°ä²¼¹¦·ò£º2020-04-14
×÷ÕߣºÎâÓ° Áõ»Ô»Ô

2020ÄêÒÁʼ£¬Ò»ÖÖÃûΪ“COVID-19”µÄÐÂÐ͹Ú×´²¡¶¾ÔÚÈ«ÇòËÁŰ£¬¶øÔÚÍøÂçÊÀ½çÀ²¡¶¾Ò²Ã»ÏÐ×Å¡£½èÖúÓÚÕæÊµÊÀ½çÀïµÄ²¡¶¾ËÁŰ£¬ÍøÂç¹¥»÷Õ߳ûú´«²¼¶ñÒâÈí¼þ£¬´óÅúÓû§“²ÒÔâϰȾ”¡£ÕâÅú±»Ï°È¾µÄÓû§£¬½èÖúÓÚ“ºÚÓòÃû”µÄÔ®ÊÖ£¬³ÖÐøÔÚÍøÂç¿Õ¼äÄÚ¶Ô²¡¶¾“ËÁÒâ´«²¼”£¬ÄÇô“ºÚÓòÃû”ÊÇʲô£¬¶ÔÎÒÃÇÓÐʲôӰÏ죬±¾Æª½«Îª¸÷λÖðһ·À´¡£
ºÚÓòÃûÊÇʲô£¿
“ºÚÓòÃû”ͨ³£Ö¸µÄÊÇÈçÏÂÁ½ÖÖÀàÐ͵ÄÓòÃû£º
ÕâÀïÎÒÃÇËùÖ¸µÄ“ºÚÓòÃû”ÌØÖ¸µÚ¶þÀ࣬¼´¶ñÒâÈí¼þ£¨ÈçÍڿ󲡶¾¡¢½©Ê¬ÍøÂç¡¢ÀÕË÷²¡¶¾µÈ£©Í¨¹ý“ºÚÓòÃû”ʵÏÖ±»½ÚÔìÖÕ¶ËÓë½ÚÔì·þÎñÆ÷Ö®¼äά³ÖͨѶµÄÓòÃû¡£“ºÚÓòÃû”»¹¿É·ÖΪ¾²Ì¬ºÍ¶¯Ì¬Á½Àà¡£
¾²Ì¬ºÚÓòÃû³£ÓÃÓÚÍÚ¿ó¡¢ÀÕË÷²¡¶¾µÈÍøÂç¹¥»÷ÐÐΪ¡£
¶¯Ì¬ºÚÓòÃû³£ÓÃÓÚ½©Ê¬ÍøÂç»òC&CµÈÍøÂç¹¥»÷ÐÐΪ£¬Ê±Ê±Ê¹ÓÃDGAËã·¨(Domain Generate Algorithm)ÌìÉú¡£
¶Ô¶ñÒⷨʽ¶øÑÔ£¬¹Ì¶¨µÄ¶ñÒâIPµØÖ·¼«Ò×±»°²È«É豸¼ì²â²¢×è¶Ï£¬ÎÞ·¨ÊµÏÖÒñ±ÎÓëÓÐЧµØ½ÚÔì¡£ËùÒÔ£¬½©Ê¬ÍøÂçÓëC&C¹¥»÷ÔÚÉèÖöñÒâÈí¼þʱ¼«Á¦Ô¤·ÀʹÓù̶¨IPµØÖ·×÷Ϊ±»¿ØÖÕ¶ËÓë·þÎñÆ÷¶ËµÄÏνӡ£ÔÚ·¨Ê½ÖÐʱʱʹÓÃDGAËã·¨À´ÌìÉúËæ»úÓòÃû(ºÚÓòÃû)£¬ÒÔÈÆ¹ý³£¼ûµÄ°²È«·À»¤¼¿Á©£¬ÊµÏÖ¶Ô±»½ÚÔì¶Ë³ÖÐø¡¢ÓÐЧµÄ½ÚÔì¡£
ͨ¹ýDGAËã·¨ÌìÉúµÄºÚÓòÃûÔÚ»¥ÁªÍøÖÐʱʱÎÞ·¨½Ó¼û£¬ÓÉÓÚ¶ñÒâ¹¥»÷ÕßÔÚ¶ñÒâÈí¼þÔËÐÐʱ£¬²Å¶ÔÓòÃû½øÐÐ×¢²á£¬ËùÒÔÎÒÃÇ·¢ÏֵĺÚÓòÃûʱʱÎÞ·¨Ö±½Ó½øÐнӼû¡£
ºÚÓòÃûÓëͨ³£ÓòÃûµÄÇø±ðÓÐÄÄЩ£¿
ÏÖÓÃÏÖ×¢²á
ÓÉÓÚ×¢²áÓòÃû±ØÒªÓöȣ¬¹Ê¶ñÒâ¹¥»÷ÕßʱʱÔÚºÚÓòÃû´òËãÉÏÏßǰ²Å×¢²áÓòÃû£¬ÔÚ´ËʱºÚÓòÃû²Å¿ÉÔÚ»¥ÁªÍø»·¾³ÖнӼû¡£
ʹÓù¦·ò¶Ì
ÓÉÓÚÏÖÓа²È«·À»¤´ëÊ©¶ÔÍøÂçÁ÷Á¿ÖеÄÐÐΪ½øÐмì²â£¬·¢ÏÖ¿ÉÒÉÒªÇóºó½«ÉÏ´«Ôƶ˰²È«ÖÎÀíÖÐÐÄ¡£ËùÒÔÔÚºÚÓòÃûÉúЧʹÓúó£¬ÏÖÓмì²â¡¢·À»¤É豸¿É¼±¾ç¼ø±ð²¢¹ã²¥·À»¤¹æ¶¨ÊµÏÖÓÐЧ×è¶Ï£¬ÎªÁËÔ¤·À³¤¹¦·ò¶¯Ì¬ÓòÃûµÄ¶³ö£¬¶ñÒâ¹¥»÷ʹÓÃÒ»¸öÌØ¶¨ºÚÓòÃûµÄ¹¦·ò¶¼²»³¤£¬Í¨¹ýÔÚ1-7Ìì×óÓÒ¡£
ͳһ¿î¶ñÒâÈí¼þÓ²±àÂë¶à¸öºÚÓòÃû
ͳһ¿î¶ñÒâÈí¼þÔÚÔì×÷ʱ¿ÉÄÜ»áÄÚÖöà¸öºÚÓòÃû£¬ÒÔÌá¸ß³É¹¦Ïνӽ©Ê¬ÍøÂçµÄ¼¸ÂÊ¡£
ºÚÓòÃûµÄ³£¼ûͨѶ¹ý³ÌÊÇÔõôµÄ£¿
µ±Ï»¥ÁªÍø»·¾³ÖУ¬Ê±Ê±Ê¹ÓúÚÓòÃûÀ´ÊµÏÖ°µ²Ø½©Ê¬ÍøÂçÖÐÖ÷¿Ø¶ËÕæÊµIP£¬ÒòÆäʹÓÃÓòÃûµÄ¶¯Ì¬ÐÔ£¬¿ÉÈÆ¹ý»ùÓÚÌØµã¼ì²âµÄ°²È«·À»¤É豸·À»¤Ö°ÄÜ¡£
ÒÔ¶¯Ì¬ºÚÓòÃûΪÀý£¬×¢Ã÷ºÚÓòÃûµÄʹÓó¡¾°¼°Ê¹Óùý³Ì¡£

1¡¢Ï°È¾²¢ÌìÉúËæ»úÓòÃû
¶ñÒâÈËԱͨ¹ý¶ñÒâÓʼþ¡¢ÍøÂçÈëÇֵȼ¿Á©£¬ÏòÓû§ÍÆËã»úͶ·Å¶ñÒⲡ¶¾£¬¿ªÊÍC&C±»¿Ø¶ËÈí¼þ¡£±»¿Ø¶ËÈí¼þ²¿Êðºó£¬Æ¾¾ÝDGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû¡£
2¡¢×¢²áËæ»úÓòÃû£¬±»¿Ø¶Ë·´ÏòÏνÓÖ÷¿Ø¶Ë
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿ÃźÚÓòÃû£¬ÔÚ¶ñÒⷨʽϰȾÖն˺óʹÓÃDGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»¹áDNS·þÎñÆ÷ÒªÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁ³É¹¦»ñÈ¡IPµØÖ·ºó¼´½øÐÐC&C»á»°Ïνӣ¬½øÐз´ÏòÏνӡ£
¶ñÒâ¹¥»÷Õß¿ÉÌáǰע²á²¿ÃźÚÓòÃû£¬ÔÚ¶ñÒⷨʽϰȾÖն˺óʹÓÃDGAËã·¨ÌìÉúÎ±Ëæ»úÓòÃû³Ø£¬Ê¹ÓóØÖÐÓòÃûÖðÒ»¹áDNS·þÎñÆ÷ÒªÇó¶ÔÓ¦µÄIPµØÖ·£¬Ö±ÖÁ³É¹¦»ñÈ¡IPµØÖ·ºó¼´½øÐÐC&C»á»°Ïνӣ¬½øÐз´ÏòÏνӡ£
¶ÔÓÚº¹ÇàÉÏ·¢ÏֵĺÚÓòÃûʾÀý£º
ºÚÓòÃûµÄ¼ø±ð
һЩµÚÈý·½Íþвµý±¨¹«¹²Æ½Ì¨Äܹ»½øÐкÚÓòÃûµÄÐÖúÈ·ÈÏ£¨ÒÔϽØÍ¼ÒÔ΢²½ÔÚÏßÍþвµý±¨ÉçÇøÎªÀý£©£º


ͬʱ½èÖúÓÚÎÒ˾RG-BDS´óÊý¾Ý°²È«Æ½Ì¨¡¢RG-BDS-TSPÁ÷Á¿Ì½ÕëÒÔ¼°RG-APT¸ß¼¶Íþв¼ì²âϵͳ£¬¾ùÄܵÚһʱ¿Ì·¢ÏÖºÚÓòÃûµÄ½âÎöÓë½Ó¼û£¬²¢½øÐи澯¡£
RG-BDS´óÊý¾Ý°²È«Æ½Ì¨Í³Ò»¸æ¾¯£º

RG-BDS-TSPÁ÷Á¿Ì½Õë¸æ¾¯£º

RG-APT¸ß¼¶Íþв¼ì²âϵͳ¸æ¾¯£º

ºÚÓòÃû·À»¤³£¼û³¡¾°
ij¿Í»§´æÔÚ±»¶ñÒâÈí¼þϰȾµÄÖ÷»ú£¬Ïò±íÍø·¢ËÍÒì³£µÄºÚÓòÃûÏνÓÒªÇó£¬É϶ËÔËÓªÉÌ¡¢Éϼ¶µ¥ÔªµÈ»ú¹¹·¢ÏÖ¿Í»§´¦´æÔÚµÄÒì³£Á÷Á¿£¬Í¬²½¿Í»§´¦ÖÃÒªÇó¡£
³ýÁËʵʱ¶ÔÔâ·ê¶ñÒâÈí¼þϰȾµÄÖ÷»ú½øÐв¡¶¾¶Ï¸ùµÈ°²È«¼Ó¹Ì´ëÊ©±í£¬¿ÉʹÓÃGA»Æ½ð¼×È«ÐÂNGFWµÄDNS¹ýÂËÖ°ÄÜ£¨»òDNSÏ´åªÖ°ÄÜ£©£¬½øÒ»²½½ÚÔìºÚÓòÃûµÄÒì³£½Ó¼û£¬½«ÓйطçÏÕ½µÖÁ×îÓס£
³£¼ûÍØÆËÈçÏ£º

ǰÖÃǰÌá×¢Ã÷£º
µÀÀí×¢Ã÷
GA»Æ½ð¼×È«ÐÂNGFWµÄDNS¹ýÂËÖ°ÄÜ£¬¹ËÃû˼Ò壬·À»ðǽÔÚÄÚ²¿Öж¾Ö÷»ú½Ó¼ûºÚÓòÃûʱµÄDNS½»»¥½×¶ÎÆð½ÚÔìÏÞ¶È×÷Óá£
ÔÚ·À»ðǽ½øÐÐDNS¹ýÂ˹ý³ÌÖУº
ÒÔ·À»ðǽ¶Ôij¸öÓòÃû£¨Èç¹ûΪÓòÃûA£©½øÐÐDNS¹ýÂ˵Ť×÷Á÷³ÌµÄÃèÊö£¬¿ÉÓÃÏÂͼ¼òÊö£º

¾ßÌåÅäÖÃ
1¡¢Óû§¸ù»ùÉÏÍøÅäÖãº
ƾ¾ÝÏÖʵÐèÒª£¬½«·À»ðǽ²¿Êðµ½ÍøÂçÖУ¬ÊµÏÖ¸ù»ùÉÏÍøÐèÒª£»
2¡¢·À»ðǽÊÚȨע²áÓ뼤»î£º
ÒÀÕÕ·À»ðǽÊÚȨע²áÁ÷³ÌʵÏÖ×¢²áÓ뼤»î£¬¼¤»îʵÏÖºóÈ·±£µ±Ç°É豸ÈÔ´¦ÔÚÊÚȨÓÐЧÆÚÄÚ£¬ÈçÏÂͼËùʾ£º

3¡¢ÅäÖÃDNS¹ýÂËÄ£°å£º
ͨ¹ýWeb ½øÈë ¶ÔÏóÅäÖÃ--DNS¹ýÂËÄ£°å£¬É豸ĬÈÏÒÑÓÐDNSÄ£°å“default”£¬¿Éµã»÷ÓÒÉϽǵÄÔö³¤°´Å¥£¬ÐÂÔöÒ»¸öÄ£°å£¬Èç±¾ÀýÔö³¤µÄÄ£°å“dns_filter”£º


ÅäÖÃÑ¡Ïî×¢Ã÷£º
×è¶Ï·¢Ë͵½botnet C&CµÄDNSÒªÇ󣺷À»ðǽÉ豸ÔÚµ¼ÈëÊÚȨºó£¬»á½«Ôƶ˵ÄBotnetµØÖ·¿â¡¢C&CµØÖ·¿âÏÂÔØµ½±¾µØ£»¿ªÆô´ËÖ°Äܺ󣬵±DNSÒªÇóµÄÓòÃûÔÚBotnetµØÖ·¿â»òC&C¿âÖУ¬DNSÒªÇó½«Ö±½Ó×è¶Ï£¬²»»á½øÐкóÐø´¦Öã»
»ùÓÚ°²È«ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£º½«DNSÒªÇóµÄÓòÃû·¢Ë͵½Ôƶˣ¬Ôƶ˻᷵»ØÒªÇóµÄÓòÃûµÄ·ÖÀàÐÅÏ¢£¬Óû§¿É»ùÓÚ·ÖÀàÁ˾֣¬¶Ô·ÖÆçµÄ·ÖÀàÖ´ÐÐ·ÖÆçµÄ×÷Ϊ£»
¾²Ì¬Óò¹ýÂËÆ÷-Óò¹ýÂË£º¿ÉÊÖ¹¤½ç˵һ¸öÓòÃûÁÐ±í£¬±¨´ðÖ¸¶¨¶ÔÌØ¶¨ÓòÃûµÄ´¦ÖÃ×÷Ϊ£»
¾²Ì¬Óò¹ýÂËÆ÷-±í²¿IP×è¶ÏÇåµ¥£ºÓëÓò¹ýÂËÀàËÆ£¬¿ÉÊÖ¹¤½ç˵һ×éIPÁÐ±í£¬µ±ÓòÃû½âÎö³öµÄµØÖ·ÔڸõØÖ·ÁбíÁìÓòÄÚ£¬±¨´ðÖ¸¶¨´¦ÖÃ×÷Ϊ£»
¿ÉÑ¡Ïî-µ±²úÉúÍøÖ··ÖÀàÃýÎóʱÔÊÐíDNSÒªÇ󣺿ªÆô´ËÖ°Äܺ󣬵±ÒªÇóµÄÓòÃû·¢Ë͸øÔƶˣ¬ÔƶËÔÝδ¶ÔÆä½øÐзÖÀ࣬»òÕß·À»ðǽÓëÔÆ¶ËÎÞ·¨Õý³£Í¨Ñ¶Ê±£¬Óû§µÄDNS½âÎö±¨ÎÄ¿ÉÕý³£×ª·¢£»¹Ø¹Ø´ËÖ°Äܺó£¬Èç³öÏÖÓòÃûûÓзÖÀ࣬»òÔÆ¶ËÏνÓÒ쳣ʱ£¬DNS±¨ÎĽ«²»½øÐÐת·¢¡£
¿ÉÑ¡Ïî-¼Í¼ËùÓÐDNS²éÎʼ°ÏàÓ¦ÈÕÖ¾£º¿ªÆô´ËÖ°Äܺ󣬿Éͬʱ¼Í¼DNSµÄÒªÇóÓë»Ø¸´ÄÚÈÝ¡£
ÍÆ¼ö±ØÐ뿪ÆôµÄÖ°ÄÜÑ¡Ï×è¶Ï·¢Ë͵½BotnetC&CµÄDNSÒªÇ󣬻ùÓÚ°²È«ÖÐÐÄ·ÖÀàµÄ¹ýÂËÆ÷£¨Îñ±ØÆ¾¾ÝÏÖʵ±ØÒª¶ÔÌØ¶¨·ÖÀàµÄ×÷Ϊ½øÐÐÅú¸ÄÓëÈ·ÈÏ£©£¬¿ÉÑ¡Ïî-µ±²úÉúÍøÖ··ÖÀàÃýÎóʱÔÊÐíDNSÒªÇó¡£
4¡¢ÅäÖÃSSLÉî¶È¼ì²âÄ£°å
ÔÚ·À»ðǽ6.0Èí¼þ°æ±¾ÉÏ£¬ÎªÁËÌá¸ß°²È«ÐÔ£¬ÔÚ°²È«Õ½Êõ¿ªÆôUTMÖ°ÄÜʱ£¬ÒªÇó±ØÐëÑ¡ÔñSSL/SSHÉî¶È¼ì²âÄ£°å¡£É豸ĬÈÏÒÑÄÚÖÃSSLÉî¶È¼ì²âÄ£°å£¬µ«Ä¬ÈÏÄ£°åÖгÇÊжÔSSL¡¢SSHºÍ̸½øÐдúÀí¼ì²â£¬ÔÚÏÖʵÀûÓÃÖпÉÄܵ¼Ö³öÏÖÒµÎñÒì³£¡£Òò¶øÈçÏÖʵ³¡¾°ÖÐûÓÐSSL¼ÓÃÜÄÚÈݵĽâÃÜÐèÒª£¬±ØÒª³ÁÐÂÉèÖÃÒ»¸ö²»¼ÓÃܼì²âµÄSSLÄ£°å¡£
ÅäÖò½Ö裺ͨ¹ýWEB·½Ê½½øÈë ¶ÔÏóÅäÖÃ--SSL/SSHÉî¶È¼ì²âÄ£°å£¬µã»÷ÓÒÉϽÇн¨°´Å¥£¬´´½¨Ò»¸öеÄSSL/SSHÉî¶È¼ì²âÄ£°å£¬ÈçÏÂͼн¨µÄSSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

н¨µÄÄ£°åÖУ¬½«“²é³ËùÓж˿ڔÒÔ¼°“HTTPS”µÈºÍ̸ºóµÄ¿ªÆôÑ¡ÏîÈ«Êý¹Ø¹Ø¼´¿É¡£
5¡¢°²È«Õ½ÊõÖÐŲÓÃDNS¹ýÂËÄ£°å
ͨ¹ýWeb½çÃæ£¬ÔÚÕ½ÊõÉèÖÃ--IPv4Õ½ÊõÖУ¬¶ÔÏÖÓÐÕ½Êõ½øÐе÷Õû¡£ÈçÏÂͼËùʾ£¬ÔÚ¶ÔÉÏÍøÉÏÍøµÄ“°²È«ÅäÖÔ½øÐÐÉèÖúó£¬Å²ÓÃDNS¹ýÂËÄ£°å“dns_filter”ÒÔ¼°SSL/SSHÉî¶È¼ì²âÄ£°å“no_ssl”£º

³ÉЧ¼ìÑé
ͨ¹ý·À»ðǽÏÂPC³¢ÊÔ½âÎöºÚÓòÃû£¬²é¿´·À»ðǽ×è¶Ï³ÉЧ£¬ÔÚ·À»ðǽÉÏͨ¹ý²é¿´ÈÕÖ¾ÒÔ¼°ÄÚ±íÍø½Ó¿Ú×¥°ü·½Ê½È·ÈϳÉЧ¡£
1¡¢±¾°¸ÀýÖÐʹÓÓv.y6h.net” “lpp.ackng.com” “loseyourip.com” 3¸öºÚÓòÃû½øÐвâÊÔ£¬£¨ÒÔÏÂÊÇʹÓÃVirusTotal¹¤¾ßÑéÖ¤Ëù²âÊÔµÄ3¸öÓòÃû·çÏÕÐÔ½ØÍ¼£¬È·ÈÏÊôÓڸ߷çÏÕÓòÃû£©£º



2¡¢ÎªÈ·±£³ÉЧ£¬Ç¿Ôì²âÊÔPCʹÓó£¼ûDNS·þÎñÆ÷£¨°¸ÀýÖÐʹÓÃ114.114.114.114 DNS·þÎñÆ÷£©¶Ô·çÏÕÓòÃû½øÐнâÎö



²âÊÔ×¢Ã÷£º
a)²ÎÊý“-qt=A”ΪnslookupµÄ²¹³ä²ÎÊý£¬ÒâΪǿÔì½øÐÐIPv4µÄÓòÃû½âÎö£»
b)ºÅÁî×îºóµÄµØÖ·£¬ÒâΪǿÔìʹÓøõØÖ·×÷ΪDNS·þÎñÆ÷£»
c)ÿ´Î²âÊÔǰ£¬¾ùʹÓúÅÁî“ipconfig /flushdns”Çå¿ÕDNS»º´æ£¬Ô¤·À»º´æÓ°Ïì²âÊÔÁ˾֡£
3¡¢·À»ðǽ¶Ë×è¶Ï³ÉЧÈÕÖ¾£º



·À»ðǽÈÕÖ¾×¢Ã÷£º
a)×÷ΪΪ“block”ÇÒÐÂÎÅ×Ö¶ÎÏÔʾ“Domain belongs to a denied category in policy”£¬Åú×¢¸ÃDNS±¨ÎÄÊÇͨ¹ýDNS·ÖÀ༿Á©±»×è¶Ï£»
b) ×÷ΪΪ“block”ÇÒÐÂÎÅ×Ö¶ÎÏÔʾ“Domain was blocked by dns botnet C&C”Åú×¢¸ÃDNS±¨ÎÄÊÇÆ¥Åäµ½±¾µØµÄBotnet C&C¿â±»×è¶Ï£»
4¡¢·À»ðǽÄÚ±íÍø±¨ÎÄÇé¿ö£º
£¨½ØÍ¼×ó²àΪ·À»ðǽÄÚÍø¿Ú±¨ÎÄ£¬ÓÒ²àÓзÀ»ðǽ±íÍø¿Ú±¨ÎÄ£©


ÆäËûµ±¿àÖÔÏî
