Okufanele ukwenze uma i-siloviki iza kumphathi wakho

Okufanele ukwenze uma i-siloviki iza kumphathi wakhokdpv - Reuters

Uma uqasha iseva, awunakho ukulawula okuphelele kuyo. Lokhu kusho ukuthi abantu abaqeqeshwe ngokukhethekile bangeza kumhlinzeki obamba noma nini futhi bacele noma iyiphi idatha yakho. Umhlinzeki wokusingatha uzonikezela uma isicelo sibophezela ngokusemthethweni.

Awufuni ngempela ukuthi amalogi wakho weseva yewebhu noma idatha yomsebenzisi ibe sengozini. Akunakwenzeka ukwakha ukuphepha okuphelele. Ukuzivikela kumhlinzeki wokusingatha ongumnikazi we-hypervisor futhi akunikeze ngomshini obonakalayo cishe akunakwenzeka. Kodwa ungase ukwazi ukunciphisa izingozi ngandlela-thile. Ukubethela imishini eqashiwe akulona ize njengoba kubonakala. Ake sibheke futhi izinsongo zokukhishwa kwedatha kusuka kumaseva aphathekayo.

Imodeli yosongo

Njengomthetho, umhlinzeki wokusingatha uzozama ukuvikela izithakazelo zeklayenti ngokugcwele ngangokunokwenzeka ngokomthetho. Uma iziphathimandla ezisemthethweni zicela kuphela amalogi okufinyelela, umhlinzeki obambayo ngeke anikeze ukulahlwa kwayo yonke imishini yakho ebonakalayo enemininingwane yolwazi. Okungenani, akufanele. Uma becela yonke idatha, umhlinzeki wokusingatha uzokopisha amadiski abonakalayo nawo wonke amafayela, futhi ngeke wazi ngisho ngakho.

Kungakhathalekile ukuthi yisiphi isimo, inhloso yakho eyinhloko ukwenza ukuhlasela kube nzima kakhulu futhi kubize. Ngokuvamile, kunezimo ezintathu eziyinhloko ezisongelayo.

Okusemthethweni

Ezikhathini eziningi, incwadi eyiphepha ithunyelwa ehhovisi elisemthethweni lomnikezeli osingethe ifuna idatha edingekayo ngokuhambisana nomthethonqubo ofanele. Uma konke kuqediwe ngendlela efanele, umhlinzeki wokusingatha unikeza amalogi okufinyelela adingekayo kanye neminye imininingwane kuziphathimandla. Ngokuvamile, bamane bacele idatha edingekayo.

Kwesinye isikhathi, uma kunesidingo, izikhulu zomthetho zizovakashela isikhungo sedatha mathupha. Lokhu kungase kube njalo, isibonelo, uma uneseva yakho ezinikele futhi idatha ingabuyiswa kuphela ngokomzimba.

Kuwo wonke amazwe, ukufinyelela empahleni yangasese, ukusesha, neminye imisebenzi kudinga ubufakazi bokuthi idatha ingase iqukathe ulwazi olubalulekile ophenyweni lobugebengu. Ngaphezu kwalokho, iwaranti yokusesha eyenziwa ngokuhambisana nayo yonke imithetho iyadingeka. Kungase kube nama-nuances lapha ngenxa yomthetho wendawo. Into eyinhloko okufanele uyiqonde ukuthi, ngisho noma ulandela umzila osemthethweni, abamele isikhungo sedatha ngeke bavumele noma ubani ukuba adlule isango lokuphepha.

Ngaphezu kwalokho, emazweni amaningi, akwenzeki ukususa izinto zokusebenza. Isibonelo, e-Russia, kuze kube sekupheleni kuka-2018, i-Article 183, Isigaba 3.1 se-Russian Criminal Procedure Code siqinisekise ukuthi, ngesikhathi sokubanjwa, imidiya yokugcina i-electronic izobanjwa ngokubamba iqhaza kochwepheshe. Ngesicelo somnikazi osemthethweni wemithombo yezokuxhumana eshaqiwe noma umnikazi wolwazi oluqukethwe lapho, uchwepheshe obambe iqhaza ekuthunjweni, phambi kofakazi, ukopisha ulwazi olusuka kwabezindaba obushaqiwe bokugcina i-elekthronikhi luye kweminye imidiya yokugcina kagesi.

Kamuva, ngeshwa, leli phuzu lasuswa esihlokweni.

Imfihlo futhi engekho emthethweni

Lesi isizinda sama-ejenti aqeqeshwe ngokukhethekile avela ku-NSA, FBI, MI5, nezinye izinhlangano ezinezinhlamvu ezintathu. Ezikhathini eziningi, umthetho kazwelonke unikeza amandla abanzi ngokwedlulele ezinhlakeni ezinjalo. Ngaphezu kwalokho, cishe ngaso sonke isikhathi kukhona ukuvinjelwa okusemthethweni kunoma yikuphi ukudalulwa okuqondile noma okungaqondile kweqiniso lokubambisana nezinhlangano ezinjalo zokuqinisa umthetho. I-Russia inezinhlangano ezifanayo. izimiso zomthetho.

Uma idatha yakho isongelwa ngale ndlela, cishe izokhishwa. Ngokungeziwe ekukhipheni okulula, bangase basebenzise yonke inqolobane yangemuva engekho emthethweni, ubungozi bosuku oluyizero, ukukhishwa kwedatha ku-RAM yomshini wakho obonakalayo, namanye amaqhinga. Umhlinzeki ozobamba uzophoqeleka ukuthi asize izikhulu zomthetho ngangokunokwenzeka.

Isisebenzi esingathembekile

Akubona bonke abantu abadalwe belingana. Omunye wabaphathi besikhungo sedatha angase anqume ukwenza imali eningi futhi adayise idatha yakho. Okuzokwenzeka ngokulandelayo kuncike egunyeni nasekufinyeleleni kwabo. Okubi kakhulu ukuthi umlawuli onokufinyelela kukhonsoli ye-virtualization unokulawula okuphelele emishinini yakho. Ungahlala uthatha isifinyezo sedatha yakho, okuhlanganisa konke okuqukethwe kwe-RAM, bese uyihlola ngokunethezeka.

I-VDS

Ngakho-ke, unomshini obonakalayo owabelwe wona ngumhlinzeki wakho wokubamba. Ungakumisa kanjani ukubethela ukuze uzivikele? Iqiniso liwukuthi, cishe akukho ndlela. Ngaphezu kwalokho, ngisho nesiphakeli somunye umuntu esizinikezele singagcina sesiwumshini obonakalayo onamadivayisi adingekayo athunyelwe kuwo.

Uma umsebenzi wesistimu ekude ungekona nje ukugcina idatha, kodwa ukwenza izibalo ezithile, khona-ke okuwukuphela kwenketho yokusebenza ngomshini ongathembekile kuzoba ukuqaliswa. ukubethela kwe-homomorphicNgaphezu kwalokho, uhlelo luzokwenza izibalo ngaphandle kwanoma iyiphi indlela yokuqonda ukuthi lenzani ngempela. Ngeshwa, i-overhead yokusebenzisa ukubethela okunjalo kuphezulu kangangokuthi ukusetshenziswa kwayo okungokoqobo okwamanje kunqunyelwe emisebenzini ecacile kakhulu.

Ukwengeza, lapho umshini we-virtual usebenza futhi wenza noma yiziphi izenzo, wonke amavolumu abethelwe ayafinyeleleka; ngaphandle kwalokho, i-OS ngeke ikwazi ukufinyelela kuzo. Lokhu kusho ukuthi ngokufinyelela kukhonsoli ye-virtualization, ungakwazi njalo ukuthatha isifinyezo somshini osebenzayo futhi ukhiphe bonke okhiye ku-RAM.

Abathengisi abaningi bazamile ukusebenzisa ukubethela kwe-RAM okususelwe kuhadiwe ukuze bavimbele ngisho nomsingathi ekufinyeleleni le datha. Isibonelo, ubuchwepheshe be-Intel Software Guard Extensions, obudala izindawo zesikhala sekheli elibonakalayo elivikelwe ekufundeni nasekubhaleni ngaphandle kwale ndawo ngezinye izinqubo, okuhlanganisa i-kernel yesistimu yokusebenza. Ngeshwa, ngeke ukwazi ukuthembela ngokugcwele kulobu buchwepheshe, njengoba uzokhawulelwa emshinini wakho obonakalayo. Ngaphezu kwalokho, izibonelo ezenziwe ngomumo sezivele zikhona. ukuhlasela ngempumelelo kulobu buchwepheshe. Futhi nokho, ukubethela imishini ebonakalayo akusizi ngalutho njengoba kungase kubonakale.

Ibethela idatha ku-VDS

Ake ngicacise ngokushesha ukuthi yonke into esiyenzayo ngezansi ayilingani nokuvikela okuphelele. I-hypervisor izokuvumela ukuthi wenze amakhophi adingekayo ngaphandle kokuphazamisa isevisi futhi ngaphandle kolwazi lwakho.

  • Uma umhlinzeki wokusingatha ehlinzeka ngesithombe esibandayo somshini wakho obonakalayo uma ucela, uphephile uma kuqhathaniswa. Lesi yisimo esivame kakhulu.
  • Uma umhlinzeki wokusingatha ehlinzeka ngesifinyezo esiphelele somshini osebenzayo, izinto zimbi kakhulu. Yonke idatha izokhwezwa ohlelweni ngombhalo ocacile. Ngaphezu kwalokho, uzokwazi ukuphenya ku-RAM usesha okhiye abayimfihlo nedatha efanayo.

Ngokuzenzakalelayo, uma ukhiphe i-OS esithombeni se-vanilla, umhlinzeki wokusingathwa akanakho ukufinyelela kwezimpande. Ungakwazi njalo ukukhweza idrayivu yesithombe sokuhlenga futhi ushintshe iphasiwedi yempande ngokukrola endaweni yomshini obonakalayo. Nokho, lokhu kuzodinga ukuqalisa phansi, okuzoqashelwa. Ukwengeza, zonke izingxenye ezibethelwe ezifakiwe zizokhiywa.

Kodwa-ke, uma umshini we-virtual ungasetshenziswanga kusukela kusithombe se-vanilla, kodwa kusukela kulowo olungiselelwe kusengaphambili, umhlinzeki wokusingatha angakwazi ukwengeza i-akhawunti enelungelo ukusiza esimweni esiphuthumayo seklayenti. Isibonelo, ukushintsha iphasiwedi yezimpande ekhohliwe.

Ngisho nesifinyezo esigcwele, izinto azimbi kangako. Umhlaseli ngeke akwazi ukuthola amafayela abethelwe uma uwakhweze esuka kusistimu yefayela eyirimothi komunye umshini. Yebo, ngokombono, kuyenzeka uvule ukulahlwa kwe-RAM futhi ukhiphe okhiye bokubethela lapho. Kodwa ekusebenzeni, lokhu kude nokuncane, futhi mancane amathuba okuthi le nqubo idlulele ngale kokudluliswa kwefayela okulula.

Si-oda imoto

Okufanele ukwenze uma i-siloviki iza kumphathi wakho

Ngezinjongo zethu zokuhlola sithatha umshini olula siwungenise isigaba soku-oda amasevaAsidingi izinsiza eziningi, ngakho-ke sizohamba nenketho yokukhokha ngakunye kwe-megahertz kanye nomkhawulokudonsa osetshenzisiwe ngempela. Isikhathi esanele sokudlala.

I-dm-crypt yakudala yayo yonke ingxenye ayizange isebenze. Ngokuzenzakalelayo, i-disk inikezwa ngocezu olulodwa, kusukela kumkhombandlela wezimpande kuya kuwo wonke ukwahlukanisa. Ukunciphisa ukwahlukanisa kwe-ext4 ngohla lwemibhalo lwempande olufakiwe kuqinisekisiwe ngokubonakalayo ukwenza izitini isistimu yefayela. Ngizamile. Ithamborini ayizange isize.

Ukudala isitsha se-crypto

Ngakho-ke, ngeke sibhale ngemfihlo yonke ingxenye, kodwa sizosebenzisa iziqukathi ezibethelwe ezisekelwe kufayela, ikakhulukazi i-VeraCrypt ehloliwe nethembekile. Lokhu kwanele ngezinjongo zethu. Okokuqala, landa futhi ufake iphakheji yenguqulo ye-CLI kusuka kuwebhusayithi esemthethweni. Ungakwazi futhi ukuqinisekisa isiginesha.

wget https://launchpad.net/veracrypt/trunk/1.24-update4/+download/veracrypt-console-1.24-Update4-Ubuntu-18.04-amd64.deb
dpkg -i veracrypt-console-1.24-Update4-Ubuntu-18.04-amd64.deb

Manje sizokwakha isiqukathi ngokwaso ndawana thize kumkhombandlela wasekhaya ukuze sikwazi ukukukhweza mathupha ekuqaliseni kabusha. Kumodi yokusebenzisana, setha usayizi wesiqukathi, iphasiwedi, nama-algorithms wokubethela. Ungakhetha i-Kuznechik cipher yokushisekela izwe kanye nomsebenzi we-Stribog hashi.

veracrypt -t -c ~/my_super_secret

Manje masifake i-nginx, sikhweze isiqukathi bese silayisha ulwazi oluyimfihlo kuso.

mkdir /var/www/html/images
veracrypt ~/my_super_secret /var/www/html/images/
wget https://upload.wikimedia.org/wikipedia/ru/2/24/Lenna.png

Ake silungise /var/www/html/index.nginx- kancanedebian.html ukuze uthole ikhasi olifunayo futhi ungalihlola.

Asixhume sihlole

Okufanele ukwenze uma i-siloviki iza kumphathi wakho
Isiqukathi sifakwe, idatha iyatholakala futhi iyadluliselwa.

Okufanele ukwenze uma i-siloviki iza kumphathi wakho
Futhi nawu umshini ngemuva kokuqalisa kabusha. Idatha igcinwe ngokuphephile kokuthi ~/my_super_secret.

Uma uyidinga ngempela futhi ufuna ukuya ku-hardcore, ungabhala ngemfihlo yonke i-OS ukuze idinge uxhumano lwe-SSH nephasiwedi lapho iqalisa kabusha. Lokhu kuzokwanela nesimo esilula sokukhishwa kwedatha. Nansi indlela Imiyalo ye-Dropbear kanye nokubethela kwediski kude. Nakuba esimweni se-VDS, lokhu kuyinkimbinkimbi futhi akudingekile.

Insimbi engenalutho

Akulula ukufaka iseva yakho esikhungweni sedatha. Iseva ezinikele yomunye umuntu ingaba umshini obonakalayo onawo wonke amadivayisi axhunyiwe. Kodwa ubumnandi bangempela bokuphepha buqala lapho unethuba lokusingatha iseva yakho ephathekayo ethembekile esikhungweni sedatha. Lapha, ungasebenzisa ngokugcwele i-dm-crypt yendabuko, i-VeraCrypt, nanoma iyiphi enye indlela yokubhala ngemfihlo oyikhethayo.

Kubalulekile ukuqonda ukuthi ngokubethela okuphelele, iseva ngeke ikwazi ukuqalisa kabusha ngokuzenzakalelayo ngemva kokuqalisa kabusha. Uxhumano kuzodingeka lusungulwe ku-IP-KVM yasendaweni, i-IPMI, noma isixhumi esibonakalayo esifanayo. Ngemva kwalokho, sifaka mathupha ukhiye oyinhloko. Lokhu kusetha kubukeka kungalungile ngokuya ngokuqhubeka nokubekezelela amaphutha, kodwa azikho ezinye izindlela eziningi uma idatha ibaluleke kangaka.

Okufanele ukwenze uma i-siloviki iza kumphathi wakho
I-NCipher nShield F3 Hardware Security Module

Inketho ethambile ihilela ukubethela idatha, nokugcina ukhiye ngokuqondile kuseva ngokwayo ku-HSM ezinikele (Imojula Yokuphepha Yezingxenyekazi Zekhompyutha). Lawa ngokuvamile amadivayisi anekhono kakhulu anganikezi kuphela i-cryptography yehadiwe kodwa futhi anezindlela zokuthola imizamo yokugebenga ngokomzimba. Uma othile eqala ukugebenga iseva yakho ngegrinder, i-HSM, namandla ayo azimele, izosetha kabusha okhiye abagcinwe kumemori yayo. Umhlaseli uzothola idatha ebethelwe. Ukuqalisa kabusha kungase kwenzeke ngokuzenzakalelayo.

Ukukhipha okhiye kuyinketho eshesha kakhulu futhi enobuntu kunokusebenzisa ibhomu le-thermite noma i-electromagnetic discharger. Omakhelwane besikhungo sakho sedatha bazokuhlukumeza ngamadivayisi anjalo isikhathi eside. Ikakhulukazi njengoba, uma isetshenziswa, I-TCG Opal 2 Ngokubethela kumadrayivu ngokwawo, awubi nakho konke okungaphezulu. Konke kwenzeka ngokusobala ku-OS. Kodwa-ke, kufanele uthembele, uthi, i-Samsung, futhi uthemba ukuthi isebenzisa ukubethela okuthembekile kwe-AES256, hhayi nje i-XOR ecacile.

Kubalulekile ukukhumbula ukuthi zonke izimbobo ezingadingekile kufanele zikhutshazwe ngokomzimba noma zivele zivalwe ngenhlanganisela. Uma kungenjalo, unikeza abahlaseli ithuba lokufeza Ukuhlaselwa kwe-DMAUma une-PCI Express noma imbobo ye-Thunderbolt eveziwe, kuhlanganise ne-USB eyisekelayo, usengozini. Umhlaseli angasebenzisa lezi zimbobo ukuze ahlasele futhi athole ukufinyelela okuqondile kumemori equkethe okhiye.

Dlala ividiyo

Umhlaseli ohlakaniphe kakhulu angenza ukuhlasela kwebhuthi ebandayo. Lokhu kufaka phakathi ukuthela inani elikhulu le-nitrogen ewuketshezi kuseva yakho, cishe ukukhipha amamojula enkumbulo afriziwe, futhi uwalahle ngazo zonke izikhiye. Ngokuvamile, isifutho esilula sokupholisa kanye nezinga lokushisa elizungeze -50 degrees Celsius kwanele ukuhlasela. Kukhona futhi inketho ecashile. Uma ungakakhubazi ukuqala kumadivayisi angaphandle, i-algorithm yomhlaseli ilula nakakhulu:

  1. Friza amamojula wememori ngaphandle kokuvula ikesi
  2. Xhuma i-USB flash drive yakho ebhuthayo
  3. Sebenzisa izinsiza ezikhethekile ukuze ususe idatha ku-RAM esinde ekuqaliseni kabusha ngenxa yokuqandisa.

Hlukanisa futhi unqobe

Kulungile, sinemishini ebonakalayo kuphela, kodwa sifuna okungenani ngandlela thize ukwehlisa ubungozi bokuvuza kwedatha.
Empeleni, singazama ukucabanga kabusha ngezakhiwo nokusabalalisa ukugcinwa kwedatha nokucubungula ezindaweni ezahlukene. Isibonelo, indawo engaphambili enokhiye bokubethela ingase isingathwe umsingathi e-Czech Republic, kuyilapho indawo engemuva enedatha ebethelwe ingase ibekwe ndawana thize e-Russia. Esimeni somzamo ojwayelekile wokuthatha idatha, mancane amathuba okuthi izikhungo ezigcina umthetho zikwazi ukwenza umsebenzi ngesikhathi esisodwa ezindaweni ezahlukene. Lokhu futhi kuzosiqinisekisa kancane mayelana nesithombe esifinyeziwe.

Noma singacabangela inketho emsulwa ngokupheleleβ€”ukubethela ngasemaphethelweni. Yebo, lokhu kungaphezu kobubanzi bokucaciswa futhi akubandakanyi ukwenza izibalo emshinini wesilawuli kude. Nokho, inketho eyamukeleka ngokuphelele uma kuziwa ekugcineni nokuvumelanisa idatha. Isibonelo, i-Nextcloud inokuqaliswa okulula kakhulu kwalokhu. Ukuvumelanisa, ukwenza inguqulo, nezinye izici zohlangothi lweseva zisele.

Inani

Awekho amasistimu avikeleke ngokuphelele. Umgomo uwukwenza ukuhlasela kubize kakhulu kunenzuzo engase ibe khona.

Okunye ukuncishiswa kwengozi yokufinyelela idatha emshinini obonakalayo kungafinyelelwa ngokuhlanganisa ukubethela kanye nesitoreji esihlukene nabahlinzeki abahlukahlukene bokusingatha.

Inketho ethembeke kakhulu noma engaphansi ukusebenzisa iseva yakho yehadiwe.

Kodwa kusafanele uthembele kumhlinzeki wokusingatha ngandlela thile. Yilokho yonke imboni encike kukho.

Okufanele ukwenze uma i-siloviki iza kumphathi wakho

Okufanele ukwenze uma i-siloviki iza kumphathi wakho

Source: www.habr.com

Thenga ukusingathwa okuthembekile kwamasayithi anokuvikelwa kwe-DDoS, amaseva e-VPS VDS πŸ”₯ Thenga ukusingathwa kwewebhusayithi okuthembekile ngokuvikelwa kwe-DDoS, amaseva e-VPS VDS | ProHoster