论文部分内容阅读
本文着眼于国外发生的电力企业信息安全事件,剖析了攻击过程,给出了防御措施。本文对伊朗震网病毒样本采用逆向分析的方法,逐步揭示了震网病毒的一系列攻击行为;对于乌克兰大规模停电事件中的病毒,根据相关资料的叙述,还原了病毒的攻击方法。最后,总结了这两起事件的一些特点,给出了防御的建议。本文最大的特色在于不单纯的叙述病毒采用的技术,而是与Windows系统相关的原理结合起来,力求不仅说清病毒的行为,更要说清病毒行为背后深层次的原理,使读者能一目了然。
This paper focuses on information security incidents that occur in foreign power companies, analyzes the attack process, and gives defensive measures. In this paper, a reverse analysis method was used for the virus samples of the Iranian earthquake network to gradually reveal a series of attacks of the earthquake-hit virus. For the virus in the Ukraine blackout, the attack method of the virus was restored according to the narration of the relevant data. Finally, summarizes some of the characteristics of these two incidents, given the defensive recommendations. The biggest feature of this article is not purely narrative virus technology used, but the principle associated with the Windows system, trying not only to clarify the behavior of the virus, but also to clarify the underlying principles behind the virus behavior, so that readers can be clear at a glance.