38 · Examining the Security Threat Landscape檢視安全威脅態勢

Other Considerations其他考量

The following are a few of the many common myths that pertain to network security:

以下是幾個關於網路安全的常見迷思:

  • No one would be interested in my network: In the past, this statement might have been true if your network was very small, but attackers are now interested in smaller targets that are easier to attack. If you think no one would be interested in attacking your network, your network is probably not as secure as it could be, making it very interesting indeed to attackers. Even if you have a two-computer network that contains no tempting information such as banking information, debit card information, or national defense secrets, your computers can still be a target for several reasons. One reason is that an attacker can use your computers to launch larger, distributed attacks. Another reason is an attacker may use your computers to access the remote systems which your computers access.不會有人對我的網路感興趣:過去,如果你的網路規模非常小,這種說法或許成立,但如今攻擊者反而對較容易攻擊的小型目標更感興趣。如果你認為不會有人想攻擊你的網路,那麼你的網路可能其實並不如你以為的那麼安全,這反而會讓它對攻擊者變得非常有吸引力。即使你的網路只有兩台電腦,也沒有銀行資訊、金融卡資訊或國防機密等誘人資訊,你的電腦仍可能因為幾個原因而成為攻擊目標。其中一個原因是攻擊者可利用你的電腦發動規模更大的分散式攻擊;另一個原因是攻擊者可能利用你的電腦,存取你的電腦所能連接到的遠端系統。
  • Router or gateway uses NAT; network is inaccessible and secure: NAT has been created to address issues with overlapping IP address spaces and allow translation between private and public address spaces. NAT has never been a security mechanism, and indeed many techniques allow bidirectional communication over NAT gateways. Without any rules, inspection, or other real firewalling procedures, pure NAT gateways should never be considered part of a network security architecture.路由器或閘道使用 NAT,網路便無法被存取且安全:NAT 的建立是為了解決 IP 位址空間重疊的問題,並允許在私有位址空間與公有位址空間之間進行轉換。NAT 從來就不是一種安全機制,事實上,有許多技術可以透過 NAT 閘道進行雙向通訊。若沒有任何規則、檢查或其他真正的防火牆程序,純粹的 NAT 閘道絕不應被視為網路安全架構的一部分。
  • The company has never been hacked: Unless you regularly monitor and analyze the activity on your assets, you cannot be sure that you have never been hacked or are not currently being attacked. Effective monitoring and analysis almost certainly require software to automate the analysis.公司從未遭到入侵:除非你定期監控並分析資產上的活動,否則你無法確定自己從未遭到入侵,或目前並未正遭受攻擊。有效的監控與分析幾乎必然需要軟體來自動化分析工作。
  • IT staff is responsible for implementing security: While IT staff play a very important role in the configuration, maintenance, and monitoring of security controls, end users play a primary role in implementing security. In a typical environment, end users heavily outnumber IT staff. End users must understand the need for security policies and their role in policy execution.安全性由 IT 人員負責實作:雖然 IT 人員在安全控制的設定、維護與監控方面扮演非常重要的角色,但終端使用者在落實安全性方面同樣扮演主要角色。在一般環境中,終端使用者的人數遠多於 IT 人員。終端使用者必須了解安全政策的必要性,以及自己在執行政策時所扮演的角色。
  • The company has a firewall in place; it is secure: It used to be very common to use resources to secure the perimeter and have very open systems within the perimeter. The understanding that internal systems must be secured has gained much traction, but there are still proponents of focusing on a hardened perimeter. Also, reliance on a single security technology is risky. For example, firewalls can be poorly configured, and client-side attacks are very difficult for firewalls to deal with. Focusing on individual security points and relying on any single security technology is insufficient in today’s networking environments.公司已設有防火牆,因此是安全的:過去很常見的做法是投入資源保護邊界,而讓邊界內部的系統相對開放。如今大家已越來越了解必須保護內部系統的重要性,但仍有人主張只需著重於強化邊界防護。此外,依賴單一安全技術也存在風險。舉例來說,防火牆可能設定不當,而用戶端攻擊對防火牆而言也非常難以應付。在當今的網路環境中,只著重個別安全防護點、依賴單一安全技術是不夠的。

This section provided an overview of the current networking threat landscape, but it only addresses the basics. The threats are innumerable and constantly changing. The list below provides more examples of today’s threat vectors:

本節概略介紹了目前的網路威脅態勢,但僅涵蓋基本內容。威脅種類繁多且不斷變化,以下清單提供了更多當今威脅向量的範例:

  • Cognitive threats via social networks: Social engineering takes a new meaning in the era of social networking. Attackers can create false identities on social networks, building and exploiting friend relationships with others on the social network. Phishing attacks can much more accurately target susceptible audiences. Confidential information may be exposed due to a lack of defined or enforced policy.透過社群網路的認知威脅:在社群網路時代,社交工程有了新的意涵。攻擊者可以在社群網路上建立虛假身分,藉此與其他人建立並利用朋友關係。網路釣魚攻擊也能更精準地鎖定容易受騙的對象。若缺乏明確或落實的政策,機密資訊便可能因此外洩。
  • Consumer electronics exploits: The operating systems on consumer devices (smartphones, tablets, and so on) are an option of choice for high-volume attacks. The proliferation of applications for these operating systems, and the nature of the development and certification processes for those applications, augments the problem. The common expectation of bring your own device (BYOD) support within an organization’s network increases the importance of this issue.消費性電子產品的漏洞利用:消費性裝置(智慧型手機、平板電腦等)上的作業系統,是大量攻擊的首選目標。這些作業系統上應用程式的氾濫,以及這些應用程式的開發與認證流程的性質,更加劇了這個問題。組織網路中普遍存在的自帶裝置(BYOD)支援需求,也提高了這個議題的重要性。
  • Widespread website compromises: Malicious attackers compromise popular websites, forcing the sites to download malware to connecting users. Attackers typically are not interested in the data on the website, but they use it as a springboard to infect the systems of users connecting to the site.大範圍的網站入侵:惡意攻擊者會入侵熱門網站,迫使這些網站向連線的使用者下載惡意軟體。攻擊者通常對網站本身的資料不感興趣,而是將其作為跳板,藉此感染連線到該網站的使用者的系統。
  • Disruption of critical infrastructure: The Stuxnet worm confirmed concerns about an increase in targeted attacks that are aimed at the power grid, nuclear plants, and other critical infrastructure.關鍵基礎設施的破壞:Stuxnet 蠕蟲證實了外界對於針對電網、核能電廠及其他關鍵基礎設施的目標式攻擊日益增加的擔憂。
  • Virtualization exploits: Device and service virtualization adds more complexity to the network. Attackers know this fact and increasingly target virtual servers, virtual switches, and trust relationships at the hypervisor level.虛擬化漏洞利用:裝置與服務虛擬化為網路增添了更多複雜性。攻擊者深知這一點,因此越來越常鎖定虛擬伺服器、虛擬交換器,以及 Hypervisor 層級的信任關係作為攻擊目標。
  • Memory scraping: Increasingly popular, this technique is aimed at fetching information directly from volatile memory. The attack tries to exploit operating systems and applications that leave traces of data in memory. Attacks are particularly aimed at accessing data that is encrypted when stored on a disk or sent across a network but is clear text when processed in the RAM of the compromised system.記憶體擷取(Memory Scraping):這項技術的普及度日益提高,其目標是直接從揮發性記憶體中擷取資訊。這種攻擊會嘗試利用會在記憶體中留下資料痕跡的作業系統與應用程式。此類攻擊特別針對那些在磁碟上儲存或透過網路傳送時是加密的、但在受入侵系統的 RAM 中處理時卻是明文的資料。
  • Hardware hacking: These attacks aim to exploit the hardware architecture of specific devices, with consumer devices being increasingly popular. Attack methods include bus sniffing, altering firmware, and memory dumping to find crypto keys. Hardware-based keyloggers can be placed between a keyboard and a computer system. Bank machines can be hacked with inconspicuous magnetic card readers and microcameras.硬體駭入:這類攻擊旨在利用特定裝置的硬體架構,而消費性裝置正日益成為熱門目標。攻擊方法包括匯流排監聽、竄改韌體,以及傾印記憶體以尋找加密金鑰等。以硬體為基礎的按鍵側錄器可以被安裝在鍵盤與電腦系統之間。提款機也可能被不起眼的磁卡讀取器與微型攝影機入侵。
  • IPv6-based attacks: These attacks are becoming more pervasive as the migration to IPv6 becomes widespread. Attackers are focus initially on covert channels through various tunneling techniques, and man-in-the-middle attacks use IPv6 to exploit IPv4 in dual-stack deployments.以 IPv6 為基礎的攻擊:隨著向 IPv6 遷移的普及,這類攻擊也變得越來越普遍。攻擊者最初著重於透過各種通道技術建立隱蔽通道,而中間人攻擊也會利用 IPv6 來攻擊雙堆疊部署中的 IPv4。
Which type of threat vector aims to attack power grids or nuclear plants?哪一種威脅向量的目標是攻擊電網或核能電廠?