²£«~ªA°È ¬ã°Q¬¡°Ê ¾P°â¸ê°T ·s»D¤¤¤ß Ãö©ó§Ú­Ì
     
 
 
TippingPoint IPS
IPS ¤J«I¨¾¿m¨t²Î
DVLabs «Â¯Ù¨¾Å@
¬ÛÃö·s»D-¥xÆW

Case Study

¦w·½³q°T (600E)
ÀR©y¤j¾Ç (2400E)
§Þ³N¸ê°T
®Õ¶éÀ³¥Î TippingPoint IPS »´ÃPºÞ²z P2P
²L½Íº|¬}¨¾¿m§Þ³N
¤µ¤Ñ¸ò¤j®a½Í½Í "Botnet"
ºô¸ô³¨³½ (Phishing) ¦¨¬° 2007 ¦~³ÌÄY­«ªº¸ê¦w«Â¯Ù¤§¤@
Gartner ³ø§i - 2007¸ê¦w«Â¯Ù
IPS³B²z®Ä¯à»P¸ê¦w¨¾Å@¯à¤Oªº§¹¬ü¤ñ¨Ò
TippingPoint IPS ±N¸ê¦w¨¾Å@±q¹h¹D©µ¦ù¨ìºÝÂI
¼Æ¦ì¬Ì­]¥þ²y§ó·s - ¬°¹s®É®t§ðÀ»´£¨Ñ¯u¥¿ªº¹s®É®t«OÅ@¾÷¨î
 

§ó¦h¸ê°T½Ð¦Ü TippingPoint ºô¯¸°ÑÆ[:
http://www.tipping-point.com/

ºô¸ô³¨³½ (Phishing) ¦¨¬° 2007 ¦~³ÌÄY­«ªº¸ê¦w«Â¯Ù¤§¤@

¬Û¹ï©ó¹L¥h®É±`Ãzµo¤j³W¼ÒªºÄ¯ÂÎÅõºÈºô¸ô¨Æ¥ó (Slammer ¡B Ninda ¡B Netsky¡K) ¡A³o¨â¤T¦~¨Óºô¸ô¥@¬É¦ü¥G¥­ÀR«Ü¦h¡A¥D­nªº­ì¦]¦b©óÀb«È¤w¸g§ïÅܤF§ðÀ»ªº¥Øªº¡A¤£¦A·Q¥X¦W¬¯Ä£¡B¤]¤£¥u¬O­nÃÒ¹ê¦Û¤vªº§Þ³N¦³¦h¦n¡A¦Ó¬O­n¹ê½èªºÀò¨ú§Q¯q¡A´N¦p¦P ª¾¦W»È¦æ·m­ê Willie Sutton ³Q°Ý¤Î¬°¦ó­n·m»È¦æ®É»¡¤F¤@¥y¸Ü¡G¡u¦]¬°¨ºùئ³¿ú¡C¡v¡CÀb«È¹B¥Îªº¤âªkÁc¦h¡A¨ä¤¤¡Aºô¸ô³¨³½ (Phishing) ¤w¦¨¬°¨­¥÷µsÅÑ¡u²£·~¡v¤¤¦¨ªø³Ì§Ö³tªº§Þ³N¤§¤@¡C 2004 ¦~ 1 ¤ë¡A¤Ïºô³¨¤u§@¤p²Õ (Anti-Phishing Working Group) ¿ëÃÑ¥X 174 ­Óºô³¨ºô¯¸¡A¦P¦~ 12 ¤ë©~µM¼É¼W¶W¹L 1,000 ­Ó¡C 2006 ¦~¡Aºô¸ô¶B´Û³y¦¨ªº®ø¶OªÌ°]°È·l¥¢¦ô­p¦b 5 »õ ( ®Ú¾Ú¬ü°êÁp¨¹¥æ©ö©e­û·|ªº²Î­p ) ¨ì 20 »õ ( ®Ú¾Ú¤Ïºô³¨¤u§@¤p²Õ²Î­p ) ¬ü¤¸¤§¶¡¡C°ê»Úª¾¦W¸ê¦w²Õ´ SANS ¬Æ¦Üµo§G§iĵ°T®§¡G 2007 ¦~±N¦¨¬°ºô¸ô³¨³½¨a®`ÄY­«¥ÆÀݪº¤@¦~¡C

ºô¸ô³¨³½¡H­n«ç»ò³¨¡H§Ú³Q³¨¤F¶Ü¡H

¤@¯ë¨Ó»¡¡Aºô¸ô³¨«È (Phisher) ·|µo¥X¤j¶qªº¹q¤l¶l¥ó°°ºÙ¦Û¤v¬O»È¦æ¡BÁʪ«ºô¯¸¡A°ò©ó¬Y¨Ç¦]¯À ( ¨Ò¦p¥Î¤á¸ê®Æ½]®Ö»Ý­n¡B±K½X¨ì´Á©Î¬O¤¤¼ú»Ý­n½Í³ø¸ê®Æµ¥ ) ­n¨D¦¬¥óªÌÂI¾\«H¤¤ªººô§}«á¶i¦æ¸ê®Æ½T»{©Î¬O§ó§ï¡C¹Ï¤@¬Oºô¸ô³¨«Èµs¥Î PayPal ¦W¸qµo¥Xªº³¨³½«H¥ó¤º®e¡G

¹Ï¤@¡G°°ºÙ Paypal ªº³¨³½«H¥ó¤º®e

¦pªG¦¬¥óªÌ¤£ºÃ¦³¥L¡AªG¯u¨Ì·Ó«H¤¤ªº»¡©ú³sµ²¸Óºô§}¡A±N·|¬Ý¨£¦p¹Ï¤Gªººô­¶µe­± ( »Å¦ü PayPal ªº°²ºô­¶ ) ¡A¨Ã­n¨D¿é¤J¤@¨Ç­«­nªº­Ó¤H¾÷±K¸ê®Æ¡G

¹Ï¤G¡G»Å¦ü PayPal ªº°²ºô­¶

³o¤@Ãþºô¸ô³¨³½¤âªkªºµn¤J­¶­±¤j³£¨ã¦³³\¦h¦@³q¯S¼x¡A¥]¬A¡G±q¯u¥¿ª¾¦Wºô¯¸§ì¤U¨Óªº¹Ï¤ù©M³sµ²¡B¨« HTTP ( ¦Ó«D HTTPS ) ¨ó©w¡A¥H¤Î¦bºô§}¦C¤¤§e²{ IP ¦ì§} ( ¦Ó«D¤@­Óºô°ì¦WºÙ ) ¡C·í³Q®`ªÌ¿é¤J±b¸¹±K½X¤§«á¡Aºô¸ô³¨«È´N¥i¥H»´©ö¦a±o¨ì³o¨Ç¸ê®Æ¡C§ó¬ÆªÌ¡A¦³¨Ç³¨³½ºô­¶ÁÙ·|­n¨D¨ü®`ªÌÄ~Äò¶ñ¼g¨ä¥L§ó¦hªº­Ó¤H¸ê®Æ¹³¬O¨­¤ÀÃÒ¦r¸¹¡B¦a§}»PÁpµ¸¹q¸Ü¡B¿ËÄݦWºÙ ( ¦]¬°»È¦æ¦æ­û·|°Ý¤Î¡Aºô¸ô³¨«È¤é«á­n¨ì¥Î±b¸¹®É¥²¶·ª¾¹D ) µ¥¡C

ºô¸ô³¨³½¤âªk¦Aºë¶i¡Gºô§}¶ù±µ (Pharming) »P³½¤e¦¡ºô¸ô³¨³½ (Spearing)

·íµM¡A¸g¹L´CÅ骺¤j¶q³ø¾É¤§«á¡A§Ú­Ì³£³Q±Ð¨|¾Ç·|¤£­nÀH·N¶ÃÂI¾\¹q¤l¶l¥ó¤¤ªººô§}³sµ²¡A¥H§KÅܦ¨³Q³¨ªº¤j³½¡C©ó¬O¥GÄF³N§ó°ª©ú¡B³]­p§ó²Ó¿°ªººô³¨§Þ³N -- ºô§}¶ù±µ (Pharming) ¥H¤Î³½¤e¦¡ºô¸ô³¨³½ (Spearing) º¥º¥¦¨¬°ºô¸ô³¨«È­Ìªº¥D¬y§@¬°¡Cºô§}¶ù±µ (Pharming) ³Ì¦­¦b 2004 ¦~®É´N¤w¸gµo²{¡A¥¦ªº¹ê¬I¤âªk¬O¡Gºô¸ô³¨«È¥ý³]ªk¤J«I DNS(Domain Name Server) ¨t²Î«á¡A¦A«§ï¨ä¦s¦b cache ¸Ìªº Domain Name »P IP ¹ï¬M¬ö¿ý ( ¦³¤HºÙ§@ DNS cache ©ñ¬r ) ¡C·í¨Ï¥ÎªÌ¦V³o¥x DNS ¬d¸ßºô§}®É¡A´N·|³Q¾É¤Þ¨ì¤@­Óºô¸ô³¨«È°°³yªººô¯¸¤W¦Ó§¹¥þ¤£¦Ûı¡C¨ü®`ªÌ¦³¥i¯à¦b°²ºô¯¸¤¤ ( ¦p¥é¯uªººô¸ô»È¦æµn¤J­º­¶ ) ¯d¤U­«­nªº±b¸¹±K½X¸ê®Æ¡A©Î¬O¦]¬°ÂsÄý§t¦³´c·Nµ{¦¡ªººô¯¸¦Ó¾D´Ó¤J¤ì°¨ (Trojan) »PÁä½L´ú¿ýµ{¦¡¡A¦b©¹«áªº¤é¤l¸Ì¬ªÅS§ó¦hªº­Ó¤H°T®§¡C

°£¤F¦b DNS ¦øªA¾¹°Ê¤â¸}¡Aºô¸ô³¨«È¤]¥i¥H³z¹L¦UºØ¤è¦¡³]ªk»¤¨Ï¨ü®`ªÌ¤U¸ü %SYSTEMROOT%/system32/drivers/etc/hosts ÀÉ®× (Windows ¨Ï¥ÎªÌ ) ¦s¦b¦Û¤vªº¹q¸£¤¤ ¡A³o­ÓÀɮ׸̴N¥]§t¤F IP »P Domain Name ªº¹ïÀ³¬ö¿ý¡A·í¨Ï¥ÎªÌÂsÄýºô­¶®É¡A¹q¸£·|Àu¥ý¨Ï¥Î³o­ÓÀɮפ¤ªº¬ö¿ý¡A¦pªG¦b¸ÓÀɮפ¤¬dµL¸ê®Æ¤~·|Âà¦Ó¸ß°Ý·í¦aªº DNS ¦øªA¾¹¡C§Q¥Î³o­Ó¤âªk¡Aºô¸ô³¨«È´N¥i¥H»´©ö­¢¨Ï¨ü®`ªÌ³s¨ì¦Û¤v¹w³]ªº´c·Nºô¯¸¤¤¨Ã¯d¤U¬Ã¶Qªº¸ê®Æ¡C

¨º»ò¡A³½¤e¦¡ºô¸ô³¨³½ (Spearing) ¤S¬O«ç»ò°µªº©O¡H³\¦hºô¯¸ ( ¯S§O¬O Portal) ªº¼gªk¤j³£±Ä¨ú¦h¼h¦¸¬[ºc©Î¬O Cross Site ³sµ²ªº¤è¦¡¡A·íÂsÄýªÌÂIÀ»ºô¯¸¬Y­Ó«öÁä©Î¬O¶W³sµ²¹Ï¥Ü®É¡A´N·|³Q¾É¤Þ¨ì¥t¤@­Ó Site( ¥i¯à¬O AP ¦øªA¾¹ ) °õ¦æ¤@¬qµ{¦¡©Î¬O¶}±Òºô¯¸¤º­¶ªºµe­±¡C§Q¥Î³o¼Ëªº¬[ºc¡Aºô¸ô³¨«È¥ý¤J«I Portal Si te( »È¦æ»P B 2C ¡B C 2C ºô¯¸©¹©¹¬O­º¿ï ) «á¡A«§ï³sµ²¤º­¶ªº¸ô®|¨ì¦Û¤v¬[³]ªººô¯¸ ( ·íµM¥~ªí¬Ý°_¨Ó»P¯uªº¤º­¶ºô¯¸¤@¼Ò¤@¼Ë ) ¡A©ó¬O¡A·í¨ü®`ªÌ¶}±ÒÂsÄý¾¹ÂsÄý³o­Ó Portal ¯¸®É¡A´N·|«D±`®e©ö¦b²@µL¨¾³Æªº±¡ªp¤U³sµ²¨ì°²ºô­¶¡A§Y¨Ï¤@¶}©l³s½uªº Portal ¯¸¥¿½TµL»~¡C

¦p¦ó°µ¨ì¦³®Äªººô¸ô³¨³½¨¾¿m¡H

·íºô¸ôª÷¿Ä¬¡°Ê¶V¨Ó¶VÀWÁc¡Aºô¸ô³¨«È¤]´NÅܱo¶V¨Ó¶V³g°ý¡Cºô¸ô¥Ç¸o¦³¬Û·íªºÁô°Î©Ê¡A¤£¶È¯}®×§xÃø¡A¥[¤WÀò§Q¥iÆ[¡A¦]¦¹¤]´N¤£Ãø·Q¹³¬°¤°»ò´X¥G¨C¶g³£¦³ºô¸ô³¨³½¨Æ¥ó³Q´CÅé³ø¾É¡C·Q­n°µ¨ì¦³®Äªº¨¾¿m¡A·íµM­n¥ý±q¤F¸Ñºô¸ô³¨³½¤âªk¶}©l¡A¦A³v¨B«ä¦Ò¨¾Å@¤§¹D¡C¹Ï¤T¤¤¸Ô­z¤Fºô¸ô³¨«È¹ê¦æºô¸ô³¨³½ªº¹Lµ{¡G

  • ¤J«I¤@¥x¹q¸£¡A³q±`·|¿ï¾Ü Web ¦øªA¾¹¡C
  • ´Ó¤J«H¥óµo°eµ{¦¡¡A¤j¶q±Hµo§t¦³³¨³½´ÛÄF°T®§ªº¹q¤l¶l¥ó¡C
  • ¦¬¨ì«H¥óªº¨ü®`ªÌ¨Ì·Ó«H¤¤«ü¥ÜÂIÀ»¤º§tªººô­¶³sµ²¡C
  • ³¨³½ºô¯¸§e²{¦b¨ü®`ªÌªº¹q¸£¿Ã¹õ¤W¡C
  • ¨ü®`ªÌ¦b³¨³½ºô¯¸¤¤¿é¤J­«­nªº­Ó¤H¸ê®Æ¡C

¹Ï¤T¡Gºô¸ô³¨³½¹Lµ{¤­³¡¦±

·Q­n¨¾Å@ºô¸ô³¨³½¡A°£¤F¤£­nÀH·NÂIÀ»¹q¤l¶l¥ó¤¤ªººô­¶³sµ²¤§¥~¡A³\¦h¤H·|¦b¦Û¤vªº¹q¸£¤¤¥[¸Ë¿ëÃѳnÅé¡A¹ï´c·Nªº³¨³½ºô¯¸«Ø¥ß¶Â¥Õ¦W³æ¡A¥HÁ×§K»~³s«á¬ªº|¸ê®Æ¡CµM¦Ó¡A¶È¨Ï¥Î²³æªº¤ñ¹ï¶Â¦W³æ©Î¬O©U§£¶l¥ó¹LÂo³W«h´N§Æ±æ§ùµ´ºô¸ô³¨³½ªº«IÂZ¨Ã¤£®e©ö¡C©ó¬O¡A¦bºô¸ôªº¹h¹DºÝ«Ø¸m¨¾¿m¾÷¨î ( ¨Ò¦p¤J«I¨¾¿m¨t²Î --IPS) ¡A°w¹ï¶i¥Xªº¹q¤l¶l¥ó»Pºô­¶³sµ²°µ¤ÀªR«á¡Aªýµ´ºô¸ô³¨³½¬¡°Êªº¶i¦æ¬O³\¦h¸ê¦w±M®a«ØÄ³ªº¤è¦¡¡C

ºô¸ô³¨«È¤§©Ò¥H¥i¥HÅý³¨³½¤âªk¶¶§Q¶i¦æ¡A§ä¨ì¥i¥H¤J«Iªº Web ¦øªA¾¹¬O«Ü­«­nªºÃöÁä¡Cºô¸ô¥@¬É¤¤¦³¤Ó¦hªº Web ¦øªA¾¹¦s¦b¦³¤Ó¦hªºº|¬} (Vulnerability) ¡A¤£½×¬O§@·~¨t²Î¥»¨­¡F¥ç©Î¬Oºô¯¸«Ø¸mªÌ±`¥Îªº IIS/Apache ³nÅé¡A¦pªG§ó·sµy¦³©µ¿ð¡A«Ü®e©ö¾DÀb«È¤J«I«á«Ø¥ß³Ì°ªºÞ²zÅv­­¡A´Ó¤J¦UºØµ{¦¡¡C©Ò¥H»¡¡Aº|¬}¨¾¿mªº§¹¾ã»P§_»Pºô¸ô³¨³½¬O§_¥i¥H¶¶§Q¶}©l®§®§¬ÛÃö¡Aµ½¥Î¤J«I¨¾¿m§Þ³N¥i¥H¦b¹h¹DºÝ±N·N¹Ï¤J«Iªº«Ê¥]Ädªý¡A¤]¬OÁ×§K¾D¨ìºô³¨ªºÃöÁä¡C§O§Ñ¤F¡Aºô¸ô³¨«È«Ü¥i¯à§Q¥Î±z¤â¤Wªº Web ¦øªA¾¹¥h³¨¨ä¥L«D±z³æ¦ì¸Ìªº¤H¡A±`±`·|Åý±z¦¨¬°¥N¸o¯Ì¦Ï¦Ó¤£¦Ûª¾¡C

±µ¤U¨Óªº¤u§@¤~¬O°w¹ï¹q¤l¶l¥ó¤º®e¥H¤Îºô­¶¸Ì¶Ç¿éªº°T®§¥[¥H¿ëÃÑ»P¹LÂo¡C¨ä¤¤¡A´X­Ó¦³®Äªº§@¬°½Ñ¦p¡G

  • °»´ú¨Ãªý¾× mess-mailer ³nÅéµo°e¤j¶qªº³¨³½¶l¥ó¡C
  • ªýÄd¥H HTML ®æ¦¡¤º´O°°³y eBay/PayPal ³sµ²ªº¹q¤l¶l¥ó¡C
  • ±N¹q¤l¶l¥ó¸Ì©Ò¦Cªººô§}³sµ²»P¯u¹êªº HTML page ¤£²Åªº¹q¤l¶l¥ó¡C
  • ¹q¤l¶l¥ó¸Ì¤º´O¦³ HTML ­Ó¬Oªºªí®æ¡A¨ü®`ªÌ¶ñ¼g¸ê®Æ¦bªí®æ¤¤«á·|¶Ç°e¨ìºô¸ô³¨«È¹w³]ªº¥Øªº¦a¤¤¡C
  • °»´ú¬O§_¨Ï¥Î HTTP( «D HTTPS) ¶Ç°e¾÷±Kªºª÷¿Ä±b¸¹±K½X¸ê®Æ¡B«H¥Î¥d¸ê®Æ¡C
  • ¦U­Óª¾¦Wª÷¿Ä¾÷ºc ( ¦pªáºX»È¦æ ) µn¤Jºô¯¸ªº½T»{¡C

³¨³½ºô¯¸ªº¿ëÃѤu¨ã -- µU¤ö (Monkeyspaw)

°ê»Ú¤W¦³¤@­Ó±Mªù¬ã¨s¨¾½dºô¸ô³¨³½¤âªkªº²Õ´ --APWG(Anti-Phishing Working Group) ¡A¨ä­º®u±M®a Tod Beardsley( ¥Ø«e¥ô¾©ó TippingPoint ªº¼Æ¦ì¬Ì­]¹êÅç«Ç DVLabs) ¼¶¼g¥X¤@®M¥i¥H°»´ú³¨³½ºô¯¸ªº¤u¨ãµ{¦¡¥s°µ¡uµU¤ö¡v ( Monkeyspaw ) ¡A ¨Ï¥ÎªÌ¥i¥H§K¶O¤U¸ü«á¦w ¸Ë¦b¦Û¤vªº¹q¸£¤W (PS ¡G Âs Äý¾¹¥²»Ý¨Ï¥Î FireFox) ¡C¸Ó¤u¨ã·|¤ÀªR±z©ÒÂsÄýªº¨C­Óºô¯¸ªº¸Ô²Ó ¸ê®Æ¡A ¥]¬A IP ¦ì§}»P©ÒÄݩҦb¦a¡F¹B¥Î DNS Lookup ¬d¸ß Domain ªºµn°OªÌ¡F¦øªA¾¹°ò¥»¸ê®Æ¡F¦P®É¤]¤ä´©±N ²§±`ºô¯¸¸ê®Æ¶Ç°eµ¹¸ê¦w²Õ´»P¼t°Ó¥\¯à¡C¨ä¸Ô²Óªº¦w¸Ë»P¾Þ§@¤è¦¡½Ð°Ñ¬Ý¤U­±ªººô §}¡A ¸Ì­±ªº»¡©ú«D±`²M·¡©öÀ´ http://www.planb-security.net/userscripts/monkeyspaw-howto.html

¨ä¥L§ó¦hÃö©ó³¨³½§Þ³Nªº°T®§¥i¥H¨ì APWG ªººô§}§ä´M http:// www.antiphishing.org

DVLabs-- ¼Æ¦ì¬Ì­] (Digital Vaccine) ¹êÅç«Ç¡G TippingPoint DVLabs ºôù¤F·~¬Éªººë­^¤H­û¡A¦p Tod Beardsley--APWG(Anti-Phishing Working Group) ªº­º®u±M®a¡B Rohit Dhamankar--SANS ¤G¤Q¤j§ðÀ»³ø§iªºÁ`½s¿è¡A¤]¦]¦¹ DVLabs ¤£¦ý©ó¤é«eÀò±o Frost & Sullivan ¬ã¨s¾÷ºcµû¿ï¬°¦¨ªø³Ì§Ö³tªº·s¦w¥þ®zÂIµo²{ªÌ¡A¦P®É¤]¬Oµo²{°ªÄY­«©Ê¸ê¦w«Â¯Ù©M Microsoft ¦w¥þ®zÂIªº»â¾É²Õ´¡C

¡½ ¤å¡G¥Û¿×Às / TippingPoint ¥xÆW ­»´ä§Þ³NÁ`ºÊ / robin_shih@3com.com
 

Datasheet

IPS Overview
IPS Specifications
TippingPoint 50
TippingPoint 200E
TippingPoint 2400E
TippingPoint 5000E
TippingPoint SMS
TippingPoint ZPHA
TippingPoint Digital VaccineR Service
TippingPoint Custom Digital Vaccine Service
TippingPoint Managed Security Service
TippingPoint NSS Gold Award Summary
 
TippingPoint IPS ²£«~¤¤¤å«¬¿ý
TippingPointºô³¨°»´ú»P¨¾¿m-¹ê¥Îªº¶B´Û¨¾½d¸Ñ¨M¤è®×
TippingPoint DDoS§ðÀ»¨¾¿m§Þ³N
TippingPoint IM/P2P¿ëÃÑ»PºÞ²z§Þ³N

 

*¥»¯¸«¬¿ý¶È´£¨Ñ°Ñ¦ÒªA°È¡A«¬¿ý½Ð¥H¦U­ì¼tºô¯¸¬°¥D

     
¤W¤@­¶
¦^­º­¶
¤U¤@­¶
¨ì³»¼h
Netfos IT/Secure Technology
 
     
 
¥x¥_Á`¤½¥q
¹q¸Ü: +886 2 6636-8889
¶Ç¯u: +886 2 6638-9998
¥x¤¤¤À¤½¥q
¹q¸Ü: +886 4 3606-8999
¶Ç¯u: +886 4 3602-0999
°ª¶¯¤À¤½¥q
¹q¸Ü: +886 7 862-8889
¶Ç¯u: +886 7 862-9998
   
 
     
 
© 2004-2007 NetFos co.,ltd. All Rights Reserved.
§K¶OªA°È±M½u¡G0809-016818