|
¨¾¤î§ðÀ»¸õªO¥D¾÷ªº¦w¥þºÞ²zµ¦²¤ ¶À¥@©ø ¤¤¥¡¬ã¨s°| ¸ê°T¬ì¾Ç¬ã¨s©Ò §U¬ã¨sû ºKn §ðÀ»¸õªO¥D¾÷ªº°ÝÃD¹ï¥Ø«eºô¸ôµ²ºc¤wºc¦¨ÄY«¦w¥þ«Â¯Ù¡A¼ç¥ñªº¦M¾÷±N¶W¹L¤@¯ë¹q¸£¯f¬r¡C¾Úĵ¬F¸p¦D¨Æ§½ªº²Îp¦ôp¡A°ê¤º¬ù¦³¤Q¤À¤§¤@ºô¸ô¥D¾÷³Q´Þ¤J¤ì°¨µ{¦¡¡]§Y§ðÀ»¸õªO©Ò§Q¥Îªº«áªù±J¥D¡^¡C³Ìªñºô¯¸¤J«I¨Æ¥óÀW¶Ç¡A¦h¼Æ»P³Q¾ÞÁaªº¥D¾÷¦³Ãö¡A¦p Yahoo¡BeBay µ¥°Ó¥Îºô¯¸¾D¨ü¤À´²¦¡ªýÂ_§ðÀ»¡]¤j¶q¥D¾÷³Q¦w©ñªýÂ_§ðÀ»µ{¦¡¡^¡ALove-You-Letter »P³Ìªñªº Navidad
¨Æ¥óµ¥«h¬OÓ¤H¹q¸£³Q¥Î¨Ó¶¡±µ´²§G§ðÀ»µ{¦¡¡C¥»¤å±´°Q¦UºØ¸õªO§ðÀ»¤èªk¡A¨¾¤îµ¦²¤¡B¨Ã±´°Q°l¬d§Þ³Nªº¥¼¨Óµo®i¡B¬ÛÃöªk«ß³d¥ôÂkÄݵ¥¡C ÃöÁä¦r: ¸õªO§ðÀ»¡B«áªù¾Þ±±¡BÁô±K³q¹D¡B»¤³´°õ¦æÀô¹Ò¡B¦æ¬°«ü¯¾¡C ¤@¡B§ðÀ»¸õªO»Pºô¸ô¦w¥þ«Â¯Ù ³Ìªñ·L³n¤½¥qµ{¦¡½X¾DÅÑ¡A¦h³B°Ó°Èºô¯¸±Á{¤À´²ªýÂ_§ðÀ»¡A¬ü°ê¦U¤j¾Ç¯É¾D¤j³W¼Ò¥þ±¤J«I¡C³o¨Ç³£¤ÏÀ³¸ê°T¦w¥þ«Â¯Ù¤wÄY«¼vÅT¤j²³ªº¤é±`¥æ©ö©¹¨Ó¡C®Ú¾Ú TW-CERT 88 ¦~ªº°ê¤ºWeb server ¦~«×¦w¥þ½Õ¬d[4]¡A¦³ 53 % ªº¥D¾÷¥i³Q¨ú±o Web Admin ªºÅv¡C§Ú̪ñ¤éªº¦Û§Ú¦w¥þÀË´ú¾÷¨îªº°O¿ý¦³Åã¥Ü¦³°ª¹F 59% ¾÷¾¹¦³µ{«×¤£µ¥ªº¦w¥þ¯Ê³´¡C¦]¦¹¦D¨Æ§½ªº¡u¤ì°¨¡v¥D¾÷¦ôp¤ñ²v(1/10)¨Ã¤£ºâ°ª¦ô¡A¦]¬°¥un¦³¤ßªº¤J«IªÌ³£¥i¯à¦b53% ªº¥D¾÷¤¤´Þ¤J¡u«áªù¡v¡C ¦ý¤@¯ë¤H¹ï©ó¦w¥þĵı³£«]©ó¡u¥iµø¡v©Î¡u¥i¹îı¡vªº¦w¥þ«Â¯Ù¡A¨Ò¦pºô¶¾DP«§ï¡A©Î¸ê®Æ³Q·´·l¡C¥h¦~¤K¤ë¬F©²ºô¯¸³Q¤jÁ|¶î´«ºô¶¡A¦U¬É¯ÉªíÃö¤Á¡A¤½Å¥¡B®y½Í·|¤£Â_Á|¦æ¡A¦ý¨Æ¶È©ó¦¹¡C¤µ¦~¤Q¤ë°ê¼yºô¸ôÁÁ¶Ç±N¦³Ãþ¦ü¨Æ¥ó«ºt¡A¨Æ«á¶È¦³¹s¬Pºô¯¸¦³ºô¶³Q§ï¸ñ¶H¡A¦]¦¹¤j®a¼y©¯¤£¤w¡A§ó²`«H¦¹¬°¡uÁÁ¶Ç¡v¡C¦ý±¡ªp¯u±o¦p¦¹¼ÖÆ[¶Ü¡H®Ú¾Ú§Ú̲`¤J½Õ¬d¡A¦b³æ¤@¾÷Ãö¤º¦³¦s¦b¦UºØ¤£¦P§Î¦¡«áªùªº¥D¾÷¡A¤ñ¨Ò¹F 50%¡C³o¼Ëªº¤ñ¨Òè¦n¤ÏÀ³ TW-CERT ¦~«×¦w¥þ½Õ¬d¼Æ¾Úªº¥i«H«×¡G¥ç§Y³o¨Ç¥i¯à³Q¨ú±o admin shell ªº¥D¾÷¡A³£¦³¬YºØ§Î¦¡ªº«áªùµ{¦¡ÁôÂè䤤¡C 1.
¥¼¨Ó§ðÀ»ÁÍ¶Õ ¥¼¨Óºô¸ô¦w¥þ«Â¯Ù³£±N»P«áªù«Ø¥ß®§®§¬ÛÃö¡A¥]¬A¡G n §ðÀ»«á·tÂÃÁô±K¾Þ±±«áªù ³o¬Oºô¸ô§ðÀ»ºë½o¤Æªº¥²µMµo®i¡C¥ç§Y½ÆÂøªº§ðÀ»¹Lµ{±N¤À¶¥¬q¡A©ÎºÙ¬°§ðÀ»ª¬ºA§Ö¨ú (Attack Process Cache)¡A¦b¤J«I¥Øªº¹F¦¨¤§«e¡A¥Î¨Óºûô«e¦¸§ðÀ»³~®|ªººZ³q¡C n «áªù»P¯f¬r·P¬V´C¤¶¾ã¦X «áªùµ{¦¡±N»P¯f¬r·P¬V¤è¦¡¤¬¬Û¾ã¦X¡C¶Ç²Î¯f¬r¬O¦P¨B«D¾Þ±±¼Ò¦¡¡A¥ç§Y¥u¯à¨Ì¿à¨Æ¥ó¦P¨B¡]¦p13¤é¬P´Á¤¡^¡A¥H¤Þµo´c·N«ü¥O¡C¦ý«áªùµ{¦¡ªº¯S©Ê¬O«D¦P¨B¾Þ±±¼Ò¦¡¡AÀH®É¥i¯àIJµo´c·N«ü¥O¡C n ¤À´²¦¡¡B¤j³W¼Ò¶¡±µ§ðÀ» ³Ì¨å«¬ªº¹ê¨Ò¬O¤À´²¦¡ªýÂ_§ðÀ»(Distributed Denial of Service)¡A§Q¥Î¤j¶q¤À´²©ó¦U¦aºô¸ôªº¥Î¤á¥D¾÷¡A¦P®É±Ò°Ê§ðÀ»¡C«áªùµ{¦¡ªº¹B¥Î¬O¤À´²¦¡§ðÀ»«nªº¤@Àô¡C 2. «Ø¥ß«áªù¤§¥Øªº n
ÅѨú¸ê·½§Q¥Î¡A¨Ò¦pºô¸ôÀW¼e¡]³]¸m http proxy
server¡^ ´²§G¦U¦a¹q¸£ªº«áªù¡A¬°¼Æ¬Æ¦h¬O¥Î¨ÓÅѨú¸ê·½¡A¥]¬A Web access »P E-mail Relay¡A¥H¨ú±oÄ_¶Qªººô¸ô¸ê·½¡CÁ|¤¤¬ã°|¬°¨Ò¡A¹ï¥~ÀW¼e¥R¨¬¡A¬O¦³¥ø¹Ï¥Î¤á«I¤Jªº³Ì¤j»¤¦]¡C¦U¤j ISP ¦P¼Ë±Á{Ãþ¦ü«Â¯Ù¡C¨Æ¹ê¤W¡A³o¼Ëªº¥Ç¸o§ÎºA¦p¦Pµs¥´¹q¸Ü¡A¥iÂÇ¥H¸`¬Ùºô¸ô¨Ï¥Î¶O¥Î¡C n
«D¦P¨B§ðÀ»ª¬ºA§Ö¨ú ºûÅ@ª¬ºA§Ö¨ú(cache)±N¥i§Ö³t¨ú±o¤W¦¸§ðÀ»ª¬ºA¡A¥iÀ³¥I½ÆÂøªº¤J«Ipµe¡A¨Ò¦p§ðÀ»¥i¨Ì¾Ú¥Ø¼ÐÅv®t²§¡A¥ý¨ú±o§CÅv¥Î¤á¹q¸£¦s¨úÅv¡A¦Aº¥¶i´x±±°ªÅv¥Î¤á¡A¶i¦Ó¤J«I«n¦øªA¾¹¡C¶¶§Ç¤W¡A¬°§CÅv¸ê°T¥Î¤á¢w> °ªÅv¸ê°T¥Î¤á ¢w> ´¶³q¦øªA¾¹±b¸¹ ¢w> ºÞ²zªÌÅv±b¸¹¡C¨C¤@¶¥¬qªº§ðÀ»ª¬ºA§Ö¨ú¥iºûô¤J«IºÞ¹DªººZ³q¡C n
³]¥ß§ðÀ»¸õªO ¶¡±µ§ðÀ»¥iÁ×§K³Q°l¬d¡A¦P®É¾Þ±±¤j¶q§ðÀ»¸õªO¡A¥H¤£¦P¨Ó·½¦ì§}¹F¨ì´ÛÄF¬y¶qºÞ²z¨t²Î¥Øªº¡A¶i¦Ó§Î¦¨¤À´²ªýÂ_§ðÀ»¡C 3. «áªùµ{¦¡«I¤J¤è¦¡ ¤@¯ë§ðÀ»«á´Þ¤J «áªù´Þ¤Jªº³Ì¨Î±J¥D¬O¹ï©ó¡u¦w¥þ¡v¤£¸g¤ßªº¨Ï¥ÎªÌ¡C²Ä¤@Ãþ¬OºÞ²z¤£µ½ªº¦øªA¾¹¡C²Ä¤GÃþ¬O¸ê°T½Ã¥Í²ßºD¤£¨}ªº¥Î¤áºÝ¹q¸£¡C¥¼¨Ó±Á{ªº³Ì¤j«áªù«Â¯Ù±N¨Ó¦Û¥Î¤á¨t²Î¡C¹ï©ó¥Î¤á¨t²Î³Ì¤j«Â¯Ù¥]¬A¡G n
E-mail: ¯f¬r¡B´c·N°õ¦æÀɧ¨±a¨Ã¤£¥i©È¡C²{¦b³Ì¨ã«Â¯Ùªº¬O¨Ï E-mail ±µ¦¬³nÅé²£¥Í°O¾ÐÅé·¸¼g§ðÀ»ªº´c·N±±¨îÀÉÀY(header)¡A³oÃþ§ðÀ»ªº¯S©Ê¬O¥un¥Î¤á±µ¦¬ E-mail¡A¤£¥²¶}±Ò´N·|·P¬V¡C³o¬O¥i¥H¬ð¬ï¥ô¦óÄY±K¨¾¤õÀ𪺧ðÀ»¡C n
Web Content: malicious
Script/Applet ¡C n
Document Contents: ²z½×¤W©Ò¦³®æ¦¡ªºÀɮ׳£¼çÂæM¾÷¡A¥i¨ÏÀ³¥Îµ{¦¡²£¥Í¯Ê³´¡A¶i¦Ó°õ¦æ«Dªk«ü¥O¡C³oºØ§ðÀ»¥i¥H¬ð¯}¹êÅéºô¸ô¹jµ´¡C ¤H¦]¯Ê³´(social engineering) n
¹ê»Ú¬° Script ©Î¥i°õ¦æÀɮסA¦ýÁôÂì° .txt .jpg .gif ÀɦW¡C n
¥H¼ôÃѪB¤Í¨¥÷¡AE-mail §¨±a´c·N¥i°õ¦æ¤º²[¡C 4. °»´ú«áªùµ{¦¡ªº§xÃø©Ê ¤@¥¹¾D¨ü§ðÀ»¡A¬°½T«O¨t²Î¤£³Q¸m¤J«áªùµ{¦¡¡AY¨Æ¥ý¨S¦³°O¿ý¦UÀɮתº½]®Ö½X (checksum)¡A©Ò¦³¥i°õ¦æÀÉ¡B¨t²Î³]©w³£n«·s¦w¸Ë¡A¦]«áªùµ{¦¡²z½×¤W¥i¤Æ¨¬°²{¦sªºÀ³¥Îµ{¦¡¡A¬Æ¦Ü²`¤J¨t²Î®Ö¤ß¡A¥i¼ÒÀÀì§@·~¤è¦¡¡A¨Ï¨t²Î¹B§@¦p±`¡A«ÜÃøµoı¨ä¦s¦b¡C¤@¯ë°»´ú³nÅé¶È¯à°»´ú¡u³Q°Ê³s½u¡v¤è¦¡ªº«áªù¡A°»´ú²v»P»~¥¢²v³£«ÜÃø¦X¥G»Ý¨D¡A¦]³Q°Ê³s½uªº port ¦ì§}¥i¥ô·N§ó°Ê¡A³s½u¨ó©w§óÀHµÛ¹B¥ÎªÌ¤£¦P¡A¥i»´©ö§ó§ï¡C¥¼¨Ó«áªùµ{¦¡ªºÅܲ§µ{«×»Pµo®i³t«×±N»·°ª©ó¤@¯ë³æ¯Â¹q¸£¯f¬r¡C 5. µo²{«áªùªº¨Æ¨Ò §Ṳ́w²³æ»¡©ú§ðÀ»ÁͶջP«áªù«Ø¥ßªºÃö«Y¡B¥Øªº¡B»P´Þ¤J¤è¦¡¡C¦¹½×¤åªº°Ê¾÷·½¦Û³Ìªñ¦b³]©w firewall ®É¡A¦]°l¬d²§±`¬y¶q·½¤~Ååı«áªùµ{¦¡¥ÆÀݪºÄY«©Ê¡C¦b firewall ¸Ì±¦³¤@¥x«Ü³æ¯Âªº¦øªA¾¹¡A¥u´£¨Ñ«H¥óÂà°e»P°ì¦W¬d¸ß¤Î©e¥ô¡A¦]¦¹°£¤º¹ï¥~ udp port 53 ¡A¥~¹ï¤º udp port 53¡B tcp port 25 ¶}©ñ¡A¨ä¥L port ¤£¸Ó¦³¬y¶q¡C¦ý´N¦b·sªº¦w¥þ¬Fµ¦¬I¦æªºÀþ¶¡¡A¤j¶q«Ê¥]³Q©Úµ´¶Ç°e¡C§Ú̦]¦¹ÃhºÃ«áªùµ{¦¡¤w«I¤J¡C¨Ï¥Î lsof (list opened file) ¤ñ¹ï¦Uµ{§Ç»P©Ò»ÝªA°È¦ì§}¡A¤~§ä¥XÁô¨¬°¥¿±`ªº¦øªAÀ³¥Î¨t²Î¡C³o¬O¤@¤ä³Q°Ê³s½u«¬ªº»·ºÝ¾Þ±± root shell¡C ¤G¡B«áªù¦w¸Ë«¬ºA»P¸õªO¤è¦¡ 1. «O¯d²{¦³©Î¦w¸Ë¦³¦w¥þ¯Ê³´ªA°È³nÅé¡B³]©w(Vulnerable Service¡BConfiguration) ³Ì¨Îªº«áªù¬O«O¯d¦³¦w¥þ¯Ê³´ªºªA°È³nÅé¡A¦ýÅý¨Ï¥ÎªÌ»~¥H¬°©Ò¥Îªº¬O³Ì·s¨S¦³¯Ê³´ªºª©¥»¡C¦]¦¹²z½×¤W¦³¦w¥þ¯Ê³´ªºªA°È³nÅé¡AY¥i¾Ú¥H¨ú±o¨t²Î¦s¨úÅv¡A³£¥iµø¬°¡u«áªù¡v¡C n
´ÛÄF¸É±jµ{¦¡¡G¤J«IªÌP¤O©ó×§ï¦w¸Ë³]©wÀÉ¡A§ó·s¸É±jª©¥»¸ê°TÅã¥Ü°T®§¡A¦ý¨ã¯Ê³´³nÅéºû«ù¤£ÅÜ¡C n
´ÛÄF¦w¥þÀË´úµ{¦¡¡G½s¿è°õ¦æÀÉ¡A§ó§ïª©¥»Åã¥Ü¸ê°T¡C¥]¸ËªA°È³nÅé (wrapper)¡A¹LÂoÄdºI¨ó©w¿é¥X¤J¤¤§t¦³¯S©wÀË´ú¦r¦ê¸ê®Æ¡]¦p±`¥Î¦w¥þ®zÂI±½ºË¨t²Î¡B¤ñ¹ï¹ï©ó¬YºØ CVE[3] ªºÀË´ú¤è¦¡¡^¡A¥OÀË´úµ{¦¡»~§P¡C 2.
¸m´«²{¦³ªA°È³nÅé¡Aºû«ù¨ä즳¨ó©w¹B§@¥¿±` ³Ì¦³¦Wªº«áªù¬O Ken Thompson ¦b¨ä¦´Áµo®iªº
Unix login µ{¦¡¤¤ÁôÂáu·tªù¡v¡A·í¿é¤J¯S©w¦WºÙ®É¡A¥i¨ú±o¶WÅv±ÂÅv¡C¦]¦¹§ó§ï login µ{¦¡¬O©ñ«áªù³Ì§Öªº³~®|¡A±N¨Ï©Ò¦³¤¬°Ê¦¡»·ºÝ³s½uµ{¦¡¦p telnet/rlogin µ¥ºû«ù즳¹B§@¥¿±`¡A¦ý¦b¯S©w¿é¤J®É±N¶}±Ò«D¥¿·í±ÂÅvªºÅv¡C 3.
«D¬J¦³ªA°È¡A¥t¦w¸Ë¾Þ±±ªA°È ³o¬O¥Ø«e³Ì¬y¦æªº«áªù¾Þ±±¤è¦¡¡AµS¦p»·ºÝ¾Þ±±Ó¤H¹q¸£¡A¦ý¤]³Ì®e©ö³Q°»´ú¥X¨Ó¡C¤@¯ë¯f¬r°»´úµ{¦¡³£¯à§ä¥X³oÃþªº«áªù¡C ¤T¡B«Ø¥ßÁô±K¾Þ±±³q¹D n«Ø¥ßÁô±K¾Þ±±³q¹D¡A¥i¤À§O«Ø¥ß¡]1¡^¾Þ±±«ü¥O³q¹D(Command Tunnel, C
Tunnel)¡A¡]2¡^¦^À³°T®§³q¹D(Response Tunnel, R Tunnel)¡C¤GªÌ¥i¬Û¨Ì©Î¿W¥ß¡C³o¨âºØ³q¹D¤S¤À§O¥i¥Ñ¾Þ±±ªÌ¥D°Ê(Active Controller)/³Q°Ê(Passive Controller)¡A»P¨ü±±ªÌ¥D°Ê(Active Responder)/³Q°Ê(Passive Responder)¡C¥H (C Tunnel, R Tunnel) ªí¥Ü¡AType I: (Active
Controller, Active Responder), Type II:(Passive Controller, Active
Responder), Type III:(Active Controller, Passive Responder), Type IV:(Passive
Controller, Passive Responder)¡C 1.
Type I Tunnel ³o¬O¤@¯ë«Ø¥ß³Q°Ê³s½u (Passive Tunnel, forward shell)ªº¤è¦¡¡C¦b¨ü±±¤è¡]³Q±H±JºÝ¡^°õ¦æ«áªù«ü¥O±µ¦¬ªA°Èµ{¦¡¡]©ó¯S©wªA°È¦ì§}¡^¡A³o¬O³Ì¼sªx¦s¦bªº¾ÞÁa¤è¦¡¡A§Î¦¨·tÂ꺦øªA¨t²Î¡C³o¬O¤@¯ë¤¬°Ê¦¡ªº²×ºÝªA°Èµ{¦¡¦p telnetd/rlogind µ¥§Î¦¡ªº«áªù¡Cºô¸ô¨¾¤õÀð§Y¥iªý¾×³oÃþªº¾Þ±±³q¹D¡C¡]¨¾¥~©¹¤º¬y¶q¡^ 2. Type II Tunnel ³o¬O¨ü±±ªÌ¥D°Ê¶Ç»¼¸ê®Æ (Active Tunnel, reverse shell)ªº¾Þ±±¤è¦¡¡A¤@¯ë³£¬O¥H http/ftp µ¥¦Xªk¹ï¥~¨ó©w¡A«Ø¥ß tunnel (¦p©Ò¦³¹ï¥~³s½u³£¸g¥Ñ http)¡A§Î¦P«Ø¥ß¥H http «Ê¥]Äâ±a¼h¡Aºc«ØµêÀÀ±MÄݺô¸ô¡C n
Reverse Shell n
Valid Protocol Tunnel
for VPN n
¨¾¤õÀ𥲶·¨¾Å@¤º©¹¥~¬y¶q¡C 3.
Type III Tunnel ¾Þ±±ªÌ¹ï¤º³¡ºô¸ô°e«ü¥O«Ê¥]¡A¨Ã¥H¶¡±µ¤èªk±µ¦¬¦^À³°T®§¡C 4.
Type IV Tunnel ¾Þ±±ªÌ±N«ü¥O¸m©ó¥~³¡¤½²³ºô¸ô¡A¨Ò¦p¸g´x±±¤§¤J¤fºô¯¸ªººô¶¡C¨ü¾Þ±±ªÌ¦A±N¦^À³¸m©ó¥~³¡´£¨Ñ¤W¸üÀÉ®× ftp ¦øªA¾¹¡C 5.
¯S®íªº Command Tunnel »P Response Tunnel 5. Command Tunnel 1. ¤º°e E-mail ¤º²[·tÂëü¥O (with Terminal
Invisible Text string) 2. ¤º°e¯S®í¨ó©w·tÂëü¥O¡A¨Ò¦p ICMP unused option (echo request, echo reply, port unreachable, host
unreachable µ¥) 3. ¥~³¡¤J¤fºô¯¸ Web Page ·tÂëü¥O 4. ¤º³¡ºô¸ô¬y¶q·tÂëü¥O Response Tunne1.
¼v¹³·tÂæ^À³¸ê®Æ (Information Hiding) 2.
¥~°e E-mail ¤º²[·tÂëü¥O ¤Wz«ü¥O©Î¦^À³³q¹D³£¥i¸g¥[±K³B²z¡C ¥|¡B¨¾¿mµ¦²¤ n
¤@¯ë©Ê«OÅ@¡]general protection¡^ 1. vulnerable host ¸T¤î¥~¹ï¤º/¤º¹ï¥~³s½u¡C»P¦w¥þÀË´úµ{¦¡°t¦X (Vulnerability Scanner/Auditor)¡AY¤@ÀË´ú¦³¦w¥þ¯Ê³´¡A°¨¤W»P firewall policy service ³s½u¡A©Úµ´©Ò¦³¤º¥~³s½u¡C 2.
«áªùµ{¦¡°»´ú (backdoor detection) Active Detection
n
¥Î¥H°»´ú passive tunnel ªº¦s¦b Passive Detection
n
¥Î¥H°»´ú
active tunnel (reverse shell) ªº¦s¦b¡C n
°»´ú well known protocol port number¡A°O¿ý«D¦Xªk¨ó©w«Ê¥]¡B¨Ó·½¤Î¥Øªº¦ì§}¡C n
°»´ú«D Interactive protocol port number¡A°O¿ý«D Interactive ¦æ¬°«Ê¥]¡C[16,17] n
¥Î¤áºÝ«OÅ@±¹¬I¡]Client Protection¡^ 1.
Sendmail SMTP authentication ¦¹±¹¬I¥i¹w¨¾Ãþ¦ü Melissa ¡BLove-letter¡BNavidad µ¥«H¥ó³sÂ근ɪº«áªù§ðÀ»¡C¦ý¥²¶·Äµ§i¨Ï¥ÎªÌ¤£n°O¾Ð»{ÃÒ±K½X¡C 2.
Delay sent of Outgoing E-mail 3.
Security Policy Enforcement n
¥~¹ï¤º¡G©Úµ´©Ò¦³³s½u (Not established) n
¤º¹ï¥~¡G¥u¶}©ñ¤¹³\¨Ï¥ÎªA°Èªº port ¦ì§}¡A¨Ã¥H application proxy ¤è¦¡¡AÀˬd³s½u«Ê¥]¡A©Úµ´«D¥¿½T¨ó©w«Ê¥]ªº¶Ç»¼¡C¦ý¬°¤F©Úµ´¥H¯S©w¨ó©w§@¬°µêÀÀ±M½u©³¼h¨ó©wªº tunnel ³s½u¡A¥²¶·¥H²§±`¤ÀªR¾÷¨îºÊ±±¡C³o¤è±ªººÊ±±¤èªk©|«Ý¸Ñ¨M¡C¦]¬° tunnel «Ê¥]¥H¦Xªkªº¨ó©w¹ï¥~¡A·¾³qªº«Ê¥]¶q»PÀW²v¤]¯à±±¨î¦b¦X²z½d³ò¡]¥u¬O°§C¾Þ±±ªÌªº¦^À³³t²v¡^¡A¦]¦¹¤£©ö°»´ú¡C n
¦øªAºÝ«OÅ@±¹¬I ¡]Server Protection¡^ 1. all open files are monitored 2. «Ø¥ß¦øªA¾¹ÀÉ®×½]®ÖÀˬd°O¿ý (¦p tripwire) 3. Security Policy Enforcement: n
¥~¹ï¤º¡G¥u¶}©ñ¦øªA¾¹ªA°È port ¦ì§}¡]¦p E-mail smtp tcp port 25¡^¡A¥B¥H application proxy ¤è¦¡±µ¨ü³s½u¡A©Úµ´«D¥¿½T¨ó©w«Ê¥]¡]¦p udp port 53 ¥u¤¹³\ DNS packet¡A¥á±ó¨Ã°O¿ý¨ä¥L©Ò¦³«D DNS ¡B¤£¦Xªk«Ê¥]¡A±Ä¨ú³o¼Ëªº±¹¬I±N¥iÁ×§K¥D°Ê°T®§«áªù¸g¥Ñ port 53 ¶Ç»¼¤Ï¦V shell «Ê¥]¡C¡^ n
¤º¹ï¥~¡G©Úµ´©Ò¦³³s½u (Not established)¡C |