首页 > 最新文献

Cybersecurity & Cybercrime最新文献

英文 中文
SELECTED ADVANCED CYBER ESPIONAGE OPERATIONS 精选高级网络间谍行动
Pub Date : 2021-03-31 DOI: 10.5604/01.3001.0053.8016
A. Wróblewska
The article presents examples of highly advanced cyber espionage operations aimed atthe structures of states and non-state entities with high impact on the economic activity.The attacks took place between 2003 and 2017. The article presents the steps ofOperation Titan Rain and Operation Gh0stNet and also one of the longest espionageoperations revealed to the public, which is Operation The Night Dragon. Anotheroperation is a series of cyber attacks identified by McAfee - Operation Shady RAT. Theyears 2009-2010 belong to Operation Aurora, whose victims were dozens oforganizations, including Google. One of the described attacks is Operation Nitro,targeting entities mostly located in the United States, Bangladesh and Great Britain. Thecourse of Project Raven was based on a Reuters investigation. The spy campaigntargeting various victims around the world, monitored by a team of BlackBerryResearch and Intelligence specialists, was named as CostaRicto.
本文介绍了针对国家和非国家实体结构的高度先进的网络间谍活动的例子,这些活动对经济活动有很大影响。这些袭击发生在2003年至2017年之间。文章介绍了“泰坦雨”行动和“幽灵网”行动的步骤,以及向公众披露的最长的间谍行动之一——“夜龙”行动。另一个行动是由McAfee识别的一系列网络攻击——Shady RAT行动。2009年至2010年属于“极光行动”,受害者包括谷歌在内的数十家组织。所描述的攻击之一是Nitro行动,目标主要是位于美国、孟加拉国和英国的实体。渡鸦计划的过程是基于路透社的一项调查。这场针对全球不同受害者的间谍活动,由黑莓研究和情报专家组成的团队监控,被命名为CostaRicto。
{"title":"SELECTED ADVANCED CYBER ESPIONAGE OPERATIONS","authors":"A. Wróblewska","doi":"10.5604/01.3001.0053.8016","DOIUrl":"https://doi.org/10.5604/01.3001.0053.8016","url":null,"abstract":"The article presents examples of highly advanced cyber espionage operations aimed atthe structures of states and non-state entities with high impact on the economic activity.The attacks took place between 2003 and 2017. The article presents the steps ofOperation Titan Rain and Operation Gh0stNet and also one of the longest espionageoperations revealed to the public, which is Operation The Night Dragon. Anotheroperation is a series of cyber attacks identified by McAfee - Operation Shady RAT. Theyears 2009-2010 belong to Operation Aurora, whose victims were dozens oforganizations, including Google. One of the described attacks is Operation Nitro,targeting entities mostly located in the United States, Bangladesh and Great Britain. Thecourse of Project Raven was based on a Reuters investigation. The spy campaigntargeting various victims around the world, monitored by a team of BlackBerryResearch and Intelligence specialists, was named as CostaRicto.","PeriodicalId":269616,"journal":{"name":"Cybersecurity & Cybercrime","volume":"409 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2021-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124355583","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
USAGE OF A COMPUTER LAB ENVIRONMENT TO PREPERECYBERSECURITY PERSONNEL IN DETETECTING ANDCOUNTERACTING CYBER ATTACKS 利用计算机实验室环境,使网络安全人员能够更好地发现和应对网络攻击
Pub Date : 2021-03-31 DOI: 10.5604/01.3001.0053.8001
Adam Stojałowski
The aim of this article is to present the conclusions from the conducted research on thepreparation of personnel responsible for cybersecurity in counteracting cyber threats. Inaddition, the aim is to analyze the use of tools offered by the cyber polygon in terms ofacquiring practical skills related to detection of vulnerabilities in ICT systems.
本文的目的是通过对网络安全人员应对网络威胁的准备进行研究,得出结论。此外,目的是分析网络多边形提供的工具在获取与检测信息通信技术系统漏洞有关的实用技能方面的使用情况。
{"title":"USAGE OF A COMPUTER LAB ENVIRONMENT TO PREPERECYBERSECURITY PERSONNEL IN DETETECTING ANDCOUNTERACTING CYBER ATTACKS","authors":"Adam Stojałowski","doi":"10.5604/01.3001.0053.8001","DOIUrl":"https://doi.org/10.5604/01.3001.0053.8001","url":null,"abstract":"The aim of this article is to present the conclusions from the conducted research on thepreparation of personnel responsible for cybersecurity in counteracting cyber threats. Inaddition, the aim is to analyze the use of tools offered by the cyber polygon in terms ofacquiring practical skills related to detection of vulnerabilities in ICT systems.","PeriodicalId":269616,"journal":{"name":"Cybersecurity & Cybercrime","volume":"48 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2021-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115908889","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
STRENGTHENING THE SECURITY OF THE ELECTRONIC BANKINGCUSTOMER IN THE LIGHT OF THE CONDUCTED RESEARCH 根据所进行的研究,加强电子银行客户的安全
Pub Date : 2021-03-31 DOI: 10.5604/01.3001.0053.8005
Paweł Ciszek
The article presents the results of the project "Security environment for electronicbanking customers". It presents the methods and research tools used to achieve theobjectives of the project - to identify the solutions used and the accompanying threats,the characteristics of customers and the direction of development in the field of ebanking. The most important results of empirical research - surveys and extended expertinterviews are presented. Recommendations on the architecture of solutions and securityof e-banking environment were presented.
本文介绍了“电子银行客户的安全环境”项目的成果。它提出了用于实现项目目标的方法和研究工具-确定所使用的解决方案和伴随的威胁,客户的特征和电子银行领域的发展方向。实证研究的最重要的结果-调查和扩展的专家访谈提出。对解决方案的架构和电子银行环境的安全性提出了建议。
{"title":"STRENGTHENING THE SECURITY OF THE ELECTRONIC BANKINGCUSTOMER IN THE LIGHT OF THE CONDUCTED RESEARCH","authors":"Paweł Ciszek","doi":"10.5604/01.3001.0053.8005","DOIUrl":"https://doi.org/10.5604/01.3001.0053.8005","url":null,"abstract":"The article presents the results of the project \"Security environment for electronicbanking customers\". It presents the methods and research tools used to achieve theobjectives of the project - to identify the solutions used and the accompanying threats,the characteristics of customers and the direction of development in the field of ebanking. The most important results of empirical research - surveys and extended expertinterviews are presented. Recommendations on the architecture of solutions and securityof e-banking environment were presented.","PeriodicalId":269616,"journal":{"name":"Cybersecurity & Cybercrime","volume":"58 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2021-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130268869","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
DEANONYMIZATION OF TOR NETWORK USERS 网络用户的去匿名化
Pub Date : 2021-03-31 DOI: 10.5604/01.3001.0053.8014
Ewelina Belka
Tor is a virtual network that implements onion routing and aims to provide the user withthe greatest possible anonymity on the Internet. Due to ensuring a high level ofanonymity, the Tor network attracts more and more criminals, mainly pedophiles,thieves and hackers, who use the opportunities associated with it for illegal activities.This paper presents the most popular attacks on the Tor network, aimed at establishingthe identity of its users. This paper will explore ways to de-anonymize by compromisingor having enough relays, and manipulating basic network communication to end up onthe Tor traffic forwarding path. The paper will also present traffic analysis techniquesthat allow an outside observer to infer which nodes are used to transmit traffic in thecircuit. Finally, the use of artificial intelligence to recognize what pages and services theTor user is visiting will be discussed. The work aims to present the vulnerability of theTor network, which should be considered an opportunity in the fight against cybercrime,and to encourage further research on the vulnerabilities of the Tor network, aimed atidentifying cybercriminals.
Tor是一个实现洋葱路由的虚拟网络,旨在为用户在互联网上提供最大可能的匿名性。由于确保了高度的匿名性,Tor网络吸引了越来越多的罪犯,主要是恋童癖者、小偷和黑客,他们利用与之相关的机会从事非法活动。本文介绍了针对Tor网络的最流行的攻击,旨在确定其用户的身份。本文将探索通过妥协或拥有足够的中继以及操纵基本网络通信以结束Tor流量转发路径来实现去匿名化的方法。本文还将介绍流量分析技术,该技术允许外部观察者推断哪些节点用于传输电路中的流量。最后,将讨论使用人工智能来识别tor用户正在访问的页面和服务。这项工作旨在展示Tor网络的脆弱性,这应被视为打击网络犯罪的机会,并鼓励对Tor网络脆弱性的进一步研究,旨在识别网络罪犯。
{"title":"DEANONYMIZATION OF TOR NETWORK USERS","authors":"Ewelina Belka","doi":"10.5604/01.3001.0053.8014","DOIUrl":"https://doi.org/10.5604/01.3001.0053.8014","url":null,"abstract":"Tor is a virtual network that implements onion routing and aims to provide the user withthe greatest possible anonymity on the Internet. Due to ensuring a high level ofanonymity, the Tor network attracts more and more criminals, mainly pedophiles,thieves and hackers, who use the opportunities associated with it for illegal activities.This paper presents the most popular attacks on the Tor network, aimed at establishingthe identity of its users. This paper will explore ways to de-anonymize by compromisingor having enough relays, and manipulating basic network communication to end up onthe Tor traffic forwarding path. The paper will also present traffic analysis techniquesthat allow an outside observer to infer which nodes are used to transmit traffic in thecircuit. Finally, the use of artificial intelligence to recognize what pages and services theTor user is visiting will be discussed. The work aims to present the vulnerability of theTor network, which should be considered an opportunity in the fight against cybercrime,and to encourage further research on the vulnerabilities of the Tor network, aimed atidentifying cybercriminals.","PeriodicalId":269616,"journal":{"name":"Cybersecurity & Cybercrime","volume":"50 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2021-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114313522","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
CYBER SECURITY REQUIREMENTS FOR PORT INFRASTRUCTURE 港口基础设施的网络安全要求
Pub Date : 2021-03-31 DOI: 10.5604/01.3001.0053.8012
M. Kamiński
The purpose of this article is to characterize cybersecurity threats related to thefunctioning of seaport infrastructure. The escalation of the use of modernteleinformation systems in maritime transport allows for the development of theefficiency of transshipment processes, improvement of the movement of multimodaltransport means and logistic processes and increasing their safety. Due to the wide useof these technologies, the possibility of cyberspace security incidents is growing. Thereis a need to define universal, basic cybersecurity requirements that will constitute thefoundation for creating solutions determining the maintained level of security in seaports. Moreover, the basic solutions and good practices allowing to meet the setrequirements were presented.
本文的目的是描述与海港基础设施功能相关的网络安全威胁。现代远程信息系统在海上运输中的使用升级,可以提高转运过程的效率,改善多式联运手段和物流过程的移动,并提高其安全性。由于这些技术的广泛使用,网络空间安全事件的可能性正在增加。有必要定义通用的、基本的网络安全要求,这些要求将构成创建确定海港安全维持水平的解决方案的基础。此外,还介绍了满足这些要求的基本解决方案和良好实践。
{"title":"CYBER SECURITY REQUIREMENTS FOR PORT INFRASTRUCTURE","authors":"M. Kamiński","doi":"10.5604/01.3001.0053.8012","DOIUrl":"https://doi.org/10.5604/01.3001.0053.8012","url":null,"abstract":"The purpose of this article is to characterize cybersecurity threats related to thefunctioning of seaport infrastructure. The escalation of the use of modernteleinformation systems in maritime transport allows for the development of theefficiency of transshipment processes, improvement of the movement of multimodaltransport means and logistic processes and increasing their safety. Due to the wide useof these technologies, the possibility of cyberspace security incidents is growing. Thereis a need to define universal, basic cybersecurity requirements that will constitute thefoundation for creating solutions determining the maintained level of security in seaports. Moreover, the basic solutions and good practices allowing to meet the setrequirements were presented.","PeriodicalId":269616,"journal":{"name":"Cybersecurity & Cybercrime","volume":"48 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2021-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121557609","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
期刊
Cybersecurity & Cybercrime
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1