Showing posts with label Kaspersky Lab. Show all posts
Showing posts with label Kaspersky Lab. Show all posts

Saturday, September 22, 2012

Kaspersky Lab will fight against botnets


Kaspersky Lab announces the obtaining of the United States, two new patents on advanced, proprietary technology. New technologies have to fight cybercrime - mainly through the effective neutralization of threats on infected systems, and to identify, analyze and block spam generated by botnets.
The first technology covered by the patent (number 8,181,247) allows you to recover systems infected by malicious software. This function analyzes the activity of various objects (eg installed programs), acting on the basis of data from the event log and determining any dependencies that may exist between objects. In case of detection of malicious activity, the technology makes it possible to block any changes that have been made to the system. Unaffected is restored version of the file and the correct entry in the registry, while the data and records as a result of malicious programs are removed. In order to prevent further infections security application severs all network connections established by malware and off by running processes. The new technology, which is part of the System Control module in Kaspersky Lab, you revert to an infection of malicious programs, while maintaining performance.
The second patent (number 8,195,750) describes a system and method of detection of botnets used to carry out mass mailings. This technology organizes the collection and analysis of statistics from mail servers. The collected data is then used to create a model of sending e-mail, depending on their size and date of shipment. Further analysis allows to identify the computers involved in the mailings certain e-mails, which are probably part of a botnet. One of the advantages of this technology is the speed of operation: collection of data on the botnet takes a relatively short time - from a few hours to one day.


Kaspersky Labは米国、先進、独自の技術上の2つの新たな特許の取得を発表しました。主に感染したシステム上の脅威を効果的に中和を介して、特定、分析、ボットネットによって生成されたスパムをブロックする - 新技術は、サイバー犯罪と戦うために持っている。
特許(番号8181247)によって覆われて初の技術を使用すると、悪意のあるソフトウェアに感染してシステムを復旧することができます。この関数は、イベント·ログからデータに基づいて行動し、オブジェクト間に存在する可能性のある依存関係を決定し、様々なオブジェクト(例えば、インストールされているプログラム)の活動を分析しています。悪意のあるアクティビティを検出した場合には、技術はそれが可能なシステムに加えられた変更をブロックすることができます。悪意のあるプログラムの結果としてのデータや記録が取り外されている間は影響を受けませんが、ファイルやレジストリ内の正しいエントリのバージョンが復元されます。さらなる感染のセキュリティアプリケーションを防止するために実行しているプロセスによってマルウェアとオフによって確立されたすべてのネットワーク接続を切断する。性能を維持しながら、カスペルスキーでシステム制御モジュールの一部である新しい技術は、あなたが、悪意のあるプログラムの感染に戻す。
2つ目の特許(番号8195750)は、大量のメールを実行するために使用されるボットネットの検出のシステムおよび方法を説明します。この技術は、メールサーバからの統計情報の収集と分析を整理します。収集されたデータは、出荷のそのサイズと日付に応じて、電子メールの送信のモデルを作成するために使用されます。さらなる分析は、おそらくボットネットの一部である電子メール特定の郵送に関わるコンピュータを識別することができます。この技術の利点の一つは、操作の速度です:ボットネットに関するデータの収集は比較的短い時間を要する - 数時間から1日。


卡巴斯基实验室宣布,获得美国两项新专利,专有技术先进的。新技术打击网络犯罪 - 主要是通过有效中和在受感染的系统的威胁,识别,分析和阻止垃圾邮件由僵尸网络产生的。
第一项技术专利(8181247号)所涵盖的让你恢复被恶意软件感染的系统。功能分析活动的各种对象(例如安装程序),数据的基础上,从事件日志中,并确定任何可能存在的对象之间的依赖关系。以检测恶意活动的情况下,该技术使得能够阻止已经作出到系统的任何更改。不受影响恢复的文件,并在注册表中的正确条目的版本,而被删除的恶意程序的数据和记录的结果。为了防止进一步的感染的安全应用程序服务器建立网络连接的恶意软件和关闭正在运行的进程。新技术,它是系统控制模块在卡巴斯基实验室的一部分,还原到感染的恶意程序,同时保持高性能。
第二项专利(8195750号)介绍了一种系统和方法,用于开展群众性的邮件的僵尸网络的检测。该技术组织从邮件服务器的统计数据的收集和分析。收集到的数据,然后创建了一个模型,发送电子邮件,这取决于它们的大小和装运日期。进一步的分析可以找出所涉及的计算机中的的邮件一定电子邮件,这可能是一个僵尸网络的一部分。这种技术的优点之一是操作的速度:僵尸网络上的数据的集合,以相对短的时间 - 从几个小时到一天。


Wiper sabotaged oil extraction


In April of this year. appeared in a series of reports of malicious malware, codenamed Wiper, who attacked the computer systems associated with many oil installations in Western Asia.
In May 2012, a team of experts from Kaspersky Lab led the search initiated by the International Telecommunication Unit (ITU) to investigate the incident and determine the potential threat posed by this new pest, because it had an impact on global sustainable development and security. Kaspersky Lab has released a study analyzing the effect of constituting the hard drives obtained from the machines affected by the wiper. The analysis revealed information about an extremely effective method used by the wiper to the destruction of computer systems, including a unique pattern of data cleaning and destructive behavior. While searching for unintentionally resulted in the detection of wiper cyber espionage campaign, Flame, Wiper he was not found and remains unidentified. However, the wiper is used effectively destroying the machines can encourage followers to create a malicious malware such as Shamoon, which appeared in August 2012,

Summary results of the analysis
• Kaspersky Lab confirms that the wiper was responsible for the attacks carried out on computer systems in Western Asia held on 21 - 30 April 2012
• Analysis of the damaged hard drive wiper cleaning regimen revealed specific data together with the name of a specific component malware that begins with the characters "~ D". These findings are reminiscent of Duqu and Stuxnet pests that also apply file names beginning with "~ D" and have been developed on the same platform attacks, known as "Tilded".
• Experts from Kaspersky Lab began to look for other files with names beginning with "~ D" with the KSN (Kaspersky Security Network) and tried to find additional files from wiper connection Tilded platform.
• The search identified a large number of files in Western Asia, called "~ DEB93D.tmp". Further analysis showed that the file was in fact part of another type of malicious software: Flame. Thus, Kaspersky Lab has detected Flame'a.
• Although the flame is detected during the search for wiper, a team of experts from Kaspersky Lab believes that the Wiper and Flame are two separate and independent malware.
• Despite signs of infection Wiper analysis carried out by Kaspersky Lab malware is still unknown, as there were no further incidents of data cleaning on the same schedule, and proactive protection Kaspersky Lab does not detect this pest.
• Wiper was extremely effective and can inspire others to create new "imitative" copies of malicious malware such as Shamoon.

Analysis of the computers cleaned by the "wiper"
Carried out by Kaspersky Lab analysis of hard drives damaged by Wiper showed that this pest has cleared all the data that could be used to identify it. The file system modified by the wiper prevented successful execution of computers. Therefore, on any machine tested was not hardly anything on the wiper activation, it was also possible to restore or recover any data. owever survey conducted by Kaspersky Lab has revealed some valuable information, including the cleaning regimen used by the pest and the names of specific malware components and, in some cases, registry keys, indicating the name of the previous files that have been deleted from the hard drive. All these registry keys to point to the file names beginning with ~ D.

The unique pattern of data cleaning wiper
The analysis revealed a pattern consistent cleaning method to be used on any machine on which the wiper is activated. Wiper algorithm was designed to quickly and effectively destroy as many files - many gigabytes at a time. Completely erase the data took place at roughly three out of four attacked machine, the operation focused on the destruction of the first half of the disk, and then systematically clean the rest of the files, which allow the proper operation of the disk, ultimately leading to the collapse of the system. Furthermore, the identified attacks Wiper, whose aim was to NF files. These attacks would be useless, if not related to the removal of additional malware components. This was an interesting finding, since Duqu and Stuxnet stored their main code is in the files PNF.

How Wiper search led to the discovery Flame'a
Temporary files (TMP) with names starting with "~ D" were also used by Duqu, which has been developed on the same platform as the Stuxnet attacks: platform "Tilded". Following this path, the team of experts began to look for other potentially unknown file names associated with Wiper, based on the platform of "Tilded" using KSN - a cloud-based infrastructure used by Kaspersky Lab products to detect the latest threats. During this process, a team of experts found that the number of computers in Western Asia contains a file named "~ DEF983D.tmp". In this way, the Kaspersky Lab discovered Flame'a. Unfortunately, Wiper not found using this method and remains unidentified.

Alexander Gostev, chief security expert at Kaspersky Lab, said: "Analysis of the patterns left by the wiper on the hard-drive images examined, it is clear that this pest has existed and has been used to attack computer systems in West Asia in April 2012, and probably even earlier - in December 2011 While the search for Wiper Flame'a discovered, we believe that the wiper was not flame, but independent and other types of malware. destructive behavior Wiper, together with the names of the files that remain on the cleaned system , like a program that used the platform Tilded. Flame'a modular architecture was completely different and is designed to perform continuous and precise campaign of cyber espionage. Flame'a The analysis also have not identified any disruptive behavior that was characteristic of the wiper. "


今年の4月に。西アジアの多くの石油のインストールに関連するコンピュータシステムを攻撃した悪意のあるマルウェアのレポート、コードネームワイパーのシリーズで登場しました。
それは世界の持続可能な開発と安全保障への影響を持っていたので、2012年5月では、カスペルスキーの専門家のチームが、事件を調査し、この新たな害虫がもたらす潜在的な脅威を決定するために、国際電気通信ユニット(ITU)によって開始された検索を主導した。 Kaspersky Labは、ワイパーの影響を受けたマシンから取得したハードドライブを構成しているの効果を分析する研究結果を発表しました。分析では、データのクリーニングおよび破壊的行動のユニークなパターンを含むコンピュータシステムの破壊にワイパーが使用する非常に効果的な方法についての情報を明らかにした。無意識にワイパーサイバースパイキャンペーン、炎、ワイパーの検出の結果を探している間に彼が発見され、身元不明のままでいませんでした。しかし、ワイパーが機械を破壊する効果的に使用されるのは、信者がそのような2012年8月に登場しShamoon、などの悪質なマルウェアを作成することをお勧めすることができ

分析結果のサマリー
•Kaspersky Labは、ワイパーが西アジアでのコンピュータシステム上で行われた攻撃を担当したことが確認され21日に開催 - 2012年4月30
損傷したハード·ドライブのワイパー洗浄レジメンの•分析は文字 "A〜D"で始まる特定のコンポーネントのマルウェアの名前と一緒に特定のデータを明らかにした。これらの知見は、 "A〜D"で始まるファイル名を適用し、 "Tilded"として知られているのと同じプラットフォームの攻撃、上に開発されてきたDuquとStuxnetの害虫を連想させる。
カスペルスキーから•専門家は、KSN(カスペルスキーセキュリティネットワーク)と "A〜D"で始まる名前を持つ他のファイルを探し始めたとワイパー接続Tildedプラットフォームから追加のファイルを見つけることを試みた。
•検索は "〜DEB93D.tmp"と呼ばれる西アジアに多数のファイルを同定した。炎:さらなる分析は、ファイルが実際に悪意のあるソフトウェアの別の型の一部であることを示した。したがって、Kaspersky LabはFlame'aを検出しました。
炎がワイパーの検索時に検出された•が、カスペルスキーの専門家チームは、ワイパーと炎が2つ別々の独立したマルウェアであると信じている。
•カスペルスキーのマルウェアによって行わ感染ワイパー分析の兆しにもかかわらず、同じスケジュールでデータクリーニングのさらなる事件がなかったとして、まだ不明であり、積極的な保護Kaspersky Labは、この害虫を検出しません。
•ワイパーは非常に有効であり、そのようなShamoonなどの悪意のあるマルウェアの新しい "模倣"コピーを作成するために他人を刺激することができます。

"ワイパー"で駆除されたコンピューターの分析
ワイパーによって損傷ハードディスクドライブのカスペルスキー分析により行っこの害虫がそれを識別するために使用することができるすべてのデータをクリアしていることが明らかになった。ワイパーによって変更されたファイル·システムは、コンピュータの実行が成功したことを防いだ。したがって、試験したいずれのマシンではほとんどワイパーの活性化には何もしませんでした、それは、任意のデータを復元したり、回収することも可能であった。 owever Kaspersky Labが行った調査では、害虫やハードディスクドライブから削除されている以前のファイルの名前を示す特定のマルウェアのコンポーネントと、いくつかのケースでは、レジストリキーの名前で使用される洗浄レジメンを含むいくつかの貴重な情報を、明らかにした。すべてのこれらのレジストリキーは、〜Dで始まるファイル名を指すように

ワイパーを清掃するデータの一意のパターン
分析は、ワイパーが作動されているすべてのマシンで使用するパターンの一貫洗浄方法を明らかにした。一度に多くのギガバイト - ワイパーアルゴリズムは、迅速かつ効果的に多くのファイルを破壊するために設計されました。完全データは、大まかに3つのうち4つ襲わマシンの時にディスクの最初の半分の破壊に焦点を当てて操作を行われ、その後、最終的に体系的にシステムの崩壊につながる、ディスクの適切な操作を可能にするファイルの残りの部分をきれいに消去します。また、その目的は特定された攻撃のワイパーは、NFのファイルにあった。追加のマルウェア成分の除去に関連していない場合、これらの攻撃は、役に立たないでしょう。 DuquとStuxnetのが彼らのメインのコードはファイルのPNFにあるストアドので、これは面白い発見でした。

どのようにワイパー検索Flame'a発見につながった
で始まる名前の一時ファイル(TMP) "A〜D"もStuxnetの攻撃と同じプラットフォーム上で開発されたDuquによって使用された:このプラットフォームは "Tilded"。最新の脅威を検出するために、カスペルスキー製品で使用されるクラウドベースのインフラストラクチャ - このパスに続いて、専門家チームがKSNを使って "Tilded"のプラットフォームに基づいて、ワイパー、関連付けられている他の潜在的に未知のファイル名を探し始めた。この過程で、専門家のチームは、西アジアでのコンピュータの数が "〜DEF983D.tmp"という名前のファイルが含まれていることを発見した。この方法では、Kaspersky LabはFlame'aを発見しました。残念なことに、ワイパーは、このメソッドを使用していて、正体不明のまま見つかりません。

アレクサンダーゴステフ、カスペルスキーチーフセキュリティ専門家は、言った: "調べハードドライブイメージでワイパーが残したパターンの分析は、それはおそらく、この害虫が存在しており、2012年4月に西アジアでコンピュータシステムを攻撃するために使用されていることは明らかである、と以前にも - は、ワイパーFlame'aを検索し、検出されたものの、2011年12月にクリーンシステムに残っているファイルの名前と一緒に、私たちは、ワイパーが炎ではなかったと信じているが、マルウェアの独立した他の種類の破壊的な行動ワイパー。 、Tildedプラットフォームを使用するプログラムのような。Flame'aモジュラアーキテクチャは完全に異なっていたとサイバースパイ活動の継続的かつ正確なキャンペーンを実行するように設計されています。Flame'a分析もワイパーの特徴であったいかなる破壊的な行動を識別していません。 "


在今年4月。出现在一系列报告的恶意程序,代号为雨刮器,攻击计算机系统与西亚的石油设施。
2012年5月,一队来自卡巴斯基实验室的专家带领的搜索发起的国际电信组(ITU)对事件进行调查,并确定这个新的有害生物的潜在威胁,因为它有一个全球的可持续发展和安全的影响。卡巴斯基实验室公布的一项研究,分析构成的雨刮器受影响的机器的硬盘驱动器的效果。分析结果显示信息的一个非常有效的方法,使用雨刮器,以破坏计算机系统,包括数据清理和破坏性行为的独特模式。在寻找无意地导致雨刮器网络间谍活动,火焰,雨刮器的检测,他没有被发现,仍然身份不明。然而,雨刮器使用,有效地破坏了机器可以鼓励信徒创建一个恶意程序,如Shamoon,2012年8月,

分析结果摘要
•卡巴斯基实验室证实,雨刮器是负责对计算机系统进行攻击,在西亚,2012年4月21 - 30日举行
•损坏的硬盘驱动器清洁刷清洁方案的分析透露具体的数据,连同一个特定的组件的恶意软件开始字符“D”的名称。这些研究结果Duqu和Stuxnet的害虫,也适用于“D”开头的文件名,并已在同一平台上的攻击,已知为“Tilded”的影子。
•卡巴斯基实验室的专家们开始寻找其他文件KSN(卡巴斯基安全网络)与“D”开头的名字,并试图找到更多的文件从雨刮器连接Tilded平台。
•搜索发现了大量的文件在西亚,“DEB93D.tmp”。进一步的分析表明,该文件是在事实上恶意软件的一部分,另一种类型的:火焰。因此,卡巴斯基实验室已经检测到Flame'a。
虽然火焰检测雨刮在搜索过程中,一队来自卡巴斯基实验室的专家认为,雨刮器和火焰是两个独立的不同的恶意软件。
尽管有迹象显示进行了卡巴斯基实验室的恶意软件感染雨刮分析仍然是未知的,有没有再发生相同的时间表上的数据清洗,并积极主动的保护卡巴斯基实验室没有检测到这种害虫。
•雨刷是非常有效的,能够激励他人创造新的“模仿”副本的恶意程序,如Shamoon。

分析的电脑清洗“抽头”
开展由卡巴斯基实验室的硬盘驱动器损坏雨刮的分析表明,这种害虫已经清除了所有可以使用的数据,以确定它。刮水器改性阻止成功执行的计算机的文件系统。因此,在任何机器上测试,几乎没有什么是不上雨刷激活,它也可以还原或恢复任何数据。然而调查由卡巴斯基实验室已经发现了一些有价值的信息,包括的害虫所使用的清洗方案和具体的恶意软件组件的名称和,在某些情况下,注册表项,说明在以前的文件,已被删除从硬盘驱动器的名称。所有这些注册表项〜D.开头的文件名

独特的模式,数据清洗雨刮器
分析揭示的图案一致的清洗方法,该雨刮器被激活的任何机器上使用。雨刮器算法的目的是要迅速和有效地摧毁尽可能多的文件 - 许多GB的一次。完全擦除的数据了地方大致有三种出的4攻击机,集中销毁的磁盘上半年的操作,然后系统清理其余的文件,它允许在适当的操作的磁盘,最终导致系统崩溃。此外,识别的攻击雨刮器,其目的是NF文件。这些攻击是无用的,如果不涉及到去除额外的恶意软件组件。这是一个有趣的发现,因为Duqu和Stuxnet存储他们的主要代码文件中的PNF。

,雨刮搜索发现Flame'a
临时文件(TMP)的名字开始与“〜D”也使用Duqu,已在同一平台上开发的Stuxnet攻击平台“Tilded”。这条道路,专家团队开始寻找其他潜在的未知文件名与雨刮上的使用KSN“Tilded”的平台 - 一个基于云的基础设施所使用的卡巴斯基实验室产品检测最新的威胁。在这个过程中,一个专家小组发现,在西亚的计算机数量包含名为“〜DEF983D.tmp”的文件。在这种方式中,卡巴斯基实验室发现Flame'a,。不幸的是,雨刮器没有发现使用这种方法,仍然身份不明。

亚历山大·高斯特夫,首席安全专家卡巴斯基实验室,说:“留下的雨刮器上的硬盘驱动器影像检查的模式分析,它是明确的,此虫已存在的和已经被使用到攻击计算机系统中西亚在2012年4月,并可能甚至更早 - 2011年12月虽然发现雨刷Flame'a搜索,我们相信,雨刮器没有火焰,但独立和其他类型的恶意软件。破坏性的行为雨刷,一起保持在清洁系统的文件的名字,像一个程序使用的平台Tilded。Flame'a模块化的架构是完全不同的,是设计用来执行连续和精确的网络间谍活动。Flame'a的分析也没有发现任何破坏性行为为特征的雨刮器。“


Wednesday, August 29, 2012

Kaspersky Lab: Internet heaviest sins - see what isthreatening you


In the period from 25 to 28 June 2012, in Moscow took place, organized by Kaspersky Lab summit devoted to cyber security. Its main theme was emerging risks for internet users. Also presented a new version of the company's flagship product - security suite Kaspersky Internet Security 2013. As the only Polish version had the opportunity to participate in this event. On the occasion of the visit we were able to take a look at the company headquarters located in a Moscow, as well as talk with the experts of Kaspersky Lab.
Kaspersky Lab is one of the fastest growing companies in the security industry. It is one of the leading providers of anti-virus software in the world. It operates in nearly 200 countries around the world. It employs more than 2,400 employees. With its products are used by over 300 million users and 200 thousand. corporations. They offer a range of solutions dedicated to residential and business users, providing protection for various devices - from personal computers to mobile, ending on servers. Conference on the theme of threats to Internet users has been scheduled on 27 June 2012. Held at the majestic halls of Radisson Royal Hotel, located in the heart of Moscow in Russia. Their speeches were leading specialists Kaspersky Lab: Head of Marketing - Alexander Erofeev, senior security - Stefan Tanase, Senior Regional Researcher - Dmitry Bestuzhev, director Globalego team of Research and Analysis - Costin Raiu, Senior Expert Committee . safety - Vitaly Kamliuk and chief technology - Nikolai Grebennikov and chief product - Peter Merkulov. The icing on the cake was the speech of the founder and CEO of Kaspersky Lab - Eugene Kaspersky. Speaking schedule was tight - there was no time for boredom.

The modern surfer

The conference began with a presentation marketing chief, Alexander Erofeev'a that characterized the modern Internet user, practically all of us. He noted that the technology has changed people. Today we can not imagine life without our electronic devices, gadgets, and above all, access to the Internet, from which you want to use anywhere, anytime.
In the past few years, it is in our area Internet community has developed most rapidly. In addition, most of us use every day more than two devices connected to the Internet. A desktop computer, notebook and smartphone that is not all. Increasingly, we decide to buy a comfortable netbooks and tablets, which are designed for surfing the web.

Everything on the Internet

Today, none of us have already sent letters and does not stand in line at the bank. Most of the cases we handle over the Internet, without leaving your home. Transfers communications over the Internet instead of in the mail, social networking sites for quick and wider communication, watching videos of various services such as YouTube, as a form of entertainment, shopping and online auctions instead of traditional shopping and e-mails instead of letters - it's all very easier our lives. Unfortunately, often we do not realize the dangers lurking on the network and we have a problem with a diagnosis of cyber attacks.

What's the problem?

Popularity computers are considered to be relatively safe for years does not change. It's not Linux or Mac OS computers dominated the Internet. The vast majority of us choose the popular Windows operating system. For many years, the trend has not changed, and at least for now is not expected in this respect of any revolution. And it is on this platform is the most risks. Using your computer, smartphone or tablet often log on to the bank and shopping. Blindly trust online banking services and devices that we have. At every fifth tablet parameters are stored access to your bank account - it's the same as if we wrote on the card ATM PIN. More and more users will be affected by a variety of problems - spam, viruses, leakage of private data, unwanted software, phishing, or loss or theft of the device. These situations are with us in everyday life and are increasingly affecting us.

モスクワで2012年6月25から28までの期間において、サイバーセキュリティに専念カスペルスキーサミットが主催し、開催されました。その主なテーマは、インターネットユーザーのためにリスクを新興た。セキュリティスイートカスペルスキーインターネットセキュリティ2013 - また、同社の主力製品の新バージョンを発表した。唯一のポーランド語版としてこのイベントに参加する機会を得ました。訪問の機会に、私たちは、モスクワにある会社の本社を見てみましょう、だけでなく、Kaspersky Labの専門家と話をすることができました。
Kaspersky Labは、セキュリティ業界で最も急成長している会社の一つです。それは世界のアンチウイルスソフトウェアの主要プロバイダの一つです。それは、世界の約200カ国で事業を展開。それは、2,400人以上の従業員を雇用しています。同社の製品で300万人以上のユーザーと20万によって使用されます。法人。サーバー上で終了、パソコンから携帯に - 彼らは様々なデバイス用の保護を提供し、住宅およびビジネスユーザーに特化したソリューションの範囲を提供しています。インターネットユーザーへの脅威をテーマにした会議が2012年6月27日に予定されています。ロシアのモスクワの中心部に位置するラディソンロイヤルホテル、荘厳なホールで開催された。 - アレクサンダーエロフェーエフ、シニアセキュリティ - ステファン棚瀬、シニアリージョナル研究者 - ドミトリーBestuzhev、調査と分析のディレクターGlobalegoチーム - Costin Raiu、シニア専門家委員会マーケティング部長:彼らのスピーチは専門カスペルスキーをリードしていた。安全 - ヴィタリーKamliuk兼最高技術責任者 - ニコライGrebennikov兼製品 - ピーターメルクーロフ。ユージン·カスペルスキー - ケーキの上のアイシングは、Kaspersky Labの創設者兼最高経営責任者(CEO)のスピーチだった。スケジュールがタイトだったといえば - 退屈する暇がありませんでした。
現代のサーファー
会議では、実質的にすべての私達の現代のインターネットユーザーを、特徴付けプレゼンテーションのマーケティング責任者、アレクサンダーErofeev'a始まった。彼は、技術が人々を変えていることを指摘した。今日、我々はいつでも、どこでも利用したい、そこから上記のすべての私たちの電子機器、ガジェット、および、インターネットへのアクセス、なしの生活を想像することはできません。
過去数年間では、それは私たちの地域のインターネットコミュニティが最も急速に発展してきたのです。また、私たちのほとんどは、毎日インターネットに接続しつ以上のデバイスを使用してください。すべてではありませんデスクトップコンピュータ、ノートPC、スマートフォン。ますます、我々はウェブサーフィンのために設計されて快適なネットブックやタブレットを買うことにする。
インターネット上のすべてのもの
今日、私たちの誰もがすでに手紙を送っていないし、銀行で並んで立っていません。例ほとんどは、我々はあなたの家を離れることなく、インターネットを介して処理されます。インターネット経由での代わりにメールで転送し、通信、迅速かつより広いコミュニケーションのためのソーシャル·ネットワーキング·サイトではなく、伝統的なショッピング、代わりに手紙の電子メールのエンターテイメント、ショッピング、オンラインオークションの形として、YouTubeなど、さまざまなサービスのビデオを見て - それはすべての非常に簡単に私たちの生活です。残念ながら、多くの場合、我々は、ネットワーク上で潜んでいる危険性を理解していないと我々はサイバー攻撃の診断と問題を抱えている。
何が問題なの?
人気のコンピュータは何年も変化しない、比較的安全であると考えられている。これは、LinuxまたはMac OSコンピュータではないインターネットを支配した。私たちの大半は、一般的なWindowsオペレーティングシステムを選択します。長年にわたり、この傾向は変わっていませんし、少なくとも今のところはいかなる革命のこの点で期待されていません。そしてそれは、このプラットフォーム上では、最もリスクがある。お使いのコンピュータ、スマートフォンやタブレットを使用するようにすると、銀行やショッピングにログオンします。盲目的に我々が持っているオンラインバンキングサービスとデバイスを信頼しています。五回ごとタブレットパラメータであなたの銀行口座へのアクセスが格納されている - 私たちはカードのATMの暗証番号を書いたかのように、それは同じだ。スパム、ウイルス、個人データの漏えい、不要なソフトウェア、フィッシング、または損失や機器の盗難 - より多くのユーザーは、さまざまな問題によって影響を受けることになります。これらの状況は、日常生活の中で我々と共にあるとますます私たちに影響を与えている。


在这段期间从25到2012年6月28日,在莫斯科举行,由卡巴斯基实验室致力于网络安全峰会举办。它的主要主题是新兴的互联网用户的风险。还提出了一个新版本的安全套件,该公司的旗舰产品 - 卡巴斯基互联网安全2013。作为唯一的波兰语版本有机会参加本次活动。在此次访问之际,我们来看一看在该公司总部设在莫斯科,以及跟卡巴斯基实验室的专家。
卡巴斯基实验室是在安防行业中增长最快的公司之一。这是在世界上的防病毒软件的领先供应商之一。它工作在世界各地的近200个国家和地区。它采用了超过2400名员工。凭借其产品所使用的300多万用户和20万。公司。他们提供了一系列的解决方案,致力于为住宅和商业用户,提供保护的各种设备 - 从个人电脑到手机,结束了在服务器上。 2012年6月27日,会议的主题是互联网用户的威胁已定。雷迪森皇家酒店,位于俄罗斯莫斯科的心脏雄伟的大厅里举行。他们的发言,领先的专业卡巴斯基实验室市场部负责人 - 高级安全Erofeev,亚历山大 - 斯特凡特纳塞,高级区域研究员 - 德米特里·别斯图热夫,导演Globalego团队的研究与分析 - 海东青Raiu,资深专家委员会安全 - 维塔利·Kamliuk兼首席技术 - 尼古拉Grebennikov兼首席产品 - 彼得·梅尔库洛夫。锦上添花的讲话,卡巴斯基实验室的创始人兼CEO - 尤金·卡巴斯基。在谈到日程很紧 - 有没有无聊的时间。
现代化的冲浪者
的会议开始演示首席营销官,的亚历山大Erofeev'a的特征的现代互联网用户,几乎所有的。他指出,该技术已经改变了人们。今天,我们不能想象生活没有我们的电子设备,小工具,以及最重要的,接入互联网,您要使用在任何地方,任何时间。
在过去的几年中,它是在我们的地区发展最迅速的互联网社区。此外,我们大多数人每天都在使用两个以上的设备连接到Internet。一台台式电脑,笔记本电脑和智能手机,是不是所有的。越来越多,我们决定买一个舒适的上网本和平板电脑,这是专为在网上冲浪。
一切都在互联网上
今天,我们没有已经致函和不排队,在银行。大多数情况下,我们在互联网上处理,而无需离开你的家。转让通信超过了互联网,而不是中的邮件,社交网络网站的快速和更广泛的沟通,各种服务,例如YouTube上观看视频,作为一个形式的娱乐,购物和在线拍卖,而不是传统的购物和电子邮件,而不是字母 - 它是所有非常更容易我们的生活。不幸的是,我们经常没有意识到的危险潜伏在网络上,我们有一个问题与诊断的网络攻击。
有什么问题吗?
热门的电脑被认为是相对安全的,多年没有改变。这不是Linux或Mac OS计算机上占主导地位的互联网。我们大多数人选择流行的Windows操作系统。多年来的趋势并没有改变,至少现在还不是预计在这方面的任何一次革命。它是在这个平台上是最危险的。经常使用电脑,智能手机或平板登录到银行和购物。盲目地相信,我们的网上银行服务及设备。五分之一的平板电脑参数存储到您的银行帐户的访问 - 这是一样的,如果我们写了卡上的ATM PIN。越来越多的用户将受到各种各样的问题 - 垃圾邮件,病毒,私人数据泄漏的,不需要的软件,网络钓鱼,或丢失或被盗的设备。这些情况与我们在日常生活中,越来越多地影响着我们。


Tuesday, August 28, 2012

The most dangerous viruses in the world


The list, published on Thursday, the 15 most significant in the history of the virus, Kaspersky Lab lists include viruses attacking Iran's nuclear facilities. Cyberwarfare is not a screenplay, and the reality - says the analyst of the Polish branch of the company.
The most significant so far in 2012 the authors of the virus recognized statement of Flame (also known as Flamer, sKyWIper and Skywiper) - a malicious program that is actively used as cyberbroń in attacks on objects in different countries, especially the Arab world. Once infected machine can record audio Flame (eg, instant messaging conversations), take screenshots and record keystrokes on the keyboard.
In contrast to the famous Stuxnetu (used among others to attack Iran's nuclear facilities - destroy centrifuges used to enrich uranium, misleading supervisor working speed devices) - Flame by experts, was created primarily for the purpose of espionage, as well as an outdoor year Duqu virus earlier.
- If I had to choose three "worst" of the threat presented by our list, it would be the three most recent. All showed the whole world that it is no longer Cyberwarfare Hollywood production scenario and the reality - said Maciej Ziarek, malware analyst at Kaspersky Lab Poland. - Despite the fact that these three are not exploited by malicious programs infecting innovative technology, it was ground-breaking in terms of the objectives that have chosen cybercriminals. They were strictly selected organizations or strategic objects, and the complexity indicates that the creation of programs involved many experts and a lot of money. We had to deal with cyberbronią aimed at specific targets.
The top fifteen most important by the company in the history of computer threats was also Brain - one of the first computer viruses infecting diagnosed IBM PC computers. Discovered in 1986 and writes its code in the boot sector of floppy virus within a few months of the uprising has spread around the world. The program itself is not destroyed a data disk only the name has changed. Considered virus writers, programmers Pakistani Basit Farooq Alvi and Amjad explained later that with the help of Brain wanted to measure the level of software piracy in the country.

Another important program that Kaspersky Lab analysts earned a place in the top fifteen is Conficker, also known as Downup, Downadup or Kido. Exploiting vulnerabilities in Windows, it was infecting computers private and corporate, where protective systems shut down, install additional malware and steal personal information. Its characteristic feature is that it automatically downloads its new, updated by cybercriminals copies. In 2009, Microsoft has set 250 thousand. U.S. dollar prize to anyone who will contribute significantly to the recognition of Conficker creator. Unfortunately, to this day do not know who was behind the creation of this program.
However, the greatest threat to individual users and businesses recognize Maciej Ziarek Trojan horses, programs that pretend useful tools perform malicious acts. - Nowadays, information is more valuable than ever before, so the cyber criminals use Trojans to steal any data that can later be sold on the black market or used to blackmail users or companies. There are also banking Trojans that "specialize" in the theft of information related to online banking - added Ziarek.
Kaspersky Lab has released a list of the occasion of the 15th anniversary of its founding.
Top 15 most important virus in chronological order:
- 1986 - Brain appears, the first computer virus. Brain spread by writing your code in the boot sector of floppy disks.
- 1988 - Morris worm infects about 10% of computers connected to the Internet (about 6 000 machines).
- 1992 - Michelangelo appears - the first virus that causes widespread media interest.
- 1995 - appears Concept - the first macro virus that infects Microsoft Word documents.
- 1999 - Melissa begins the era of mass mailing malware responsible for the massive global epidemics.
- 2003 - appears Slammer worm bezplikowy responsible for massive worldwide epidemic.
- 2004 - Cabir appears: the first worm a "Proof-of-Concept" for Symbian, Cabir infects mobile phones through Bluetooth.
- 2006 - Leap appears, the first virus for Mac OS X.
- 2007 - Storm worm (also known as Zhelatin) initiates the use of distributed servers through which the cybercriminals controlling malicious programs.
- 2008 - there is Koobface, the first malicious program that attacks Facebook.
- 2008 - appears Conficker, the worm that caused one of the biggest epidemics in history, attacking corporate networks, consumers and governments in more than 200 countries.
- 2010 - appears FakePlayer, pink SMS Trojan for Android.
- 2010 - there is Stuxnet, which is used to carry out targeted attacks on SCADA systems (Supervisory Control and Data Acquisition), signaling the arrival of cyberwars.
- 2011 - appears Duqu, a sophisticated Trojan that collects information about its carefully selected targets.
- 2012 - Flame appears highly sophisticated malicious software that is actively used as cyberbroń in attacks on objects in different countries.


カスペルスキーのリストが含まれて木曜日に発行されるリストは、ウイルスの歴史の中で最も重要な15日イランの核施設を攻撃するウイルス。サイバー戦争は、脚本、そして現実ではない - 会社のポーランド支店のアナリストは述べています。
特に積極的に様々な国、アラブ世界内のオブジェクトへの攻撃にcyberbrońとして使用された悪意のあるプログラム - 最も重要なのは、これまでのところ、2012年にはウイルスの作者は、炎の文(もFLAMER、sKyWIperとSkywiperとしても知られる)を認識した。一度感染するとマシンは、(例えば、インスタントメッセージングの会話)オーディオ炎を記録するキーボード上のスクリーンショットと、レコードのキーストロークを取ることができます。
有名Stuxnetu( - 高速デバイスをワーキングウラン、誤解を招くようなスーパーバイザーを豊かにするために使用される遠心分離機を破壊するイランの核施設を攻撃するためにとりわけ使用される) - とは対照的に、専門家による炎、主にスパイの目的だけでなく、屋外の年間のために作成されました以前Duquウイルス。
- 私は私たちのリストが提示した脅威の3 "最悪"を選択しなければならないとしたら、それは最新の3つであろう。すべては、それがもはやサイバー戦争ハリウッド製作のシナリオと現実でないことを全世界に示した - マチェイZiarek、カスペルスキーでマルウェアのアナリストは述べています。 - これらの3つの革新的な技術を感染させる悪意のあるプログラムによって悪用されていないという事実にもかかわらず、それはサイバー犯罪者を選択した目標の観点から画期的だった。彼らは、厳選された組織や戦略的なオブジェクトであった、と複雑さは、プログラムの作成は、多くの専門家や多くのお金が関与していることを示します。我々は、具体的な目標に向けたcyberbroniąに対処しなければならなかった。
診断されたIBM PCのコンピュータを感染させる最初のコンピュータウイルスの1 - コンピュータの脅威の歴史の中で会社でトップ15で最も重要なのは、脳であった。 1986年に発見され、反乱の数ヶ月以内にフロッピーウイルスのブートセクタに自身のコードを書き込むには、世界中に広がっています。プログラム自体は名前だけが変更されたデータディスクが破壊されていません。ウイルス作成者と見なされ、プログラマーパキスタンBasitファルークAlviと民放は、脳の助けを借りて国にソフトウェア著作権侵害のレベルを測定したいと思ったことを後で説明した。

Kaspersky Labのアナリストは、トップ15内に地位を獲得したもう1つの重要なプログラムはまたDownup、Downadupや木戸として知られているConfickerのです。 Windowsの脆弱性を悪用し、それは、保護システムがシャットダウンする個人や企業のコンピュータを感染させる追加のマルウェアをインストールし、個人情報を盗みました。その特徴は、それが自動的にその新しい、サイバー犯罪のコピーによって更新がダウンロードされていることです。 2009年、マイクロソフトは250万人を設定しています。 Confickerワーム作成者の認識に大きく貢献します誰にも米国ドルの賞金。残念なことに、この日にこのプログラムの作成の背後にいたのか分からない。
ただし、個々のユーザーや企業への最大の脅威はマチェイZiarekトロイの木馬、便利なツールが悪質な行為を行うふりをするプログラムを認識しています。 - 今日では、情報がかつてないほど貴重なものですので、サイバー犯罪者は、後で闇市場で売られたり、ユーザーや企業を脅迫するために使用できる任意のデータを盗むトロイの木馬を使用しています。 Ziarekを追加しました - それはオンラインバンキングに関連する情報の窃盗に "特化"銀行のトロイの木馬もあります。
Kaspersky Labは、創立15周年の機会のリストを公表した。
年代順にトップ15最も重要なウイルス:
- 1986 - 脳は、最初のコンピュータウイルスが表示されます。脳はフロッピーディスクのブートセクターにあなたのコードを記述することによって広がる。
- 1988 - モリスワームは、インターネット(約6 000機)に接続されたコンピュータの約10%に感染します。
- 1992年 - ミケランジェロが表示されます - 広範囲のメディアの関心を引き起こした最初のウイルスを。
- 1995 - Microsoft Word文書に感染する最初のマクロウイルス - コンセプトが表示されます。
- 1999 - メリッサは、大規模な世界的流行を担うマスメーリングマルウェアの時代が始まります。
- 2003 - 大規模な世界的流行にbezplikowy責任Slammerワームが表示されます。
- 2004 - Cabirはが表示されます:最初のワームSymbian向けの "プルーフ·オブ·コンセプト"、CabirはBluetooth経由で携帯電話に感染する。
- 2006 - リープが表示され、Mac OS X用の最初のウイルス
- 2007 - Stormワーム(またZhelatinとして知られている)、サイバー犯罪者は、悪意のあるプログラムを制御しているを通じて配布サーバの使用を開始します。
- 2008 - Koobfaceは、Facebookを利用して攻撃する第一の悪意のあるプログラムがある。
- 2008 - Confickerを、200カ国以上で企業ネットワーク、消費者、政府を攻撃し、史上最大の流行の一つの原因となったワームが表示されます。
- 2010 - FakePlayer、Android用のピンクのSMSトロイの木馬が表示されます。
- 2010 - cyberwarsの到着を合図に、SCADAシステム(監視制御およびデータ収集)に標的型攻撃を実行するために使用されるStuxnetは、があります。
- 2011 - Duqu、その厳選されたターゲットに関する情報を収集し、洗練されたトロイの木馬が表示されます。
- 2012 - 炎は積極的に様々な国のオブジェクトへの攻撃にcyberbrońとして使用され、高度に洗練された悪意のあるソフトウェアが表示されます。


周四公布的名单,15个最重要的在历史上的病毒,卡巴斯基实验室列表病毒攻击伊朗的核设施。网络战是不是一个电影剧本,而现实 - 波兰的分支公司的分析师说。
最重要的,到目前为止,在2012年确认的病毒作者声明火焰(也称为火焰喷射器,sKyWIper和Skywiper的) - 是一种恶意程序,积极作为cyberbroń的攻击对象在不同的​​国家,特别是阿拉伯世界。一旦感染的机器可以录制音频火焰(如即时消息对话),键盘上的截图,记录键击。
相反的,著名Stuxnetu(以及其他攻击伊朗的核设施 - 摧毁离心机进行铀浓缩活动,误导性导师工作的测速设备使用) - 火焰由专家,间谍活动的目的,主要是为创建,以及一个室外的一年Duqu病毒。
- 如果我不得不选择三个“最差”的威胁,提出了我们的名单,这将是最近三个。都表现出了整个世界,它不再是网络战的好莱坞生产场景和现实 - 马切伊Ziarek说,波兰卡巴斯基实验室的恶意软件分析师。 - 尽管这三者都无法利用恶意程序感染的创新技术,突破性的选择了网络罪犯的目标。他们是经过严格挑选的组织或战略的对象,并创建程序的复杂性表明,涉及许多专家和大量的资金。我们要处理的具体目标,旨在与cyberbronią。
前15个最重要的公司在历史上对计算机的威胁也是脑 - 感染诊断的IBM PC计算机的计算机病毒之一。 1986年发现的,其代码病毒的软盘的引导扇区写入的起义在短短几个月内已传播到世界各地。这个程序本身不被破坏的数据磁盘的名称发生了变化。考虑病毒作家,程序员巴基斯坦的巴西特法鲁克ALVI和Amjad解释的帮助下,脑想的盗版软件在国内的高低来衡量。

另一项重要的程序,卡巴斯基实验室的分析师顶部15赢得了一个地方是Conficker的,也称为Downup的,Downadup或Kido。利用Windows的漏洞,它被感染计算机的私人和企业,保护系统关闭,安装额外的恶意软件,窃取个人信息。它的特征是,它会自动下载新的,更新的网络犯罪分子的副本。在2009年,微软已经设置为250000。美元奖金,任何人都将有助于显着的Conficker创造者的认可。不幸的是,这一天不知道谁是背后的创造这一计划。
然而,最大的威胁为个人用户和企业认识到的马切伊Ziarek特洛伊木马,伪装成有用的工具,执行恶意行为的程序。 - 现在比以往任何时候都更有价值,因此网络罪犯使用的木马程序窃取,以后可以在黑市上销售或使用要挟用户或公司的任何数据。也有银行木马“专门”的盗窃网上银行的相关信息 - Ziarek。
卡巴斯基实验室已经发布了其成立15周年之际列表。
15个最重要的病毒按时间顺序排列:
- 1986 - 大脑出现的第一个计算机病毒。脑软盘的引导扇区写代码的传播。
- 1988年 - 莫里斯蠕虫感染的电脑连接到互联网(约000台)的10%左右。
- 1992年 - 米开朗基罗出现了 - 第一个病毒,引起了媒体的广泛关注。
- 1995 - 出现的概念 - 第一个宏病毒感染Microsoft Word文档。
- 1999 - 梅丽莎开始群发邮件恶意软件负责大规模的全球流行病的时代。
- 2003 - 出现Slammer蠕虫病毒bezplikowy负责的为大规模的全球性流行病。
- 2004 - Cabir蠕虫病毒出现:“证明概念”为Symbian的首个蠕虫病毒,Cabir蠕虫病毒感染的手机通过蓝牙。
- 2006 - 飞跃出现​​的第一个病毒的Mac OS X
- 2007 - 风暴蠕虫病毒(也称为Zhelatin)发起使用分布式服务器通过网络罪犯控制的恶意程序。
- 2008 - Koobface的恶意程序,第一攻击Facebook的。
- 2008 - 出现Conficker蠕虫,该蠕虫造成攻击企业网络,在超过200个国家和地区的消费者和政府在历史上,最大的流行病之一。
- 2010 - 出现FakePlayer的,粉红色的Andr​​oid短信木马。
- 2010 - Stuxnet的,它是用来进行有针对性的攻击SCADA系统(监控和数据采集系统),信号cyberwars的到来。
- 2011 - 出现Duqu,一个复杂的木马程序,收集信息,其精心挑选的目标。
- 2012 - 火焰高度复杂的恶意软件积极作为cyberbroń的攻击对象在不同的​​国家出现。