¡¾±¨¸æ·ÖÏí¡¿¿¨°Í˹»ù - 2018ϰëÄêICSÍþв¾°¹Û
Ðû²¼Ê±¼ä 2019-04-26Ò»¡¢2018ϰëÄêÖ÷Òª¹¥»÷ÊÂÎñ
1.1 Õë¶Ô¹¤ÒµÐÐÒµµÄAPT¹¥»÷
1.1.1 ·¸·¨ÍÅ»ïLeafminerµÄAPT¹¥»÷
Leafminer¹¥»÷Ä¿µÄµÄÐÐÒµÂþÑÜ£¨ÈªÔ´£ºÈüÃÅÌú¿Ë£©
¹¥»÷ÕßʹÓÃÁ˶àÖÖ¹ûÕæ»ò¶¨ÖƵŤ¾ß¡¢exploitÒÔ¼°Ë®¿Ó¹¥»÷ºÍ×ֵ乥»÷£¬£¬£¬£¬£¬ÀýÈçÓÀºãÖ®À¶µÄexploitºÍMimikatz±äÌå¡£¡£¡£¡£¡£¡£
1.1.2 жñÒâÈí¼þGreyEnergy
EsetÑо¿Ö°Ô±±¨¸æÁËÓë·¸·¨ÍÅ»ïBlackEnergyÓйصĶàÆð¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬ÔÚÕâЩ¹¥»÷Öй¥»÷ÕßʹÓÃÁËÒ»¸öеĶñÒâÈí¼þGreyEnergy¡£¡£¡£¡£¡£¡£BlackEnergyÏÈǰÒÑ´ÓAPTÑо¿Ö°Ô±µÄÀ×´ïÉÏÏûÊÅ£¬£¬£¬£¬£¬µ«ÕâÒ»´Î¹¥»÷ÕßÔÙ´ÎÏÖÉí£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖÐÅ·ºÍ¶«Å·²î±ðÐÐÒµµÄ¹¤ÒµÍøÂ磬£¬£¬£¬£¬°üÀ¨ÄÜÔ´¹«Ë¾¡¢ÔËÊ乫˾µÈ£¬£¬£¬£¬£¬²¢ÖØµã¹Ø×¢ÈÏÕæÔËÓªÒªº¦»ù´¡ÉèÊ©µÄÆóÒµ¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±·¢Ã÷GreyEnergyÓë2015ÄêBlackEnergyÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄ¶ñÒâÈí¼þ±£´æ¿´·¨ÉϵÄÏàËÆÖ®´¦¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷GreyEnergyÓë·¸·¨ÍÅ»ïTeleBotsµÄ¹¥»÷»î¶¯±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£TeleBotsÒÔ¶àÆð´ó¹æÄ£¹¥»÷ÊÂÎñÖøÃû£¬£¬£¬£¬£¬ÀýÈç2017ÄêµÄNotPetyaºÍBadRabbit¡£¡£¡£¡£¡£¡£¿£¿£¿£¿¨°Í˹»ùÑо¿Ö°Ô±Ëæºó·¢Ã÷GreyEnergy»¹ÓëSofacy£¨¼´APT28£©µÄ×ÓÍÅ»ïZebrocy±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£
GreyEnergy¾ßÓÐÄ£¿£¿£¿£¿é»¯µÄϵͳ½á¹¹£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ý¼ÓÔØÏà¹ØDLLÀ´×éºÏ²î±ðµÄ¶ñÒâÈí¼þ¹¦Ð§¡£¡£¡£¡£¡£¡£Ä³Ð©ÇéÐÎÏ£¬£¬£¬£¬£¬ÕâЩ¶ñÒâÄ£¿£¿£¿£¿é´ÓC&CЧÀÍÆ÷ÏÂÔØ²¢Ö±½Ó¼ÓÔØ½øÄڴ棨²»Ð´Èë´ÅÅÌÎļþ£¬£¬£¬£¬£¬¼´ÎÞÎļþ¹¥»÷£©¡£¡£¡£¡£¡£¡£GreyEnergy¿ÉÍøÂçÊܺ¦Õߵį¾Ö¤ÒÔÉøÍ¸¹¤¿ØÍøÂç¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄ¹¤¾ß°ü»¹°üÀ¨¿ªÔ´¹¤¾ßMimikatz¡¢PsExec¡¢WinExeºÍNmapµÈ¡£¡£¡£¡£¡£¡£
GreyEnergyµÄ³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹ÂÚÓʼþ¼°ÆóÒµµÄ¹«¹²ÍøÂç×ÊÔ´£¬£¬£¬£¬£¬ËäÈ»ºÜÓпÉÄÜ»¹°üÀ¨ÆäËü¹¥»÷ÏòÁ¿¡£¡£¡£¡£¡£¡£
ÔÚ֮ǰµÄ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬¸Ã×éÖ¯ÔøÊ¹ÓÃGE CimplicityÖеÄÎó²î£¨CVE-2014-0751£©ÔÚHMIЧÀÍÆ÷ÉÏÖ´ÐжñÒâ.cimÎļþ£¬£¬£¬£¬£¬²¢×îÖÕ×°ÖÃBlackEnergy¡£¡£¡£¡£¡£¡£Æ¾Ö¤¿¨°Í˹»ùµÄÑо¿£¬£¬£¬£¬£¬¸Ã×éÖ¯»¹ÔøÔÚ2014ÄêʹÓÃÎ÷ÃÅ×ÓWinCCÖеÄÎó²î£¨CVE-2014-8551£©À´ÉøÍ¸Ä¿µÄÍøÂç¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖиÃÎó²îÒ²Ôø±»Ê¹Óᣡ£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬ÒÑÍù¸Ã×éÖ¯ÔøÈëÇÖÄ¿µÄÆóÒµµÄ·ÓÉÆ÷²¢×°ÖÃÖÖÖÖ¶ñÒâÄ£¿£¿£¿£¿éºÍ¾ç±¾£¬£¬£¬£¬£¬ÒÔ¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄGreyEnergy¹¥»÷ÖÐÉÐδ·¢Ã÷ÕâÖÖÐÐΪ£¬£¬£¬£¬£¬µ«¸ÃÐÐΪºÜ¿ÉÄܱ£´æ£¬£¬£¬£¬£¬ÓÉÓڸù¥»÷ÏòÁ¿¶Ô¹¥»÷ÕߺÜÊÇÓÐÀû£¬£¬£¬£¬£¬¿ÉÓÃÓÚ°´ÆÚÍøÂç¸÷¸ö·ÓÉÆ÷Ðͺű£´æµÄÎó²îÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨0day¡£¡£¡£¡£¡£¡£
1.1.3 ¹¥»÷»î¶¯Sharpshooter
SharpshooterµÄÄ¿µÄÐÐÒµºÍ¹ú¼ÒÂþÑÜ£¨ÈªÔ´£ºMcAfee£©
ѬȾÁ´Ê¼ÓÚ°üÀ¨¶ñÒâºêµÄMicrosoft WordÎĵµ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâºê×÷Ϊһ¸öµä·¶µÄdownloader£¬£¬£¬£¬£¬ÓÃÓÚ½»¸¶¶ñÒâÖ²ÈëÎï¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýDropboxÀ´·Ö·¢ÊÜѬȾµÄÎļþ¡£¡£¡£¡£¡£¡£¸ÃÖ²ÈëÎÃûΪRising Sun£©ÊÇÒ»¸öеÄÄ£¿£¿£¿£¿é»¯ºóÃÅ£¬£¬£¬£¬£¬Ö»ÔÚÄÚ´æÖÐÔËÐУ¬£¬£¬£¬£¬Ö÷ÒªÍøÂçÓû§Êý¾Ý£¬£¬£¬£¬£¬°üÀ¨ÅÌËã»úÃû³Æ¡¢IPµØµã¡¢ÏµÍ³ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÍøÂçµ½µÄÊý¾Ý±»¼ÓÃÜ´«ÊäÖÁ¹¥»÷ÕßµÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¿£¿£¿£¿¨°Í˹»ùÑо¿Ö°Ô±ÒÔΪ·¸·¨ÍÅ»ïLazarusÓëÕâЩ¹¥»÷»î¶¯±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£
1.1.4 ¹¥»÷»î¶¯MuddyWater
MuddyWater¹¥»÷Ä¿µÄµÄÐÐÒµÂþÑÜ£¨ÈªÔ´£ºÈüÃÅÌú¿Ë£©
1.1.5 ¹¥»÷»î¶¯Cloud Hopper
2018Äê12ÔÂÖÐÑ®£¬£¬£¬£¬£¬µÂ¹úÁª°îÐÅÏ¢Çå¾²°ì¹«ÊÒ£¨BSI£©ÏòһЩµÂ¹úÆóÒµÐû²¼Á˾ݳÆÓëAPT10ÓйصÄCloudHopper¹¥»÷¾¯±¨¡£¡£¡£¡£¡£¡£BSI³Æ¶à¼Ò´óÐ͹¤³ÌÆóÒµÒѾÔâµ½¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õß»¹¶ÔÐÞ½¨ºÍÖÊÁÏѧÁìÓòµÄÆóÒµ¸ÐÐËȤ¡£¡£¡£¡£¡£¡£
¹¥»÷Õß²¢Ã»ÓÐÖ±½Ó¹¥»÷Ä¿µÄÆóÒµ£¬£¬£¬£¬£¬¶øÊÇͨ¹ýÉøÍ¸Ä¿µÄÆóҵʹÓõÄСÐÍÔÆÐ§ÀͺÍÍйÜЧÀ͹©Ó¦ÉÌÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£ÕâÀ๩ӦÉÌͨ³£Çå¾²ÐԽϲ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÉøÍ¸Ä¿µÄ¹«Ë¾µÄÆóÒµÍøÂç¡£¡£¡£¡£¡£¡£
1.1.6 ¶ñÒâÈí¼þShamoon v.3
2018Äê12ÔÂ10ÈÕ£¬£¬£¬£¬£¬Òâ´óÀûʯÓͺÍ×ÔÈ»Æø¹«Ë¾SiapemÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÕë¶Ô¸Ã¹«Ë¾Î»ÓÚÖж«¡¢Ó¡¶È¡¢ËÕ¸ñÀ¼ºÍÒâ´óÀûµÄЧÀÍÆ÷£¬£¬£¬£¬£¬Ê¹ÓõĶñÒâÈí¼þÊÇShamoonÈ䳿µÄбäÌåShamoon v.3¡£¡£¡£¡£¡£¡£Ô¼ÓÐ300µ½400̨ЧÀÍÆ÷¼°100̨ÊÂÇéÕ¾Ôڴ˴ι¥»÷ÊÂÎñÖÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÚSaipemÐû²¼ÉùÃ÷Ö®ºó£¬£¬£¬£¬£¬ÈüÃÅÌú¿Ë·¢Ã÷ÏÕЩÔÚͳһʱ¼äÉÐÓÐÁ½¼ÒλÓÚÉ³ÌØ°¢À²®ºÍ°¢ÁªÇõµÄʯÓͺÍ×ÔÈ»Æø¹«Ë¾Ôâµ½ÀàËÆµÄ¹¥»÷¡£¡£¡£¡£¡£¡£
ShamoonÈ䳿Ê״ηºÆðÓÚ2012ÄêÕë¶ÔÉ³ÌØ°¢À²®¹ú¼ÒʯÓ͹«Ë¾AramcoºÍ¿¨Ëþ¶û×ÔÈ»Æø¹«Ë¾RasgasµÄ¹¥»÷»î¶¯ÖС£¡£¡£¡£¡£¡£ÔÚ2016-2017ÄêµÄÐÂÒ»ÂÖ¹¥»÷ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËShamoonµÄ±äÖÖ£¨Shamoon v2£©ºÍ¶ñÒâÈí¼þStoneDrill¡£¡£¡£¡£¡£¡£
ÔÚ2018ÄêµÄ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬Åãͬ×ÅShamoon v.3·ºÆðµÄÉÐÓÐÐÂÊý¾Ý²Á³ýÆ÷Filerase¡£¡£¡£¡£¡£¡£Filerase¿É²Á³ý£¨¸²Ð´£©ÊÜѬȾϵͳÉϵÄÎļþ¡£¡£¡£¡£¡£¡£2018ÄêµÄShamoon¹¥»÷»î¶¯ÓÉÓÚʹÓÃÁËFilerase¶ø¸ü¾ßÆÆËðÐÔ¡£¡£¡£¡£¡£¡£Shamoon¿ÉÒÔ²Á³ýÊÜѬȾϵͳµÄÖ÷Ö¸µ¼¼Í¼£¨MBR£©£¬£¬£¬£¬£¬µ«Ó²ÅÌÉϵÄÎļþ¿É±»»Ö¸´£¬£¬£¬£¬£¬¶øÊ¹ÓÃÁËFileraseÖ®ºóÈκÎÎļþ¶¼²»¿É»Ö¸´¡£¡£¡£¡£¡£¡£
Filerase¾ßÓÐÄ£¿£¿£¿£¿é»¯½á¹¹£¬£¬£¬£¬£¬°üÀ¨¶à¸öÓÃÓÚÔÚÍâµØÍøÂçÉϾÙÐÐÈö²¥µÄ×é¼þ¡£¡£¡£¡£¡£¡£ÕâÒâζ×ÅFilerase×Ô¼º¿ÉÒÔ×÷Ϊһ¸öµ¥¶ÀµÄÍþв¡£¡£¡£¡£¡£¡£FileraseÔÚÊܺ¦ÕßµÄÍâµØÍøÂçÉÏÈö²¥Ê±£¬£¬£¬£¬£¬ÒÀÀµÒ»¸öÄ¿µÄÃûµ¥À´Ñ¡È¡Ä¿µÄ¡£¡£¡£¡£¡£¡£ÔÚ³õʼѬȾÀú³ÌÖУ¬£¬£¬£¬£¬¸ÃÃûµ¥ÊÇÓÉOCLC.exe×é¼þ¸´ÖƵ쬣¬£¬£¬£¬²¢·¢Ë͸øSpreader.exe¹¤¾ß£¬£¬£¬£¬£¬ºóÕß½«Filerase¸´ÖƵ½Ãûµ¥ÉϵĻúе¡£¡£¡£¡£¡£¡£¸ÃÃûµ¥ÊÇÒ»¸ö°üÀ¨²î±ðÊܺ¦ÕßÃû×ÖµÄÎı¾Îļþ£¬£¬£¬£¬£¬ÕâЩÃû×ÖºÜÓпÉÄÜÊǹ¥»÷ÕßÔÚ¹¥»÷µÄÔçÆÚ½×¶ÎÍøÂçµÄ¡£¡£¡£¡£¡£¡£
McAfeeµÄÑо¿Ö°Ô±ÒÔΪShamoon v3¹¥»÷»î¶¯¿ÉÄÜÓëÒÁÀÊ·¸·¨ÍÅ»ïAPT33Óйأ¬£¬£¬£¬£¬»òÊÇÁíÍâÒ»¸ö·¸·¨ÍÅ»ïαװ³ÉAPT33¡£¡£¡£¡£¡£¡£ÈüÃÅÌú¿ËÑо¿Ö°Ô±³ÖÏàÔ޳ɼû¡£¡£¡£¡£¡£¡£
1.2ÍøÂç·¸·¨»î¶¯
1.2.1 ÀÕË÷Èí¼þ¹¥»÷
ƾ֤¿¨°Í˹»ùµÄÊý¾Ý£¬£¬£¬£¬£¬ÔâÊÜÀÕË÷Èí¼þ¹¥»÷µÄICSÅÌËã»ú±ÈÀý´Ó1.6%ÉÏÉýÖÁ2%¡£¡£¡£¡£¡£¡£
WannaCryÒÀ¾ÉÊǹ¤ÒµÆóÒµÃæÁÙµÄÒ»¸öÕæÊµµÄÍþв£¬£¬£¬£¬£¬Ò²ÊÇÒ»¸ö³£¼ûµÄÍþв¡£¡£¡£¡£¡£¡£Æ¾Ö¤¿¨°Í˹»ùµÄÊý¾Ý£¬£¬£¬£¬£¬WannaCry£¨28.72%£©ÊÇÀÕË÷Èí¼þÍþвÖеÄÁìÍ·Ñò£¨2018ÄêµÚÈý¼¾¶È£©¡£¡£¡£¡£¡£¡£×ÝÈ»ÊÇÔÚ´ó¹æÄ£±¬·¢µÄÒ»ÄêÖ®ºó£¬£¬£¬£¬£¬WannaCryÒÀ¾É¼ÌÐøÑ¬È¾¹¤ÒµÆóÒµµÄICSÍøÂ磬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬2018Äê8ÔÂ3ÈǪ̃»ýµç£¨TSMC£©µÄ¶à¼Ò¹¤³§Ôâµ½WannaCry¹¥»÷¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÏÖÓÐÐÅÏ¢£¬£¬£¬£¬£¬Ñ¬È¾ÊÇÓÉÒ»¸ö¹©Ó¦ÉÌÔÚÐÂÉú²ú¹¤¾ßÉÏ×°ÖÃÁËÊÜËðÈí¼þµ¼Öµģº¸Ã¹©Ó¦É̲¢Î´¾ÙÐÐÈκÎÇ徲ɨÃè¾Í½«Èí¼þÁ¬ÈëÉú²úÍøÂ磬£¬£¬£¬£¬µ¼Ö¶ñÒâÈí¼þÔŲ́ÄÏ¡¢ÐÂÖñºĮ́ÖеĶà¼Ò¹¤³§Ö®¼äѸËÙÈö²¥£¬£¬£¬£¬£¬Ì¨Í幤³§µÄÉú²ú±»ÆÈÖÐÖ¹ÁË3Ìì¡£¡£¡£¡£¡£¡£
1.2.2 Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷
2018Äê8Ô£¬£¬£¬£¬£¬¿¨°Í˹»ùICS CERTÐû²¼Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷µÄÊÓ²ìЧ¹û¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇ´Ó¹«Ë¾µÄÕË»§ÖÐÇÔÈ¡¿î×Ó¡£¡£¡£¡£¡£¡£
¹¥»÷ʼÓÚ2017Äê11Ô£¬£¬£¬£¬£¬²¢ÇÒÈÔÔÚÒ»Á¬¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷Òª·¢ËÍαװ³ÉÕýµ±ÉÌÒµ±¨¼ÛµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬ÓʼþÖеĶñÒ⸽¼þÊÜÃÜÂë±£»£»£»£»¤£¬£¬£¬£¬£¬¶øÃÜÂ븽ÔÚÓʼþÄÚÈÝÖС£¡£¡£¡£¡£¡£ÕâÀàÓʼþ×Ô¼º¾Óɸ߶Èαװ£¬£¬£¬£¬£¬ÇкϹ«Ë¾µÄÓªÒµÇéÐΡ£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÒ»²¨¹¥»÷ÖУ¬£¬£¬£¬£¬´¹ÂÚÓʼþαװ³ÉÊܺ¦ÆóÒµµÄÏàÖúͬ°é¡£¡£¡£¡£¡£¡£¶ñÒ⸽¼þÖеľ籾½«ÔÚϵͳÉÏ×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬È»ºóÅþÁ¬µ½¹¥»÷ÕßµÄÔ¶³ÌЧÀÍÆ÷²¢ÏÂÔØÖ®Ç°ÍµÇÔµÄÕýµ±Îĵµ¡£¡£¡£¡£¡£¡£
¹¥»÷Õß»áÔÚÊÜѬȾµÄϵͳÉÏ×°ÖÃÕýµ±µÄÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©- ÈçTeamViewerºÍRMS¡£¡£¡£¡£¡£¡£µ«¶ñÒâÈí¼þ»áÒþ²ØÕâЩRATµÄͼÐνçÃæ£¬£¬£¬£¬£¬ÒÔÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ¿ØÖÆÊÜѬȾµÄ»úе¡£¡£¡£¡£¡£¡£
¹¥»÷Õß½ø¶øËÑË÷ϵͳÉϵIJÆÎñºÍ»á¼ÆÈí¼þ£¬£¬£¬£¬£¬²¢²éÕÒºÍÆÊÎöÓë²É¹ºÏà¹ØµÄÕÊÄ¿Îĵµ¡¢ÏàÖúÉ̵ÄÓʼþµØµãÒÔ¼°ÓëÏàÖúÉ̵ÄͨѶÍùÀ´£¬£¬£¬£¬£¬È»ºó½øÒ»²½Ê¹ÓÃÕâЩ˽ÓÐÊý¾Ý¾ÙÐвÆÎñڲƣ¬£¬£¬£¬£¬ÀýÈçÐ޸Ķ©µ¥ÖеÄÒøÐп¨Õ˺ŵȡ£¡£¡£¡£¡£¡£
¹¥»÷Á÷³ÌµÄÕûÌåʾÒâͼ
¿¨°Í˹»ùICS CERTÒÔΪÕâЩ¹¥»÷ºÜÓпÉÄÜÊÇÓɶíÓï¹¥»÷ÕßÌᳫµÄ¡£¡£¡£¡£¡£¡£
1.2.3 Õë¶ÔÈ«ÇòÆóÒµµÄ´¹ÂÚ¹¥»÷
2018Äê10ÔÂYoroi CERT¼ì²âµ½¼¸ÆðÕë¶ÔÒâ´óÀûˮʦºÍ¹ú·ÀÆóÒµµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£Ä¿µÄÆóÒµµÄÔ±¹¤ÎüÊÕµ½Ð¯´ø¶ñÒâExcelÎļþµÄ´¹ÂÚÓʼþ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâExcelÖ¼ÔÚÏÂÔØRATľÂíMartyMcFly£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃľÂí¿ØÖÆÄ¿µÄ»úе¼°ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÁíÒ»¸öÔ¶³ÌÖÎÀí¹¤¾ßQuasarRAT£¨Ô´´úÂëÔÚgithubÉÏ¿ÉÓ㩵ıäÌå¡£¡£¡£¡£¡£¡£
´¹ÂÚÓʼþÖжñÒâxlsxÎļþµÄÂþÑÜ£¨ÈªÔ´£ºKSN£©
¿¨°Í˹»ùICS CERTÒÔΪ£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÊÇÓÉÕë¶Ô¶à¸öÆóÒµ£¨ÓÐʱ°üÀ¨Òªº¦»ù´¡ÉèÊ©£©¾ÙÐдó¹æÄ£´¹ÂÚ¹¥»÷µÄÏàͬ·¸·¨ÍÅ»ïÌᳫµÄ¡£¡£¡£¡£¡£¡£ÕâЩÍÅ»ïרעÓÚÇÔÈ¡¿î×ӺͲÆÎñÊý¾Ý¡£¡£¡£¡£¡£¡£
¶þ¡¢2018ÄêICSÎó²îͳ¼Æ
±¾Ð¡½ÚÖеÄÎó²îÆÊÎöÊÇ»ùÓÚ³§ÉÌͨ¸æ¡¢¿ªÔ´Îó²î¿â£¨US ICS-CERT¡¢CVE¡¢Î÷ÃÅ×Ó CERT£©µÄ¹ûÕæÐÅÏ¢ÒÔ¼°¿¨°Í˹»ùICS CERTµÄÑо¿Ð§¹û¾ÙÐеġ£¡£¡£¡£¡£¡£US ICS-CERTÍøÕ¾ÉϵÄ2018ÄêÎó²îÐÅÏ¢±»ÓÃ×÷ͳ¼ÆÊý¾ÝµÄȪԴ¡£¡£¡£¡£¡£¡£
2.1 Îó²îÊýÄ¿
US ICS-CERTÅû¶µÄICSÎó²îÊýÄ¿
2.2 ÐÐÒµÂþÑÜ
2018ÄêICSÎó²îµÄÐÐÒµÂþÑÜ£¨»ùÓÚUS ICS-CERTµÄ·ÖÀࣩ
2.3 Îó²îÑÏÖØÐÔÂþÑÜ
ÑÏÖØÐÔÆÀ·Ö
9 - 10 (ÑÏÖØ)
7 - 8.9 (¸ßΣ)
4 - 6.9 (ÖÐΣ)
0 - 3.9 (µÍΣ)
ICSÎó²îÊýÄ¿
92
192
128
3
2017 vs 2018£¬£¬£¬£¬£¬ICSÎó²îµÄÑÏÖØÐÔÂþÑÜ£¨»ùÓÚCVSS v3ÆÀ·Ö£©
ÒÔϲúÆ·ÖаüÀ¨ÆÀ·ÖΪ10·ÖµÄÎó²î£º
- Siemens TIM 1531 IRC Modules
- Siemens SINUMERIK Controllers
- Circontrol CirCarLife
- NUUO NVRmini2 and NVRsolo
- Emerson AMS Device Manager
- Rockwell Automation RSLinx Classic
- Schneider Electric U.motion Builder
- Martem TELEM-GW6/GWM
´ó´ó¶¼ÆÀ·ÖΪ10·ÖµÄÎó²î¶¼ÊÇÉí·ÝÑéÖ¤»ò»º³åÇøÒç³öÎÊÌâ¡£¡£¡£¡£¡£¡£
2.4 ÀàÐÍÂþÑÜ
ÓëǰһÄêÏà±È£¬£¬£¬£¬£¬»º³åÇøÒç³öÎó²îµÄ±ÈÀýÏÔÖøÔöÌí¡£¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâÓëÇå¾²Ñо¿Ö°Ô±¶ÔICS×é¼þÖеÄÎó²îÔ½À´Ô½¸ÐÐËȤÓйأ¬£¬£¬£¬£¬Ò²ÓëfuzzingµÈ×Ô¶¯»¯²âÊÔÊֶεÄʹÓÃÓйء£¡£¡£¡£¡£¡£
2017 vs 2018, ICSÎó²îÀàÐ͵ÄÂþÑÜ
2.5 ÊÜÓ°ÏìµÄICS×é¼þÂþÑÜ
Îó²îÊýÄ¿×î¶àµÄICS×é¼þ°üÀ¨£º
- ¹¤³ÌÈí¼þ£¨143¸ö£©
- SCADA/HMI×é¼þ£¨81¸ö£©
- רΪ¹¤ÒµÇéÐÎÉè¼ÆµÄÍøÂç×°±¸£¨66¸ö£©
- PLC£¨47¸ö£©
ÊÜÓ°ÏìµÄICS×é¼þ»¹°üÀ¨¹¤ÒµÅÌËã»úºÍЧÀÍ£¨5%£©¡¢¹¤ÒµÊÓÆµ¼à¿ØÏµÍ³£¨4%£©¡¢ÖÖÖÖ³¡¼¶×°±¸ºÍ±£»£»£»£»¤¼ÌµçÆ÷¡£¡£¡£¡£¡£¡£
2.6 ¹¤³ÌÈí¼þÖеÄÎó²î
¹¤³ÌÈí¼þÖеÄÇå¾²ÎÊÌâͨ³£ÊÇÓɵÚÈý·½Èí¼þµ¼Öµġ£¡£¡£¡£¡£¡£ÓÉÓÚµÚÈý·½×é¼þµÄÆÕ±éʹÓ㬣¬£¬£¬£¬Ò»µ©·ºÆðÎó²î¾Í»áÓ°Ïì´ó×Ú¹¤Òµ²úÆ·¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬Î÷ÃÅ×ÓÂ¥Óî¿Æ¼¼²úÆ·ºÍÎ÷ÃÅ×ÓSIMATIC WinCC²å¼þÓÉÓÚ¼¯³ÉÁ˰üÀ¨Îó²îµÄSentinel LDK RTElicenseÖÎÀíÆ÷¶øÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Î÷ÃÅ×ÓµÄÕû¸ö¹¤Òµ²úÆ·Ïß¶¼Êܵ½OpenSSLÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£ÀàËÆµØ£¬£¬£¬£¬£¬×÷ΪFloating License ManagerµÄÒ»²¿·Ö£¬£¬£¬£¬£¬Flexera PublisherÈí¼þÖеÄÎó²îͬʱӰÏìÁËÊ©Ä͵µĶà¸öµçÆø²úÆ·¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬Ó¦ÌØÊâ×¢ÖØÓÃÓÚ»á¼ûICSϵͳµÄÒÆ¶¯APP£¨Android»òiOSƽ̨µÄÖÇÄÜÊÖ»ú¡¢Æ½°åµÈ£©¡£¡£¡£¡£¡£¡£Ò×Êܹ¥»÷µÄ´ËÀà²úÆ·°¸Àý°üÀ¨SIMATIC WinCC OA iOS App¡¢IGSS Mobile¡¢SIMATIC WinCC OA UIMobile App¡¢General Motors¼°OnStar (SOS) iOS¿Í»§¶Ë¡£¡£¡£¡£¡£¡£´ËÀàÒÆ¶¯APPÔ½À´Ô½¶àµØÓ¦ÓÃÓÚICS»ù´¡ÉèÊ©£¬£¬£¬£¬£¬µ«ÆäÇ徲ˮƽÈÔÓдýÌá¸ß£¬£¬£¬£¬£¬Í¨¹ýÈëÇÖÒÆ¶¯APP¿ÉÄܵ¼ÖÂÕû¸öICS»ù´¡ÉèÊ©ÃæÁÙ±»ÈëÇÖµÄΣº¦¡£¡£¡£¡£¡£¡£
ÁíÒ»¸öÀàËÆµÄÇå¾²ÎÊÌâÓëICSºÍÔÆÊÖÒÕµÄÁ¬ÏµÓйء£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬2018ÄêMindConnect NanoºÍMindConnect IoT2040£¨IoTÓ²¼þÍø¹Ø£¬£¬£¬£¬£¬ÓÃÓÚÅþÁ¬¹¤Òµ×°±¸ºÍÎ÷ÃÅ×ÓMindSphereÔÆÆ½Ì¨£©¾Í±»·¢Ã÷Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£
2.7 ¹¤ÒµÅÌËã»úºÍЧÀÍÆ÷ÖеÄÎó²î
2018Ä깤ҵÅÌËã»úºÍЧÀÍÆ÷ÖеÄÇå¾²ÎÊÌâÖ÷ÒªÓëÖ÷Á÷¹©Ó¦É̵ÄоƬÎó²îÓйأ¬£¬£¬£¬£¬ÀýÈçÈÛ»ÙºÍÓÄÁéÎó²î£¬£¬£¬£¬£¬ÉÐÓÐSpectre-NGÎó²î¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÓ°Ïì´ó×Ú¹¤ÒµÅÌËã»úµÄÎó²îÊÇ¿ÉÐÅÆ½Ì¨Ä£¿£¿£¿£¿é£¨TPM£©ÖеÄRCEÎó²î¡£¡£¡£¡£¡£¡£ÕâÔÙÒ»´Î֤ʵÎú£¬£¬£¬£¬£¬¹Å°åÊÖÒÕ£¨¼´·ÇICSÌØÓеÄÊÖÒÕ£©ÖеÄÎó²î¿ÉÒÔÓ°Ï칤ҵϵͳ¡£¡£¡£¡£¡£¡£
2.8 ¹¤ÒµÍøÂçÇå¾²½â¾ö¼Æ»®ÖеÄÎó²î
Èý¡¢³£¼ûÍþв
3.1 Õë¶Ô¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷
°üÀ¨¶ñÒ⸽¼þµÄ´¹ÂÚÓʼþÈÔÊÇÉøÍ¸¹¤ÒµÆóÒµµÄÖ÷Òª¹¥»÷ÏòÁ¿¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùÊýÄêÖУ¬£¬£¬£¬£¬ÕâÀàÍþвÒѳÉΪ¹¤ÒµÊÂÇéÕ¾µÄ³£¼ûÍþв¡£¡£¡£¡£¡£¡£

´¹ÂÚÓʼþÑùÀý
Ò»Ñùƽ³£ËµÀ´£¬£¬£¬£¬£¬Õë¶Ô¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷Æä×îÖÕÄ¿µÄ¶¼ÊÇΪÁËÇÔÈ¡¿î×Ó¡£¡£¡£¡£¡£¡£ËäÈ»£¬£¬£¬£¬£¬Ò²ÓÐһЩαװ³É¡°±ê×¼¡±´¹ÂÚ¹¥»÷µÄÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£
ƾ֤¿·¢k8ͳ¼Æ£¬£¬£¬£¬£¬¹¤Òµ´¹ÂÚ¹¥»÷²»µ«Õë¶ÔÆóÒµÍøÂçÖеÄЧÀÍÆ÷£¬£¬£¬£¬£¬»¹Õë¶Ô¹¤Òµ»ù´¡ÉèÊ©ÖеÄһЩÅÌËã»ú¡£¡£¡£¡£¡£¡£ÔÚÈ«Çò¹æÄ£ÄÚ£¬£¬£¬£¬£¬ÖÁÉÙ4.3%µÄICSÅÌËã»úÔø¼ì³ö¹ýÌØ¹¤Èí¼þ¡¢ºóÃźͼüÅ̼ͼľÂí¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ³£ÓÉ´¹ÂÚÓʼþ¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâЩ¶ñÒâÈí¼þµÄ¹æÄ£¿ÉÄÜÔ½·¢ÆÕ±é£¬£¬£¬£¬£¬ÓÉÓÚ´¹ÂÚ¹¥»÷Õß³£¸üлò°´ÆÚת»»Æä¶ñÒ⹤¾ß£¬£¬£¬£¬£¬Ê¹µÃһЩ×îÐÂÑù±¾Î´±»Í³¼Æµ½¡£¡£¡£¡£¡£¡£
ÓÉÓÚ´¹ÂÚ¹¥»÷Õ߯ð¾¢Ê¹Óô¹ÂÚÓʼþ¾ÙÐй¥»÷£¬£¬£¬£¬£¬ÎÒÃÇÊӲ쵽ÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀýÒ»Ö±ÅÊÉý¡£¡£¡£¡£¡£¡££¨ÓëITÅÌËã»úÒ»Ñù£¬£¬£¬£¬£¬OTÅÌËã»úͨ³£Ò²×°ÖÃÁËÓʼþ¿Í»§¶Ë£¬£¬£¬£¬£¬ÒԿ繫˾½»Á÷ÐÅÏ¢ ¨C ͨ³£»£»£»£»¹Ê¹ÓÃÁËÏàͬµÄÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£ÎÒÃǺÜÉÙ¿´µ½OTÍøÂçÖÐʹÓÃÁËÓëIT²î±ðµÄÓʼþÕÊ»§£©¡£¡£¡£¡£¡£¡£2018ÄêϰëÄêÎÒÃÇÔÚÈ«ÌìϹæÄ£ÄÚ¶¼·¢Ã÷ÁËÕâÒ»ÔöÌí¡£¡£¡£¡£¡£¡£
ÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀý
ÈçÉÏͼËùʾ£¬£¬£¬£¬£¬Î÷Å·µØÇøÒâÍâµØÅÅÃûTop3£º¸ÃµØÇøµÄÊý×ÖÔöÌíÁË2.7¸ö°Ù·Öµã£¬£¬£¬£¬£¬ÆäÖÐÔöÌí·ù¶È×î´óµÄÊǵ¹ú£¬£¬£¬£¬£¬¸ÃµØÇøµÄÊý×ÖÏÕЩ··¬¡£¡£¡£¡£¡£¡£
Î÷Å·µØÇøÊÜ´¹ÂÚÓʼþ¹¥»÷µÄICSÅÌËã»ú±ÈÀý
ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬´¹ÂÚÓʼþÖеÄÐí¶à¶ñÒ⸽¼þÏÖÔÚ¶¼ÊǼÓÃܵÄѹËõÎļþ£¬£¬£¬£¬£¬ÃÜÂ븽ÔÚÓʼþµÄÕýÎÄÖ®ÖС£¡£¡£¡£¡£¡£´Ë¾ÙÊÇΪÁËÌӱܼì²â£¬£¬£¬£¬£¬Í¨³£ÇéÐÎ϶ñÒâÈí¼þÖ»ÓÐÔÚÊÕ¼þÈË·¿ª¸½¼þʱ²Å»ª¼ì²âµ½¡£¡£¡£¡£¡£¡£
ÎÒÃǽ¨Ò飬£¬£¬£¬£¬ËùÓй«Ë¾¶¼ÒªÌáÐÑÔ±¹¤ÕâÒ»ÕæÕýµÄÍþв£¬£¬£¬£¬£¬²¢Ñ·üçûÃÇʶ±ð¹¥»÷¼£Ï󣬣¬£¬£¬£¬²»Òª·¿ª¿ÉÒÉÎļþ»òµã»÷Á´½Ó£¬£¬£¬£¬£¬²¢½«ÈκÎDZÔÚÊÂÎñÍ¨ÖªÍøÂçÇå¾²²¿·Ö¡£¡£¡£¡£¡£¡£
2018ÄêϰëÄ꿨°Í˹»ùµÄÇå¾²²úÆ·¹²ÔÚ40.8%µÄICSÅÌËã»úÉϼì²âµ½¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£
ÕâЩ¶ñÒâÑù±¾¿É¹éÀàÓÚÒÔÏÂÖֱ𣬣¬£¬£¬£¬ÁбíÖл¹±ê³öÁËÊÜ´ËÀàÑù±¾¹¥»÷µÄICSÅÌËã»úµÄ±ÈÀý¡£¡£¡£¡£¡£¡£Çë×¢ÖØÓÉÓÚͳ¼ÆÊý¾Ý½ÓÄÉÁË»ùÓÚÊðÃûºÍÆô·¢Ê½µÄ¼ì²âÒªÁ죬£¬£¬£¬£¬Ò»Ð©ÎÞ·¨Çø·ÖµÄ¶ñÒâÈí¼þÑù±¾±»¹éÀàÓÚGeneric£¨Í¨Óã©Öֱ𣬣¬£¬£¬£¬ÕâÒâζ×ÅijЩÀà±ðµÄ¶ñÒâÈí¼þµÄ±ÈÀýÏÖʵÉÏÒª¸ü¸ß¡£¡£¡£¡£¡£¡£
¼ì²âµ½µÄ¶ñÒâÑù±¾¹éÀ༰Æä±ÈÀý£º
- 15.9% - ÁÐÈëºÚÃûµ¥µÄ»¥ÁªÍø×ÊÔ´
ÕâÀà¶ñÒâÑù±¾Í¨³£ÊÇÓû§ÔÚä¯ÀÀÆ÷Öз¿ªÒ»¸ö¶ñÒâ»òÊÜѬȾµÄÍøÒ³Ê±ÏÂÔØµÃÀ´¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÒ³Òѱ»ÁÐÈëºÚÃûµ¥£¬£¬£¬£¬£¬Òò´Ë´ó´ó¶¼ÇéÐÎÏÂÇå¾²²úƷͨ¹ý¼ì²âURL¼´¿É·¢Ã÷¹¥»÷¡£¡£¡£¡£¡£¡£ÕâÀà×ÊÔ´³£ÓÃÓÚ·Ö·¢Ä¾Âí¡¢ÌØ¹¤Èí¼þºÍÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÇÒͨ³£Î±×°³É¸÷³§¼Ò¿ØÖÆÆ÷µÄÆÆ½â¹¤¾ß»òÃÜÂëÖØÖù¤¾ß£¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇαװ³É¹¤Òµ/¹¤³ÌÈí¼þµÄÆÆ½â°æ»ò²¹¶¡¡£¡£¡£¡£¡£¡£
- 8.7% - ¶ñÒâ¾ç±¾£¬£¬£¬£¬£¬ÍøÒ³Öض¨Ïò£¨JSºÍHTML£©£¬£¬£¬£¬£¬ÒÔ¼°ä¯ÀÀÆ÷Îó²îʹÓà ¨C 0.17%
- 6.36% - È䳿£¬£¬£¬£¬£¬°üÀ¨Í¨¹ý¿ÉÒÆ¶¯Ã½ÌåºÍÍøÂç¹²ÏíÈö²¥µÄÈ䳿£¨Worm£©¡¢Í¨¹ýµç×ÓÓʼþÈö²¥µÄÈ䳿£¨Email-Worm£©¡¢Í¨¹ýÍøÂçÎó²îÈö²¥µÄÈ䳿£¨Net-Worm£©ºÍ¼´Ê±Ì¸ÌìÓ¦ÓÃÖеÄÈ䳿£¨IM-Worm£©¡£¡£¡£¡£¡£¡£´ÓÍøÂç»ù´¡ÉèÊ©µÄ½Ç¶ÈÀ´¿´£¬£¬£¬£¬£¬´ó´ó¶¼È䳿¶¼ÊǹýʱµÄ¡£¡£¡£¡£¡£¡£
ÕâÒ»ÖÖ±ðÖеļÒ×å°üÀ¨£º
- Worm.Win32.VBNA (0.2%)£¬£¬£¬£¬£¬·ºÆðÓÚ2009Äê¡£¡£¡£¡£¡£¡£
- Worm.Win32.Vobfus (0.05%)£¬£¬£¬£¬£¬·ºÆðÓÚ2012Ä꣬£¬£¬£¬£¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¨Zbot¡¢Fareit¡¢CutwailµÈ£©¡£¡£¡£¡£¡£¡£
- Andromeda/Gamarue (0.69%)£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¹¹½¨µÄ¾ÞÐͽ©Ê¬ÍøÂçÓÚ2017Äê±»ìî³ý¡£¡£¡£¡£¡£¡£
ÓÈÆäÖµµÃ×¢ÖØµÄÊÇÒ»¸ö¹ýʱµ«Ä;ò»Ë¥µÄ¶ñÒâÈí¼þNetWorm.Win32.Kido(3.14%)¡£¡£¡£¡£¡£¡£×Ô2010ÄêÎÊÊÀÒÔÀ´£¬£¬£¬£¬£¬ËüÒ»Ö±ÊÇÅÅÃû×î¸ßµÄ¼ì²âÑù±¾Ö®Ò»¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬Ò²±£´æÏñWorm.Win32.Zombaque (0.02%)ÕâÑùµÄP2PÍøÂç¼Ü¹¹µÄÈ䳿£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔËæÊ±¼¤»îËüÃÇ¡£¡£¡£¡£¡£¡£»£»£»£»¹±£´æÊ¹ÓÃHTTPÐÒéµÄ»îÔ¾È䳿£¬£¬£¬£¬£¬ËüÃdz£ÓÉVBS±àд£¬£¬£¬£¬£¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÀýÈçºóÃźÍÌØ¹¤Ä¾ÂíµÈ¡£¡£¡£¡£¡£¡£
- 6.35% - ÔËÐÐÔÚä¯ÀÀÆ÷ÖеÄÍÚ¿óľÂí
0.76% - WindowsÍÚ¿óľÂí
- 5.78% - ¶ñÒâLNKÎļþ
ÕâÀàÑù±¾Ö÷ÒªÔÚ¿ÉÒÆ¶¯Ã½ÌåÉϼì²âµ½£¬£¬£¬£¬£¬³£×÷ΪÆäËü¶ñÒâÈí¼þ¼Ò×åµÄÈö²¥»úÖÆµÄÒ»²¿·Ö£¬£¬£¬£¬£¬ÀýÈçAndromeda/Gamarue¡¢Dorkbot¡¢Jenxcus/DinihouµÈ¡£¡£¡£¡£¡£¡£ÕâÒ»Öֱ𻹰üÀ¨CVE-2010-2568£¨¸ÃÎó²î×îÔçÓÃÓÚ·Ö·¢ÕðÍø²¡¶¾£©Îó²îʹÓõÄLNKÎļþ£¨0.66%£©¡£¡£¡£¡£¡£¡£¸ÃÎó²î»¹±»ÓÃÓÚÈö²¥Sality¡¢Nimnul/Ramnit¡¢ZeuSºÍVobfusµÈ¼Ò×å¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬Î±×°³ÉÕýµ±ÎĵµµÄLNKÎļþ±»ÓÃ×÷¶à½×¶Î´¹ÂÚ¹¥»÷µÄÒ»²¿·Ö£¬£¬£¬£¬£¬ÓÃÓÚÔËÐÐPowerShell¾ç±¾²¢ÏÂÔØ¶ñÒâpayload¡£¡£¡£¡£¡£¡£ÔÚÉÙÉÙÊýÇéÐÎÏ£¬£¬£¬£¬£¬PowerShell¾ç±¾»áÏÂÔØÒ»¸öMetasploitÄ£¿£¿£¿£¿é£¨MetasploitÖеÄTCPºóÃÅ£©µÄÌØ¶¨±äÌå¡£¡£¡£¡£¡£¡£
- 2.85% - °üÀ¨exploits¡¢¶ñÒâºê»ò¶ñÒâÁ´½ÓµÄ¶ñÒâÎĵµ£¨MSOffice + PDF£©
- 2.31% - ϵͳÆô¶¯Ê±»ò²åÈë¿ÉÒÆ¶¯Ã½Ìåʱ×Ô¶¯ÔËÐеĶñÒâÎļþ£¨¿ÉÖ´ÐÐÎļþ¡¢¾ç±¾¡¢autorun.inf¡¢.LNKÎļþµÈ£©
ÕâÀàÑùÔÀ´×ÔÓÚ¶à¸ö¼Ò×壬£¬£¬£¬£¬µ«¶¼ÓÐÒ»¸öÅäºÏµã ¨C ×Ô¶¯ÔËÐС£¡£¡£¡£¡£¡£Óк¦Ë®Æ½×îµÍµÄÑù±¾ÊÇʹÓÃÔ¤½ç˵µÄÖ÷Ò³×Ô¶¯Æô¶¯ä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£Ðí¶àʹÓÃautorun.infµÄ¼Ò×åÔÚÍøÂç»ù´¡ÉèÊ©·½Ãæ¶¼Òѹýʱ£¨Palevo¡¢ SalityºÍ KidoµÈ£©¡£¡£¡£¡£¡£¡£
- 2.28% - ²¡¶¾
ÕâÀà³ÌÐò°üÀ¨Virus.Win32.Sality (1.22%)¡¢Virus.Win32.Nimnul (0.87%)ºÍVirus.Win32.Virut (0.61%)¼Ò×壨ÒÑÒ»Á¬¶àÄ꣩µÈ¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩ¼Ò×åµÄÍøÂç»ù´¡ÉèÊ©¶¼ÒÑʧЧ£¬£¬£¬£¬£¬µ«ÓÉÓÚ×ÔÎÒÈö²¥µÄÌØÕ÷ºÍÍêÈ«×èÖ¹ËüÃǵÄÇå¾²²½·¥µÄȱ·¦£¬£¬£¬£¬£¬ËüÃÇÈÔÔÚͳ¼ÆÊý¾ÝÖÐÕ¼ÓдóÍ·¡£¡£¡£¡£¡£¡£
- 2% - ÀÕË÷Èí¼þ
- 1.26% - ÒøÐÐľÂí
- 0.9% - AutoCad¶ñÒâÈí¼þ
- 0.61% - Õë¶ÔÒÆ¶¯×°±¸µÄ¶ñÒâÎļþ£¨ÔÚ×°±¸ÅþÁ¬µ½ÅÌËã»úʱ¼ì²âµ½£©
3.3 Õë¶ÔÆû³µÖÆÔìÒµµÄÍþвTop3
´ÓÕâ·Ý±¨¸æ×îÏÈ£¬£¬£¬£¬£¬ÎÒÃǽ«Ã¿Áù¸öÔ¶ÔÒ»¸öÐÐÒµµÄTop3Íþв¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£¡£
µ«ÔÚ2018ÄêϰëÄ꣬£¬£¬£¬£¬¿¨°Í˹»ùµÄ²úÆ·×èÖ¹ÁË´ó×ÚÕë¶ÔÆû³µ¹¤³§×°ÅäÏߺÍÊÐËÁÒÔ¼°Õë¶ÔÒ»¼¶¹©Ó¦É̹¤³§£¨°üÀ¨ÔËÐÐÆû³µÐÐÒµ¶àÖÖÈí¼þ²úÆ·µÄWindowsÅÌËã»ú£©µÄ¡°Í¨Ëס±¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ×Ô¼º²¢²»ÊÇÕë¶ÔICSÇéÐε쬣¬£¬£¬£¬ËüÃǰüÀ¨ÒÑÖªµÄ²¡¶¾¡¢ÍÚ¿óÈí¼þ¡¢³£¼ûµÄÌØ¹¤Èí¼þµÈ¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩ¶ñÒâÈí¼þµÄÄ¿µÄÊÇÔì³ÉÎïÀíÍøÂçµÄË𺦣¬£¬£¬£¬£¬µ«Æä¸±×÷ÓÿÉÄÜ»á¶ÔICSºÍOTϵͳµÄ¿ÉÓÃÐÔºÍÍêÕûÐÔÔì³ÉÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£
Ö÷ÒªµÄÊÇÒª¹Ø×¢Î´À´¹¥»÷µÄDZÔÚΣº¦£¬£¬£¬£¬£¬ÕâЩÍþвµÄÎÞаÐÔºÍÕë¶ÔÐÔ£¨¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷£©¼Ó¾çÁËÕâÒ»µã¡£¡£¡£¡£¡£¡£
3.3.1 Sality½©Ê¬ÍøÂç
ÆäÖÐÒ»¸ö×î³£¼ûµÄÍþвÊÇSality£¬£¬£¬£¬£¬ËüÊÇÒ»¸ö×ÅÃûµÄÄ£¿£¿£¿£¿é»¯¶à̬²¡¶¾/È䳿£¬£¬£¬£¬£¬×îÔç·ºÆðÓÚ2003Ä꣬£¬£¬£¬£¬²¢ÔÚ2015Ä껹ÔÚά»¤¡£¡£¡£¡£¡£¡£
ÔÚÒÑÍù£¬£¬£¬£¬£¬SalityµÄC&CЧÀÍÆ÷ÓÃÓÚÏÂÔØÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¼°ÇÔÈ¡Óû§µÄÕË»§Æ¾Ö¤¡£¡£¡£¡£¡£¡£µ«ÏÖÔÚÕâЩC&CÒѾ²»ÔÙ¿ÉÓ㬣¬£¬£¬£¬²¢ÇÒËùÓеÄSalityÑù±¾¶¼¿Éͨ¹ý³£¼ûµÄAVÊÖÒÕ¼ì²âµ½¡£¡£¡£¡£¡£¡£
Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÈÔÔÚÈ«ÇòÍøÂç¼ÌÐøÈö²¥¡£¡£¡£¡£¡£¡£¿£¿£¿£¿¨°Í˹»ùÔÚÆû³µÐÐÒµµÄ´ó×ÚOTÅÌËã»úÉϼì²âµ½ÁËSality£¬£¬£¬£¬£¬ÎÒÃÇÒÔΪÏÖʵÊܵ½Ñ¬È¾µÄOTÅÌËã»úÊýÄ¿¸ü¶à¡£¡£¡£¡£¡£¡£
SalityµÄ×ÔÎÒÈö²¥ÌØÕ÷ʹµÃËü³ÉΪOT/ICS»ù´¡ÉèÊ©µÄÑÏÖØÍþв£¬£¬£¬£¬£¬Ëü¿ÉÒÔ´¥·¢¾Ü¾øÐ§Àͼ°ÓÉÓÚ¶ñÒâÁ÷Á¿µ¼ÖÂÍâµØÍøÂçµÄÐÔÄÜϽµ¡£¡£¡£¡£¡£¡£
3.3.2 Bladabindi/njRAT½©Ê¬ÍøÂç
Õë¶ÔÆû³µÐÐÒµµÄÁíÒ»¸öÖØ´óÍþвÊÇBladabindi ¨C Ò»¸öÄ£¿£¿£¿£¿é»¯µÄ¶à¹¦Ð§½©Ê¬ÍøÂçÊðÀí£¬£¬£¬£¬£¬ÆäÐÎʽÊDZàÒëºÃµÄÒ»×éAutoIT¾ç±¾¡£¡£¡£¡£¡£¡£ËüµÄºóÃÅ/ÌØ¹¤¹¦Ð§Ê®·Öǿʢ£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡¶àÖÖÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂ绹¾ßÓÐÀàËÆÈ䳿µÄ¹¦Ð§£¬£¬£¬£¬£¬¿Éͨ¹ý¿ÉÒÆ¶¯Ã½ÌåÈö²¥¡£¡£¡£¡£¡£¡£
ËüµÄC&CЧÀÍÆ÷´¦ÓÚ»îԾ״̬£¬£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢·Ö·¢ÏÂÁîºÍÏÂÔØÏÂÒ»½×¶Î¶ñÒâÈí¼þ£¨¶ñÒâ¿ó¹¤¡¢DDoSÊðÀí¡¢ÀÕË÷Èí¼þµÈ£©¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓö¯Ì¬DNSÊÖÒÕÀ´Ìӱܼì²âºÍ¶ñÒâÈí¼þÆÊÎö¡£¡£¡£¡£¡£¡£ÓÉÓÚ¹¦Ð§Ç¿Ê¢£¬£¬£¬£¬£¬Bladabindi¿ÉÄܶÔOTÍøÂ籬·¢ÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£
3.3.3 AutoCAD½©Ê¬ÍøÂç
»ùÓÚAutoCADµÄ½©Ê¬ÍøÂçÊÇÓÉAutoLISP (FAS)ľÂí¹¹½¨µÄ£¬£¬£¬£¬£¬ÆäC&CЧÀÍÆ÷Ê״ηºÆðÓÚ2013Äê¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÈÔÈ»Óɹ¥»÷Õß¾ÙÐÐά»¤¡£¡£¡£¡£¡£¡£
FASľÂí»á¸Ä¶¯AutoCADµÄÉèÖ㬣¬£¬£¬£¬Ê¹µÃÿ´ÎÓû§·¿ªAutoCAD¹¤³Ìʱ¶¼»áÖ´ÐиÃľÂí£¬£¬£¬£¬£¬ÕâÒ²µ¼ÖÂÿһ¸öн¨µÄÏîÄ¿¶¼»áÊܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£
ÆäC&CÈÔ´¦ÓÚ»îԾ״̬,ÓÃÓÚÏòÊÜѬȾµÄÅÌËã»ú·Ö·¢ÏÂÒ»½×¶Î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£Ä¿½ñ£¬£¬£¬£¬£¬ÒÑÖªµÄΨÖðÒ»¸öÕâÖÖpayloadµÄÑùÀýÊÇÒ»¸öVB¾ç±¾£¬£¬£¬£¬£¬¸Ã¾ç±¾ÓÃÓÚÐÞ¸Ää¯ÀÀÆ÷µÄÖ÷Ò³ÉèÖúͽ«ä¯ÀÀÆ÷µ¼º½ÖÁí§ÒâURL¡£¡£¡£¡£¡£¡£
¸ÃľÂíÖ÷ÒªÕë¶ÔÑÇÖÞ£¨ÓÈÆäÊÇÖйú£©µÄ¹¤ÒµºÍ¹¤³ÌÆóÒµ£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄܶÔOTÍøÂçÔì³ÉÑÏÖØÓ°Ïì¡£¡£¡£¡£¡£¡£
- ¸½¼þÖаüÀ¨Ä¾ÂíÏÂÔØÆ÷acad.fas£¨Òþ²ØÔÚAutoCADÖÆÍ¼ÖУ©µÄµç×ÓÓʼþ£¬£¬£¬£¬£¬¸ÃÓʼþÓɲ»ÊÜÏÓÒɵijаüÉÌ/·Ö°üÉÌÕýµ±¹¤³Ìʦ·¢ËÍ¡£¡£¡£¡£¡£¡£
- ¹¥»÷Õß·¢Ë͵Ĵ¹ÂÚÓʼþ£¬£¬£¬£¬£¬Í¬ÑùЯ´ø°üÀ¨acad.fasµÄ¸½¼þ
- Я´øacad.fasµÄ¿ÉÒÆ¶¯Ã½Ì壨ÈçUÅÌ£©
- ÍâµØÍøÂçÉϵĹ²ÏíÎļþ£¨°üÀ¨Òþ²ØµÄacad.fas£©
Ï£ÆæµÄÊÇ£¬£¬£¬£¬£¬C&CЧÀÍÆ÷¶ËµÄ´úÂë¶Ô´«ÈëµÄÇëÇó×öÁËһЩ¼ì²é£¨ÀýÈçIPµØµãµÄ¹ú¼Ò¹ýÂË£©£¬£¬£¬£¬£¬ÈôÊǼì²éʧ°Ü£¬£¬£¬£¬£¬Ôò²»»á½»¸¶µÚ¶þºÍµÚÈý½×¶Îpayload£¨ÀýÈçIPµØµãËùÔڵĹú¼Ò²»ÇкϹ¥»÷ÕßµÄÐËȤ£©¡£¡£¡£¡£¡£¡£
µÚÈý½×¶ÎVB ¾ç±¾ÑùÀý
ËÄ¡¢Íþвͳ¼Æ
±¾±¨¸æÖеÄͳ¼ÆÊý¾Ý¶¼ÊǾÓÉÔÊÐí´ÓKSNÓû§µÄÅÌËã»úÉÏÄäÃûÍøÂçµÃÀ´¡£¡£¡£¡£¡£¡£
4.1 Ñо¿ÒªÁì
¿¨°Í˹»ùICS CERT½«ÆóÒµÖеĹ¤Òµ»ù´¡ÉèÊ©¹éÀàΪICSÅÌËã»ú¡£¡£¡£¡£¡£¡£Ïà¹ØÍ³¼ÆÊý¾Ý´ÓÕâÒ»Àà±ðµÄÅÌËã»úÉÏÍøÂçµÃÀ´¡£¡£¡£¡£¡£¡£ÕâЩÅÌËã»ú°üÀ¨ÔËÐÐÒÔϹ¦Ð§µÄWindowsÅÌËã»ú£º
? Êý¾Ý´æ´¢Ð§ÀÍÆ÷£¨Historian£©£»£»£»£»
? Êý¾ÝÍø¹Ø£¨OPC£©£»£»£»£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÀο¿ÊÂÇéÕ¾£»£»£»£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÒÆ¶¯ÊÂÇéÕ¾£»£»£»£»
? ÈË»ú½çÃæ£¨HMI£©¡£¡£¡£¡£¡£¡£
»¹°üÀ¨´Ó¹¤¿ØÍøÂçÖÎÀíÔ±ÒÔ¼°¹¤Òµ×Ô¶¯»¯ÏµÍ³¿ª·¢Ö°Ô±µÄÅÌËã»úÉÏÍøÂçµ½µÄÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÚ±¾±¨¸æÖУ¬£¬£¬£¬£¬ÔâÊܹ¥»÷µÄÅÌËã»úÊÇÖ¸ÔÚ±¨¸æÊ±´ú¿·¢k8Çå¾²½â¾ö¼Æ»®ÖÁÉÙ±»´¥·¢Ò»´ÎµÄÅÌËã»ú¡£¡£¡£¡£¡£¡£ÔâÊܹ¥»÷µÄÅÌËã»úµÄ±ÈÀýÊÇÖ¸ÔâÊܹ¥»÷µÄÅÌËã»ú£¨È¥ÖØ£©Õ¼ËùÓÐÑù±¾ÅÌËã»ú£¨ÔÚ±¨¸æÊ±´úÏòÎÒÃÇ·¢ËÍÁËÄäÃûÊý¾ÝµÄÅÌËã»ú£©µÄ±ÈÀý¡£¡£¡£¡£¡£¡£
ͨ³£ÇéÐÎÏ£¬£¬£¬£¬£¬ÓÉÓÚ¹¤ÒµÍøÂçµÄÏÞÖÆ£¬£¬£¬£¬£¬ICSЧÀÍÆ÷ºÍ¹¤³Ìʦ/²Ù×÷Ô±µÄÀο¿ÊÂÇéÕ¾²»ÊÇ24СʱÁªÍøµÄ¡£¡£¡£¡£¡£¡£ÕâÀàÅÌËã»ú¿ÉÄÜÖ»ÔÚ£¬£¬£¬£¬£¬ÀýÈçά»¤Ê±´ú£¬£¬£¬£¬£¬²Å»ªÁªÍø¡£¡£¡£¡£¡£¡£
ϵͳ/ÍøÂçÖÎÀíÔ±¡¢¹¤³Ìʦ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³µÄ¿ª·¢Ö°Ô±ºÍ¼¯³ÉÖ°Ô±µÄÊÂÇéÕ¾¿ÉÄܻᾳ£ÁªÍø£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜÊÇ24СʱÁªÍø¡£¡£¡£¡£¡£¡£
Òò´Ë£¬£¬£¬£¬£¬2018ÄêϰëÄê¿·¢k8Ñù±¾ÅÌËã»úÖÐÔ¼ÓÐ40%µÄÅÌËã»úÊǰ´ÆÚ»òÈ«ÌìÁªÍøµÄ¡£¡£¡£¡£¡£¡£ÆäÓà»úеµÄÁªÍøÊ±¼ä²»Áè¼ÝÒ»¸öÔ£¬£¬£¬£¬£¬ÆäÖÐÐí¶àÊÇÔ¶Ô¶ÉÙÓÚÕâ¸öʱ¼äµÄ¡£¡£¡£¡£¡£¡£
4.2ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý
2017 vs 2018£¬£¬£¬£¬£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý
ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý
2018ÄêÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨Ô¶ÈÂþÑÜ£©
2017 vs 2018£¬£¬£¬£¬£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨Ô¶ÈÂþÑÜ£©
4.3 ¶ñÒâÈí¼þµÄÖÖ±ðÂþÑÜ
ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨¶ñÒâÈí¼þÖÖ±ðÂþÑÜ£©
2017 ¨C 2018£¬£¬£¬£¬£¬ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý£¨¶ñÒâÈí¼þÖÖ±ðÂþÑÜ£©
4.4 µØÀíÂþÑÜ
2018ÄêϰëÄ꣬£¬£¬£¬£¬ICS¹¥»÷±ÈÀý×î¸ßµÄ¹ú¼Ò/µØÇø£¨Top 15£©
Óë2018ÄêÉϰëÄêÏà±È£¬£¬£¬£¬£¬ICS¹¥»÷±ÈÀý¹ú¼ÒÅÅÃûµÄǰÎåÃûûÓб任£¬£¬£¬£¬£¬µ«Morocco£¨ÏÖÔÚ´¦ÓÚµÚÈýÃû£©ºÍTunisia£¨µÚËÄÃû£©½»Á÷ÁËλÖᣡ£¡£¡£¡£¡£
2018ÄêϰëÄê¶íÂÞ˹ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀýÊÇ45.3%£¬£¬£¬£¬£¬ºÍÉϰëÄ꣨44.7%£©´¦ÓÚͳһˮƽ¡£¡£¡£¡£¡£¡£¶íÂÞ˹µÄÅÅÃûÊǵÚ16Ãû¡£¡£¡£¡£¡£¡£
2018ÄêϰëÄêICS¹¥»÷±ÈÀý×îµÍµÄ¹ú¼Ò/µØÇø
2018ÄêH1ºÍH2£¬£¬£¬£¬£¬ICS¹¥»÷±ÈÀýµÄµØÀíÇøÓòÂþÑÜ
4.5 ѬȾԴ
ICSÅÌËã»ú*µÄÖ÷ÒªÍþвȪԴ£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©
* ÔâÊܹ¥»÷µÄICSÅÌËã»ú±ÈÀý
4.6 Ö÷ҪѬȾԴµÄµØÇøÂþÑÜ
2018ÄêϰëÄ꣬£¬£¬£¬£¬ICSÅÌËã»úÖ÷ÒªÍþвȪԴµÄµØÀíÂþÑÜ
4.6.1 »¥ÁªÍø
2018ÄêϰëÄ꣬£¬£¬£¬£¬»¥ÁªÍøÍþвÅÅÃû½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15
4.6.2 ¿ÉÒÆ¶¯Ã½Ìå
2018ÄêϰëÄ꣬£¬£¬£¬£¬¿ÉÒÆ¶¯Ã½ÌåÍþвÅÅÃû½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15
4.6.3 Óʼþ¿Í»§¶Ë
µÂ¹úÔÚµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄ¹ú¼Ò/µØÇøTop15ÖÐÉϰñ£¬£¬£¬£¬£¬ÖµµÃ×¢ÖØµÄÊǸùú¼ÒÔÚÆäËü·½Ã涼δÉϰñ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2018/90041/


¾©¹«Íø°²±¸11010802024551ºÅ