1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Tikugashirei kune nyowani nyowani yezvinyorwa, panguva ino pamusoro penyaya yekuferefeta chiitiko, kureva malware kuongororwa uchishandisa Check Point forensics. Isu takamboburitsa zvidzidzo zvevhidhiyo zvakawanda pakushanda muSmart Chiitiko, asi panguva ino isu tichatarisa kune forensics mishumo pane chaiyo zviitiko mune akasiyana Check Point zvigadzirwa:

Sei zviitiko zvekudzivirira zviitiko zvakakosha? Zvinoita sekunge wabata hutachiona, zvatonaka, wadii nazvo? Sezvinoratidzwa nemaitiro, zvinokurudzirwa kwete kungovhara kurwiswa, asiwo kuti unzwisise kuti inoshanda sei: nzvimbo yekupinda yaive yei, njodzi yakashandiswa sei, maitiro api anosanganisirwa, kana registry uye faira system zvinokanganiswa, ndeipi mhuri. zvemavhairasi, chii chinogona kukanganisa, nezvimwewo. Iyi uye imwe data inobatsira inogona kuwanikwa kubva kuCheck Point's yakazara forensics mishumo (zvese zvinyorwa uye graphical). Zvakaoma zvikuru kuwana mushumo wakadaro nemaoko. Iyi data inogona kubatsira kutora matanho akakodzera uye kudzivirira kurwiswa kwakafanana kubudirira mune ramangwana. Nhasi tichatarisa kuCheck Point SandBlast Network forensics report.

SandBlast Network

Kushandiswa kwemabhokisi ejecha kusimbisa kuchengetedzwa kwetiweki perimeter kwagara kwave kwakajairika uye kunosungirwa sechikamu se IPS. PaCheck Point, iyo Threat Emulation blade, inova chikamu cheSandBlast tekinoroji (kune zvakare Threat Extraction), ine basa rekuita kwebhokisi rejecha. Takatoburitsa kare kosi diki paCheck Point SandBlast uyewo nokuda kweshanduro yeGaia 77.30 (Ini ndinokurudzira zvikuru kuitarisa kana iwe usinganzwisisi zvatiri kutaura nezvazvo ikozvino). Kubva pakuona kwekuvaka, hapana chakachinja kubva ipapo. Kana iwe uine Cheki Point Gateway painotenderera yetiweki yako, saka unogona kushandisa maviri sarudzo yekubatanidza nejecha bhokisi:

  1. SandBlast Local Appliance - imwe yekuwedzera SandBlast appliance yakaiswa panetiweki yako, iyo mafaera anotumirwa kuti aongororwe.
  2. SandBlast Cloud - mafaera anotumirwa kuti aongororwe kune iyo Check Point gore.

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Bhokisi rejecha rinogona kutorwa semutsara wekupedzisira wekudzivirira pane network perimeter. Inobatanidza chete mushure mekuongorora nenzira dzechinyakare - antivirus, IPS. Uye kana maturusi echinyakare akadaro asingape chero analytics, saka bhokisi rejecha rinogona "kutaurira" zvakadzama kuti sei faira rakavharwa uye kuti chii charinoita zvakaipa. Iyi forensics report inogona kuwanikwa kubva kune ese emunharaunda uye gore sandbox.

Tarisa Point Forensics Report

Ngatiti iwe, senyanzvi yekuchengetedza ruzivo, wakauya kuzoshanda uye wakavhura dashboard muSmartConsole. Pakarepo iwe unoona zviitiko zvemaawa makumi maviri nemana apfuura uye kutarisisa kwako kunokweverwa kune Kutyisidzira Emulation zviitiko - zvakanyanya kurwiswa zvine njodzi izvo zvisina kuvharwa nekuongorora siginecha.

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Iwe unogona "kudonha" muzviitiko izvi uye woona matanda ese eThreat Emulation blade.

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Mushure meizvi, iwe unogona kuwedzera kusefa matanda nekutyisidzira kutsoropodza nhanho (Severity), pamwe neChivimbo Chikamu (kuvimbika kwemhinduro):

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Mushure mekuwedzera chiitiko chatinofarira, tinogona kujairana neruzivo rwese (src, dst, kuomarara, mutumi, nezvimwewo):

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Uye ipapo unogona kuona chikamu Forensics with available pfupiso report. Kudzvanya pairi kuchavhura kuongororwa kwakadzama kweiyo malware muchimiro cheinoshanda HTML peji:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network
(Ichi chikamu chepeji. Yekutanga inogona kutariswa pano)

Kubva pamushumo mumwechete, tinogona kudhawunirodha iyo yekutanga malware (mune password-yakachengetedzwa archive), kana nekukasira taura neCheck Point timu yekupindura.

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Pazasi iwe unogona kuona yakanaka animation inoratidza muzvikamu zvematemu izvo zvinotozivikanwa kodhi yakaipa iyo muenzaniso wedu wakafanana (kusanganisira iyo kodhi pachayo uye macros). Aya analytics anounzwa uchishandisa muchina kudzidza muCheck Point Threat Cloud.

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Ipapo iwe unogona kuona chaizvo izvo zviitiko mubhokisi rejecha zvakatibvumidza kugumisa kuti iyi faira ine hutsinye. Muchiitiko ichi, tinoona kushandiswa kwemaitiro ekupfuura uye kuedza kurodha ransomware:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Zvinogona kucherechedzwa kuti muchiitiko ichi, emulation yakaitwa mumasisitimu maviri (Win 7, Win XP) uye akasiyana software shanduro (Hofisi, Adobe). Pazasi pane vhidhiyo (slide show) ine maitiro ekuvhura iyi faira mubhokisi rejecha:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Vhidhiyo yemuenzaniso:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Pakupedzisira tinogona kuona zvakadzama kuti kurwisa kwacho kwakatanga sei. Ingave mune tabular fomu kana graphically:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

Ikoko isu tinogona kudhawunirodha ruzivo urwu muRAW fomati uye pcap faira yeakadzama analytics yeiyo inogadzirwa traffic muWireshark:

1. Kuongororwa kwemalware uchishandisa Check Point forensics. SandBlast Network

mhedziso

Uchishandisa ruzivo urwu, unogona kusimbisa zvakanyanya kuchengetedzwa kwetiweki yako. Vhara mavhairasi ekuparadzira mauto, vhara kudzvanyirirwa kusagadzikana, vhara mhinduro inobvira kubva kuC&C nezvimwe zvakawanda. Kuongorora uku hakufanirwe kuregererwa.

Muzvinyorwa zvinotevera, isu tichatarisa zvakafanana mishumo yeSandBlast Agent, SnadBlast Mobile, pamwe neCloudGiard SaaS. Saka gara wakatarisa (teregiramu, Facebook, VK, TS Solution Blog)!

Source: www.habr.com

Voeg