¡¾»ã±¨·ÖÏí¡¿¿¨°Í˹»ù - 2018ϰëÄêICSÍþв¾°¹Û

°ä²¼¹¦·ò 2019-04-26

Ò»¡¢2018ϰëÄêÖØÒª¹¥»÷ÊÂÎñ



1.1 Õë¶Ô¹¤ÒµÐÐÒµµÄAPT¹¥»÷


1.1.1 ·¸×ïÍÅ»ïLeafminerµÄAPT¹¥»÷


2018Äê8ÔÂÒ»·Ýл㱨Åû¶ÁË·¸×ïÍÅ»ïLeafminer£¨ÓÖ³ÆRASPITE£©µÄÍøÂç¼äµý»î¶¯¡£¸Ã×éÖ¯ÖØÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢Öж«ºÍ¶«ÑǵØÓòÈ·µ±¾Ö»ú¹¹ÒÔ¼°Ã³Ò׺͹¤Òµ¹«Ë¾£¬ÆäÖ¸±êÐÐÒµÔ̺¬ÄÜÔ´¡¢µ±¾Ö¡¢½ðÈÚ¡¢º½Ô˺ÍÔËÊäµÈ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Leafminer¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©


¹¥»÷ÕßʹÓÃÁ˶àÖÖ¹«¿ª»ò¶¨ÔìµÄ¹¤¾ß¡¢exploitÒÔ¼°Ë®¿Ó¹¥»÷ºÍ×ֵ乥»÷£¬ÀýÈçÓÀºãÖ®À¶µÄexploitºÍMimikatz±äÌå¡£


1.1.2 жñÒâÈí¼þGreyEnergy


Eset×êÑÐÈËÔ±»ã±¨ÁËÓë·¸×ïÍÅ»ïBlackEnergyÓйصĶàÆð¹¥»÷ÊÂÎñ£¬ÔÚÕâЩ¹¥»÷Öй¥»÷ÕßʹÓÃÁËÒ»¸öеĶñÒâÈí¼þGreyEnergy¡£BlackEnergyÏÈǰÒÑ´ÓAPT×êÑÐÈËÔ±µÄÀ×´ïÉÏÒþû£¬µ«ÕâÒ»´Î¹¥»÷ÕßÔÙ´ÎÏÖÉí£¬ÖØÒªÕë¶ÔÖÐÅ·ºÍ¶«Å··ÖÆçÒµÒµµÄ¹¤ÒµÍøÂ磬Ô̺¬ÄÜÔ´¹«Ë¾¡¢ÔËÊ乫˾µÈ£¬²¢³Áµã¹Ø×¢ÕƹÜÔËÓª¹Ø¼ü»ù´¡ÉèÊ©µÄÆóÒµ¡£


×êÑÐÈËÔ±·¢ÏÖGreyEnergyÓë2015ÄêBlackEnergyÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µçÍøµÄ¶ñÒâÈí¼þ´æÔÚ¸ÅÏëÉϵÄÀàËÆÖ®´¦¡£´Ë±í£¬×êÑÐÈËÔ±»¹·¢ÏÖGreyEnergyÓë·¸×ïÍÅ»ïTeleBotsµÄ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£TeleBotsÒÔ¶àÆð´ó¹æÄ£¹¥»÷ÊÂÎñÎÅÃû£¬ÀýÈç2017ÄêµÄNotPetyaºÍBadRabbit¡£¿¨°Í˹»ù×êÑÐÈËÔ±Ëæºó·¢ÏÖGreyEnergy»¹ÓëSofacy£¨¼´APT28£©µÄ×ÓÍÅ»ïZebrocy´æÔÚ¹ØÁª¡£


GreyEnergyÓµÓÐÄ£¿é»¯µÄϵͳ½á¹¹£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ý¼ÓÔØÓйØDLLÀ´×éºÏ·ÖÆçµÄ¶ñÒâÈí¼þÖ°ÄÜ¡£Ä³Ð©Çé¿öÏ£¬ÕâЩ¶ñÒâÄ£¿é´ÓC&C·þÎñÆ÷ÏÂÔØ²¢Ö±½Ó¼ÓÔØ½øÄڴ棨²»Ð´Èë´ÅÅÌÎļþ£¬¼´ÎÞÎļþ¹¥»÷£©¡£GreyEnergy¿ÉÍøÂçÊܺ¦ÕßµÄÍ´´¦ÒÔÉøÈ빤¿ØÍøÂç¡£¸Ã×éÖ¯µÄ¹¤¾ß°ü»¹Ô̺¬¿ªÔ´¹¤¾ßMimikatz¡¢PsExec¡¢WinExeºÍNmapµÈ¡£


GreyEnergyµÄ³õʼ¹¥»÷ÏòÁ¿ÊÇ´¹µöÓʼþ¼°ÆóÒµµÄ¹«¹²ÍøÂç×ÊÔ´£¬µ±È»ºÜÓпÉÄÜ»¹Ô̺¬ÆäËü¹¥»÷ÏòÁ¿¡£


ÔÚ֮ǰµÄ¹¥»÷»î¶¯ÖУ¬¸Ã×éÖ¯ÔøÀûÓÃGE CimplicityÖеķì϶£¨CVE-2014-0751£©ÔÚHMI·þÎñÆ÷ÉÏÖ´ÐжñÒâ.cimÎļþ£¬²¢×îÖÕ×°ÖÃBlackEnergy¡£Æ¾¾Ý¿¨°Í˹»ùµÄ×êÑУ¬¸Ã×éÖ¯»¹ÔøÔÚ2014ÄêÀûÓÃÎ÷ÃÅ×ÓWinCCÖеķì϶£¨CVE-2014-8551£©À´ÉøÈëÖ¸±êÍøÂç¡£ÔÚ×î½üµÄ¹¥»÷Öи÷ìÏ¶Ò²Ôø±»ÀûÓá£


´Ë±í£¬´Óǰ¸Ã×éÖ¯ÔøÈëÇÖÖ¸±êÆóÒµµÄ·ÓÉÆ÷²¢×°Öø÷Àà¶ñÒâÄ£¿éºÍ¾ç±¾£¬ÒÔ½øÐкáÏòÒÆ¶¯¡£ÔÚ×î½üµÄGreyEnergy¹¥»÷ÖÐÉÐδ·¢ÏÖÕâÖÖÐÐΪ£¬µ«¸ÃÐÐΪºÜ¿ÉÄÜ´æÔÚ£¬ÓÉÓڸù¥»÷ÏòÁ¿¶Ô¹¥»÷Õß¼«¶ÈÓÐÀû£¬¿ÉÓÃÓÚ¶¨ÆÚÍøÂç¸÷¸ö·ÓÉÆ÷ÐͺŴæÔڵķì϶ÐÅÏ¢£¬Ô̺¬0day¡£


1.1.3 ¹¥»÷»î¶¯Sharpshooter


2018Äê12ÔÂMcAfee¼ì²âµ½Ò»¸öÕë¶ÔÈ«Çò¹ú·À³Ð°üÉÌ¡¢ºËÄÜÐÐÒµÒÔ¼°½ðÈÚÐÐÒµµÄ¹¥»÷»î¶¯Sharpshooter¡£×êÑÐÈËÔ±³ÆSharpshooterµÄÖØÒªÖ÷ÕÅÊǽøÐмäµý»î¶¯¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


SharpshooterµÄÖ¸±êÐÐÒµºÍ¹ú¶ÈÉ¢²¼£¨ÆðÔ´£ºMcAfee£©


ϰȾÁ´Ê¼ÓÚÔ̺¬¶ñÒâºêµÄMicrosoft WordÎĵµ¡£¸Ã¶ñÒâºê×÷Ϊһ¸öµäÐ͵Ädownloader£¬ÓÃÓÚ½»¸¶¶ñÒâÖ²ÈëÎï¡£¹¥»÷Õßͨ¹ýDropboxÀ´·Ö·¢ÊÜϰȾµÄÎļþ¡£¸ÃÖ²ÈëÎÃûΪRising Sun£©ÊÇÒ»¸öеÄÄ£¿é»¯ºóÃÅ£¬Ö»ÔÚÄÚ´æÖÐÔËÐУ¬ÖØÒªÍøÂçÓû§Êý¾Ý£¬Ô̺¬ÍÆËã»úÃû³Æ¡¢IPµØÖ·¡¢ÏµÍ³ÐÅÏ¢µÈ¡£ÍøÂçµ½µÄÊý¾Ý±»¼ÓÃÜ´«ÊäÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¿¨°Í˹»ù×êÑÐÈËÔ±ÒÔΪ·¸×ïÍÅ»ïLazarusÓëÕâЩ¹¥»÷»î¶¯´æÔÚ¹ØÁª¡£


1.1.4 ¹¥»÷»î¶¯MuddyWater


2018Äê12Ô³õÈüÃÅÌú¿Ë»ã±¨ÁË·¸×ïÍÅ»ïMuddyWater£¨ÓÖ³ÆSeedÈ䳿£©µÄ¼äµý¹¥»÷»î¶¯¡£¹¥»÷ÕßÖØÒªÕë¶ÔÖж«¡¢Å·Ö޺ͱ±ÃÀµØÓòµÄÆóÒµ¡£Æ¾¾ÝÕâÏî×êÑУ¬2018Äê9ÔÂÄ©ÖÁ11ÔÂÖÐÑ®ÆÚ¼ä¹²ÓÐ30¼ÒÆóÒµµÄ130ÃûÔ±¹¤Êܵ½¹¥»÷£¬´óÎÞÊýÊܺ¦ÕßλÓÚ°Í»ù˹̹ºÍÍÁ¶úÆä£¬»¹ÓÐÉÙÊýÊܺ¦ÕßλÓÚ¶íÂÞ˹¡¢É³Ìذ¢À­²®¡¢°¢¸»º¹¡¢Ô¼µ©µÈ¹ú¶È¡£¹¥»÷ÕßÖØÒª¶Ô×¼µÄÖ¸±êÖ®Ò»ÊÇÓÍÆøÐÐÒµ¡£Öж«µØÓòµÄ´óѧºÍÅ·ÖÞµÄÖж«´óʹ¹ÝͬÑùÔâµ½¹¥»÷¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


MuddyWater¹¥»÷Ö¸±êµÄÐÐҵɢ²¼£¨ÆðÔ´£ºÈüÃÅÌú¿Ë£©


1.1.5 ¹¥»÷»î¶¯Cloud Hopper


2018Äê12ÔÂÖÐÑ®£¬µÂ¹úÁª¹úÐÅÏ¢°²È«°ì¹«ÊÒ£¨BSI£©ÏòһЩµÂ¹úÆóÒµ°ä²¼Á˾ݳÆÓëAPT10ÓйصÄCloudHopper¹¥»÷¾¯±¨¡£BSI³Æ¶à¼Ò´óÐ͹¤³ÌÆóÒµÒѾ­Ôâµ½¹¥»÷£¬¹¥»÷Õß»¹¶Ô¹¹ÖþºÍ×ÊÁÏѧÁìÓòµÄÆóÒµ¸ÐÐËÖ¡£


¹¥»÷Õß²¢Ã»ÓÐÖ±½Ó¹¥»÷Ö¸±êÆóÒµ£¬¶øÊÇͨ¹ýÉøÈëÖ¸±êÆóҵʹÓõÄÓ×ÐÍÔÆ·þÎñºÍÍйܷþÎñ¹©¸øÉÌÌáÒé¹¥»÷¡£ÕâÀ๩¸øÉÌͨ³£°²È«ÐԽϲ¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÉøÈëÖ¸±ê¹«Ë¾µÄÆóÒµÍøÂç¡£


1.1.6 ¶ñÒâÈí¼þShamoon v.3


2018Äê12ÔÂ10ÈÕ£¬Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SiapemÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷ÕßÖØÒªÕë¶Ô¸Ã¹«Ë¾Î»ÓÚÖж«¡¢Ó¡¶È¡¢ËÕ¸ñÀ¼ºÍÒâ´óÀûµÄ·þÎñÆ÷£¬Ê¹ÓõĶñÒâÈí¼þÊÇShamoonÈ䳿µÄбäÌåShamoon v.3¡£Ô¼ÓÐ300µ½400̨·þÎñÆ÷¼°100̨¹¤×÷Õ¾ÔÚÕâ´Î¹¥»÷ÊÂÎñÖÐÊܵ½Ó°Ïì¡£


ÔÚSaipem°ä²¼ÉêÃ÷Ö®ºó£¬ÈüÃÅÌú¿Ë·¢ÏÖÏÕЩÔÚͳһ¹¦·ò»¹ÓÐÁ½¼ÒλÓÚÉ³ÌØ°¢À­²®ºÍ°¢ÁªÇõµÄʯÓͺÍÌìÈ»Æø¹«Ë¾Ôâµ½ÀàËÆµÄ¹¥»÷¡£


ShamoonÈ䳿³õ´Î³öÏÖÓÚ2012ÄêÕë¶ÔÉ³ÌØ°¢À­²®¹ú¶ÈʯÓ͹«Ë¾AramcoºÍ¿¨Ëþ¶ûÌìÈ»Æø¹«Ë¾RasgasµÄ¹¥»÷»î¶¯ÖС£ÔÚ2016-2017ÄêµÄÐÂÒ»ÂÖ¹¥»÷ÖУ¬¹¥»÷ÕßʹÓÃÁËShamoonµÄ±äÖÖ£¨Shamoon v2£©ºÍ¶ñÒâÈí¼þStoneDrill¡£


ÔÚ2018ÄêµÄ¹¥»÷»î¶¯ÖУ¬Åã°é×ÅShamoon v.3³öÏֵϹÓÐÐÂÊý¾Ý²Á³ýÆ÷Filerase¡£Filerase¿É²Á³ý£¨¸²Ð´£©ÊÜϰȾϵͳÉϵÄÎļþ¡£2018ÄêµÄShamoon¹¥»÷»î¶¯ÓÉÓÚʹÓÃÁËFilerase¶ø¸ü¾ß·ÛËéÐÔ¡£ShamoonÄܹ»²Á³ýÊÜϰȾϵͳµÄÖ÷Êèµ¼¼Í¼£¨MBR£©£¬µ«Ó²ÅÌÉϵÄÎļþ¿É±»¸´Ô­£¬¶øÊ¹ÓÃÁËFileraseÖ®ºóÈκÎÎļþ¶¼²»³É¸´Ô­¡£


FileraseÓµÓÐÄ£¿é»¯½á¹¹£¬Ô̺¬¶à¸öÓÃÓÚÔÚ±¾µØÍøÂçÉϽøÐд«²¼µÄ×é¼þ¡£ÕâÒâζ×ÅFilerase×ÔÉíÄܹ»×÷Ϊһ¸öµ¥¶ÀµÄÍþв¡£FileraseÔÚÊܺ¦Õߵı¾µØÍøÂçÉÏ´«²¼Ê±£¬ÒÀÀµÒ»¸öÖ¸±êÃûµ¥À´°Îȡָ±ê¡£ÔÚ³õʼϰȾ¹ý³ÌÖУ¬¸ÃÃûµ¥ÊÇÓÉOCLC.exe×é¼þ¸´ÔìµÄ£¬²¢·¢Ë͸øSpreader.exe¹¤¾ß£¬ºóÕß½«Filerase¸´Ôìµ½Ãûµ¥ÉϵĻúе¡£¸ÃÃûµ¥ÊÇÒ»¸öÔ̺¬·ÖÆçÊܺ¦ÕßÃû×ÖµÄÎı¾Îļþ£¬ÕâЩÃû×ÖºÜÓпÉÄÜÊǹ¥»÷ÕßÔÚ¹¥»÷µÄÔçÆÚ½×¶ÎÍøÂçµÄ¡£


McAfeeµÄ×êÑÐÈËÔ±ÒÔΪShamoon v3¹¥»÷»î¶¯¿ÉÄÜÓëÒÁÀÊ·¸×ïÍÅ»ïAPT33ÓйØ£¬»òÊÇÁí±íÒ»¸ö·¸×ïÍÅ»ï¼Ù×°³ÉAPT33¡£ÈüÃÅÌú¿Ë×êÑÐÈËÔ±³ÖÒ»Ñù¶¨¼û¡£


2018Äê12Ôµ×£¬Anomali Labs»ã±¨ÁËShamoonµÄÁíÒ»¸ö±äÌ壬¸Ã±äÌåÓÚ12ÔÂ23ÈÕ±»ÉÏ´«ÖÁVirusTotal¡£¸Ã±äÌå¼Ù×°³É°Ù¶È¹«Ë¾µÄÒ»¸öϵͳÅäÖúÍÓÅ»¯¹¤¾ß½øÐд«²¼¡£

1.2ÍøÂç·¸×ï»î¶¯


1.2.1 ÀÕË÷Èí¼þ¹¥»÷


ƾ¾Ý¿¨°Í˹»ùµÄÊý¾Ý£¬Ôâ·êÀÕË÷Èí¼þ¹¥»÷µÄICSÍÆËã»ú±ÈÀý´Ó1.6%ÉÏÉýÖÁ2%¡£


WannaCryÈÔ¾ÉÊǹ¤ÒµÆóÒµÃæ¶ÔµÄÒ»¸öÕæÊµµÄÍþв£¬Ò²ÊÇÒ»¸ö³£¼ûµÄÍþв¡£Æ¾¾Ý¿¨°Í˹»ùµÄÊý¾Ý£¬WannaCry£¨28.72%£©ÊÇÀÕË÷Èí¼þÍþвÖеÄÁìÍ·Ñò£¨2018ÄêµÚÈý¼¾¶È£©¡£¼´±ãÊÇÔÚ´ó¹æÄ£·¢×÷µÄÒ»ÄêÖ®ºó£¬WannaCryÈԾɳÖÐøÏ°È¾¹¤ÒµÆóÒµµÄICSÍøÂ磬ÀýÈ磬2018Äê8ÔÂ3ÈǪ̃»ýµç£¨TSMC£©µÄ¶à¼Ò¹¤³§Ôâµ½WannaCry¹¥»÷¡£Æ¾¾ÝÏÖÓÐÐÅÏ¢£¬Ï°È¾ÊÇÓÉÒ»¸ö¹©¸øÉÌÔÚгö²ú¹¤¾ßÉÏ×°ÖÃÁËÊÜËðÈí¼þµ¼Öµģº¸Ã¹©¸øÉ̲¢Î´½øÐÐÈκΰ²È«É¨Ãè¾Í½«Èí¼þÁ¬Èë³ö²úÍøÂ磬µ¼Ö¶ñÒâÈí¼þÔŲ́ÄÏ¡¢ÐÂÖñºĮ́ÖеĶà¼Ò¹¤³§Ö®¼äѸËÙ´«²¼£¬Ì¨Í幤³§µÄ³ö²ú±»ÆÈÖжÏÁË3Ìì¡£


ÆäËü¹¥»÷ÊÂÎñ»¹Ô̺¬2018Äê11ÔÂ28ÈÕĪ˹¿ÆÀ³µ¹«Ë¾£¨MCC£©Ôâµ½µÄÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾³ÆÔÚ¹¥»÷ÆÚ¼äÆäÖØÒªµçÄÔϵͳÉϵÄÎļþ¾ù±»¼ÓÃÜ£¬Ô±¹¤Ñ¸ËÙÖÕ³¡ÁËÀ³µ²¢·ÖÉ¢Á˳˿Í¡£¹¥»÷ÕßÒªÇóÖ§¸¶±ÈÌØ±Ò²Å»á½âÃÜ¡£¸Ã¹«Ë¾ÔÚÁ½Ììºó¸´Ô­ÁËÔËÓª¡£

1.2.2 Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷


2018Äê8Ô£¬¿¨°Í˹»ùICS CERT°ä²¼Õë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷µÄµ÷²éÁ˾Ö¡£¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇ´Ó¹«Ë¾µÄÕË»§ÖÐÇÔÈ¡½ðÇ®¡£


¹¥»÷ʼÓÚ2017Äê11Ô£¬²¢ÇÒÈÔÔÚ³ÖÐø¡£¹¥»÷ÕßÖØÒª·¢ËͼÙ×°³ÉºÏ·¨Ã³Ò×±¨¼ÛµÄ´¹µöÓʼþ£¬ÓʼþÖеĶñÒ⸽¼þÊÜÃÜÂë±£»¤£¬¶øÃÜÂ븽ÔÚÓʼþÄÚÈÝÖС£ÕâÀàÓʼþ×ÔÉí¾­¹ý¸ß¶È¼Ù×°£¬ÇкϹ«Ë¾µÄÒµÎñÇé¿ö¡£ÔÚ×î½üµÄÒ»²¨¹¥»÷ÖУ¬´¹µöÓʼþ¼Ù×°³ÉÊܺ¦ÆóÒµµÄºÏ×÷ͬ°é¡£¶ñÒ⸽¼þÖеľ籾½«ÔÚϵͳÉÏ×°ÖöñÒâÈí¼þ£¬¶øºóÏνӵ½¹¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷²¢ÏÂÔØÖ®Ç°ÍµÇԵĺϷ¨Îĵµ¡£


¹¥»÷Õß»áÔÚÊÜϰȾµÄϵͳÉÏ×°ÖúϷ¨µÄÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©- ÈçTeamViewerºÍRMS¡£µ«¶ñÒâÈí¼þ»á°µ²ØÕâЩRATµÄͼÐνçÃæ£¬ÒÔÔÚÓû§²»ÖªÇéµÄÇé¿öϽÚÔìÊÜϰȾµÄ»úе¡£


¹¥»÷Õß½ø¶øËÑË÷ϵͳÉϵIJÆÕþºÍ¹ÜÕÊÈí¼þ£¬²¢²éÕҺͷÖÎöÓë²É¹ºÓйصÄÕÊÄ¿Îĵµ¡¢ºÏ×÷É̵ÄÓʼþµØÖ·ÒÔ¼°ÓëºÏ×÷É̵ÄͨѶÍùÀ´£¬¶øºó½øÒ»²½ÀûÓÃÕâЩ˽º±¼û¾Ý½øÐвÆÕþڲƭ£¬ÀýÈçÅú¸Ä¶©µ¥ÖеÄÒøÐп¨Õ˺ŵÈ¡£


¸ü½øÒ»²½µØ£¬¹¥»÷Õß»áÔÚ±ØÒªµÄÇé¿öÏÂ×°Öøü¶àµÄ¶ñÒâÈí¼þ£¨ÒÀÊܺ¦Õß·ÖÆç¶ø·ÖÆç£©£¬ÀýÈçͨ¹ý¼äµýÈí¼þºÍMimikatzÇÔÈ¡Éí·ÝÑé֤ʹ´¦£¬¶øºóϰȾÆóÒµÍøÂçÖеĸü¶à»úе¡£·¸×ï·Ö×Ó»¹Ê±Ê±½«¶ñÒâÈí¼þµÄ×é¼þ¼Ù×°³ÉWindowsϵͳ×é¼þ£¬ÒÔ°µ²Ø¶ñÒâ»î¶¯µÄ×ÙÓ°¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷Á÷³ÌµÄÕûÌåʾÒâͼ


¿¨°Í˹»ùICS CERTÒÔΪÕâЩ¹¥»÷ºÜÓпÉÄÜÊÇÓɶíÓï¹¥»÷ÕßÌáÒéµÄ¡£


1.2.3 Õë¶ÔÈ«ÇòÆóÒµµÄ´¹µö¹¥»÷


2018Äê10ÔÂYoroi CERT¼ì²âµ½¼¸ÆðÕë¶ÔÒâ´óÀûˮʦºÍ¹ú·ÀÆóÒµµÄ¹¥»÷»î¶¯¡£Ö¸±êÆóÒµµÄÔ±¹¤½Ó¹Üµ½Ð¯´ø¶ñÒâExcelÎļþµÄ´¹µöÓʼþ¡£¸Ã¶ñÒâExcelÖ¼±ÉÈËÔØRATľÂíMartyMcFly£¬¹¥»÷Õß¿ÉÀûÓøÃľÂí½ÚÔìÖ¸±ê»úе¼°ÇÔÈ¡Êý¾Ý¡£´Ë±í£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÁíÒ»¸öÔ¶³ÌÖÎÀí¹¤¾ßQuasarRAT£¨Ô´´úÂëÔÚgithubÉÏ¿ÉÓ㩵ıäÌå¡£


ƾ¾Ý¿¨°Í˹»ùICS CERTµÄ˵·¨£¬Yoroi»ã±¨ÖÐÌáµ½µÄ´¹µöÓʼþÒÔ·ÖÆçµÄÃû³ÆÔÚÈ«ÊÀ½çÁìÓòÄÚ´«²¼£¬Ö¸±ê¹ú¶ÈÔ̺¬µÂ¹ú¡¢Î÷°àÑÀ¡¢±£¼ÓÀûÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ó¡¶È¡¢ÂÞÂíÄáÑǵÈ¡£Ö¸±êÆóÒµº­¸Ç¶à¸ö´¹Ö±ÐÐÒµ£¬´Ó¶¹À๩¸øÉ̵½Õ÷ѯ¹«Ë¾¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´¹µöÓʼþÖжñÒâxlsxÎļþµÄÉ¢²¼£¨ÆðÔ´£ºKSN£©


¿¨°Í˹»ùICS CERTÒÔΪ£¬Õâ´Î¹¥»÷ÊÇÓÉÕë¶Ô¶à¸öÆóÒµ£¨ÓÐʱÔ̺¬¹Ø¼ü»ù´¡ÉèÊ©£©½øÐдó¹æÄ£´¹µö¹¥»÷µÄÒ»Ñù·¸×ïÍÅ»ïÌáÒéµÄ¡£ÕâЩÍÅ»ïרһÓÚÇÔÈ¡½ðÇ®ºÍ²ÆÕþÊý¾Ý¡£



¶þ¡¢2018ÄêICS·ì϶ͳ¼Æ



ICS×é¼þÖеķì϶


±¾Ó×½ÚÖеķì϶·ÖÎöÊÇ»ùÓÚ³§É̲¼¸æ¡¢¿ªÔ´·ì϶¿â£¨US ICS-CERT¡¢CVE¡¢Î÷ÃÅ×Ó CERT£©µÄ¹«¿ªÐÅÏ¢ÒÔ¼°¿¨°Í˹»ùICS CERTµÄ×êÑÐÁ˾ֽøÐеÄ¡£US ICS-CERTÍøÕ¾ÉϵÄ2018Äê·ì϶ÐÅÏ¢±»ÓÃ×÷ͳ¼ÆÊý¾ÝµÄÆðÔ´¡£


2.1 ·ì϶ÊýÁ¿


2018Ä꣬US ICS-CERTÍøÕ¾ÉÏÅû¶µÄICS·ì϶ÊýÁ¿Îª415¸ö ¨C ±È2017Äê¶àÁË93¸ö¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


US ICS-CERTÅû¶µÄICS·ì϶ÊýÁ¿


2.2 ÐÐҵɢ²¼


ICS·ì϶ÊýÁ¿×î¶àµÄÐÐÒµÊÇÔì×÷Òµ£¨115£©¡¢ÄÜÔ´Òµ£¨110£©¼°¹©Ë®ÏµÍ³£¨63£©¡£´Ë±í£¬Ê³Æ·¼Ó¹¤/ũҵ£¨49£©ºÍ»¯Ñ§Òµ£¨44£©Ò²ÅÅÔÚǰÁС£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 

2018ÄêICS·ì϶µÄÐÐҵɢ²¼£¨»ùÓÚUS ICS-CERTµÄ·ÖÀࣩ


2.3 ·ì϶ÑϳÁÐÔÉ¢²¼


³¬¹ýÒ»°ëµÄICS·ì϶£¨284¸ö£¬2017ÄêΪ194¸ö£©µÄCVSS v.3.0ÆÀ·Ö¸ßÓÚ7·Ö£¬¼´Îª¸ßΣ£¨high£©»òÑϳÁ£¨critical£©·ì϶¡£

ÑϳÁÐÔÆÀ·Ö

9 - 10 (ÑϳÁ)

7 - 8.9 (¸ßΣ)

4 - 6.9 (ÖÐΣ)

0 - 3.9 (µÍΣ)

ICS·ì϶ÊýÁ¿

92

192

128

3



±í1 ¨C ICS·ì϶µÄÑϳÁÐÔÉ¢²¼

ÓëǰһÄêµÄÊý¾ÝÏà±È£¬¸ßΣ¼°ÑϳÁ·ì϶µÄ±ÈÀýÓÐËùÔö³¤¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2017 vs 2018£¬ICS·ì϶µÄÑϳÁÐÔÉ¢²¼£¨»ùÓÚCVSS v3ÆÀ·Ö£©


ÒÔϲúÆ·ÖÐÔ̺¬ÆÀ·ÖΪ10·ÖµÄ·ì϶£º


  • Siemens TIM 1531 IRC Modules
  • Siemens SINUMERIK Controllers
  • Circontrol CirCarLife
  • NUUO NVRmini2 and NVRsolo
  • Emerson AMS Device Manager
  • Rockwell Automation RSLinx Classic
  • Schneider Electric U.motion Builder
  • Martem TELEM-GW6/GWM


´óÎÞÊýÆÀ·ÖΪ10·ÖµÄ·ì϶¶¼ÊÇÉí·ÝÑéÖ¤»ò»º³åÇøÒç³öÎÊÌâ¡£


Ó¦¸Ã°ÑÎȵÄÊÇ£¬CVSSÆÀ·Ö²¢Î´Ë¼¿¼µ½ICSÏµÍ³ÌØÓеݲȫÐÔºÍ·ÖÆçÆóÒµ¹¤ÒµÁ÷³ÌµÄ²î¾àÐÔ£¬Òò¶øÔÚÆÀ¹ÀICS·ì϶µÄÑϳÁÐÔʱ£¬ÎÒÃǽ¨Òé³ýÁËCVSSÆÀ·ÖÖ®±í»¹Òª¹Ø×¢·ì϶ÀûÓõĿÉÄܺó¹û£¬ÀýÈçµ¼Ö¹¤ÒµÁ÷³ÌµÄÖжϻò²¿ÃÅÖжϵÈ¡£

2.4 ÀàÐÍÉ¢²¼


×î³£¼ûµÄICS·ì϶ÀàÐÍÊÇ»º³åÇøÒç³ö£¨Õ»»º³åÇøÒç³ö¡¢¶Ñ»º³åÇøÒç³ö¡¢µäÐÍ»º³åÇøÒç³ö£©¼°²»ÕýÈ·µÄÊäÈëÑéÖ¤¡£Í¬Ê±£¬16%µÄ·ì϶ÊÇÉí·ÝÑéÖ¤ÎÊÌ⣨²»ÕýÈ·µÄÉí·ÝÑéÖ¤¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢¹Ø¼üÖ°ÄÜȱʧÉí·ÝÑéÖ¤£©ºÍ½Ó¼û½ÚÔìÎÊÌ⣨½Ó¼û½ÚÔì¡¢²»ÕýÈ·µÄĬÈÏȨÏÞ¡¢²»ÕýÈ·µÄȨÏÞÖÎÀí¡¢Í´´¦ÖÎÀí£©£¬10%µÄ·ì϶ÊÇWebÓйطì϶£¨×¢Èë¡¢õè¾¶±éÀú¡¢CSRF¡¢XSS¡¢XXE£©¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêICS·ì϶ÀàÐ͵ÄÉ¢²¼

ÓëǰһÄêÏà±È£¬»º³åÇøÒç¶Âí½ÅµÄ±ÈÀýÏÔÖøÔö³¤¡£ÎÒÃÇÒÔΪÕâÓ밲ȫ×êÑÐÈËÔ±¶ÔICS×é¼þÖеķì϶ԽÀ´Ô½¸ÐÐËÖÂÓйØ£¬Ò²ÓëfuzzingµÈ×Ô¶¯»¯²âÊÔ¼¿Á©µÄʹÓÃÓйØ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 

2017 vs 2018, ICS·ì϶ÀàÐ͵ÄÉ¢²¼


¹¥»÷Õß¿ÉÀûÓÃICS×é¼þÖеķì϶´¥·¢ËÁÒâ´úÂëÖ´ÐÓ×¢¹¤ÒµÉ豸µÄδÊÚȨ½ÚÔì¼°»Ø¾ø·þÎñ£¨DoS£©¡£³ÁÒªµÄÊÇ£¬´óÎÞÊý·ì϶£¨342¸ö£©¿É±»Ô¶³ÌÀûÓ㬲¢ÇÒÎÞÐèÉí·ÝÑéÖ¤ºÍרҵ֪ʶ/¸ß¼¶¼¼Êõ¡£Æ¾¾ÝUS ICS-CERTµÄÊý¾Ý£¬23¸ö·ì϶µÄexploit¹«¿ª¿ÉÓã¬ÕâÔö³¤ÁËËüÃDZ»¶ñÒâÀûÓõķçÏÕ¡£

2.5 ÊÜÓ°ÏìµÄICS×é¼þÉ¢²¼


·ì϶ÊýÁ¿×î¶àµÄICS×é¼þÔ̺¬£º


  • ¹¤³ÌÈí¼þ£¨143¸ö£©
  • SCADA/HMI×é¼þ£¨81¸ö£©
  • רΪ¹¤Òµ»·¾³Éè¼ÆµÄÍøÂçÉ豸£¨66¸ö£©
  • PLC£¨47¸ö£©


ÊÜÓ°ÏìµÄICS×é¼þ»¹Ô̺¬¹¤ÒµÍÆËã»úºÍ·þÎñ£¨5%£©¡¢¹¤ÒµÊÓÆµ¼à¿ØÏµÍ³£¨4%£©¡¢¸÷Àೡ¼¶É豸ºÍ±£»¤¼ÌµçÆ÷¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 
2018ÄêICS·ì϶ӰÏìµÄ×é¼þÉ¢²¼

2.6 ¹¤³ÌÈí¼þÖеķì϶


Ò×Êܹ¥»÷µÄ¹¤³ÌÈí¼þÔ̺¬·ÖÆçµÄHMI/SCADA¿ª·¢Æ½Ì¨¡¢½ÚÔìÆ÷±à³Ì¹¤¾ßµÈ¡£

¹¤³ÌÈí¼þÖеݲȫÎÊÌâͨ³£ÊÇÓɵÚÈý·½Èí¼þµ¼ÖµÄ¡£ÓÉÓÚµÚÈý·½×é¼þµÄ¿í·ºÊ¹Óã¬Ò»µ©³öÏÖ·ì϶¾Í»áÓ°Ïì´óÁ¿¹¤Òµ²úÆ·¡£ÀýÈ磬Î÷ÃÅ×ÓÂ¥Óî¿Æ¼¼²úÆ·ºÍÎ÷ÃÅ×ÓSIMATIC WinCC²å¼þÓÉÓÚ¼¯³ÉÁËÔ̺¬·ì϶µÄSentinel LDK RTElicenseÖÎÀíÆ÷¶øÒ×Êܹ¥»÷¡£´Ë±í£¬Î÷ÃÅ×ÓµÄÕû¸ö¹¤Òµ²úÆ·Ïß¶¼Êܵ½OpenSSL·ì϶µÄÓ°Ïì¡£ÀàËÆµØ£¬×÷ΪFloating License ManagerµÄÒ»²¿ÃÅ£¬Flexera PublisherÈí¼þÖеķì϶ͬʱӰÏìÁËÊ©Ä͵µĶà¸öµçÆø²úÆ·¡£


´Ë±í£¬Ó¦³ö¸ñ°ÑÎÈÓÃÓÚ½Ó¼ûICSϵͳµÄÒÆ¶¯APP£¨Android»òiOSƽ̨µÄÖÇÄÜÊÖ»ú¡¢Æ½°åµÈ£©¡£Ò×Êܹ¥»÷µÄ´ËÀà²úÆ·°¸ÀýÔ̺¬SIMATIC WinCC OA iOS App¡¢IGSS Mobile¡¢SIMATIC WinCC OA UIMobile App¡¢General Motors¼°OnStar (SOS) iOS¿Í»§¶Ë¡£´ËÀàÒÆ¶¯APPÔ½À´Ô½¶àµØÀûÓÃÓÚICS»ù´¡ÉèÊ©£¬µ«Æä°²È«Ë®Æ½ÈÔÓдýÌá¸ß£¬Í¨¹ýÈëÇÖÒÆ¶¯APP¿ÉÄܵ¼ÖÂÕû¸öICS»ù´¡ÉèÊ©Ãæ¶Ô±»ÈëÇֵķçÏÕ¡£


ÁíÒ»¸öÀàËÆµÄ°²È«ÎÊÌâÓëICSºÍÔÆ¼¼ÊõµÄ½áºÏÓйØ¡£ÀýÈ磬2018ÄêMindConnect NanoºÍMindConnect IoT2040£¨IoTÓ²¼þÍø¹Ø£¬ÓÃÓÚÏνӹ¤ÒµÉ豸ºÍÎ÷ÃÅ×ÓMindSphereÔÆÆ½Ì¨£©¾Í±»·¢ÏÖÒ×Êܹ¥»÷¡£


2.7 ¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷Öеķì϶


2018Äê¹¤ÒµÍÆËã»úºÍ·þÎñÆ÷ÖеݲȫÎÊÌâÖØÒªÓëÖ÷Á÷¹©¸øÉ̵ÄоƬ·ì϶ÓйØ£¬ÀýÈçÈۻٺ͹í»ê·ì϶£¬»¹ÓÐSpectre-NG·ì϶¡£ÁíÒ»¸öÓ°Ïì´óÁ¿¹¤ÒµÍÆËã»úµÄ·ì϶ÊÇ¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©ÖеÄRCE·ì϶¡£ÕâÔÙÒ»´ÎÖ¤ÁËÈ»£¬´«Í³¼¼Êõ£¨¼´·ÇICSÌØÓеļ¼Êõ£©Öеķì϶Äܹ»Ó°Ï칤ҵϵͳ¡£


2.8 ¹¤ÒµÍøÂ簲ȫ½â¾ö¹æ»®Öеķì϶


³ýÁËICSµÄÓ²¼þºÍÈí¼þ×é¼þÖеķì϶֮±í£¬2018Äê×êÑÐÈËÔ±»¹ÔÚ¹¤ÒµÍøÂçµÄ°²È«½â¾ö¹æ»®Öз¢ÏÖÁË·ì϶£¬ÀýÈçNortekµÄ½Ó¼û½ÚÔìÆ½Ì¨Linear eMerge E3 SeriesºÍÂÞ¿ËΤ¶û×Ô¶¯»¯µÄÍøÂ簲ȫÉ豸Allen-Bradley Stratix 5950¡£ÕâÔÙ´ÎÌáÐÑÁËÎÒÃÇ£¬¹¤ÒµÏµÍ³µÄ°²È«²»½öÓëICSÓ²¼þºÍÈí¼þ×é¼þÓйØ£¬»¹Ó빤ҵ°²È«½â¾ö¹æ»®Öеķì϶ÓйØ¡£


Èý¡¢³£¼ûÍþв



3.1 Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷


Ô̺¬¶ñÒ⸽¼þµÄ´¹µöÓʼþÈÔÊÇÉøÈ빤ҵÆóÒµµÄÖØÒª¹¥»÷ÏòÁ¿¡£ÔÚ´ÓǰÊýÄêÖУ¬ÕâÀàÍþвÒѳÉΪ¹¤Òµ¹¤×÷Õ¾µÄ³£¼ûÍþв¡£


ºÜ¶à´¹µöÓʼþ¶¼¾­¹ýÁ˾«ÐļÙ×°£ºËüÃǼÙ×°³ÉÕæÊµ¹«Ë¾·¢³öµÄóÒ×Ðź¯¡¢ÒµÎñ±¨¼Û¡¢Ô¼Ç뺯µÈ¡£´Ë±í£¬Ò»Ð©´¹µö¹¥»÷ÀûÓÃÁ˺Ϸ¨µÄÕæÊµÎĵµ×ÊÁÏ¡£ÕâÒâζ×Å´¹µö¹¥»÷Õß½«ÇÔÈ¡ºÏ·¨ÐÅÏ¢×÷Ϊ³ï±¸»î¶¯µÄÒ»²¿ÃÅ¡£
 

 ±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´¹µöÓʼþÑùÀý


ͨ³£Ë·´£¬Õë¶Ô¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷Æä×îÖÕÖ÷ÕŶ¼ÊÇΪÁËÇÔÈ¡½ðÇ®¡£µ±È»£¬Ò²ÓÐһЩ¼Ù×°³É¡°³ß¶È¡±´¹µö¹¥»÷µÄÕë¶ÔÐÔ¹¥»÷¡£


ƾ¾Ý±¦ÔËÀ³¹Ù·½ÍøÕ¾Í³¼Æ£¬¹¤Òµ´¹µö¹¥»÷²»½öÕë¶ÔÆóÒµÍøÂçÖеķþÎñÆ÷£¬»¹Õë¶Ô¹¤Òµ»ù´¡ÉèÊ©ÖеÄÒ»Ð©ÍÆËã»ú¡£ÔÚÈ«ÇòÁìÓòÄÚ£¬ÖÁÉÙ4.3%µÄICSÍÆËã»úÔø¼ì³ö¹ý¼äµýÈí¼þ¡¢ºóÃźͼüÅ̼ͼľÂí¡£ÕâЩ¶ñÒâÈí¼þ³£ÓÉ´¹µöÓʼþ½øÐзַ¢¡£ÎÒÃÇÒÔΪÕâЩ¶ñÒâÈí¼þµÄÁìÓò¿ÉÄÜÔ½·¢¿í·º£¬ÓÉÓÚ´¹µö¹¥»÷Õß³£¸üлò¶¨ÆÚת»»Æä¶ñÒ⹤¾ß£¬Ê¹µÃһЩ×îÐÂÑù±¾Î´±»Í³¼Æµ½¡£


ÓÉÓÚ´¹µö¹¥»÷Õß»ý¼«Ê¹Óô¹µöÓʼþ½øÐй¥»÷£¬ÎÒÃǹ۲쵽ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý²»ÐÝÅÊÉý¡££¨ÓëITÍÆËã»úÒ»Ñù£¬OTÍÆËã»úͨ³£Ò²×°ÖÃÁËÓʼþ¿Í»§¶Ë£¬ÒԿ繫˾»¥»»ÐÅÏ¢ ¨C ͨ³£»¹Ê¹ÓÃÁËÒ»ÑùµÄÓʼþÕÊ»§¡£ÎÒÃǺÜÉÙ¿´µ½OTÍøÂçÖÐʹÓÃÁËÓëIT·ÖÆçµÄÓʼþÕÊ»§£©¡£2018ÄêϰëÄêÎÒÃÇÔÚÈ«ÊÀ½çÁìÓòÄÚ¶¼·¢ÏÖÁËÕâÒ»Ôö³¤¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 

ÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý


ÈçÉÏͼËùʾ£¬Î÷Å·µØÓòÒâ±íµØÅÅÃûTop3£º¸ÃµØÓòµÄÊý×ÖÔö³¤ÁË2.7¸ö°Ù·Öµã£¬ÆäÖÐÔö³¤·ù¶È×î´óµÄÊǵ¹ú£¬¸ÃµØÓòµÄÊý×ÖÏÕЩ·­·¬¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 

Î÷Å·µØÓòÊÜ´¹µöÓʼþ¹¥»÷µÄICSÍÆËã»ú±ÈÀý


Õâµ¼ÖÂÁ˵¹úÔÚÈ«ÇòÅÅÃûÖÐÒÔ6.5%λÁеÚÊ®Èý£¬¶øÒâ´óÀû£¨6.8%£©ÔòÊÇΨһÅÅÃû±ÈµÂ¹ú¸ßµÄÅ·ÖÞ¹ú¶È¡£

ÖµÍ×ÌùÐĵÄÊÇ£¬´¹µöÓʼþÖеĺܶà¶ñÒ⸽¼þ´Ë¿Ì¶¼ÊǼÓÃܵÄѹËõÎļþ£¬ÃÜÂ븽ÔÚÓʼþµÄÕýÎÄÖ®ÖС£´Ë¾ÙÊÇΪÁËÌӱܼì²â£¬Í¨³£Çé¿ö϶ñÒâÈí¼þÖ»ÓÐÔÚÊÕ¼þÈË´ò¿ª¸½¼þʱÄÜÁ¦¼ì²âµ½¡£


ÎÒÃǽ¨Ò飬ËùÓй«Ë¾¶¼ÒªÌáÐÑÔ±¹¤ÕâÒ»ÕæÕýµÄÍþв£¬²¢ÑµÁ·ËûÃǼø±ð¹¥»÷¼£Ï󣬲»Òª´ò¿ª¿ÉÒÉÎļþ»òµã»÷Á´½Ó£¬²¢½«ÈκÎDZÔÚÊÂÎñÍ¨ÖªÍøÂ簲ȫÊýÃÅ¡£


3.2 ¼ì²âÑù±¾

2018ÄêϰëÄ꿨°Í˹»ùµÄ°²È«²úÆ·¹²ÔÚ40.8%µÄICSÍÆËã»úÉϼì²âµ½¶ñÒâÑù±¾¡£


ÕâЩ¶ñÒâÑù±¾¿É¹éÀàÓÚÒÔÏÂÀà±ð£¬ÁбíÖл¹±ê³öÁËÊÜ´ËÀàÑù±¾¹¥»÷µÄICSÍÆËã»úµÄ±ÈÀý¡£Çë°ÑÎÈÓÉÓÚͳ¼ÆÊý¾ÝѡȡÁË»ùÓÚÊðÃûºÍÆô·¢Ê½µÄ¼ì²â²½Ö裬һЩÎÞ·¨·Ö±æµÄ¶ñÒâÈí¼þÑù±¾±»¹éÀàÓÚGeneric£¨Í¨Óã©Àà±ð£¬ÕâÒâζ×ÅijЩÀà´ËÍâ¶ñÒâÈí¼þµÄ±ÈÀýÏÖʵÉÏÒª¸ü¸ß¡£


¼ì²âµ½µÄ¶ñÒâÑù±¾¹éÀ༰Æä±ÈÀý£º



  • 15.9% - ÁÐÈëºÚÃûµ¥µÄ»¥ÁªÍø×ÊÔ´


ÕâÀà¶ñÒâÑù±¾Í¨³£ÊÇÓû§ÔÚä¯ÀÀÆ÷Öдò¿ªÒ»¸ö¶ñÒâ»òÊÜϰȾµÄÍøÒ³Ê±ÏÂÔØµÃÀ´¡£ÕâÐ©ÍøÒ³Òѱ»ÁÐÈëºÚÃûµ¥£¬Òò¶ø´óÎÞÊýÇé¿öϰ²È«²úƷͨ¹ý¼ì²âURL¼´¿É·¢ÏÖ¹¥»÷¡£ÕâÀà×ÊÔ´³£ÓÃÓÚ·Ö·¢Ä¾Âí¡¢¼äµýÈí¼þºÍÀÕË÷Èí¼þ£¬ÇÒͨ³£¼Ù×°³É¸÷³§¼Ò½ÚÔìÆ÷µÄÆÆ½â¹¤¾ß»òÃÜÂë³ÁÖù¤¾ß£¬Ò²¿ÉÄÜÊǼÙ×°³É¹¤Òµ/¹¤³ÌÈí¼þµÄÆÆ½â°æ»ò²¹¶¡¡£


  • 8.7% - ¶ñÒâ¾ç±¾£¬ÍøÒ³³Á¶¨Ïò£¨JSºÍHTML£©£¬ÒÔ¼°ä¯ÀÀÆ÷·ì϶ÀûÓà ¨C 0.17%
  • 6.36% - È䳿£¬Ô̺¬Í¨¹ý¿ÉÒÆ¶¯Ã½ÌåºÍÍøÂç¹²Ïí´«²¼µÄÈ䳿£¨Worm£©¡¢Í¨¹ýµç×ÓÓʼþ´«²¼µÄÈ䳿£¨Email-Worm£©¡¢Í¨¹ýÍøÂç·ì϶´«²¼µÄÈ䳿£¨Net-Worm£©ºÍ¼´Ê±Ì¸ÌìÀûÓÃÖеÄÈ䳿£¨IM-Worm£©¡£´ÓÍøÂç»ù´¡ÉèÊ©µÄ½Ç¶ÈÀ´¿´£¬´óÎÞÊýÈ䳿¶¼ÊǹýÆÚµÄ¡£



ÕâÒ»Àà±ðÖеļÒ×åÔ̺¬£º


  • Worm.Win32.VBNA (0.2%)£¬³öÏÖÓÚ2009Äê¡£
  • Worm.Win32.Vobfus (0.05%)£¬³öÏÖÓÚ2012Ä꣬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¨Zbot¡¢Fareit¡¢CutwailµÈ£©¡£
  • Andromeda/Gamarue (0.69%)£¬¸Ã¶ñÒâÈí¼þ¹¹½¨µÄ¾ÞÐͽ©Ê¬ÍøÂçÓÚ2017Äê±»ÆËÃð¡£


ÓÈÆäÖµÍ×ÌùÐĵÄÊÇÒ»¸ö¹ýÆÚµ«¾­¾Ã²»Ë¥µÄ¶ñÒâÈí¼þNetWorm.Win32.Kido(3.14%)¡£×Ô2010ÄêÎÊÊÀÒÔÀ´£¬ËüÒ»ÏòÊÇÅÅÃû×î¸ßµÄ¼ì²âÑù±¾Ö®Ò»¡£


´Ë±í£¬Ò²´æÔÚÏñWorm.Win32.Zombaque (0.02%)ÕâÑùµÄP2PÍøÂç¼Ü¹¹µÄÈ䳿£¬¹¥»÷ÕßÄܹ»ËæÊ±¼¤»îËüÃÇ¡£»¹´æÔÚʹÓÃHTTPºÍ̸µÄ»îÔ¾È䳿£¬ËüÃdz£ÓÉVBS±àд£¬ÓÃÓÚÏÂÔØÆäËü¶ñÒâÈí¼þ£¬ÀýÈçºóÃźͼäµýľÂíµÈ¡£


  • 6.35% - ÔËÐÐÔÚä¯ÀÀÆ÷ÖеÄÍÚ¿óľÂí

          0.76% - WindowsÍÚ¿óľÂí


  • 5.78% - ¶ñÒâLNKÎļþ


ÕâÀàÑù±¾ÖØÒªÔÚ¿ÉÒÆ¶¯Ã½ÌåÉϼì²âµ½£¬³£×÷ΪÆäËü¶ñÒâÈí¼þ¼Ò×åµÄ´«²¼»úÔìµÄÒ»²¿ÃÅ£¬ÀýÈçAndromeda/Gamarue¡¢Dorkbot¡¢Jenxcus/DinihouµÈ¡£ÕâÒ»Àà±ð»¹Ô̺¬CVE-2010-2568£¨¸Ã·ì϶×îÔçÓÃÓÚ·Ö·¢ÕðÍø²¡¶¾£©·ì϶ÀûÓõÄLNKÎļþ£¨0.66%£©¡£¸Ã·ì϶»¹±»ÓÃÓÚ´«²¼Sality¡¢Nimnul/Ramnit¡¢ZeuSºÍVobfusµÈ¼Ò×å¡£

Ŀǰ£¬¼Ù×°³ÉºÏ·¨ÎĵµµÄLNKÎļþ±»ÓÃ×÷¶à½×¶Î´¹µö¹¥»÷µÄÒ»²¿ÃÅ£¬ÓÃÓÚÔËÐÐPowerShell¾ç±¾²¢ÏÂÔØ¶ñÒâpayload¡£ÔÚ¼«ÉÙÊýÇé¿öÏ£¬PowerShell¾ç±¾»áÏÂÔØÒ»¸öMetasploitÄ£¿é£¨MetasploitÖеÄTCPºóÃÅ£©µÄÌØ¶¨±äÌå¡£


  • 2.85% - Ô̺¬exploits¡¢¶ñÒâºê»ò¶ñÒâÁ´½ÓµÄ¶ñÒâÎĵµ£¨MSOffice + PDF£©
  • 2.31% - ϵͳÆô¶¯Ê±»ò²åÈë¿ÉÒÆ¶¯Ã½Ìåʱ×Ô¶¯ÔËÐеĶñÒâÎļþ£¨¿ÉÖ´ÐÐÎļþ¡¢¾ç±¾¡¢autorun.inf¡¢.LNKÎļþµÈ£©


ÕâÀàÑùÕý±¾×ÔÓÚ¶à¸ö¼Ò×壬µ«¶¼ÓÐÒ»¸ö¹²Í¬µã ¨C ×Ô¶¯ÔËÐС£Óк¦Ë®Æ½×îµÍµÄÑù±¾ÊÇʹÓÃÔ¤Ô¼ÒåµÄÖ÷Ò³×Ô¶¯Æô¶¯ä¯ÀÀÆ÷¡£ºÜ¶àʹÓÃautorun.infµÄ¼Ò×åÔÚÍøÂç»ù´¡ÉèÊ©·½Ãæ¶¼ÒѹýÆÚ£¨Palevo¡¢ SalityºÍ KidoµÈ£©¡£

  • 2.28% - ²¡¶¾

ÕâÀ෨ʽÔ̺¬Virus.Win32.Sality (1.22%)¡¢Virus.Win32.Nimnul (0.87%)ºÍVirus.Win32.Virut (0.61%)¼Ò×壨ÒѳÖÐø¶àÄ꣩µÈ¡£Ö»¹ÜÕâЩ¼Ò×åµÄÍøÂç»ù´¡ÉèÊ©¶¼ÒÑʧЧ£¬µ«ÓÉÓÚ×ÔÎÒ´«²¼µÄ¸öÐÔºÍÆëÈ«×èÖ¹ËüÃǵݲȫ´ëÊ©µÄ²»¼°£¬ËüÃÇÈÔÔÚͳ¼ÆÊý¾ÝÖÐÕ¼¾Ý´óÍ·¡£

  • 2% - ÀÕË÷Èí¼þ
  • 1.26% - ÒøÐÐľÂí
  • 0.9% - AutoCad¶ñÒâÈí¼þ
ÖµÍ×ÌùÐĵÄÊÇ£¬AutoCad¶ñÒâÈí¼þ£¬ÓÈÆäÊDz¡¶¾£¬ÖØÒªÔÚ¶«ÑǵØÓòµÄICSÍÆËã»úÉϼì²âµ½¡£¸ÃÀà¶ñÒâÈí¼þ³£ÔÚÍøÂçÎļþ¼ÐºÍ¹¤³Ì¹¤×÷Õ¾Öз¢ÏÖ¡£Ö»¹ÜAutoCad¶ñÒâÈí¼þµÄϰȾ¶¥·åÔÚ2000ÄêÖÁ2010ÄêÔçÆÚ³öÏÖ£¬µ±Ç°ÈÔ¿É·¢ÏÖ»îÔ¾µÄÑù±¾¡£
  • 0.61% - Õë¶ÔÒÆ¶¯É豸µÄ¶ñÒâÎļþ£¨ÔÚÉ豸Ïνӵ½ÍÆËã»úʱ¼ì²âµ½£©

3.3 Õë¶ÔÆû³µÔì×÷ÒµµÄÍþвTop3


´ÓÕâ·Ý»ã±¨ÆðÍ·£¬ÎÒÃǽ«Ã¿Áù¸öÔ¶ÔÒ»¸öÐÐÒµµÄTop3Íþв½øÐзÖÎö¡£


Õë¶ÔÆû³µÐÐÒµµÄ¹¥»÷ÖØÒªÊÔͼ°Ñ³ÖÆû³µµÄÔì×÷/Õï¶Ï¹¤ÒµÁ÷³Ì»ò³µÔØÏµÍ³£¬½ñÌìÎÒÃDz¢Ã»Óз¢ÏÖÕâÑùµÄ¹¥»÷¡£

µ«ÔÚ2018ÄêϰëÄ꣬¿¨°Í˹»ùµÄ²úÆ·×èÖ¹ÁË´óÁ¿Õë¶ÔÆû³µ¹¤³§×°ÅäÏߺÍÉ̵êÒÔ¼°Õë¶ÔÒ»¼¶¹©¸øÉ̹¤³§£¨Ô̺¬ÔËÐÐÆû³µÐÐÒµ¶àÖÖÈí¼þ²úÆ·µÄWindowsÍÆËã»ú£©µÄ¡°Í¨³£¡±¶ñÒâÈí¼þ¡£ÕâЩ¶ñÒâÈí¼þ×ÔÉí²¢²»ÊÇÕë¶ÔICS»·¾³µÄ£¬ËüÃÇÔ̺¬ÒÑÖªµÄ²¡¶¾¡¢ÍÚ¿óÈí¼þ¡¢³£¼ûµÄ¼äµýÈí¼þµÈ¡£Ö»¹ÜÕâЩ¶ñÒâÈí¼þµÄÖ÷ÕÅÊÇÔì³ÉÎïÀíÍøÂçµÄÇÖº¦£¬µ«Æä¸±×÷ÓÿÉÄÜ»á¶ÔICSºÍOTϵͳµÄ¿ÉÓÃÐÔºÍÆëÈ«ÐÔÔì³É³Á´óÓ°Ïì¡£


³ÁÒªµÄÊÇÒª¹Ø×¢½«À´¹¥»÷µÄDZÔÚ·çÏÕ£¬ÕâЩÍþвµÄ½Ã½ÝÐÔºÍÕë¶ÔÐÔ£¨¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷£©¼Ó¾çÁËÕâÒ»µã¡£


3.3.1 Sality½©Ê¬ÍøÂç


ÆäÖÐÒ»¸ö×î³£¼ûµÄÍþвÊÇSality£¬ËüÊÇÒ»¸ö³ÛÃûµÄÄ£¿é»¯¶à̬²¡¶¾/È䳿£¬×îÔç³öÏÖÓÚ2003Ä꣬²¢ÔÚ2015Ä껹ÔÚÊØ»¤¡£


ÔÚ´Óǰ£¬SalityµÄC&C·þÎñÆ÷ÓÃÓÚÏÂÔØÏÂÒ»½×¶ÎµÄ¶ñÒâÈí¼þ¼°ÇÔÈ¡Óû§µÄÕË»§Í´´¦¡£µ«´Ë¿ÌÕâЩC&CÒѾ­²»ÔÙ¿ÉÓ㬲¢ÇÒËùÓеÄSalityÑù±¾¶¼¿Éͨ¹ý³£¼ûµÄAV¼¼Êõ¼ì²âµ½¡£


Ö»¹ÜÈç´Ë£¬¸Ã¶ñÒâÈí¼þÈÔÔÚÈ«ÇòÍøÂç³ÖÐø´«²¼¡£¿¨°Í˹»ùÔÚÆû³µÐÐÒµµÄ´óÁ¿OTÍÆËã»úÉϼì²âµ½ÁËSality£¬ÎÒÃÇÒÔΪÏÖʵÊܵ½Ï°È¾µÄOTÍÆËã»úÊýÁ¿¸ü¶à¡£


SalityµÄ×ÔÎÒ´«²¼¸öÐÔʹµÃËü³ÉΪOT/ICS»ù´¡ÉèÊ©µÄÑϳÁÍþв£¬ËüÄܹ»´¥·¢»Ø¾ø·þÎñ¼°ÓÉÓÚ¶ñÒâÁ÷Á¿µ¼Ö±¾µØÍøÂçµÄ»úÄܽµÂä¡£


3.3.2 Bladabindi/njRAT½©Ê¬ÍøÂç


Õë¶ÔÆû³µÐÐÒµµÄÁíÒ»¸ö³Á´óÍþвÊÇBladabindi ¨C Ò»¸öÄ£¿é»¯µÄ¶àÖ°Äܽ©Ê¬ÍøÂç´úÀí£¬Æä´ó¾ÖÊDZàÒëºÃµÄÒ»×éAutoIT¾ç±¾¡£ËüµÄºóÃÅ/¼äµýÖ°Äܼ«¶È׳´ó£¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡¶àÖÖÃô¸ÐÐÅÏ¢¡£¸Ã½©Ê¬ÍøÂ绹ӵÓÐÀàËÆÈ䳿µÄÖ°ÄÜ£¬¿Éͨ¹ý¿ÉÒÆ¶¯Ã½Ìå´«²¼¡£


ËüµÄC&C·þÎñÆ÷´¦ÓÚ»îԾ״̬£¬ÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢·Ö·¢ºÅÁîºÍÏÂÔØÏÂÒ»½×¶Î¶ñÒâÈí¼þ£¨¶ñÒâ¿ó¹¤¡¢DDoS´úÀí¡¢ÀÕË÷Èí¼þµÈ£©¡£¹¥»÷ÕßʹÓö¯Ì¬DNS¼¼ÊõÀ´Ìӱܼì²âºÍ¶ñÒâÈí¼þ·ÖÎö¡£ÓÉÓÚÖ°ÄÜ׳´ó£¬Bladabindi¿ÉÄܶÔOTÍøÂç²úÉú³Á´óÓ°Ïì¡£


3.3.3 AutoCAD½©Ê¬ÍøÂç


»ùÓÚAutoCADµÄ½©Ê¬ÍøÂçÊÇÓÉAutoLISP (FAS)ľÂí¹¹½¨µÄ£¬ÆäC&C·þÎñÆ÷³õ´Î³öÏÖÓÚ2013Äê¡£¸Ã½©Ê¬ÍøÂçÒÀÈ»Óɹ¥»÷Õß½øÐÐÊØ»¤¡£


FASľÂí»á´Û¸ÄAutoCADµÄÉèÖã¬Ê¹µÃÿ´ÎÓû§´ò¿ªAutoCAD¹¤³Ìʱ³ÇÊÐÖ´ÐиÃľÂí£¬ÕâÒ²µ¼ÖÂÿһ¸öн¨µÄÏîÄ¿³ÇÊÐÊܵ½Ï°È¾¡£


ÆäC&CÈÔ´¦ÓÚ»îԾ״̬,ÓÃÓÚÏòÊÜϰȾµÄÍÆËã»ú·Ö·¢ÏÂÒ»½×¶Î¶ñÒâÈí¼þ¡£µ±Ç°£¬ÒÑÖªµÄΨÖðÒ»¸öÕâÖÖpayloadµÄÑùÀýÊÇÒ»¸öVB¾ç±¾£¬¸Ã¾ç±¾ÓÃÓÚÅú¸Ää¯ÀÀÆ÷µÄÖ÷Ò³ÉèÖúͽ«ä¯ÀÀÆ÷µ¼º½ÖÁËÁÒâURL¡£


¸ÃľÂíÖØÒªÕë¶ÔÑÇÖÞ£¨ÓÈÆäÊÇÖйú£©µÄ¹¤ÒµºÍ¹¤³ÌÆóÒµ£¬²¢ÇÒ¿ÉÄܶÔOTÍøÂçÔì³ÉÑϳÁÓ°Ïì¡£


¿ÉÄܵijõʼϰȾõè¾¶£º
  • ¸½¼þÖÐÔ̺¬Ä¾ÂíÏÂÔØÆ÷acad.fas£¨°µ²ØÔÚAutoCADÔìͼÖУ©µÄµç×ÓÓʼþ£¬¸ÃÓʼþÓɲ»ÊÜÒÉ»óµÄ³Ð°üÉÌ/·Ö°üÉ̺Ϸ¨¹¤³Ìʦ·¢ËÍ¡£
  • ¹¥»÷Õß·¢Ë͵Ĵ¹µöÓʼþ£¬Í¬ÑùЯ´øÔ̺¬acad.fasµÄ¸½¼þ
  • Я´øacad.fasµÄ¿ÉÒÆ¶¯Ã½Ì壨ÈçUÅÌ£©
  • ±¾µØÍøÂçÉϵĹ²ÏíÎļþ£¨Ô̺¬°µ²ØµÄacad.fas£©
ÖµÍ×ÌùÐĵÄÊÇ£¬ÔÚÍÆËã»ú±»Ï°È¾ºó£¬Êܺ¦Õß»áÔÚ²»ÖªÇéµÄÇé¿öÏÂͨ¹ýUSB¡¢µç×ÓÓʼþ¡¢±¾µØºÍÔÆ¹²ÏíÎļþ³ÖÐø´«²¼ÊÜϰȾµÄAutoCAD¹¤³ÌÎļþ¡£
Ææ¹ÖµÄÊÇ£¬C&C·þÎñÆ÷¶ËµÄ´úÂë¶Ô´«ÈëµÄÒªÇó×öÁËһЩ²é³­£¨ÀýÈçIPµØÖ·µÄ¹ú¶È¹ýÂË£©£¬ÈôÊDz鳭ʧ°Ü£¬Ôò²»»á½»¸¶µÚ¶þºÍµÚÈý½×¶Îpayload£¨ÀýÈçIPµØÖ·µØµãµÄ¹ú¶È²»ÇкϹ¥»÷ÕßµÄÐËÖ£©¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿ÉÄܵijõʼϰȾõè¾¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷ɱ¾Á´


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


µÚÒ»½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Î


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


µÚ¶þ½×¶ÎFASľÂíµÄ´úÂëÆ¬¶Î

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 

µÚÈý½×¶ÎVB ¾ç±¾ÑùÀý



ËÄ¡¢Íþвͳ¼Æ



±¾»ã±¨ÖеÄͳ¼ÆÊý¾Ý¶¼ÊǾ­¹ýÐí¿É´ÓKSNÓû§µÄÍÆËã»úÉÏÄäÃûÍøÂçµÃÀ´¡£


4.1 ×êÑв½Öè


¿¨°Í˹»ùICS CERT½«ÆóÒµÖеĹ¤Òµ»ù´¡ÉèÊ©¹éÀàΪICSÍÆËã»ú¡£ÓйØÍ³¼ÆÊý¾Ý´ÓÕâÒ»Àà´ËÍâÍÆËã»úÉÏÍøÂçµÃÀ´¡£ÕâÐ©ÍÆËã»úÔ̺¬ÔËÐÐÒÔÏÂÖ°ÄܵÄWindowsÍÆËã»ú£º


? Êý¾Ý²É¼¯Óë¼à¿Ø·þÎñÆ÷£¨SCADA£©£»
? Êý¾Ý´æ´¢·þÎñÆ÷£¨Historian£©£»
? Êý¾ÝÍø¹Ø£¨OPC£©£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾£»
? ¹¤³ÌʦºÍ²Ù×÷Ô±µÄÒÆ¶¯¹¤×÷Õ¾£»

? ÈË»ú½çÃæ£¨HMI£©¡£


»¹Ô̺¬´Ó¹¤¿ØÍøÂçÖÎÀíÔ±ÒÔ¼°¹¤Òµ×Ô¶¯»¯ÏµÍ³¿ª·¢ÈËÔ±µÄÍÆËã»úÉÏÍøÂçµ½µÄÊý¾Ý¡£


ÔÚ±¾»ã±¨ÖУ¬Ôâ·ê¹¥»÷µÄÍÆËã»úÊÇÖ¸Ôڻ㱨ÆÚ¼ä±¦ÔËÀ³¹Ù·½ÍøÕ¾°²È«½â¾ö¹æ»®ÖÁÉÙ±»´¥·¢Ò»´ÎµÄÍÆËã»ú¡£Ôâ·ê¹¥»÷µÄÍÆËã»úµÄ±ÈÀýÊÇÖ¸Ôâ·ê¹¥»÷µÄÍÆËã»ú£¨È¥³Á£©Õ¼ËùÓÐÑù±¾ÍÆËã»ú£¨Ôڻ㱨ÆÚ¼äÏòÎÒÃÇ·¢ËÍÁËÄäÃûÊý¾ÝµÄÍÆËã»ú£©µÄ±ÈÀý¡£


ͨ³£Çé¿öÏ£¬ÓÉÓÚ¹¤ÒµÍøÂçµÄÏÞ¶È£¬ICS·þÎñÆ÷ºÍ¹¤³Ìʦ/²Ù×÷Ô±µÄ¹Ì¶¨¹¤×÷Õ¾²»ÊÇ24Ó×ʱÁªÍøµÄ¡£ÕâÀàÍÆËã»ú¿ÉÄÜÖ»ÔÚ£¬ÀýÈçÊØ»¤ÆÚ¼ä£¬ÄÜÁ¦ÁªÍø¡£


ϵͳ/ÍøÂçÖÎÀíÔ±¡¢¹¤³Ìʦ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³µÄ¿ª·¢ÈËÔ±ºÍ¼¯³ÉÈËÔ±µÄ¹¤×÷Õ¾¿ÉÄÜ»áʱʱÁªÍø£¬ÉõÖÁ¿ÉÄÜÊÇ24Ó×ʱÁªÍø¡£


Òò¶ø£¬2018ÄêϰëÄ걦ÔËÀ³¹Ù·½ÍøÕ¾Ñù±¾ÍÆËã»úÖÐÔ¼ÓÐ40%µÄÍÆËã»úÊǶ¨ÆÚ»òÈ«ÌìÁªÍøµÄ¡£ÆäÓà»úеµÄÁªÍø¹¦·ò²»³¬¹ýÒ»¸öÔ£¬ÆäÖкöàÊÇÔ¶Ô¶ÉÙÓÚÕâ¸ö¹¦·òµÄ¡£


4.2Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêÕûÄêÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÏà±È2017ÄêÔö³¤ÁË3.2¸ö°Ù·Öµã£¬´ï47.2%¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2017 vs 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêϰëÄ꣨H2£©£¬È«ÇòÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÓëÉϰëÄ꣨H1£©Ïà±ÈÇá΢½µÂ䣬½µÂäÁË0.37¸ö°Ù·Öµã£¬ÖÁ40.8%.


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018Äê5ÔÂÖÁ8ÔÂÆÚ¼äÕâÒ»Êý×ÖÔø½µÂäÇ÷Ïò£¬µ«´Ó9ÔÂÆðÍ·ÓÖ³öÏÖÁËеÄÔö³¤£¬×îÖÕÒ»Ïò²»±äÔÚ22%Ö®ÉÏ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©


Óë2017ÄêÏà±È£¬2018Äêÿ¸öÔ·ݵÄÊý×Ö¶¼Òª¸ü¸ß¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2017 vs 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨Ô¶ÈÉ¢²¼£©


4.3 ¶ñÒâÈí¼þµÄÀà±ðÉ¢²¼


2018ÄêϰëÄ꣬¿¨°Í˹»ù¹²¼ì²âµ½2700¸ö¼Ò×åµÄ1.91Íò¸öICS¶ñÒâÈí¼þ±äÌå¡£ÓëÒÔǰһÑù£¬¾ø´óÎÞÊýÕë¶ÔICSµÄ¹¥»÷°¸Àý¶¼ÊÇËæ»ú¹¥»÷£¬¶ø²»ÊÇÕë¶ÔÐÔ¹¥»÷¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©


ľÂíÈÔÊÇ×î³£¼ûµÄÍþв£¬Óë2018ÄêÉϰëÄêÏà±È£¬ºóÃÅ£¨Backdoor£©µÄ·Ý¶îÔö³¤ÁË1¸ö°Ù·Öµã£¬ÀÕË÷Èí¼þ£¨Trojan-Ransom£©ÔòÔö³¤ÁË0.44¸ö°Ù·Öµã¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 

2017 ¨C 2018£¬Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨¶ñÒâÈí¼þÀà±ðÉ¢²¼£©


4.4 µØÀíÉ¢²¼


ÏÂÃæµÄµØÍ¼ÏÔʾÁË·ÖÆç¹ú¶ÈµÄICSÍÆËã»úÔâ·ê¹¥»÷µÄ±ÈÀý¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬ICS¹¥»÷*µÄµØÀíÉ¢²¼
*¸Ã¹ú¶ÈÔâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬ICS¹¥»÷±ÈÀý×î¸ßµÄ¹ú¶È/µØÓò£¨Top 15£©


Óë2018ÄêÉϰëÄêÏà±È£¬ICS¹¥»÷±ÈÀý¹ú¶ÈÅÅÃûµÄǰÎåÃûûÓиĹÛ£¬µ«Morocco£¨´Ë¿Ì´¦ÓÚµÚÈýÃû£©ºÍTunisia£¨µÚËÄÃû£©»¥»»Á˵ØÎ»¡£


2018ÄêϰëÄê¶íÂÞ˹Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀýÊÇ45.3%£¬ºÍÉϰëÄ꣨44.7%£©´¦ÓÚͳһˮƽ¡£¶íÂÞ˹µÄÅÅÃûÊǵÚ16Ãû¡£


ÅÅÃûÖнÏΪ°²È«µÄ¹ú¶È/µØÓòÊǰ®¶ûÀ¼£¨11.7%£©¡¢ÈðÊ¿£¨14.9%£©¡¢µ¤Âó£¨15.2%£©¡¢ÖйúÏã¸Û£¨15.3%£©¡¢Ó¢¹ú£¨15.7%£©ºÍºÉÀ¼£¨15.7%£©¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄêICS¹¥»÷±ÈÀý×îµÍµÄ¹ú¶È/µØÓò


ÈôÊÇÒÀÕÕµØÀíÇøÓòÀ´»®·Ö£¬·ÖÆçÇøÓòÖ®¼äµÄÊý×ÖͬÑùÏà²îºÜ´ó¡£·ÇÖÞ¡¢¶«ÄÏÑǺͶ«ÑÇÒ»ÏòÊÇÅÅÃû½Ï¸ßµÄµØÓò¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêH1ºÍH2£¬ICS¹¥»÷±ÈÀýµÄµØÀíÇøÓòÉ¢²¼


4.5 ϰȾԴ


´ÓǰÊýÄê¼ä£¬»¥ÁªÍø¡¢¿ÉÒÆ¶¯Ã½ÌåºÍµç×ÓÓʼþ³ÉΪICSÍÆËã»úµÄÖØÒªÍþвÆðÔ´¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ICSÍÆËã»ú*µÄÖØÒªÍþвÆðÔ´£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©


* Ôâ·ê¹¥»÷µÄICSÍÆËã»ú±ÈÀý


2018ÄêϰëÄ꣬»¥ÁªÍøÊÇ26.1%µÄICS¹¥»÷µÄÍþвÆðÔ´¡£Óë2018ÄêÉϰëÄêÏà±È£¬ÕâÒ»Êý×ÖÇá΢½µÂ䣬¶øÓëÖ®Ïà·´µÄÊǵç×ÓÓʼþÍþвµÄ±ÈÀýÇá΢Ôö³¤¡£ÆäËüÖØÒªÏ°È¾Ô´µÄ·Ý¶îÓë2018ÄêÉϰëÄêµÄˮƽÏà²î²»´ó¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ICSÍÆËã»úµÄÖØÒªÍþвÆðÔ´£¨ÒÔÁù¸öÔÂΪͳ¼ÆÖÜÆÚ£©

4.6 ÖØÒªÏ°È¾Ô´µÄµØÓòÉ¢²¼


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬ICSÍÆËã»úÖØÒªÍþвÆðÔ´µÄµØÀíÉ¢²¼


4.6.1 »¥ÁªÍø


ÔÚËùÓÐµÄ·ÖÆçµØÓò£¬»¥ÁªÍø¶¼ÊÇÖØÒªµÄÍþвÆðÔ´¡£µ«ÕûÌå¶øÑÔ±±Å·¡¢Î÷Å·ºÍ±±ÃÀµÄÍþвÊý×ֽϵÍ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬Ôâ·ê»¥ÁªÍøÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬»¥ÁªÍøÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15


4.6.2 ¿ÉÒÆ¶¯Ã½Ìå


Õë¶ÔICSµÄ¿ÉÒÆ¶¯Ã½ÌåÍþв±ÈÀý½Ï¸ßµÄµØÓò³¤¶ÌÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ£¬½ÏµÍµÄµØÓòÊDZ±ÃÀ¡¢°Ä´óÀûÑǺͱ±Å·¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬Ôâ·ê¿ÉÒÆ¶¯Ã½ÌåÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬¿ÉÒÆ¶¯Ã½ÌåÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15


4.6.3 Óʼþ¿Í»§¶Ë


Õë¶ÔICSµÄµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄµØÓòÊÇÀ­¶¡ÃÀÖÞ¡¢ÄÏÅ·ºÍÎ÷Å·£¬µ«ÕûÌå¶øÑÔ¸÷¸öµØÓòµÄÊý×ÖÏà²î²»´ó¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2018ÄêϰëÄ꣬Ôâ·ê¶ñÒâÓʼþÍþв¹¥»÷µÄICSÍÆËã»ú±ÈÀý£¨°´µØÓòÉ¢²¼£©

µÂ¹úÔÚµç×ÓÓʼþÍþв±ÈÀý½Ï¸ßµÄ¹ú¶È/µØÓòTop15ÖÐÉϰñ£¬ÖµÍ×ÌùÐĵÄÊǸùú¶ÈÔÚÆäËü·½Ã涼δÉϰñ¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
2018ÄêϰëÄ꣬µç×ÓÓʼþÍþвÅÅÃû½Ï¸ßµÄ¹ú¶È/µØÓòTop15

Ô­ÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h2-2018/90041/