ»¸öÔ̺¬·ÖÆçÊܺ¦ÕßÃû×ÖµÄÎı¾Îļþ £¬ÕâЩÃû×ÖºÜÓпÉÄÜÊǹ¥»÷ÕßÔÚ¹¥»÷µÄÔçÆÚ½×¶ÎÍøÂçµÄ¡£


McAfeeµÄ×êÑÐÈËÔ±ÒÔΪShamoon v3¹¥»÷»î¶¯¿ÉÄÜÓëÒÁÀÊ·¸×ïÍÅ»ïAPT33ÓйØ £¬»òÊÇÁí±íÒ»¸ö·¸×ïÍÅ»ï¼Ù×°³ÉAPT33¡£ÈüÃÅÌú¿Ë×êÑÐÈËÔ±³ÖÒ»Ñù¶¨¼û¡£


2018Äê12Ôµ× £¬Anomali Labs»ã±¨ÁËShamoonµÄÁíÒ»¸ö±äÌå £¬¸Ã±äÌåÓÚ12ÔÂ23ÈÕ±»ÉÏ´«ÖÁVirusTotal¡£¸Ã±äÌå¼Ù×°³É°Ù¶È¹«Ë¾µÄÒ»¸öϵͳÅäÖúÍÓÅ»¯¹¤¾ß½øÐд«²¼¡£

1.2ÍøÂç·¸×ï»î¶¯


1.2.1 ÀÕË÷Èí¼þ¹¥»÷


ƾ¾Ý¿¨°Í˹»ùµÄÊý¾Ý £¬Ôâ·êÀÕË÷Èí¼þ¹¥»÷µÄICSÍÆËã»ú±ÈÀý´Ó1.6%ÉÏÉýÖÁ2%¡£


WannaCryÈÔ¾ÉÊǹ¤ÒµÆóÒµÃæ¶ÔµÄÒ»¸öÕæÊµµÄÍþв £¬Ò²ÊÇÒ»¸ö³£¼ûµÄÍþв¡£Æ¾¾Ý¿¨°Í˹»ùµÄÊý¾Ý £¬WannaCry£¨28.72%£©ÊÇÀÕË÷Èí¼þÍþвÖеÄÁìÍ·Ñò£¨2018ÄêµÚÈý¼¾¶È£©¡£¼´±ãÊÇÔÚ´ó¹æÄ£·¢×÷µÄÒ»ÄêÖ®ºó £¬WannaCryÈԾɳÖÐøÏ°È¾¹¤ÒµÆóÒµµÄICSÍøÂç £¬ÀýÈç £¬2018Äê8ÔÂ3ÈǪ̃»ýµç£¨TSMC£©µÄ¶à¼Ò¹¤³§Ôâµ½WannaCry¹¥»÷¡£Æ¾¾ÝÏÖÓÐÐÅÏ¢ £¬Ï°È¾ÊÇÓÉÒ»¸ö¹©¸øÉÌÔÚгö²ú¹¤¾ßÉÏ×°ÖÃÁËÊÜËðÈí¼þµ¼Öµģº¸Ã¹©¸øÉ̲¢Î´½øÐÐÈκΰ²È«É¨Ãè¾Í½«Èí¼þÁ¬Èë³ö²úÍøÂç £¬µ¼Ö¶ñÒâÈí¼þÔŲ́ÄÏ¡¢ÐÂÖñºĮ́ÖеĶà¼Ò¹¤³§Ö®¼äѸ¿ì´«²¼ £¬Ì¨Í幤³§µÄ³ö²ú±»ÆÈÖжÏÁË3Ìì¡£


ÆäËü¹¥»÷ÊÂÎñ»¹Ô̺¬2018Äê11ÔÂ28ÈÕĪ˹¿ÆÀ³µ¹«Ë¾£¨MCC£©Ôâµ½µÄÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾³ÆÔÚ¹¥»÷ÆÚ¼äÆäÖØÒªµçÄÔϵͳÉϵÄÎļþ¾ù±»¼ÓÃÜ £¬Ô±¹¤Ñ¸¿ìÖÕ³¡ÁËÀ³µ²¢·ÖÉ¢Á˳˿Í¡£¹¥»÷ÕßÒªÇóÖ§¸¶±ÈÌØ±Ò²Å»á½âÃÜ¡£¸Ã¹«Ë¾ÔÚÁ½Ììºó¸´Ô­ÁËÔËÓª¡£

1.2.2 Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷


2018Äê8Ô £¬¿¨°Í˹»ùICS CERT°ä²¼Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷µÄµ÷²éÁ˾Ö¡£¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇ´Ó¹«Ë¾µÄÕË»§ÖÐÇÔÈ¡½ðÇ®¡£


¹¥»÷ʼÓÚ2017Äê11Ô £¬²¢ÇÒÈÔÔÚ³ÖÐø¡£¹¥»÷ÕßÖØÒª·¢ËͼÙ×°³ÉºÏ·¨Ã³Ò×±¨¼ÛµÄ´¹µöÓʼþ £¬ÓʼþÖеĶñÒ⸽¼þÊÜÃÜÂë±£»¤ £¬¶øÃÜÂ븽ÔÚÓʼþÄÚÈÝÖС£ÕâÀàÓʼþ×ÔÉí¾­¹ý¸ß¶È¼Ù×° £¬ÇкϹ«Ë¾µÄÒµÎñÇé¿ö¡£ÔÚ×î½üµÄÒ»²¨¹¥»÷ÖÐ £¬´¹µöÓʼþ¼Ù×°³ÉÊܺ¦ÆóÒµµÄºÏ×÷ͬ°é¡£¶ñÒ⸽¼þÖеľ籾½«ÔÚϵͳÉÏ×°ÖöñÒâÈí¼þ £¬¶øºóÏνӵ½¹¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷²¢ÏÂÔØÖ®Ç°ÍµÇԵĺϷ¨Îĵµ¡£


¹¥»÷Õß»áÔÚÊÜϰȾµÄϵͳÉÏ×°ÖúϷ¨µÄÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©- ÈçTeamViewerºÍRMS¡£µ«¶ñÒâÈí¼þ»á°µ²ØÕâЩRATµÄͼÐνçÃæ £¬ÒÔÔÚÓû§²»ÖªÇéµÄÇé¿öϽÚÔìÊÜϰȾµÄ»úе¡£


¹¥»÷Õß½ø¶øËÑË÷ϵͳÉϵIJÆÕþºÍ¹ÜÕÊÈí¼þ £¬²¢²éÕҺͷÖÎöÓë²É¹ºÓйصÄÕÊÄ¿Îĵµ¡¢ºÏ×÷É̵ÄÓʼþµØÖ·ÒÔ¼°ÓëºÏ×÷É̵ÄͨѶÍùÀ´ £¬¶øºó½øÒ»²½ÀûÓÃÕâЩ˽º±¼û¾Ý½øÐвÆÕþڲƭ £¬ÀýÈçÅú¸Ä¶©µ¥ÖеÄÒøÐп¨Õ˺ŵÈ¡£


¸ü½øÒ»²½µØ £¬¹¥»÷Õß»áÔÚ±ØÒªµÄÇé¿öÏÂ×°Öøü¶àµÄ¶ñÒâÈí¼þ£¨ÒÀÊܺ¦Õß·ÖÆç¶ø·ÖÆç£© £¬ÀýÈçͨ¹ý¼äµýÈí¼þºÍMimikatzÇÔÈ¡Éí·ÝÑé֤ʹ´¦ £¬¶øºóϰȾÆóÒµÍøÂçÖеĸü¶à»úе¡£·¸×ï·Ö×Ó»¹Ê±Ê±½«¶ñÒâÈí¼þµÄ×é¼þ¼Ù×°³ÉWindowsϵͳ×é¼þ £¬ÒÔ°µ²Ø¶ñÒâ»î¶¯µÄ×ÙÓ°¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷Á÷³ÌµÄÕûÌåʾÒâͼ


¿¨°Í˹»ùICS CERTÒÔΪÕâЩ¹¥»÷ºÜÓпÉÄÜÊÇÓɶíÓï¹¥»÷ÕßÌáÒéµÄ¡£


1.2.3 Õë¶ÔÈ«ÇòÆóÒµµÄ´¹µö¹¥»÷


2018Äê10ÔÂYoroi CERT¼ì²âµ½¼¸ÆðÕë¶ÔÒâ´óÀûˮʦºÍ¹ú·ÀÆóÒµµÄ¹¥»÷»î¶¯¡£Ö¸±êÆóÒµµÄÔ±¹¤½Ó¹Üµ½Ð¯´ø¶ñÒâExcelÎļþµÄ´¹µöÓʼþ¡£¸Ã¶ñÒâExcelÖ¼±ÉÈËÔØRATľÂíMartyMcFly £¬¹¥»÷Õß¿ÉÀûÓøÃľÂí½ÚÔìÖ¸±ê»úе¼°ÇÔÈ¡Êý¾Ý¡£´Ë±í £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÁíÒ»¸öÔ¶³ÌÖÎÀí¹¤¾ßQuasarRAT£¨Ô´´úÂëÔÚgithubÉÏ¿ÉÓ㩵ıäÌå¡£


ƾ¾Ý¿¨°Í˹»ùICS CERTµÄ˵·¨ £¬Yoroi»ã±¨ÖÐÌáµ½µÄ´¹µöÓʼþÒÔ·ÖÆçµÄÃû³ÆÔÚÈ«ÊÀ½çÁìÓòÄÚ´«²¼ £¬Ö¸±ê¹ú¶ÈÔ̺¬µÂ¹ú¡¢Î÷°àÑÀ¡¢±£¼ÓÀûÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ó¡¶È¡¢ÂÞÂíÄáÑǵÈ¡£Ö¸±êÆóÒµº­¸Ç¶à¸ö´¹Ö±ÐÐÒµ £¬´Ó¶¹À๩¸øÉ̵½Õ÷ѯ¹«Ë¾¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´¹µöÓʼþÖжñÒâxlsxÎļþµÄÉ¢²¼£¨ÆðÔ´£ºKSN£©


¿¨°Í˹»ùICS CERTÒÔΪ £¬Õâ´Î¹¥»÷ÊÇÓÉÕë¶Ô¶à¸öÆóÒµ£¨ÓÐʱÔ̺¬¹Ø¼ü»ù´¡ÉèÊ©£©½øÐдó¹æÄ£´¹µö¹¥»÷µÄÒ»Ñù·¸×ïÍÅ»ïÌáÒéµÄ¡£ÕâЩÍÅ»ïרһÓÚÇÔÈ¡½ðÇ®ºÍ²ÆÕþÊý¾Ý¡£



¶þ¡¢2018ÄêICS·ì϶ͳ¼Æ



ICS×é¼þÖеķì϶


±¾Ó×½ÚÖеķì϶·ÖÎöÊÇ»ùÓÚ³§É̲¼¸æ¡¢¿ªÔ´·ì϶¿â£¨US ICS-CERT¡¢CVE¡¢Î÷ÃÅ×Ó CERT£©µÄ¹«¿ªÐÅÏ¢ÒÔ¼°¿¨°Í˹»ùICS CERTµÄ×êÑÐÁ˾ֽøÐеÄ¡£US ICS-CERTÍøÕ¾ÉϵÄ2018Äê·ì϶ÐÅÏ¢±»ÓÃ×÷ͳ¼ÆÊý¾ÝµÄÆðÔ´¡£


2.1 ·ì϶ÊýÁ¿


2018Äê £¬US ICS-CERTÍøÕ¾ÉÏÅû¶µÄICS·ì϶ÊýÁ¿Îª415¸ö ¨C ±È2017Äê¶àÁË93¸ö¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


US ICS-CERTÅû¶µÄICS·ì϶ÊýÁ¿


2.2 ÐÐҵɢ²¼


ICS·ì϶ÊýÁ¿×î¶àµÄÐÐÒµÊÇÔì×÷Òµ£¨115£©¡¢ÄÜÔ´Òµ£¨110£©¼°¹©Ë®ÏµÍ³£¨63£©¡£´Ë±í £¬Ê³Æ·¼Ó¹¤/ũҵ£¨49£©ºÍ»¯Ñ§Òµ£¨44£©Ò²ÅÅÔÚǰÁС£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 

2018ÄêICS·ì϶µÄÐÐҵɢ²¼£¨»ùÓÚUS ICS-CERTµÄ·ÖÀࣩ


2.3 ·ì϶ÑϳÁÐÔÉ¢²¼


³¬¹ýÒ»°ëµÄICS·ì϶£¨284¸ö £¬2017ÄêΪ194¸ö£©µÄCVSS v.3.0ÆÀ·Ö¸ßÓÚ7·Ö £¬¼´Îª¸ßΣ£¨high£©»òÑϳÁ£¨critical£©·ì϶¡£

ÑϳÁÐÔÆÀ·Ö

9 - 10 (ÑϳÁ)

7 - 8.9 (¸ßΣ)

4 - 6.9 (ÖÐΣ)

0 - 3.9 (µÍΣ)

ICS·ì϶ÊýÁ¿

92

192

128

3



±í1 ¨C ICS·ì϶µÄÑϳÁÐÔÉ¢²¼

ÓëǰһÄêµÄÊý¾ÝÏà±È £¬¸ßΣ¼°ÑϳÁ·ì϶µÄ±ÈÀýÓÐËùÔö³¤¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2017 vs 2018 £¬ICS·ì϶µÄÑϳÁÐÔÉ¢²¼£¨»ùÓÚCVSS v3ÆÀ·Ö£©


ÒÔϲúÆ·ÖÐÔ̺¬ÆÀ·ÖΪ10·ÖµÄ·ì϶£º


  • Siemens TIM 1531 IRC Modules
  • Siemens SINUMERIK Controllers
  • Circontrol CirCarLife
  • NUUO NVRmini2 and NVRsolo
  • Emerson AMS Device Manager
  • Rockwell Automation RSLinx Classic
  • Schneider Electric U.motion Builder
  • Martem TELEM-GW6/GWM


´óÎÞÊýÆÀ·ÖΪ10·ÖµÄ·ì϶¶¼ÊÇÉí·ÝÑéÖ¤»ò»º³åÇøÒç³öÎÊÌâ¡£


Ó¦¸Ã°ÑÎȵÄÊÇ £¬CVSSÆÀ·Ö²¢Î´Ë¼¿¼µ½ICSÏµÍ³ÌØÓеݲȫÐÔºÍ·ÖÆçÆóÒµ¹¤ÒµÁ÷³ÌµÄ²î¾àÐÔ £¬Òò¶øÔÚÆÀ¹ÀICS·ì϶µÄÑϳÁÐÔʱ £¬ÎÒÃǽ¨Òé³ýÁËCVSSÆÀ·ÖÖ®±í»¹Òª¹Ø×¢·ì϶ÀûÓõĿÉÄܺó¹û £¬ÀýÈçµ¼Ö¹¤ÒµÁ÷³ÌµÄÖжϻò²¿ÃÅÖжϵÈ¡£

2.4 ÀàÐÍÉ¢²¼


×î³£¼ûµÄICS·ì϶ÀàÐÍÊÇ»º³åÇøÒç³ö£¨Õ»»º³åÇøÒç³ö¡¢¶Ñ»º³åÇøÒç³ö¡¢µäÐÍ»º³åÇøÒç³ö£©¼°²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£Í¬Ê± £¬16%µÄ·ì϶ÊÇÉí·ÝÑéÖ¤ÎÊÌ⣨²»ÕýÈ·µÄÉí·ÝÑéÖ¤¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢¹Ø¼üÖ°ÄÜȱʧÉí·ÝÑéÖ¤£©ºÍ½Ó¼û½ÚÔìÎÊÌ⣨½Ó¼û½ÚÔì¡¢²»ÕýÈ·µÄĬÈÏȨÏÞ¡¢²»ÕýÈ·µÄȨÏÞÖÎÀí¡¢Í´´¦ÖÎÀí£© £¬10%µÄ·ì϶ÊÇWebÓйطì϶£¨×¢Èë¡¢õè¾¶±éÀú¡¢CSRF¡¢XSS¡¢XXE£©¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêICS·ì϶ÀàÐ͵ÄÉ¢²¼

ÓëǰһÄêÏà±È £¬»º³åÇøÒç¶Âí½ÅµÄ±ÈÀýÏÔÖøÔö³¤¡£ÎÒÃÇÒÔΪÕâÓ밲ȫ×êÑÐÈËÔ±¶ÔICS×é¼þÖеķì϶ԽÀ´Ô½¸ÐÐËÖÂÓйØ £¬Ò²ÓëfuzzingµÈ×Ô¶¯»¯²âÊÔ¼¿Á©µÄʹÓÃÓйØ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

2017 vs 2018, ICS·ì϶ÀàÐ͵ÄÉ¢²¼


¹¥»÷Õß¿ÉÀûÓÃICS×é¼þÖеķì϶´¥·¢ËÁÒâ´úÂëÖ´ÐÓ×¢¹¤ÒµÉ豸µÄδÊÚȨ½ÚÔì¼°»Ø¾ø·þÎñ£¨DoS£©¡£³ÁÒªµÄÊÇ £¬´óÎÞÊý·ì϶£¨342¸ö£©¿É±»Ô¶³ÌÀûÓà £¬²¢ÇÒÎÞÐèÉí·ÝÑéÖ¤ºÍרҵ֪ʶ/¸ß¼¶¼¼Êõ¡£Æ¾¾ÝUS ICS-CERTµÄÊý¾Ý £¬23¸ö·ì϶µÄexploit¹«¿ª¿ÉÓà £¬ÕâÔö³¤ÁËËüÃDZ»¶ñÒâÀûÓõķçÏÕ¡£

2.5 ÊÜÓ°ÏìµÄICS×é¼þÉ¢²¼


·ì϶ÊýÁ¿×î¶àµÄICS×é¼þÔ̺¬£º


  • ¹¤³ÌÈí¼þ£¨143¸ö£©
  • SCADA/HMI×é¼þ£¨81¸ö£©
  • רΪ¹¤Òµ»·¾³Éè¼ÆµÄÍøÂçÉ豸£¨66¸ö£©
  • PLC£¨47¸ö£©


ÊÜÓ°ÏìµÄICS×é¼þ»¹Ô̺¬¹¤ÒµÍÆËã»úºÍ·þÎñ£¨5%£©¡¢¹¤ÒµÊÓÆµ¼à¿ØÏµÍ³£¨4%£©¡¢¸÷Àೡ¼¶É豸ºÍ±£»¤¼ÌµçÆ÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 
2018ÄêICS·ì϶ӰÏìµÄ×é¼þÉ¢²¼

2.6 ¹¤³ÌÈí¼þÖеķì϶


Ò×Êܹ¥»÷µÄ¹¤³ÌÈí¼þÔ̺¬·ÖÆçµÄHMI/SCADA¿ª·¢Æ½Ì¨¡¢½ÚÔìÆ÷±à³Ì¹¤¾ßµÈ¡£

¹¤³ÌÈí¼þÖеݲȫÎÊÌâͨ³£ÊÇÓɵÚÈý·½Èí¼þµ¼ÖµÄ¡£ÓÉÓÚµÚÈý·½×é¼þµÄ¿í·ºÊ¹Óà £¬Ò»µ©³öÏÖ·ì϶¾Í»áÓ°Ïì´óÁ¿¹¤Òµ²úÆ·¡£ÀýÈç £¬Î÷ÃÅ×ÓÂ¥Óî¿Æ¼¼²úÆ·ºÍÎ÷ÃÅ×ÓSIMATIC WinCC²å¼þÓÉÓÚ¼¯³ÉÁËÔ̺¬·ì϶µÄSentinel LDK RTElicenseÖÎÀíÆ÷¶øÒ×Êܹ¥»÷¡£´Ë±í £¬Î÷ÃÅ×ÓµÄÕû¸ö¹¤Òµ²úÆ·Ïß¶¼Êܵ½OpenSSL·ì϶µÄÓ°Ïì¡£ÀàËÆµØ £¬×÷ΪFloating License ManagerµÄÒ»²¿ÃÅ £¬Flexera PublisherÈí¼þÖеķì϶ͬʱӰÏìÁËÊ©Ä͵µĶà¸öµçÆø²úÆ·¡£


´Ë±í £¬Ó¦³ö¸ñ°ÑÎÈÓÃÓÚ½Ó¼ûICSϵͳµÄÒÆ¶¯APP£¨Android»òiOSƽ̨µÄÖÇÄÜÊÖ»ú¡¢Æ½°åµÈ£©¡£Ò×Êܹ¥»÷µÄ´ËÀà²úÆ·°¸ÀýÔ̺¬SIMATIC WinCC OA iOS App¡¢IGSS Mobile¡¢SIMATIC WinCC OA UIMobile App¡¢General Motors¼°OnStar (SOS) iOS¿Í»§¶Ë¡£´ËÀàÒÆ¶¯APPÔ½À´Ô½¶àµØÀûÓÃÓÚICS»ù´¡ÉèÊ© £¬µ«Æä°²È«Ë®Æ½ÈÔÓдýÌá¸ß £¬Í¨¹ýÈëÇÖÒÆ¶¯APP¿ÉÄܵ¼ÖÂÕû¸öICS»ù´¡ÉèÊ©Ãæ¶Ô±»ÈëÇֵķçÏÕ¡£


ÁíÒ»¸öÀàËÆµÄ°²È«ÎÊÌâÓëICSºÍÔÆ¼¼ÊõµÄ½áºÏÓйØ¡£ÀýÈç £¬2018ÄêMindConnect NanoºÍMindConnect IoT2040£¨IoTÓ²¼þÍø¹Ø £¬ÓÃÓÚÏνӹ¤ÒµÉ豸ºÍÎ÷ÃÅ×ÓMindSphereÔÆÆ½Ì¨£©¾Í±»·¢ÏÖÒ×Êܹ¥»÷¡£


2.7 ¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷Öеķì϶


2018Äê¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷ÖеݲȫÎÊÌâÖØÒªÓëÖ÷Á÷¹©¸øÉ̵ÄоƬ·ì϶ÓйØ £¬ÀýÈçÈۻٺ͹í»ê·ì϶ £¬»¹ÓÐSpectre-NG·ì϶¡£ÁíÒ»¸öÓ°Ïì´óÁ¿¹¤ÒµÍÆËã»úµÄ·ì϶ÊÇ¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©ÖеÄRCE·ì϶¡£ÕâÔÙÒ»´ÎÖ¤ÁËÈ» £¬´«Í³¼¼Êõ£¨¼´·ÇICSÌØÓеļ¼Êõ£©Öеķì϶Äܹ»Ó°Ï칤ҵϵͳ¡£


2.8 ¹¤ÒµÍøÂ簲ȫ½â¾ö¹æ»®Öеķì϶


³ýÁËICSµÄÓ²¼þºÍÈí¼þ×é¼þÖеķì϶֮±í £¬2018Äê×êÑÐÈËÔ±»¹ÔÚ¹¤ÒµÍøÂçµÄ°²È«½â¾ö¹æ»®Öз¢ÏÖÁË·ì϶ £¬ÀýÈçNortekµÄ½Ó¼û½ÚÔìÆ½Ì¨Linear eMerge E3 SeriesºÍÂÞ¿ËΤ¶û×Ô¶¯»¯µÄÍøÂ簲ȫÉ豸Allen-Bradley Stratix 5950¡£ÕâÔÙ´ÎÌáÐÑÁËÎÒÃÇ £¬¹¤ÒµÏµÍ³µÄ°²È«²»½öÓëICSÓ²¼þºÍÈí¼þ×é¼þÓйØ £¬»¹Ó빤ҵ°²È«½â¾ö¹æ»®Öеķì϶ÓйØ¡£


Èý¡¢³£¼ûÍþв



3.1 Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷


Ô̺¬¶ñÒ⸽¼þµÄ´¹µöÓʼþÈÔÊÇÉøÈ빤ҵÆóÒµµÄÖØÒª¹¥»÷ÏòÁ¿¡£ÔÚ´ÓǰÊýÄêÖÐ £¬ÕâÀàÍþвÒѳÉΪ¹¤Òµ¹¤×÷Õ¾µÄ³£¼ûÍþв¡£


ºÜ¶à´¹µöÓʼþ¶¼¾­¹ýÁ˾«ÐļÙ×°£ºËüÃǼÙ×°³ÉÕæÊµ¹«Ë¾·¢³öµÄóÒ×Ðź¯¡¢ÒµÎñ±¨¼Û¡¢Ô¼Ç뺯µÈ¡£´Ë±í £¬Ò»Ð©´¹µö¹¥»÷ÀûÓÃÁ˺Ϸ¨µÄÕæÊµÎĵµ×ÊÁÏ¡£ÕâÒâζ×Å´¹µö¹¥»÷Õß½«ÇÔÈ¡ºÏ·¨ÐÅÏ¢×÷Ϊ³ï±¸»î¶¯µÄÒ»²¿ÃÅ¡£
 

 GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´¹µöÓʼþÑùÀý


ͨ³£Ë·´ £¬Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷Æä×îÖÕÖ÷ÕŶ¼ÊÇΪÁËÇÔÈ¡½ðÇ®¡£µ±È» £¬Ò²ÓÐһЩ¼Ù×°³É¡°³ß¶È¡±´¹µö¹¥»÷µÄÕë¶ÔÐÔ¹¥»÷¡£


ƾ¾ÝGA»Æ½ð¼×ͳ¼Æ £¬¹¤Òµ´¹µö¹¥»÷²»½öÕë¶ÔÆóÒµÍøÂçÖеķþÎñÆ÷ £¬»¹Õë¶Ô¹¤Òµ»ù´¡ÉèÊ©ÖеÄÒ»Ð©ÍÆËã»ú¡£ÔÚÈ«ÇòÁìÓòÄÚ £¬ÖÁÉÙ4.3%µÄICSÍÆËã»úÔø¼ì³ö¹ý¼äµýÈí¼þ¡¢ºóÃźͼüÅ̼ͼľÂí¡£ÕâЩ¶ñÒâÈí¼þ³£ÓÉ´¹µöÓʼþ½øÐзַ¢¡£ÎÒÃÇÒÔΪÕâЩ¶ñÒâÈí¼þµÄÁìÓò¿ÉÄÜÔ½·¢¿í·º £¬ÓÉÓÚ´¹µö¹¥»÷Õß³£¸üлò¶¨ÆÚת»»Æä¶ñÒ⹤¾ß £¬Ê¹µÃһЩ×îÐÂÑù±¾Î´±»Í³¼Æµ½¡£


ÓÉÓÚ´¹µö¹¥»÷Õß»ý¼«Ê¹Óô¹µöÓʼþ½øÐй¥»÷ £¬ÎÒÃǹ۲쵽ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý²»ÐÝÅÊÉý¡££¨ÓëITÍÆËã»úÒ»Ñù £¬OTÍÆËã»úͨ³£Ò²×°ÖÃÁËÓʼþ¿Í»§¶Ë £¬ÒԿ繫˾»¥»»ÐÅÏ¢ ¨C ͨ³£»¹Ê¹ÓÃÁËÒ»ÑùµÄÓʼþÕÊ»§¡£ÎÒÃǺÜÉÙ¿´µ½OTÍøÂçÖÐʹÓÃÁËÓëIT·ÖÆçµÄÓʼþÕÊ»§£©¡£2018ÄêϰëÄêÎÒÃÇÔÚÈ«ÊÀ½çÁìÓòÄÚ¶¼·¢ÏÖÁËÕâÒ»Ôö³¤¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý


ÈçÉÏͼËùʾ £¬Î÷Å·µØÓòÒâ±íµØÅÅÃûTop3£º¸ÃµØÓòµÄÊý×ÖÔö³¤ÁË2.7¸ö°Ù·Öµã £¬ÆäÖÐÔö³¤·ù¶È×î´óµÄÊǵ¹ú £¬¸ÃµØÓòµÄÊý×ÖÏÕЩ·­·¬¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

Î÷Å·µØÓòÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý


Õâµ¼ÖÂÁ˵¹úÔÚÈ«ÇòÅÅÃûÖÐÒÔ6.5%λÁеÚÊ®Èý £¬¶øÒâ´óÀû£¨6.8%£©ÔòÊÇΨһÅÅÃû±ÈµÂ¹ú¸ßµÄÅ·ÖÞ¹ú¶È¡£

ÖµÍ×ÌùÐĵÄÊÇ £¬´¹µöÓʼþÖеĺܶà¶ñÒ⸽¼þ´Ë¿Ì¶¼ÊǼÓÃܵÄѹËõÎļþ £¬ÃÜÂ븽ÔÚÓʼþµÄÕýÎÄÖ®ÖС£´Ë¾ÙÊÇΪÁËÌӱܼì²â £¬Í¨³£Çé¿ö϶ñÒâÈí¼þÖ»ÓÐÔÚÊÕ¼þÈË´ò¿ª¸½¼þʱÄÜÁ¦¼ì²âµ½¡£


ÎÒÃǽ¨Òé £¬ËùÓй«Ë¾¶¼ÒªÌáÐÑÔ±¹¤ÕâÒ»ÕæÕýµÄÍþв £¬²¢ÑµÁ·ËûÃǼø±ð¹¥»÷¼£Ïó £¬²»Òª´ò¿ª¿ÉÒÉÎļþ»òµã»÷Á´½Ó £¬²¢½«ÈκÎDZÔÚÊÂÎñÍ¨ÖªÍøÂ簲ȫÊýÃÅ¡£


3.2 ¼ì²âÑù±¾

2018ÄêϰëÄ꿨°Í˹»ùµÄ°²È«²úÆ·¹²ÔÚ40.8%µÄICSÍÆËã»úÉϼì²âµ½¶ñÒâÑù±¾¡£


ÕâЩ¶ñÒâÑù±¾¿É¹éÀàÓÚÒÔÏÂÀà±ð £¬ÁбíÖл¹±ê³öÁËÊÜ´ËÀàÑù±¾¹¥»÷µÄICSÍÆËã»úµÄ±ÈÀý¡£Çë°ÑÎÈÓÉÓÚͳ¼ÆÊý¾ÝѡȡÁË»ùÓÚÊðÃûºÍÆô·¢Ê½µÄ¼ì²â²½Öè £¬Ò»Ð©ÎÞ·¨·Ö±æµÄ¶ñÒâÈí¼þÑù±¾±»¹éÀàÓÚGeneric£¨Í¨Óã©Àà±ð £¬ÕâÒâζ×ÅijЩÀà´ËÍâ¶ñÒâÈí¼þµÄ±ÈÀýÏÖʵÉÏÒª¸ü¸ß¡£


¼ì²âµ½µÄ¶ñÒâÑù±¾¹éÀ༰Æä±ÈÀý£º



  • 15.9% - ÁÐÈëºÚÃûµ¥µÄ»¥ÁªÍø×ÊÔ´


ÕâÀà¶ñÒâÑù±¾Í¨³£ÊÇÓû§ÔÚä¯ÀÀÆ÷Öдò¿ªÒ»¸ö¶ñÒâ»òÊÜϰȾµÄÍøÒ³Ê±ÏÂÔØµÃÀ´¡£ÕâÐ©ÍøÒ³Òѱ»ÁÐÈëºÚÃûµ¥ £¬Òò¶ø´óÎÞÊýÇé¿öϰ²È«²úƷͨ¹ý¼ì²âURL¼´¿É·¢ÏÖ¹¥»÷¡£ÕâÀà×ÊÔ´³£ÓÃÓÚ·Ö·¢Ä¾Âí¡¢¼äµýÈí¼þºÍÀÕË÷Èí¼þ £¬ÇÒͨ³£¼Ù×°³É¸÷³§¼Ò½ÚÔìÆ÷µÄÆÆ½â¹¤¾ß»òÃÜÂë³ÁÖù¤¾ß £¬Ò²¿ÉÄÜÊǼÙ×°³É¹¤Òµ/¹¤³ÌÈí¼þµÄÆÆ½â°æ»ò²¹¶¡¡£


  • 8.7% - ¶ñÒâ¾ç±¾ £¬ÍøÒ³³Á¶¨Ïò£¨JSºÍHTML£© £¬ÒÔ¼°ä¯ÀÀÆ÷·ì϶ÀûÓà ¨C 0.17%
  • 6.36% - È䳿 £¬Ô̺¬Í¨¹ý¿ÉÒÆ¶¯Ã½ÌåºÍÍøÂç¹²Ïí´«²¼µÄÈ䳿£¨Worm£©¡¢Í¨¹ýµç×ÓÓʼþ´«²¼µÄÈ䳿£¨Email-Worm£©¡¢Í¨¹ýÍøÂç·ì϶´«²¼µÄÈ䳿£¨Net-Worm£©ºÍ¼´Ê±Ì¸ÌìÀûÓÃÖеÄÈ䳿£¨IM-Worm£©¡£´ÓÍøÂç»ù´¡ÉèÊ©µÄ½Ç¶ÈÀ´¿´ £¬´óÎÞÊýÈ䳿¶¼ÊǹýÆÚµÄ¡£



ÕâÒ»Àà±ðÖеļÒ×åÔ̺¬£º


  • Worm.Win32.VBNA (0.2%) £¬³öÏÖÓÚ2009Äê¡£
  • Worm.Win32.Vobfus (0.05%) £¬³öÏÖÓÚ2012Äê £¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¨Zbot¡¢Fareit¡¢CutwailµÈ£©¡£
  • Andromeda/Gamarue (0.69%) £¬¸Ã¶ñÒâÈí¼þ¹¹½¨µÄ¾ÞÐͽ©Ê¬ÍøÂçÓÚ2017Äê±»ÆËÃð¡£


ÓÈÆäÖµÍ×ÌùÐĵÄÊÇÒ»¸ö¹ýÆÚµ«¾­¾Ã²»Ë¥µÄ¶ñÒâÈí¼þNetWorm.Win32.Kido(3.14%)¡£×Ô2010ÄêÎÊÊÀÒÔÀ´ £¬ËüÒ»ÏòÊÇÅÅÃû×î¸ßµÄ¼ì²âÑù±¾Ö®Ò»¡£


´Ë±í £¬Ò²´æÔÚÏñWorm.Win32.Zombaque (0.02%)ÕâÑùµÄP2PÍøÂç¼Ü¹¹µÄÈ䳿 £¬¹¥»÷ÕßÄܹ»ËæÊ±¼¤»îËüÃÇ¡£»¹´æÔÚʹÓÃHTTPºÍ̸µÄ»îÔ¾È䳿 £¬ËüÃdz£ÓÉVBS±àд £¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ £¬ÀýÈçºóÃźͼäµýľÂíµÈ¡£


  • 6.35% - ÔËÐÐÔÚä¯ÀÀÆ÷ÖеÄÍÚ¿óľÂí

          0.76% - WindowsÍÚ¿óľÂí


  • 5.78% - ¶ñÒâLNKÎļþ


ÕâÀàÑù±¾ÖØÒªÔÚ¿ÉÒÆ¶¯Ã½ÌåÉϼì²âµ½ £¬³£×÷ΪÆäËü¶ñÒâÈí¼þ¼Ò×åµÄ´«²¼»úÔìµÄÒ»²¿ÃÅ £¬ÀýÈçAndromeda/Gamarue¡¢Dorkbot¡¢Jenxcus/DinihouµÈ¡£ÕâÒ»Àà±ð»¹Ô̺¬CVE-2010-2568£¨¸Ã·ì϶×îÔçÓÃÓÚ·Ö·¢ÕðÍø²¡¶¾£©·ì϶ÀûÓõÄLNKÎļþ£¨0.66%£©¡£¸Ã·ì϶»¹±»ÓÃÓÚ´«²¼Sality¡¢Nimnul/Ramnit¡¢ZeuSºÍVobfusµÈ¼Ò×å¡£

Ŀǰ £¬¼Ù×°³ÉºÏ·¨ÎĵµµÄLNKÎļþ±»ÓÃ×÷¶à½×¶Î´¹µö¹¥»÷µÄÒ»²¿ÃÅ £¬ÓÃÓÚÔËÐÐPowerShell¾ç±¾²¢ÏÂÔØ¶ñÒâpayload¡£ÔÚ¼«ÉÙÊýÇé¿öÏ £¬PowerShell¾ç±¾»áÏÂÔØÒ»¸öMetasploitÄ£¿é£¨MetasploitÖеÄTCPºóÃÅ£©µÄÌØ¶¨±äÌå¡£


  • 2.85% - Ô̺¬exploits¡¢¶ñÒâºê»ò¶ñÒâÁ´½ÓµÄ¶ñÒâÎĵµ£¨MSOffice + PDF£©
  • 2.31% - ϵͳÆô¶¯Ê±»ò²åÈë¿ÉÒÆ¶¯Ã½Ìåʱ×Ô¶¯ÔËÐеĶñÒâÎļþ£¨¿ÉÖ´ÐÐÎļþ¡¢¾ç±¾¡¢autorun.inf¡¢.LNKÎļþµÈ£©


ÕâÀàÑùÕý±¾×ÔÓÚ¶à¸ö¼Ò×å £¬µ«¶¼ÓÐÒ»¸ö¹²Í¬µã ¨C ×Ô¶¯ÔËÐС£Óк¦Ë®Æ½×îµÍµÄÑù±¾ÊÇʹÓÃÔ¤Ô¼ÒåµÄÖ÷Ò³×Ô¶¯Æô¶¯ä¯ÀÀÆ÷¡£ºÜ¶àʹÓÃautorun.infµÄ¼Ò×åÔÚÍøÂç»ù´¡ÉèÊ©·½Ãæ¶¼ÒѹýÆÚ£¨Palevo¡¢ SalityºÍ KidoµÈ£©¡£

  • 2.28% - ²¡¶¾

ÕâÀ෨ʽÔ̺¬Virus.Win32.Sality (1.22%)¡¢Virus.Win32.Nimnul (0.87%)ºÍVirus.Win32.Virut (0.61%)¼Ò×壨ÒѳÖÐø¶àÄ꣩µÈ¡£Ö»¹ÜÕâЩ¼Ò×åµÄÍøÂç»ù´¡ÉèÊ©¶¼ÒÑʧЧ £¬µ«ÓÉÓÚ×ÔÎÒ´«²¼µÄ¸öÐÔºÍÆëÈ«×èÖ¹ËüÃǵݲȫ´ëÊ©µÄ²»¼° £¬ËüÃÇÈÔÔÚͳ¼ÆÊý¾ÝÖÐÕ¼¾Ý´óÍ·¡£

  • 2% - ÀÕË÷Èí¼þ
  • 1.26% - ÒøÐÐľÂí
  • 0.9% - AutoCad¶ñÒâÈí¼þ
ÖµÍ×ÌùÐĵÄÊÇ £¬AutoCad¶ñÒâÈí¼þ £¬ÓÈÆäÊDz¡¶¾ £¬ÖØÒªÔÚ¶«ÑǵØÓòµÄICSÍÆËã»úÉϼì²âµ½¡£¸ÃÀà¶ñÒâÈí¼þ³£ÔÚÍøÂçÎļþ¼ÐºÍ¹¤³Ì¹¤×÷Õ¾Öз¢ÏÖ¡£Ö»¹ÜAutoCad¶ñÒâÈí¼þµÄϰȾ¶¥·åÔÚ2000ÄêÖÁ2010ÄêÔçÆÚ³öÏÖ £¬µ±Ç°ÈÔ¿É·¢ÏÖ»îÔ¾µÄÑù±¾¡£
  • 0.61% - Õë¶ÔÒÆ¶¯É豸µÄ¶ñÒâÎļþ£¨ÔÚÉ豸Ïνӵ½ÍÆËã»úʱ¼ì²âµ½£©

3.3 Õë¶ÔÆû³µÔì×÷ÒµµÄÍþвTop3


´ÓÕâ·Ý»ã±¨ÆðÍ· £¬ÎÒÃǽ«Ã¿Áù¸öÔ¶ÔÒ»¸öÐÐÒµµÄTop3Íþв½øÐзÖÎö¡£


Õë¶ÔÆû³µÐÐÒµµÄ¹¥»÷ÖØÒªÊÔͼ°Ñ³ÖÆû³µµÄÔì×÷/Õï¶Ï¹¤ÒµÁ÷³Ì»ò³µÔØÏµÍ³ £¬½ñÌìÎÒÃDz¢Ã»Óз¢ÏÖÕâÑùµÄ¹¥»÷¡£

µ«ÔÚ2018ÄêϰëÄê £¬¿¨°Í˹»ùµÄ²úÆ·×èÖ¹ÁË´óÁ¿Õë¶ÔÆû³µ¹¤³§×°ÅäÏߺÍÉ̵êÒÔ¼°Õë¶ÔÒ»¼¶¹©¸øÉ̹¤³§£¨Ô̺¬ÔËÐÐÆû³µÐÐÒµ¶àÖÖÈí¼þ²úÆ·µÄWindowsÍÆËã»ú£©µÄ¡°Í¨³£¡±¶ñÒâÈí¼þ¡£ÕâЩ¶ñÒâÈí¼þ×ÔÉí²¢²»ÊÇÕë¶ÔICS»·¾³µÄ £¬ËüÃÇÔ̺¬ÒÑÖªµÄ²¡¶¾¡¢ÍÚ¿óÈí¼þ¡¢³£¼ûµÄ¼äµýÈí¼þµÈ¡£Ö»¹ÜÕâЩ¶ñÒâÈí¼þµÄÖ÷ÕÅÊÇÔì³ÉÎïÀíÍøÂçµÄÇÖº¦ £¬µ«Æä¸±×÷ÓÿÉÄÜ»á¶ÔICSºÍOTϵͳµÄ¿ÉÓÃÐÔºÍÆëÈ«ÐÔÔì³É³Á´óÓ°Ïì¡£


³ÁÒªµÄÊÇÒª¹Ø×¢½«À´¹¥»÷µÄDZÔÚ·çÏÕ £¬ÕâЩÍþвµÄ½Ã½ÝÐÔºÍÕë¶ÔÐÔ£¨¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷£©¼Ó¾çÁËÕâÒ»µã¡£


3.3.1 Sality½©Ê¬ÍøÂç


ÆäÖÐÒ»¸ö×î³£¼ûµÄÍþвÊÇSality £¬ËüÊÇÒ»¸ö³ÛÃûµÄÄ£¿é»¯¶à̬²¡¶¾/È䳿 £¬×îÔç³öÏÖÓÚ2003Äê £¬²¢ÔÚ2015Ä껹ÔÚÊØ»¤¡£


ÔÚ´Óǰ £¬SalityµÄC&C·þÎñÆ÷ÓÃÓÚÏÂÔØÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¼°ÇÔÈ¡Óû§µÄÕË»§Í´´¦¡£µ«´Ë¿ÌÕâЩC&CÒѾ­²»ÔÙ¿ÉÓà £¬²¢ÇÒËùÓеÄSalityÑù±¾¶¼¿Éͨ¹ý³£¼ûµÄAV¼¼Êõ¼ì²âµ½¡£


Ö»¹ÜÈç´Ë £¬¸Ã¶ñÒâÈí¼þÈÔÔÚÈ«ÇòÍøÂç³ÖÐø´«²¼¡£¿¨°Í˹»ùÔÚÆû³µÐÐÒµµÄ´óÁ¿OTÍÆËã»úÉϼì²âµ½ÁËSality £¬ÎÒÃÇÒÔΪÏÖʵÊܵ½Ï°È¾µÄOTÍÆËã»úÊýÁ¿¸ü¶à¡£


SalityµÄ×ÔÎÒ´«²¼¸öÐÔʹµÃËü³ÉΪOT/ICS»ù´¡ÉèÊ©µÄÑϳÁÍþв £¬ËüÄܹ»´¥·¢»Ø¾ø·þÎñ¼°ÓÉÓÚ¶ñÒâÁ÷Á¿µ¼Ö±¾µØÍøÂçµÄ»úÄܽµÂä¡£


3.3.2 Bladabindi/njRAT½©Ê¬ÍøÂç


Õë¶ÔÆû³µÐÐÒµµÄÁíÒ»¸ö³Á´óÍþвÊÇBladabindi ¨C Ò»¸öÄ£¿é»¯µÄ¶àÖ°Äܽ©Ê¬ÍøÂç´úÀí £¬Æä´ó¾ÖÊDZàÒëºÃµÄÒ»×éAutoIT¾ç±¾¡£ËüµÄºóÃÅ/¼äµýÖ°Äܼ«¶È׳´ó £¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡¶àÖÖÃô¸ÐÐÅÏ¢¡£¸Ã½©Ê¬ÍøÂ绹ӵÓÐÀàËÆÈ䳿µÄÖ°ÄÜ £¬¿Éͨ¹ý¿ÉÒÆ¶¯Ã½Ìå´«²¼¡£


ËüµÄC&C·þÎñÆ÷´¦ÓÚ»îԾ״̬ £¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢·Ö·¢ºÅÁîºÍÏÂÔØÏÂÒ»½×¶Î¶ñÒâÈí¼þ£¨¶ñÒâ¿ó¹¤¡¢DDoS´úÀí¡¢ÀÕË÷Èí¼þµÈ£©¡£¹¥»÷ÕßʹÓö¯Ì¬DNS¼¼ÊõÀ´Ìӱܼì²âºÍ¶ñÒâÈí¼þ·ÖÎö¡£ÓÉÓÚÖ°ÄÜ׳´ó £¬Bladabindi¿ÉÄܶÔOTÍøÂç²úÉú³Á´óÓ°Ïì¡£


3.3.3 AutoCAD½©Ê¬ÍøÂç


»ùÓÚAutoCADµÄ½©Ê¬ÍøÂçÊÇÓÉAutoLISP (FAS)ľÂí¹¹½¨µÄ £¬ÆäC&C·þÎñÆ÷³õ´Î³öÏÖÓÚ2013Äê¡£¸Ã½©Ê¬ÍøÂçÒÀÈ»Óɹ¥»÷Õß½øÐÐÊØ»¤¡£


FASľÂí»á´Û¸ÄAutoCADµÄÉèÖà £¬Ê¹µÃÿ´ÎÓû§´ò¿ªAutoCAD¹¤³Ìʱ³ÇÊÐÖ´ÐиÃľÂí £¬ÕâÒ²µ¼ÖÂÿһ¸öн¨µÄÏîÄ¿³ÇÊÐÊܵ½Ï°È¾¡£


ÆäC&CÈÔ´¦ÓÚ»îԾ״̬,ÓÃÓÚÏòÊÜϰȾµÄÍÆËã»ú·Ö·¢ÏÂÒ»½×¶Î¶ñÒâÈí¼þ¡£µ±Ç° £¬ÒÑÖªµÄΨÖðÒ»¸öÕâÖÖpayloadµÄÑùÀýÊÇÒ»¸öVB¾ç±¾ £¬¸Ã¾ç±¾ÓÃÓÚÅú¸Ää¯ÀÀÆ÷µÄÖ÷Ò³ÉèÖúͽ«ä¯ÀÀÆ÷µ¼º½ÖÁËÁÒâURL¡£


¸ÃľÂíÖØÒªÕë¶ÔÑÇÖÞ£¨ÓÈÆäÊÇÖйú£©µÄ¹¤ÒµºÍ¹¤³ÌÆóÒµ £¬²¢ÇÒ¿ÉÄܶÔOTÍøÂçÔì³ÉÑϳÁÓ°Ïì¡£


¿ÉÄܵijõʼϰȾõè¾¶£º
  • ¸½¼þÖÐÔ̺¬Ä¾ÂíÏÂÔØÆ÷acad.fas£¨°µ²ØÔÚAutoCADÔìͼÖУ©µÄµç×ÓÓʼþ £¬¸ÃÓʼþÓɲ»ÊÜÒÉ»óµÄ³Ð°üÉÌ/·Ö°üÉ̺Ϸ¨¹¤³Ìʦ·¢ËÍ¡£
  • ¹¥»÷Õß·¢Ë͵Ĵ¹µöÓʼþ £¬Í¬ÑùЯ´øÔ̺¬acad.fasµÄ¸½¼þ
  • Я´øacad.fasµÄ¿ÉÒÆ¶¯Ã½Ì壨ÈçUÅÌ£©
  • ±¾µØÍøÂçÉϵĹ²ÏíÎļþ£¨Ô̺¬°µ²ØµÄacad.fas£©
ÖµÍ×ÌùÐĵÄÊÇ £¬ÔÚÍÆËã»ú±»Ï°È¾ºó £¬Êܺ¦Õß»áÔÚ²»ÖªÇéµÄÇé¿öÏÂͨ¹ýUSB¡¢µç×ÓÓʼþ¡¢±¾µØºÍÔÆ¹²ÏíÎļþ³ÖÐø´«²¼ÊÜϰȾµÄAutoCAD¹¤³ÌÎļþ¡£
Ææ¹ÖµÄÊÇ £¬C&C·þÎñÆ÷¶ËµÄ´úÂë¶Ô´«ÈëµÄÒªÇó×öÁËһЩ²é³­£¨ÀýÈçIPµØÖ·µÄ¹ú¶È¹ýÂË£© £¬ÈôÊDz鳭ʧ°Ü £¬Ôò²»»á½»¸¶µÚ¶þºÍµÚÈý½×¶Îpayload£¨ÀýÈçIPµØÖ·µØµãµÄ¹ú¶È²»ÇкϹ¥»÷ÕßµÄÐËÖ£©¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿ÉÄܵijõʼϰȾõè¾¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷ɱ¾Á´


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÚÒ»½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÚ¶þ½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 

µÚÈý½×¶ÎVB ¾ç±¾ÑùÀý



ËÄ¡¢Íþвͳ¼Æ



±¾»ã±¨ÖеÄͳ¼ÆÊý¾Ý¶¼ÊǾ­¹ýÐí¿É´ÓKSNÓû§µÄÍÆËã»úÉÏÄäÃûÍøÂçµÃÀ´¡£


4.1 ×êÑв½Öè


¿¨°Í˹»ùICS CERT½«ÆóÒµÖеĹ¤Òµ»ù´¡ÉèÊ©¹éÀàΪICSÍÆËã»ú¡£ÓйØÍ³¼ÆÊý¾Ý´ÓÕâÒ»Àà´ËÍâÍÆËã»úÉÏÍøÂçµÃÀ´¡£ÕâÐ©ÍÆËã»úÔ̺¬ÔËÐÐÒÔÏÂÖ°ÄܵÄWindowsÍÆËã»ú£º


? Êý¾Ý²É¼¯Óë¼à¿Ø·þÎñÆ÷£¨SCADA£©£»
? Êý¾Ý´æ´¢·þÎñÆ÷£¨Historian£©£»
? Êý¾ÝÍø¹Ø£¨OPC£©£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÒÆ¶¯¹¤×÷Õ¾£»

? ÈË»ú½çÃæ£¨HMI£©¡£


»¹Ô̺¬´Ó¹¤¿ØÍøÂçÖÎÀíÔ±ÒÔ¼°¹¤Òµ×Ô¶¯»¯ÏµÍ³¿ª·¢ÈËÔ±µÄÍÆËã»úÉÏÍøÂçµ½µÄÊý¾Ý¡£


ÔÚ±¾»ã±¨ÖÐ £¬Ôâ·ê¹¥»÷µÄÍÆËã»úÊÇÖ¸Ôڻ㱨ÆÚ¼äGA»Æ½ð¼×°²È«½â¾ö¹æ»®ÖÁÉÙ±»´¥·¢Ò»´ÎµÄÍÆËã»ú¡£Ôâ·ê¹¥»÷µÄÍÆËã»úµÄ±ÈÀýÊÇÖ¸Ôâ·ê¹¥»÷µÄÍÆËã»ú£¨È¥³Á£©Õ¼ËùÓÐÑù±¾ÍÆËã»ú£¨Ôڻ㱨ÆÚ¼äÏòÎÒÃÇ·¢ËÍÁËÄäÃûÊý¾ÝµÄÍÆËã»ú£©µÄ±ÈÀý¡£


ͨ³£Çé¿öÏ £¬ÓÉÓÚ¹¤ÒµÍøÂçµÄÏÞ¶È £¬ICS·þÎñÆ÷ºÍ¹¤³Ìʦ/²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾²»ÊÇ24Ó×ʱÁªÍøµÄ¡£ÕâÀàÍÆËã»ú¿ÉÄÜÖ»ÔÚ £¬ÀýÈçÊØ»¤ÆÚ¼ä £¬ÄÜÁ¦ÁªÍø¡£


ϵͳ/ÍøÂçÖÎÀíÔ±¡¢¹¤³Ìʦ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³µÄ¿ª·¢ÈËÔ±ºÍ¼¯³ÉÈËÔ±µÄ¹¤×÷Õ¾¿ÉÄÜ»áʱʱÁªÍø £¬ÉõÖÁ¿ÉÄÜÊÇ24Ó×ʱÁªÍø¡£


Òò¶ø £¬2018ÄêϰëÄêGA»Æ½ð¼×Ñù±¾ÍÆËã»úÖÐÔ¼ÓÐ40%µÄÍÆËã»úÊǶ¨ÆÚ»òÈ«ÌìÁªÍøµÄ¡£ÆäÓà»úеµÄÁªÍø¹¦·ò²»³¬¹ýÒ»¸öÔ £¬ÆäÖкöàÊÇÔ¶Ô¶ÉÙÓÚÕâ¸ö¹¦·òµÄ¡£


4.2Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêÕûÄêÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÏà±È2017ÄêÔö³¤ÁË3.2¸ö°Ù·Öµã £¬´ï47.2%¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2017 vs 2018 £¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêϰëÄ꣨H2£© £¬È«ÇòÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÓëÉϰëÄ꣨H1£©Ïà±ÈÇá΢½µÂä £¬½µÂäÁË0.37¸ö°Ù·Öµã £¬ÖÁ40.8%.


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018Äê5ÔÂÖÁ8ÔÂÆÚ¼äÕâÒ»Êý×ÖÔø½µÂäÇ÷Ïò £¬µ«´Ó9ÔÂÆðÍ·ÓÖ³öÏÖÁËеÄÔö³¤ £¬×îÖÕÒ»Ïò²»±äÔÚ22%Ö®ÉÏ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©


Óë2017ÄêÏà±È £¬2018Äêÿ¸öÔ·ݵÄÊý×Ö¶¼Òª¸ü¸ß¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2017 vs 2018 £¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©


4.3 ¶ñÒâÈí¼þµÄÀà±ðÉ¢²¼


2018ÄêϰëÄê £¬¿¨°Í˹»ù¹²¼ì²âµ½2700¸ö¼Ò×åµÄ1.91Íò¸öICS¶ñÒâÈí¼þ±äÌå¡£ÓëÒÔǰһÑù £¬¾ø´óÎÞÊýÕë¶ÔICSµÄ¹¥»÷°¸Àý¶¼ÊÇËæ»ú¹¥»÷ £¬¶ø²»ÊÇÕë¶ÔÐÔ¹¥»÷¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©


ľÂíÈÔÊÇ×î³£¼ûµÄÍþв £¬Óë2018ÄêÉϰëÄêÏà±È £¬ºóÃÅ£¨Backdoor£©µÄ·Ý¶îÔö³¤ÁË1¸ö°Ù·Öµã £¬ÀÕË÷Èí¼þ£¨Trojan-Ransom£©ÔòÔö³¤ÁË0.44¸ö°Ù·Öµã¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 

2017 ¨C 2018 £¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©


4.4 µØÀíÉ¢²¼


ÏÂÃæµÄµØÍ¼ÏÔʾÁË·ÖÆç¹ú¶ÈµÄICSÍÆËã»úÔâ·ê¹¥»÷µÄ±ÈÀý¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬ICS¹¥»÷*µÄµØÀíÉ¢²¼
*¸Ã¹ú¶ÈÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬ICS¹¥»÷±ÈÀý×î¸ßµÄ¹ú¶È/µØÓò£¨Top 15£©


Óë2018ÄêÉϰëÄêÏà±È £¬ICS¹¥»÷±ÈÀý¹ú¶ÈÅÅÃûµÄǰÎåÃûûÓиĹÛ £¬µ«Morocco£¨´Ë¿Ì´¦ÓÚµÚÈýÃû£©ºÍTunisia£¨µÚËÄÃû£©»¥»»Á˵ØÎ»¡£


2018ÄêϰëÄê¶íÂÞ˹Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÊÇ45.3% £¬ºÍÉϰëÄ꣨44.7%£©´¦ÓÚͳһˮƽ¡£¶íÂÞ˹µÄÅÅÃûÊǵÚ16Ãû¡£


ÅÅÃûÖнÏΪ°²È«µÄ¹ú¶È/µØÓòÊǰ®¶ûÀ¼£¨11.7%£©¡¢ÈðÊ¿£¨14.9%£©¡¢µ¤Âó£¨15.2%£©¡¢ÖйúÏã¸Û£¨15.3%£©¡¢Ó¢¹ú£¨15.7%£©ºÍºÉÀ¼£¨15.7%£©¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄêICS¹¥»÷±ÈÀý×îµÍµÄ¹ú¶È/µØÓò


ÈôÊÇÒÀÕÕµØÀíÇøÓòÀ´»®·Ö £¬·ÖÆçÇøÓòÖ®¼äµÄÊý×ÖͬÑùÏà²îºÜ´ó¡£·ÇÖÞ¡¢¶«ÄÏÑǺͶ«ÑÇÒ»ÏòÊÇÅÅÃû½Ï¸ßµÄµØÓò¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêH1ºÍH2 £¬ICS¹¥»÷±ÈÀýµÄµØÀíÇøÓòÉ¢²¼


4.5 ϰȾԴ


´ÓǰÊýÄê¼ä £¬»¥ÁªÍø¡¢¿ÉÒÆ¶¯Ã½ÌåºÍµç×ÓÓʼþ³ÉΪICSÍÆËã»úµÄÖØÒªÍþвÆðÔ´¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ICSÍÆËã»ú*µÄÖØÒªÍþвÆðÔ´£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©


* Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêϰëÄê £¬»¥ÁªÍøÊÇ26.1%µÄICS¹¥»÷µÄÍþвÆðÔ´¡£Óë2018ÄêÉϰëÄêÏà±È £¬ÕâÒ»Êý×ÖÇá΢½µÂä £¬¶øÓëÖ®Ïà·´µÄÊǵç×ÓÓʼþÍþвµÄ±ÈÀýÇá΢Ôö³¤¡£ÆäËüÖØÒªÏ°È¾Ô´µÄ·Ý¶îÓë2018ÄêÉϰëÄêµÄˮƽÏà²î²»´ó¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ICSÍÆËã»úµÄÖØÒªÍþвÆðÔ´£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©

4.6 ÖØÒªÏ°È¾Ô´µÄµØÓòÉ¢²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬ICSÍÆËã»úÖØÒªÍþвÆðÔ´µÄµØÀíÉ¢²¼


4.6.1 »¥ÁªÍø


ÔÚËùÓÐµÄ·ÖÆçµØÓò £¬»¥ÁªÍø¶¼ÊÇÖØÒªµÄÍþвÆðÔ´¡£µ«ÕûÌå¶øÑÔ±±Å·¡¢Î÷Å·ºÍ±±ÃÀµÄÍþвÊý×ֽϵÍ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬Ôâ·ê»¥ÁªÍøÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬»¥ÁªÍøÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15


4.6.2 ¿ÉÒÆ¶¯Ã½Ìå


Õë¶ÔICSµÄ¿ÉÒÆ¶¯Ã½ÌåÍþв±ÈÀý½Ï¸ßµÄµØÓò³¤¶ÌÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ £¬½ÏµÍµÄµØÓòÊDZ±ÃÀ¡¢°Ä´óÀûÑǺͱ±Å·¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬Ôâ·ê¿ÉÒÆ¶¯Ã½ÌåÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬¿ÉÒÆ¶¯Ã½ÌåÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15


4.6.3 Óʼþ¿Í»§¶Ë


Õë¶ÔICSµÄµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄµØÓòÊÇÀ­¶¡ÃÀÖÞ¡¢ÄÏÅ·ºÍÎ÷Å· £¬µ«ÕûÌå¶øÑÔ¸÷¸öµØÓòµÄÊý×ÖÏà²î²»´ó¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018ÄêϰëÄê £¬Ôâ·ê¶ñÒâÓʼþÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©

µÂ¹úÔÚµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄ¹ú¶È/µØÓòTop15ÖÐÉϰñ £¬ÖµÍ×ÌùÐĵÄÊǸùú¶ÈÔÚÆäËü·½Ã涼δÉϰñ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
2018ÄêϰëÄê £¬µç×ÓÓʼþÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15

Ô­ÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2018/90041/