什么是网络钓鱼,攻击类型和防御?

Phishing is a cybersecurity attack to convince target humans to convince to provide some valuable information about them or their assets. Phishing mainly targets human being and human-related vulnerabilities to exploit.

网络钓鱼是一种网络安全攻击,目的是诱使目标人员诱使他们提供有关其或其资产的一些有价值的信息。 网络钓鱼主要针对人类和与人类相关的漏洞加以利用。

网络钓鱼历史 (Phishing History)

The first legal lawsuit was filled in 2004 about the phishing. The attacker was a Californian teenager who has created a fake American Online web site. By sending emails to the targets where they are redirected to this fake web site the credit card details can be collected easily.

关于网络钓鱼的第一起法律诉讼于2004年提出。 攻击者是一位加利福尼亚少年,他创建了一个虚假的American Online网站。 通过将电子邮件发送到目标,然后将其重定向到该虚假网站,可以轻松收集信用卡详细信息。

网络钓鱼攻击类型 (Phishing Attack Types)

Phishing attacks can be implemented in different ways. Here is some of the most used.

网络钓鱼攻击可以以不同的方式实施。 这是一些最常用的。

  • `Email` is the most common and know the type where fake emails are sent to the targets with different content and aim.

    “电子邮件”是最常见的一种,并且知道将虚假电子邮件发送到具有不同内容和目标的目标的类型。
  • `Phone Calls` are made to the target in order to get some user name password or convenience to do some action which will exploit target assets.

    对目标进行“电话呼叫”是为了获得一些用户名密码或方便地执行将利用目标资产的某些操作。
  • `Text messages` can be also used similar to email but with a less effectivity.

    “文本消息”也可以类似于电子邮件使用,但效果较差。

网络钓鱼的共同特征 (Common Features Of Phishing)

There are different ways to catch phishing but in general, phishing has some common features like below.

有多种捕获网络钓鱼的方法,但是通常,网络钓鱼具有一些共同的特征,如下所示。

  • `Too Good To Be True` means it is not possible in a normal life which is very lucrative.

    “太好了不能成为现实”意味着在一个非常有利可图的正常生活中这是不可能的。
  • `Sense of Urgency` means it tries to take some actions without thinking or checking the truth.

    “紧迫感”意味着它试图采取一些行动,而没有考虑或核实事实。
  • `Hyperlinks` are generally used to redirect a user to the attacker’s site, application or action

    “超链接”通常用于将用户重定向到攻击者的站点,应用程序或操作
  • `Attachment` mainly used to run some script, tool, application or exploit the targets system like desktop, laptop, smartphone etc.

    附件主要用于运行某些脚本,工具,应用程序或利用目标系统,例如台式机,笔记本电脑,智能手机等。
  • `Unusual Sender` means the phishing sender or attackers are generally unknown by the target.

    “不正常的发送者”表示目标通常不知道网络钓鱼发送者或攻击者。

你可能感兴趣的:(网络,java,css,html,安全)