当前位置:首页 >英文主页 >中英对照 > 报告详情

美国网络安全和基础设施安全局:2025 Fast Flux网络安全警告报告(英文版)(10页).pdf

上传人: Y**** 编号:630469 2025-04-23 10页 840.93KB

下载:

1、 TLP:CLEAR This information is marked TLP:CLEAR.Recipients may share this information without restriction.U/OO/136180-25|PP-25-1337|April 2025 Ver.1.0 TLP:CLEAR Cybersecurity Advisory Fast Flux:A National Security Threat Executive summary Many networks have a gap in their defenses for detecting and

2、blocking a malicious technique known as“fast flux.”This technique poses a significant threat to national security,enabling malicious cyber actors to consistently evade detection.Malicious cyber actors,including cybercriminals and nation-state actors,use fast flux to obfuscate the locations of malici

3、ous servers by rapidly changing Domain Name System(DNS)records.Additionally,they can create resilient,highly available command and control(C2)infrastructure,concealing their subsequent malicious operations.This resilient and fast changing infrastructure makes tracking and blocking malicious activiti

4、es that use fast flux more difficult.The National Security Agency(NSA),Cybersecurity and Infrastructure Security Agency(CISA),Federal Bureau of Investigation(FBI),Australian Signals Directorates Australian Cyber Security Centre(ASDs ACSC),Canadian Centre for Cyber Security(CCCS),and New Zealand Nati

5、onal Cyber Security Centre(NCSC-NZ)are releasing this joint cybersecurity advisory(CSA)to warn organizations,Internet service providers(ISPs),and cybersecurity service providers of the ongoing threat of fast flux enabled malicious activities as a defensive gap in many networks.This advisory is meant

6、 to encourage service providers,especially Protective DNS(PDNS)providers,to help mitigate this threat by taking proactive steps to develop accurate,reliable,and timely fast flux detection analytics and blocking capabilities for their customers.This CSA also provides guidance on detecting and mitigat

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要内容是关于网络安全威胁“快速流量”(Fast Flux)的联合网络安全通告。快速流量是一种恶意技术,通过快速改变域名系统(DNS)记录来隐藏恶意服务器的地理位置,使网络防御者难以检测和阻止。这种技术被包括网络犯罪分子和国家行为体在内的恶意网络行为者广泛使用,以逃避检测并建立强大的、高可用的命令和控制(C2)基础设施。 文章指出,快速流量技术的主要优势包括增加的弹性、使IP封锁无效和匿名性。此外,快速流量不仅用于维护C2通信,还用于使网络钓鱼活动更难以阻止或关闭,以及为网络犯罪论坛和市场提供高可用性。 为了检测快速流量活动,建议采用多层方法,包括利用威胁情报、异常检测系统、分析TTL值、审查DNS解析、使用流数据、开发快速流量检测算法、监控网络钓鱼活动以及实施客户透明度和信息共享。 为了减轻快速流量带来的风险,建议采取以下措施:DNS和IP封锁和沉洞、快速流量启用的恶意活动的声誉过滤、增强监控和日志记录、协作防御和信息共享、网络钓鱼意识和培训。 文章强调,通过实施稳健的检测和缓解策略,组织可以显著降低由快速流量启用的威胁所带来的风险。
什么是快速流量技术?它对网络安全有何威胁? 快速流量技术如何被恶意行为者用于逃避检测? 组织如何检测和缓解快速流量技术带来的威胁?
客服
商务合作
小程序
服务号
折叠