-- ·|­û / µù¥U -- ¡@
¡@±b¸¹¡G
¡@±K½X¡G
¡@ | µù¥U | §Ñ°O±K½X
3/26 ·s®Ñ¨ì¡I 3/19 ·s®Ñ¨ì¡I 3/14 ·s®Ñ¨ì¡I 12/12 ·s®Ñ¨ì¡I
ÁʮѬyµ{¡EQ & A¡E¯¸°È¯d¨¥ª©¡E«ÈªA«H½c
¢x 3ds Max¢x Maya¢x Rhino¢x After Effects¢x SketchUp¢x ZBrush¢x Painter¢x Unity¢x
¢x PhotoShop¢x AutoCad¢x MasterCam¢x SolidWorks¢x Creo¢x UG¢x Revit¢x Nuke¢x
¢x C#¢x C¢x C++¢x Java¢x ¹CÀ¸µ{¦¡¢x Linux¢x ´O¤J¦¡¢x PLC¢x FPGA¢x Matlab¢x
¢x Àb«È¢x ¸ê®Æ®w¢x ·j¯Á¤ÞÀº¢x ¼v¹³³B²z¢x Fluent¢x VR+AR¢x ANSYS¢x ²`«×¾Ç²ß¢x
¢x ³æ´¹¤ù¢x AVR¢x OpenGL¢x Arduino¢x Raspberry Pi¢x ¹q¸ô³]­p¢x Cadence¢x Protel¢x
¢x Hadoop¢x Python¢x Stm32¢x Cortex¢x Labview¢x ¤â¾÷µ{¦¡¢x Android¢x iPhone¢x
¥i¬d®Ñ¦W,§@ªÌ,ISBN,3dwoo®Ñ¸¹
¸Ô²Ó®ÑÄy¤ÀÃþ

¶Â«È¤j°lÂÜ¡Gºôµ¸¨úÃҮ֤߭ì²z»P¹ê½î

( ²Åé ¦r)
§@ªÌ¡G±Z§µ±á,³°¹D§» µ¥Ãþ§O¡G1. -> ¦w¥þ -> ºô¸ô¦w¥þ -> Àb«È§ðÀ»»P¤J«I
ĶªÌ¡G
¥Xª©ªÀ¡G¹q¤l¤u·~¥Xª©ªÀ¶Â«È¤j°lÂÜ¡Gºôµ¸¨úÃҮ֤߭ì²z»P¹ê½î 3dWoo®Ñ¸¹¡G 40477
¸ß°Ý®ÑÄy½Ð»¡¥X¦¹®Ñ¸¹¡I

¡i¯Ê®Ñ¡j
¡i¤£±µ¨ü­qÁÊ¡j

¥Xª©¤é¡G1/1/2015
­¶¼Æ¡G504
¥úºÐ¼Æ¡G0
¯¸ªø±ÀÂË¡G
¦L¨ê¡G¶Â¥Õ¦L¨ê»y¨t¡G ( ²Åé ª© )
¡i¤£±µ¨ü­qÁÊ¡j
ISBN¡G9787121245541
§@ªÌ§Ç¡@|¡@ĶªÌ§Ç¡@|¡@«e¨¥¡@|¡@¤º®e²¤¶¡@|¡@¥Ø¿ý¡@|¡@§Ç
(²Åé®Ñ¤W©Ò­z¤§¤U¸ü³sµ²¯Ó®É¶O¥\, ®¤¤£¾A¥Î¦b¥xÆW, ­YŪªÌ»Ý­n½Ð¦Û¦æ¹Á¸Õ, ®¤¤£«OÃÒ)
§@ªÌ§Ç¡G

ĶªÌ§Ç¡G

«e¨¥¡G

±ÀÂ˧Ç

·í¦w¥þ°é«e½úcnhawk§ä¨ì§Ú¡A§Æ±æ§Ú¬°³o¥»¥Ñ±Z§µ±á¦Ñ®v¤Î¤½¦w¨t²Î¤@½u±M®a¹Î¶¤Â½Ä¶ªº¨È°¨»¹5¬PºZ¾P®Ñ¼g¥÷±ÀÂ˪º®É­Ô¡A¤p¥Í¦ó¨ä´q®£¡Cºôµ¸¥Ç¸o¨úÃÒ©M¶Â«È°lÂÜ·¹·½¡A¤£¦ý¬O¡§¿ß®»¦Ñ¹«¡¨¯ëªº¤æ´¼¤æ¤O¡A§ó»Ý­n°»¬d¤H­û¼s³Õ²`«pªºª¾Ãѧ޳N¤ô¥­©Mªø®É¶¡ªº¸gÅç¿n²Ö¡C
¦b³o­Ó»â°ì¡A¤p¥Í¨I¾K¦h¦~¡A±q³Ì¶}©lºN¯Á¦p¦ó§Q¥ÎNetwork general ªºsniffer portable«KÄ⦡³]³Æ©èªñ¥Ø¼Ð§½°ìºô¡A¨ì§Q¥ÎºôÃö³]³Æ®Ç¸ô¤À¥ú/Ãè¹³ªö¶°¡B¤ÀªR­«­n¤ººôºôµ¸¬y¶q©M¨óij¡A¦A¨ì§Q¥Î¾÷¾¹¾Ç²ß¤èªk«õ±¸³B²z®ü¶q¤é§Ó©MªÀ¤uÃÒ¾Ú¡A§ó¿Ë¨­¹ê½î¹L¥ý¶i¤ì°¨©M»ø¤rºôµ¸ªº§ð¨¾¹ï§Ü¡K¡K10¦h¦~¤@¸ô¨«¨Ó¡A²`·Pºôµ¸¨úÃÒ°lÂÜ»â°ìªº¯EÃv´_Âø¡B¬ÛÃö§Þ³N¸ê®Æ·j¶°¾ã²zªºÁ}¨¯¡A§ó¬°¡§¦p¦óºc«Ø§¹³Æªººôµ¸¨úÃÒª¾ÃѧޯàÅé¨t¡H¦p¦ó±Nªø´Á¥H¨Ó¦b¦U­Ó¼h¦¸¹ê¬I¨úÃÒ/¹ï§Üªº¸gÅç±Ð°V¶i¦æ¨t²Î¤Æªº®Þ²z¡H¡¨³o­Ó¥¨¤jªº½ÒÃD¦Óªø´Áªº§x´bµÛ¡K¡Kª½¨ì§ÚŪ§¹³o¥»®Ñ¡C
±q¥»¦a¨úÃÒ¨ìºôµ¸°lÂÜ¡A»·¤£¶È¶È¬O±qºÏ½L¼Æ¾Ú«ì´_+¤º¦sdump¨ìºôµ¸¼Æ¾Ú¥]ºIÀò¤ÀªRªº¡§¤É¯Å¡¨¡A¦Ó¬O¹ê²{¤F±q¡§³æÂIÃÒ¾Úªö¶°¡¨¨ì¡§¥þ°ì¡B¦h¼h¦¸®ü¶q¼Æ¾ÚÃÒ¾ÚÃì«H®§ªº«õ±¸±À²z¡¨ªºÅDÅÜ¡C¨úÃÒªº¸Ë³Æ©M§Þ³N¦bµo®i¡A°»¬d¤H­ûªº«äºû©M²´¬É§ó­n§ïÅÜ¡C
®Ñ¤¤§â¡§ÃÒ¾Ú¡¨©w¸q¬°¡G¥ô¦ó¥iÆ[¹î¥B¥i°O¿ýªº¨Æ¥ó©ÎªÌ¬O¨Æ¥óªº¦]¯À¡A§Y¯à¥Î¨Ó¥¿½T²z¸Ñ¤@­Ó¤w³QÆ[¹î¨ìªº¨Æ¥óµo¥Í­ì¦]©M¥»½èªº¡A¥ô¦ó¥i¥H³QÆ[¹î¨ì¦}³Q°O¿ý¤U¨Óªº¬¡°Ê©Î²£¥Í¬¡°Êªº¤H¬°¦]¯À¡C±q§Úªº²z¸Ñ¬Ý¡A¥»®Ñ³ò¶ºôµ¸¨úÃÒ©M¶Â«È°lÂܳo­Ó¥DÃD¡A³q¹L²`¤J²L¥Xªº§Þ³NÁ`µ²©M¹ê¾Ô®×¨Ò¤ÀªR¡AÅn¬A¤F¡§Æ[¹î¡¨¡§°O¿ý¡¨©M¡§²z¸Ñ¡¨¤T­Ó®Ö¤ß­n¯À¡G
1¡D¦p¦ó¦¨¬°¤@¦Wºë³qµL½u/¦³½uºôµ¸³q«H©M¨óij¤ÀªRªº°»¬d­û¡H
°w¹ï¼s°ìºô¡B¶é°Ï¦³½uºô¡BµL½uºôµ¥¤£¦Pºôµ¸¥Ø¼Ð¡A¤F¸Ñºôµ¸¤¤¦UÃþ¨t²Îªº°t¸m¡B±µ¤f©M¥\¯à¡A±q¤£¦PÃþ«¬ªº±µ¤JÂI¡]¦p¡GµL½uAP¡B¥æ´«¾÷¡^©Î¤¤¶¡´C¤¶¡]¦p¥úÅÖ¡B¥H¤Óºô½u¡^¤Á¤Jºôµ¸¡A¥D°Ê/³Q°Ê¦aºIÀò¦U¯Å¦UÃþºôµ¸¬y¶q¡A±q¦UºØ¼Ð·Çºôµ¸¨óij¦p802.11b/g/n, ARP, DHCP, IPv4, IPv6, TCP, UDP, ICMP, TLS/SSL, SMTP, IMAP, DNS, HTTP, SMB, FTP, RTPµ¥©Î¥Ø¼Ð¤º³¡³q«H¨óij¤J¤â¡A¤ÀªR¶Â«Èªº³q«H­n¯À©M«H®§¤º®e¡A°lÂܶ«Ȧbºôµ¸¤¤ªº¦æ°Ê­y¸ñ¡C
2¡D¦p¦ó¦¨¬°¤@¦W²`¨è²z¸Ñºôµ¸¹Bºû©M¦w¥þ¨¾Å@ªº°»¬d­û¡H
¤j«¬­«­nºôµ¸ªº¹Bºû©M¤@Åé¤Æ¦w¥þ¨¾Å@¡A¤£¦A¬O¹L¥hºôºÞ­û¡§­«¸Ë¨t²Î¡B°t¸mDHCP¡B¤É¯Å±þ¬r³n¥ó¯f¬r®w¡¨ªºÂ²³æ­«´_³Ò°Ê¡C¦UÃþ¦Û°Ê¤Æ¹Bºû¨t²Î©M¦w¥þ¨¾±s¤u¨ã¡A©w´Á¹ïÀ³¥ÎªA°È¾¹¡B¸ô¥Ñ¾¹¡B¨¾¤õùÙ¡Bºôµ¸³]³Æ¡B·Ó¬Û¾÷©M¦UºØ¨ä¥L³]³Æ²£¥Íªº¨Æ¥ó¤é§Ó¤¤¶i¦æªö¶°¡AÀò¨ú¯S©w®É¶¡¡B¯S©w¨t²Î/Àô¹Ò¤Uªº³]³Æª¬ºA¡A¦}¶i¦æ¥iµø¤Æªº²Î­p©M®æ¦¡¤Æ¼Ð·Ç¤Æ³B²z¡C¦UÃþºÊ±±Äá¹³±´ÀYªº¿ý¹³¡Bµn°O°O¿ý¡Bºôµ¸³X°Ý¤é§Ó¡BµL½u±µ¤JÂIªº¤é§Ó¡B°ÊºA¥D¾÷°t¸m¨óij«O¯dªº¦a§}¤À°t¤é§Ó¡B¬¡°Ê¥Ø¿ý¡B°ì±±¨î¾¹¡BVPN±±¨î¾¹µ¥´£¨Ñªº¤é§Ó¡B¬¡°Ê¥Ø¿ý¨Æ¥ó¤é§Ó¡BWeb¥N²zªA°È¾¹¤é§Ó¥H¤Î¥Ø¼Ð¹q¸£¤¤¥i¯à·|¦w¸Ëªº¦ì¸m°lÂܳn¥ó¤é§Óµ¥¡A³£¬O§Ú­Ì¶i¦æºî¦XÃöÁp»P¤ÀªRªº­«­n¯À§÷¡C¦h·½¤é§Ó«H®§ªº¿Ä¦X»PÃöÁp¤ÀªR±N¦¨¬°°»¬d­û­Ìªº§Q¾¹¡A§Ú­Ì±N¯à°÷§Ö³t·Ç½T¦a©w¦ì¶Â«È¹q¸£ªºª«²z¦ì¸m¡X¡X²¾°Ê³]³ÆÁp¤J«Øµ®ª«¨½ªº­þ­ÓµL½u±µ¤JÂI¡HÁÙ¥i¥H³q¹L¸òÂܲ¾°Ê³]³ÆÁp¤J¦U­ÓWAPªº±¡ªp¡A¤Äµe¥X¶Â«È³]³Æ²¾°Êªº­y¸ñ¹Ï¡F·Ç½Tªº®É¶¡©M¦ì¸m­n¯À¡A¯àÅý§Ú­Ì±q®ü¶qªººÊ±±Äá¹³¼Æ¾Ú¤¤¨³³t§ä¨ì¶Â«Èªº­±³¡¯S©º¡C
3¡D¦p¦ó¦¨¬°¤@¦W¼ô½m¹B¥Î¨t²Î¬[ºc«ä·Q©M¼Æ¾Ú¬ì¾Ç¤èªkªº°»¬d­û¡H
¤¬Ápºô¦p¦¹´_Âø¡A¥H¦Ü¤_§Ú­Ì¤wµLªk¹ý©³¤ÀªR©M²z¸Ñ¨ä¤u§@¼Ò¦¡¡C¦Û¨ä½Ï¥Í¥H¨Ó¡A°Î¦W©Ê´N¬O¤¬Ápºôªº¯S½è¤§¤@¡A¬Æ¦Ü§Y«K³]³Æ¦ì¤_§A´x´¤ªº²Õ´¤º³¡®É¡A·Ç½T©w¦ì¨ì¥¦¤]»Ý­n¤ÀªR®ü¶qªººôµ¸¤åÀÉ©M¤é§Ó¡C·í«eªº¦UºØ¦Û°Ê¤Æ¹Bºû¡]slunk¡^©Î¦w¨¾³]³Æ¡]¦pIDS¡^¤w¸g¨ã¦³¤@©wªº²Î­p³B²z©MÃöÁp¤ÀªR¯à¤O¡A¦ý¹ï¤_¡§¶Â«È¦æ¬°¼Ò¦¡ÃѧO¡B§ðÀ»ªÌ¤ÀÃþ¡B¥¼¨Ó§ðÀ»°Ê§@¹w´ú¡B¶Â«ÈÁ`Åé¹ê¤Oµû¦ô¡¨µ¥§ó°ªµ¥¯Åªº°»¬d¤u§@¤´µM¤O¤£±q¤ß¡C§Ú­Ì¤´µM»Ý­n§ó¥[²`¨è¦a²z¸Ñºôµ¸«H®§¨t²Îªº¬[ºc¡A¹ï®ü¶qªº¼Ë¥»¼Æ¾Ú¤¤¥D°Êªº¾Ç²ß¯S©º¡B«Ø¥ß¼Ò«¬¡A¦b¾÷¾¹¾Ç²ß¡B¤H¤u´¼¯àµ¥¬ì¾Ç¤èªkªºÀ°§U¤U¡A¦b­«­«°gÃú¤¤©âµ·­éõ¡A²z²MÁcºa´_Âøªº®ü¶qÃÒ¾Ú¶¡Ãö¨t¡C
¬Û«HŪ§¹¥»®Ñ¡AµL½×¬O¤j±M°|®Õ­pºâ¾÷©Mºôµ¸¦w¥þ¬ÛÃö±M·~ªº¾Ç¥Í¡AÁÙ¬O¤½¦wºôµ¸¦w¥þ«O½Ã³¡ªùªº¤@½u°»¬d­û¡A¥ç©Î°ê®aºôµ¸¦w¥þÀ³«æÅTÀ³³æ¦ìªº§Þ³N¤H­û¡A³£·|¤j¦³»t¯q¡C¥½¤F¡A¤p¥Í¤£¤~¡A¤]ªþ°e¤@¥y©¾§i¡G¶Â«È©MAPT§ðÀ»ªÌ¥¿Åܱo¶V¨Ó¶V±j¤j¡A°»¬d­û­Ì¤@¨è³£¤£¯à°±·²¡A½ÐºÉ§Öªº¶i¤@¨B¾Ç²ß´x´¤°ò¤_¤j¼Æ¾Úªº´¼¯à¤Æ®ü¶q±¡³ø¤ÀªR¤èªk©M§Þ¯à¡AÅý¥Ç¸oªÌ¦b§Ú°êªººôµ¸ªÅ¶¡¤¤µL©Ò¹P¸ñ¡C

±i¦tµ¾¡]ID¡G¼ç¥ñÆN¡^
2014.11.1.¥_¨Ê.




ĶªÌ§Ç

³o¬O¤@¥»µø¨¤¿W¯Sªº¹q¤l¨úÃÒ®ÑÄy¡A¥O¤H¦Õ¥Ø¤@·s¡I
§Ú¦Û±q2002¦~°_±q¨Æ¹q¤l¨úÃÒ¤u§@¦Ü¤µ¤w¦³¤Q§E¦~¤F¡AÀ³¸Ó»¡³o¤@¦æ¨½´X¥G¤@ª½¤£°±¦a¯F²{¥X·sªº§Þ³N¡B«ä¸ô¡A§A¬Ý¹À¡G
¤Q´X¦~«e¡A´X¥G©Ò¦³ªº¨úÃÒ®ÑÄy°Q½×ªº³£¥u¦³¤@¥ó¨Æ¡X¡X¼Æ¾Ú«ì´_/¤å¥ó¨t²Î¤ÀªR¡C¦n¹³¾ÌµÛ¤@¤â¼Æ¾Ú«ì´_§Þ³N´N¯à¥]¥´¤Ñ¤U¤F¡C2005¦~¥Xª©ªºFile System Forensic Analysis¬O­ÓÅq®p¡A¦Ü¦¹¤å¥ó¨t²Î¤ÀªR§Þ³N¤w¸g«D±`¦¨¼ô¤F¡A¦}¥X²{¤F¦UºØ¶Ì¥Ê¦¡ªº¤u¨ã¡C²@¤£¦j±i¦a»¡¡A²{¦b¥Î¤@¼Ëªº¤u¨ã¡A¤@­Óªì¥X­TÃfªº·s¤â°µ¼Æ¾Ú«ì´_¡A±o¨ìªºµ²ªG¤w¸g©M¦Ñ³¾­Ì®t¤£¦h¤F¡X¡X¨ì°±º¢´Á¤F¡H¤~¤£¬O©O¡I
±µ¤U¨Óªº´X¦~®É¶¡¨½¡A¦UºØ©_©Û¡B©Ç©Û¡B·l©Û¼h¥X¤£½a¡C®³ª`¥Uªí¨½ªº¦UºØ«H®§¡]¤ñ¦p³q¹Lª`¥Uªí¨½½w¦sªºÅX°Ê«H®§¡A­Ë±À­pºâ¾÷¤W´¿´¡¹L´X­Ó¤°¤\¼ËªºUSB³]³Æ¡^¡A¤ÀªR¤º¦s¤¤ªº¼Æ¾Ú¡]§ä³QrootkitÁôÂ꺶iµ{/¼Æ¾Ú¡^¡A¤ÀªRÀ³¥Îµ{§Ç¦sÀx¤U¨Óªº«H®§¡]¤ñ¦p®³¦UºØIM¤u¨ãªº²á¤Ñ°O¿ý¡^¡A¹ïÀ³¥Îµ{§Ç/¯f¬r¤ì°¨¥»¨­¶i¦æ¤ÀªR±q¤¤Àò¨ú«H®§¡]¤ñ¦p¤W®ü2009.7.18¨p¨®ÃB«×©ç½æºô¯¸¾DDDOS§ðÀ»®×¡A´N¬O§Ú³q¹L¤ÀªR§ðÀ»¥Îªº¤ì°¨¯}Àòªº¡^¡Aµ¥µ¥¤£¤@¦Ó¨¬¡C§Ú¥»¤H¤]¤À§O¦b2008¦~©M2012¦~¦b¦w¥þµJÂI®p·|¤W´£¥X¹L§Q¥Î«H®§æi¤ÀªR­«ºcraid 5°}¦C©M°w¹ï³æ­Ó¤å¥ó¡]¦Ó«D¤å¥ó¨t²Î¡^°µ¼Æ¾Ú«ì´_ªº¨â­Ó«ä¸ô¡A¤]´¿©M¤@¨ÇªB¤Í¦X§@½Ķ¥Xª©¤F¡mWindows¨úÃÒ¤ÀªR¡n¤@®Ñ¡Aºî­z¤F·í¦~Windows¥­»O¤Uªº¨úÃÒ§Þ¥©¡C
¤£¹L¡A³o±ø¸ô»ª¦ü¤S¦³ÂI¡K¡K¡A³æ¾÷¥­»O¤W¯à«õªº¦a¤è°ò¥»¤W³£¤w¸g¹L¤F¤@¹M¤F¡A¦A­n§äÂI·sÂAªº¹ê¦b¬OÃø°Ú¡K¡K
¤W­±ªº¾ú¥v¸gÅç§i¶D§Ú­Ì¡A¨C¨ì³o¼ËªºÃöÀY´N·|¦³¥þ·sªº«ä¸ô¥X²{¡C°ÝÃD¬O³o­Ó¥þ·sªº«ä¸ô¬O¤°¤\©O¡H¬OAndroid/iOS¥­»O¡H·íµM³o¬O«D±`¦³¥i¯àªº¡A¤£¹L¤£­n§Ñ¤FÁÙ¦³¥t¤@­Ó­«­n¤è¦V¡X¡Xºôµ¸¨úÃÒ¡A¤]´N¬O¥»®Ñªº¥DÃD¡C
¥ô¦ó§Þ³N­nµo®i³£Â÷¤£¶}¤Ñ®É¡B¦a§Q¡B¤H©M¡C¤Ñ®ÉªÌ¡A®É¥N¤j­I´º¤]¡C¥Ø«e²¾°Êºôµ¸¡Bª«Ápºôµ¥ºôµ¸§Þ³Nªºµo®i´¶¤Î¬O©Ò¿×¡§¤Ñ®É¡¨¡A¥¿¦p²Ä1³¹¤¤ªº¨º­Ó®×¨Ò¨º¼Ë¡A²{¦b¥á­Ó¤â¾÷³£¯à³q¹L³æ¦ì¤º³¡ªºWi-Fi¼öÂI¤é§Ó´MÂÜ¡A³o¦b¥H«e¬O¤£¥i·Q¶Hªº¡CÂ÷¶}³o­Ó­I´º¥h½Íºôµ¸¨úÃÒ³£¬O§è¡F¦a§QªÌ¡A©Ò»Ýªº¦UÃþ³]³Æ¤W¨úÃÒ§Þ³Nªº¦¨¼ô¡Cºôµ¸³]³ÆºØÃþÁc¦h¡A¦ýÀHµÛªñ¦~¨Óºôµ¸³]³Æªº´¶¤Î¡A³o¨Ç³]³Æªº¾Þ§@¤èªk¤]¤£¦A¬O¤Ö¼Æ¤Hªº±M§Q¤F¡A¶V¨Ó¶V¦hªº¤H¯àª±Âà³o¨Ç³]³Æ¬O°ò¦¡F¤H©MªÌ¡A¤HªºÆ[©À¡C¦Û±q¤º¦s¨úÃÒªº·§©À³Q´£¥X¨Ó¤§¦Z¡AÃÒ¾Úªº©ö·À¥¢µ¥¯Å´N¶}©l¨ü¨ì¤F¤j®aªº­«µø¡C ¶Ç²Îªº­pºâ¾÷¨úÃÒªº²´¥ú«ª¤_­pºâ¾÷³æ¾÷³]³Æ¡A§Ú­Ìªº«ä¸ôÁ`¬O±q¬Y¤@»O¨ãÅ骺³]³Æ¤J¤â¶i¦æ¤ÀªRªº¡CºÉºÞ§Ú­Ì¤]±j½Õ¹q¤l²{³õªºÁÙ­ì¡A¦ý¨º¤]¶È¶È¬O«ª¤_¬Y»O³]³Æ¤º³¡ª¬ºAªº«OÅ@©M¤ÀªR¡C¦³¤H»¡¡A¨ãÅé¿ì®×®É¤£¬O¤@¼Ë·|§â¦U»O³]³Æ¤¤Àò±oªº«H®§¦ê¨ì¤@°_¤ÀªR¶Ü¡H³o¤£´N¬Oºôµ¸¨úÃҶܡHÁÙ¯u¤£¤@¼Ë¡I¦]¬°ºôµ¸¨úÃÒ¬O§âºôµ¸¾ãÅé¬Ý§@¤@­Ó²{³õªº°ª«×¡C³o­Ó°ª«×ªº¤W¤É¥ß°¨¾É­P§A¤ÀªR°ÝÃDªº«ä¸ôµo¥Í¤FÅܤơC²{¦b§A·|¦Ò¼{¦U­Ó³]³Æ¤WÃÒ¾Úªº©ö·À¥¢µ¥¯Å¡A®e©ö·À¥¢ªº¥ý¨ú¡A¤£®e©ö·À¥¢ªº¦Z¨ú¡C¦Ó¤£¹³¥H«e¬Ý¨ì¤@»O³]³Æ¡A¤£¤ÀªRºôµ¸´N©Ô°_³S¤l¶}©l¤z¬¡¤F¡Aµ²ªG¾É­P¦]¬°¨S¦³¤Î®É°É¬d¸ü¦³©ö·À¥¢ÃÒ¾Úªº³]³Æ¦Ó³y¦¨ÃÒ¾Úªº¥Ã¤[©Ê¥á¥¢¡C¦b³o¤è­±¡A¥»®Ñ§@ªÌ´£¥XªºOSCAR¤èªkµ´¹ï¬O­Ó«GÂI¡C
¤]¥¿¬O¥Ñ¤_³o¨Ç­ì¦]¡A³o¥»Network Forensics: Tracking Hackers through Cyberspace¦Û±q2012¦~6¤ë¥Xª©¦Z¡A¦bAmazon¤W¤@ª½²`¨ü¦nµû±Æ¦W©~°ª¤£¤U¡C§Ú¦³©¯Åª¨ì³o¥»®Ñ¡A¦}±N¨ä±ÀÂ˨ì°ê¤º¡A²`·PÀ£¤O¡C
¥»®ÑªºÂ½Ä¶¹Î¶¤¬O­Ó«D±`±j¤jªº¹Î¶¤¡A¦³¸gÅçÂ×´IªºÅ³©w®v¡]¾Ö¦³¤½¦w³¡©M¥qªk³¡»{ÃÒªº¹q¤l¼Æ¾Úų©w¸ê½èªºÅ³©w¤H¦U¤@¦W¡^¡A¤]¦³¨Ó¦Û¤@½uªº§Þ³N¤ä«ù¤H­û©Mºôµ¸¦w¥þ«O½Ã¹ê¾Ô³æ¦ìªº¿ì®×¥Áĵ¡AÁÙ¦³±Ð¾Ç¸gÅçÂ×´Iªº¥~»y±M·~±Ð®v¡C³o¤]¬O¤@¦¸¤½¦w±M·~°|®Õ»P¦a¤èºôµ¸¦w¥þ/¹q¤l¨úÃÒ±M·~¹Î¶¤¦X§@ªº¹Á¸Õ¡C¥þ®Ñ¤Q¤G³¹¤º®e½Ķªº¤À¤u¦w±Æ¦p¤U¡G
²Ä1³¹¥ÑªZ¾å­µ¦P§Ó½Ķ¡A²Ä2³¹¥ÑÅÇÀÙ®®¦P§Ó½Ķ¡A²Ä3³¹¥Ñ®ï¤è¦P§Ó½Ķ¡A²Ä4¡B5¡B6¡B7¡B8¡B9³¹¥Ñ¤W®ü¥°³sºôµ¸¬ì§Þ¦³­­¤½¥qªº³°¹D§»¦P§Ó¤Î¼Æ¦r¥Ç¸o½Õ¬d¤p²Õ¡]DCI¡^ªº¨H¥Ã¦w¡Bù»ï©MP«G¦P§Ó½Ķ¡A²Ä10³¹¥Ñ¤ý§»¦P§Ó½Ķ¡A²Ä11¡B12³¹¤Î³Ñ§E¨ä¥L³¡¤À¥Ñ§Ú½Ķ¡C¥þ®Ñ¥Ñ§Ú©M³°¹D§»¦P§Ó²Î¤@¼f®Õ¡C°£³°¹D§»¡B¨H¥Ã¦w¡Bù»ï©MP«G¦P§Ó¤§¥~ªº¨ä¥LĶªÌ§¡¬°¤W®ü¤½¦w°ªµ¥±M¬ì¾Ç®Õ«H®§¤Æ¡B¯A¥~ĵ°Èµ¥±Ð¬ã«Çªº±Ð®v±Ð©x¡C¥»®Ñ¤¤¤åª©ªº­±¥@­º¥ý­n·PÁ¦U¦ìĶªÌ¥I¥Xªº¨¯¶Ô³Ò°Ê¡C
¨ä¦¸¡A§Ú­n·PÁ³դåµøÂIªº¦U¦ì½s¿è¦Ñ®v¡A¯S§O¬OÅU¼zªÚ¡B¼B²®¦Ñ®v¡A·PÁ§A­Ì¹ï§Úªº¤@³e¤ä«ù©M­@¤ßªº«ü¾É¡A¨Ï§Ú±q¤¤Àò¯q¨}¦h¡I¦P®É¤]·PÁ§A­Ì¬°¥»®Ñªº¥Xª©©Òªá¶Oªº¤j¶q®É¶¡¡I
·í«e¡A²ßªñ¥­Á`®Ñ°O´£¥X¤F¡§§â§Ú°ê±qºôµ¸¤j°ê«Ø³]¦¨¬°ºôµ¸±j°ê¡¨ªº¾Ô²¤ºc·Q¡A2013ª©ªº¡m¤¤µØ¤H¥Á¦@©M°ê¦D¨Æ¶D³^ªk¡n¤¤¤]­º¦¸±N¹q¤l¼Æ¾Ú§@¬°¤@ºØ¥¿¦¡ªºªk©wÃÒ¾ÚÃþ«¬¡C¥i¥H¹w¨£¡Aºôµ¸¦w¥þ-¹q¤l¨úÃÒ¤u§@¦b§Ú°ê±N·|¦³¤@­Ó¸û¤jªºµo®i¡C¥»®Ñ¬J¥i¨Ñ¼s¤j±q¨Æ¹q¤l¨úÃұоǩM¹ê»Ú¤u§@ªº¤H­û¾\Ū¡A¤]­p¹º§@¬°§Ú®Õ°»¬d±M·~²Ä¤G¥»¬ì¹q¤l¨úÃÒÃþ½Òµ{ªº°Ñ¦Ò¸ê®Æ¨Ï¥Î¡C

±Z§µ±á
2014¦~5¤ë


§Ç

§Úªº´¿¯ª¤÷¬O­Ó¤ì¦K¡C§Ú²{¦b´N­w¦b¥L°µªº®à¤l¤W¡A§¤µÛ¥L°µªº´È¤l¼g³o½g§Ç¡C¥Lªº¥@¬É¬O¤@ªù¤âÃÀ¡A¡§¼ô¯à¥Í¥©¡¨ ¡C¥L¥Í©R¦Z´Áªº§@«~¡A§Y¨Ïªí­±¤W¬Ý¬O­Ó»P¬Y­Ó¦­´Á§@«~¤@¼ËªºªF¦è¡A¦ý®Ç¤H¤´¯à¬Ý¥X¥L§ÞÃÀªººë´ï¡C
ºôµ¸¦w¥þªº¯SÂI¬O¨ä­²·s³t«×¡X¡X¤£¥ú¬O¨³³t¼Wªøªº¶i¨B¡AÁÙ¦³¨º¨Ç®É¤£®É«_¥X¨Óªº¡§Åå³ß¡¨¡C¥Î¼Æ¾Ç³N»y»¡¡Aºôµ¸¦w¥þªº¡§¥\¨t¼Æ¡¨¬O¤£Â_³Q§Þ³N¶i¨B¥´Â_ªº¶¥±è¨ç¼Æªº¿n¤À¡C§Úªº¯ª¥ý¦b´£°ª¥Lªº§ÞÃÀ®É¡A¥i¤£·|¨ü§x¤_­J®ç¤ì¡B¿ûÅK©Î¨È³Â¬óµ¥­ì§÷®Æ©Êª¬ªº§ïÅÜ¡A¦ý¦b²{¦p¤µ´£¤Éºôµ¸¦w¥þ¤ô¥­®É¥i¨S¦³³o¤\¦n¹B¡C
¥E¤@¬Ý¡A¨úÃÒ¦n¹³¥u¬O¬°¸ÑÄÀ¤w¸gµo¥Íªº¨Æ¦Ó°µªºÂ²³æ¬¡­p¡A¦]¦¹ÁÙÅã±o¦³¨ÇÁB±¡¡C¦ý¨Æ¹ê¦}«D¦p¦¹¡A¨s¨ä­ì¦]¦b¤_¥¦ªº´_Âø©Ê¡C³o­Ó´_Âø©Ê¬O³vº¥¿n²Ö°_¨Óªº¡C¦Ó¥B¡A´N¹³§@ªÌ¦b¤@¶}©l»¡¹Lªº¨º¼Ë¡A¦pªG¿n²Ö¨¬°÷¦hªº¸Ü¡A§Y«K¥u¬O¤@­Ó³Ì²³æªººôµ¸¡A·Qª¾¹D¨ä¤¤µo¥Íªº©Ò¦³¨Æ¤]·|Åܱo¤£¥i¯à¡C¦]¦¹¡A¨úÃÒªº¥Øªº´N¦b¤_´¦¥Ü¨º¨Çµo¥Í¦bºôµ¸¤Î¨ä°ò¦³]¬I¤Wªº¡A¦³·N¸qªº¡A¥ý«e¤£¬°¤Hª¾ªº­«­n¦]¯À¡C¥u¦³¦bª¾¹D¤F³o¨Ç¦]¯À¤§¦Z¡A±N¨Ó¤~¯u¥¿¦³§ï¶iªº¾÷·|¡C
¨úÃÒ¬O¤@ªùÃÀ³N¡A¶Ô¯à¸É©å¡C¨úÃÒªºµo²{¹Lµ{´N¦b¤_±Æ°£¥¿¦b½Õ¬dªº¨Æ¥óªº¥i¯à¦¨¦]¡C´N¹³ÀJ¨è®É¡A§Ú­Ìªº¥Øªº´N¬O¥h±¼©Ò¦³¨Ï¥¦¬Ý¤W¥h¤£¹³¤@ÀY¤j¶Hªº¦h§E¥Û®Æ¤@¼Ë¡A¨úÃÒ¤]¬O­n¥h±¼©Ò¦³¸gÆ[¹î¦}¤£¦¨¥ßªº°²»¡¡A¦}³Ì²×±o¥Xµ²½×¡C®M¥ÎEF µÎ°¨»®ªºÆ[ÂI¡A¨úÃÒ¬O­Ó¦¬ÀĪº°ÝÃD¡F¦ýºôµ¸¦w¥þ«o¬O­Óµo´²ªº°ÝÃD¡C´«¦Ó¨¥¤§¡A¦b¨úÃÒ¤¤¥I¥Xªº§V¤O¶V¦h¡A¸Ñªº¶°¦X´N¶VÁͦV¤_¬Y¤@­Óµª®×¡A¦ý³o¤@µ²½×¦b¤@¯ëªººôµ¸¦w¥þ°ÝÃD¤W«o¤£¦¨¥ß¡C
©Î³\§Ú­ÌÀ³¸Ó»¡¡G¨úÃÒ¤£¬O¤@ªùÃö¤_¦w¥þªº¾Ç¬ì¡A¦Ó¬O¤@ªùÃö¤_¡§¤£¦w¥þ¡¨ªº¾Ç¬ì¡C¦w¥þ¬OÃö¤_©Ò¦³¼ç¦bªº¨Æ¥óªº¡A¥¿¦pPeter Bernsteinªº©w¸q¡G¡§­·ÀI´N¬O½Ñ¦hÃø¥H¹w¨£ªº±¡ªp¡¨¡C¨úÃÒ¤£¥²±q¶V¨Ó¶V´_Âøªº¨Æ¹ê¤¤Âk¯Ç¥X¦UºØ¥i¯à©Ê¡A¥u¶·±À¾É¥X¨ä¡§¦ó¥H¦Ü¦¹¡¨ªº­ì¦]§Y¥i¡CµM¦Ó¡A¤@¯ë¨Ó»¡¡A¦bºôµ¸¦w¥þ¤¤¡A¥Ç¸o¤À¤lÁ`¬O¦³¤@ºØ¥ý¤ÑªºÀu¶Õ¡A¦Ó¦b¨úÃÒ¤¤¡A¬O¨¾±sªÌ¾Ö¦³³o¤@Àu¶Õ¡C
¨úÃÒ¬OªùÃÀ³N¡A¡§¯uªº°²¤£¤F¡A°²ªº¯u¤£¤F¡¨¬O¥¦¤Ñ¥Í¨ã¦³ªº¾Ô²¤Àu¶Õ¡C¹ï§A¡]²{¦b©Î±N¨Óªº¨úÃÒ¤H­û¡^¨Ó»¡¡A§Aªº¥ô°È´N¬O¦b§A¾Ö¦³¾Ô²¤Àu¶Õªº¦a¤è´£°ª§Aªº§ÞÃÀ¡X¡X¤£¥ú¬O²z½×¤Wªº¡AÁÙ­n¦³¹ê»Ú¾Þ§@§Þ¯à¡C³o´N¬O§A»Ý­n³o¥»®Ñªº­ì¦]¡C
§Þºë¤_¾Ç¥Í¬O¦Ñ®vªº¸q°È¡A¦Ó¡§«C¥X¤_ÂŦӳӤ_ÂÅ¡¨¦P¼Ë¤]¬O¾Ç¥Íªº³d¥ô¡C¦ý¬O¦bÅܦ¨³»¦y°ª¤â¤§«e¡A§AÁÙ¬O»Ý­n¦Ñ®vªº±Ð¾É¡A¶W¶V¥L­Ì¦}«D©ö¨Æ¡C»¡¨ì©³¡A§ÞÃÀ«D¤Zªº¤j®v¯àÅý§Aª¾¹D·í«eªº¤u¨ã½c¤¤­þ¨ÇªF¦è¬O¤@ª½¯à¥Îªº¡A­þ¨Ç¬OÀHµÛ®É¥Nªº¶i¨B¥i¯à³Q²^¨O±¼ªº¡C¥L¦P¼Ë¤]¯à²M·¡¦aª¾¹D¡A§A¯Ê¨Ç¤°¤\¡C±q³o­Ó¨¤«×¨ÓÁ¿¡A³o¥»®Ñªº½g´T¦w±Æµ´¹ï¬O¤j®v©Ò¿ï¡C
°ò¥»¤W¡A¥Ñ¤_¨C°_®×¥ó®×±¡ªº¤£¦P¡A¦U­Ó®×¥óªº¨úÃÒ½Õ¬d¹Lµ{¤¤¡A¦U¦Û©Ò»Ýªº¤u¨ã¶°¤]³£¤£ºÉ¬Û¦P¡A©Ò¥H³Ì¦nªº¿ìªk´N¬O¾Ö¦³©Ò¦³·|¥Î¨ìªº±M·~¤u¨ã¡A·íµM¨ä¤¤ªº¤@¨Ç¤u¨ãªº¨Ï¥ÎÀW²v·|°ª¤_¨ä¥L¤u¨ã¡C±N¤u¨ã¶°ªº§@¥Îµo´§¨ì·¥­Pªº«e´£¬O¡G§A²`¤J¤F¸Ñ¨ä¤¤ªº¨C­Ó¥\¯à¡A·íµM¡A³o¦}¤£¬O»¡§A»Ý­n¦ÓµL¶·¸g±`¨Ï¥Î¨ä¤¤ªº¨C¤@­Ó¤u¨ã¡CNicholas Taleb¬O³o¼Ë´y­zUnberto Ecoªº°f¹Ï®Ñ¦¬ÂÃ¥D¸qªº¡G¡§¡K¡KÀ³¸Ó¦b§Aªº¸gÀÙª¬ªp¡B«ö´¦§Q²v¥H¤Î¤£°Ê²£¸ê²£¤¹³\ªº±¡ªp¤U¡AºÉ¥i¯à¦h¦a¦¬¶°§A©Ò¤£¤F¸Ñªº¸ê®Æ¡C¡¨
§A¡A¿Ë·RªºÅªªÌ¡A¯à®³¨ì³o¼Ë¤@¥»»P²³¤£¦Pªº¨úÃÒ®ÑÄy¡A¥BŪ¥B¬Ã±¤¡I

Daniel E. Geer, Jr., Sc.D.






«e ¨¥

¨C¤Ñ¡A¤¬Ápºô¤W¬y¸gªº¤ñ¯S¼Æ¤ñ¥@¬É¤W¥þ³¡¨FÅy¤Wªº©Ò¦³¨F¤lÁÙ¦h¡C®Ú¾Ú«ä¬ìVisual Networking Index¡AºI¤î¨ì2011¦~¡A¥þ²yªºIP¬y¶q¹w­p·|¹F¨ì¨C¤Ñ¬ù8.4 1018¤ñ¯S¡C¦Ó¾Ú®L«Â¦i¤j¾Çªº¼Æ¾Ç®a­Ì¦ôºâ¡A¥@¬É¤W¥þ³¡¨FÅy¤Wªº©Ò¦³¨F¤l³£¥[°_¨Ó¤]¤£¹L¥u¦³¬ù7.5 1018Áû¡C«ö«ä¬ìªº¦ô­p¡A¥þ²yIP¬y¶qªº¦~¼Wªø²v¬O32%¡A©Ò¥H·í§AŪ¨ì³o¤@¬q®É¡A¨C¤Ñ¬y¸g¤¬Ápºôªº¤ñ¯S¼Æ¥i¯à¤w¸g»·»·¶W¹L¥@¬É¤W¥þ³¡¨FÅy¤Wªº©Ò¦³¨F¤l¼Æ¤F¡C
·íµM³o¨Ç¦ôºâ³£¬O«D±`²Ê²¤ªº¡C¦]¬°³o¨â­Ó¨Ò¤l¤¤©Ò¯A¤Îªº¨t²Î¤§¤j¡A¤§´_Âø¡A¤w¸g»·»·¶W¹L¤F¤HÃþªº¤u¨ã©Ò¯à¶q¤Æ¤ÀªRªº­S³ò¡C¤¬Ápºô¦­¤w¹L¤F§Ú­Ì¥i¥H§¹¥þ¤ÀªR©M²z¸Ñ¨ä¤u§@¼Ò¦¡ªº®É¥N¤F¡C§Ú­Ì¥i¥H²`¤J­åªR¥¦ªº¬Y¤@³¡¤À¡A¤]¥i¥H°µ¤@­Ó¼eªxªº·§¬A¡A¦ý¨Æ¹ê¬O¡G§Ú­Ì¤HÃþ¤w¸g³Ð³y¥X¤F¤@­Ó¯à¤O©M´_Âø«×»·»·¶W¹L§Ú­Ìªº²z¸Ñ¯à¤OªºÃeµM¤jª«¡C
¦b³o¤@Àô¹Ò¤U¡A¥X²{¤F¤@­Ó·s¿³ªº¡A¥Ø«eÁ٬ݤ£¨ì¨äµo®iºÉÀYªº¬ã¨s»â°ì¡X¡Xºôµ¸¨úÃÒ¡C¤@¯ë¨Ó»¡¡A¨úÃÒ´N¬O¡§§â¬ì¾Çª¾ÃÑÀ³¥Î¦bªk«ß°ÝÃD¤W¡A¯S§O¬O¹ï¡]¤ñ¦p¨Ó¦Û¬Y­Ó¥Ç¸o²{³õªº¡^ª«²zÃÒ¾Ú¶i¦æ¬ì¾Ç¤ÀªR¡¨¡C¦]¦¹¡Aºôµ¸¨úÃÒ´N¬O«ü¡G³q±`À³¥Î¦b¥qªk°ÝÃD¤Wªº¡A¹ï°ò¤_ºôµ¸ªºÃÒ¾Ú¶i¦æªº¬ì¾Ç¬ã¨s¡C·íµM¡Aºôµ¸¨úÃÒ¦}¤£¬O¤@­Ó²æÂ÷¨ãÅé®×±¡ªº¬ã¨s»â°ì¡A¦Ó¥B³\¦h±M¬°¥qªk½Õ¬d¦Ó°µªº¾Ç¬ì«eªu¶i®i¡B¤u¨ã©M§Þ³N¦P¼Ë¥i¥H¥Î¤_ªÀ·|¾Ç¬ã¨s¡B¾ú¥v¤ÀªR¥H¤Îºôµ¸Àô¹Òªº¬ì¾Ç±´¯Á¡C¦b¥»®Ñ¤¤¡A§Ú­Ì¤O¹Ï´£¨Ñ¤@­Ó¤£¥ú¹ïªÓ­t§¹¦¨¥qªk½Õ¬d¥ô°Èªº±M·~ºôµ¸¨úÃÒ¤ÀªR®v¦³¥Î¡A¤]¹ï¾Ç¥Í¡B¿W¥ß¬ã¨s­û¥H¤Î¨ä¥L©Ò¦³¹ï¦¹·P¿³½ìªº¤H¤h¨ã¦³¹ê¥Î»ù­Èªº§Þ³N°ò¦¡C
0.1 ¤£Â_ÅܤƵ۪º¤gÄ[
¤¬Ápºô¬OÅܤƵL±`ªº¡C¨C·íµw¥ó©Î³n¥ó¤W¶}µo¥X¤F¤@ºØ·sªº¯S©Ê®É¡A´N·|¦³¤Ï¬M³o¨ÇÅܤƪº·s¨óij¥X²{¡A¦Ó¦Ñªº¨óij¤]·|³Q­×­q©Î§ó·s¡A¥H¾AÀ³³Ì·sªº§Þ³N¡C¦b¹L¥hªº³o­Ó¥@¬ö¨½¡A¦b§Ú­Ì¨£ÃÒ¤U¡A¯F²{¥X¨Óªº·s¨óij¦³¡G¤À¥¬¦¡ÂI¹ïÂIµøÀW²á¤Ñ¨t²Î¡B¦b¼Æ¤d­^¨½¤§¥~¬°±wªÌ»·µ{°Ê¤â³Nªº¨óij¡A¥H¤Î¯à¶¹L¥b­Ó¦a²y¾ÞÁa¾÷¾¹¤Hªº¨óij¡C
¹ï¤_¼ô±x¶Ç²Îªº¤å¥ó¨t²Î¨úÃÒ§Þ³Nªº½Õ¬d¤H­û¨Ó»¡¡Aºôµ¸¨úÃҬݤW¥h¬O¨º¤\¥O¤H±æ¦Ó«o¨B¡C¬Û¹ï¤_°Ê»³¦¨¦Ê¤W¤dºØªººôµ¸¨óij¡A³Q¼sªx¨Ï¥Îªº¤å¥ó¨t²Î®æ¦¡¤]´N¨º¤\¹é¹é´XºØ¡C¦bWindows¨t²Î¤¤¤@¯ë´N¬OFAT32©ÎNTFS¤å¥ó¨t²Î¡A¦bUNIX/Linux¨t²Î¤¤¡A±`¨£ªº¤]´N¬Oext2, 3, 4, ZFS, ©Î¬OHFS+¤å¥ó¨t²Î¡C¬Û¤Ï¡A¦pªGÀH·N«ü©w¤@­Óºôµ¸¡A§A¥i¥H¦b¤W­±µo²{¥H¤Óºô¡A802.11b/g/n, ARP, DHCP, IPv4, IPv6, TCP, UDP, ICMP, TLS/SSL, SMTP, IMAP, DNS, HTTP, SMB, FTP, RTPµ¥³\¦h³\¦hªº¨óij¡C
¦b¤¬Ápºô¤W¡A¤]¨S¤°¤\¯à«OÃÒ§A¹J¨ìªº¨óij¤@©w·|²Å¦X¤åÀɳW©w¡A©ÎªÌ¯à°¨¤W§ä±o¨ì¤åÀÉ¡C¦¹¥~¡A¨óij¹ê²{ªº²Ó¸`¤]·|¸g±`ÅܤơC¼t°Ó­Ì¤£·|ªÈµ²¤_¥ô¦ó¼Ð·Ç¡A¬°¤F¯à³Ì¨Î¾A°t¥L­Ìªº²£«~¡A¦b¹ê²{¨óij®É¥L­Ì·|¦b³n¥ó©Îµw¥ó¤WÀH¤ß©Ò±ý¦a¶i¦æ­×¥¿¡C
¦³®É¡A¨óijªº¶}µo¹L¦­¡A©Î¦b¨óijµo®i¦¨¼ô¨ì¯à¤ä«ù¨óij¤¤©Ò¦³¯S©Ê¤§«e¡A´N»Ý­n½s¼g¥XÀ³¥Îµ{§Ç¡C¦b³o¤@¹L´ç¶¥¬q¡A¬ÛÃö¨óij©ÎªÌ¯S©wªº¦r¬q¥i¯à·|³Q¶~¸m¡A©ÎªÌ³Q¾P°â°Ó¡B¼Ð·Ç©e­û·|©Î¶Â«È®¿§@¥L¥Î¡C¦Ó·íÀô¹Òµo¥ÍÅܤơAªº¨óij¤£¦A¯à¥¿±`¤u§@®É¡A¨óij¤]·|³Q´À´«±¼¡C³o¤è­±ªº¤@­Ó§¹¬ü¨Ò¤l´N¬OIPv4¡C³o­Ó¨óij¦b³Ìªì¬Û¹ï¸û¤pªºÀô¹Ò¤¤¤u§@¨}¦n¡CIPv4³]­p®É¨Ï¥Î32¦ìªº¤@­Ó¦r¬q¨Ó¦s©ñ·½©M¥Øªº¦a§}¡A¥¦¯à®e¯Ç232©ÎªÌ»¡¤j¬ù43»õ­Ó¤£­«´_ªº¦a§}¡C¦Ó¦b¤¬Ápºôµo®iªº¦­´Á¡A³o¤@¦a§}¤è®×¤¤ªº¤jºô¬q¬O¤À°tµ¹¥Î¤á¬Û¹ï¸û¤Öªº¤£¦Pªº²Õ´ªº¡C²{¦b¡A¦³¶W¹L¤Q»õ¤H³s¦b¤¬Ápºô¤W¡A¹ï¤_³o¤@»Ý¨D¡A32¦ìªº¦a§}ªÅ¶¡´NÅã±o¬Û·íµ~­¢¡C¦]¦Ó¡A´N¶}µo¥X¤F¾Ö¦³¤j±o¦hªº128¦ì¦a§}ªÅ¶¡¡]2128¡A©ÎªÌ3.4 1038­Ó¤£­«´_ªº¦a§}¡^ªºIPv6¡CÀH¤§¯F²{¥X¨ÓªºÁÙ¦³³\¦h¨ä¥L¨óij¡A¤ñ¦pTeredo¡]³o­Ó¨óij¬O¥Î¨Ó¦b¥u¤ä«ùIPv4ªººôµ¸¤¤ÀG¹D³s±µIPv6¬y¶qªº¡^¡C
·í¨óijµo¥ÍÅܤƮɡA¨úÃÒ¤u¨ã¤]·|ÀH¤§§ïÅܩέץ¿¡C¤@­Ó2010¦~½s¼gªº¤u¨ã¥i¯àµLªk¥¿½T¸ÑªR2002¦~§ì¤U¨Óªº¬Y­Ó¼Æ¾Ú¥]¡A¤Ï¤§¥çµM¡C¦³®É³o¨Ç¿ù»~¥i¯à·|«D±`·L§®¡A¬Æ¦Ü¥i¯àµLªk³Q¹îı¡C©Ò¥H¹ï¤_½Õ¬d¤H­û¨Ó»¡¡A²z¸Ñ¨úÃÒ¤u¨ãªº¤u§@­ì²z¡A¦}¯à²`¤J¨ì³Ì©³¼hÅçÃÒ©Òµo²{ªºµ²ªG¬O«D±`­«­nªº¡Cºôµ¸¨úÃÒ±M®a¥²¶·¬O§Þ¯à°ª¶W¡B¿n·¥©Ê°ª¦}¦³Â×´I¸gÅ窺¤H­û¡A¦]¬°§O¤H½s¼gªº¤u¨ã¦}¤£Á`¯àÀ°§U§A¥¿½T¦a¸ÑÄÀµ²ªG¡A¬Æ¦ÜµLªk¦bªk®x¤W§¹¦¨µ²ªGªºÅçÃÒ¡C
§â³o¨Ç°ÝÃDºî¦X°_¨Óªº¬O¦UºØ¤£¦Pªº®ü¶qªººôµ¸³]³Æ¡A¨ä¤¤¦³¸ô¥Ñ¾¹¡B¥æ´«¾÷¡BÀ³¥ÎªA°È¾¹µ¥¡A¥ô¦ó¤@­Óµ¹©wºôµ¸¤¤ªº¨C¤@­Ó¨t²Î³£¥i¯à·|¦³°ß¤@ªº°t¸m¡B±µ¤f©M¥\¯à¡C¹ï¤_½Õ¬d¤H­û¨Ó»¡¡A¬O¤£¥i¯à¼ô±x©Ò¦³ªººôµ¸³]³Æªº¡X¡X¬Æ¦Ü¥u¬O¨ä¤¤¦Ê¤À¤§´X³£¤£²{¹ê¡X¡X¥]¬A²{¦b©M¹L¥h¥Í²£©w«¬ªº³]³Æ¡C¬Û¤Ï¡Aºôµ¸½Õ¬d¤H­û¥²¶··Ç³Æ¦n¡A­n¦b¸ûµuªº®É¶¡¤º¾Ç·|©M´x´¤¬ÛÃö³]³Æªº¨Ï¥Î¤èªk¡C¦P®ÉÁÙ­n¦Û«Hº¡º¡¦aºÞ²z½Õ¬d©M¶µ¥Øªº¶i®i¡C³o²ª½´N¬O¦b¨«¿ûµ·¡C
¦b²Ä¤@®É¶¡¨½°lÂܨì»Ý­nÀˬdªº³]³Æ·|¬O«D±`§xÃø¡A¬Æ¦Ü¬O¤£¥i¯àªº¡C¦Û¨ä½Ï¥Í¥H¨Ó¡A°Î¦W©Ê´N¬O¤¬Ápºôªº¯S½è¤§¤@¡C¦³®É¡A¤@­ÓIP¦a§}«Ü¥i¯à·|¸¨¨ì¤@­Ó¥~¦aISP¨º¨½¡A³o®É±q²Ä¤T¤è¨º¨½®³¨ì§ó¶i¤@¨Bªº¦ì¸m«H®§°ò¥»´N¬O¤£¥i¯àªº¤F¡X¡X¯S§O¬O·í³o­ÓIP¦a§}¸¨¨ì¤F¤@­Ó¦w¥þ¥ßªk¼eªQªº¨ä¥L°ê®a®É¤×¬°¦p¦¹¡C¬Æ¦Ü§Y«K³]³Æ¦ì¤_§A¯à´x±±ªº²Õ´¤º³¡®É¡A·Ç½T©w¦ì¨ì¥¦ªºª«²z¦ì¸m¡A¤]»Ý­n¤ÀªR®ü¶qªººôµ¸¤åÀÉ©M¤é§Ó¡X¡X³o¨ÇªF¦è¥i¤£«OÃү৹¥þº¡¨¬¨úÃҩһݡCÀHµÛ²¾°Êºôµ¸ªº¿³°_¡A°lÂܳ]³Æªº¦ì¸m±`±`´N¹³¬O®»°gÂôåÀ¸¡A¦Ó¦b³o³õ´åÀ¸¤¤¡A¥e±o¥ý¾÷ªºÁ`¬O¡]¬Æ¦Ü¥i¯à¬O¦bµL·N¶¡¡^²¾°Ê³]³Æªº¥Î¤á¡C
°ÝÃDªºÃöÁä¬O­n§â¤¬Ápºôªº³o¨Ç¥\¯à¬Ý§@¥ÍºA¨t²Î¡C¥¦¤£¨ü¥ô¦ó¤¤¥¡¶Õ¤Oªº±±¨î¡A¤]¤£·|¹³§Ú­Ì³]­p¤@½ø¨T¨®¨º¼Ë³Q¡§³]­p¡¨¥X¨Ó¡C·í§AÀˬdºôµ¸¬y¶q®É¡A¨S¦³¤H¯à§i¶D§A¥i¯à·|¹J¨ì¤°¤\¡A©ÎªÌ§Aªº¤u¨ã¬O¤£¬O¯à¥¿½T¦a¸ÑªR§Aªº§ì¥]¤å¥ó¤¤¡A¬Y­Ó¯S©wª©¥»ªº¨óij¡C·í§A»Ý­n±qºôµ¸³]³Æ¤¤¦¬¶°ÃҾکέ«·s°t¸m¥¦­Ì®É¡A§A¥i¯à¤£±o¤£¬ã¨s¯S©w«¬¸¹ªº³]³Æ¡A¤~¯à¥¿½T²z¸Ñ±µ¤f©MÃÒ¾Ú¨Ó·½¡C·í§A»Ý­n©w¦ì¬Y¨Ç¨t²Î®É¡A§A©Î³\¤£±o¤£º¡¥@¬É¦a°µ¥¬®Ô¹B°Ê¡A¥h°lÂܤ@»O²¾°Ê³]³Æ¡A©ÎªÌµ¹³\¦h¤£¦P°ê®a¨½ªºISPÁp¨t¤H©M°õªk©x­û¥´¹q¸Ü¡A¤~¯à·Ç½T©w¦ì·½ÀY¡C
¨S¦³³W©w¤j®a³£¤@©w­n¨Ï¥Î­þ®a¼t°Ó¥Í²£ªº³]³Æ¡A¤]¨S¦³¥þ²y©Ò¦³¥Î¤á³£¥²¶·¿í¦uªº³W«h¡A§ó¨S¦³­þ¥»¤â¥U¯à·Ç½T¦a§i¶D§A¸Ó«ç¼Ë¶}®i½Õ¬d¤u§@¡C
0.2 ²Õ´µ²ºc
¥»®Ñ¤O¹Ï¯à³Ì¤j­­«×¦aÅn¬Aºôµ¸¨úÃÒ¤¤ªº©Ò¦³³Ì­«­nªº¥DÃD¡C¥þ®Ñ¦@¤À¬°4­Ó³¡¤À¡G¡m°ò¦½g¡n¡B¡m¼Æ¾Ú¬y¤ÀªR¡n¡B¡mºôµ¸³]³Æ©MªA°È¾¹¡n©M¡m°ª¯ÅijÃD¡n¡C
0.2.1 ²Ä¤@³¡¤À °ò¦½g
²Ä¤@³¡¤À¡m°ò¦½g¡n¤¤²[»\ªº¬OÃÒ¾Ú³B²z¡Bºôµ¸©M³]³ÆÀò¨úªº°ò¥»·§©À¡A¬°¥»®Ñ¤§¦Z±N­n°Q½×ªº§ó°ª¤@¯Åªº¥DÃD¥´¦n°ò¦¡C°£¤F³o´X³¹¨½ªº¬ÛÃö¥DÃD¤§¥~¡A§Ú­Ì±j¯P«Øij©Ò¦³ªºÅªªÌ¯à«Ü¦n¦a²z¸ÑTCP/IPºôµ¸¡CW. Richard Stevens½s¼gªº¡mTCP/IP¸Ô¸Ñ¡n¤@®Ñ¬O¤@¥»·¥¦nªº®ÑÄy¡A§Ú­Ì±j¯P±ÀÂ˧A§â¥¦§@¬°°Ñ¦Ò¸ê®Æ¡C
²Ä¤@³¡¤À¤¤¥]§t¥H¤U³¹¸`¡G
²Ä1³¹¡m¹ê¥Î½Õ¬dµ¦²¤¡n¡A®i¥Ü¤Fºôµ¸¨úÃÒ½Õ¬d¤H­û±N·|­±Á{ªº¤j¶q¬D¾Ô¡C¤¶²Ð¤F¹q¤l¨úÃÒ¤¤ªº­«­n·§©À¡A¦}µ¹¥X¤F¤@­Ó¦p¦óµÛ¤â¶}®i°ò¤_ºôµ¸ªº½Õ¬dªº¤èªk²M³æ¡C
²Ä2³¹¡m§Þ³N°ò¦¡n¡A³o¤@³¹¨½µ¹¥X¤F³q¥Îºôµ¸²Õ¥óªº§Þ³N·§Äý¡A¥H¤Î¥¦­Ì¦b¨úÃÒ½Õ¬d¤¤ªº»ù­È¡C¦P®É¤]·|¨Ìºôµ¸¨úÃÒ½Õ¬dªº­I´ºµ¹¥X¨óij©MOSI¼Ò«¬ªº·§©À¡C
²Ä3³¹¡mÃÒ¾ÚÀò¨ú¡n¡A¬ã¨s¦UºØ³Q°Ê¦¡©M¥D°Ê¦¡ªºÃÒ¾ÚÀò¨ú¤èªk¡A¨ä¤¤¥]¬A¨Ï¥Î³n¥ó©Îµw¥ó¶å±´ºôµ¸¬y¶q¡A¥H¤Î±qºôµ¸³]³Æ¤¤¥D°Ê¦¬¶°ÃÒ¾Úªºµ¦²¤¡C
0.2.2 ²Ä¤G³¡¤À ¼Æ¾Ú¬y¤ÀªR
²Ä¤G³¡¤À¡m¼Æ¾Ú¬y¤ÀªR¡n¤¤°Q½×¦UºØ¥i¨Ñ½Õ¬d¤H­û¤ÀªRºôµ¸¬y¶qªº¤èªk¡C§Ú­Ì±q¼Æ¾Ú¥]¤ÀªR¶}©lÁ¿°_¡A±qÀˬd¨óijÀY³¡¡A¨ì´£¨ú¼Æ¾Ú¥]ªº¸ü²ü¡A¦A¨ì­«ºc¶Ç¿éªº¼Æ¾Ú¡C¥Ñ¤_«O¯d°O¿ý¤U¨Óªº¼Æ¾Ú¬y¤w¸g¬O¤@ºØ¥qªÅ¨£ºDªº¨Æ¤F¡A©Ò¥H§Ú­Ì¯S·N¥Î¤F¤@¾ã³¹ªº½g´T°Q½×¹ï¬y°O¿ýªº²Î­p¤ÀªR¡C¦A±µ¤U¨Ó·|²`¤J±´¨sµL½uºôµ¸©M802.11¨óij±Ú¡C³Ì¦Z¡A§Ú­Ì±N°Q½×³]­p¥Î¨Ó¹ê®É¤ÀªR¬y¶q¡B¥Í¦¨³øĵ¥H¤Î¦b¬Y¨Ç±¡ªp¤U¯à§Y®É§ì¥]ªººôµ¸¤J«IÀË´ú©M¨¾­S¨t²Î¡C
²Ä¤G³¡¤À¤¤¥]§t¥H¤U³¹¸`¡G
²Ä4³¹¡m¼Æ¾Ú¥]¤ÀªR¡n¡Aºî¦X¬ã¨s¤F¦UºØ¨óij¡B¼Æ¾Ú¥]¤Î¼Æ¾Ú¬y¡A¥H¤Î¤ÀªR¥¦­Ìªº¦UºØ¤èªk¡C
²Ä5³¹¡m¬y²Î­p¤ÀªR¡n¡A®i¥Ü¤F¤@­Ó¤é¯q­«­nªº»â°ì¡X¡XÀRºA¬y°O¿ýªº¦¬¶°¡B¦X¦}©M¤ÀªR¤èªk
²Ä6³¹¡mµL½u¡GµL¶·ºô½uªº¨úÃÒ¡n¡A°Q½×µL½uºôµ¸¡A¯S§O¬O¦bIEEE 802.11¨óij±Ú¤¤ªºÃÒ¾Ú¦¬¶°©M¤ÀªR§Þ³N¡C
²Ä7³¹¡mºôµ¸¤J«Iªº°»´ú¤Î¤ÀªR¡n¡A³o¤@³¹¦^ÅU¤F±Mªù¥Î¤_¥Í¦¨¦w¥þ³øĵ¡A¦}¤ä«ùÃÒ¾Ú©T©wªººôµ¸¤J«I¨¾Å@¨t²Î©M¤J«IÀË´ú¨t²Î¡C
0.2.3 ²Ä¤T³¡¤À ºôµ¸³]³Æ©MªA°È¾¹
²Ä¤T³¡¤À¡mºôµ¸³]³Æ©MªA°È¾¹¡n¤¤°Q½×¤F±q¦UÃþºôµ¸³]³Æ¤¤Àò¨ú©M¤ÀªRÃÒ¾Úªº¤èªk¡C¤@¶}©l§Ú­Ì¥ý°Q½×¨Æ¥ó¤é§Óªº¦¬¶°©MÀˬd¤èªk¡AÁÙ°Q½×¤F¦UºØ¤é§Ó¬[ºcªºÀu¯ÊÂI¡C±µ¤U¨Ó¡A§Ú­Ì±Mªù°Q½×¹ï¥æ´«¾÷¡B¸ô¥Ñ¾¹¥H¤Î¨¾¤õùÙ¡X¡X³o¨Çºc¦¨¤F§Ú­Ìºôµ¸°©¤z³¡¤Àªº³]³Æªº¨úÃÒ½Õ¬d§Þ¥©¡C¥Ñ¤_Web¥N²z¤éÁͬy¦æ¡A¦Ó¥B¨ä¤¤±`±`§t¦³³\¦h´I¦³»ù­ÈªºÃÒ¾Ú¡A¦]¦¹§Ú­Ì±N¸Ô²Ó°Q½×Web¥N²z¤¤ÃÒ¾Úªº¦¬¶°©M¤ÀªR¤èªk¡C
²Ä¤T³¡¤À¤¤¥]§t¥H¤U³¹¸`¡G
²Ä8³¹¡m¨Æ¥ó¤é§Óªº»E¦X¡BÃöÁp©M¤ÀªR¡n¡A°Q½×±q¤£¦Pªº·½¡A¥]¬A±qªA°È¾¹©Î¤u§@¯¸ªº¾Þ§@¨t²Î¡]¤ñ¦pWindows¡BLinux©MUNIX¡^¡BÀ³¥Îµ{§Ç¡Bºôµ¸³]³Æ©Mª«²z³]³Æ¤¤¡A¦¬¶°©M¤ÀªR¤é§Óªº¤èªk¡C
²Ä9³¹¡m¥æ´«¾÷¡B¸ô¥Ñ¾¹¡B¨¾¤õùÙ¡n¡A¬ã¨s¦p¦ó±q¤£¦Pªººôµ¸³]³Æ¤¤¦¬¶°ÃÒ¾Ú¡A¥H¤Î®Ú¾Ú¤£¦Pªº±µ¤f©MÃÒ¾Úªº©ö·À¥¢¯Å§O¡A¦¬¶°ÃÒ¾Úªºµ¦²¤¡C
²Ä10³¹¡mWeb¥N²z¡n¡A¦^ÅU¤FWeb¥N²z¤é¯q¬y¦æªºÁͶաA¥H¤Î½Õ¬d¤H­û¦p¦ó§Q¥Î³o¨Ç³]³Æ¦¬¶°¤Wºô¨R®öªº¾ú¥v°O¿ý¡A¬Æ¦Ü¬O½w¦s¤U¨ÓªºWeb¹ï¶Hªº°Æ¥»¡C
0.2.4 ²Ä¥|³¡¤À °ª¯ÅijÃD
²Ä¥|³¡¤À¡m°ª¯ÅijÃD¡n°Q½×¤Fºôµ¸¨úÃÒ¤¤³Ì¥O¤HµÛ°gªº¨â­ÓijÃD¡Gºôµ¸ÀG¹D©M´c·N³n¥ó¡C§Ú­Ì±N¦^ÅUºôµ¸ÀG¹Dªº¦Xªk©Ê©MÁô½ª©Ê¡A¦}°Q½×³B²z¤£¦PÃþ«¬ÀG¹D®Éªº½Õ¬dµ¦²¤¡C¬°¤F¨Ï±Ô­z¤º®e§¹³Æ¡A§Ú­ÌÁÙ±N¦^ÅU´c·N³n¥óªºµo®i¾ú¥v¤Î¨ä¹ï¨úÃÒ¤ÀªR²£¥Íªº¼vÅT¡A¨ä¤¤¥]¬A©R¥O©M±±¨î«H¹Dªº¶i¤Æ¥v¡B»ø¤rºôµ¸¡B³WÁ×IDS/IPSªºÀË´ú¥H¤Î°ª¯Å«ùÄò©Ê«Â¯Ù¡]Advanced Persistent Threat¡AAPT¡^
²Ä¥|³¡¤À¥]¬A¥H¤U³¹¸`¡G
²Ä11³¹¡mºôµ¸ÀG¹D¡n¡A°Q½×¤Fºôµ¸ÀG¹Dªº¦Xªk©Ê©MÁô½ª©Ê¡AÃѧOÀG¹Dªº¤èªk¥H¤Î­«ºc¸gÀG¹D¶Ç¿éªº¬y¶q¤¤ªºÃÒ¾Úªºµ¦²¤¡C
²Ä12³¹¡m´c·N³n¥ó¨úÃÒ¡n¡A¦b³o¤@³¹¨½±N·§­z´c·N³n¥ó¶}µoªºÂ²¥v¡A¥]¬A©R¥O©M±±¨î«H¹Dªº¶i¤Æ¡B»ø¤rºôµ¸¡B³WÁ×IDS/IPSªºÀË´ú¥H¤Î°ª¯Å«ùÄò©Ê«Â¯Ù¡]APT¡^¡C¦b³o¤@¹Lµ{¤¤¡A§Ú­ÌÁÙ±N¬ï´¡°Q½×´c·N³n¥ó¹ï¨úÃÒ½Õ¬dªº¼vÅT¡A¥H¤Î¨úÃÒ½Õ¬d¬O¦p¦ó§ïÅÜ´c·N³n¥óªº¡C
0.3 ¤u¨ã
¥»®Ñ¤º®eªº½s±Æ­±¦V³Ì¼s¤jªºÅªªÌ¡A±Ð§Aºôµ¸¨úÃÒªº°ò¥»­ì«h©M§Þ³N¡CºÉºÞ¦³³\¦h°Ó¥Îªº¡BÂIÂI¹«¼Ð´N¯àÀ°§U§A§ä¨ì¦P¼Ëµª®×ªº¤u¨ã¡A¦Ó¥B§Ú­Ì¦b®Ñ¤¤¤]·|ªxªx¦a¤¶²Ð¨ä¤¤ªº¤@¨Ç¡C¦ý¬O§Ú­ÌÁÙ¬OµÛ­«¤¶²Ð¨º¨Ç¥i¥H§K¶OÀò±o¡A¦P®É¤]¯à¥Î¨Óºt¥Ü°ò¥»§Þ³Nªº¤u¨ã¡C³q¹L³o¤@¤è¦¡¡A§Ú­Ì§Æ±æ¯àÅý§A²z¸Ñ¨úÃÒ¤u¨ãªº©³¼h¤u§@­ì²z¡A¾Ö¦³ÅçÃҦ۰ʤƤu¨ã±o¥Xªºµ²½×¡A¥H¤Î¦b½Õ¬d¹Lµ{¤¤¿ï¥Î¥¿½T¤u¨ãªº¯à¤O¡C
0.4 ®×¨Ò
²Ä¤G¡B¤T¡B¥|³¡¤Àªº¨C¤@³¹¤¤³£·|¦w±Æ¤@­Ó¸Ô²Óªº®×¨Ò¡A¥Î¥H®i¥Ü³o¤@³¹¤¤°Q½×ªº¤u¨ã©M§Þ³N¡C§A¥i¥H§âÃÒ¾Ú¤å¥ó¤U¸ü¨ì§A¦Û¤vªº¨úÃÒ¤u§@¯¸¤¤¡A¦}¿Ë¦Û°Ê¤â¤ÀªR¥¦­Ì¡C
³o¨Ç®×¨Ò¤¤ªºÃÒ¾Ú¤å¥ó¦ì¤_¡G
http://lmgsecurity.com/nf/
§A¥i¥H§K¶O¨Ï¥Î¥¦­Ì¡A¦ý¶È­­¤_­Ó¤H¨Ï¥Î¡C
0.5 °É»~ªí
¥ô¦ó¤@¥»³o¤\«p¡B«H®§¶q³o¤\¤jªº®Ñ¤¤¡A³£¤£¥iÁקK¦a·|¦³¤@¨Ç¿ù»~¡A§Ú­Ì§â°É»~ªí©ñ¦b¤U­±³o­Óºô§}¤¤¡G
http://lmgsecurity.com/nf/errata
¦pªG§A§ä¨ì¤F¤@­Ó¿ù»~¡A§Ú­Ì±N«Ü°ª¿³¯àª¾¹D¥¦¡A½Ðµ¹§Ú­Ìµo°e¹q¤l¶l¥ó¡Gerrata@lmgsecurity. com¡C¤£¹L¦b¼g«H¤§«e¡A½Ð¥ý¹ï·Ó¤@¤U°É»~ªí¡A¤£­n­«´_µo°e°É»~ªí¤W¤w¦³ªº¤º®e¡C
0.6 ³Ì¦Z¤@ÂI»¡©ú
¥»®Ñ¬O·Rªºµ²´¹¡C¨C¤@³¹³£ªá±¼¤FµL¼Æ¬ã¨s¡B°Q½×¡B½èºÃ©M¼g§@ªº®É¶¡¡C¦b½s¼g®×¨Ò¤Î¬ÛÃö§ì¥]¤å¥ó®É¡A§Ú­Ì±Mªùºc«Ø¤F¤@­Ó¬Û·í¤_¤@­Ó¤p«¬°Ó°Èºôµ¸ªº¹êÅç«Ç¡C¦b¨C¤@¦¸½m²ß¡B½s¼g¨C¤@­Ó³õ´º®É¡A§Ú­Ì³£¤Ï´_°t¸m/­«·s°t¸m³o­Óºôµ¸¡AµM¦Z¤@¹M¤S¤@¹M¦a¹B¦æ¬ÛÃö³õ´º¡Aª½¨ì±o¨ìªº©Ò¦³µ²ªG³£§¹¥þ¥¿½T¬°¤î¡C
µL¼Æ­Ó¥Õ¤Ñ¶Â©]¡AµL¼Æ¦¸¤Ï´_¶}ÃöªºÂ_¸ô¶}Ãö¡AµL¼Æ¶ô±¾±¼ªºµw½L¡AµL¼ÆÅø©ñ·Å¤Fªº°à°s©MµL¼Æ¶ô©ñ²D¤Fªº¤ñÂÄ¡X¡X³Ì²×¦¨´N¤F¥»®Ñ¡CºÉºÞ³o¥»®Ñ¤w¸g¦³´X¦Ê­¶«p¤F¡A¦ý§Ú­Ì¤´ÂÂı±o§Ú­Ì¥u¬Oªxªx¦a¤¶²Ð¤F³Õ¤jºë²`ªººôµ¸¨úÃÒ¤u§@¤¤¤@¨Ç½§²Lªº¤º®e¡C§Ú­Ì±q¥I¥XªºÁ}­W³Ò°Ê¤¤¾Ç¨ì¤F«Ü¦hªF¦è¡A§Æ±æ§A¤]¬O¡C








­P ÁÂ

¦pªG¨S¦³¨â¦ì¼s¨ü´L·qªº¦w¥þ±M®a¡GRob Lee ©M Ed Skoudisªº¤ä«ù¡A³o¥»®Ñ¤£¥i¯à°Ý¥@¡C¤T¦~«e¡ARob Lee©Ô§Ú­Ì¥h¬°SANS¨ó·|¶}³]¤@ªùºôµ¸¨úÃÒ½Òµ{¡C³o¬O§Ú­Ì²Ä¤@¦¸§â¦@¦Pªº¤~´¼¥æ¶×¦b³o­Ó¥DÃD¤W¡A¦}¥¿¦¡µ¹³o¤@¤u§@ªº¥DÅé°_¤F­Ó¦W¦r¡C¥´¨º¥H¦Z¡ARob´N¦¨¤F§Úªº¨}®v¯q¤Í¡A¤£Â_±À°Ê§Ú­Ì§ï¶i¤u§@¡A§l¨ú¤ÏõX·N¨£¥H¤Î©Ý®i§Ú­Ìª¾ÃѪº·¥­­¡CRob¡A·PÁ§Aªº°ª¼Ð·Ç¡B¶}¸Û¥¬¤½ªº·N¨£¡A¥H¤Î³Ì­«­nªº¡X¡X¹ï§Ú­Ìªº«H¥ô¡C¨S¦³§A¡A§Ú­Ì¤£¥i¯à§¹¦¨³o¥»®Ñ¡C
ÁÙ¦³Ed¡A¬O§A¹ªÀy§Ú­Ì¼g¥X¤F³o¥»®Ñ¡A¦}ªá®É¶¡§â§Ú­Ì¤¶²Ðµ¹§A­Ìªº½s¿è¡C¦b³o¤@¹Lµ{¤¤¡A§Aªº«Øij³QÃÒ©ú¬OµL»ùªº¡C·PÁ§AªºÀ°§U©M¤ä«ù¡AEd¡A§Ú­Ì·|¥Ã»··P¿E§A¡C
·PÁ¬°¥Xª©³o¥»®Ñªá¤F¤j¶qªº®É¶¡©Mºë¤OªºPearson¥Xª©ªÀªº¥þÅé¤u§@¤H­û¡A¯S§O¬O¥»®Ñªº½s¿è¦Ñ®vChris Guzikowski¡A¦P®ÉÁÙ¦³Jessica Goldstein, Raina Chrobak, Julie Nahil, Olivia Basegio, Chris Zahn, Karen Gettman, Chuti Prasertsith, John Fuller©MElizabeth Ryan¦Ñ®v¡A¦b¦¹¤@¦}·PÁ¡C¦P®É¤]¯S§O·PÁÂLaserwords¹Î¶¤¬°¥»®Ñªº¥Xª©¥I¥Xªº§V¤O¡A¯S§O·PÁÂPatty Donovanªº­@¤ß«ü¾É¡C
«D±`·PÁÂJonah Elgart¬°¥»®Ñ³Ð§@ªººë¬ü«Ê­±¡C§Ú­Ì¤]«D±`ªY½à¥»®Ñ§Ç¨¥ªº§@ªÌDan Geer³Õ¤hªº¤u§@¡C¥t¥~¡A§Ú­Ì¤]«D±`·PÁ¬°¥»®Ñ¶i¦æ§Þ³N¼f®ÕªºªB¤Í©M¦P¤¯­Ì¡A¥L­Ì¬O¡GMichael Ford, Erik Hjelmvik, Randy Marchany, Craig Wright©MJoshua Wright¡C¥L­Ìªº·N¨£©M¹ï²Ó¸`ªºÃöª`¬°¥»®Ñ¼W½÷µL­­¡C
§Ú­Ì¤]·Q§âÅw©I°eµ¹§Ú­ÌLMG Security¹Î¶¤ªºÀu¨qªº²Õ­û­Ì¡A¯S§O¬OEric Fulton, Jody Miller, Randi Price, Scott Fretheim, David Harrison©MDiane Byrne¡A§A­Ì¦bÀ°§U§Ú­Ì¶i¦æºôµ¸¨úÃÒ§Þ³N¬ã¨s©M½Òµ{¶}µo¤Wªá¤F¤j¶qªº®É¶¡¡CEric Fulton¬OForensicsContest.comºô¯¸¤W¦h­ÓÁ¼ÃDªº½s¼gªÌ¡A¥»®Ñ¤¤ªº¤@¨Ç®×¨Ò¡A¯S§O¬O¡§HackMe¡¨©M¡§Annªº·¥¥ú¦æ°Ê¡¨¡A´N¬O±q³o¨ÇÁ¼ÃD¨º¨½µo®i¦Ó¨Óªº¡CJody Miller¡A¦b§A¨R¶i¨Ó¡AÂ\¥­¤F¾uÅ\¤ýªº¨¸´cÅ]¤O¤§¦Z¡A§A´N¦¨¤F§Ú­Ìªºµwº~¡X¡X§c¡A§Ú¬O»¡¡A§A²Î¤@¤F¥»®Ñ©Ò¦³ª`ÄÀªº®æ¦¡¡]±Nªñ500¦æ¡I¡^¡C
·PÁ§ڭ̪ºªB¤Í¡B¦P¨Æ¥H¤Î±Ð¾É¤F§Ú­Ì¦h¦~ªº¾É®v¡GShane Vannatta, Marsha¡®Bill Dahlgren, Pohl Longsine, Gary Longsine, John Strand, Michael P. Kenny, Gary ¡® Pue Williams¡A¡]¬ü°ê¡^¤¤¦è³¡ªº¦n¶m¿Ë­Ì¡AMike Poor, Kevin Johnson, Alan Ptak, Michael Grinberg, Sarah ¡® Kerry Metlen, Anissa Schroeder, Bradley Coleman, Blake Brasher, Stephanie Henry, Nadia Madden ©M Jon McElroy, Clay Ward¡A³Â¬Ù²z¤u¾Ç°|¾Ç¥Í«H®§³B²zªO¡]Student Information Processing Board¡ASIPB¡^¡AWally Deschene, Steven ¡® Linda Abate, Karl Reinhard, Brad Cool, Nick Lewis, Richard Souza, Paul Asadoorian, Larry Pesce, George Bakos, Johannes Ullrich, Paul A. Henry, Rick Smith, Guy Bruneau, Lenny Zeltser, Eric Cole, Judy Novak, Alan Tu, Fabienne van Cappel, Robert C de Baca, Mark Galassi©MDan Starr¡C
¯S§O·PÁÂSANS¨ó·|ªº±Ð¾­û¤u¡A¤×¨ä¬O¡GSteven ¡® Kathy Northcutt¡ADeb Jorgensen¡AKatherine Webb Calhoon¡ALana Emery¡AKate Marshall¡AVelda Lempka¡ANorris Campbell©MLynn Lewis¡C
§Ú­Ì¤]­n·PÁ¨C¤@¦ì¦bForensicsContest.com¤W°µ¥X¹L°^Ämªº¤H¡X¡X¤£½×±z¬O­ì³Ð¤F¤u¨ã/¤å³¹¡A¦^©«¡AÁÙ¬O¥u¬O¬°¤F¦nª±¤~¨Óªº¡C§Ú­Ì³£±q§A­Ì¨­¤W¾Ç¨ì¤F«Ü¦h¡I
·PÁ¦b¥»®Ñ½s¼g¹Lµ{¤¤¤@ª½¹ªÀy©M¤ä«ù§Ú­Ìªº®a¤H¡A¯S§O¬O¡GSheila Temkin Davidoff, E. Martin Davidoff, Philip ¡® Lynda Ham, Barbara ¡® Larry Oltmanns, Laura Davidoff, Michele Kirk, ©MNaomi Robertson, Latisha Mike, Makenna, Braelyn Monnier, Chad, Amy, Brady Rempel, Sheryl ¡® Tommy Davidoff, Jonathan ¡® Stefanie Davidoff, Jill ¡® Jake Dinov, Jamie ¡® Adam Levine, Annabelle Temkin, Norman ¡® Eileen Shoenfeld, Brian ¡® Marie Shoenfeld¡A¥H¤ÎDebbie Shoenfeld¡C
·PÁ§ڭ̪º¤p¿ß¡X¡XShark¡A¦b§Ú­Ì¼g§@ªº³o¤W¦Ê­Ó¤p®É¨½¡A§A¤@ª½¨Ì°¹¦b§Ú­Ì¨­Ãä¡C

³Ì­«­nªº¡X¡X·PÁ§ڭ̪º¨â­Ó¤k¨à¡GCharlie©MViolet¡A³o¥»®Ñ¬O¼gµ¹§A­Ìªº¡C
¤º®e²¤¶¡G

ºôµ¸¨úÃÒ¬O­pºâ¾÷¨úÃÒ§Þ³Nªº¤@­Ó·sªºµo®i¤è¦V¡A¬O­pºâ¾÷ºôµ¸§Þ³N»Pªk¾Çªº¥æ¤e¾Ç¬ì¡C¥»®Ñ¬Oºôµ¸¨úÃҤ譱ªº²Ä¤@¥»±MµÛ¡A¤@¸g¥Xª©«K¦nµû¦p¼é¡A¦bAmazonºô¯¸¤Wªºµû¤À¹F4.5¬P¡C
¥»®Ñ®Ú¾Úºôµ¸¨úÃÒ½Õ¬d¤H­ûªº¹ê»Ú»Ý­n¡A·§­z¤Fºôµ¸¨úÃÒªº¦U­Ó¤è­±¡A¤£½×¬O¹ï¦UºØºôµ¸¨óijªº¤ÀªR©M¹ï¦UºØºôµ¸³]³Æªº³B²z¤è¦¡¡AÁÙ¬O¨úÃÒ¬yµ{ªº³]­p³£¦³¿W¨ì¤§³B¡C
¥»®Ñ¦@¤À¥|¤j³¡¤À¤Q¤G³¹¡A²Ä1³¹¡§¹ê¥Î½Õ¬dµ¦²¤¡¨¡A²Ä2³¹¡§§Þ³N°ò¦¡¨©M²Ä3³¹¡§ÃÒ¾ÚÀò¨ú¡¨Äݤ_²Ä¤@³¡¤À¡A¨ä¤¤µ¹¥X¤F¤@­Ó¨úÃÒªº¤èªk®Ø¬[¡A¦}¤¶²Ð¤F¬ÛÃöªº°ò¦ª¾ÃÑ¡F²Ä4³¹¡§¼Æ¾Ú¥]¤ÀªR¡¨¡A²Ä5³¹¡§¬y²Î­p¤ÀªR¡¨¡B²Ä6³¹¡§µL½u¡GµL¶·ºô½uªº¨úÃÒ¡¨©M²Ä7³¹¡§ºôµ¸¤J«Iªº°»´ú¤Î¤ÀªR¡¨Äݤ_²Ä¤G³¡¤À¡A¤¶²Ð¤F¹ïºôµ¸¬y¶q¶i¦æ¤ÀªRªº¦UºØ§Þ³N¡F²Ä8³¹¡§¨Æ¥ó¤é§Óªº»E¦X¡BÃöÁp©M¤ÀªR¡¨¡B²Ä9³¹¡§¥æ´«¾¹¡B¸ô¥Ñ¾¹¡B¨¾¤õùÙ¡¨©M²Ä10³¹¡§Web¥N²z¡¨Äݤ_²Ä¤T³¡¤À¡A¸Ô­z¤F¦b¦UºØºôµ¸³]³Æ©MªA°È¾¹¤¤Àò¨ú©M¤ÀªRÃÒ¾Úªº¤èªk¡C²Ä11³¹¡§ºôµ¸ÀG¹D¡¨©M²Ä12³¹¡§´c·N³n¥ó¨úÃÒ¡¨Äݤ_²Ä¥|³¡¤À¡A°w¹ïºôµ¸ÀG¹D©M´c·N³n¥ó¤ÀªR³o¨â­Óºôµ¸¨úÃÒ¤¤ªºÃøÂI©M¼öÂI°ÝÃD®i¶}°Q½×¡C

¥Ø¿ý¡G

²Ä¤@³¡¤À °ò¦½g
²Ä1³¹ ¹ê¥Î½Õ¬dµ¦²¤ 2
1.1 ¯u¹êªº®×¨Ò 2
1.1.1 Âå°|¨½³Qµsªºµ§°O¥»¹q¸£ 3
1.1.2 µo²{¤½¥qªººôµ¸³Q¥Î¤_¶Ç¼½µsª© 5
1.1.3 ³Q¶Âªº¬F©²ªA°È¾¹ 6
1.2 ¨¬¸ñ 7
1.3 ¹q¤lÃÒ¾Úªº·§©À 8
1.3.1 ¹êª«ÃÒ¾Ú 9
1.3.2 ³Ì¨ÎÃÒ¾Ú 9
1.3.3 ª½±µÃÒ¾Ú 10
1.3.4 ±¡ªpÃÒ¾Ú 11
1.3.5 ¶Ç»DÃÒ¾Ú 11
1.3.6 ¸gÀç°O¿ý 12
1.3.7 ¹q¤lÃÒ¾Ú 13
1.3.8 °ò¤_ºôµ¸ªº¹q¤lÃÒ¾Ú 14
1.4 Ãö¤_ºôµ¸ÃÒ¾Ú¬ÛÃöªº¬D¾Ô 14
1.5 ºôµ¸¨úÃÒ½Õ¬d¤èªk¡]OSCAR¡^ 15
1.5.1 Àò¨ú«H®§ 15
1.5.2 ¨î­q¤è®× 16
1.5.3 ¦¬¶°ÃÒ¾Ú 17
1.5.4 ¤ÀªR 18
1.5.5 ¥X¨ã³ø§i 19
1.6 ¤pµ² 19
²Ä2³¹ §Þ³N°ò¦ 21
2.1 °ò¤_ºôµ¸ªºÃÒ¾Ú¨Ó·½ 21
2.1.1 ª«²z½uÆl 22
2.1.2 µL½uºôµ¸ªÅ¤f 22
2.1.3 ¥æ´«¾÷ 23
2.1.4 ¸ô¥Ñ¾¹ 23
2.1.5 DHCPªA°È¾¹ 24
2.1.6 °ì¦WªA°È¾¹ 24
2.1.7 µn¿ý»{ÃÒªA°È¾¹ 25
2.1.8 ºôµ¸¤J«IÀË´ú/¨¾±s¨t²Î 25
2.1.9 ¨¾¤õùÙ 25
2.1.10 Web¥N²z 26
2.1.11 À³¥ÎªA°È¾¹ 27
2.1.12 ¤¤¥¡¤é§ÓªA°È¾¹ 27
2.2 ¤¬Ápºôªº¤u§@­ì²z 27
2.2.1 ¨óij 28
2.2.2 ¶}©ñ¨t²Î¤¬³s¼Ò«¬ 29
2.2.3 ¨Ò¤l¡G©P´å¥@¬É¡K¡KµM¦Z¦A¦^¨Ó 30
2.3 ¤¬Ápºô¨óij²Õ 32
2.3.1 ¤¬Ápºô¨óij²Õªº¦­´Á¾ú¥v©M¶}µo¹Lµ{ 33
2.3.2 ºô»Ú¨óij 34
2.3.3 ¶Ç¿é±±¨î¨óij 38
2.3.4 ¥Î¤á¼Æ¾Ú³ø¨óij 40
2.4 ¤pµ² 42
²Ä3³¹ ÃÒ¾ÚÀò¨ú 43
3.1 ª«²z°»Å¥ 43
3.1.1 ½uÆl 44
3.1.2 µL½u¹qÀW²v 48
3.1.3 Hub 49
3.1.4 ¥æ´«¾÷ 50
3.2 ¬y¶q§ì¨ú³n¥ó 52
3.2.1 libpcap©MWinPcap 53
3.2.2 §B§J§Q¥]¹LÂo¡]Berkeley Packet Filter¡ABPF¡^»y¨¥ 53
3.2.3 tcpdump 57
3.2.4 Wireshark 61
3.2.5 tshark 62
3.2.6 dumpcap 62
3.3 ¥D°Ê¦¡Àò¨ú 63
3.3.1 ±`¥Î±µ¤f 63
3.3.2 ¨S¦³Åv­­®É©Q¿ì 68
3.3.3 µ¦²¤ 68
3.4 ¤pµ² 69
²Ä¤G³¡¤À ¼Æ¾Ú¬y¤ÀªR
²Ä4³¹ ¼Æ¾Ú¥]¤ÀªR 72
4.1 ¨óij¤ÀªR 73
4.1.1 ­þ¨½¥i¥H±o¨ì¨óij«H®§ 73
4.1.2 ¨óij¤ÀªR¤u¨ã 76
4.1.3 ¨óij¤ÀªR§Þ¥© 79
4.2 ¥]¤ÀªR 91
4.2.1 ¥]¤ÀªR¤u¨ã 91
4.2.2 ¥]¤ÀªR§Þ³N 94
4.3 ¬y¤ÀªR 99
4.3.1 ¬y¤ÀªR¤u¨ã 100
4.3.2 ¬y¤ÀªR§Þ³N 103
4.4 ¤ÀªR§ó°ª¼hªº¶Ç¿é¨óij 113
4.4.1 ¤@¨Ç±`¥Îªº°ª¼h¨óij 114
4.4.2 °ª¼h¨óij¤ÀªR¤u¨ã 122
4.4.3 °ª¼h¨óij¤ÀªR§Þ³N 124
4.5 µ²½× 127
4.6 ®×¨Ò¬ã¨s¡GAnnªº¬ù·| 127
4.6.1 ¤ÀªR¡G¨óij·§­n 128
4.6.2 DHCP³q«H 128
4.6.3 ÃöÁäµü·j¯Á 130
4.6.4 SMTP¤ÀªR¡X¡XWireshark 133
4.6.5 SMTP¤ÀªR¡X¡XTCPFlow 136
4.6.6 SMTP ¤ÀªR¡X¡Xªþ¥ó´£¨ú 137
4.6.7 ¬d¬Ýªþ¥ó 139
4.6.8 §ä¨ìAnnªºÂ²³æ¤èªk 140
4.6.9 ®É¶¡½u 145
4.6.10 ®×¥óªº²z½×±À¾É 145
4.6.11 ¬D¾ÔÁÉ°ÝÃDªºÀ³µª 146
4.6.12 ¤U¤@¨B 148
²Ä5³¹ ¬y²Î­p¤ÀªR 149
5.1 ³B²z¹Lµ{·§­z 150
5.2 ¶Ç·P¾¹ 151
5.2.1 ¶Ç·P¾¹Ãþ«¬ 151
5.2.2 ¶Ç·P¾¹³n¥ó 152
5.2.3 ¶Ç·P¾¹¦ì¸m 153
5.2.4 ­×§ïÀô¹Ò 154
5.3 ¬y°O¿ý¾É¥X¨óij 155
5.3.1 NetFlow 155
5.3.2 IPFIX 156
5.3.3 sFlow 156
5.4 ¦¬¶°©M¶×Á` 157
5.4.1 ¦¬¶°¾¹ªº¦ì¸m©M¬[ºc 157
5.4.2 ¼Æ¾Ú¦¬¶°¨t²Î 158
5.5 ¤ÀªR 160
5.5.1 ¬y°O¿ý¤ÀªR§Þ³N 160
5.5.2 ¬y°O¿ý¤ÀªR¤u¨ã 164
5.6 µ²½× 169
5.7 ®×¨Ò¬ã¨s¡G©_©ÇªºX¥ý¥Í 169
5.7.1 ¤ÀªR¡G²Ä¤@¨B 170
5.7.2 ¥~³¡§ðÀ»ªÌ©MºÝ¤f22ªº³q«H 171
5.7.3 DMZ¤¤ªº¨ü®`ªÌ¡X¡X10.30.30.20¡]¤]¬O172.30.1.231¡^ 174
5.7.4 ¤º³¡¨ü®`¨t²Î¡X¡X192.30.1.101 178
5.7.5 ®É¶¡½u 179
5.7.6 ®×¥ó¤ÀªR 180
5.7.7 ¦^À³¬D¾ÔÁÉ°ÝÃD 180
5.7.8 ¤U¤@¨B 181
²Ä6³¹ µL½u¡GµL¶·ºô½uªº¨úÃÒ 183
6.1 IEEE ²Ä¤G¼h¨óij¨t¦C 184
6.1.1 ¬°¤°¤\¨º¤\¦h²Ä¤G¼h¨óij 185
6.1.2 802.11 ¨óij±Ú 186
6.1.3 802.1X 195
6.2 µL½u±µ¤JÂI¡]WAP¡^ 196
6.2.1 ¬°¤°¤\­n½Õ¬dµL½u±µ¤JÂI 196
6.2.2 µL½u±µ¤JÂIªºÃþ«¬ 196
6.2.3 WAPÃÒ¾Ú 200
6.3 µL½u¼Æ¾Ú®·Àò¤Î¤ÀªR 201
6.3.1 ÀWÃФÀªR 201
6.3.2 µL½u³Q°ÊÃÒ¾Ú¦¬¶° 202
6.3.3 ¦³®Ä¦a¤ÀªR802.11 203
6.4 ±`¨£§ðÀ»Ãþ«¬ 205
6.4.1 ¶å±´ 205
6.4.2 ¥¼±ÂÅvªºµL½u±µ¤JÂI 205
6.4.3 ¨¸´cÂù¤l 208
6.4.4 WEP¯}¸Ñ 208
6.5 ©w¦ìµL½u³]³Æ 209
6.5.1 Àò¨ú³]³Æ´y­z 210
6.5.2 §ä¥XªþªñªºµL½u±µ¤JÂI 210
6.5.3 «H¸¹±j«× 211
6.5.4 °Ó·~¤Æ¥ø·~¯Å¤u¨ã 213
6.5.5 Skyhook 214
6.6 Á`µ² 215
6.7 ®×¨Ò¬ã¨s¡GHackMe¤½¥q 215
6.7.1 ½Õ¬dWAP 216
6.7.2 §Ö³t²Ê²¤ªº²Î­p 221
6.7.3 ¹ï¤_ºÞ²z´Vªº²`¼h¦¸Æ[¹î 226
6.7.4 ¤@­Ó¥i¯àªº¡§¶ûºÃ¥Ç¡¨ 228
6.7.5 ®É¶¡½u 229
6.7.6 ®×¨ÒÁ`µ² 230
6.7.7 ¬D¾Ô°ÝÃDªºÀ³µª 231
6.7.8 ¤U¤@¨B 233
²Ä7³¹ ºôµ¸¤J«Iªº°»´ú¤Î¤ÀªR 235
7.1 ¬°¤°¤\­n½Õ¬dNIDS/NIPS 236
7.2 NIDS/NIPSªº¨å«¬¥\¯à 236
7.2.1 ¶å±´ 236
7.2.2 °ª¼h¨óij¿ëÃÑ 237
7.2.3 ¥iºÃ¦r¸`ªº³øĵ 238
7.3 ÀË´úªº¼Ò¦¡ 239
7.3.1 °ò¤_¯S©ºªº¤ÀªR 239
7.3.2 ¨óij¿ëÃÑ 239
7.3.3 ¦æ¬°¤ÀªR 239
7.4 NIDS/NIPSªººØÃþ 239
7.4.1 °Ó·~¤ÆNIDS/NIPS 239
7.4.2 ¦Û§Ú©w¨î 241
7.5 NIDS/NIPSªº¹q¤lÃÒ¾Úªö¶° 241
7.5.1 ¹q¤lÃÒ¾ÚÃþ«¬ 241
7.5.2 NIDS/NIPS¬É­± 243
7.6 ºî¦X©Êºôµ¸«Ê¥]¤é§Ó 244
7.7 Snort¨t²Î 245
7.7.1 °ò¥»µ²ºc 246
7.7.2 °t¸m 246
7.7.3 Snort³W«h»y¨¥ 247
7.7.4 ¨Ò¤l 249
7.8 Á`µ² 251
7.9 ±Ð¾Ç®×¨Ò¡GInter0ptic¬@±Ï¦a²y¡]²Ä¤@³¡¤À¡^ 252
7.9.1 ¤ÀªR¡GSnort ĵ³ø 253
7.9.2 ªì¨B¼Æ¾Ú¥]¤ÀªR 254
7.9.3 Snort³W«h¤ÀªR 255
7.9.4 ±qSnort§ì¥]¼Æ¾Ú¤¤´£¨ú¥iºÃ¤å¥ó 257
7.9.5 ¡§INFO Web Bug¡¨Äµ³ø 257
7.9.6 ¡§Tcp Window Scale Option¡¨Äµ³ø 259
7.9.7 ®É¶¡½u 261
7.9.8 ®×±¡±À´ú 261
7.9.9 ¤U¤@¨B 262
²Ä¤T³¡¤À ºôµ¸³]³Æ©MªA°È¾¹
²Ä8³¹ ¨Æ¥ó¤é§Óªº»E¦X¡BÃöÁp©M¤ÀªR 266
8.1 ¤é§Ó¨Ó·½ 267
8.1.1 ¾Þ§@¨t²Î¤é§Ó 267
8.1.2 À³¥Î¤é§Ó 275
8.1.3 ª«²z³]³Æ¤é§Ó 277
8.1.4 ºôµ¸³]³Æ¤é§Ó 279
8.2 ºôµ¸¤é§ÓªºÅé¨tµ²ºc 280
8.2.1 ¤TºØÃþ«¬ªº¤é§Ó°O¿ý¬[ºc 280
8.2.2 »·µ{¤é§Ó¡G±`¨£°ÝÃD¤ÎÀ³¹ï¤èªk 282
8.2.3 ¤é§Ó»E¦X©M¤ÀªR¤u¨ã 283
8.3 ¦¬¶°©M¤ÀªRÃÒ¾Ú 285
8.3.1 Àò¨ú«H®§ 285
8.3.2 µ¦²¤¨î©w 286
8.3.3 ¦¬¶°ÃÒ¾Ú 287
8.3.4 ¤ÀªR 289
8.3.5 ³ø§i 290
8.4 Á`µ² 290
8.5 ®×¨Ò¡GL0ne Sh4rkªº³ø´_ 290
8.5.1 ªì¨B¤ÀªR 291
8.5.2 ¥iµø¤Æ¥¢±Ñªºµn¿ý¹Á¸Õ 292
8.5.3 ¥Ø¼Ð½ã¤á 294
8.5.4 ¦¨¥\µn¿ý 295
8.5.5 §ð³´¦Zªº¬¡°Ê 296
8.5.6 ¨¾¤õùÙ¤é§Ó 297
8.5.7 ¤º³¡³Q®`ªÌ¡X¡X192.30.1.101 300
8.5.8 ®É¶¡½u 301
8.5.9 ®×¥óµ²½× 303
8.5.10 ¹ï¬D¾Ô°ÝÃDªºÀ³µª 303
8.5.11 ¤U¤@¨B 304
²Ä9³¹ ¥æ´«¾÷¡B¸ô¥Ñ¾¹©M¨¾¤õùÙ 305
9.1 ¦sÀx¤¶½è 305
9.2 ¥æ´«¾÷ 306
9.2.1 ¬°¤°¤\½Õ¬d¥æ´«¾÷ 306
9.2.2 ¤º®e´M§}¤º¦sªí 307
9.2.3 ¦a§}¸ÑªR¨óij 307
9.2.4 ¥æ´«¾÷Ãþ«¬ 308
9.2.5 ¥æ´«¾÷ÃÒ¾Ú 309
9.3 ¸ô¥Ñ¾¹ 310
9.3.1 ¬°¤°¤\½Õ¬d¸ô¥Ñ¾¹ 310
9.3.2 ¸ô¥Ñ¾¹Ãþ«¬ 310
9.3.3 ¸ô¥Ñ¾¹¤WªºÃÒ¾Ú 312
9.4 ¨¾¤õùÙ 313
9.4.1 ¬°¤°¤\½Õ¬d¨¾¤õùÙ 313
9.4.2 ¨¾¤õùÙÃþ«¬ 313
9.4.3 ¨¾¤õùÙÃÒ¾Ú 315
9.5 ±µ¤f 317
9.5.1 Web±µ¤f 317
9.5.2 ±±¨î»O©R¥O¦æ±µ¤f¡]CLI¡^ 318
9.5.3 »·µ{±±¨î»O 319
9.5.4 ²³æºôµ¸ºÞ²z¨óij¡]SNMP¡^ 319
9.5.5 ¨p¦³±µ¤f 320
9.6 ¤é§Ó 320
9.6.1 ¥»¦a¤é§Ó 321
9.6.2 ²³æºôµ¸ºÞ²z¨óij 322
9.6.3 syslog 322
9.6.4 ¨­¥÷ÅçÃÒ¡B±ÂÅv©M½ã¤á¤é§Ó 323
9.7 Á`µ² 323
9.8 ®×¨Ò¬ã¨s¡GAnnªº©@°ØÀô 323
9.8.1 ¨¾¤õùÙ¶EÂ_©R¥O 325
9.8.2 DHCPªA°È¤é§Ó 326
9.8.3 ¨¾¤õùÙ³X°Ý±±¨î¦Cªí 327
9.8.4 ¨¾¤õùÙ¤é§Ó¤ÀªR 327
9.8.5 ®É¶¡½u 331
9.8.6 ®×¨Ò¤ÀªR 332
9.8.7 ¬D¾Ô°ÝÃDªºµª´_ 333
9.8.8 ¤U¤@¨B 334
²Ä10³¹ Web¥N²z 335
10.1 ¬°¤°¤\­n½Õ¬dWeb¥N²z 335
10.2 Web¥N²zªº¥\¯à 337
10.2.1 ½w¦s 337
10.2.2 URI¹LÂo 339
10.2.3 ¤º®e¹LÂo 339
10.2.4 ¤À¥¬¦¡½w¦s 339
10.3 ÃÒ¾Ú 341
10.3.1 ÃÒ¾ÚªºÃþ«¬ 341
10.3.2 Àò¨úÃÒ¾Ú 342
10.4 Squid 342
10.4.1 Squidªº°t¸m¤å¥ó 343
10.4.2 SquidªºAccess¤é§Ó¤å¥ó 343
10.4.3 Squid½w¦s 344
10.5 Web¥N²z¤ÀªR 346
10.5.1 Web¥N²z¤é§Ó¤ÀªR¤u¨ã 347
10.5.2 ¨Ò¤l¡G­åªR¤@­ÓSquidºÏ½L½w¦s 350
10.6 ¥[±KªºWeb¬y¶q 357
10.6.1 TLS¡]¶Ç¿é¼h¦w¥þ¡^ 358
10.6.2 ³X°Ý¥[±Kªº¤º®e 360
10.6.3 °Ó¥ÎªºTLS/SSLÄdºI¤u¨ã 364
10.7 ¤pµ² 364
10.8 ±Ð¾Ç®×¨Ò¡GInter0ptic¬@±Ï¦a²y¡]¤§¤G¡^ 365
10.8.1 ¤ÀªR¡Gpwny.jpg 366
10.8.2 Squid½w¦sªººô­¶ªº´£¨ú 368
10.8.3 SquidªºAccess.log¤å¥ó 371
10.8.4 ¶i¤@¨B¤ÀªRSquid½w¦s 373
10.8.5 ®É¶¡½u 377
10.8.6 ®×±¡±À´ú 379
10.8.7 ¦^µª¤§«e´£¥Xªº°ÝÃD 380
10.8.8 ¤U¤@¨B 381
²Ä¥|³¡¤À °ª¯ÅijÃD
²Ä11³¹ ºôµ¸ÀG¹D 384
11.1 ¥\¯à«¬ÀG¹D 384
11.1.1 ­I´ºª¾ÃÑ¡GVLANÃì¸ô»E¶° 385
11.1.2 ¥æ´«¾÷¶¡Ãì¸ô¡]Inter-Switch Link¡AISL¡^ 385
11.1.3 ³q¥Î¸ô¥Ñ«Ê¸Ë¡]Generic Routing Encapsulation¡AGRE¡^ 386
11.1.4 Teredo¡GIPv4ºô¤WªºIPv6 386
11.1.5 ¹ï½Õ¬d¤H­ûªº·N¸q 387
11.2 ¥[±K«¬ÀG¹D 387
11.2.1 IPsec 388
11.2.2 TLS©MSSL 389
11.2.3 ¹ï¨úÃÒ¤H­ûªº¼vÅT 390
11.3 Áô½ª³q«H«¬ÀG¹D 391
11.3.1 µ¦²¤ 391
11.3.2 TCP§Ç¦C¸¹ 391
11.3.3 DNSÀG¹D 392
11.3.4 ICMPÀG¹D 393
11.3.5 ¨Ò¤l¡G¤ÀªRICMPÀG¹D 395
11.3.6 ¹ï½Õ¬d¤H­ûªº¼vÅT 398
11.4 ¤pµ² 399
11.5 ®×¨Ò±Ð¾Ç¡GAnnªº¯µ±KÀG¹D 400
11.5.1 ¤ÀªR¡G¨óij²Î­p 401
11.5.2 DNS¤ÀªR 402
11.5.3 °l¬dÀG¹D¶Ç¿éªºIP¥] 405
11.5.4 ¹ïÀG¹D¶Ç¿éªºIP¥]ªº¤ÀªR 409
11.5.5 ¹ïÀG¹D¶Ç¿éªºTCP³ø¤å¬qªº¤ÀªR 412
11.5.6 ®É¶¡½u 414
11.5.7 ®×±¡±À´ú 414
11.5.8 ¦^µª¤§«e´£¥Xªº°ÝÃD 415
11.5.9 ¤U¤@¨B 416
²Ä12³¹ ´c·N³n¥ó¨úÃÒ 418
12.1 ´c·N³n¥ó¶i¤ÆªºÁÍ¶Õ 419
12.1.1 »ø¤rºôµ¸ 419
12.1.2 ¥[±K©M²V²c 420
12.1.3 ¤À¥¬¦¡©R¥O©M±±¨î¨t²Î 422
12.1.4 ¦Û°Ê¦Û§Ú¤É¯Å 426
12.1.5 ÅܤƧκAªººôµ¸¦æ¬° 428
12.1.6 ²V¦bºôµ¸¬¡°Ê¤¤ 434
12.1.7 Fast-Flux DNS 436
12.1.8 °ª¯Å«ùÄò«Â¯Ù¡]Advanced Persistent Threat¡AAPT¡^ 437
12.2 ´c·N³n¥óªººôµ¸¦æ¬° 440
12.2.1 ¶Ç¼½ 441
12.2.2 ©R¥O©M±±¨î³q«H 443
12.2.3 ¸ü²üªº¦æ¬° 446
12.3 ¥¼¨Óªº´c·N³n¥ó©Mºôµ¸¨úÃÒ 446
12.4 ±Ð¾Ç®×¨Ò¡GAnnªº¡§·¥¥ú¦æ°Ê¡¨ 447
12.4.1 ¤ÀªR¡G¤J«IÀË´ú 447
12.4.2 TCP·|¸Ü¡G10.10.10.10:4444¡V10.10.10.70:1036 449
12.4.3 TCP·|¸Ü¡G10.10.10.10:4445 455
12.4.4 TCP·|¸Ü¡G10.10.10.10:8080¡V10.10.10.70:1035 461
12.4.5 ®É¶¡½u 466
12.4.6 ®×±¡±À´ú 467
12.4.7 ¦^µª¤§«e´£¥Xªº°ÝÃD 468
12.4.8 ¤U¤@¨B 468
¦Z°O 470
§Ç¡G