{"id":76039,"date":"2020-03-30T13:43:09","date_gmt":"2020-03-30T11:43:09","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery"},"modified":"2020-03-30T13:43:09","modified_gmt":"2020-03-30T11:43:09","slug":"kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery","title":{"rendered":"Si sistemet e analiz\u00ebs s\u00eb trafikut zbulojn\u00eb taktikat e hak\u00ebrave sipas MITRE ATT&amp;CK me shembullin e PT Network Attack Discovery","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/493082\/\"><img decoding=\"async\" alt=\"Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery\" src=\"\/wp-content\/uploads\/2020\/03\/75b6c4846867a15776529105f9657ffb.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.verizonenterprise.com\/resources\/reports\/rp_DBIR_2018_Report_execsummary_en_xg.pdf\">Sipas Verizon<\/a><\/noindex>, shumica (87%) e incidenteve t\u00eb siguris\u00eb ndodhin brenda disa minutash, nd\u00ebrsa zbulimi i tyre zgjat muaj p\u00ebr 68% t\u00eb kompanive. Kjo konfirmohet gjithashtu nga <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ibm.com\/security\/data-breach\">hulumtimi i Institutit Ponemon<\/a><\/noindex>, sipas t\u00eb cilit shumica e organizatave iu nevojitet mesatarisht 206 dit\u00eb p\u00ebr t\u00eb zbuluar nj\u00eb incident. Nga p\u00ebrvoja e hetimeve tona, haker\u00ebt mund t\u00eb kontrollojn\u00eb infrastruktur\u00ebn e nj\u00eb kompanie p\u00ebr vite t\u00eb t\u00ebra pa u zbuluar. N\u00eb nj\u00eb nga organizatat ku ekspert\u00ebt tan\u00eb kryen nj\u00eb hetim mbi nj\u00eb incident t\u00eb siguris\u00eb, u zbulua se haker\u00ebt kishin kontrolluar plot\u00ebsisht infrastruktur\u00ebn e organizat\u00ebs dhe rregullisht kishin vjedhur informacion t\u00eb r\u00ebnd\u00ebsish\u00ebm <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ptsecurity.com\/ru-ru\/research\/analytics\/operation-taskmasters-2019\/?sphrase_id=71910\">p\u00ebr gjasht\u00eb vjet<\/a><\/noindex>.<\/p>\n<p>Le t\u00eb supozojm\u00eb se ju tashm\u00eb keni nj\u00eb SIEM q\u00eb mbledh log-e dhe analizon ngjarje, dhe antiviruset jan\u00eb instaluar n\u00eb pik\u00ebt e fundit. Megjithat\u00eb, <noindex><a rel=\"nofollow\" href=\"https:\/\/safe.cnews.ru\/articles\/2019-10-15_pochemu_hakery_legko_vzlamyvayut_nasa\">nuk \u00ebsht\u00eb e mundur t\u00eb zbuloni gjith\u00e7ka me SIEM<\/a><\/noindex>, ashtu si nuk \u00ebsht\u00eb e mundur t\u00eb implementoni sisteme EDR p\u00ebr t\u00eb gjith\u00eb rrjetin, dhe kjo do t\u00eb thot\u00eb se nuk do t\u00eb shmangni 'zona t\u00eb verbra'. Sistemet e analiz\u00ebs s\u00eb trafikut t\u00eb rrjetit (network traffic analysis, NTA) ndihmojn\u00eb n\u00eb menaxhimin e tyre. K\u00ebto zgjidhje zbulojn\u00eb aktivitetin e sulmuesve n\u00eb fazat m\u00eb t\u00eb hershme t\u00eb dep\u00ebrtimit n\u00eb rrjet, si dhe gjat\u00eb p\u00ebrpjekjeve p\u00ebr t'u vendosur dhe zhvilluar sulmin brenda rrjetit. <\/p>\n<p>NTA jan\u00eb dy lloje: disa funksionojn\u00eb me NetFlow, t\u00eb tjerat analizojn\u00eb trafik t\u00eb pap\u00ebrpunuar. Avantazhi i sistemeve t\u00eb dyta \u00ebsht\u00eb se ato mund t\u00eb ruajn\u00eb regjistrimet e trafikut t\u00eb pap\u00ebrpunuar. Fal\u00eb k\u00ebsaj, specialisti i siguris\u00eb mund t\u00eb verifikoj\u00eb suksesin e sulmit, t\u00eb lokalizoj\u00eb k\u00ebrc\u00ebnimin, t\u00eb kuptoj\u00eb se si ndodhi sulmi dhe si t\u00eb parandaloj\u00eb t\u00eb ngjashme n\u00eb t\u00eb ardhmen.<\/p>\n<p>Ne do t\u00eb tregojm\u00eb se si me ndihm\u00ebn e NTA mund t\u00eb identifikoni t\u00eb gjitha taktikat e njohura t\u00eb sulmeve, t\u00eb p\u00ebrshkruara n\u00eb baz\u00ebn e njohurive <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/\">MITRE ATT&amp;CK<\/a><\/noindex>. Ne do t\u00eb flasim p\u00ebr secil\u00ebn nga 12 taktikat, do t\u00eb analizojm\u00eb teknikat q\u00eb zbulohen n\u00ebp\u00ebrmjet trafikut dhe do t'i demonstrojm\u00eb ato me sistemin ton\u00eb NTA. <noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Rreth baz\u00ebs s\u00eb njohurive ATT&amp;CK<\/h2>\n<p>\nMITRE ATT&amp;CK \u00ebsht\u00eb nj\u00eb baz\u00eb e njohurive q\u00eb \u00ebsht\u00eb n\u00eb dispozicion publik, e zhvilluar dhe mbajtur nga korporata MITRE mbi baz\u00ebn e analiz\u00ebs s\u00eb APT-ve reale. Ajo p\u00ebrb\u00ebn nj\u00eb grup t\u00eb strukturuar taktikash dhe teknikash q\u00eb p\u00ebrdoren nga sulmuesit. Kjo i lejon specialist\u00ebt e siguris\u00eb kibernetike nga e gjith\u00eb bota t\u00eb komunikojn\u00eb n\u00eb nj\u00eb gjuh\u00eb t\u00eb p\u00ebrbashk\u00ebt. Baza vazhdon t\u00eb zgjerohesh dhe t\u00eb plot\u00ebsohet me njohuri t\u00eb reja.<\/p>\n<p>N\u00eb baz\u00eb identifikohen 12 taktika, t\u00eb cilat ndahen sipas fazave t\u00eb sulmit kibernetik: <\/p>\n<ul>\n<li>qasje e par\u00eb (initial access);<\/li>\n<li>ekzekutimi (execution);<\/li>\n<li>nd\u00ebrhyrja (persistence);<\/li>\n<li>ngritja e privilegjeve (privilege escalation);<\/li>\n<li>parandalimi i zbulimit (defense evasion);<\/li>\n<li>fitimi i akreditiveve (credential access);<\/li>\n<li>eksplorimi (discovery);<\/li>\n<li>l\u00ebvizja brenda perimetrave (lateral movement);<\/li>\n<li>grumbullimi i t\u00eb dh\u00ebnave (collection);<\/li>\n<li>menaxhimi dhe kontrolli (command and control);<\/li>\n<li>eksfiltrimi i t\u00eb dh\u00ebnave (exfiltration);<\/li>\n<li>ndikimi (impact).<\/li>\n<\/ul>\n<p>\nP\u00ebr secil\u00ebn taktik\u00eb n\u00eb baz\u00ebn e njohurive ATT&amp;CK, list\u00ebsohet nj\u00eb grup teknika q\u00eb ndihmojn\u00eb sulmuesit t\u00eb arrijn\u00eb objektivin n\u00eb faz\u00ebn aktuale t\u00eb sulmit. Pasi e nj\u00ebjta teknik\u00eb mund t\u00eb p\u00ebrdoret n\u00eb faza t\u00eb ndryshme, ajo mund t\u00eb p\u00ebrfshihet n\u00eb disa taktika. <\/p>\n<p>P\u00ebrshkrimi i \u00e7do teknike p\u00ebrfshin:<\/p>\n<ul>\n<li>identifikuesin;<\/li>\n<li>list\u00ebn e taktikave n\u00eb t\u00eb cilat ajo aplikohet;<\/li>\n<li>shembuj t\u00eb p\u00ebrdorimit nga grupet APT;<\/li>\n<li>masa p\u00ebr t\u00eb zvog\u00ebluar d\u00ebmin nga aplikimi i saj;<\/li>\n<li>rekomandimet p\u00ebr zbulimin. <\/li>\n<\/ul>\n<p>\nSpecialist\u00ebt e siguris\u00eb mund t\u00eb p\u00ebrdorin njohurit\u00eb nga baza p\u00ebr t\u00eb strukturuar informacionin mbi metodat aktuale t\u00eb sulmeve dhe duke pasur parasysh k\u00ebt\u00eb, p\u00ebr t\u00eb nd\u00ebrtuar nj\u00eb sistem efikas t\u00eb siguris\u00eb. Kuptimi i se si funksionojn\u00eb grupet reale APT gjithashtu mund t\u00eb sh\u00ebrbej\u00eb si burim hipotezash p\u00ebr k\u00ebrkimin proaktiv t\u00eb k\u00ebrc\u00ebnimeve n\u00eb kuad\u00ebr t\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ptsecurity.com\/ru-ru\/research\/webinar\/302112\/\">threat hunting<\/a><\/noindex>. <\/p>\n<h3>Rreth PT Network Attack Discovery<\/h3>\n<p>\nNe do t\u00eb zbulojm\u00eb p\u00ebrdorimin e teknikave nga matrica ATT&amp;CK duke p\u00ebrdorur sistemin <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ptsecurity.com\/ru-ru\/products\/network-attack-discovery\/?utm_source=press_release&amp;utm_medium=press_release&amp;utm_campaign=new_nad\">PT Network Attack Discovery <\/a><\/noindex>\u2014 \u00ebsht\u00eb nj\u00eb sistem NTA i Positive Technologies, i dedikuar p\u00ebr zbuluar sulmet n\u00eb perimetrin dhe brenda rrjetit. PT NAD mbulon n\u00eb m\u00ebnyr\u00eb t\u00eb ndryshme t\u00eb 12 taktikat e matrice MITRE ATT&amp;CK. Ai \u00ebsht\u00eb m\u00eb i fuqish\u00ebm n\u00eb zbuluar teknikat e qasjes fillestare (initial access), l\u00ebvizjes brenda perimetrave (lateral movement) dhe menaxhimit dhe kontrollit (command and control). N\u00eb k\u00ebto t\u00eb fundit, PT NAD mbulon mbi gjysm\u00ebn e teknikave t\u00eb njohura, duke zbuluar p\u00ebrdorimin e tyre p\u00ebrmes treguesve direkt\u00eb ose t\u00ebrthor\u00eb. <\/p>\n<p>Sistemi identifikon sulmet duke p\u00ebrdorur teknikat ATT&amp;CK me an\u00eb t\u00eb rregullave t\u00eb zbulimit t\u00eb krijuara nga ekipi <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ptsecurity.com\/ru-ru\/products\/network-attack-discovery\/?utm_source=press_release&amp;utm_medium=press_release&amp;utm_campaign=new_nad\">PT Expert Security Center<\/a><\/noindex> (PT ESC), m\u00ebsimin e makinerive, tregues t\u00eb kompromisit, analiz\u00eb t\u00eb thell\u00eb dhe analiz\u00eb retrospektive. Analiza e trafikut n\u00eb koh\u00eb reale n\u00eb kombinim me retrospektiv\u00ebn lejon zbules\u00ebn e aktivitetit t\u00eb d\u00ebmsh\u00ebm aktual t\u00eb fshehur dhe ndjekjen e vektor\u00ebve t\u00eb zhvillimit dhe kronologjis\u00eb s\u00eb sulmeve.<\/p>\n<blockquote><p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/-l\/o8\/yc\/-lo8ycywq-rl1g_v1pt9-lmnj3y.png\">K\u00ebtu<\/a><\/noindex> hartimi i plot\u00eb i PT NAD n\u00eb matric\u00ebn MITRE ATT&amp;CK. Pamja \u00ebsht\u00eb e madhe, ndaj ju sugjerojm\u00eb ta shikoni n\u00eb nj\u00eb dritare t\u00eb ve\u00e7ant\u00eb.<\/p><\/blockquote>\n<p><\/p>\n<h3>Qasja fillestare (initial access)<\/h3>\n<p><img decoding=\"async\" alt=\"Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery\" src=\"\/wp-content\/uploads\/2020\/03\/93cc3669c7de3b5193897d685e63a72f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nTaktikat p\u00ebr t\u00eb siguruar qasjen fillestare p\u00ebrfshijn\u00eb teknika p\u00ebr t\u00eb dep\u00ebrtuar n\u00eb rrjetin e kompanis\u00eb. Q\u00ebllimi i sulmuesve n\u00eb k\u00ebt\u00eb faz\u00eb \u00ebsht\u00eb t\u00eb futin kod t\u00eb d\u00ebmsh\u00ebm n\u00eb sistemin e sulmuar dhe t\u00eb sigurojn\u00eb mund\u00ebsin\u00eb e ekzekutimit t\u00eb tij m\u00eb tej.<\/p>\n<p>Analiza e trafikut me PT NAD lejon identifikimin e shtat\u00eb teknikave t\u00eb sigurimit t\u00eb qasjes fillestare:<\/p>\n<h3>1. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1189\/\">T1189<\/a><\/noindex>: kompromisi i drejtp\u00ebrdrejt\u00eb<\/h3>\n<p>\nTeknika ku viktima hap nj\u00eb faqe interneti q\u00eb p\u00ebrdoret nga sulmuesit p\u00ebr t\u00eb shfryt\u00ebzuar shfletuesin, duke marr\u00eb tok\u00ebn e aksesit n\u00eb aplikacion. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: n\u00ebse trafiku web nuk \u00ebsht\u00eb i enkriptuar, PT NAD inspekton p\u00ebrmbajtjen e p\u00ebrgjigjeve t\u00eb server\u00ebve HTTP. Pik\u00ebrisht n\u00eb k\u00ebto p\u00ebrgjigje ndodhen eksploitat q\u00eb lejojn\u00eb sulmuesit t\u00eb ekzekutojn\u00eb kod t\u00eb rast\u00ebsish\u00ebm brenda shfletuesit. PT NAD automatikisht identifikon k\u00ebto eksploita me ndihm\u00ebn e rregullave t\u00eb zbulimit. <\/p>\n<p>P\u00ebrve\u00e7 k\u00ebsaj, PT NAD zb\u53d1\u73b0r k\u00ebrc\u00ebnimin n\u00eb hapin e m\u00ebparsh\u00ebm. Rregullat dhe treguesit e kompromisit aktivizohen n\u00ebse p\u00ebrdoruesi viziton nj\u00eb faqe q\u00eb e ka redirection n\u00eb nj\u00eb faqe me nj\u00eb grup eksploitesh.<\/p>\n<h3>2. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1190\">T1190<\/a><\/noindex>: shfryt\u00ebzimi i aplikacioneve q\u00eb jan\u00eb t\u00eb ekspozuara publikisht<\/h3>\n<p>\nShfryt\u00ebzimi i dob\u00ebsive n\u00eb sh\u00ebrbimet q\u00eb jan\u00eb t\u00eb aksesueshme nga interneti. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: kryen nj\u00eb inspektim t\u00eb thell\u00eb t\u00eb p\u00ebrmbajtjes s\u00eb pakove t\u00eb rrjetit, duke zbuluar shenjat e aktivitetit anormal. N\u00eb ve\u00e7anti, ka rregulla q\u00eb lejojn\u00eb zbulimin e sulmeve ndaj sistemeve t\u00eb menaxhimit t\u00eb p\u00ebrmbajtjes (content management system, CMS), nd\u00ebrfaqeve web t\u00eb pajisjeve rrjet\u00ebrore, sulmeve ndaj serverave t\u00eb post\u00ebs dhe FTP.<\/p>\n<h3>3. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1133\/\">T1133<\/a><\/noindex>: sh\u00ebrbimet e jashtme t\u00eb larg\u00ebta <\/h3>\n<p>\nP\u00ebrdorimi nga sulmuesit i sh\u00ebrbimeve t\u00eb aksesit t\u00eb larg\u00ebt p\u00ebr t'u lidhur me burimet e rrjetit t\u00eb brendsh\u00ebm nga jasht\u00eb. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: pasi sistemi njeh protokollet jo nga numrat e porteve, por nga p\u00ebrmbajtja e pakove, p\u00ebrdoruesit e sistemit mund t\u00eb filtruar trafikun p\u00ebr t\u00eb gjetur t\u00eb gjitha sesionet e protokollit t\u00eb aksesit t\u00eb larg\u00ebt dhe t\u00eb kontrollojn\u00eb legjitimitetin e tyre. <\/p>\n<h3>4. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1193\/\">T1193<\/a><\/noindex>: bashkangjitja e spearphishing <\/h3>\n<p>\nFjala b\u00ebhet p\u00ebr d\u00ebrgimin e p\u00ebrmendur t\u00eb bashkangjitjeve phishing.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: automatikisht nxjerr skedar\u00ebt nga trafik dhe i kontrollon ata sipas treguesve t\u00eb kompromisit. Skedar\u00ebt ekzekutiv\u00eb n\u00eb bashk\u00ebngjitje identifikohen nga rregullat q\u00eb analizojn\u00eb p\u00ebrmbajtjen e trafik t\u00eb post\u00ebs. N\u00eb nj\u00eb mjedis korporativ, nj\u00eb bashk\u00ebngjitje e till\u00eb konsiderohet anormale. <\/p>\n<h3>5. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1192\/\">T1192<\/a><\/noindex>: lidhja e spearphishing <\/h3>\n<p>\nP\u00ebrdorimi i lidhjeve phishing. Teknika p\u00ebrfshin d\u00ebrgimin nga sulmuesit t\u00eb nj\u00eb letre phishing me nj\u00eb lidhje, duke klikuar mbi t\u00eb shkarkohet nj\u00eb program t\u00eb d\u00ebmsh\u00ebm. Zakonisht, lidhja shoq\u00ebrohet nga nj\u00eb tekst i formuluar sipas t\u00eb gjitha rregullave t\u00eb inxhinieris\u00eb sociale. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: identifikon lidhjet phishing me ndihm\u00ebn e treguesve t\u00eb kompromisit. P\u00ebr shembull, n\u00eb nd\u00ebrfaqen e PT NAD ne shohim nj\u00eb sesion ku ka pasur nj\u00eb lidhje HTTP p\u00ebrmes nj\u00eb lidhjeje q\u00eb \u00ebsht\u00eb e listuar n\u00eb adresat phishing (phishing-urls).<\/p>\n<p><img decoding=\"async\" alt=\"Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery\" src=\"\/wp-content\/uploads\/2020\/03\/f8b8f0ed7e64da6a9ceb2c3e8d3b3202.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>Lidhja p\u00ebrmes nj\u00eb lidhjeje nga lista e treguesve t\u00eb kompromisit phishing-urls<\/i><\/p>\n<h3>6. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1199\">T1199<\/a><\/noindex>: marr\u00ebdh\u00ebnie besimi<\/h3>\n<p>\nAksesi n\u00eb rrjetin e viktim\u00ebs p\u00ebrmes pal\u00ebve t\u00eb treta me t\u00eb cilat viktima ka marr\u00ebdh\u00ebnie besimi. Sulmuesit mund t\u00eb hakerojn\u00eb nj\u00eb organizat\u00eb t\u00eb besuar dhe t\u00eb lidhen p\u00ebrmes saj me rrjetin e targetuar. P\u00ebr k\u00ebt\u00eb ata p\u00ebrdorin lidhjet VPN ose marr\u00ebdh\u00ebnie besimi t\u00eb Domaineve, q\u00eb mund t\u00eb identifikohen p\u00ebrmes analiz\u00ebs s\u00eb trafik. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: analizon protokollet aplikative dhe ruan fushat e analizuar n\u00eb nj\u00eb baz\u00eb t\u00eb dh\u00ebnash, duke i mund\u00ebsuar analistit t\u00eb siguris\u00eb t\u00eb gjej\u00eb t\u00eb gjitha lidhjet e dyshimta VPN ose lidhjet nd\u00ebr-domenesh p\u00ebrmes filtrave.<\/p>\n<h3>7. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1078\/\">T1078<\/a><\/noindex>: llogari valide<\/h3>\n<p>\nP\u00ebrdorimi i kredencialeve standarde, lokale ose t\u00eb domeneve p\u00ebr autorizimin n\u00eb sh\u00ebrbime t\u00eb brendshme dhe t\u00eb jashtme.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: n\u00eb m\u00ebnyr\u00eb automatike nxjerr kredencialet nga protokollet HTTP, FTP, SMTP, POP3, IMAP, SMB, DCE\/RPC, SOCKS5, LDAP, Kerberos. N\u00eb p\u00ebrgjith\u00ebsi kjo \u00ebsht\u00eb emri i p\u00ebrdoruesit, fjal\u00ebkalimi dhe shenja e suksesit t\u00eb autentifikimit. N\u00ebse ato jan\u00eb p\u00ebrdorur, ato shfaqen n\u00eb kartel\u00ebn p\u00ebrkat\u00ebse t\u00eb sesionit.<\/p>\n<h2>Ekzekutimi (execution)<\/h2>\n<p><img decoding=\"async\" alt=\"Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery\" src=\"\/wp-content\/uploads\/2020\/03\/54cfa8b924eb5061d7cc8bc93335c735.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nTeknikat e Ekzekutimit p\u00ebrfshijn\u00eb teknikat q\u00eb sulmuesit p\u00ebrdorin p\u00ebr t\u00eb ekzekutuar kodin n\u00eb sistemet e komprometuar. Aktivizimi i kodit t\u00eb d\u00ebmsh\u00ebm ndihmon sulmuesit t\u00eb konsolidojn\u00eb pranin\u00eb e tyre (taktika e persistenc\u00ebs) dhe t\u00eb zgjasin qasjen n\u00eb sistemet e larg\u00ebta n\u00eb rrjet, duke u l\u00ebvizur brenda perimetrit. <\/p>\n<p>PT NAD lejon t\u00eb zbuloj\u00eb p\u00ebrdorimin nga sulmuesit t\u00eb 14 teknikave t\u00eb p\u00ebrdorura p\u00ebr t\u00eb ekzekutuar kod t\u00eb d\u00ebmsh\u00ebm. <\/p>\n<h3>1. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1191\/\">T1191<\/a><\/noindex>: CMSTP (Microsoft Connection Manager Profile Installer)<\/h3>\n<p>\nTaktika ku t\u00eb cil\u00ebn aktor\u00ebt e k\u00ebrc\u00ebnimit p\u00ebrgatisin nj\u00eb skedar INF t\u00eb d\u00ebmsh\u00ebm t\u00eb ve\u00e7ant\u00eb p\u00ebr utilitarin CMSTP.exe t\u00eb integruar n\u00eb Windows (instaluesi i profileve t\u00eb menaxherit t\u00eb lidhjeve). CMSTP.exe merr skedarin si nj\u00eb paramet\u00ebr dhe instalon nj\u00eb profil sh\u00ebrbimi p\u00ebr lidhje t\u00eb larg\u00ebta. Si rezultat, CMSTP.exe mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb shkarkuar dhe ekzekutuar bibliotekat e lidhura dinamikisht (*.dll) ose skriptet (*.sct) nga server\u00eb t\u00eb larg\u00ebt. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: zbulon automatikisht n\u00eb trafikun HTTP transferimin e skedar\u00ebve INF t\u00eb nj\u00eb lloji t\u00eb ve\u00e7ant\u00eb. P\u00ebrve\u00e7 k\u00ebsaj, zbulon transferimin p\u00ebrmes protokollit HTTP t\u00eb skripteve t\u00eb d\u00ebmshme dhe bibliotekave t\u00eb lidhura dinamikisht nga nj\u00eb server i larg\u00ebt. <\/p>\n<h3>2. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1059\">T1059<\/a><\/noindex>: nd\u00ebrfaqja e komand\u00ebs <\/h3>\n<p>\nNd\u00ebrveprimi me nd\u00ebrfaqen e komand\u00ebs. Mund t\u00eb nd\u00ebrveprohet me nd\u00ebrfaqen e komand\u00ebs lokal ose n\u00eb m\u00ebnyr\u00eb t\u00eb larg\u00ebt, p\u00ebr shembull, duke p\u00ebrdorur utilitar\u00ebt e aksesit t\u00eb larg\u00ebt.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: zbulon automatikisht pranin\u00eb e shell-eve n\u00eb baz\u00eb t\u00eb p\u00ebrgjigjeve nga komandat p\u00ebr nisjen e utilitar\u00ebve t\u00eb ndrysh\u00ebm t\u00eb komand\u00ebs, si ping, ifconfig.<\/p>\n<h3>3. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1175\/\">T1175<\/a><\/noindex>: modeli i objektit t\u00eb komponent\u00ebs dhe DCOM i shp\u00ebrndar\u00eb <\/h3>\n<p>\nP\u00ebrdorimi i teknologjive COM ose DCOM p\u00ebr t\u00eb ekzekutuar kodin n\u00eb sisteme lokale ose t\u00eb larg\u00ebta gjat\u00eb avancimit n\u00eb rrjet.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: zbulon thirrjet e dyshimta DCOM q\u00eb aktor\u00ebt e k\u00ebrc\u00ebnimit zakonisht p\u00ebrdorin p\u00ebr t\u00eb nisur programe. <\/p>\n<h3>4. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1203\/\">T1203<\/a><\/noindex>: shfryt\u00ebzimi p\u00ebr ekzekutimin e klient\u00ebve <\/h3>\n<p>\nShfryt\u00ebzimi i dob\u00ebsive p\u00ebr t\u00eb ekzekutuar kod t\u00eb rast\u00ebsish\u00ebm n\u00eb stacionin e pun\u00ebs. Eksploit\u00ebt m\u00eb t\u00eb dobish\u00ebm p\u00ebr sulmuesit jan\u00eb ata q\u00eb lejojn\u00eb ekzekutimin e kodit n\u00eb nj\u00eb sistem t\u00eb larg\u00ebt, pasi me an\u00eb t\u00eb tyre aktor\u00ebt e k\u00ebrc\u00ebnimit mund t\u00eb fitojn\u00eb akses n\u00eb nj\u00eb sistem t\u00eb till\u00eb. Teknikat mund t\u00eb realizohen me metoda t\u00eb ndryshme: mb\u00ebshtetje t\u00eb d\u00ebmshme me email, faqe interneti me eksploit\u00eb p\u00ebr shfletuesit dhe shfryt\u00ebzime t\u00eb dob\u00ebsive t\u00eb aplikacioneve nga larg. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: gjat\u00eb analiz\u00ebs s\u00eb trafikut t\u00eb post\u00ebs, PT NAD e kontrollon at\u00eb p\u00ebr skedar\u00eb ekzekutiv\u00eb n\u00eb t\u00ebbashk\u00ebngjitje. Nxjerr automatikisht dokumentet zyrtare nga emailet q\u00eb mund t\u00eb ken\u00eb eksploit\u00eb. Tentativat e shfryt\u00ebzimit t\u00eb dob\u00ebsive jan\u00eb t\u00eb dukshme n\u00eb trafik, q\u00eb PT NAD e identifikon automatikisht.<\/p>\n<h3>5. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1170\">T1170<\/a><\/noindex>: mshta<\/h3>\n<p>\nP\u00ebrdorimi i utilitarit mshta.exe, i cili ekzekuton aplikacione Microsoft HTML (HTA) me zgjerimin .hta. Duke qen\u00eb se mshta trajton skedar\u00ebt duke anashkaluar parametrat e siguris\u00eb t\u00eb shfletuesit, aktor\u00ebt e k\u00ebrc\u00ebnimit mund ta p\u00ebrdorin mshta.exe p\u00ebr t\u00eb ekzekutuar skedar\u00eb HTA, JavaScript ose VBScript t\u00eb d\u00ebmsh\u00ebm. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: skedar\u00ebt .hta p\u00ebr ekzekutimin p\u00ebrmes mshta d\u00ebrgohen gjithashtu p\u00ebrmes rrjetit - kjo \u00ebsht\u00eb e dukshme n\u00eb trafik. PT NAD e identifikon automatikisht transferimin e k\u00ebtyre skedar\u00ebve t\u00eb d\u00ebmsh\u00ebm. Ai kap skedar\u00ebt, dhe informacioni rreth tyre mund t\u00eb shihet n\u00eb kartel\u00ebn e seanc\u00ebs.<\/p>\n<h3>6. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1086\">T1086<\/a><\/noindex>: PowerShell <\/h3>\n<p>\nP\u00ebrdorimi i PowerShell p\u00ebr t\u00eb k\u00ebrkuar informacion dhe p\u00ebr t\u00eb ekzekutuar kod t\u00eb d\u00ebmsh\u00ebm. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: kur PowerShell p\u00ebrdoret nga sulmuesit n\u00eb m\u00ebnyr\u00eb t\u00eb larg\u00ebt, PT NAD e zbulon k\u00ebt\u00eb duke p\u00ebrdorur rregulla. Ai identifikon fjal\u00eb ky\u00e7e t\u00eb gjuh\u00ebs PowerShell, t\u00eb cilat p\u00ebrdoren m\u00eb s\u00eb shpeshti n\u00eb skriptet e d\u00ebmshme, dhe transferimin e skripteve PowerShell p\u00ebrmes protokollit SMB.<\/p>\n<p>7. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1053\">T1053<\/a><\/noindex>: detyra t\u00eb planifikuara<br \/>\nP\u00ebrdorimi i planifikuesit t\u00eb detyrave Windows dhe utilitar\u00ebve t\u00eb tjer\u00eb p\u00ebr t\u00eb nisur automatikisht programe ose skripte n\u00eb nj\u00eb koh\u00eb t\u00eb p\u00ebrcaktuar. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: aktor\u00ebt e k\u00ebrc\u00ebnimit krijojn\u00eb detyra t\u00eb tilla, zakonisht n\u00eb distanc\u00eb, prandaj k\u00ebto seanca jan\u00eb t\u00eb dukshme n\u00eb trafik. PT NAD automatikisht identifikon operacionet e dyshimta p\u00ebr krijimin dhe modifikimin e detyrave duke p\u00ebrdorur nd\u00ebrfaqet RPC ATSVC dhe ITaskSchedulerService.<\/p>\n<h3>8. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1064\">T1064<\/a><\/noindex>: skriptimi <\/h3>\n<p>\nEkzekutimi i skripteve p\u00ebr t\u00eb automatizuar veprime t\u00eb ndryshme t\u00eb aktor\u00ebve t\u00eb k\u00ebrc\u00ebnimit. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: identifikon faktet e transferimit t\u00eb skripteve n\u00eb rrjet, pra para ekzekutimit t\u00eb tyre. Ai zbulojn\u00eb p\u00ebrmbajtjen e skripteve n\u00eb trafik t\u00eb pap\u00ebrpunuar dhe identifikon transferimin e skedar\u00ebve me zgjerime q\u00eb i p\u00ebrgjigjen gjuh\u00ebve t\u00eb njohura t\u00eb skriptimit.<\/p>\n<h3>9. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1035\">T1035<\/a><\/noindex>: ekzekutimi i sh\u00ebrbimeve<\/h3>\n<p>\nNisja e nj\u00eb skedari ekzekutiv, komandave t\u00eb nd\u00ebrfaqes s\u00eb komand\u00ebs ose skripti duke nd\u00ebrvepruar me sh\u00ebrbimet Windows, p\u00ebr shembull me menaxherin e kontrollit t\u00eb sh\u00ebrbimeve (Service Control Manager, SCM). <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: inspekton trafik SMB dhe identifikon k\u00ebrkesat p\u00ebr SCM me rregulla p\u00ebr krijimin, modifikimin dhe nisjen e sh\u00ebrbimeve. <\/p>\n<p>Teknika e nisjes s\u00eb sh\u00ebrbimeve mund t\u00eb realizohet duke p\u00ebrdorur nj\u00eb utilitar p\u00ebr ekzekutimin e komandave n\u00eb distanc\u00eb PSExec. PT NAD analizon protokollin SMB dhe identifikon p\u00ebrdorimin e PSExec, kur ajo p\u00ebrdor skedarin PSEXESVC.exe ose emrin standard t\u00eb sh\u00ebrbimit PSEXECSVC p\u00ebr t\u00eb ekzekutuar kodin n\u00eb nj\u00eb makin\u00eb t\u00eb larg\u00ebt. P\u00ebrdoruesi duhet t\u00eb kontrolloj\u00eb list\u00ebn e komandave t\u00eb ekzekutuara dhe legjitimitetin e ekzekutimit t\u00eb komandeve n\u00eb distanc\u00eb nga nodi. <\/p>\n<blockquote><p>N\u00eb kartel\u00ebn e sulmit n\u00eb PT NAD shfaqen t\u00eb dh\u00ebna mbi taktikat dhe teknik\u00ebt e p\u00ebrdorura sipas matric\u00ebs ATT&amp;CK, n\u00eb m\u00ebnyr\u00eb q\u00eb p\u00ebrdoruesi t\u00eb kuptoj\u00eb n\u00eb cil\u00ebn faz\u00eb t\u00eb sulmit ndodhen aktor\u00ebt e k\u00ebrc\u00ebnimit, cili \u00ebsht\u00eb q\u00ebllimi i tyre dhe cilat masa kompensuese duhet t\u00eb merren. <\/p><\/blockquote>\n<p>\n<img decoding=\"async\" alt=\"Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery\" src=\"\/wp-content\/uploads\/2020\/03\/cef63cd458947bf4b4a7735a44362f30.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<i>Aktivizimi i rregullit p\u00ebr p\u00ebrdorimin e vegl\u00ebs PSExec, q\u00eb mund t\u00eb tregoj\u00eb p\u00ebr nj\u00eb p\u00ebrpjekje p\u00ebr t\u00eb ekzekutuar komanda n\u00eb nj\u00eb makin\u00eb t\u00eb larg\u00ebt<\/i><\/p>\n<h3>10. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1072\/\">T1072<\/a><\/noindex>: softuer i pal\u00ebs s\u00eb tret\u00eb<\/h3>\n<p>\nTeknika n\u00eb t\u00eb cil\u00ebn nj\u00eb sulmues merr qasje n\u00eb softuerin p\u00ebr administrim t\u00eb larg\u00ebt ose n\u00eb sistemin korporativ p\u00ebr shp\u00ebrndarjen e softuerit dhe me ndihm\u00ebn e tyre ekzekuton kod t\u00eb d\u00ebmsh\u00ebm. Disa shembuj t\u00eb k\u00ebtij softueri jan\u00eb: SCCM, VNC, TeamViewer, HBSS, Altiris. <br \/>\nP\u00ebr ta th\u00ebn\u00eb ndryshe, teknika \u00ebsht\u00eb ve\u00e7an\u00ebrisht e r\u00ebnd\u00ebsishme p\u00ebr shkak t\u00eb kalimit masiv n\u00eb pun\u00eb t\u00eb larg\u00ebt dhe, si pasoj\u00eb, lidhjes shum\u00eb t\u00eb pajisjeve t\u00eb pap\u00ebrguarduar n\u00eb sht\u00ebpi p\u00ebrmes kanaleve t\u00eb dyshimta t\u00eb qasjes s\u00eb larg\u00ebt<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: e zbuloj automatikisht n\u00eb rrjet funksionimin e k\u00ebtij softueri. P\u00ebr shembull, rregullat aktivizohen n\u00eb rastet e lidhjes p\u00ebrmes protokollit VNC dhe aktivitetit t\u00eb trojanit EvilVNC, i cili fshehurazi instalon serverin VNC n\u00eb kompjuterin e viktim\u00ebs dhe e aktivizon at\u00eb automatikisht. Po ashtu, PT NAD e identifikon automatikisht protokollin TeamViewer, e cila ndihmon analistin t\u00eb gjej\u00eb t\u00eb gjitha k\u00ebto seanca me ndihm\u00ebn e filtreve dhe t\u00eb verifikoj\u00eb legjitimitetin e tyre.<\/p>\n<h3>11. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1204\/\">T1204<\/a><\/noindex>: ekzekutimi nga p\u00ebrdoruesi<\/h3>\n<p>\nTeknika n\u00eb t\u00eb cil\u00ebn p\u00ebrdoruesi ekzekuton skedar\u00eb q\u00eb mund t\u00eb \u00e7onin n\u00eb ekzekutimin e kodit. Kjo mund t\u00eb ndodh\u00eb, p\u00ebr shembull, n\u00ebse ai hap nj\u00eb skedar ekzekutues ose nis nj\u00eb dokument zyre me makro.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: sheh k\u00ebta skedar\u00eb q\u00eb n\u00eb faz\u00ebn e transmetimit, para se t\u00eb ekzekutohen. Informacioni p\u00ebr ta mund t\u00eb studiohet n\u00eb kartelat e seancave, n\u00eb t\u00eb cilat jan\u00eb transmetuar.<\/p>\n<h3>12. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1047\">T1047<\/a><\/noindex>: Windows Management Instrumentation<\/h3>\n<p>\nP\u00ebrdorimi i vegl\u00ebs WMI, e cila ofron mund\u00ebsin\u00eb e qasjes lokale dhe t\u00eb larg\u00ebt n\u00eb komponentet sistemos Windows. Me ndihm\u00ebn e WMI-s\u00eb, sulmuesit mund t\u00eb nd\u00ebrveprojn\u00eb me sistemet lokale dhe t\u00eb larg\u00ebta dhe t\u00eb kryejn\u00eb shum\u00eb detyra, si mbledhjen e informacionit p\u00ebr q\u00ebllime zbulimi dhe ekzekutimin e proceseve nga larg gjat\u00eb l\u00ebvizjes horizontale.<\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: pasi nd\u00ebrveprimet me sistemet e larg\u00ebta p\u00ebrmes WMI-s\u00eb jan\u00eb t\u00eb dukshme n\u00eb trafik, PT NAD e zbuloj automatikisht k\u00ebrkesat rrjetore p\u00ebr krijimin e seancave WMI dhe kontrollon trafikun p\u00ebr faktet e transmetimit t\u00eb skenar\u00ebve q\u00eb p\u00ebrdorin WMI.<\/p>\n<h3>13. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1028\">T1028<\/a><\/noindex>: Windows Remote Management <\/h3>\n<p>\nP\u00ebrdorimi i sh\u00ebrbimit dhe protokollit t\u00eb Windows q\u00eb lejon p\u00ebrdoruesin t\u00eb nd\u00ebrveproj\u00eb me sistemet e larg\u00ebta. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: sheh lidhjet rrjetore t\u00eb krijuara p\u00ebrmes Windows Remote Management. K\u00ebto seanca detektohen p\u00ebrmes rregullave n\u00eb m\u00ebnyr\u00eb automatike. <\/p>\n<h3>14. <noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/techniques\/T1220\/\">T1220<\/a><\/noindex>: p\u00ebrpunimi i skriptave XSL (Extensible Stylesheet Language)<\/h3>\n<p>\nGjuha e shenjtimit t\u00eb stilit XSL p\u00ebrdoret p\u00ebr t\u00eb p\u00ebrshkruar p\u00ebrpunimin dhe vizualizimin e t\u00eb dh\u00ebnave n\u00eb skedar\u00ebt XML. P\u00ebr t\u00eb mb\u00ebshtetur operacione t\u00eb nd\u00ebrlikuara, standardi XSL p\u00ebrfshin mb\u00ebshtetje p\u00ebr skripta t\u00eb brendshme n\u00eb gjuh\u00eb t\u00eb ndryshme. K\u00ebto gjuh\u00eb lejojn\u00eb ekzekutimin e kodit t\u00eb rast\u00ebsish\u00ebm, duke \u00e7uar n\u00eb shmangien e politikave t\u00eb siguris\u00eb t\u00eb bazuara n\u00eb lista t\u00eb bardha. <\/p>\n<p><b>\u00c7far\u00eb b\u00ebn PT NAD<\/b>: identifikon faktet e transferimit t\u00eb skedar\u00ebve t\u00eb till\u00eb p\u00ebrmes rrjetit, dometh\u00ebn\u00eb, p\u00ebrpara se ato t\u00eb lan\u00e7ohet. Ai automatikisht zb descobin faktin e transferimit p\u00ebrmes rrjetit t\u00eb skedar\u00ebve XSL dhe skedar\u00ebve me markup XSL anormal.<\/p>\n<p>N\u00eb materialet n\u00eb vijim, ne do t\u00eb shqyrtojm\u00eb se si sistemi NTA PT Network Attack Discovery gjen taktika dhe teknika t\u00eb tjera t\u00eb sulmuesve sipas MITRE ATT&amp;CK. Q\u00ebndroni t\u00eb informuar!<\/p>\n<p><b>Autor\u00ebt<\/b>: <\/p>\n<ul>\n<li>Anton Kutepov, specialist n\u00eb Qendr\u00ebn e Siguris\u00eb Ekspert (PT Expert Security Center) t\u00eb Positive Technologies<\/li>\n<li>Natalia Kazankova, marketing produkti n\u00eb Positive Technologies<\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/493082\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043e\u0433\u043b\u0430\u0441\u043d\u043e Verizon, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e (87%) \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u043e\u0432 \u0418\u0411 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u044f\u0442 \u0437\u0430 \u0441\u0447\u0438\u0442\u0430\u043d\u043d\u044b\u0435 \u043c\u0438\u043d\u0443\u0442\u044b, \u0430 \u043d\u0430 \u0438\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0443 68% \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0443\u0445\u043e\u0434\u044f\u0442 \u043c\u0435\u0441\u044f\u0446\u044b. \u042d\u0442\u043e \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f \u0438 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435\u043c Ponemon Institute, \u0441\u043e\u0433\u043b\u0430\u0441\u043d\u043e \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0443 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0443\u0445\u043e\u0434\u0438\u0442 \u0432 \u0441\u0440\u0435\u0434\u043d\u0435\u043c 206 \u0434\u043d\u0435\u0439 \u043d\u0430 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0430. \u041f\u043e \u043e\u043f\u044b\u0442\u0443 \u043d\u0430\u0448\u0438\u0445 \u0440\u0430\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0439, \u0445\u0430\u043a\u0435\u0440\u044b \u043c\u043e\u0433\u0443\u0442 \u0433\u043e\u0434\u0430\u043c\u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u043d\u0435 \u0431\u044b\u0442\u044c \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u043c\u0438. \u0422\u0430\u043a, \u0432 \u043e\u0434\u043d\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":76040,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-76039","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u044e\u0442 \u0442\u0430\u043a\u0442\u0438\u043a\u0438 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u043f\u043e MITRE ATT&amp;CK \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 PT Network Attack Discovery | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-30T11:43:09+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-30T11:43:09+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Si sistemet e analiz\u00ebs s\u00eb trafikuesve zbulojn\u00eb taktikat e haker\u00ebve sipas MITRE ATT&amp;CK n\u00eb shembullin e PT Network Attack Discovery | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u044e\u0442 \u0442\u0430\u043a\u0442\u0438\u043a\u0438 \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u043f\u043e MITRE ATT&amp;CK \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 PT Network Attack Discovery | ProHoster","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-sistemy-analiza-trafika-obnaruzhivayut-taktiki-hakerov-po-mitre-attck-na-primere-pt-network-attack-discovery","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-30T11:43:09+00:00","article:modified_time":"2020-03-30T11:43:09+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"76039","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:44:27","updated":"2022-09-27 21:17:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/76039","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=76039"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/76039\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/76040"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=76039"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=76039"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=76039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}