Detecting Attacks on Devices · 检测对设备的攻击
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| indicator of compromise/ˈɪndɪkeɪtə ɒv ˈkɒmprəmaɪz/ | 入侵指标 | rù qīn zhǐ biāo |
| password spraying/ˈpæswɜːd ˈspreɪɪŋ/ | 密码喷洒 | mì mǎ pēn sǎ |
| credential stuffing/krɪˈdenʃl ˈstʌfɪŋ/ | 撞库 | zhuàng kù |
| endpoint detection and response/endˈpɔɪnt dɪˈtekʃn ænd rɪˈspɒns/ | 端点检测与响应 | duān diǎn jiǎn cè yǔ xiǎng yìng |
Indicators of compromise
- Logs reveal an indicator of compromise (IoC) 入侵指标 — evidence an adversary got in.
- Host-based IoCs: unexpected processes or changed settings.
- File-based IoCs: a file whose hash matches known malware.
入侵指标
- 日志揭示入侵指标(indicator of compromise)——对手进入的证据。
- 基于主机的IoC:意外的进程或被更改的设置。
- 基于文件的IoC:散列值匹配已知恶意软件的文件。
Reading auth logs
- Many wrong passwords for one user = a guessing attack.
- Many users failing from one IP = password spraying 密码喷洒.
- A burst of default credentials = credential stuffing 撞库.
读取身份验证日志
- 一个用户的许多错误密码=猜测攻击。
- 许多用户从一个IP失败=密码喷洒(password spraying)。
- 一连串默认凭据=撞库(credential stuffing)。
Read the log: which password attack? · 读取日志:哪种密码攻击?
One user + many wrong passwords = guessing; many users + one IP = spraying; default credentials = stuffing. · 一个用户 + 多次错误密码 = 猜测;多个用户 + 一个IP = 喷洒;默认凭据 = 填充。
Evidence in a log that an adversary has compromised a device is an... · 日志中显示对手已攻破设备的证据是……
An IoC is an indicator of compromise. · IoC 即入侵指标。
Many different users failing to log in from ONE IP address suggests... · 从同一个IP地址登录失败的大量不同用户表明……
One IP, many users = password spraying. · 一个IP,多个用户 = 密码喷洒。
A powerful third-party device-detection service is called ____ (endpoint detection and response). · 一种强大的第三方设备检测服务称为 ____(端点检测与响应)。
EDR is powerful but expensive. · EDR 功能强大但价格昂贵。
Which are kinds of indicators of compromise? (Choose all) · 哪些是入侵指标的类别?(多选)
There is no weather-based IoC. · 不存在基于天气的IoC。
Choosing detection
- Signature-based is lighter — better for weak devices.
- An endpoint detection and response (EDR) 端点检测与响应 service is powerful but costly.
- Some attacks cannot be detected on the device at all.
选择检测方法
- 基于特征更轻——更适合弱设备。
- 端点检测与响应(endpoint detection and response)服务强大但昂贵。
- 有些攻击根本无法在设备上被检测到。
Offline password attacks cannot be detected. The adversary already stole the hash database and is cracking it on their own computer, far from your logs. This is a favourite exam "gotcha" — the only defense is strong, salted hashing.
离线密码攻击无法被检测到。对手已经偷走了散列数据库,正在他们自己的计算机上破解它,远离你的日志。这是考试常见的"陷阱"——唯一的防御是强的、加盐的散列。
Offline password attacks generally cannot be detected on your systems. · 离线密码攻击通常无法在你的系统上被检测到。
The cracking happens on the adversary's own machine. · 破解发生在对手自己的机器上。
An auth log shows 50 failed logins for user admin in 30 seconds, all from one IP. That pattern — one account, many wrong passwords, fast — is the signature of an online password-guessing attack that can be blocked with a lockout policy.
一份身份验证日志显示用户 admin 在30秒内有50次失败登录,全部来自一个IP。那个模式——一个账户、许多错误密码、快速——是可以用锁定策略阻止的在线密码猜测攻击的特征。
Device attacks leave an IoC in logs (host-based, file-based, behaviour-based). Auth logs distinguish guessing (one user), spraying (many users, one IP), and stuffing (default credentials). Pick detection by device power (EDR is powerful but costly). Offline attacks cannot be detected.
设备攻击在日志中留下IoC(基于主机、文件、行为)。身份验证日志区分猜测(一个用户)、喷洒(许多用户,一个IP)和撞库(默认凭据)。按设备性能选择检测(EDR强大但昂贵)。离线攻击无法被检测到。