¡¾±¨¸æ·ÖÏí¡¿¿¨°Í˹»ù - 2018ϰëÄêICSÍþв¾°¹Û

Ðû²¼Ê±¼ä 2019-04-26

Ò»¡¢2018ϰëÄêÖ÷Òª¹¥»÷ÊÂÎñ



1.1 Õë¶Ô¹¤ÒµÐÐÒµµÄAPT¹¥»÷


1.1.1 ·¸·¨ÍÅ»ïLeafminerµÄAPT¹¥»÷


2018Äê8ÔÂÒ»·Ýб¨¸æÅû¶ÁË·¸·¨ÍÅ»ïLeafminer£¨ÓÖ³ÆRASPITE£©µÄÍøÂçÌØ¹¤Ô˶¯¡£¸Ã×éÖ¯Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢Öж«ºÍ¶«ÑǵØÇøµÄÕþ¸®»ú¹¹ÒÔ¼°ÉÌÒµºÍ¹¤Òµ¹«Ë¾£¬ÆäÄ¿µÄÐÐÒµ°üÀ¨ÄÜÔ´¡¢Õþ¸®¡¢½ðÈÚ¡¢º½Ô˺ÍÔËÊäµÈ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Leafminer¹¥»÷Ä¿µÄµÄÐÐÒµÂþÑÜ£¨ÈªÔ´£ºÈüÃÅÌú¿Ë£©


¹¥»÷ÕßʹÓÃÁ˶àÖÖ¹ûÕæ»ò¶¨ÖƵŤ¾ß¡¢exploitÒÔ¼°Ë®¿Ó¹¥»÷ºÍ×ֵ乥»÷£¬ÀýÈçÓÀºãÖ®À¶µÄexploitºÍMimikatz±äÌå¡£


1.1.2 жñÒâÈí¼þGreyEnergy


EsetÑо¿Ö°Ô±±¨¸æÁËÓë·¸·¨ÍÅ»ïBlackEnergyÓйصĶàÆð¹¥»÷ÊÂÎñ£¬ÔÚÕâЩ¹¥»÷Öй¥»÷ÕßʹÓÃÁËÒ»¸öеĶñÒâÈí¼þGreyEnergy¡£BlackEnergyÏÈǰÒÑ´ÓAPTÑо¿Ö°Ô±µÄÀ×´ïÉÏÏûÊÅ£¬µ«ÕâÒ»´Î¹¥»÷ÕßÔÙ´ÎÏÖÉí£¬Ö÷ÒªÕë¶ÔÖÐÅ·ºÍ¶«Å·²î±ðÐÐÒµµÄ¹¤ÒµÍøÂ磬°üÀ¨ÄÜÔ´¹«Ë¾¡¢ÔËÊ乫˾µÈ£¬²¢ÖØµã¹Ø×¢ÈÏÕæÔËÓªÒªº¦»ù´¡ÉèÊ©µÄÆóÒµ¡£


Ñо¿Ö°Ô±·¢Ã÷GreyEnergyÓë2015ÄêBlackEnergyÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄ¶ñÒâÈí¼þ±£´æ¿´·¨ÉϵÄÏàËÆÖ®´¦¡£±ðµÄ£¬Ñо¿Ö°Ô±»¹·¢Ã÷GreyEnergyÓë·¸·¨ÍÅ»ïTeleBotsµÄ¹¥»÷Ô˶¯±£´æ¹ØÁª¡£TeleBotsÒÔ¶àÆð´ó¹æÄ£¹¥»÷ÊÂÎñÖøÃû£¬ÀýÈç2017ÄêµÄNotPetyaºÍBadRabbit¡£¿¨°Í˹»ùÑо¿Ö°Ô±Ëæºó·¢Ã÷GreyEnergy»¹ÓëSofacy£¨¼´APT28£©µÄ×ÓÍÅ»ïZebrocy±£´æ¹ØÁª¡£


GreyEnergy¾ßÓÐÄ£¿é»¯µÄϵͳ½á¹¹£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ý¼ÓÔØÏà¹ØDLLÀ´×éºÏ²î±ðµÄ¶ñÒâÈí¼þ¹¦Ð§¡£Ä³Ð©ÇéÐÎÏ£¬ÕâЩ¶ñÒâÄ£¿é´ÓC&C·þÎñÆ÷ÏÂÔØ²¢Ö±½Ó¼ÓÔØ½øÄڴ棨²»Ð´Èë´ÅÅÌÎļþ£¬¼´ÎÞÎļþ¹¥»÷£©¡£GreyEnergy¿ÉÍøÂçÊܺ¦Õߵį¾Ö¤ÒÔÉøÍ¸¹¤¿ØÍøÂç¡£¸Ã×éÖ¯µÄ¹¤¾ß°ü»¹°üÀ¨¿ªÔ´¹¤¾ßMimikatz¡¢PsExec¡¢WinExeºÍNmapµÈ¡£


GreyEnergyµÄ³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹ÂÚÓʼþ¼°ÆóÒµµÄ¹«¹²ÍøÂç×ÊÔ´£¬ËäÈ»ºÜÓпÉÄÜ»¹°üÀ¨ÆäËü¹¥»÷ÏòÁ¿¡£


ÔÚ֮ǰµÄ¹¥»÷Ô˶¯ÖУ¬¸Ã×éÖ¯ÔøÊ¹ÓÃGE CimplicityÖеÄÎó²î£¨CVE-2014-0751£©ÔÚHMI·þÎñÆ÷ÉÏÖ´ÐжñÒâ.cimÎļþ£¬²¢×îÖÕ×°ÖÃBlackEnergy¡£Æ¾Ö¤¿¨°Í˹»ùµÄÑо¿£¬¸Ã×éÖ¯»¹ÔøÔÚ2014ÄêʹÓÃÎ÷ÃÅ×ÓWinCCÖеÄÎó²î£¨CVE-2014-8551£©À´ÉøÍ¸Ä¿µÄÍøÂç¡£ÔÚ×î½üµÄ¹¥»÷ÖиÃÎó²îÒ²Ôø±»Ê¹Óá£


±ðµÄ£¬ÒÑÍù¸Ã×éÖ¯ÔøÈëÇÖÄ¿µÄÆóÒµµÄ·ÓÉÆ÷²¢×°ÖÃÖÖÖÖ¶ñÒâÄ£¿éºÍ¾ç±¾£¬ÒÔ¾ÙÐкáÏòÒÆ¶¯¡£ÔÚ×î½üµÄGreyEnergy¹¥»÷ÖÐÉÐδ·¢Ã÷ÕâÖÖÐÐΪ£¬µ«¸ÃÐÐΪºÜ¿ÉÄܱ£´æ£¬ÓÉÓڸù¥»÷ÏòÁ¿¶Ô¹¥»÷ÕߺÜÊÇÓÐÀû£¬¿ÉÓÃÓÚ°´ÆÚÍøÂç¸÷¸ö·ÓÉÆ÷Ðͺű£´æµÄÎó²îÐÅÏ¢£¬°üÀ¨0day¡£


1.1.3 ¹¥»÷Ô˶¯Sharpshooter


2018Äê12ÔÂMcAfee¼ì²âµ½Ò»¸öÕë¶ÔÈ«Çò¹ú·À³Ð°üÉÌ¡¢ºËÄÜÐÐÒµÒÔ¼°½ðÈÚÐÐÒµµÄ¹¥»÷Ô˶¯Sharpshooter¡£Ñо¿Ö°Ô±³ÆSharpshooterµÄÖ÷ҪĿµÄÊǾÙÐÐÌØ¹¤Ô˶¯¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


SharpshooterµÄÄ¿µÄÐÐÒµºÍ¹ú¼ÒÂþÑÜ£¨ÈªÔ´£ºMcAfee£©


ѬȾÁ´Ê¼ÓÚ°üÀ¨¶ñÒâºêµÄMicrosoft WordÎĵµ¡£¸Ã¶ñÒâºê×÷Ϊһ¸öµä·¶µÄdownloader£¬ÓÃÓÚ½»¸¶¶ñÒâÖ²ÈëÎï¡£¹¥»÷Õßͨ¹ýDropboxÀ´·Ö·¢ÊÜѬȾµÄÎļþ¡£¸ÃÖ²ÈëÎÃûΪRising Sun£©ÊÇÒ»¸öеÄÄ£¿é»¯ºóÃÅ£¬Ö»ÔÚÄÚ´æÖÐÔËÐУ¬Ö÷ÒªÍøÂçÓû§Êý¾Ý£¬°üÀ¨ÅÌËã»úÃû³Æ¡¢IPµØµã¡¢ÏµÍ³ÐÅÏ¢µÈ¡£ÍøÂçµ½µÄÊý¾Ý±»¼ÓÃÜ´«ÊäÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¿¨°Í˹»ùÑо¿Ö°Ô±ÒÔΪ·¸·¨ÍÅ»ïLazarusÓëÕâЩ¹¥»÷Ô˶¯±£´æ¹ØÁª¡£


1.1.4 ¹¥»÷Ô˶¯MuddyWater


2018Äê12ÔÂÔ¤ÈüÃÅÌú¿Ë±¨¸æÁË·¸·¨ÍÅ»ïMuddyWater£¨ÓÖ³ÆSeedÈ䳿£©µÄÌØ¹¤¹¥»÷Ô˶¯¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÖж«¡¢Å·Ö޺ͱ±ÃÀµØÇøµÄÆóÒµ¡£Æ¾Ö¤ÕâÏîÑо¿£¬2018Äê9ÔÂÄ©ÖÁ11ÔÂÖÐѮʱ´ú¹²ÓÐ30¼ÒÆóÒµµÄ130ÃûÔ±¹¤Êܵ½¹¥»÷£¬´ó´ó¶¼Êܺ¦ÕßλÓÚ°Í»ù˹̹ºÍÍÁ¶úÆä£¬ÉÐÓÐÉÙÊýÊܺ¦ÕßλÓÚ¶íÂÞ˹¡¢É³Ìذ¢À­²®¡¢°¢¸»º¹¡¢Ô¼µ©µÈ¹ú¼Ò¡£¹¥»÷ÕßÖ÷ÒªÃé×¼µÄÄ¿µÄÖ®Ò»ÊÇÓÍÆøÐÐÒµ¡£Öж«µØÇøµÄ´óѧºÍÅ·ÖÞµÄÖж«´óʹ¹ÝͬÑùÔâµ½¹¥»÷¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


MuddyWater¹¥»÷Ä¿µÄµÄÐÐÒµÂþÑÜ£¨ÈªÔ´£ºÈüÃÅÌú¿Ë£©


1.1.5 ¹¥»÷Ô˶¯Cloud Hopper


2018Äê12ÔÂÖÐÑ®£¬µÂ¹úÁª°îÐÅÏ¢Çå¾²°ì¹«ÊÒ£¨BSI£©ÏòһЩµÂ¹úÆóÒµÐû²¼Á˾ݳÆÓëAPT10ÓйصÄCloudHopper¹¥»÷¾¯±¨¡£BSI³Æ¶à¼Ò´óÐ͹¤³ÌÆóÒµÒѾ­Ôâµ½¹¥»÷£¬¹¥»÷Õß»¹¶ÔÐÞ½¨ºÍÖÊÁÏѧÁìÓòµÄÆóÒµ¸ÐÐËȤ¡£


¹¥»÷Õß²¢Ã»ÓÐÖ±½Ó¹¥»÷Ä¿µÄÆóÒµ£¬¶øÊÇͨ¹ýÉøÍ¸Ä¿µÄÆóҵʹÓõÄСÐÍÔÆ·þÎñºÍÍйܷþÎñ¹©Ó¦ÉÌÌᳫ¹¥»÷¡£ÕâÀ๩ӦÉÌͨ³£Çå¾²ÐԽϲ¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÉøÍ¸Ä¿µÄ¹«Ë¾µÄÆóÒµÍøÂç¡£


1.1.6 ¶ñÒâÈí¼þShamoon v.3


2018Äê12ÔÂ10ÈÕ£¬Òâ´óÀûʯÓͺÍ×ÔÈ»Æø¹«Ë¾SiapemÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷ÕßÖ÷ÒªÕë¶Ô¸Ã¹«Ë¾Î»ÓÚÖж«¡¢Ó¡¶È¡¢ËÕ¸ñÀ¼ºÍÒâ´óÀûµÄ·þÎñÆ÷£¬Ê¹ÓõĶñÒâÈí¼þÊÇShamoonÈ䳿µÄбäÌåShamoon v.3¡£Ô¼ÓÐ300µ½400̨·þÎñÆ÷¼°100̨ÊÂÇéÕ¾Ôڴ˴ι¥»÷ÊÂÎñÖÐÊܵ½Ó°Ïì¡£


ÔÚSaipemÐû²¼ÉùÃ÷Ö®ºó£¬ÈüÃÅÌú¿Ë·¢Ã÷ÏÕЩÔÚͳһʱ¼äÉÐÓÐÁ½¼ÒλÓÚÉ³ÌØ°¢À­²®ºÍ°¢ÁªÇõµÄʯÓͺÍ×ÔÈ»Æø¹«Ë¾Ôâµ½ÀàËÆµÄ¹¥»÷¡£


ShamoonÈ䳿Ê״ηºÆðÓÚ2012ÄêÕë¶ÔÉ³ÌØ°¢À­²®¹ú¼ÒʯÓ͹«Ë¾AramcoºÍ¿¨Ëþ¶û×ÔÈ»Æø¹«Ë¾RasgasµÄ¹¥»÷Ô˶¯ÖС£ÔÚ2016-2017ÄêµÄÐÂÒ»ÂÖ¹¥»÷ÖУ¬¹¥»÷ÕßʹÓÃÁËShamoonµÄ±äÖÖ£¨Shamoon v2£©ºÍ¶ñÒâÈí¼þStoneDrill¡£


ÔÚ2018ÄêµÄ¹¥»÷Ô˶¯ÖУ¬Åãͬ×ÅShamoon v.3·ºÆðµÄÉÐÓÐÐÂÊý¾Ý²Á³ýÆ÷Filerase¡£Filerase¿É²Á³ý£¨¸²Ð´£©ÊÜѬȾϵͳÉϵÄÎļþ¡£2018ÄêµÄShamoon¹¥»÷Ô˶¯ÓÉÓÚʹÓÃÁËFilerase¶ø¸ü¾ßÆÆËðÐÔ¡£Shamoon¿ÉÒÔ²Á³ýÊÜѬȾϵͳµÄÖ÷Ö¸µ¼¼Í¼£¨MBR£©£¬µ«Ó²ÅÌÉϵÄÎļþ¿É±»»Ö¸´£¬¶øÊ¹ÓÃÁËFileraseÖ®ºóÈκÎÎļþ¶¼²»¿É»Ö¸´¡£


Filerase¾ßÓÐÄ£¿é»¯½á¹¹£¬°üÀ¨¶à¸öÓÃÓÚÔÚÍâµØÍøÂçÉϾÙÐÐÈö²¥µÄ×é¼þ¡£ÕâÒâζ×ÅFilerase×Ô¼º¿ÉÒÔ×÷Ϊһ¸öµ¥¶ÀµÄÍþв¡£FileraseÔÚÊܺ¦ÕßµÄÍâµØÍøÂçÉÏÈö²¥Ê±£¬ÒÀÀµÒ»¸öÄ¿µÄÃûµ¥À´Ñ¡È¡Ä¿µÄ¡£ÔÚ³õʼѬȾÀú³ÌÖУ¬¸ÃÃûµ¥ÊÇÓÉOCLC.exe×é¼þ¸´ÖƵÄ£¬²¢·¢Ë͸øSpreader.exe¹¤¾ß£¬ºóÕß½«Filerase¸´ÖƵ½Ãûµ¥ÉϵĻúе¡£¸ÃÃûµ¥ÊÇÒ»¸ö°üÀ¨²î±ðÊܺ¦ÕßÃû×ÖµÄÎı¾Îļþ£¬ÕâЩÃû×ÖºÜÓпÉÄÜÊǹ¥»÷ÕßÔÚ¹¥»÷µÄÔçÆÚ½×¶ÎÍøÂçµÄ¡£


McAfeeµÄÑо¿Ö°Ô±ÒÔΪShamoon v3¹¥»÷Ô˶¯¿ÉÄÜÓëÒÁÀÊ·¸·¨ÍÅ»ïAPT33ÓйØ£¬»òÊÇÁíÍâÒ»¸ö·¸·¨ÍÅ»ïαװ³ÉAPT33¡£ÈüÃÅÌú¿ËÑо¿Ö°Ô±³ÖÏàÔ޳ɼû¡£


2018Äê12ÔÂ⣬Anomali Labs±¨¸æÁËShamoonµÄÁíÒ»¸ö±äÌ壬¸Ã±äÌåÓÚ12ÔÂ23ÈÕ±»ÉÏ´«ÖÁVirusTotal¡£¸Ã±äÌåαװ³É°Ù¶È¹«Ë¾µÄÒ»¸öϵͳÉèÖúÍÓÅ»¯¹¤¾ß¾ÙÐÐÈö²¥¡£

1.2ÍøÂç·¸·¨Ô˶¯


1.2.1 ÀÕË÷Èí¼þ¹¥»÷


ƾ֤¿¨°Í˹»ùµÄÊý¾Ý£¬ÔâÊÜÀÕË÷Èí¼þ¹¥»÷µÄICSÅÌËã»ú±ÈÀý´Ó1.6%ÉÏÉýÖÁ2%¡£


WannaCryÒÀ¾ÉÊǹ¤ÒµÆóÒµÃæÁÙµÄÒ»¸öÕæÊµµÄÍþв£¬Ò²ÊÇÒ»¸ö³£¼ûµÄÍþв¡£Æ¾Ö¤¿¨°Í˹»ùµÄÊý¾Ý£¬WannaCry£¨28.72%£©ÊÇÀÕË÷Èí¼þÍþвÖеÄÁìÍ·Ñò£¨2018ÄêµÚÈý¼¾¶È£©¡£×ÝÈ»ÊÇÔÚ´ó¹æÄ£±¬·¢µÄÒ»ÄêÖ®ºó£¬WannaCryÒÀ¾É¼ÌÐøÑ¬È¾¹¤ÒµÆóÒµµÄICSÍøÂ磬ÀýÈ磬2018Äê8ÔÂ3ÈǪ̃»ýµç£¨TSMC£©µÄ¶à¼Ò¹¤³§Ôâµ½WannaCry¹¥»÷¡£Æ¾Ö¤ÏÖÓÐÐÅÏ¢£¬Ñ¬È¾ÊÇÓÉÒ»¸ö¹©Ó¦ÉÌÔÚÐÂÉú²ú¹¤¾ßÉÏ×°ÖÃÁËÊÜËðÈí¼þµ¼Öµģº¸Ã¹©Ó¦É̲¢Î´¾ÙÐÐÈκÎÇ徲ɨÃè¾Í½«Èí¼þÁ¬ÈëÉú²úÍøÂ磬µ¼Ö¶ñÒâÈí¼þÔŲ́ÄÏ¡¢ÐÂÖñºĮ́ÖеĶà¼Ò¹¤³§Ö®¼äѸËÙÈö²¥£¬Ì¨Í幤³§µÄÉú²ú±»ÆÈÖÐÖ¹ÁË3Ìì¡£


ÆäËü¹¥»÷ÊÂÎñ»¹°üÀ¨2018Äê11ÔÂ28ÈÕĪ˹¿ÆÀ³µ¹«Ë¾£¨MCC£©Ôâµ½µÄÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾³ÆÔÚ¹¥»÷ʱ´úÆäÖ÷ÒªµçÄÔϵͳÉϵÄÎļþ¾ù±»¼ÓÃÜ£¬Ô±¹¤Ñ¸ËÙ×èÖ¹ÁËÀ³µ²¢ÊèÉ¢ÁËÂÿÍ¡£¹¥»÷ÕßÒªÇóÖ§¸¶±ÈÌØ±Ò²Å»á½âÃÜ¡£¸Ã¹«Ë¾ÔÚÁ½Ììºó»Ö¸´ÁËÔËÓª¡£

1.2.2 Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷


2018Äê8Ô£¬¿¨°Í˹»ùICS CERTÐû²¼Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷µÄÊÓ²ìЧ¹û¡£¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇ´Ó¹«Ë¾µÄÕË»§ÖÐÇÔÈ¡¿î×Ó¡£


¹¥»÷ʼÓÚ2017Äê11Ô£¬²¢ÇÒÈÔÔÚÒ»Á¬¡£¹¥»÷ÕßÖ÷Òª·¢ËÍαװ³ÉÕýµ±ÉÌÒµ±¨¼ÛµÄ´¹ÂÚÓʼþ£¬ÓʼþÖеĶñÒ⸽¼þÊÜÃÜÂë±£»¤£¬¶øÃÜÂ븽ÔÚÓʼþÄÚÈÝÖС£ÕâÀàÓʼþ×Ô¼º¾­Óɸ߶Èαװ£¬ÇкϹ«Ë¾µÄÓªÒµÇéÐΡ£ÔÚ×î½üµÄÒ»²¨¹¥»÷ÖУ¬´¹ÂÚÓʼþαװ³ÉÊܺ¦ÆóÒµµÄÏàÖúͬ°é¡£¶ñÒ⸽¼þÖеľ籾½«ÔÚϵͳÉÏ×°ÖöñÒâÈí¼þ£¬È»ºóÅþÁ¬µ½¹¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷²¢ÏÂÔØÖ®Ç°ÍµÇÔµÄÕýµ±Îĵµ¡£


¹¥»÷Õß»áÔÚÊÜѬȾµÄϵͳÉÏ×°ÖÃÕýµ±µÄÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©- ÈçTeamViewerºÍRMS¡£µ«¶ñÒâÈí¼þ»áÒþ²ØÕâЩRATµÄͼÐνçÃæ£¬ÒÔÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ¿ØÖÆÊÜѬȾµÄ»úе¡£


¹¥»÷Õß½ø¶øËÑË÷ϵͳÉϵIJÆÎñºÍ»á¼ÆÈí¼þ£¬²¢²éÕÒºÍÆÊÎöÓë²É¹ºÏà¹ØµÄÕÊÄ¿Îĵµ¡¢ÏàÖúÉ̵ÄÓʼþµØµãÒÔ¼°ÓëÏàÖúÉ̵ÄͨѶÍùÀ´£¬È»ºó½øÒ»²½Ê¹ÓÃÕâЩ˽ÓÐÊý¾Ý¾ÙÐвÆÎñڲƭ£¬ÀýÈçÐ޸Ķ©µ¥ÖеÄÒøÐп¨Õ˺ŵÈ¡£


¸ü½øÒ»²½µØ£¬¹¥»÷Õß»áÔÚÐëÒªµÄÇéÐÎÏÂ×°Öøü¶àµÄ¶ñÒâÈí¼þ£¨ÒÀÊܺ¦Õß²î±ð¶ø²î±ð£©£¬ÀýÈçͨ¹ýÌØ¹¤Èí¼þºÍMimikatzÇÔÈ¡Éí·ÝÑé֤ƾ֤£¬È»ºóѬȾÆóÒµÍøÂçÖеĸü¶à»úе¡£·¸·¨·Ö×Ó»¹¾­³£½«¶ñÒâÈí¼þµÄ×é¼þαװ³ÉWindowsϵͳ×é¼þ£¬ÒÔÒþ²Ø¶ñÒâÔ˶¯µÄ×Ù¼£¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¹¥»÷Á÷³ÌµÄÕûÌåʾÒâͼ


¿¨°Í˹»ùICS CERTÒÔΪÕâЩ¹¥»÷ºÜÓпÉÄÜÊÇÓɶíÓï¹¥»÷ÕßÌᳫµÄ¡£


1.2.3 Õë¶ÔÈ«ÇòÆóÒµµÄ´¹ÂÚ¹¥»÷


2018Äê10ÔÂYoroi CERT¼ì²âµ½¼¸ÆðÕë¶ÔÒâ´óÀûˮʦºÍ¹ú·ÀÆóÒµµÄ¹¥»÷Ô˶¯¡£Ä¿µÄÆóÒµµÄÔ±¹¤ÎüÊÕµ½Ð¯´ø¶ñÒâExcelÎļþµÄ´¹ÂÚÓʼþ¡£¸Ã¶ñÒâExcelÖ¼ÔÚÏÂÔØRATľÂíMartyMcFly£¬¹¥»÷Õß¿ÉʹÓøÃľÂí¿ØÖÆÄ¿µÄ»úе¼°ÇÔÈ¡Êý¾Ý¡£±ðµÄ£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÁíÒ»¸öÔ¶³ÌÖÎÀí¹¤¾ßQuasarRAT£¨Ô´´úÂëÔÚgithubÉÏ¿ÉÓ㩵ıäÌå¡£


ƾ֤¿¨°Í˹»ùICS CERTµÄ˵·¨£¬Yoroi±¨¸æÖÐÌáµ½µÄ´¹ÂÚÓʼþÒÔ²î±ðµÄÃû³ÆÔÚÈ«ÌìϹæÄ£ÄÚÈö²¥£¬Ä¿µÄ¹ú¼Ò°üÀ¨µÂ¹ú¡¢Î÷°àÑÀ¡¢±£¼ÓÀûÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ó¡¶È¡¢ÂÞÂíÄáÑǵÈ¡£Ä¿µÄÆóÒµº­¸Ç¶à¸ö±ÊÖ±ÐÐÒµ£¬´Ó¶¹À๩ӦÉ̵½×Éѯ¹«Ë¾¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


´¹ÂÚÓʼþÖжñÒâxlsxÎļþµÄÂþÑÜ£¨ÈªÔ´£ºKSN£©


¿¨°Í˹»ùICS CERTÒÔΪ£¬´Ë´Î¹¥»÷ÊÇÓÉÕë¶Ô¶à¸öÆóÒµ£¨ÓÐʱ°üÀ¨Òªº¦»ù´¡ÉèÊ©£©¾ÙÐдó¹æÄ£´¹ÂÚ¹¥»÷µÄÏàͬ·¸·¨ÍÅ»ïÌᳫµÄ¡£ÕâЩÍÅ»ïרעÓÚÇÔÈ¡¿î×ӺͲÆÎñÊý¾Ý¡£



¶þ¡¢2018ÄêICSÎó²îͳ¼Æ



ICS×é¼þÖеÄÎó²î


±¾Ð¡½ÚÖеÄÎó²îÆÊÎöÊÇ»ùÓÚ³§ÉÌͨ¸æ¡¢¿ªÔ´Îó²î¿â£¨US ICS-CERT¡¢CVE¡¢Î÷ÃÅ×Ó CERT£©µÄ¹ûÕæÐÅÏ¢ÒÔ¼°¿¨°Í˹»ùICS CERTµÄÑо¿Ð§¹û¾ÙÐеÄ¡£US ICS-CERTÍøÕ¾ÉϵÄ2018ÄêÎó²îÐÅÏ¢±»ÓÃ×÷ͳ¼ÆÊý¾ÝµÄȪԴ¡£


2.1 Îó²îÊýÄ¿


2018Ä꣬US ICS-CERTÍøÕ¾ÉÏÅû¶µÄICSÎó²îÊýĿΪ415¸ö ¨C ±È2017Äê¶àÁË93¸ö¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


US ICS-CERTÅû¶µÄICSÎó²îÊýÄ¿


2.2 ÐÐÒµÂþÑÜ


ICSÎó²îÊýÄ¿×î¶àµÄÐÐÒµÊÇÖÆÔìÒµ£¨115£©¡¢ÄÜÔ´Òµ£¨110£©¼°¹©Ë®ÏµÍ³£¨63£©¡£±ðµÄ£¬Ê³Îï¼Ó¹¤/ũҵ£¨49£©ºÍ»¯Ñ§Òµ£¨44£©Ò²ÅÅÔÚǰÏß¡£

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 

2018ÄêICSÎó²îµÄÐÐÒµÂþÑÜ£¨»ùÓÚUS ICS-CERTµÄ·ÖÀࣩ


2.3 Îó²îÑÏÖØÐÔÂþÑÜ


Áè¼ÝÒ»°ëµÄICSÎó²î£¨284¸ö£¬2017ÄêΪ194¸ö£©µÄCVSS v.3.0ÆÀ·Ö¸ßÓÚ7·Ö£¬¼´Îª¸ßΣ£¨high£©»òÑÏÖØ£¨critical£©Îó²î¡£

ÑÏÖØÐÔÆÀ·Ö

9 - 10 (ÑÏÖØ)

7 - 8.9 (¸ßΣ)

4 - 6.9 (ÖÐΣ)

0 - 3.9 (µÍΣ)

ICSÎó²îÊýÄ¿

92

192

128

3



±í1 ¨C ICSÎó²îµÄÑÏÖØÐÔÂþÑÜ

ÓëǰһÄêµÄÊý¾ÝÏà±È£¬¸ßΣ¼°ÑÏÖØÎó²îµÄ±ÈÀýÓÐËùÔöÌí¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2017 vs 2018£¬ICSÎó²îµÄÑÏÖØÐÔÂþÑÜ£¨»ùÓÚCVSS v3ÆÀ·Ö£©


ÒÔϲúÆ·ÖаüÀ¨ÆÀ·ÖΪ10·ÖµÄÎó²î£º


  • Siemens TIM 1531 IRC Modules
  • Siemens SINUMERIK Controllers
  • Circontrol CirCarLife
  • NUUO NVRmini2 and NVRsolo
  • Emerson AMS Device Manager
  • Rockwell Automation RSLinx Classic
  • Schneider Electric U.motion Builder
  • Martem TELEM-GW6/GWM


´ó´ó¶¼ÆÀ·ÖΪ10·ÖµÄÎó²î¶¼ÊÇÉí·ÝÑéÖ¤»ò»º³åÇøÒç³öÎÊÌâ¡£


Ó¦¸Ã×¢ÖØµÄÊÇ£¬CVSSÆÀ·Ö²¢Î´Ë¼Á¿µ½ICSÏµÍ³ÌØÓеÄÇå¾²ÐԺͲî±ðÆóÒµ¹¤ÒµÁ÷³ÌµÄ²î±ðÐÔ£¬Òò´ËÔÚÆÀ¹ÀICSÎó²îµÄÑÏÖØÐÔʱ£¬ÎÒÃǽ¨Òé³ýÁËCVSSÆÀ·ÖÖ®Í⻹Ҫ¹Ø×¢Îó²îʹÓõĿÉÄÜЧ¹û£¬ÀýÈçµ¼Ö¹¤ÒµÁ÷³ÌµÄÖÐÖ¹»ò²¿·ÖÖÐÖ¹µÈ¡£

2.4 ÀàÐÍÂþÑÜ


×î³£¼ûµÄICSÎó²îÀàÐÍÊÇ»º³åÇøÒç³ö£¨Õ»»º³åÇøÒç³ö¡¢¶Ñ»º³åÇøÒç³ö¡¢µä·¶»º³åÇøÒç³ö£©¼°²»×¼È·µÄÊäÈëÑéÖ¤¡£Í¬Ê±£¬16%µÄÎó²îÊÇÉí·ÝÑéÖ¤ÎÊÌ⣨²»×¼È·µÄÉí·ÝÑéÖ¤¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢Òªº¦¹¦Ð§È±Ê§Éí·ÝÑéÖ¤£©ºÍ»á¼û¿ØÖÆÎÊÌ⣨»á¼û¿ØÖÆ¡¢²»×¼È·µÄĬÈÏȨÏÞ¡¢²»×¼È·µÄȨÏÞÖÎÀí¡¢Æ¾Ö¤ÖÎÀí£©£¬10%µÄÎó²îÊÇWebÏà¹ØÎó²î£¨×¢È롢·¾¶±éÀú¡¢CSRF¡¢XSS¡¢XXE£©¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêICSÎó²îÀàÐ͵ÄÂþÑÜ

ÓëǰһÄêÏà±È£¬»º³åÇøÒç³öÎó²îµÄ±ÈÀýÏÔÖøÔöÌí¡£ÎÒÃÇÒÔΪÕâÓëÇå¾²Ñо¿Ö°Ô±¶ÔICS×é¼þÖеÄÎó²îÔ½À´Ô½¸ÐÐËȤÓйØ£¬Ò²ÓëfuzzingµÈ×Ô¶¯»¯²âÊÔÊֶεÄʹÓÃÓйØ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

 

2017 vs 2018, ICSÎó²îÀàÐ͵ÄÂþÑÜ


¹¥»÷Õß¿ÉʹÓÃICS×é¼þÖеÄÎó²î´¥·¢í§Òâ´úÂëÖ´ÐС¢¹¤Òµ×°±¸µÄδÊÚȨ¿ØÖƼ°¾Ü¾ø·þÎñ£¨DoS£©¡£Ö÷ÒªµÄÊÇ£¬´ó´ó¶¼Îó²î£¨342¸ö£©¿É±»Ô¶³ÌʹÓ㬲¢ÇÒÎÞÐèÉí·ÝÑéÖ¤ºÍרҵ֪ʶ/¸ß¼¶ÊÖÒÕ¡£Æ¾Ö¤US ICS-CERTµÄÊý¾Ý£¬23¸öÎó²îµÄexploit¹ûÕæ¿ÉÓã¬ÕâÔöÌíÁËËüÃDZ»¶ñÒâʹÓõÄΣº¦¡£

2.5 ÊÜÓ°ÏìµÄICS×é¼þÂþÑÜ


Îó²îÊýÄ¿×î¶àµÄICS×é¼þ°üÀ¨£º


  • ¹¤³ÌÈí¼þ£¨143¸ö£©
  • SCADA/HMI×é¼þ£¨81¸ö£©
  • רΪ¹¤ÒµÇéÐÎÉè¼ÆµÄÍøÂç×°±¸£¨66¸ö£©
  • PLC£¨47¸ö£©


ÊÜÓ°ÏìµÄICS×é¼þ»¹°üÀ¨¹¤ÒµÅÌËã»úºÍ·þÎñ£¨5%£©¡¢¹¤ÒµÊÓÆµ¼à¿ØÏµÍ³£¨4%£©¡¢ÖÖÖÖ³¡¼¶×°±¸ºÍ±£»¤¼ÌµçÆ÷¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

 
2018ÄêICSÎó²îÓ°ÏìµÄ×é¼þÂþÑÜ

2.6 ¹¤³ÌÈí¼þÖеÄÎó²î


Ò×Êܹ¥»÷µÄ¹¤³ÌÈí¼þ°üÀ¨²î±ðµÄHMI/SCADA¿ª·¢Æ½Ì¨¡¢¿ØÖÆÆ÷±à³Ì¹¤¾ßµÈ¡£

¹¤³ÌÈí¼þÖеÄÇå¾²ÎÊÌâͨ³£ÊÇÓɵÚÈý·½Èí¼þµ¼ÖµÄ¡£ÓÉÓÚµÚÈý·½×é¼þµÄÆÕ±éʹÓã¬Ò»µ©·ºÆðÎó²î¾Í»áÓ°Ïì´ó×Ú¹¤Òµ²úÆ·¡£ÀýÈ磬Î÷ÃÅ×ÓÂ¥Óî¿Æ¼¼²úÆ·ºÍÎ÷ÃÅ×ÓSIMATIC WinCC²å¼þÓÉÓÚ¼¯³ÉÁ˰üÀ¨Îó²îµÄSentinel LDK RTElicenseÖÎÀíÆ÷¶øÒ×Êܹ¥»÷¡£±ðµÄ£¬Î÷ÃÅ×ÓµÄÕû¸ö¹¤Òµ²úÆ·Ïß¶¼Êܵ½OpenSSLÎó²îµÄÓ°Ïì¡£ÀàËÆµØ£¬×÷ΪFloating License ManagerµÄÒ»²¿·Ö£¬Flexera PublisherÈí¼þÖеÄÎó²îͬʱӰÏìÁËÊ©Ä͵µĶà¸öµçÆø²úÆ·¡£


±ðµÄ£¬Ó¦ÌØÊâ×¢ÖØÓÃÓÚ»á¼ûICSϵͳµÄÒÆ¶¯APP£¨Android»òiOSƽ̨µÄÖÇÄÜÊÖ»ú¡¢Æ½°åµÈ£©¡£Ò×Êܹ¥»÷µÄ´ËÀà²úÆ·°¸Àý°üÀ¨SIMATIC WinCC OA iOS App¡¢IGSS Mobile¡¢SIMATIC WinCC OA UIMobile App¡¢General Motors¼°OnStar (SOS) iOS¿Í»§¶Ë¡£´ËÀàÒÆ¶¯APPÔ½À´Ô½¶àµØÓ¦ÓÃÓÚICS»ù´¡ÉèÊ©£¬µ«ÆäÇ徲ˮƽÈÔÓдýÌá¸ß£¬Í¨¹ýÈëÇÖÒÆ¶¯APP¿ÉÄܵ¼ÖÂÕû¸öICS»ù´¡ÉèÊ©ÃæÁÙ±»ÈëÇÖµÄΣº¦¡£


ÁíÒ»¸öÀàËÆµÄÇå¾²ÎÊÌâÓëICSºÍÔÆÊÖÒÕµÄÍŽáÓйØ¡£ÀýÈ磬2018ÄêMindConnect NanoºÍMindConnect IoT2040£¨IoTÓ²¼þÍø¹Ø£¬ÓÃÓÚÅþÁ¬¹¤Òµ×°±¸ºÍÎ÷ÃÅ×ÓMindSphereÔÆÆ½Ì¨£©¾Í±»·¢Ã÷Ò×Êܹ¥»÷¡£


2.7 ¹¤ÒµÅÌËã»úºÍ·þÎñÆ÷ÖеÄÎó²î


2018Ä깤ҵÅÌËã»úºÍ·þÎñÆ÷ÖеÄÇå¾²ÎÊÌâÖ÷ÒªÓëÖ÷Á÷¹©Ó¦É̵ÄоƬÎó²îÓйØ£¬ÀýÈçÈÛ»ÙºÍÓÄÁéÎó²î£¬ÉÐÓÐSpectre-NGÎó²î¡£ÁíÒ»¸öÓ°Ïì´ó×Ú¹¤ÒµÅÌËã»úµÄÎó²îÊÇ¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©ÖеÄRCEÎó²î¡£ÕâÔÙÒ»´Î֤ʵÎú£¬¹Å°åÊÖÒÕ£¨¼´·ÇICSÌØÓеÄÊÖÒÕ£©ÖеÄÎó²î¿ÉÒÔÓ°Ï칤ҵϵͳ¡£


2.8 ¹¤ÒµÍøÂçÇå¾²½â¾ö¼Æ»®ÖеÄÎó²î


³ýÁËICSµÄÓ²¼þºÍÈí¼þ×é¼þÖеÄÎó²îÖ®Í⣬2018ÄêÑо¿Ö°Ô±»¹ÔÚ¹¤ÒµÍøÂçµÄÇå¾²½â¾ö¼Æ»®Öз¢Ã÷ÁËÎó²î£¬ÀýÈçNortekµÄ»á¼û¿ØÖÆÆ½Ì¨Linear eMerge E3 SeriesºÍÂÞ¿ËΤ¶û×Ô¶¯»¯µÄÍøÂçÇå¾²×°±¸Allen-Bradley Stratix 5950¡£ÕâÔÙ´ÎÌáÐÑÁËÎÒÃÇ£¬¹¤ÒµÏµÍ³µÄÇå¾²²»µ«ÓëICSÓ²¼þºÍÈí¼þ×é¼þÓйØ£¬»¹Ó빤ҵÇå¾²½â¾ö¼Æ»®ÖеÄÎó²îÓйØ¡£


Èý¡¢³£¼ûÍþв



3.1 Õë¶Ô¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷


°üÀ¨¶ñÒ⸽¼þµÄ´¹ÂÚÓʼþÈÔÊÇÉøÍ¸¹¤ÒµÆóÒµµÄÖ÷Òª¹¥»÷ÏòÁ¿¡£ÔÚÒÑÍùÊýÄêÖУ¬ÕâÀàÍþвÒѳÉΪ¹¤ÒµÊÂÇéÕ¾µÄ³£¼ûÍþв¡£


Ðí¶à´¹ÂÚÓʼþ¶¼¾­ÓÉÁËÈ«ÐÄαװ£ºËüÃÇαװ³ÉÕæÊµ¹«Ë¾·¢³öµÄÉÌÒµÐź¯¡¢ÓªÒµ±¨¼Û¡¢Ô¼Ç뺯µÈ¡£±ðµÄ£¬Ò»Ð©´¹ÂÚ¹¥»÷ʹÓÃÁËÕýµ±µÄÕæÊµÎĵµ×ÊÁÏ¡£ÕâÒâζ×Å´¹ÂÚ¹¥»÷Õß½«ÇÔÈ¡Õýµ±ÐÅÏ¢×÷Ϊ׼±¸Ô˶¯µÄÒ»²¿·Ö¡£
 

 ×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


´¹ÂÚÓʼþÑùÀý


Ò»Ñùƽ³£ËµÀ´£¬Õë¶Ô¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷Æä×îÖÕÄ¿µÄ¶¼ÊÇΪÁËÇÔÈ¡¿î×Ó¡£ËäÈ»£¬Ò²ÓÐһЩαװ³É¡°±ê×¼¡±´¹ÂÚ¹¥»÷µÄÕë¶ÔÐÔ¹¥»÷¡£


ƾ֤ÎÒÃǵÄͳ¼Æ£¬¹¤Òµ´¹ÂÚ¹¥»÷²»µ«Õë¶ÔÆóÒµÍøÂçÖеķþÎñÆ÷£¬»¹Õë¶Ô¹¤Òµ»ù´¡ÉèÊ©ÖеÄһЩÅÌËã»ú¡£ÔÚÈ«Çò¹æÄ£ÄÚ£¬ÖÁÉÙ4.3%µÄICSÅÌËã»úÔø¼ì³ö¹ýÌØ¹¤Èí¼þ¡¢ºóÃźͼüÅ̼ͼľÂí¡£ÕâЩ¶ñÒâÈí¼þ³£ÓÉ´¹ÂÚÓʼþ¾ÙÐзַ¢¡£ÎÒÃÇÒÔΪÕâЩ¶ñÒâÈí¼þµÄ¹æÄ£¿ÉÄÜÔ½·¢ÆÕ±é£¬ÓÉÓÚ´¹ÂÚ¹¥»÷Õß³£¸üлò°´ÆÚת»»Æä¶ñÒ⹤¾ß£¬Ê¹µÃһЩ×îÐÂÑù±¾Î´±»Í³¼Æµ½¡£


ÓÉÓÚ´¹ÂÚ¹¥»÷Õ߯ð¾¢Ê¹Óô¹ÂÚÓʼþ¾ÙÐй¥»÷£¬ÎÒÃÇÊӲ쵽ÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀýÒ»Ö±ÅÊÉý¡££¨ÓëITÅÌËã»úÒ»Ñù£¬OTÅÌËã»úͨ³£Ò²×°ÖÃÁËÓʼþ¿Í»§¶Ë£¬ÒԿ繫˾½»Á÷ÐÅÏ¢ ¨C ͨ³£»¹Ê¹ÓÃÁËÏàͬµÄÓʼþÕÊ»§¡£ÎÒÃǺÜÉÙ¿´µ½OTÍøÂçÖÐʹÓÃÁËÓëIT²î±ðµÄÓʼþÕÊ»§£©¡£2018ÄêϰëÄêÎÒÃÇÔÚÈ«ÌìϹæÄ£ÄÚ¶¼·¢Ã÷ÁËÕâÒ»ÔöÌí¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

 

ÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀý


ÈçÉÏͼËùʾ£¬Î÷Å·µØÇøÒâÍâµØÅÅÃûTop3£º¸ÃµØÇøµÄÊý×ÖÔöÌíÁË2.7¸ö°Ù·Öµã£¬ÆäÖÐÔöÌí·ù¶È×î´óµÄÊǵ¹ú£¬¸ÃµØÇøµÄÊý×ÖÏÕЩ·­·¬¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

 

Î÷Å·µØÇøÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀý


Õâµ¼ÖÂÁ˵¹úÔÚÈ«ÇòÅÅÃûÖÐÒÔ6.5%λÁеÚÊ®Èý£¬¶øÒâ´óÀû£¨6.8%£©ÔòÊÇΨһÅÅÃû±ÈµÂ¹ú¸ßµÄÅ·ÖÞ¹ú¼Ò¡£

ÖµµÃ×¢ÖØµÄÊÇ£¬´¹ÂÚÓʼþÖеÄÐí¶à¶ñÒ⸽¼þÏÖÔÚ¶¼ÊǼÓÃܵÄѹËõÎļþ£¬ÃÜÂ븽ÔÚÓʼþµÄÕýÎÄÖ®ÖС£´Ë¾ÙÊÇΪÁËÌӱܼì²â£¬Í¨³£ÇéÐÎ϶ñÒâÈí¼þÖ»ÓÐÔÚÊÕ¼þÈË·­¿ª¸½¼þʱ²Å»ª¼ì²âµ½¡£


ÎÒÃǽ¨Ò飬ËùÓй«Ë¾¶¼ÒªÌáÐÑÔ±¹¤ÕâÒ»ÕæÕýµÄÍþв£¬²¢Ñ·üçûÃÇʶ±ð¹¥»÷¼£Ï󣬲»Òª·­¿ª¿ÉÒÉÎļþ»òµã»÷Á´½Ó£¬²¢½«ÈκÎDZÔÚÊÂÎñÍ¨ÖªÍøÂçÇå¾²²¿·Ö¡£


3.2 ¼ì²âÑù±¾

2018ÄêϰëÄ꿨°Í˹»ùµÄÇå¾²²úÆ·¹²ÔÚ40.8%µÄICSÅÌËã»úÉϼì²âµ½¶ñÒâÑù±¾¡£


ÕâЩ¶ñÒâÑù±¾¿É¹éÀàÓÚÒÔÏÂÖÖ±ð£¬ÁбíÖл¹±ê³öÁËÊÜ´ËÀàÑù±¾¹¥»÷µÄICSÅÌËã»úµÄ±ÈÀý¡£Çë×¢ÖØÓÉÓÚͳ¼ÆÊý¾Ý½ÓÄÉÁË»ùÓÚÊðÃûºÍÆô·¢Ê½µÄ¼ì²âÒªÁ죬һЩÎÞ·¨Çø·ÖµÄ¶ñÒâÈí¼þÑù±¾±»¹éÀàÓÚGeneric£¨Í¨Óã©ÖÖ±ð£¬ÕâÒâζ×ÅijЩÀà±ðµÄ¶ñÒâÈí¼þµÄ±ÈÀýÏÖʵÉÏÒª¸ü¸ß¡£


¼ì²âµ½µÄ¶ñÒâÑù±¾¹éÀ༰Æä±ÈÀý£º



  • 15.9% - ÁÐÈëºÚÃûµ¥µÄ»¥ÁªÍø×ÊÔ´


ÕâÀà¶ñÒâÑù±¾Í¨³£ÊÇÓû§ÔÚä¯ÀÀÆ÷Öз­¿ªÒ»¸ö¶ñÒâ»òÊÜѬȾµÄÍøÒ³Ê±ÏÂÔØµÃÀ´¡£ÕâÐ©ÍøÒ³Òѱ»ÁÐÈëºÚÃûµ¥£¬Òò´Ë´ó´ó¶¼ÇéÐÎÏÂÇå¾²²úƷͨ¹ý¼ì²âURL¼´¿É·¢Ã÷¹¥»÷¡£ÕâÀà×ÊÔ´³£ÓÃÓÚ·Ö·¢Ä¾Âí¡¢ÌØ¹¤Èí¼þºÍÀÕË÷Èí¼þ£¬ÇÒͨ³£Î±×°³É¸÷³§¼Ò¿ØÖÆÆ÷µÄÆÆ½â¹¤¾ß»òÃÜÂëÖØÖù¤¾ß£¬Ò²¿ÉÄÜÊÇαװ³É¹¤Òµ/¹¤³ÌÈí¼þµÄÆÆ½â°æ»ò²¹¶¡¡£


  • 8.7% - ¶ñÒâ¾ç±¾£¬ÍøÒ³Öض¨Ïò£¨JSºÍHTML£©£¬ÒÔ¼°ä¯ÀÀÆ÷Îó²îʹÓà ¨C 0.17%
  • 6.36% - È䳿£¬°üÀ¨Í¨¹ý¿ÉÒÆ¶¯Ã½ÌåºÍÍøÂç¹²ÏíÈö²¥µÄÈ䳿£¨Worm£©¡¢Í¨¹ýµç×ÓÓʼþÈö²¥µÄÈ䳿£¨Email-Worm£©¡¢Í¨¹ýÍøÂçÎó²îÈö²¥µÄÈ䳿£¨Net-Worm£©ºÍ¼´Ê±Ì¸ÌìÓ¦ÓÃÖеÄÈ䳿£¨IM-Worm£©¡£´ÓÍøÂç»ù´¡ÉèÊ©µÄ½Ç¶ÈÀ´¿´£¬´ó´ó¶¼È䳿¶¼ÊǹýʱµÄ¡£



ÕâÒ»ÖÖ±ðÖеļÒ×å°üÀ¨£º


  • Worm.Win32.VBNA (0.2%)£¬·ºÆðÓÚ2009Äê¡£
  • Worm.Win32.Vobfus (0.05%)£¬·ºÆðÓÚ2012Ä꣬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¨Zbot¡¢Fareit¡¢CutwailµÈ£©¡£
  • Andromeda/Gamarue (0.69%)£¬¸Ã¶ñÒâÈí¼þ¹¹½¨µÄ¾ÞÐͽ©Ê¬ÍøÂçÓÚ2017Äê±»ìî³ý¡£


ÓÈÆäÖµµÃ×¢ÖØµÄÊÇÒ»¸ö¹ýʱµ«Ä;ò»Ë¥µÄ¶ñÒâÈí¼þNetWorm.Win32.Kido(3.14%)¡£×Ô2010ÄêÎÊÊÀÒÔÀ´£¬ËüÒ»Ö±ÊÇÅÅÃû×î¸ßµÄ¼ì²âÑù±¾Ö®Ò»¡£


±ðµÄ£¬Ò²±£´æÏñWorm.Win32.Zombaque (0.02%)ÕâÑùµÄP2PÍøÂç¼Ü¹¹µÄÈ䳿£¬¹¥»÷Õß¿ÉÒÔËæÊ±¼¤»îËüÃÇ¡£»¹±£´æÊ¹ÓÃHTTPЭÒéµÄ»îÔ¾È䳿£¬ËüÃdz£ÓÉVBS±àд£¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¬ÀýÈçºóÃźÍÌØ¹¤Ä¾ÂíµÈ¡£


  • 6.35% - ÔËÐÐÔÚä¯ÀÀÆ÷ÖеÄÍÚ¿óľÂí

          0.76% - WindowsÍÚ¿óľÂí


  • 5.78% - ¶ñÒâLNKÎļþ


ÕâÀàÑù±¾Ö÷ÒªÔÚ¿ÉÒÆ¶¯Ã½ÌåÉϼì²âµ½£¬³£×÷ΪÆäËü¶ñÒâÈí¼þ¼Ò×åµÄÈö²¥»úÖÆµÄÒ»²¿·Ö£¬ÀýÈçAndromeda/Gamarue¡¢Dorkbot¡¢Jenxcus/DinihouµÈ¡£ÕâÒ»Öֱ𻹰üÀ¨CVE-2010-2568£¨¸ÃÎó²î×îÔçÓÃÓÚ·Ö·¢ÕðÍø²¡¶¾£©Îó²îʹÓõÄLNKÎļþ£¨0.66%£©¡£¸ÃÎó²î»¹±»ÓÃÓÚÈö²¥Sality¡¢Nimnul/Ramnit¡¢ZeuSºÍVobfusµÈ¼Ò×å¡£

ÏÖÔÚ£¬Î±×°³ÉÕýµ±ÎĵµµÄLNKÎļþ±»ÓÃ×÷¶à½×¶Î´¹ÂÚ¹¥»÷µÄÒ»²¿·Ö£¬ÓÃÓÚÔËÐÐPowerShell¾ç±¾²¢ÏÂÔØ¶ñÒâpayload¡£ÔÚÉÙÉÙÊýÇéÐÎÏ£¬PowerShell¾ç±¾»áÏÂÔØÒ»¸öMetasploitÄ£¿é£¨MetasploitÖеÄTCPºóÃÅ£©µÄÌØ¶¨±äÌå¡£


  • 2.85% - °üÀ¨exploits¡¢¶ñÒâºê»ò¶ñÒâÁ´½ÓµÄ¶ñÒâÎĵµ£¨MSOffice + PDF£©
  • 2.31% - ϵͳÆô¶¯Ê±»ò²åÈë¿ÉÒÆ¶¯Ã½Ìåʱ×Ô¶¯ÔËÐеĶñÒâÎļþ£¨¿ÉÖ´ÐÐÎļþ¡¢¾ç±¾¡¢autorun.inf¡¢.LNKÎļþµÈ£©


ÕâÀàÑùÔ­À´×ÔÓÚ¶à¸ö¼Ò×壬µ«¶¼ÓÐÒ»¸öÅäºÏµã ¨C ×Ô¶¯ÔËÐС£Óк¦Ë®Æ½×îµÍµÄÑù±¾ÊÇʹÓÃÔ¤½ç˵µÄÖ÷Ò³×Ô¶¯Æô¶¯ä¯ÀÀÆ÷¡£Ðí¶àʹÓÃautorun.infµÄ¼Ò×åÔÚÍøÂç»ù´¡ÉèÊ©·½Ãæ¶¼Òѹýʱ£¨Palevo¡¢ SalityºÍ KidoµÈ£©¡£

  • 2.28% - ²¡¶¾

ÕâÀà³ÌÐò°üÀ¨Virus.Win32.Sality (1.22%)¡¢Virus.Win32.Nimnul (0.87%)ºÍVirus.Win32.Virut (0.61%)¼Ò×壨ÒÑÒ»Á¬¶àÄ꣩µÈ¡£Ö»¹ÜÕâЩ¼Ò×åµÄÍøÂç»ù´¡ÉèÊ©¶¼ÒÑʧЧ£¬µ«ÓÉÓÚ×ÔÎÒÈö²¥µÄÌØÕ÷ºÍÍêÈ«×èÖ¹ËüÃǵÄÇå¾²²½·¥µÄȱ·¦£¬ËüÃÇÈÔÔÚͳ¼ÆÊý¾ÝÖÐÕ¼ÓдóÍ·¡£

  • 2% - ÀÕË÷Èí¼þ
  • 1.26% - ÒøÐÐľÂí
  • 0.9% - AutoCad¶ñÒâÈí¼þ
ÖµµÃ×¢ÖØµÄÊÇ£¬AutoCad¶ñÒâÈí¼þ£¬ÓÈÆäÊDz¡¶¾£¬Ö÷ÒªÔÚ¶«ÑǵØÇøµÄICSÅÌËã»úÉϼì²âµ½¡£¸ÃÀà¶ñÒâÈí¼þ³£ÔÚÍøÂçÎļþ¼ÐºÍ¹¤³ÌÊÂÇéÕ¾Öз¢Ã÷¡£Ö»¹ÜAutoCad¶ñÒâÈí¼þµÄѬȾá¯ÁëÔÚ2000ÄêÖÁ2010ÄêÔçÆÚ·ºÆð£¬Ä¿½ñÈÔ¿É·¢Ã÷»îÔ¾µÄÑù±¾¡£
  • 0.61% - Õë¶ÔÒÆ¶¯×°±¸µÄ¶ñÒâÎļþ£¨ÔÚ×°±¸ÅþÁ¬µ½ÅÌËã»úʱ¼ì²âµ½£©

3.3 Õë¶ÔÆû³µÖÆÔìÒµµÄÍþвTop3


´ÓÕâ·Ý±¨¸æ×îÏÈ£¬ÎÒÃǽ«Ã¿Áù¸öÔ¶ÔÒ»¸öÐÐÒµµÄTop3Íþв¾ÙÐÐÆÊÎö¡£


Õë¶ÔÆû³µÐÐÒµµÄ¹¥»÷Ö÷ÒªÊÔͼʹÓÃÆû³µµÄÖÆÔì/Õï¶Ï¹¤ÒµÁ÷³Ì»ò³µÔØÏµÍ³£¬½ñÌìÎÒÃDz¢Ã»Óз¢Ã÷ÕâÑùµÄ¹¥»÷¡£

µ«ÔÚ2018ÄêϰëÄ꣬¿¨°Í˹»ùµÄ²úÆ·×èÖ¹ÁË´ó×ÚÕë¶ÔÆû³µ¹¤³§×°ÅäÏߺÍÊÐËÁÒÔ¼°Õë¶ÔÒ»¼¶¹©Ó¦É̹¤³§£¨°üÀ¨ÔËÐÐÆû³µÐÐÒµ¶àÖÖÈí¼þ²úÆ·µÄWindowsÅÌËã»ú£©µÄ¡°Í¨Ëס±¶ñÒâÈí¼þ¡£ÕâЩ¶ñÒâÈí¼þ×Ô¼º²¢²»ÊÇÕë¶ÔICSÇéÐεÄ£¬ËüÃǰüÀ¨ÒÑÖªµÄ²¡¶¾¡¢ÍÚ¿óÈí¼þ¡¢³£¼ûµÄÌØ¹¤Èí¼þµÈ¡£Ö»¹ÜÕâЩ¶ñÒâÈí¼þµÄÄ¿µÄÊÇÔì³ÉÎïÀíÍøÂçµÄË𺦣¬µ«Æä¸±×÷ÓÿÉÄÜ»á¶ÔICSºÍOTϵͳµÄ¿ÉÓÃÐÔºÍÍêÕûÐÔÔì³ÉÖØ´óÓ°Ïì¡£


Ö÷ÒªµÄÊÇÒª¹Ø×¢Î´À´¹¥»÷µÄDZÔÚΣº¦£¬ÕâЩÍþвµÄÎÞаÐÔºÍÕë¶ÔÐÔ£¨¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷£©¼Ó¾çÁËÕâÒ»µã¡£


3.3.1 Sality½©Ê¬ÍøÂç


ÆäÖÐÒ»¸ö×î³£¼ûµÄÍþвÊÇSality£¬ËüÊÇÒ»¸ö×ÅÃûµÄÄ£¿é»¯¶à̬²¡¶¾/È䳿£¬×îÔç·ºÆðÓÚ2003Ä꣬²¢ÔÚ2015Ä껹ÔÚά»¤¡£


ÔÚÒÑÍù£¬SalityµÄC&C·þÎñÆ÷ÓÃÓÚÏÂÔØÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¼°ÇÔÈ¡Óû§µÄÕË»§Æ¾Ö¤¡£µ«ÏÖÔÚÕâЩC&CÒѾ­²»ÔÙ¿ÉÓ㬲¢ÇÒËùÓеÄSalityÑù±¾¶¼¿Éͨ¹ý³£¼ûµÄAVÊÖÒÕ¼ì²âµ½¡£


Ö»¹ÜÔÆÔÆ£¬¸Ã¶ñÒâÈí¼þÈÔÔÚÈ«ÇòÍøÂç¼ÌÐøÈö²¥¡£¿¨°Í˹»ùÔÚÆû³µÐÐÒµµÄ´ó×ÚOTÅÌËã»úÉϼì²âµ½ÁËSality£¬ÎÒÃÇÒÔΪÏÖʵÊܵ½Ñ¬È¾µÄOTÅÌËã»úÊýÄ¿¸ü¶à¡£


SalityµÄ×ÔÎÒÈö²¥ÌØÕ÷ʹµÃËü³ÉΪOT/ICS»ù´¡ÉèÊ©µÄÑÏÖØÍþв£¬Ëü¿ÉÒÔ´¥·¢¾Ü¾ø·þÎñ¼°ÓÉÓÚ¶ñÒâÁ÷Á¿µ¼ÖÂÍâµØÍøÂçµÄÐÔÄÜϽµ¡£


3.3.2 Bladabindi/njRAT½©Ê¬ÍøÂç


Õë¶ÔÆû³µÐÐÒµµÄÁíÒ»¸öÖØ´óÍþвÊÇBladabindi ¨C Ò»¸öÄ£¿é»¯µÄ¶à¹¦Ð§½©Ê¬ÍøÂçÊðÀí£¬ÆäÐÎʽÊDZàÒëºÃµÄÒ»×éAutoIT¾ç±¾¡£ËüµÄºóÃÅ/ÌØ¹¤¹¦Ð§Ê®·Öǿʢ£¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡¶àÖÖÃô¸ÐÐÅÏ¢¡£¸Ã½©Ê¬ÍøÂ绹¾ßÓÐÀàËÆÈ䳿µÄ¹¦Ð§£¬¿Éͨ¹ý¿ÉÒÆ¶¯Ã½ÌåÈö²¥¡£


ËüµÄC&C·þÎñÆ÷´¦ÓÚ»îԾ״̬£¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢·Ö·¢ÏÂÁîºÍÏÂÔØÏÂÒ»½×¶Î¶ñÒâÈí¼þ£¨¶ñÒâ¿ó¹¤¡¢DDoSÊðÀí¡¢ÀÕË÷Èí¼þµÈ£©¡£¹¥»÷ÕßʹÓö¯Ì¬DNSÊÖÒÕÀ´Ìӱܼì²âºÍ¶ñÒâÈí¼þÆÊÎö¡£ÓÉÓÚ¹¦Ð§Ç¿Ê¢£¬Bladabindi¿ÉÄܶÔOTÍøÂ籬·¢ÖØ´óÓ°Ïì¡£


3.3.3 AutoCAD½©Ê¬ÍøÂç


»ùÓÚAutoCADµÄ½©Ê¬ÍøÂçÊÇÓÉAutoLISP (FAS)ľÂí¹¹½¨µÄ£¬ÆäC&C·þÎñÆ÷Ê״ηºÆðÓÚ2013Äê¡£¸Ã½©Ê¬ÍøÂçÈÔÈ»Óɹ¥»÷Õß¾ÙÐÐά»¤¡£


FASľÂí»á¸Ä¶¯AutoCADµÄÉèÖã¬Ê¹µÃÿ´ÎÓû§·­¿ªAutoCAD¹¤³Ìʱ¶¼»áÖ´ÐиÃľÂí£¬ÕâÒ²µ¼ÖÂÿһ¸öн¨µÄÏîÄ¿¶¼»áÊܵ½Ñ¬È¾¡£


ÆäC&CÈÔ´¦ÓÚ»îԾ״̬,ÓÃÓÚÏòÊÜѬȾµÄÅÌËã»ú·Ö·¢ÏÂÒ»½×¶Î¶ñÒâÈí¼þ¡£Ä¿½ñ£¬ÒÑÖªµÄΨÖðÒ»¸öÕâÖÖpayloadµÄÑùÀýÊÇÒ»¸öVB¾ç±¾£¬¸Ã¾ç±¾ÓÃÓÚÐÞ¸Ää¯ÀÀÆ÷µÄÖ÷Ò³ÉèÖúͽ«ä¯ÀÀÆ÷µ¼º½ÖÁí§ÒâURL¡£


¸ÃľÂíÖ÷ÒªÕë¶ÔÑÇÖÞ£¨ÓÈÆäÊÇÖйú£©µÄ¹¤ÒµºÍ¹¤³ÌÆóÒµ£¬²¢ÇÒ¿ÉÄܶÔOTÍøÂçÔì³ÉÑÏÖØÓ°Ïì¡£


¿ÉÄܵijõʼѬȾ·¾¶£º
  • ¸½¼þÖаüÀ¨Ä¾ÂíÏÂÔØÆ÷acad.fas£¨Òþ²ØÔÚAutoCADÖÆÍ¼ÖУ©µÄµç×ÓÓʼþ£¬¸ÃÓʼþÓɲ»ÊÜÏÓÒɵijаüÉÌ/·Ö°üÉÌÕýµ±¹¤³Ìʦ·¢ËÍ¡£
  • ¹¥»÷Õß·¢Ë͵Ĵ¹ÂÚÓʼþ£¬Í¬ÑùЯ´ø°üÀ¨acad.fasµÄ¸½¼þ
  • Я´øacad.fasµÄ¿ÉÒÆ¶¯Ã½Ì壨ÈçUÅÌ£©
  • ÍâµØÍøÂçÉϵĹ²ÏíÎļþ£¨°üÀ¨Òþ²ØµÄacad.fas£©
ÖµµÃ×¢ÖØµÄÊÇ£¬ÔÚÅÌËã»ú±»Ñ¬È¾ºó£¬Êܺ¦Õß»áÔÚ²»ÖªÇéµÄÇéÐÎÏÂͨ¹ýUSB¡¢µç×ÓÓʼþ¡¢ÍâµØºÍÔÆ¹²ÏíÎļþ¼ÌÐøÈö²¥ÊÜѬȾµÄAutoCAD¹¤³ÌÎļþ¡£
Ï£ÆæµÄÊÇ£¬C&C·þÎñÆ÷¶ËµÄ´úÂë¶Ô´«ÈëµÄÇëÇó×öÁËһЩ¼ì²é£¨ÀýÈçIPµØµãµÄ¹ú¼Ò¹ýÂË£©£¬ÈôÊǼì²éʧ°Ü£¬Ôò²»»á½»¸¶µÚ¶þºÍµÚÈý½×¶Îpayload£¨ÀýÈçIPµØµãËùÔڵĹú¼Ò²»ÇкϹ¥»÷ÕßµÄÐËȤ£©¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿ÉÄܵijõʼѬȾ·¾¶


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¹¥»÷ɱ¾Á´


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


µÚÒ»½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Ï


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


µÚ¶þ½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Ï

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 

µÚÈý½×¶ÎVB ¾ç±¾ÑùÀý



ËÄ¡¢Íþвͳ¼Æ



±¾±¨¸æÖеÄͳ¼ÆÊý¾Ý¶¼ÊǾ­ÓÉÔÊÐí´ÓKSNÓû§µÄÅÌËã»úÉÏÄäÃûÍøÂçµÃÀ´¡£


4.1 Ñо¿ÒªÁì


¿¨°Í˹»ùICS CERT½«ÆóÒµÖеĹ¤Òµ»ù´¡ÉèÊ©¹éÀàΪICSÅÌËã»ú¡£Ïà¹ØÍ³¼ÆÊý¾Ý´ÓÕâÒ»Àà±ðµÄÅÌËã»úÉÏÍøÂçµÃÀ´¡£ÕâЩÅÌËã»ú°üÀ¨ÔËÐÐÒÔϹ¦Ð§µÄWindowsÅÌËã»ú£º


? Êý¾ÝÊÕÂÞÓë¼à¿Ø·þÎñÆ÷£¨SCADA£©£»
? Êý¾Ý´æ´¢·þÎñÆ÷£¨Historian£©£»
? Êý¾ÝÍø¹Ø£¨OPC£©£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÀο¿ÊÂÇéÕ¾£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÒÆ¶¯ÊÂÇéÕ¾£»

? ÈË»ú½çÃæ£¨HMI£©¡£


»¹°üÀ¨´Ó¹¤¿ØÍøÂçÖÎÀíÔ±ÒÔ¼°¹¤Òµ×Ô¶¯»¯ÏµÍ³¿ª·¢Ö°Ô±µÄÅÌËã»úÉÏÍøÂçµ½µÄÊý¾Ý¡£


ÔÚ±¾±¨¸æÖУ¬ÔâÊܹ¥»÷µÄÅÌËã»úÊÇÖ¸ÔÚ±¨¸æÊ±´úÎÒÃǵÄÇå¾²½â¾ö¼Æ»®ÖÁÉÙ±»´¥·¢Ò»´ÎµÄÅÌËã»ú¡£ÔâÊܹ¥»÷µÄÅÌËã»úµÄ±ÈÀýÊÇÖ¸ÔâÊܹ¥»÷µÄÅÌËã»ú£¨È¥ÖØ£©Õ¼ËùÓÐÑù±¾ÅÌËã»ú£¨ÔÚ±¨¸æÊ±´úÏòÎÒÃÇ·¢ËÍÁËÄäÃûÊý¾ÝµÄÅÌËã»ú£©µÄ±ÈÀý¡£


ͨ³£ÇéÐÎÏ£¬ÓÉÓÚ¹¤ÒµÍøÂçµÄÏÞÖÆ£¬ICS·þÎñÆ÷ºÍ¹¤³Ìʦ/²Ù×÷Ô±µÄÀο¿ÊÂÇéÕ¾²»ÊÇ24СʱÁªÍøµÄ¡£ÕâÀàÅÌËã»ú¿ÉÄÜÖ»ÔÚ£¬ÀýÈçά»¤Ê±´ú£¬²Å»ªÁªÍø¡£


ϵͳ/ÍøÂçÖÎÀíÔ±¡¢¹¤³Ìʦ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³µÄ¿ª·¢Ö°Ô±ºÍ¼¯³ÉÖ°Ô±µÄÊÂÇéÕ¾¿ÉÄܻᾭ³£ÁªÍø£¬ÉõÖÁ¿ÉÄÜÊÇ24СʱÁªÍø¡£


Òò´Ë£¬2018ÄêϰëÄêÎÒÃǵÄÑù±¾ÅÌËã»úÖÐÔ¼ÓÐ40%µÄÅÌËã»úÊǰ´ÆÚ»òÈ«ÌìÁªÍøµÄ¡£ÆäÓà»úеµÄÁªÍøÊ±¼ä²»Áè¼ÝÒ»¸öÔ£¬ÆäÖÐÐí¶àÊÇÔ¶Ô¶ÉÙÓÚÕâ¸öʱ¼äµÄ¡£


4.2ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý


2018ÄêÕûÄêÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀýÏà±È2017ÄêÔöÌíÁË3.2¸ö°Ù·Öµã£¬´ï47.2%¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2017 vs 2018£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý


2018ÄêϰëÄ꣨H2£©£¬È«ÇòÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀýÓëÉϰëÄ꣨H1£©Ïà±ÈÉÔ΢Ͻµ£¬Ï½µÁË0.37¸ö°Ù·Öµã£¬ÖÁ40.8%.


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý


2018Äê5ÔÂÖÁ8ÔÂʱ´úÕâÒ»Êý×ÖÔøÏ½µÇ÷ÊÆ£¬µ«´Ó9ÔÂ×îÏÈÓÖ·ºÆðÁËеÄÔöÌí£¬×îÖÕÒ»Ö±ÎȹÌÔÚ22%Ö®ÉÏ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨Ô¶ÈÂþÑÜ£©


Óë2017ÄêÏà±È£¬2018Äêÿ¸öÔ·ݵÄÊý×Ö¶¼Òª¸ü¸ß¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2017 vs 2018£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨Ô¶ÈÂþÑÜ£©


4.3 ¶ñÒâÈí¼þµÄÖÖ±ðÂþÑÜ


2018ÄêϰëÄ꣬¿¨°Í˹»ù¹²¼ì²âµ½2700¸ö¼Ò×åµÄ1.91Íò¸öICS¶ñÒâÈí¼þ±äÌå¡£ÓëÒÔǰһÑù£¬¾ø´ó´ó¶¼Õë¶ÔICSµÄ¹¥»÷°¸Àý¶¼ÊÇËæ»ú¹¥»÷£¬¶ø²»ÊÇÕë¶ÔÐÔ¹¥»÷¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨¶ñÒâÈí¼þÖÖ±ðÂþÑÜ£©


ľÂíÈÔÊÇ×î³£¼ûµÄÍþв£¬Óë2018ÄêÉϰëÄêÏà±È£¬ºóÃÅ£¨Backdoor£©µÄ·Ý¶îÔöÌíÁË1¸ö°Ù·Öµã£¬ÀÕË÷Èí¼þ£¨Trojan-Ransom£©ÔòÔöÌíÁË0.44¸ö°Ù·Öµã¡£

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 

2017 ¨C 2018£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨¶ñÒâÈí¼þÖÖ±ðÂþÑÜ£©


4.4 µØÀíÂþÑÜ


ÏÂÃæµÄµØÍ¼ÏÔʾÁ˲î±ð¹ú¼ÒµÄICSÅÌËã»úÔâÊܹ¥»÷µÄ±ÈÀý¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ICS¹¥»÷*µÄµØÀíÂþÑÜ
*¸Ã¹ú¼ÒÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ICS¹¥»÷±ÈÀý×î¸ßµÄ¹ú¼Ò/µØÇø£¨Top 15£©


Óë2018ÄêÉϰëÄêÏà±È£¬ICS¹¥»÷±ÈÀý¹ú¼ÒÅÅÃûµÄǰÎåÃûûÓб任£¬µ«Morocco£¨ÏÖÔÚ´¦ÓÚµÚÈýÃû£©ºÍTunisia£¨µÚËÄÃû£©½»Á÷ÁËλÖá£


2018ÄêϰëÄê¶íÂÞ˹ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀýÊÇ45.3%£¬ºÍÉϰëÄ꣨44.7%£©´¦ÓÚͳһˮƽ¡£¶íÂÞ˹µÄÅÅÃûÊǵÚ16Ãû¡£


ÅÅÃûÖнÏΪÇå¾²µÄ¹ú¼Ò/µØÇøÊǰ®¶ûÀ¼£¨11.7%£©¡¢ÈðÊ¿£¨14.9%£©¡¢µ¤Âó£¨15.2%£©¡¢ÖйúÏã¸Û£¨15.3%£©¡¢Ó¢¹ú£¨15.7%£©ºÍºÉÀ¼£¨15.7%£©¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄêICS¹¥»÷±ÈÀý×îµÍµÄ¹ú¼Ò/µØÇø


ÈôÊÇÆ¾Ö¤µØÀíÇøÓòÀ´»®·Ö£¬²î±ðÇøÓòÖ®¼äµÄÊý×ÖͬÑùÏà²îºÜ´ó¡£·ÇÖÞ¡¢¶«ÄÏÑǺͶ«ÑÇÒ»Ö±ÊÇÅÅÃû½Ï¸ßµÄµØÇø¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêH1ºÍH2£¬ICS¹¥»÷±ÈÀýµÄµØÀíÇøÓòÂþÑÜ


4.5 ѬȾԴ


ÒÑÍùÊýÄê¼ä£¬»¥ÁªÍø¡¢¿ÉÒÆ¶¯Ã½ÌåºÍµç×ÓÓʼþ³ÉΪICSÅÌËã»úµÄÖ÷ÒªÍþвȪԴ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ICSÅÌËã»ú*µÄÖ÷ÒªÍþвȪԴ£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©


* ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý


2018ÄêϰëÄ꣬»¥ÁªÍøÊÇ26.1%µÄICS¹¥»÷µÄÍþвȪԴ¡£Óë2018ÄêÉϰëÄêÏà±È£¬ÕâÒ»Êý×ÖÉÔ΢Ͻµ£¬¶øÓëÖ®Ïà·´µÄÊǵç×ÓÓʼþÍþвµÄ±ÈÀýÉÔ΢ÔöÌí¡£ÆäËüÖ÷ҪѬȾԴµÄ·Ý¶îÓë2018ÄêÉϰëÄêµÄˮƽÏà²î²»´ó¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ICSÅÌËã»úµÄÖ÷ÒªÍþвȪԴ£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©

4.6 Ö÷ҪѬȾԴµÄµØÇøÂþÑÜ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ICSÅÌËã»úÖ÷ÒªÍþвȪԴµÄµØÀíÂþÑÜ


4.6.1 »¥ÁªÍø


ÔÚËùÓеIJî±ðµØÇø£¬»¥ÁªÍø¶¼ÊÇÖ÷ÒªµÄÍþвȪԴ¡£µ«ÕûÌå¶øÑÔ±±Å·¡¢Î÷Å·ºÍ±±ÃÀµÄÍþвÊý×ֽϵÍ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ÔâÊÜ»¥ÁªÍøÍþв¹¥»÷µÄICSÅÌËã»ú±ÈÀý£¨°´µØÇøÂþÑÜ£©


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬»¥ÁªÍøÍþвÅÅÃû½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15


4.6.2 ¿ÉÒÆ¶¯Ã½Ìå


Õë¶ÔICSµÄ¿ÉÒÆ¶¯Ã½ÌåÍþв±ÈÀý½Ï¸ßµÄµØÇøÊÇ·ÇÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ£¬½ÏµÍµÄµØÇøÊDZ±ÃÀ¡¢°Ä´óÀûÑǺͱ±Å·¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ÔâÊÜ¿ÉÒÆ¶¯Ã½ÌåÍþв¹¥»÷µÄICSÅÌËã»ú±ÈÀý£¨°´µØÇøÂþÑÜ£©


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬¿ÉÒÆ¶¯Ã½ÌåÍþвÅÅÃû½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15


4.6.3 Óʼþ¿Í»§¶Ë


Õë¶ÔICSµÄµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄµØÇøÊÇÀ­¶¡ÃÀÖÞ¡¢ÄÏÅ·ºÍÎ÷Å·£¬µ«ÕûÌå¶øÑÔ¸÷¸öµØÇøµÄÊý×ÖÏà²î²»´ó¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2018ÄêϰëÄ꣬ÔâÊܶñÒâÓʼþÍþв¹¥»÷µÄICSÅÌËã»ú±ÈÀý£¨°´µØÇøÂþÑÜ£©

µÂ¹úÔÚµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15ÖÐÉϰñ£¬ÖµµÃ×¢ÖØµÄÊǸùú¼ÒÔÚÆäËü·½Ã涼δÉϰñ¡£

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
2018ÄêϰëÄ꣬µç×ÓÓʼþÍþвÅÅÃû½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15

Ô­ÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2018/90041/