這次要介紹的主題是漏洞 (Vulnerability)以及有關漏洞的相關介紹,首先讓我們先定義一下,漏洞是什麼意思呢?
美國國家標準暨技術研究院 (National Institute of Standards and Technology, NIST)在NISTIR 8138草案中提到:
A Vulnerability is any weakness in the computational logic found in products or devices that could be exploited by a threat source.
美國電腦緊急應變小組 (United States Computer Emergency Readiness Team, US-CERT):
Report software vulnerabilities defined as defects that allow an attacker to violate an explicit (or implicit) security policy to achieve some impact (or consequence). In particular, defects that allow intruders to gain increased levels of access or interfere with the normal operation of systems are vulnerabilities. Insecure configurations, design choices, and changing environmental conditions can also cause vulnerabilities.
國際電腦稽核協會 (Information Systems Audit and Control Association, ISACA):
A weakness in the design, implementation, operation or internal control of a process that could expose the system to adverse threats from threat events.
開放網路軟體安全計畫 (Open Web Application Security Project, OWASP):
A vulnerability is a hole or a weakness in the application, which can be a design flaw or an implementation bug, that allows an attacker to cause harm to the stakeholders of an application. Stakeholders include the application owner, application users, and other entities that rely on the application.
微軟安全回應中心 (Microsoft Security Response Center, MSRC):
A security vulnerability is a weakness in a product that could allow an attacker to compromise the integrity, availability, or confidentiality of that product.
通用漏洞揭露計畫 (Common Vulnerabilities and Exposures, CVE®):
In general, a vulnerability is defined as a weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, OR availability.
台灣電腦網路危機處理暨協調中心 (Taiwan Computer Emergency Response Team / Coordination Center, TWCERT/CC):
漏洞 (Vulnerability)之定義為發生於軟體、韌體及微程式中的 Bug,且若此
Bug 遭利用,會導致資料的機密性、完整性或可用性產生負面影響。因此,若為
接下來的30天會陸續介紹現在坊間有哪些處理漏洞的組織、描述漏洞的資訊、 漏洞種類、知名漏洞介紹及POC及發現漏洞了怎麼處理等,就請大家拭目以待吧,有任何問題也都歡迎提出討論喔!
[1] https://csrc.nist.gov/publications/detail/nistir/8138/draft
[2] https://www.us-cert.gov/report
[3] https://www.isaca.org/Pages/Glossary.aspx?tid=1975&char=V
[4] https://www.owasp.org/index.php/Category:Vulnerability
[5] https://docs.microsoft.com/en-us/previous-versions/tn-archive/cc751383(v=technet.10)
[6] https://cve.mitre.org/cve/cna/rules.html
[7] https://twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?id=65