àÇçºÁ͹ÊàµÍÃì
Administrator
Hero Member
   
¾Åѧ¹éÓ㨠+10003/-0
ÍÍ¿äŹì
à¾È: 
¡ÃзÙé: 585
ÊÒÁѤ¤Õ ¤×;Åѧ
|
 |
« àÁ×èÍ: 25 ÁԶعÒ¹ 2009, 11:01:47 AM » |
|
͸ԺÒª×èÍ ¤ÇÒÁËÁÒ ·ÕèÁÒ ¤ÇÒÁᵡµèÒ§ÃÐËÇèÒ§ Virus, Worm, Spyware, Trojan, Malware áÅÐÊÒà˵ØËÅÑ¡æ·Õè·ÓãËé¤ÍÁ¾ÔÇàµÍÃìµÔ´àª×éÍ
Virus = á¾Ãèàª×éÍ仵Դä¿ÅìÍ×è¹æã¹¤ÍÁ¾ÔÇàµÍÃìâ´Â¡ÒÃṺµÑÇÁÑ ¹àͧà¢éÒä» ÁѹäÁèÊÒÁÒöÊè§µÑÇàͧä»Âѧ¤ÍÁ¾ÔÇàµÍÃìà¤Ã×èͧÍ×è¹æä ´éµéͧÍÒÈÑÂä¿Åì¾ÒËÐ ÊÔè§·ÕèÁѹ·Ó¤×ÍÊÃéÒ§¤ÇÒÁàÊÕÂËÒÂãËé¡Ñºä¿Åì
Worm = ¤Ñ´ÅÍ¡µÑÇàͧáÅÐÊÒÁÒöÊè§µÑÇàͧä»Âѧ¤ÍÁ¾ÔÇàµÍÃìà¤Ã× èͧÍ×è¹æä´éÍÂèÒ§ÍÔÊÃÐ â´ÂÍÒÈÑÂÍÕàÁÅÅìËÃ×ͪèͧâËÇè¢Í§Ãкº»¯ÔºÑµÔ¡Òà ÁÑ¡¨ÐäÁèá¾Ãèàª×èÍ仵Դä¿ÅìÍ×è¹ ÊÔè§·ÕèÁѹ·Ó¤×ÍÁÑ¡¨ÐÊÃéÒ§¤ÇÒÁàÊÕÂËÒÂãËé¡ÑºÃкºà¤Ã× Í¢èÒÂ
Trojan = äÁèá¾Ãèàª×éÍ仵Դä¿ÅìÍ×è¹æ äÁèÊÒÁÒöÊè§µÑÇàͧä»Âѧ¤ÍÁ¾ÔÇàµÍÃìà¤Ã×èͧÍ×è¹æä´é µéͧÍÒÈÑ¡ÒÃËÅÍ¡¤¹ãªéãËé´ÒÇâËÅ´àÍÒä»ãÊèà¤Ã×èͧàÍ§Ë Ã×Í´éÇÂÇÔ¸ÕÍ×è¹æ ÊÔè§·ÕèÁѹ·Ó¤×Íà»Ô´âÍ¡ÒÊãËé¼ÙéäÁè»ÃÐʧ¤ì´Õà¢éÒÁÒ¤Ç º¤ØÁà¤Ã×èͧ·ÕèµÔ´àª×éͨҡÃÐÂÐä¡Å «Ö觨зÓÍÐäáçä´é áÅÐâ·Ã¨Ñ¹ÂѧÁÕÍÕ¡ËÅÒª¹Ô´
Spyware = äÁèá¾Ãèàª×éÍ仵Դä¿ÅìÍ×è¹æ äÁèÊÒÁÒöÊè§µÑÇàͧä»Âѧ¤ÍÁ¾ÔÇàµÍÃìà¤Ã×èͧÍ×è¹æä´é µéͧÍÒÈÑ¡ÒÃËÅÍ¡¤¹ãªéãËé´ÒÇâËÅ´àÍÒä»ãÊèà¤Ã×èͧàÍ§Ë Ã×ÍÍÒÈѪèͧâËÇè¢Í§ web browser 㹡ÒõԴµÑé§µÑÇàͧŧã¹à¤Ã×èͧàËÂ×èÍ ÊÔè§·ÕèÁѹ·Ó¤×Íú¡Ç¹áÅÐÅÐàÁÔ´¤ÇÒÁà»ç¹ÊèǹµÑǢͧ¼Ùé ãªé
Hybrid malware/Blended Threats = ¤×Í malware ·ÕèÃÇÁ¤ÇÒÁÊÒÁÒö¢Í§ virus, worm, trojan, spyware à¢éÒäÇé´éÇ¡ѹ
Phishing = à»ç¹à·¤¹Ô¤¡ÒÃ·Ó social engineer â´ÂãªéÍÕàÁÅÅìà¾×èÍËÅÍ¡ãËéàËÂ×èÍà»Ô´à¼Â¢éÍÁÙÅ¡Ò÷Ӹ ØÃ¡ÃÃÁ·Ò§¡ÒÃà§Ô¹º¹ÍÔ¹àµÍÃìà¹çµàªè¹ ºÑµÃà¤Ã´ÔµËÃ×;ǡ online bank account
Zombie Network = à¤Ã×èͧ¤ÍÁ¾ÔÇàµÍÃì¨Ó¹Ç¹ÁÒ¡æ ¨Ò¡·ÑèÇâÅ¡·Õ赡à»ç¹àËÂ×èͧ͢ worm, trojan áÅÐ malware ÍÂèÒ§Í×è¹ (compromised machine) «Ö觨ж١ attacker/hacker ãªéà»ç¹°Ò¹»¯ÔºÑµÔ¡ÒÃ㹡ÒÃÊè§ spam mail, phishing, DoS ËÃ×ÍàÍÒäÇéà¡çºä¿ÅìËÃ×ͫͿáÇÃì·Õè¼Ô´¡®ËÁÒÂ
Malware ÂèÍÁÒ¨Ò¡ Malicious Software ËÁÒ¶֧â»Ãá¡ÃÁ¤ÍÁ¾ÔÇàµÍÃì·Ø¡ª¹Ô´·ÕèÁըش»ÃÐʧ¤ìÃéÒ ÂµèͤÍÁ¾ÔÇàµÍÃìáÅÐà¤Ã×Í¢èÒ ËÃ×Íà»ç¹¤Ó·ÕèãªéàÃÕ¡â»Ãá¡ÃÁ·ÕèÁÕ ¨Ø´»ÃÐʧ¤ìÃéÒµèÍ Ãкº¤ÍÁ¾ÔÇàµÍÃì·Ø¡ª¹Ô´áººÃÇÁæ â»Ãá¡ÃÁ¾Ç¡¹Õé¡çàªè¹ virus, worm, trojan, spyware, keylogger, hack tool, dialer, phishing, toolbar, BHO, etc
áµèà¹×èͧ¨Ò¡ virus ¤×Í malware ª¹Ô´áá·Õèà¡Ô´¢Ö鹺¹âÅ¡¹ÕéáÅÐÍÂÙèÁÒ¹Ò¹ ´Ñ§¹Ñé¹â´Â·ÑèÇ仵ÒÁ¢èÒÇËÃ×ͺ ·¤ÇÒÁµèÒ§æ·ÕèäÁèà¹é¹ä» ã¹·Ò§ÇÔªÒ¡ÒÃÁÒ¡à¡Ô¹ä» ËÃ×Íà¾×èͤÇÒÁ§èÒ ¡ç¨Ðãªé¤ÓÇèÒ virus á·¹¤ÓÇèÒ malware áµè¶éҨФԴ¶Ö§¤ÇÒÁ¨ÃÔ§áÅéÇÁѹäÁè¶Ù¡µéͧ malware áµèÅЪ¹Ô´äÁèàËÁ×͹¡Ñ¹
¤ÓÇèÒäÇÃÑÊ (virus) 㹻Ѩ¨ØºÑ¹¹Õé¶Ù¡ãªéẺäÁè¤èͨж١µéͧµÃ§¡Ñº¤ÇÒÁ໠繨ÃÔ§à·èÒäËÃè ÍÒ¨¨Ðà»ç¹à¾ÃÒФÇÒÁà¤ÂªÔ¹ËÃ×ÍÍÐäáçµÒÁáµè (¼Áàͧ¡çà»ç¹) Áѹ¡ÅÒÂà»ç¹ÇèÒ¤¹ÊèǹãËèãªé¤Ó ÇèÒ virus á·¹ worm, trojan, adware, spyware, malicious code, etc. ãªéàÃÕ¡᷹ÂѧäÁèà·èÒäËÃè áµè¶éÒà¢éÒã¨ÇèÒ virus ¤×Í malicious software ·Ñé§ËÁ´·ÕèºÍ¡ä»¹Ñè¹ Íѹ¹Õéà»ç¹¤ÇÒÁà¢éÒ㨷Õè¼Ô´ áÁé¡ÃзÑè§ã¹ÃèÒ§¡®ËÁÒÂÍÒªÒ¡ÃÃÁ·Ò§¤ÍÁ¾ÔÇàµÍÃì ¡çÂѧ ÁÕ¡ÒÃàʹ͢ÍãËéá¡é䢤ÓÇèÒ virus â´Âà»ÅÕè¹ä»ãªé¤ÓÇèÒ malware á·¹ à¾ÃÒжéÒäÁè§Ñé¹áÅéǤ¹·Õèãªé worm, trojan â¨ÁµÕ¤¹Í×è¹ÍÒ¨¨ÐäÁèÁÕ¤ÇÒÁ¼Ô´ à¾ÃÒÐ worm, trojan äÁèãªè virus
·Õè¶Ù¡µéͧãªé¤ÓÇèÒÁÒÅáÇÃì «Öè§ÁÒ¨Ò¡¤Óã¹ÀÒÉÒÍѧ¡ÄÉÇèÒ malware (malicious software) ÍѹËÁÒ¶֧ â»Ãá¡ÃÁ¤ÍÁ¾ÔÇàµÍÃì·Ñé§ËÁ´·Õè¶Ù¡Í͡ẺÁÒãËéÁըش»ÃРʧ¤ìÃéÒµèÍÃкº¤ÍÁ¾ÔÇàµÍÃìáÅÐ à¤Ã×Í¢èÒ â»Ãá¡ÃÁàËÅèÒ¹Õé¡çàªè¹ classic virus, worm, trojan, adware, spyware, toolbar, BHO, hijacker, downloader, phishing, exploit malware ÃÇÁä»¶Ö§ zero-day attack, zombie network áÅÐÍ×è¹æ
ITW malware ã¹ the wildlist (áÁé¡ÃзÑè§ã¹ supplemental list) ÁÒ¡¡ÇèÒ 90% à»ç¹ worm (hybrid worm) ¤ÃѺ äÁèãªè virus (classic virus) ¡çµÒÁ·Õè¤ÇÒÁ¤Ô´àËç¹·Õè 2 ºÍ¡¹Ñè¹ÅèФÃѺ classic virus â´Â੾ÒÐẺ file infector ·ÕèṺµÑÇÁѹàͧà¢éÒä»ÂѧÊèǹµèÒ§æ¢Í§ä¿ÅìÍ×è¹ (host file) áÅÐ boot sector virus Áѹ᷺¨ÐËÁ´Âؤä»áÅéÇ (ÍÒ¨¨ÐÁվǡ proof-of-concept virus ºéÒ§) ·ÕèÂѧ¾ºàËç¹ÍÂÙèã¹ the wildlist ÊèǹãËè¨Ðà»ç¹ macro virus («Öè§à»ç¹ virus º¹ PC ã¹Âؤ·éÒÂæ) «Öè§Âѧ¾ºàË繡ÒÃá¾ÃèÃкҴÍÂÙèºéÒ§ áÅÐ virus ·Õèª×èÍ VBS/Redlof ¤×͵ÑÇÍÂèÒ§¢Í§ classic virus ·ÕèÂѧ¾Í¾ºàËç¹ä´é·ÑèÇä»
Malware ·Õ辺àË繡ÒÃá¾ÃèÃкҴ·ÑèÇä»áÅÐàËÁ×͹¨ÐÊÃéÒ§¤ÇÒÁàÊÕ ÂËÒÂãËé¡ÑºÃкºàÈÃɰ¡Ô¨ÁÒ¡·ÕèÊØ´¡ç¤×Í worm áÅÐ worm ¡çÂѧáºè§ÍÍ¡à»ç¹ª¹Ô´á¡ÂèÍÂä´é´Ñ§µèÍ仹Õé
- Email Worm àªè¹ mass-mailing worm ·Õè¤é¹ËÒÃÒª×èÍÍÕàÁÅÅìã¹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍáÅéÇ ¡çÊè§µÑÇàͧä»ËÒÍÕàÁÅÅìàËÅèÒ¹Ñé¹ - File-sharing Networks Worm ¤Ñ´ÅÍ¡µÑÇàͧä»äÇéã¹â¿Åà´ÍÃì·Õè¢Ö鹤é¹ËÃ×Í»ÃСͺ´éÇ Â¤ÓÇèÒ´éÇ sha áÅÐáªÃìâ¿Åà´ÍÃì¢Í§â»Ãá¡ÃÁ P2P àªè¹ KaZaa - Internet Worm, Network Worm â¨ÁµÕªèͧâËÇè¢Í§â»Ãá¡ÃÁáÅÐÃкº»®ÔºÑµÔ¡ÒÃàªè¹àÇÔÃìÁ Blaster, Sasser ·ÕèàÃÒÃÙé¨Ñ¡¡Ñ¹´Õ - IRC Worm Êè§µÑÇàͧ¨Ò¡à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍä»ËÒ¤¹·ÕèÍÂÙèã¹Ë éͧʹ·¹Òà´ÕÂǡѹ - Instant Messaging Worm Êè§µÑÇàͧ¨Ò¡à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍä»ËÒ¤¹·ÕèÍÂÙèã¹ contact list ¼èÒ¹·Ò§â»Ãá¡ÃÁ IM àªè¹ MSN, ICQ
Trojan à»ç¹ malware ÍÕ¡ª¹Ô´·Õ辺àË繡ÒÃá¾ÃèÃкҴä´é·ÑèÇä» trojan Âѧáºè§ÍÍ¡ä´éà»ç¹ËÅÒª¹Ô´´Ñ§¹Õé
- Remote Access Trojan (RAT) ËÃ×Í Backdoor ·Õèà»Ô´ªèͧ·Ò§ãËé¼ÙéäÁè»ÃÐʧ¤ì´ÕÊÒÁÒöà¢éÒÁҤǺ¤ØÁ ËÃ×Í·ÓÍÐäáçä´éº¹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍã¹áººÃÐÂÐä¡ Å - Data Sending/Password Sending Trojan â¢ÁÂÃËÑʼèÒ¹áÅéÇÊè§ä»ãËé¼ÙéäÁè»ÃÐʧ¤ì´Õ - Keylogger Trojan ´Ñ¡¨Ñº·Ø¡¢éͤÇÒÁ·Õè¾ÔÁ¾ì¼èÒ¹á»é¹¾ÔÁ¾ì - Destructive Trojan źä¿Å캹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍ - Denial of Service (DoS) Attack Trojan ãªé·Ó DDoS à¾×èÍâ¨ÁµÕÃкºÍ×è¹ - Proxy Trojan à»ÅÕè¹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍãËé¡ÅÒÂà»ç¹ proxy server ËÃ×Í web server, mail server à¾×èÍÊÃéÒ§ zombie network - FTP Trojan à»ÅÕè¹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍãËé¡ÅÒÂà»ç¹ FTP server - Security software Killer Trojan ¦èÒ process ËÃ×Íźâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ/â·Ã¨Ñ¹/ä¿ÅìÇÍź¹à¤Ã×èͧ·Õ赡à»ç¹àËÂ×èÍ - Trojan Downloader ´ÒǹìâËÅ´ adware, spyware, worm àÍÒÁÒµÔ´µÑ駺¹à¤Ã×èͧàËÂ×èÍ
áÅÐ malware ·Õ辺àËç¹ä´é§èÒ·ÑèÇä»ã¹»Ñ¨¨ØºÑ¹áÅÐÊÃéÒ§¤ÇÒÁÃÓ ¤Òã ËéÁÒ¡·ÕèÊØ´¡ç¤×Í spyware (ºÒ§µÓÃÒÍÒ¨ãªé¤ÓÇèÒ grayware) «Öè§áºè§ÍÍ¡ä´éà»ç¹ËÅÒª¹Ô´ («Ö觺ҧÊèǹ¡çÁվĵԡÃÃÁ¤ÅéÒÂæ trojan ´éÇÂ) àªè¹
- Adware ´ÒǹìâËÅ´áÅÐáÊ´§áº¹à¹ÍÃìâ¦É³Ò - Dialer ÍÂÙèµÒÁàÇçºâ»êà¾×èÍãªéµèÍâ·ÃÈѾ·ì·Ò§ä¡Å仵èÒ§»ÃÐà· È - Spyware à¡çºÃÇÁÃÇÁ¾ÄµÔ¡ÃÃÁ¡ÒÃãªéÍÔ¹àµÍÃìà¹çµº¹à¤Ã×èͧàËÂ×è Í - Hijacker à»ÅÕè¹á»Å§ start page, bookmark º¹ºÃÒÇà«ÍÃìàªè¹ã¹ IE - Trojan like àªè¹ trojan downlaoder ´ÒǹìâËÅ´ spyware ËÃ×Íẹà¹ÍÃìâ¦É³Ò - BHO (Browser Helper Objects) ÂÑ´àÂÕ´¿Ñ§¡ìªÑè¹·ÕèäÁè¾Ö§»ÃÐʧ¤ìº¹ºÃÒÇà«ÍÃìàªè¹ã¹ IE - Toolbar ÂÑ´àÂÕ´ toolbar ·ÕèäÁè¾Ö§»ÃÐʧ¤ìº¹ºÃÒÇà«ÍÃìàªè¹ã¹ IE
áÅеèÍ仹Õé¤×Í trend ãËÁè¢Í§ malware º¹ PC ·Õèà¡Ô´¢Öé¹áÅéÇ㹻Ѩ¨ØºÑ¹áÅСÓÅѧ¨Ðà¡Ô´¢Öé¹ã¹Í¹Ò¤µ Íѹã¡Åé «Öè§áµèà´ÔÁ¹Ñ¡à¢Õ¹äÇÃÑÊÂØ¤âºÃÒ³ à¢Õ¹äÇÃÑÊ¢Öé¹à¾ÃÒ Ð¤ÇÒÁʹء áµè attacker 㹻Ѩ¨ØºÑ¹à¢Õ¹ malware à¾×èÍà§Ô¹¡Ñ¹áÅéÇ ÁÕ¡Òë×éÍ¢ÒÂáÅ¡à»ÅÕè¹ zombie ¡Ñ¹´éÇÂàªè¹ zombie ¨Ó¹Ç¹ 5,000 à¤Ã×èͧ¢Ò 500 àËÃÕÍÐäÃẺ¹Õé
Hybrid malware/Blended Threat ¤×Í malware ·ÕèÃÇÁ¤ÇÒÁÊÒÁÒö¢Í§ virus, worm, trojan, spyware à¢éÒäÇé´éÇ¡ѹ
Zero-day attack ã¹·Õè¹ÕéËÁÒ¶֧ ¡ÒÃâ¨ÁµÕ¢Í§ÁÒÅáÇÃì/áΤà¡ÍÃì â´Â¡ÒÃãªé»ÃÐ⪹ì¨Ò¡ªèͧâËÇè (vulnerability) ·ÕèÁÕÍÂÙè㹫ͿáÇÃìËÃ×ÍÃкº»®ÔºÑµÔ¡ÒëÖè§äÁèÁÕã¤ÃÃÙ éÁÒ¡è͹ÇèÒÁÕªèͧâËÇè¹Ñé¹ÍÂÙè ËÃ×ÍÃÙéáÅéÇáµèÂѧäÁèÁÕ patch ÊÓËÃÑºÍØ´ªèͧâËÇè ËÃ×ÍÂѧäÁèÁÕ signature ¢Í§â»Ãá¡ÃÁ´éÒ¹ security ÊÓËÃѺµÃǨËÒ¡ÒÃâ¨ÁµÕ·ÕèÇèÒã¹àÇÅÒ¹Ñé¹
Zombie Network ¤×Í à¤Ã×èͧ¤ÍÁ¾ÔÇàµÍÃì¨Ó¹Ç¹ÁÒ¡æ ¨Ò¡·ÑèÇâÅ¡·Õ赡à»ç¹àËÂ×èͧ͢ worm, trojan áÅÐ malware ÍÂèÒ§Í×è¹ (compromised machine) «Ö觨ж١ attacker/hacker ãªéà»ç¹°Ò¹»¯ÔºÑµÔ¡ÒÃ㹡ÒÃÊè§ spam mail, phishing, DoS ËÃ×ÍàÍÒäÇéà¡çºä¿ÅìËÃ×ͫͿáÇÃì·Õè¼Ô´¡®ËÁÒÂ
¨ÐàËç¹ä´éÇèÒ worm, trojan, spyware (grayware) «Öè§¾ºàË繡ÒÃá¾ÃèÃкҴ·ÑèÇä»ã¹»Ñ¨¨ØºÑ¹¹ÕéÁѹäÁèãªè virus áÅÐâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ·ÑèÇä»ÊèǹãËè¡çäÁèÊÒÁÒö»éÍ §¡Ñ¹ malware ¾Ç¡¹Õéä´é·Ñé§ËÁ´´éÇ â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ·ÑèÇä»ãËé¼Å´Õá·º¨Ð 100% ¡Ñº ITW malware áµè¡ÑºÁÒÅáÇÃìÍ×è¹æáÅéÇÁѹÂѧäÁèÁÕÁҵðҹÍÐäÃÁÒ·´ÊÍ ºâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ ´Ñ§¹Ñé¹á¤èâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊ (¨ÃÔ§æáÅéǹèÒ¨ÐàÃÕ¡ÇèÒâ»Ãá¡ÃÁ»éͧ¡Ñ¹ÁÒÅáÇÃìÁÒ¡¡Çè Ò) á¤èÍÂèÒ§à´ÕÂÇäÁèÊÒÁÒö»éͧ¡Ñ¹ÁÒÅáÇÃì·Õè¡ÅèÒÇÁÒä´é· Ñé§ËÁ´
áµèÁÕâ»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊÍÂÙèÂÕèËéÍ˹Öè§«Öè§à¹é¹¡Òà µÃǨËÒÁÒÅáÇÃì·Ø¡æÍÂèÒ§·Õè¡ÅèÒÇÁÒẺàÍÒ¨ÃÔ§àÍҨѧ ẺàÍÒà»ç¹àÍÒµÒ (äÁèÁÒÅáÇÃì¡çà¤Ã×èͧ¢Í§àÃÒä´éµÒ ¡Ñ¹ä»¢éҧ˹Öè§) â»Ãá¡ÃÁ¹Ñ鹤×Í Kaspersky Anti-Virus (KAV) Íѹ¹Õé¼ÁäÁèä´é¤èÒâ¦É³Ò ¼ÁäÁèä´é¢Ò KAV áÅÐäÁèä´éªÕé¹Óã¤Ã¹Ð¤ÃѺ áµèºÍ¡¨Ò¡¤ÇÒÁÃÙéáÅлÃÐʺ¡Òóì·Õè¼ÁÁÕ áµè¡çäÁèä´éËÁÒ¤ÇÒÁÇèÒâ»Ãá¡ÃÁÍ×è¹æ äÁè´Õ¹Ð¤ÃѺ ¡çÍÂèÒ§·ÕèºÍ¡¤×Í â»Ãá¡ÃÁ»éͧ¡Ñ¹äÇÃÑÊá·º¨Ð·Ø¡ÂÕèËéÍ ÊÒÁÒö»éͧ¡Ñ¹¡ÅØè ÁÁÒÅáÇÃì·ÕèÊӤѷÕèÊØ´ ·Õè¾Ç¡àÃÒÁÕâÍ¡Òʾºà¨ÍÁÒ¡·ÕèÊØ´ ÍѹµÃÒ·ÕèÊØ´ ·ÕèàÃÕ¡ÇèÒ ITW malware ä´éẺ 100% ËÒ¡àÃÒÍѾഷÁѹ·Ñ¹àÇÅÒáÅÐãªéÁѹÍÂèÒ§¶Ù¡µéͧ ÊèǹÁÒÅáÇÃìÍ×è¹æ·ÕèàËÅ×ÍàÃÒ¡çãªéâ»Ãá¡ÃÁ੾ÒзҧÍ×è ¹æ ªèÇ àªè¹ â»Ãá¡ÃÁ»éͧ¡Ñ¹â·Ã¨Ñ¹ â»Ãá¡ÃÁ»éͧ¡Ñ¹Ê»ÒÂáÇÃì ä¿ÅìÇÍÅ áÅÐÍ×è¹æ
ÊÒà˵ØËÅÑ¡æ ·Õè·ÓãËé¤ÍÁ¾ÔÇàµÍÃìµÔ´ malware (virus, worm, trojan, spyware, etc)
1. ·Ò§ÍÕàÁÅÅì â´Â੾ÒСÒôٴÍÕàÁÅÅì¨Ò¡ pop3 server ´éÇÂâ»Ãá¡ÃÁÍÂèÒ§ Outlook Express ÊèǹãËè¨Ðà»ç¹¾Ç¡Ë¹Í¹ÍÔ¹àµÍÃìà¹çµ»ÃÐàÀ·
mass-mailing worm àªè¹ Netsky, Beagle, Mydoom
2. ¨Ò¡ªèͧâËÇè (vulnerability) ¢Í§Ãкº»¯ÔºÑµÔ¡ÒÃËÃ×ͧ͢ â»Ãá¡ÃÁ â´Â network worm, mass-mailing worm ·Õèâ¨ÁµÕªèͧâËÇè¢Í§ Windows àªè¹ Blaster, Sasser, Bobax «Öè§µèÍä»ÍÒ¨¨Ðà»ç¹¡Ã³Õ¢Í§ zero-day attack
3. ¨Ò¡¡ÒÃà¢éÒä»ã¹àÇ纷ÕèÁÕ malicious script/malware «è͹ÍÂÙè¡çÍÂèÒ§àÇçºâ»ê àÇçº crack ·Ñé§ËÅÒ àªè¹¾Ç¡ dialer, trojan downloader,
spyware, browser hijacker
4. ¨Ò¡¡ÒÃà¢éÒä»ã¹àÇ纸ÃÃÁ´Ò·ÕèµÔ´äÇÃÑÊàªè¹ VBS/Redlof
5. ¨Ò¡¡ÒÃà¤Å×è͹ÂéÒÂä¿Åì¨Ò¡à¤Ã×èͧ˹Öè§ä»ÂѧÍÕ¡à¤Ã×èÍ §Ë¹Öè§¼èÒ¹·Ò§á¼è¹´ÔÊ¡ìàªè¹ macro virus ·ÕèÍÂÙèã¹ä¿Åì¢Í§ MS Office
6. ¡ÒôÒÇâËÅ´ä¿Åì¨Ò¡à¤Ã×Í¢èÒ P2P ÍÂèÒ§àªè¹ KaZaA àªè¹ P2P worm áÅÐâ·Ã¨Ñ¹·Ñé§ËÅÒÂ
7. ¨Ò¡¡ÒôÒÇâËÅ´ä¿Åì¨Ò¡áËÅè§·ÕèäÁè¹èÒàª×èͶ×ÍÍÂèÒ§àªè ¹àÇçº crack, warez ÊèǹãËè¨Ðà»ç¹¾Ç¡ private/modified trojan
8. ¨Ò¡¡ÒÃàÅè¹ËÃ×ÍÃѺä¿Åì¨Ò¡â»Ãá¡ÃÁ»ÃÐàÀ· Instant Message àªè¹ MSN, ICQ
9. ¨Ò¡¡ÒÃàÅè¹â»Ãá¡ÃÁ»ÃÐàÀ· IRC àªè¹ Pirch98 àªè¹ IRC Worm áÅÐÍ×è¹æ ·ÕèÂѧ¹Ö¡äÁèÍÍ¡µÍ¹¹Õé
àÃÒÁÒ´Ù¤ÇÒÁËÁÒ¢ͧª×èÍäÇÃÑʡѹ¤ÃѺ
à¾×è͹椧¨ÐàËç¹ÃÒª×èÍÍѾഷäÇÃÑʵç˹éÒàÇ纵èÒ§æà »ç¹»ÃÐ¨Ó áÅÐà¤ÂʧÊÑ¡ѹºéÒ§äËÁ¤ÃѺ ÇèÒª×èͧ͢äÇÃÑÊ·ÕèàËç¹·ÑèÇ仹Ñé¹ÁÕ¤ÇÒÁËÁÒÂÇèÒÍÂèÒ§ äÃ
Êèǹ»ÃСͺ¢Í§ª×èÍäÇÃÑʹÑé¹áºè§ä´éà»ç¹ÊèÇ¹æ ´Ñ§¹Õé¤ÃѺ Family_Names Group_Name Variant Tail W32 Mydoom bb @mm
1. ÊèǹáááÊ´§ª×è͵ÃСÙŢͧäÇÃÑÊ (Family_Names) ÊèǹÁÒ¡áÅéǨеÑé§µÒÁ·ÕèäÇÃÑʵÑǹÑé¹ ¡èÍ»ÑËÒ¢Ö鹡ѺÃкº»¯ÔºÑµÔ¡ÒÃÍÐäà ËÃ×ÍÀÒÉÒ·Õèãªé㹡ÒÃà¢Õ¹¢Í§äÇÃÑÊ ´Ñ§µÒÃÒ§¹Õé
Family_Names ¤ÇÒÁËÁÒÂ
WM äÇÃÑÊ·Õèà»ç¹ÁÒâ¤Ã¢Í§â»Ãá¡ÃÁ Word W97M äÇÃÑÊ·Õèà»ç¹ÁÒâ¤Ã¢Í§â»Ãá¡ÃÁ Word 97 XM äÇÃÑÊ·Õèà»ç¹ÁÒâ¤Ã¢Í§â»Ãá¡ÃÁ Excel X97M äÇÃÑÊ·Õèà»ç¹ÁÒâ¤Ã¢Í§â»Ãá¡ÃÁ Excel 97 W95 äÇÃÑÊ·ÕèÁռšÃзº¡ÑºÃкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì 95 W32/Win32 äÇÃÑÊ·ÕèÁռšÃзº¡ÑºÃкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì 32 ºÔµ WNT äÇÃÑÊ·ÕèÁռšÃзº¡ÑºÃкº»¯ÔºÑµÔ¡ÒÃÇÔ¹â´ÇÊì NT 32 ºÔµ I-Worm/Worm ˹͹ÍÔ¹à·ÍÃìà¹çµ Trojan/Troj â·Ã¨Ñ¹ VBS äÇÃÑÊ·Õè¶Ù¡¾Ñ²¹Ò´éÇ Visual Basic Script AOL â·Ã¨Ñ¹ America Online PWSTEAL â·Ã¨Ñ¹·ÕèÁÕ¤ÇÒÁÊÒÁÒö㹡ÒââÁÂÃËÑʼèÒ¹ Java äÇÃÑÊ·Õè¶Ù¡¾Ñ²¹Ò´éÇÂÀÒÉÒ¨ÒÇÒ Linux äÇÃÑÊ·ÕèÁռšÃзº¡ÑºÃкº»¯ÔºÑµÔ¡ÒÃÅԹء«ì Palm äÇÃÑÊ·ÕèÁռšÃзº¡ÑºÃкº»¯ÔºÑµÔ¡Òà Palm OS Backdoor à»Ô´ªèͧãËé¼ÙéºØ¡ÃØ¡à¢éÒ¶Ö§à¤Ã×èͧä´é HILLW ºè§ºÍ¡ÇèÒäÇÃÑʶ١¤ÍÁä¾Åì´éÇÂÀÒÉÒÃдѺÊÙ§
2. Êèǹª×èͧ͢äÇÃÑÊ (Group_Name) µÑǹÕé¨Ð¶Ù¡µÑé§¢Ö鹨ҡª×èͧ͢¼Ùé·Õèà¢Õ¹äÇÃÑÊ ËÃ×͹ÒÁá½§ ·Õèãªéá·Ã¡ã¹â¤é´¢Í§µÑÇâ»Ãá¡ÃÁäÇÃÑÊ
3. Êèǹ¢Í§ Variant ÃÒÂÅÐàÍÕ´Êèǹ¹Õé¨ÐºÍ¡ÇèÒÊÒ¾ѹ¸Øì¢Í§äÇÃÑʪ¹Ô´¹Ñé¹ æ ÁÕ¡ÒûÃѺ»ÃاÊÒ¾ѹ¸Øì¨¹ÁÕ¤ÇÒÁÊÒÁÒöµèÒ§¨Ò¡ÊÒ¾ѹ¸ Øìà´ÔÁ·ÕèÁÕÍÂÙè
Vvariant ÁÕ 2 ÅѡɳФ×Í
Major_Variants ¨ÐµÒÁËÅѧÊèǹª×èͧ͢äÇÃÑÊ à¾×èͺ觺͡ÇèÒÁÕ¤ÇÒÁᵡµèÒ§¡Ñ¹ÍÂèÒ§ªÑ´à¨¹ àªè¹ W32.Mydoom.bb@MM (bb à»ç¹ Major_Variant) ᵡµèÒ§¨Ò¡ W32.Mydoom.Q@MM ÍÂèÒ§ªÑ´à¨¹ Minor_Variants ãªéºè§ºÍ¡ã¹¡Ã³Õ·ÕèᵡµèÒ§¡Ñ¹¹Ô´Ë¹èÍ 㹺ҧ¤ÃÑé§ Minor_Variant à»ç¹µÑÇàÅ¢·ÕèºÍ¡¢¹Ò´ä¿Åì¢Í§äÇÃÑÊ µÑÇÍÂèÒ§àªè¹ W32.Funlove.4099 ˹͹ª¹Ô´¹ÕéÁÕ¢¹Ò´ 4099 KB.
4. Êèǹ·éÒ (Tail) à»ç¹Êèǹ·Õè¨ÐºÍ¡ÇèÒÇÔ¸Õ¡ÒÃá¾Ãè¡ÃШÒ »ÃСͺ´éÇÂ
@M ËÃ×Í @m ºÍ¡ãËéÃÙéÇèÒäÇÃÑÊËÃ×Í˹͹ª¹Ô´¹Õéà»ç¹ "mailer" ·Õè¨ÐÊè§µÑÇàͧ¼èÒ¹·Ò§ÍÕ-àÁÅìàÁ×èͼÙéãªéÊè§ÍÕ-àÁÅìà·èÒ¹Ñé¹ @MM ËÃ×Í @mm ºÍ¡ãËéÃÙéÇèÒäÇÃÑÊËÃ×Í˹͹ª¹Ô´¹Õéà»ç¹ "mass-mailer" ·Õè¨ÐÊè§µÑÇàͧ¼èÒ¹·Ø¡ÍÕ-àÁÅìáÍ´à´ÃÊ·ÕèÍÂÙèã¹àÁÅìºÍ¡«ì
µÑÇÍÂèÒ§ W32/Mydoom.bb@mm ËÁÒ¤ÇÒÁÇèÒ äÇÃÑʪ¹Ô´¹Õéâ¨ÁµÕã¹à¾Åµ¿ÍÃìÁ¢Í§ÇÔ¹â´Ç 32 ºÔµ ª×èͧ͢äÇÃÑʤ×Í Mydoom Variant ÊÒ¾ѹ¸Øì¢Í§µÑǹÕé¤×Í bb áÅÐÁÕ¤ÇÒÁÊÒÁÒö·Õè¨ÐÊè§µÑÇàͧ¼èÒ¹·Ø¡ÍÕ-àÁÅìáÍ´à´ÃÊ·ÕèÍÂÙèã¹àÁÅìºÍ¡«ì
ËÇѧÇèÒ¤§à¢éÒã¨ä´éÁÒ¡¢Öé¹
·ÕèÁÒ: gGroup
|