【正文】
ment and boundary ? 在不同階段、不同人手中保持安全很困難 different phases and anizations ? 人把科學變成了藝術 Human transform science to art 54 結構本身可能就有問題 Find vulnerabilities from structure itself 55 ? 對于 AR/PEP/PDP的偽裝,可能打破整個結構 every role may be spoofed ? 所有看似漂亮的結構,其性能和可用性問題可能會非常嚴重,會輕易被拒絕服務攻擊擊垮 Most beautiful structures have performance and availability problems and may be easy to be kick down by DoS. ? 那么多傳統(tǒng)攻擊方式,可能有的還有效 Some traditional attacks are still effective 結構本身可能就有問題 Find vulnerabilities from structure itself 56 結構性安全還要繼續(xù)博弈 We are still in the game ? 怎么博弈? How to Play the game? – 你了解對方的結構嗎? Do you know the structure of all players? – 你了解對方了解多少自己的結構嗎? Do you know ―how much have the other player known about your structure‖ ? 57 結構性威脅 Structural threats 知識、資源和原則 Knowledge, Resources and Principles 58 知識 Knowledge ? 尋求對于系統(tǒng)更深層次技術結構的研究 Who know lower? ? 尋求對于系統(tǒng)宏觀結構的了解 Who know the macrostructure better? ? 尋求對于具體對象的全面了解 How many details do you know? ? … … 59 資源 Resources ? 從分布式拒絕服務攻擊到僵尸網絡,掌握具有結構和組織的攻擊體 Bot is a sample of structural software anization for attacking ? 在時序上組成結構,非常有利于攻擊 Time sequence spreading is a good thinking of structural attack ? … … 60 結構的一些關鍵字 Key words of structure ? Business ? Distribution ? Hierarchy ? Time sequence ? Lifecycle ? Management – Organization – Regular – Process Control ? Value ? 業(yè)務 ? 分布式 ? 層次 ? 時序 ? 生命周期 ? 管理 – 組織 – 制度 – 過程控制 ? 價值 61 流程化的結構思路 Processoriented structure process input output Process owner operator Infra structure Knowledge base LOG Archive Process improving Monitor 62 原則 Principles ? 安全沒有百分之百 No 100% Security ? 安全相對性的三個原則 3 security relativity rule –生存原則 survival rule –風險原則 Risk rule –保鏢原則 bodyguard rule 自身完備性要求 Perfective requirement 63 總結 Conclusion ? 脆弱性安全 Vulnerabilityoriented security ? 結構性安全 Structural security ? 結構性安全中的脆弱性 Vulnerabilities in structures ? 結構性威脅 Structural threats 64 總結:一個可以持續(xù)研究下去的課題 Conclusion: A good problem to keep approaching 脆弱性防御 . defend 結構性防御 Structural defend 脆弱性攻擊 . attack 結構性攻擊 Structural attack 脆弱性和結構性 Vulnerabilityoriented vs. structural 攻擊和防守 defend vs. attack 65 謝謝 … Thanks… 大潘 Jordan Pan