什么是抵赖攻击?

数字化转型1000问-数字化转型网szhzxw.cn

抵赖攻击是W通信双方在进行网络交换时,一方面否认自己的行为,尤其是在被发现并收到指责时,通过伪造信息嫁接给其他组织或删除关键证据导致另一方(受害者)无法维护自己权益的攻击行为。

    某教育单位网站官网图片被恶意篡改,安全运维人员通过还原问题时间段客户访问网站记录,分析攻击者攻击过程的抵赖操作,具体如下:

    1、身份隐匿:通过多次代理实现攻击者身份的隐匿。

    2、操作隐匿:攻击者进入服务器,通过指令删除原图片文件,并且上传了具有恶意代码的图片文件,并删除操作日志。

    3、工具隐匿:最后删除webshell文件。

英文翻译:

Denial attack is an attack in which the two parties of W communication deny their own behavior during network exchange, especially when they are discovered and criticized, and the other party (the victim) is unable to defend its own rights and interests by forging information and transferring it to other organizations or deleting key evidence.
The picture of the official website of an educational institution is maliciously tampered with. Security operation and maintenance personnel restore the records of customers’ visits to the website during the problem period and analyze the deniability operation of the attacker during the attack process, as follows:
1, identity hiding: through multiple agents to achieve the identity of the attacker hiding.

  1. Operation hiding: The attacker enters the server, deletes the original image file through instructions, uploads the image file with malicious code, and deletes the operation log.
    3, tool hiding: Finally delete the webshell file.

本文由数字化转型网(www.szhzxw.cn)转载而成,来源于网络;编辑/翻译:数字化转型网默然。

免责声明: 本网站(http://www.szhzxw.cn/)内容主要来自原创、合作媒体供稿和第三方投稿,凡在本网站出现的信息,均仅供参考。本网站将尽力确保所提供信息的准确性及可靠性,但不保证有关资料的准确性及可靠性,读者在使用前请进一步核实,并对任何自主决定的行为负责。本网站对有关资料所引致的错误、不确或遗漏,概不负任何法律责任。 本网站刊载的所有内容(包括但不仅限文字、图片、LOGO、音频、视频、软件、程序等) 版权归原作者所有。任何单位或个人认为本网站中的内容可能涉嫌侵犯其知识产权或存在不实内容时,请及时通知本站,予以删除。https://www.szhzxw.cn/48168.html
联系我们

联系我们

17717556551

邮箱: editor@cxounion.org

关注微信
微信扫一扫关注我们

微信扫一扫关注我们

关注微博
返回顶部