在這相信眼見為憑的世代中,聲音和圖像已然成為真理的基石。不僅記錄歷史,也構築成為我們對真實的感知。但事實真如我們所看、所聞嗎?隨著 AI 技術快速發展,Deepfake 造假技術不再高深,機器學習偽造臉部表情動作及聲音,製造幾可亂真的假影片散佈肆虐在媒體串流平台上,成為政治、詐欺或其他惡意目的武器,藉假新聞將資訊戰爭推至全新的水平。
綜觀各個受駭案例,不同的攻擊者可能利用類似的手法進行入侵。原先被設計來進行紅隊測試(Red Team Assessment)的工具,也遭到駭客的濫用,往往也開放原始碼,致使原先用於提升安全、進行安全評估的方法,淪為駭客的入侵手段。然而,工具的公開,是駭客的機會,同時也是防禦方的轉機。攻擊者可以隨意取得這些公開工具進行攻擊,而我們也能對這些工具同樣進行研究。本次的我們將透過這些常見的公開工具的研究,以駭客的思維了解這些工具、駭客的手法,進而提升網路防禦意識,確保網路安全。
Speaker:YCY
In many cases, different attackers may use similar methods for intrusion. Meanwhile, lots of tools designed to do Red Team Assessment are abused by attackers. These tools, as well as their source codes, are easily available in public. It makes the tools for security improvement and assessment become the intrusion means. However, the public tools are not only the attackers’ chances, but also the defenders' turning points. Attackers can access the public tools to attack at will, we can study the tools as well. In this talk, we understand attackers’ thinkings and methodologies through open source tools to strengthen the defense awareness and to ensure the network security.
Special thanks to everyone who invited us, helped us and patiently answered our questions. Thanks Suhee. Thanks Jihye. 😍😍😍
簡介
2017年11月9~10日南韓資安研討會 POC 在首爾舉辦。其中 Power of XX 是由南韓淑明女子大學資安研究社(SISS)與 Demon 及 Layer7 合辦的一場參賽者女性限定的 CTF 競賽。感謝 Power of XX 的邀請,讓我們有機會參與此次競賽,並與同樣對資訊安全領域有興趣的女孩們交流和學習。