114 年 國立成功大學智慧資訊安全碩士學位學程《資訊安全概論》
第 1 題
Please explain what "Phishing" (7%) and "Spear Phishing" (7%) are and how they differ (6%).
登入後即可作答並保存紀錄。
此題考驗考生對網路釣魚(Phishing)與進階式網路釣魚(Spear Phishing)的理解及其差異。
Phishing (網路釣魚)
Phishing 是一種網路詐騙的行為,攻擊者透過偽裝成可信賴的機構(如銀行、社交媒體平台、電子商務網站等)發送電子郵件、訊息或建立假冒網站,誘騙使用者提供個人敏感資訊,例如帳號密碼、信用卡號碼、身分證字號等。其特點是攻擊範圍廣泛,通常一次性針對大量使用者,而不區分特定目標。
Spear Phishing (進階式網路釣魚)
Spear Phishing 是 Phishing 的一種更具針對性的變體。攻擊者會事先收集目標的個人資訊(如姓名、職位、公司、興趣、同事關係等),並利用這些資訊來客製化攻擊訊息,使其看起來更加可信,以提高成功率。例如,攻擊者可能會偽裝成目標的同事、上司,或是與目標公司有業務往來的合作夥伴。
兩者差異
| 特徵 | Phishing (網路釣魚) | Spear Phishing (進階式網路釣魚) |
|---|
第 2 題
Please explain what the "Cyber Kill Chain" is (10%), and describe its main standardized stages, providing an explanation for each stage (10%).
登入後即可作答並保存紀錄。
此題考驗考生對「網路殺戮鏈」(Cyber Kill Chain)模型的理解,包括其定義、目的以及各個階段的詳細說明。
網路殺戮鏈 (Cyber Kill Chain)
網路殺戮鏈是由洛克希德·馬丁公司(Lockheed Martin)提出的一個資安模型,用於描述攻擊者在發動網路攻擊時所遵循的一系列階段。這個模型將攻擊過程分解為可識別的步驟,以便防禦者能夠理解攻擊者的行為模式,並在攻擊的任一階段進行偵測、攔截或阻斷,從而破壞攻擊鏈,阻止攻擊成功。
網路殺戮鏈的七個階段
-
偵察 (Reconnaissance)
- 說明: 攻擊者在發動攻擊前,會先收集目標系統、網路、人員等相關資訊。這包括公開資訊搜尋(OSINT)、掃描目標網路、識別漏洞、研究目標組織結構和員工等。目的是了解目標的弱點和可利用的途徑。
- 範例: 攻擊者透過 Google 搜尋、LinkedIn、公司網站等管道,了解目標公司的技術堆疊、員工名單、聯絡方式等。
-
武器化 (Weaponization)
- 說明: 攻擊者將偵察階段收集到的資訊,與惡意軟體(如病毒、木馬、勒索軟體)或攻擊工具結合,製作出能夠利用目標漏洞的攻擊載具(Payload)。
- 範例: 攻擊者將一個後門程式(Backdoor)與一個偽裝成重要文件的附件打包,製作成一個可執行檔。
-
傳遞 (Delivery)
- 說明: 攻擊者將武器化階段製作的攻擊載具傳遞給目標。常見的傳遞方式包括透過電子郵件附件、惡意連結、USB 隨身碟、入侵的網站等。
- 範例: 將惡意附件透過釣魚郵件發送給目標使用者。
-
利用 (Exploitation)
- 說明: 當攻擊載具成功傳遞到目標系統後,攻擊者會觸發載具中的漏洞,執行惡意程式碼。這通常是攻擊者首次獲得對目標系統的存取權限的階段。
第 3 題
There are many types of malware, please try to define "WORM" (10%) and "Trojan horse" (10%) among them.
登入後即可作答並保存紀錄。
此題考驗考生對兩種常見惡意軟體(Malware)的定義與區別的理解:蠕蟲(WORM)和特洛伊木馬(Trojan horse)。
WORM (蠕蟲)
蠕蟲是一種獨立的惡意程式,其主要特點是能夠自我複製並透過網路傳播,而不需要使用者介入或依賴其他程式。蠕蟲通常利用系統的漏洞(如作業系統的漏洞、網路協定的弱點)來感染其他電腦,並在感染過程中不斷地創建副本並散播。由於其自我傳播的能力,蠕蟲可以快速地在廣泛的網路範圍內擴散,造成嚴重的網路擁塞和系統癱瘓。
- 主要特點:
- 自我複製 (Self-replication): 能夠不斷產生自己的副本。
- 自我傳播 (Self-propagation): 無需使用者互動,主動透過網路(如網際網路、區域網路)尋找並感染其他電腦。
- 獨立性: 作為獨立的程式存在,不依附於其他檔案。
Trojan horse (特洛伊木馬)
特洛伊木馬是一種偽裝成合法、有用的程式,但實際上卻包含惡意功能的惡意軟體。它不會自我複製或主動傳播,而是依賴使用者的下載和執行。使用者可能因為被程式的表面功能所吸引,或被欺騙而主動執行它,從而無意中將木馬引入系統。一旦執行,木馬就會執行其隱藏的惡意行為,例如:竊取資訊、建立後門、破壞檔案、遠端控制等。
- 主要特點:
- 偽裝性 (Disguise): 偽裝成合法或有用的軟體。
- 欺騙性 (Deception): 誘騙使用者執行。
- 無自我複製/傳播: 不會主動自我複製或透過網路傳播。
第 4 題
【題組共用題幹】
Various approaches for modeling cybersecurity attacks and defenses have been developed over time.
Among them are methodologies based on tree structures, as well as frameworks introduced by
organizations such as Lockheed Martin's Cyber Kill Chain, Microsoft's STRIDE, and the MITRE
ATT&CK framework. These models describe the steps involved in either executing an attack or
defending against one, and they provide different levels of detail depending on the context. This paper
expands upon previous work that employed the Blackboard Architecture for cyber warfare and
introduces a more generalized framework for modeling attacks based on frameworks or paradigms. This
approach goes beyond the typical focus on exploiting a single vulnerability targeting a specific asset.
The proposed system, known as the Blackboard Architecture Cyber Command Entity Attack Route
(BACCER), integrates a set of rules and factual information to determine the type of attack and guide
decision-making. It also incorporates actions that support reconnaissance activities and both offensive
and defensive measures. The paper illustrates how BACCER can effectively model tree-structured
attacks and other complex models. (from IEEE SmartCloud 2020)
(1) Which manufacturer or organization proposed the STRIDE model? (3%)
(2) What is the name of the model proposed by Lockheed Martin? (3%)
(3) What is the name of the system or framework proposed in this abstract? Please write the full text
and abbreviations. (3%)
登入後即可作答並保存紀錄。
此題為閱讀測驗題組,考生需要根據提供的英文摘要,回答關於資安模型與框架的相關問題。
核心觀念: 閱讀理解、辨識關鍵資訊、資安模型與框架。
(1) Which manufacturer or organization proposed the STRIDE model? (3%)
詳解: 摘要中提到:「Among them are methodologies based on tree structures, as well as frameworks introduced by organizations such as Lockheed Martin's Cyber Kill Chain, Microsoft's STRIDE, and the MITRE ATT&CK framework.」這句話明確指出 STRIDE 模型是由 Microsoft 提出的。
【答案】Microsoft
第 5 題
【題組共用題幹】
The Diamond model uses a diamond-shaped structure to highlight the relationships and characteristics
of an attack, based on its four essential components: adversary, infrastructure, capability, and victim.
This model illustrates how an adversary leverages a capability over an infrastructure to target a victim.
The four key components of an attack form the vertices of the diamond, which is the origin of the model's
name. Additionally, the model defines supplementary meta-features to support higher-level constructs,
applying measurement, testability, and repeatability to establish a more thorough scientific method of
analysis. Released by the US Department of Defense in 2013, the Diamond model serves as both a
cognitive framework and a set of mathematical techniques. The cognitive model helps security
professionals organize complex, interrelated logic, while the mathematical techniques aid in refining
strategic decision-making and analytical workflows in the face of adversarial threats. (from IEEE ISSE
2022)
(1) What elements does the core component of the diamond model consist of? (3%)
(2) When and who proposed the diamond model? (3%)
(3) From the information, which journal or conference do you think the above article was published in?
Please specify the journal or conference and provide its name. (3%)
登入後即可作答並保存紀錄。
此題為閱讀測驗題組,考生需要根據提供的英文摘要,回答關於「Diamond Model」的相關問題。
核心觀念: 閱讀理解、辨識關鍵資訊、資安模型。
(1) What elements does the core component of the diamond model consist of? (3%)
詳解: 摘要中提到:「The Diamond model uses a diamond-shaped structure to highlight the relationships and characteristics of an attack, based on its four essential components: adversary, infrastructure, capability, and victim.」這清楚列出了模型的核心四個組成要素。
【答案】Adversary, infrastructure, capability, and victim.
(2) When and who proposed the diamond model? (3%)
詳解: 摘要中說明:「Released by the US Department of Defense in 2013, the Diamond mod