目前,国内外很多厂商推出了Linux系统中的终端检测响应(Endpoint Detection and Response,EDR)系统,为云平台、物联网、大数据计算等基础设施提供全面的安全检测和防护服务。但是,针对EDR文件防护功能的绕过攻击能够帮助恶意行为规避监...目前,国内外很多厂商推出了Linux系统中的终端检测响应(Endpoint Detection and Response,EDR)系统,为云平台、物联网、大数据计算等基础设施提供全面的安全检测和防护服务。但是,针对EDR文件防护功能的绕过攻击能够帮助恶意行为规避监控,造成严重的系统和数据安全风险。针对开源和商业闭源的Linux EDR系统,首先,阐述了文件防护功能的底层实现机制,对其核心技术原理进行了分析;其次,重点梳理了4种现有公开的文件防护绕过技术,提出了3种尚未公开的绕过技术,并且总结提炼为3种攻击类型;再次,基于上述绕过技术编写了验证工具,通过测试证明了这些技术方法对于部分Linux EDR系统的文件防护绕过能力;最后,给出了相应的安全防护建议。展开更多
With the development of computer network, network security has become a very Important problem that must be solved by us. A distributed and layered skeleton has been presented, which can be deployed over all the count...With the development of computer network, network security has become a very Important problem that must be solved by us. A distributed and layered skeleton has been presented, which can be deployed over all the country easily. The monitor and management system can recognize the illegal information and automatically take action according the analysis result. As a sample, an illegal VPN(Virtual Private Network) monitor and management system have been implemented based on Linux, which can dynamically find illegal IPSec tunnels and then filter them.展开更多
从当前在欧美盛行的"社会的技术形成(Social shaping of Technology SST)"的观点出发,以Linux在国内的发展为案例,指出对于Linux在国内发展的不理想现状并不是由于技术本身,而是由于四大社会和经济的瓶颈:即缺乏合理的市场定...从当前在欧美盛行的"社会的技术形成(Social shaping of Technology SST)"的观点出发,以Linux在国内的发展为案例,指出对于Linux在国内发展的不理想现状并不是由于技术本身,而是由于四大社会和经济的瓶颈:即缺乏合理的市场定位和商业模式、缺乏统一的行业标准、缺乏合理的相关教育机制、缺乏良好的Linux社区环境。由此引申出:要促进当代技术,特别是信息与通信技术的快速发展,一个与之相适宜的社会和经济环境是必不可少的。展开更多
文摘With the development of computer network, network security has become a very Important problem that must be solved by us. A distributed and layered skeleton has been presented, which can be deployed over all the country easily. The monitor and management system can recognize the illegal information and automatically take action according the analysis result. As a sample, an illegal VPN(Virtual Private Network) monitor and management system have been implemented based on Linux, which can dynamically find illegal IPSec tunnels and then filter them.
文摘从当前在欧美盛行的"社会的技术形成(Social shaping of Technology SST)"的观点出发,以Linux在国内的发展为案例,指出对于Linux在国内发展的不理想现状并不是由于技术本身,而是由于四大社会和经济的瓶颈:即缺乏合理的市场定位和商业模式、缺乏统一的行业标准、缺乏合理的相关教育机制、缺乏良好的Linux社区环境。由此引申出:要促进当代技术,特别是信息与通信技术的快速发展,一个与之相适宜的社会和经济环境是必不可少的。