摘要
针对特定用户和系统的高级持续性威胁(简称APT攻击)愈演愈烈,给广大用户造成了极大的安全威胁。APT攻击所使用的攻击手法多种多样,其中危害最大的技术手段是攻击者对各种漏洞的利用。本次研究针对攻击者对各种漏洞利用的问题,提出了漏洞挖掘技术在APT攻击中的应用。本文详细描述了补丁对比漏洞挖掘技术的原理、案例以及在APT攻击中的应用和危害并提出了相应的加固建议。
It is the seriousness of APT attack that poses a great threat to the network security of mass use rs. The ways that APT attacks are various, while the most dangerous one is the technology of taking advantag e of bugs. This research brings forward how vulnerability detection is applied in dealing with APT Attacks. It elaborates vulnerability mining technology principle of comparative patch and examples and the harm and proposes suggestion accordingly.
出处
《电子测试》
2015年第12期32-34,共3页
Electronic Test
基金
云南电网年度科技基金资助项目"高级持续性威胁检测研究"(K-YN2013-148)
关键词
APT攻击
Oday漏洞
补丁对比
漏洞挖掘
社会工程学
Advanced Persistent Threat
Zero day Vulnerability
Patches Comparison
Vulnerability detection
Social Engineering