Safe protection: Suit the remedy to the case Rescue the invading system
The assailant invades a certain system, always driven by a certain main purpose. For example show off technology, get enterprise's confidential data, destroy enterprise's normal Business Process,etc., it is possible after invasion too sometimes, the assailant's attack, turn from a certain purpose into another purpose, for example, originally showed off technology, but after the login, found some important confidential data, because the driving of the interests, the assailant has stolen these confidential data finally.
And the assailant's purpose to invade the system is different, attacking methods used will be different, incidences and losses caused would not be the same. So, should suit the remedy to the case while dealing with different systems and invading the incident, different systems invade the type, should solve by different processing methods, in this way, may just have an object in view, reach the optimal treatment effect.
First, the system by showing off the technological purpose invades and resumes
There is some assailants' purpose to invade the system, but in order to show off their superb network techniques to counterpart or other people, or the system that carries on for experiment, a certain systematic loophole, invades the activity. Invade incident as to the system, assailant can in leave, come on, prove he succeed in, invade the system already by some evidence among the systems invaded generally, will also announce his invasion achievement in a certain forum on Internet sometimes, for example the invading assailant is a Web server, they will prove that has already invaded this system by oneself through changing the home information of this WEB website, or will become his meat chicken the invading system by way of installing the back door, then sell openly or announce on some forums, in order to declare that has already invaded some system by oneself. That is to say, we can invade the system of this kind and subdivide into the system taking control system as purpose to invade and revise service content to invade for the system of the purpose again.
Invade the activity as to the system taking revising service content as purpose, can change to finish the work of system recovery when needn't need shutting down ing.
1.Processing mode that should be adopted
(1), set up, invade into the intersection of system and present intact the intersection of system and snapshot, keep, fix into the partial snapshot only, so that ex post analysis, with reserving for the evidence.
(2), recover the modified webpage through the backup immediately.
(3), under Windows system, pass network monitoring software or " netstat - an " Order to come to check the present network connections of the system, if find abnormal network link, should disconnect the connection with it immediately. Then pass the journal file which looks over system process, service, real-time analysis system and service, what kind of operation is checkout system assailant comes to also do in the systemmed, in order to do corresponding recovery.
(4), through the journal file of real-time analysis system, or understand by measuring tools in weakness the assailant invades the loophole that the system utilizes. If the assailant makes use of loophole of the system or network utility program to invade the systematic one, then, should look for the corresponding system or utility program loophole patch to mend it, if there are not the relevant patches of these loopholes at present, we should use other means to take precautions against temporarily that utilize the invasion activity of these loopholes again. If the assailant utilizes other ways, for example the social engineering way invades the systematic one, there is no new loophole in the checkout system, needn't then do this step, and the target who must attack implementing to the social engineering understands and trains.
(5), after repairing the system or utility program loophole, should add the corresponding fire wall rule to prevent the recuring of this kind of incident, it install on IDS/IPS and antivirus software,should staging they characteristic storehouse.
(6), the end, use the system or corresponding utility program to find the software measures a thorough weakness to the system or service, guarantee before detection it was newly that it measured the characteristic storehouse. After all work finish, should in subsequent a some time, arrange for special messenger go on, real-time monitor to system this, in order to be sure the system will not be attacked by this kind of invasion incident again.
If the assailant becomes the meat chicken for the control system to attacks the system, so, they for can control systems long-term,be which install corresponding for back door procedure in being at system. Meanwhile, in order to prevent being found by the system user or controller, the assailant will hide the operation trace of he in the system by every possible means, and hide the back door that he installs.