Title: Windows?? ?????????
1Windows???????????
2??
- ????
- ??????
- PC?????
- Windows?????????
3?????
- ?????????????(PC)????,???????
- ??????,???????????????????
- ?????????????????,?????????????????????(???????)
4?????
- ??
- ????
- ????
- ????
- ??
- ??????
5????
- ????????worm??,?????????????(???????????)????????
,????????????(????????????) - ????????????????,?????,??,??????????,????????,???
?????????????(ex ?????????) ,????????????????
6??Life_cycle
- ???????????
- ??????
- ????(???, ????, ????)
- ????
- ?????????
- ????
7Windows ?????
- ????
- ????
- ?????
- ??????
- ???????
8????
- ????
- ???????????
- ???????????
- ???????????(ex ??????)
- ??????????
- ?????????,??????????????????
9????
????????,??????????,?????????? ??,???DOS?DDOS???
10????(netstat)
?? ??/???/??????/??????,???????netstat
,???????????? Proto Local Address Foreign
Address StateTCP yang1026
yang20032 ESTABLISHEDTCP
yang20032 yang1026
ESTABLISHEDTCP yang3024
dec4000.cc.ncku.edu.tw22 ESTABLISHEDTCP
yang3613 mail.ncku.edu.twtelnet
ESTABLISHED??Froeign Address?????Address?port,?S
tate?????,???ESTABLISHED?????? ?????Services
port????????????????????,????Server?port???????,?c
lient???????????Foreign Address???????????,?????
????Services ports
11Process(?????)
???????(?CtrlAltDel?,???????),???????,??????????
CPU??????????????? ????windows process
services
12????
- ?? ??/??/???,?? ??????/????,????????,????????????
??,???????????????????????share?????,?????????????
???????????????????????????????????????
13??????
- ??????/????/?????Path ???????,????
/WINNT/system32???? - ?????????????/??????????????
14??????(??????)
15???(registry)
?????(cmd)??regedit ,??\HKEY_LOCAL_MACHINE\SOFTWAR
E\Microsoft\Windows\CurrentVersion??Run?RunOnce?Ru
nServices???????????
16????
?? ??/??/???,?? ??????/?????,??????????
17Internet Services Logs
- ?????Internet(www?ftp)Services,Log?????/WINNT/syst
em32/logFiles
18Internet Services Logs
19??(Service)
- ????/??????/?? ,???,?????????,???????,????????????
,?????????
20?????????
- ?????????,????????administrator?????
21??
- Autoexec.bat
- Config.sys
- windir/win.ini ? load run
- windir/system.ini ? shall
- ???/?? ?????????
- ???/??????/????/?????
- ??????????
22?????
???????????Service ???????
- ???????TCP/IP??
- ????????????
- ??????????(BlackICE)
23?????TCP/IP??
24?????TCP/IP??
- TCP/UDP port ?? service ports
- IP Protocol
- ICMP 1 Internet Control Message Protocol
- IGMP 2 Internet Group Management Protocol
- GGP 3 Gateway-to Gateway Protocol
- IP 4 IP in IP encapsulation
- TCP 6 Transmission Control Protocol
- EGP 8 Exterior Gateway Protocol
- IGP 9 Interior Gateway Protocol
- UDP 17 User Datagram Protocol
25BlackICE
26BlackICE
27BlackICE
28??Life-cycle
- ????????????????
- ????????????
- ??????????,?????
- ??????
- ???????????
- ??????????
- ??????????????
29????????
- ??
- Open ??? ?pattern?????Virus
- ???????????????
- ??
- ???????????
- ?????
- ????????????,?????
-
- ???????(?mail)???????,????????,?????????????,???
??????,??????
30Baseline Security Analyzer
- Baseline Security Analyzer (MBSA)
?????????????,?????????? Hotfix ?????????? - Windows NT 4.0, Windows 2000, Windows XP,
Internet Information Server (IIS) 4.0/5.0, SQL
Server 7.0/2000, Internet Explorer (IE) 5.01 ??,
?? Office 2000/XP? - ?????????????????????????????,????????
- ?? MBSA ?? Internet Explorer 5.01 ???
31(No Transcript)
32(No Transcript)