<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>大兵说安全</title>
    <link>https://wechat2rss.xlab.app/feed/e5d7d4cd30d4467c6e50410a89bd5262c21eae22.xml</link>
    <description>在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (大兵说安全)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM5r4ftiaBia4I3mI6sViczuvNhzVsB3nUibueawicWlicS8CJGQ/0</url>
      <title>大兵说安全</title>
      <link>https://wechat2rss.xlab.app/feed/e5d7d4cd30d4467c6e50410a89bd5262c21eae22.xml</link>
    </image>
    <item>
      <title>如何检测利用CVE-2026-31431漏洞的攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485790&amp;idx=1&amp;sn=ad6ce9c4ab67c830b03edc85ee02f976</link>
      <description>昨天的文章《警惕，最新LINUX漏洞》中，给大家提醒了最近的CVE-2026-31431漏洞，怎么才能检测到利用该漏洞进行的攻击呢？</description>
      <content:encoded><![CDATA[<p>原创 <span>大兵说安全</span> <span>2026-05-03 18:47</span> <span style="display: inline-block;">河南</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bb42fc70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCIAKucYmbGOicFdOnU6lg3cibTibeibYcjbXpibEMqRV5QPqz9OPG9WfCx0oliavkI80ZwroSccNHic7jPTaibVWrF06GyafMj7YoiabsXI%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>昨天的文章《警惕，最新LINUX漏洞》中，给大家提醒了最近的CVE-2026-31431漏洞，怎么才能检测到利用该漏洞进行的攻击呢？</p>
  <p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" data-imgfileid="100000009" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">昨天的文章《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485783&amp;idx=1&amp;sn=dd472c09e33232ab844dc0d30614ee09&amp;scene=21#wechat_redirect" textvalue="警惕，最新LINUX漏洞" data-itemshowtype="0" linktype="text" data-linktype="2">警惕，最新LINUX漏洞</a>》中，给大家提醒了最近的</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="">CVE-2026-31431漏洞，有同学问如果有黑客利用这个漏洞发起攻击，有没有办法可以检测到。</span></span></p><p style="text-indent: 2em;"><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="">今天，我公司技术部的同事使用一些安全软件进行了测试。对具有该漏洞的主机进行了攻击测试，结果表明，如果部署的有卡巴斯基的EDR产品，在利用该漏洞进行攻击 的时候，在EDR中会触发possible_lpe_by__python的IOA规则。</span></span></p><p style="text-indent: 2em;"><span leaf="">其他产品的测试结果我就不说了，大家自行测试吧。也欢迎大家把测试结果贴在评论中。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5009259259259259" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100002136" src="https://wechat2rss.xlab.app/img-proxy/?k=186e9073&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2nYVbJUzOCLzkvEqH6WFxlibC7sicVaGjdpdT0EupLq7A5aiaBmMic28cdUy0NPz7nLFEIqSONtcNHibuj3SHGlwf4KNDAqnBxUFpIAUGTkRyjck%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.275" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100002138" src="https://wechat2rss.xlab.app/img-proxy/?k=466431ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2nYVbJUzOCLIHUSmJ7jeRLyL9pdvibIkShBA4m7zTqflCibAtx1uLibtam91IpJ3GWzLsJzhrLYR0LUlibtM36Xs1AxkdfG8XC06c9OUHOryTic4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0851851851851853" data-s="300,640" data-type="png" data-w="540" type="block" data-imgfileid="100002139" src="https://wechat2rss.xlab.app/img-proxy/?k=b8db6f0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2nYVbJUzOCLuyq6s8vL6PZywyx4eoiaDL38RNicr5hg2fnswHROy2OZyFSbkr1kRHWWgDK16M4mWOkEufQ1XWrow0PagEqz9FUS71pPTwCbrI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">*感谢邵博同学的实际测试</span></span></p><p style="text-indent: 2em;"><span leaf="">另外，有同学私信我为什么不说如何测试本机有没有这个漏洞，这个国家有法律规定啊，公布漏洞的时候不得公布详细的POC过程。2021年9月1号正式实施的《</span><span leaf="">网络产品安全漏洞管理规定</span><span leaf="">》中第九条有明确规定，不敢多说，大家去网上自行查找吧。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><span leaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=22d9a861&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485790%26idx%3D1%26sn%3Dad6ce9c4ab67c830b03edc85ee02f976">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 03 May 2026 18:47:00 +0800</pubDate>
    </item>
    <item>
      <title>警惕，最新LINUX漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485783&amp;idx=1&amp;sn=dd472c09e33232ab844dc0d30614ee09</link>
      <description>近⽇，Linux Kernel 披露本地权限提升漏洞CVE-2026-31431，该可能导致本地普通⽤户提升⾄ root 权限。</description>
      <content:encoded><![CDATA[<p>原创 <span>大兵说安全</span> <span>2026-05-02 08:25</span> <span style="display: inline-block;">河南</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1ccef52c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCLbKicCeDibzpoYsOP6C78mmEwmkqppBOwJibQIJJcBUSzn2KrtjicCVeougic7SEkib87Am4EwibNlgCzdUdtC3BCicDMve05eQz5QQ3s%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近⽇，Linux Kernel 披露本地权限提升漏洞CVE-2026-31431，该可能导致本地普通⽤户提升⾄ root 权限。</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100000009" data-ratio="0.18977272727272726" type="block" data-type="gif" data-w="880" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">近⽇，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Theori / Xint Code </span><span leaf="">披露本地权限提升漏洞CVE-2026-31431，该漏洞⼜被称为Copy Fail。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Ubuntu 安全公告显示该漏洞发布时间为2026-04-23，最近更新时间为2026-04-29；</span></p><p style="text-indent: 2em;"><span leaf="">该漏洞存在于 Linux 内核加密子系统相关逻辑中，攻击者在获得本地普通用户权限后，可通过 AF_ALG、splice() 与 authencesn 相关逻辑组合，触发对 page cache 的受控写入，从而实现本地提权。研究方称，公开 PoC 可在多个主流 Linux 发行版上将普通用户提升为 root。</span></p><p style="text-indent: 2em;"><span leaf="">该漏洞的危险点不在于远程直接入侵，而在于它会把“已经获得的低权限执行点”迅速放大为 root 权限。因此，对于多用户 Linux 主机、Kubernetes 节点、容器平台、CI/CD 构建机、自托管 Runner、云端 Notebook、沙箱执行环境等场景，风险显著高于普通单用户服务器。研究方特别指出，page cache 在宿主机范围内共享，因此该问题也具备容器逃逸和跨租户影响。</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">所以，</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">对现在有很多这种养马的、养小龙虾的，特别是在用这种容器去跑的，尤其应该注意。</span></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">一、漏洞描述</span></span></p><p><span leaf="">CVE 编号：CVE－2026－31431 </span></p><p><span leaf="">漏洞类型：内存破坏 ／ 逻辑错误</span></p><p><span leaf="">危险等级：高 （High） </span></p><p><span leaf="">CVSS 评分：7.8 （CVSS：3.1／AV：L／AC：L／PR：L／UI：N／S：U／C：H／I：H／A：H）</span></p><p><span leaf="">受影响组件：Linux Kernel 中的crypto：algif＿aead模块（用户空间加密接口）</span></p><p data-pm-slice="0 0 []" style="text-align: center;"><span style="font-size: 15.95pt;font-family: 黑体;color: rgb(0, 0, 0);"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">二、漏洞描述</span></span></span></p><p><span leaf="">该漏洞源于 </span><span leaf="">Linux </span><span leaf="">内核加密子系统的 </span><span leaf="">algif</span><span leaf="">＿</span><span leaf="">aead </span><span leaf="">模块在处理</span><span leaf="">“</span><span leaf="">原地操作</span><span leaf="">”</span><span leaf="">（</span><span leaf="">in</span><span leaf="">－</span><span leaf="">place operation</span><span leaf="">）时的逻辑缺陷。</span></p><p><span leaf="">技术细节：原本内核试图通过 </span><span leaf="">72548b093ee3 </span><span leaf="">次提交引入优化，允许在同一内存地址进行加密／解密映射。然而，由于 </span><span leaf="">AEAD（关联数据的认证加密）的源地址和目的地址通常来自不同的映射，这种</span><span leaf="">“</span><span leaf="">原地</span><span leaf="">”</span><span leaf="">处理带来了极高的复杂度并导致了潜在的缓冲区溢出或内存损坏风险。</span></p><p><span leaf="">影响：本地攻击者可以利用此漏洞通过构造特定的加密请求，导致系统崩溃（</span><span leaf="">DoS</span><span leaf="">）或实现内核层面的权限提升（</span><span leaf="">PrivilegeEscalation</span><span leaf="">）。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">三、影响范围</span></span></p><p><span leaf="">受影响系统：Debian 安全跟踪⻚⾯显示 bookworm、bullseye 等分⽀中的相关linux包仍有 vulnerable 状态记录,Linux 内核版本：⾃ 2017 年后引⼊该优化的所有发⾏版均受影响，包括但不限于：</span></p><p><span leaf="">CentOS 7/8/9</span></p><p><span leaf="">RHEL 7/8/9</span></p><p><span leaf="">Ubuntu 18.04–24.04</span></p><p><span leaf="">Debian 10/11/12</span></p><p><span leaf="">国产麒麟、统信等基于 Linux 的系统</span></p><p><span leaf="">建议重点排查以下环境：</span></p><p><span leaf="">1. 多⽤户共享服务器、堡垒机、CI/CD Runner、容器宿主机；</span></p><p><span leaf="">2. 允许低权限⽤户登录或执⾏代码的 Linux 主机；</span></p><p><span leaf="">3. Web 服务、应⽤服务、数据库服务等⼀旦被低权限⼊⼝突破即可继续本地提权的场景；</span></p><p><span leaf="">4. 云主机、Kubernetes Node、虚拟化宿主机等对本地提权⻛险敏感的基础设施。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">三、修复建议</span></span></p><p><span leaf="">（一）、临时缓解⽅案</span></p><p><span leaf="">截⾄⽬前，部分主流 Linux 发⾏版稳定分⽀的内核安全更新仍可能未完全推送或尚未覆盖所有环境。对于暂时⽆法⽴即升级内核的系统，建议临时禁⽤ algif_aead 模块。公开缓解建议也明确提到，在补丁部署前可禁⽤ algif_aead 模块以降低攻击⾯。</span></p><table interlaced="enabled" style="width:576px;"><tbody><tr class="ue-table-interlace-color-single"><td data-colwidth="576"><p data-pm-slice="2 2 []"><span leaf="">1. 创建禁⽤配置⽂件</span></p><p><span leaf="">echo &#34;install algif_aead /bin/false&#34; | sudo tee /etc/modprobe.d/disable-algif_aead.conf</span></p><p><span leaf="">2. ⽴即尝试卸载已加载的模块</span></p><p><span leaf="">sudo rmmod algif_aead 2&gt;/dev/null || true</span></p><p><span leaf="">3. 更新 initramfs（Ubuntu/Debian 建议执⾏）</span></p><p><span leaf="">sudo update-initramfs -u</span></p><p><span leaf="">4. 建议在业务允许的窗⼝重启服务器</span></p><p><span leaf="">sudo reboot</span></p><p><span leaf="">5. 验证是否⽣效，正常情况下应⽆输出</span></p><p><span leaf="">lsmod | grep algif_aead</span></p></td></tr></tbody></table><p><span leaf="">如系统中确有显式依赖 AF_ALG AEAD 能⼒的业务，禁⽤前应进⾏兼容性评估。公开资料称，⼤多数常⻅场景如 dm-crypt/LUKS、kTLS、IPsec/XFRM、OpenSSL/GnuTLS/NSS 默认构建、SSH 等通常不通过 AF_ALG 使⽤该路径，但显式配置使⽤ AF_ALG 的⽤户态程序可能受影响。</span></p><p><span leaf="">如需恢复启⽤</span></p><table interlaced="enabled"><tbody><tr class="ue-table-interlace-color-single"><td data-colwidth="576"><p data-pm-slice="2 2 []"><span leaf="">1. 删除禁⽤配置⽂件</span></p><p><span leaf="">sudo rm -f /etc/modprobe.d/disable-algif_aead.conf</span></p><p><span leaf="">2. ⽴即尝试加载模块</span></p><p><span leaf="">sudo modprobe algif_aead</span></p><p><span leaf="">3. 验证是否加载成功</span></p><p><span leaf="">lsmod | grep algif_aead</span></p></td></tr></tbody></table><p><span leaf="">（二）、⻓期修复⽅案。</span></p><p data-pm-slice="2 2 []"><span leaf="">请立即检查您的 Linux 内核版本，并同步至官方发布的稳定分支。 </span></p><p><span leaf="">截至撰稿时间</span><span style="margin: 0px;padding: 0px;list-style: none;line-height: 28.5px;font-size: 19px;"><span style="margin: 0px;padding: 0px;list-style: none;font-family: &#34;Times New Roman&#34;;"><span leaf="">2026</span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: 宋体;"><span leaf="">年</span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: &#34;Times New Roman&#34;;"><span leaf="">4</span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: 宋体;"><span leaf="">月</span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: &#34;Times New Roman&#34;;"><span leaf="">30</span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: 宋体;"><span leaf="">日 </span></span><span style="margin: 0px;padding: 0px;list-style: none;font-family: &#34;Times New Roman&#34;;"><span leaf="">14:30</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Debian </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">所有支持中版本仍未修复，请参考下文部署缓解措施。</span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://www.suse.com/security/cve/CVE-2026-31431.html" target="_blank">https://www.suse.com/security/cve/CVE-2026-31431.html</a></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31431&amp;packageName=kernel" target="_blank">https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-31431&amp;packageName=kernel</a></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Ubuntu </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">仅 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">26.04 LTS </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">不受影响，其他支持中版本仍未修复，请参考下文部署缓解措施。</span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://access.redhat.com/security/cve/cve-2026-31431#cve-affected-packages" target="_blank">https://access.redhat.com/security/cve/cve-2026-31431#cve-affected-packages</a></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">RHEL 8</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">9</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">10 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">仍未修复，请参考下文部署缓解措施。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">RHEL 6</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">7 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">不受影响。</span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://ubuntu.com/security/CVE-2026-31431" target="_blank">https://ubuntu.com/security/CVE-2026-31431</a></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">openEuler </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">已独立验证 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">24.03</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">24.03-LTS-SP3 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">可复现，官方仍在调查中，请参考下文部署缓解措施。</span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://security-tracker.debian.org/tracker/CVE-2026-31431" target="_blank">https://security-tracker.debian.org/tracker/CVE-2026-31431</a></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">SUSE 12~16 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">仍未修复，请参考下文部署缓解措施。（除</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">15.6</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">15SP6</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">、</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">16.0</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">部分内核）</span></p></li></ul><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a href="https://deb.freexian.com/extended-lts/tracker/CVE-2026-31431" target="_blank">https://deb.freexian.com/extended-lts/tracker/CVE-2026-31431</a></span></p><p data-pm-slice="2 2 []"><span leaf="">（三）、安全审计建议 </span></p><p><span leaf="">权限限制：由于该漏洞需要本地访问权限（Local Access），建议严格审查系统上的低权限用户账号，防止攻击者获取初始立足点。 </span></p><p><span leaf="">日志监控：监控系统日志（如dmesg 或／var／log／syslog），关注与 crypto 或 segmentation fault 相关的内核异常。</span></p><p><span leaf="">建议处置优先级：</span></p><p><span leaf=""> 公⽹业务主机、CI Runner、容器宿主机、多⽤户登录主机 &gt; 内⽹核⼼服务器 &gt; 普通终端与低暴露⾯主机。</span></p><h2 data-startline="100" data-endline="100" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 24px 0px 16px;padding: 0px 0px 0.3em;outline: 0px;font-weight: 600;font-size: 1.5em;max-width: 100%;box-sizing: border-box;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;;line-height: 1.25;color: rgb(51, 51, 51);border-bottom: 1px solid rgb(238, 238, 238);letter-spacing: 0.35px;text-align: center;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;">五、外部参考</span></span></h2><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin-top: 0px;margin-right: 0px;margin-bottom: 0px !important;margin-left: 0px;padding: 0px 0px 0px 2em;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;;font-size: 16px;letter-spacing: 0.35px;text-align: start;background-color: rgb(255, 255, 255);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Copy.fail 网站：<a href="https://copy.fail/" target="_blank">https://copy.fail/</a></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.25em 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞报告者 Xint Code 技术分析：<a href="https://xint.io/blog/copy-fail-linux-distributions" target="_blank">https://xint.io/blog/copy-fail-linux-distributions</a></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.25em 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">OSS-SEC 邮件列表： <a href="https://seclists.org/oss-sec/2026/q2/283" target="_blank">https://seclists.org/oss-sec/2026/q2/283</a></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.25em 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">CNVD 安全公告：<a href="https://www.cnvd.org.cn/webinfo/show/12336" target="_blank">https://www.cnvd.org.cn/webinfo/show/12336</a></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.75" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100002132" src="https://wechat2rss.xlab.app/img-proxy/?k=a856a57e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F2nYVbJUzOCLdfwkVMSk0PQYHGMMEeUNNNEtadibvO9kdyxU8pNwe61WYA1VNIsFb5AzQOUvsPBOwFKoZHkaC3ZTq4fJWYQKthBnK62bicYtJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">（图片由邵博同学提供）</span></p><p><span leaf="">感谢我公司邵博同学提供素材并进行漏洞验证。</span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=debdd583&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485783%26idx%3D1%26sn%3Ddd472c09e33232ab844dc0d30614ee09">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 02 May 2026 08:25:00 +0800</pubDate>
    </item>
    <item>
      <title>你的备份安全吗？</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485778&amp;idx=1&amp;sn=8ff47f5f8a64f5ec7800c39b9e18be1f</link>
      <description>3月31号，国际备份日。关于备份的重要性，我想很多人应该都已经明白了。但我今天想强调的不是备份的重要性，而是你的备份文件安全吗？</description>
      <content:encoded><![CDATA[<p>原创 <span>大兵说安全</span> <span>2026-03-31 19:32</span> <span style="display: inline-block;">河南</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=07dcc686&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCKhA3sZwlIH4CqRAF70Pl9ajYjl76Sgah1zpY1yPnib0mF6X77EycydhQ28bNP0ScSOIsWvGyIPOK1aDgNbVOBu4bWPHMheasgo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>3月31号，国际备份日。关于备份的重要性，我想很多人应该都已经明白了。但我今天想强调的不是备份的重要性，而是你的备份文件安全吗？</p>
  <p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" data-imgfileid="100000009" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></span></p><p style="text-indent: 2em;"><span leaf="">3月31号，国际备份日。</span></p><p style="text-indent: 2em;"><span leaf="">关于备份的重要性，我想大家应该都已经明白了。很多人也都采取了备份手段保护自己的数据安全。</span></p><p style="text-indent: 2em;"><span leaf="">但我今天想强调的不是备份的重要性，而是——你的备份文件安全吗？</span></p><p style="text-indent: 2em;"><span leaf="">在防范勒索病毒的过程中，备份系统经常被视为数据保护的“最后一道防线”，为企业提供关键的数据恢复保障。然而，随着备份系统复杂性不断攀升，它如今却逐渐成为安全风险的源头之一。备份系统可能成为安全风险源，缺乏访问控制和安全测试令其易受攻击。</span></p><p style="text-indent: 2em;"><span leaf="">备份只是第一步，恢复才是企业的真正挑战。要确保数据可以恢复，就要确保备份数据的安全，包括以下几个方面：</span></p><p><span leaf="">1、完整性：备份数据是否完整？如何验证？</span></p><p><span leaf="">2、保密性：备份数据同样会造成数据泄露。</span></p><p><span leaf="">3、可用性：遇到灾难发生事件能否确定可以恢复？如何验证？</span></p><p><span leaf="">4、安全性：会不会被勒索病毒加密？备份数据的安全如何保障？</span></p><p><span leaf="">5、真实性：备份文件会不会被篡改？如何验证？</span></p><p style="text-align: left;text-indent: 2em;"><span leaf=""> 近年来，我们见过太多备份数据被加密和破坏的例子。因此不要以为备份了就是安全的，只有安全的备份才能确保数据可恢复。那么，我们应该如何保证备份数据的安全呢？</span></p><p style="text-indent: 2em;"><span leaf="">先来说说安全性。勒索是目前企业数据（含备份数据）遇到的最大的安全隐患，为了防止备份数据被勒索，一般有以下措施：</span></p><p><span leaf="">一、主动防御：在备份资料存取的过程中，透过备份软件自身的检测措施或备份服务器上安全软件的检测措施，例如检测文件签名（File Signatures）是否错误，检测文件名称、扩展名或存取权限是否出现异常变动，以及是否出现大规模文件内容的变动或删除行为等，来判断是否有勒索病毒入侵，并向用户管理者发出警报。</span></p><p><span leaf="">      目前，一些备份软件自身具备防范勒索病毒攻击的功能模块，有的是利用病毒库技术，有的是利用行为检测技术，都可以抵御一部分对文件加密的攻击行为。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">但防御不可能做到100%。</span></p><p><span leaf="">二、被动防御：被动防御主要包括两类技术，<span textstyle="" style="font-weight: bold;">不可变存储和AIR GAP。</span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf=""> 不可变存储（Immutable storage）：采用一写多读（Write Once Read Many，WORM）等不可变存储技术，能够锁定备份副本的状态，防止备份副本遭到删除、覆盖或者修改。</span></p><p><span leaf="">WORM是一项历史悠久的技术。最初，WORM 技术是为了长期数据保存或合规性要求而诞生，通过存储介质的物理特性，或是存储系统底层软件、固件功能，确保写入存储介质或指定存储区的数据，无法再被更改或删除，以提供法律与诉讼上的有效性。</span></p><p><span leaf=""> 而利用 WORM 技术保存数据的特性，对于保障安全也能发挥作用。由于 WORM 能保证写入后的数据，状态不再变化 —— 既不可删除，也不可更改，彻底 “锁住” 了数据状态，那么自然也不会遭到勒索软件的加密。当 WORM 用于备份存储时，即使备份副本已感染勒索软件，但由于 WORM 机制已经 “锁住” 了数据状态，从根本上杜绝了勒索软件发作、加密或删除数据的可能性。</span></p></li></ol><p style="text-indent: 2em;"><span leaf="">所以在勒索软件危害盛行的今日，WORM 技术也展现出应用于合规性以外领域的潜力，开始有厂商推出结合了 WORM 技术的备份防护解决方案。</span></p><p style="text-indent: 2em;"><span leaf="">一般来说，WORM 技术可以依照储存媒体的类型，分为光学媒体式与磁性媒体式两大类型，也可以依照 WORM「锁住」资料的方式，将 WORM 分为物理型、固件型与软件型等三大类，分别透过物理特性或机构，储存装置固件，或是储存系统软件，来提供 WORM 能力，这三种形式各自利用不同原理运作，从而拥有不同层次的保存资料能力，以及使用特性。</span><span leaf="">。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">物理型的WORM技术：</span>利用存储介质本⾝的物理性质，或是物理机构方面的设计，来提供⼀写多读的能力。许多光学存储介质如CD-R、DVD-R等，都能透过材料本身的特性，提供只允许写入⼀次。物理型WORM最⼤优点是极为可靠，其防写措施是建立在存储介质的物理性质上，从根本上防止了删改资料的可能性，也不可能会被勒索病毒加密。光学式WORM的主要缺点，是使用较为不便。首先，光学介质的容量较⼩，目前主流单面单层DVD光盘（DVD-5）的容量为4.7GB（实际二进制容量为4.38GiB），而单面双层（DVD-9）的容量为8.5GB，双面单层（DVD-10）的容量为9.4GB，双面双层DVD光盘（DVD-18）的容量则可以达到17GB。对于大型数据中心动辄几百TB或上PB的数据，无疑极不为方便的。其次，光学式WORM离线存储装置，不能满足经常读取或检索的需求，因此适用于数据量不是太大，合规要求严，无需经常读取且需要长期保存（寿命可达50年）的<span textstyle="" style="font-weight: bold;">冷数据，如</span>金融原始凭证、司法证物、不可篡改永久归档等。除光学介质之外，还有</span><span leaf="">带物理写保护拨片的磁带、磁盘；也同样算是一种物理的防写手段——当写入资料后，随即遮盖防写孔，便构成了一写多读应用，但这种防写能力是可逆的，只要解除防写孔就能写入资料。因此不算是彻底的WORM介质。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">固件型的WORM技术：</span></span><span leaf="">利用存储设备的固件，将存储介质设定为WORM格式，常见的如磁带。几乎所有主流磁带系统都能提供专用的WORM卡匣，透过磁带机的控制功能，与磁带槽上的识别微码配合。当磁带机识别出磁带是WORM形式时，便会禁止更改或删除已写入该磁带中的资料。</span><span leaf="">如当前最普遍的LTO磁带，只要是LTO 3以后的规格，都有对应的WORM磁带版本。不过，即使是WORM磁带，理论上，也能透过从外部施加强力磁场的方式，透过消磁来强制删除这类磁性介绍中的资料，所以一般要配合实体管制措施，如防磁磁带柜，才能完整保证资料的完整性。磁带容量大（LTO8格式单盘容量12TB，LTO9格式单盘容量18TB）、保存时间长（约为30年以上），是目前很多大型数据中心<span textstyle="" style="font-weight: bold;">冷数据</span>备份的首选。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">软件型的WORM技术：</span>在存储阵列设备上，也能利用存储操作系统的软件功能，将指定的存储区域指定为一写多读，只要设定了WORM,即使是系统管理员，也无法删改该存储区域的资料。不过，与物理型或固件型WORM技术比起来，软件型WORM技术的防删改能力，仍相对不可靠，由于是依靠存储控制器的软件来提供WORM功能，其仍然是在线的，仍存在被绕过的可能，而且，只要将磁盘取出来，就失去了WORM特性。软件型WORM技术的优势，是使用便利，首先，是可透过CIFS/SMB、NFS等标准传输协议存取，满足快速读取与检索的需求。其次， 可透过设定保存期限，提供「有管制」的可逆机制。⼀般来說，WORM软件都会提供设定保存期限的选项，让管理者选择「锁住」特定档案的时间，到期后，便会解除该档案的WORM状态，此后便能将资料删除，回收存储空间。</span></p></li></ul><p><span leaf="">2. Air Gap技术：可以理解为离线技术，Air-Gap能将备份环境与可能的威胁来源隔离，特别是断开与网络和互联网的边接，减少备份副本暴露在攻击下的机会。</span></p><p style="text-indent: 2em;"><span leaf="">但实际上只有磁带、光盘这类可以实体移除、分离保存的抽取式储存装置，才能做到彻底的Air-Gap效果，也就是实体的离线（offline），通过网络将备份文件写入磁带或光盘后，就将这些存储介质取出，完全与前端生产环境断开，甚至断电，彻底确保攻击者无法接触与存取这些备份存储介质。</span></p><p style="text-indent: 2em;"><span leaf="">至于基于磁盘存储或云端存储的备份环境，虽然许多声称能提供Air-Gap机制，但其实都只是逻辑架构与设定上的「虚拟」隔离，利用存取控制技术来隔离备份环境与生产环境，而百真正断开实体的网络连接，因而仍存在着因不当的系统配置、系统漏洞或人为操作错误，导致隔离失效，备份文件暴露在网络上的可能性。</span></p><p style="text-indent: 2em;"><span leaf="">由于Air-Gap的目的是安全地保存关键资料副本，所以，原则上是与备份、归档系统结合使用，而非用于须承载线上即时存取服务的主存储系统。</span></p><p style="text-indent: 2em;"><span leaf="">广受推崇的3-2-1-1备份策略建议企业采用三种介质备份数据：两份存储于不同介质，一份异地存放，另一份采用物理隔离备份。通过将物理隔离备份与加密技术及只读写入磁带（WORM）相结合，可显著提升数据中心的网络安全韧性。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100002124" data-ratio="0.5907407407407408" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7c293b8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F2nYVbJUzOCKicc9jpCR2Zm9fQNibGsJXhaMobz8rZia2OcrPGXUJrVOtOczBh6ARcRfdtROaWdM00fuXqayda97ia0wpoXXbt5TzNTmT7Zg2qAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">除此之外，要保证数据的完整可用。还需要具备以下技术：</span></p><p><span leaf="">1、完整备份。备份内容要完整，不仅要备份数据，有时候也要备份系统和运行环境。以避免数据无法运行的情况。在备份策略上，要有增量备份，还要定期进行完全备份或定期备份合并。笔者曾在一家客户单位见过一年做了一次完全备份，每天一次增量，我们去的时候已经两百多个增量文件了。这样也是极不安全的。</span></p><p><span leaf="">2、保存多个数据副本。按照32110的原则，至少要有三份数据，存储在两种不同的介质上，其中有一份在异地保存。我们见到过太多单位，将备份数据和业务数据存储在同一个存储设备上，结果遭遇硬件损坏或勒索病毒导致业务数据和备份数据都无法打开。</span></p><p><span leaf="">3、验证技术。备份完成后能对备份文件和原始文件进行完整性验证，确保数据一致性。也可以采用区块链技术，防止文件被篡改。</span></p><p><span leaf="">4、加密技术。备份文件要加密保存，防止备份被窃取，从中恢复数据。</span></p><p><span leaf="">5、灾难恢复演练。为确保数据可恢复，应定期对备份数据进行恢复演练。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100002125" data-ratio="0.5592592592592592" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6b3ddf02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F2nYVbJUzOCLycpoOvJR0Gslmo3QjvUtbp8uo7MJIvSoAk4cREahsbxJ4NtcCZ95EDMs2Ph2rrPc50PmhVhzibTyFWzCib69VgMfwkgejDibVrU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">最后，祝大家所有的数据“安全无忧”，“有备无患”。都能选择到合适自己的安全的备份软件。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">所有不安全的备份都是在耍流氓。</span></span></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p style="text-align: left;"><span leaf="">历史文章阅读：</span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485770&amp;idx=1&amp;sn=2bd311829244a956557ecbd179e231c0&amp;scene=21#wechat_redirect" textvalue="实时备份是个伪命题吗？" data-itemshowtype="0" linktype="text" data-linktype="2">实时备份是个伪命题吗？</a></span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485649&amp;idx=1&amp;sn=0eee1e8bc636a6478a77162b1a9393ce&amp;scene=21#wechat_redirect" textvalue="从《论持久战》看网络安全建设" data-itemshowtype="0" linktype="text" data-linktype="2">从《论持久战》看网络安全建设</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2">如果你被勒索病毒勒索了……</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485492&amp;idx=1&amp;sn=c6381e936653651cf534303e386f8c14&amp;scene=21#wechat_redirect" textvalue="世界备份日，今天你备份了吗？" data-itemshowtype="0" linktype="text" data-linktype="2">世界备份日，今天你备份了吗？</a></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=80ae2b2e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485778%26idx%3D1%26sn%3D8ff47f5f8a64f5ec7800c39b9e18be1f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 31 Mar 2026 19:32:00 +0800</pubDate>
    </item>
    <item>
      <title>实时备份是个伪命题吗？</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485770&amp;idx=1&amp;sn=2bd311829244a956557ecbd179e231c0</link>
      <description>为什么说实时备份是个伪命题？又为什么这种说法这么流行？什么场景适合实时备份？什么场景适合定时备份？</description>
      <content:encoded><![CDATA[<p>原创 <span>大兵说安全</span> <span>2026-03-29 12:16</span> <span style="display: inline-block;">河南</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9521c8c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCLbI3pEV7LqjqSLZuBWfHwxcdwMhKE1r9x3k4ZfmibtSGHd0qdoicVHMmKHiaORtqtSqGGE54rKoFOdQHM346LicIS3qf0oLQia5CLc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>为什么说实时备份是个伪命题？又为什么这种说法这么流行？什么场景适合实时备份？什么场景适合定时备份？</p>
  <p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" data-imgfileid="100000009" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">好久没有写文章了，今天之所以想写这个话题，是因为一个合作伙伴找我咨询产品，又提到了实时备份。</span></p><p style="text-indent: 2em;"><span leaf="">实时备份这个概念有一大半的客户来电都会提到，开始我还会很较真的跟客户解释，后来就懒的再解释了。</span></p><p style="text-indent: 2em;"><span leaf="">今天，我们就来聊聊“实时备份”这个话题。</span></p><p style="text-indent: 2em;"><span leaf="">先说结论：实时备份是个伪命题。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">为什么是说实时备份是个</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">伪命题</span></span></p><p style="text-indent: 2em;"><span leaf="">“实时备份”确实是一个在概念上存在矛盾的术语，为什么这么说呢？。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">一、“备份”的本质是定时</span></span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">1、传统的备份本质上是一个时间点的操作。</span><span leaf="">无论是全量、增量还是差异备份，它都是在一个特定的时间点，对数据状态进行一次捕获和保存。这个操作本身是离散的、周期性的。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">这个操作需要时间，并且会产生性能开销。如果每秒都做一次全量或增量备份，数据库系统是无法承受的。因此，传统备份的恢复点目标（RPO）通常是几小时甚至几天。所以他不可能是实时的。</span></p><p style="text-indent: 2em;"><span leaf="">2、备份的核心目标是数据的历史保留和多版本化，主要用于应对数据误删、逻辑错误、版本回退或满足合规性要求。它的恢复点目标（RPO）不可能是0。为了保证备份数据安全，一般会遵循32110原则，其中有一个重要的要求就是要离线保存。</span></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5592592592592592" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100002112" src="https://wechat2rss.xlab.app/img-proxy/?k=a4f3149b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2nYVbJUzOCLL1njtYiaibRE4onNTq9mEFFdULbZiab2spChsunyiaCquiblJJADKeWsZxMYoGHbiawpAVNTx59JsJGoenroaWTd7mot1ZXZVMF9Ek%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">二、“实时”意味着持续性和同步</span></span></p><p style="text-indent: 2em;"><span leaf="">1、它追求的是RPO（恢复点目标）趋近于零，即几乎没有数据丢失。</span></p><p style="text-indent: 2em;"><span leaf="">2、实现这一目标的技术，其本质是复制（Replication），而不是备份（Backup）。它通过持续不断地将数据变化（如事务日志、数据块）从一个位置同步到另一个位置来实现。</span></p><p style="text-indent: 2em;"><span leaf="">所以，如果严格抠字眼，“实时备份”这个组合词本身就是不严谨的，它混淆了“数据保护”中两种不同目标和技术路径。从这个角度看，说它是一个“伪命题”或“营销术语”是有道理的。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">为什么“实时备份”的说法如此流行？</span></span></p><p style="text-indent: 2em;"><span leaf="">尽管技术上不严谨，但“实时备份”这个词之所以被广泛使用，是因为：</span></p><p style="text-indent: 2em;"><span leaf="">营销需要：我们都知道，备份和复制是两种不是的技术路线，各有优缺点。两种技术的厂商也会互相攻击对方的缺点，同时自己也在想办法向对方靠拢，于是形成了一个新的概念，也就是所谓的实时备份，其本质还是复制技术，但同时也借鉴了备份技术。</span></p><p style="text-indent: 2em;"><span leaf="">客户期望：既然两种技术各有优缺点。对于客户来说，总想既要又要，这时，实时备份这个概念，客户就比较喜欢。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">用户最终关心的不是技术实现原理，而是业务结果。他们想要的就是“我的数据时时刻刻都是安全的，随时能恢复”。这个业务目标可以被简单概括为“实时备份”。</span></p><p style="text-indent: 2em;"><span leaf="">沟通便利：对于非技术人员或管理者来说，“备份”的概念很好懂，就是多一份数据，至于这个数据是什么格式？用的复制技术还是备份技术？这些并不重要，他比“高可用”、“同步异步”等概念更易懂、更基础。用“实时备份”来描述HADR等技术的最终效果（数据不丢失、业务快速恢复），在沟通上非常高效。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">什么场景适用“实时备份”</span></span></p><p style="text-indent: 2em;"><span leaf="">实时备份（</span><span leaf="">含同步复制、CDP持续数据保护）</span><span leaf="">和定时备份的核心区别在于 RPO（恢复点目标，即能容忍丢失多少数据） 与 对业务系统的影响。实时备份追求 RPO ≈ 0（近乎零丢失），但占用资源和成本较高；定时备份允许一定量的数据丢失，但资源占用少且架构简单。</span></p><p style="text-indent: 2em;"><span leaf="">选择什么样的技术主要参考以下几个指标：</span></p><p style="text-indent: 2em;"><span leaf="">1、RPO：恢复点目标，即能容忍丢失多少数据。可以考虑以下问题：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 2em;"><span leaf="">如果丢失 1 小时的数据，公司是否会产生重大经济损失或不可逆的品牌声誉风险？</span></p></li><li><p style="text-indent: 2em;"><span leaf="">业务系统的数据写入频率是否极高（如每秒数千笔），且无法容忍任何积压？</span></p></li></ul><p style="text-indent: 2em;"><span leaf="">如果答案都是肯定的。那么就要采用实时技术。</span></p><p style="text-indent: 2em;"><span leaf="">2、RTO：恢复时间目标，即出现故障后多长时间可以恢复。备份的数据需要经过恢复的过程才能使用，RTO的时间相对要长一些。</span></p><p style="text-indent: 2em;"><span leaf="">3、数据保存时间：备份数据可以长时间保存，对于一些合规要求长时间保存的数据，一般采用备份技术，保存在磁带或光盘等离线介质上。</span></p><p style="text-indent: 2em;"><span leaf="">4、故障类型：复制技术一般针对硬件故障，不能解决逻辑错误。而备份可以针对硬件故障，也可以针对逻辑错误。因为备份可以保留多版本，实现版本回退。</span></p><p style="text-indent: 2em;"><span leaf="">5、数据类型：对于结构化数据和读写频繁的热数据，一般采用同步技术为主，备份技术为辅。对于非结构化数据和不经常使用的冷数据，一般采用备份技术。</span></p><p style="text-indent: 2em;"><span leaf="">6、成本：实时</span><span leaf="">对网络带宽要求高，存储一般使用SSD或SAS硬盘，另外，为实现接管需要，对备用服务器的性能要求和原环境接近，所以存储成本和算力成本较高。而备份数据存储一般使用SATA硬盘或者离线保存介质如磁带和光盘，存储成本和算力成本较低。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">定时备份适用的业务场景：</span></span></p><p style="text-indent: 2em;"><span leaf="">1、</span><span leaf="">配合归档策略的冷数据：需要长期保留用于合规审计的数据，如医院PACS数据，按国家规定门诊记录保存15年，住院记录保存30年。实时备份的成本过高，定时备份并转磁带/对象存储是更合适的选择。</span></p><p style="text-indent: 2em;"><span leaf="">2、非核心业务系统：如企业内部 知识库、公告栏等系统。即使丢失最近 24 小时的数据，也基本不影响企业核心运营，业务部门可接受通过人工补录恢复。</span></p><p style="text-indent: 2em;"><span leaf="">3、高吞吐、低敏的日志/监控数据：如 IoT（物联网）传感器数据、服务器监控指标。数据量极大，若采用实时备份，网络和存储成本会急剧膨胀；定时备份可在业务低峰期压缩传输，性价比更高。</span></p><p style="text-indent: 2em;"><span leaf="">4、静态网站或内容管理系统：内容更新频率低（如企业官网、新闻发布站），每次更新后手动或每日备份即可满足恢复需求。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">实时技术适用的场景：</span></span></p><p style="text-indent: 2em;"><span leaf="">1、交易系统：如银行核心账务、互联网电子商务平台、证券交易、支付网关。每一笔交易都涉及资金流动，丢失几秒甚至毫秒级的数据都会造成对账差异和资损。</span></p><p style="text-indent: 2em;"><span leaf="">2、数据库系统（高敏）：如 Oracle、MySQL 等关系型数据库，且开启了 Binlog/Archive Log 实时同步。适用于 ERP（企业资源计划系统）、CRM（客户关系管理系统）等核心业务库，一旦宕机，业务链条会瞬间中断。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p style="text-indent: 2em;"><span leaf="">技术没有好坏之分，只有适合不适合。希望大家能根据自身业务场景选择适合的技术。</span></p><p style="text-indent: 2em;"><span leaf="">在实际生产环境中，推荐对数据分层，采用多种数据保护方式相结合：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;"><span leaf="">核心库：采用 实时技术（CDP/同步复制） + 每日定时全量/增量备份。实时技术用于应对软硬件故障时的分钟级接管，定时备份用于应对逻辑错误（如数据误删、SQL 语句误执行）后的定点回滚。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 2em;"><span leaf="">非核心系统和非结构化文件：采用 定时备份（每日增量，每周全量），但对关键子目录（如财务共享文件夹）单独开启 实时同步。</span></p><p style="line-height: 2em;"><span leaf="">注：备份数据不要使用SSD硬盘存储，易丢失且不可恢复。</span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.891005291005291" data-s="300,640" data-type="png" data-w="945" type="block" data-imgfileid="100002114" src="https://wechat2rss.xlab.app/img-proxy/?k=6bdd7f70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F2nYVbJUzOCJiaTroHgn3JSpUoxAEppxSn19d9s2IojglGG78vITmZ5Ctib1UFWpGicK0bVEUqDZPnalTDWcrkG7ficdIpDrlMqiaS5SFCqW2EMrs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485492&amp;idx=1&amp;sn=c6381e936653651cf534303e386f8c14&amp;scene=21#wechat_redirect" textvalue="世界备份日，今天你备份了吗？" data-itemshowtype="0" linktype="text" data-linktype="2">世界备份日，今天你备份了吗？</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485459&amp;idx=1&amp;sn=59ea874337f518c82e5cbccdba782824&amp;scene=21#wechat_redirect" textvalue="315，我们也来打打安全圈的假（一）" data-itemshowtype="0" linktype="text" data-linktype="2">315，我们也来打打安全圈的假（一）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485469&amp;idx=1&amp;sn=1a0c151e8a4e49c9905d4ed771711df1&amp;scene=21#wechat_redirect" textvalue="315，也来打打安全圈的假（二）" data-itemshowtype="0" linktype="text" data-linktype="2">315，也来打打安全圈的假（二）</a></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=891a0638&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485770%26idx%3D1%26sn%3D2bd311829244a956557ecbd179e231c0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 29 Mar 2026 12:16:00 +0800</pubDate>
    </item>
    <item>
      <title>昭君博物馆</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485726&amp;idx=1&amp;sn=1db73667273767b1138aff98904fc8b9</link>
      <description>昭君博物馆&#xA;</description>
      <content:encoded><![CDATA[<p><span>大兵说安全</span> <span>2026-03-20 15:20</span> <span style="display: inline-block;">内蒙古</span></p>






  
  
  <p>昭君博物馆</p>
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=221d5c99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCIdKWbV1nVO7330G8YCvjF8QXOZW5j6kUXUpMgNmb4PFgKzLobLs67a9NqpcAHueMlm7Ae37GYaAGhlyiayWf5UPAg5rsEHZncg%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d9600239&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCIYC8y1KU6oicxBUIYlk868NDj8YAFK9AgD7gwGnxt77iaqzXGgsW9tVZrIHSPXXUaUmC4JtEuOaCPS4icVymkWHbereH9UPfho6Q%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99ef8e46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCKVibV5kmeOpIqKoNrDetfzJcB2ChB3EOINyphFgCCerOds9FmWpZePaXlHr1TzzznC5iaMClHAnAOC1z2Kh2Awv0tNCAHFkDaTE%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=66a7589a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCLxeibfib0OqPJKstysBgAmp3Uh24uqaPAaJZ3p0yJbTwvraFcMxaEUibLq0icOHib0ibKA4aFDvV5NsDlibMj4WdOvXZMT4eQWCJoCMk%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5fd88333&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCKR0mQPW0TtVzvV3xTVQ2L2WFVl2MXiaxZteEnBZjicO87AVcicCfC7A2nqZ0qCvFka3Fq5oe16xNOg68xDzpJpcNp3YITCXiaCoiao%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=aef7de84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCJJG8GRxMTw9FTmSlJIIEwnUOIU9DKP6fVVkibgNewp6uEZClwY0qGxsuY8WjezMtXz8ic657hD7bLEkxhTGhtzbZF4tHkticQ4ico%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5511d66b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCLcZT4hAaXv8PzLk4CBXkC2HicGY0nxI5iapukZGYrJ0ibWmibdLicAer9fVBPhZg5lHyaXSfqt1icwMrtsvrokjqjibUiaX9r6ZzyMHcY%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c4c20154&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCLZZQ61b5HmREHmPNibZDHaKoZ1WQyiaZKAbAAX3OQnZgicAOfgNpNz3cRnQlgQQo3btSWIstlQlZicgHkYqiaU0TYfxjsVeDUL54kw%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8eb70ab6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCJKMkYAyUyQPlebFLaqAbdic2prk57NEQ7XBlno42Z7wJ3ibtJSwkSgTB964LsSFD3dicS9ka6D0hEKsPmib3nJLPg29LG6kcyiclia0%2F0%3Fwx_fmt%3Djpeg"/></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=502ade8e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485726%26idx%3D1%26sn%3D1db73667273767b1138aff98904fc8b9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 20 Mar 2026 15:20:00 +0800</pubDate>
    </item>
    <item>
      <title>前几天跟几个朋友聊天，说到一个为什么南北</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485710&amp;idx=1&amp;sn=a1c931e804967642d3eda63e589e1499</link>
      <description>前几天跟几个朋友聊天，说到一个为什么南北方小年不是同一天的民间传说，我突然想起来小时候我还帮忙整理过一个民间传说的书，回家找了一下果然找到了。&#xA;这是濮阳县文化馆当年的一个活动，对各种民间传说、戏曲等进行整理，90年出版的，当时我上初中，每天放学回家就帮忙校对文稿，也参与一些故事的记录。包括姥姥讲的一些民间故事，印象比较深的是王二麻子系列故事（有点像新疆的阿凡提），还有她讲的《女儿经》，这些故事估计现在的孩子都没有听说过了。&#xA;&lt;a class=&#34;wx_topic_link&#34; data-topic=&#34;1&#34; style=&#34;color: #576B95;&#34;&gt;#民间传说故事&lt;/a&gt;  &lt;a class=&#34;wx_topic_link&#34; data-topic=&#34;1&#34; style=&#34;color: #576B95;&#34;&gt;#濮阳县民间文学&lt;/a&gt; &#xA;</description>
      <content:encoded><![CDATA[<p><span>大兵说安全</span> <span></span> <span style="display: inline-block;">河南</span></p>






  
  
  <p>前几天跟几个朋友聊天，说到一个为什么南北方小年不是同一天的民间传说，我突然想起来小时候我还帮忙整理过一个民间传说的书，回家找了一下果然找到了。</p><p>这是濮阳县文化馆当年的一个活动，对各种民间传说、戏曲等进行整理，90年出版的，当时我上初中，每天放学回家就帮忙校对文稿，也参与一些故事的记录。包括姥姥讲的一些民间故事，印象比较深的是王二麻子系列故事（有点像新疆的阿凡提），还有她讲的《女儿经》，这些故事估计现在的孩子都没有听说过了。</p><p><a class="wx_topic_link" data-topic="1" style="color: #576B95;">#民间传说故事</a>  <a class="wx_topic_link" data-topic="1" style="color: #576B95;">#濮阳县民间文学</a> </p>
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fffb12b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCIicz4ickHNMOuBrYWDC6BYBgaGjW2MHewNg3fwPv3nMNU03u0zfBiaaO85GjxnmbkJBicOicRET0o19icBkye9kibNyuEf5EfhDzuvEg%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c88ced43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCLmKiba6Jycthrw1htAt1ic3Hdg3rVlWzk9q7fjuttPYDYQ4GibOzBfpSauSrzo38pjPicxZDI9jxQLQ0C1beluQJq7DNMKxOj1wicg%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d608bd05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCKa0IJKjiciblrictyAHevj9iblZ44bZQKEtp7VgO87Ulg7CCciaJB3cjZVhpCyibkRaGzCEmiaWY5RYIqN6RmITH6suXj8X0bjibYF2Wo%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=796acc70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCKkWE3opueRdXsnZBHE6HkFbBrHQjaeibGgJVWOmicYdU3Gib6piaK0lDia282144XoFocVcWeW6FjLeQeJicUoia0iaIwFAqmmDW33slI%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fc1bc2d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCIUNoG2C5kcahOKGECBMg4TWkt2n2iaPib7Q0Cm37YH1drw7uOFQLKm9FPZjrkSBCrJJ9TDhhnWkbU8qGh03ZDZuyuX5fjIvib0PA%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9537d2cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCKLaVqM3q2gCRzWT33aF8U0KC8k9Q4LmEjs4LEY2YnY2M2JFJvIYCEq2TpeiaSJ9Bv1TTGbjzWU1krNMFTia2TlWg4P8k1mXfhhY%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d9f66941&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F2nYVbJUzOCKtBmfULbEf5oyJsyybMqC1UgefBergwDHSlGRBC6LRs2xt4uasJBI7oMDTGWO9GXv4YqL6DEhMHbfxX14puoVYIGJuhHwc4W0%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=abfe670e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCISQlOncjYAe6BDxs4NRt4pnPzcqAf8gSyp6tvVZiaic9wt424rwMiamClj8Q9L9cZEea3KAejCtP3MrhuUypU4icBg2Esic7xFBKyI%2F0%3Fwx_fmt%3Djpeg"/></p><p><img src="https://wechat2rss.xlab.app/img-proxy/?k=abbfc5c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F2nYVbJUzOCL3WqVm3UWGEjRtojdr5iaozAWdk7icZfSSibXfwfVzln5K4FVEA2zuZKqCDFlcsjzFdmcQEZ1Biby9xPaRKlfbgutMeqXTaxNWIiaE%2F0%3Fwx_fmt%3Djpeg"/></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=96e0598f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485710%26idx%3D1%26sn%3Da1c931e804967642d3eda63e589e1499">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Feb 2026 12:51:52 +0800</pubDate>
    </item>
    <item>
      <title>国家互联网信息办公室关于《互联网应用程序个人信息收集使用规定（征求意见稿）》公开征求意见的通知</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485693&amp;idx=1&amp;sn=08d39c1470d937245d0fd2e44b469124</link>
      <description>为规范互联网应用程序个人信息收集使用活动，保护个人信息权益，促进个人信息合理利用，根据《中华人民共和国网络安全法》等法律法规，国家互联网信息办公室起草了《互联网应用程序个人信息收集使用规定（征求意见稿）》，现向社会公开征求意见。</description>
      <content:encoded><![CDATA[<p><span>大兵说安全</span> <span>2026-01-24 14:44</span> <span style="display: inline-block;">河南</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=079419bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqRIHa7ZmY34PTqR0ia2zf0XXkTBnnFTianNd2g3cjCfGU0S0icy6lCAZIOBS94zWyUpWFlEAmAsXuHLw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>为规范互联网应用程序个人信息收集使用活动，保护个人信息权益，促进个人信息合理利用，根据《中华人民共和国网络安全法》等法律法规，国家互联网信息办公室起草了《互联网应用程序个人信息收集使用规定（征求意见稿）》，现向社会公开征求意见。</p>
  <p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;" data-pm-slice="0 0 []"><span leaf="">为规范互联网应用程序个人信息收集使用活动，保护个人信息权益，促进个人信息合理利用，根据《中华人民共和国网络安全法》《中华人民共和国个人信息保护法》《网络数据安全管理条例》等法律法规，国家互联网信息办公室起草了《互联网应用程序个人信息收集使用规定（征求意见稿）》，现向社会公开征求意见。公众可以通过以下途径和方式提出反馈意见：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.登录中国网信网（www.cac.gov.cn），进入首页“网信要闻”查看文稿。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.通过电子邮件方式发送至：shujuju@cac.gov.cn。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.通过信函方式将意见寄至：北京市海淀区阜成路15号国家互联网信息办公室网络数据管理局，邮编100048，并在信封上注明“互联网应用程序个人信息收集使用规定征求意见”。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">意见反馈截止时间为2026年2月9日。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">附件：《互联网应用程序个人信息收集使用规定（征求意见稿）》</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: right;"><span leaf="">国家互联网信息办公室</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: right;"><span leaf="">2026年1月10日</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">互联网应用程序个人信息收集使用规定</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><span leaf="">（征求意见稿）</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第一章 总则</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第一条</span></strong><span leaf=""> 为了规范互联网应用程序个人信息收集使用活动，保护个人信息权益，促进个人信息合理利用，根据《中华人民共和国网络安全法》《中华人民共和国个人信息保护法》《网络数据安全管理条例》等法律法规，制定本规定。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二条</span></strong><span leaf=""> 在中华人民共和国境内运营互联网应用程序过程中收集使用个人信息，以及软件开发工具包、分发平台、智能终端等为互联网应用程序收集使用个人信息活动提供服务的，应当遵守相关法律法规和本规定的要求。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序在中华人民共和国境外收集使用中华人民共和国境内自然人个人信息的活动，符合《中华人民共和国个人信息保护法》第三条第二款规定情形的，适用本规定。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三条</span></strong><span leaf=""> 收集使用个人信息应当遵循合法、正当、必要和诚信原则，不得通过误导、欺诈、胁迫等方式收集使用个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">收集使用个人信息应当向个人信息主体充分告知收集使用规则，并取得个人信息主体同意；收集使用敏感个人信息的，应当取得个人信息主体的单独同意。法律、行政法规另有规定的，依照其规定。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">收集使用个人信息应当采取对个人信息主体权益影响最小的方式，限于提供产品或者服务所必需，不得超范围收集使用个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">不得以个人信息主体不同意收集使用其个人信息或者撤回同意为由，拒绝提供产品或者服务，个人信息属于提供产品或者服务所必需的除外。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第四条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包运营者分别对所运营的互联网应用程序、软件开发工具包个人信息收集使用活动及安全保护承担主体责任。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序运营者对嵌入的软件开发工具包、分发平台运营者对分发的互联网应用程序、智能终端厂商对预置的互联网应用程序依法履行审核义务。未能进行有效审核，对个人信息主体权益造成损害的，依法承担相应责任。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第五条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包、分发平台运营者和智能终端厂商对汇聚、关联后属于国家秘密事项的个人信息，按照国家有关安全保密规定加强管理。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序、软件开发工具包、分发平台运营者和智能终端厂商对掌握的属于通信秘密的个人信息，不得对内容进行检查，不得向第三方提供。法律、行政法规另有规定的，依照其规定。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第六条</span></strong><span leaf=""> 鼓励行业组织建立完善行业自律机制，制定个人信息保护行业规范和自律公约，指导会员单位依法依规开展个人信息收集使用活动，接受社会监督。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第二章 互联网应用程序运营安全管理要求</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第七条</span></strong><span leaf=""> 互联网应用程序收集使用个人信息应当遵循公开、透明原则，制定公开个人信息收集使用规则，通过清晰易懂的语言真实、准确、完整、逐项列明下列事项：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（一）运营者名称或者姓名和有效的联系方式；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（二）以结构化清单形式列明每项功能服务收集使用个人信息的目的、方式、种类，调用权限名称、频度，收集使用敏感个人信息的必要性以及对用户权益的影响；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（三）嵌入软件开发工具包的，应当以结构化清单形式列明嵌入的软件开发工具包名称（包名）、版本、主要功能、运营者名称或者姓名、收集使用个人信息的种类和完整的软件开发工具包个人信息收集使用规则链接；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（四）个人信息保存期限和到期后的处理方式，保存期限难以确定的，应当明确保存期限的确定方法；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（五）用户查阅、复制、转移、更正、补充、删除、限制处理个人信息以及注销账号、撤回同意的方法和途径等；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（六）法律、行政法规规定应当告知的其他事项。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序对于前款所述重点内容，应当以加粗字体、放大字号、标记不同颜色等显著方式向用户提示。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第八条</span></strong><span leaf=""> 收集使用个人信息的目的、方式、种类、保存期限或者保存期限的确定方法，调用权限名称、频度和嵌入的软件开发工具包收集使用个人信息行为等情况发生变化的，互联网应用程序应当及时修订、更新个人信息收集使用规则。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">注册用户5000万以上或者月活跃用户1000万以上，业务类型复杂的互联网应用程序依照前款规定修订、更新个人信息收集使用规则的，应当同步通过互联网应用程序首页、官方网站、公众号等途径公开征求意见，征求意见期限不少于7个工作日。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第九条</span></strong><span leaf=""> 互联网应用程序应当在首次启动时，通过弹窗等显著方式向用户告知个人信息收集使用规则，并在用户充分知情的前提下，取得用户同意规则的明确表示。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序向第三方提供个人信息的，应当取得用户的单独同意。互联网应用程序应当在设置页面等醒目位置提供个人信息收集使用规则一键访问功能，方便用户查阅和保存。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序更新个人信息收集使用规则，符合第八条第一款所列情形的，应当通过弹窗、消息推送等显著方式及时向用户告知更新的具体内容，并重新征得用户同意。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十条</span></strong><span leaf=""> 互联网应用程序不得通过调用通讯录、通话记录、短信权限收集使用用户以外其他个人信息主体的个人信息，确需用于满足通讯联系、添加好友、数据备份的除外。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序收集使用前款个人信息，属于通信秘密的，应当符合本规定第五条第二款规定。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十一条</span></strong><span leaf=""> 互联网应用程序应当提供基于功能场景的个人信息收集使用配置选项，允许用户根据需要，同意部分功能场景收集使用相关个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十二条</span></strong><span leaf=""> 互联网应用程序应当在用户使用具体功能时方可索要对应的必要个人信息权限，并同步告知使用目的，不得提前索要。用户拒绝的，互联网应用程序不得频繁索要影响用户正常使用其他功能。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十三条</span></strong><span leaf=""> 互联网应用程序不得在用户同意个人信息收集使用规则前收集使用个人信息，不得超出用户同意的目的、方式、种类、保存期限收集使用个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序调用权限需与当前功能场景直接相关，应当仅在用户使用具体功能时以所需的最低频度、最小范围收集个人信息。在当前功能场景不再需要权限时停止调用权限，不得收集非必要个人信息、调用非必要权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十四条</span></strong><span leaf=""> 互联网应用程序应当仅在用户主动选择使用拍照、发送语音、录音录像等功能时调用相机、麦克风权限，不得在用户停止使用相关功能或者无关场景调用相机、麦克风权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序在地图导航、路径记录、外卖闪送、位置共享等需要实时定位的场景，持续调用位置权限的频率应当限于实现业务功能的最低频度；在添加地点、内容搜索、内容推荐、广告营销等需单次定位场景，应当仅在用户进入功能界面或者用户主动刷新时调用一次位置权限。除法律、行政法规另有规定或者所提供业务功能确需后台持续获取位置外，互联网应用程序不应索要后台访问用户位置信息权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户选择使用上传或者发送图片、文件等功能，互联网应用程序可使用智能终端提供的存储访问框架实现的，不得索要手机相册、通讯录、短信、存储等权限。互联网应用程序通过提供文件编辑、文件备份等功能获得存储权限的，不得访问用户主动选择以外的文件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十五条</span></strong><span leaf=""> 互联网应用程序收集人脸、指纹、声纹等生物识别信息应当具有特定的目的和充分的必要性，采取对个人权益影响最小的方式，并实施严格的保护措施。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">除法律、行政法规另有规定或者取得用户单独同意外，互联网应用程序收集使用人脸、指纹、声纹等信息应当存储于生物识别设备内，不得通过互联网对外传输。除法律、行政法规另有规定外，生物识别信息的保存期限不得超过实现处理目的所必需的最短时间。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十六条</span></strong><span leaf=""> 互联网应用程序运营者应当采取充分的管理措施和必要的技术措施，严格落实未成年人个人信息保护要求，切实防范未成年人个人信息泄露、篡改、丢失。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序收集使用不满十四周岁未成年人个人信息的，应当制定专门的个人信息收集使用规则，并取得未成年人父母或者其他监护人的同意。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十七条</span></strong><span leaf=""> 互联网应用程序通过自动化决策方式向用户进行信息推送、商业营销的，应当设置易于理解、便于访问和操作的个性化推荐关闭选项。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户关闭个性化推荐功能时，互联网应用程序应当停止将用户相关个人信息用于个性化推荐目的。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十八条</span></strong><span leaf=""> 互联网应用程序应当为用户提供注销账号的便捷功能。用户注销账号的，除确有必要用于防范黑灰产、安全风控等情形，互联网应用程序不得要求用户新增提供人脸、手持身份证照片等超出互联网应用程序已收集范围以外的个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户注销账号的，互联网应用程序应当在15个工作日内完成账号注销，删除已收集的相关个人信息或者进行匿名化处理，法律、行政法规另有规定的除外。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">对于同一企业主体或者集团旗下多款互联网应用程序采用统一账号进行一体化管理的，应当允许用户选择注销其中一款互联网应用程序账号，或者允许用户选择关闭该账号在此互联网应用程序的使用权限，并删除仅用于此互联网应用程序的个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十九条</span></strong><span leaf=""> 互联网应用程序应当与嵌入的软件开发工具包约定收集使用个人信息的目的、方式、种类和安全保护责任及违约责任，并采取有效的技术措施对嵌入的软件开发工具包个人信息收集使用行为进行审核，确保软件开发工具包实际个人信息收集和权限调用行为与互联网应用程序个人信息收集使用规则中声明的软件开发工具包相关内容保持一致。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户向互联网应用程序提出查阅、复制、更正、补充、删除、限制处理其个人信息，或者注销账号、撤回同意等相关请求涉及软件开发工具包个人信息收集使用活动的，互联网应用程序应当将用户请求及时通知软件开发工具包，并督促软件开发工具包及时响应用户请求。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十条</span></strong><span leaf=""> 互联网应用程序就个人信息收集使用行为进行优化、改进，发布或者更新版本后，应当采取有效方式提醒用户进行版本升级，并对所有授权发布渠道的旧版本互联网应用程序进行更新替换。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十一条</span></strong><span leaf=""> 鼓励互联网应用程序接入国家网络身份认证公共服务，用以支持用户使用网号、网证登记、核验真实身份信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户选择使用网号、网证登记、核验身份信息并通过验证的，互联网应用程序不得强制要求用户另行提供明文身份信息，法律、行政法规另有规定或者用户同意提供的除外。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第三章 软件开发工具包运营安全管理要求</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十二条</span></strong><span leaf=""> 软件开发工具包收集使用个人信息的，应当制定个人信息收集使用规则并在产品官方网站公开。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">对于同时运营多个历史版本的，软件开发工具包应当在个人信息收集使用规则中列明不同版本个人信息收集使用行为。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">软件开发工具包收集使用个人信息的目的、方式、范围等发生变化的，应当同步更新相应的个人信息收集使用规则。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十三条</span></strong><span leaf=""> 软件开发工具包不得超出收集使用规则声明的范围收集使用个人信息，不得超出实现业务功能的最小范围收集使用个人信息，不得超出实现业务功能的最低频度调用权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十四条</span></strong><span leaf=""> 软件开发工具包应当提供基于功能的个人信息配置选项，允许互联网应用程序按照不同功能需要对软件开发工具包个人信息收集行为进行管理配置。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">软件开发工具包通过自动化决策方式向用户进行信息推送、商业营销的，应当向互联网应用程序提供个性化推荐关闭选项，在关闭后停止将用户相关个人信息用于个性化推荐目的。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">软件开发工具包应当及时响应互联网应用程序通知的用户个人信息查阅、复制、更正、补充、删除、限制处理等相关请求。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十五条</span></strong><span leaf=""> 软件开发工具包应当建立有效方式和途径，直接响应用户查阅、复制、转移、更正、补充、删除、限制处理个人信息的请求，相关方式和途径应当在个人信息收集使用规则中予以列明。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第四章 应用程序分发平台安全管理要求</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十六条</span></strong><span leaf=""> 分发平台应当加强互联网应用程序上架审核，建立互联网应用程序收集使用个人信息规范性档案，在受理互联网应用程序发布及版本更新上架申请时，登记并核验互联网应用程序运营者的真实身份、联系方式等信息，记录互联网应用程序个人信息收集使用问题以及因违法违规收集使用个人信息被省级以上履行个人信息保护职责的部门通报或行政处罚的情况。对未提供相关信息或者提供虚假信息，互联网应用程序无个人信息收集使用规则、无账号注销功能或者删除个人信息途径的，不予上架。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">分发平台在上架审核中应根据互联网应用程序运营者获得个人信息保护认证和互联网应用程序安全认证的结果，予以优先展示推荐。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">分发平台应当自本规定生效之日起6个月内，完成对在架存量互联网应用程序的审核，审核不通过的予以清理下架。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十七条</span></strong><span leaf=""> 分发平台应当在互联网应用程序分发、下载页面，清晰准确展示下列信息：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（一）互联网应用程序运营者名称或者姓名、联系方式；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（二）互联网应用程序主要功能介绍；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（三）互联网应用程序运行所需具体权限列表；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（四）个人信息收集使用规则文本或者链接；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（五）对因违法违规收集使用个人信息被省级以上履行个人信息保护职责的部门通报或行政处罚的互联网应用程序，应当自通报或处罚之日起6个月内，在分发、下载页面发布个人信息安全风险提示。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十八条</span></strong><span leaf=""> 对履行个人信息保护职责的部门认定存在违法违规收集使用个人信息行为的互联网应用程序，分发平台应当积极配合采取警示、不予分发、暂停分发或者终止分发等处置措施。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第五章 智能终端安全管理要求</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二十九条</span></strong><span leaf=""> 智能终端厂商在受理互联网应用程序预置申请时，应当登记并核验互联网应用程序运营者的真实身份、联系方式等信息，对未提供上述信息或者提供虚假信息，互联网应用程序无个人信息收集使用规则、无账号注销功能或者删除个人信息途径的，不予预置。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十条</span></strong><span leaf=""> 互联网应用程序索要日历、通话记录、相机、通讯录、位置、麦克风、电话、短信、存储、身体活动等权限时，智能终端操作系统应弹窗征得用户同意，根据权限特点提供可基于时间、频度、精度等精细化授权模式选项。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十一条</span></strong><span leaf=""> 智能终端应当在屏幕顶部等显著位置，以易于理解的图标等显著标识，如实地向用户提示当前正在调用的麦克风、摄像头、位置等权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十二条</span></strong><span leaf=""> 智能终端应当如实记录并集中展示互联网应用程序调用日历、通话记录、相机、通讯录、位置、麦克风、电话、短信、存储、身体活动等权限情况；互联网应用程序后台静默期间自启动、关联启动情况；互联网应用程序通过智能终端收集剪切板、设备唯一标识、应用程序列表等个人信息行为。记录规则应当予以公开。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">智能终端应当准确提示互联网应用程序调用权限可能带来的安全风险。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第六章 监督管理</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十三条</span></strong><span leaf=""> 国家网信部门负责统筹协调和监督管理互联网应用程序、软件开发工具包、分发平台和智能终端个人信息保护工作。国务院电信主管部门、公安部门和其他有关机关依照有关法律法规和本规定的要求，在各自职责范围内负责互联网应用程序、软件开发工具包、分发平台和智能终端个人信息保护和监督管理工作。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">地方网信部门负责统筹协调和监督管理本行政区域内互联网应用程序、软件开发工具包、分发平台和智能终端个人信息保护工作，地方电信管理部门、公安部门和其他有关机关依据各自职责做好本行政区域内互联网应用程序、软件开发工具包、分发平台和智能终端个人信息保护和监督管理工作。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十四条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包运营者应当在产品官方网站、个人信息收集使用规则中提供有效的、易于访问的投诉举报渠道，健全投诉举报的受理、处置、反馈机制，在承诺时限内（承诺时限不得超过15个工作日，无承诺时限的，以15个工作日为限）受理并处置个人信息相关投诉。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序运营者应当同时受理、处置、反馈关于嵌入的软件开发工具包相关个人信息问题举报，核验属实的，应当督促软件开发工具包运营者进行整改。分发平台运营者、智能终端厂商应当同时受理、处置、反馈关于分发和预置的互联网应用程序相关个人信息问题举报，核验属实的，应当督促互联网应用程序运营者进行整改。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十五条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包、分发平台运营者和智能终端厂商应当制定内部管理制度和操作规程，建立健全内部合规管理体系和问责机制，防止个人信息被用于电信网络诈骗等违法犯罪活动，充分保护用户个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序、软件开发工具包、分发平台运营者和智能终端厂商应当对履行个人信息保护职责的部门依法开展的个人信息保护监督检查予以配合，并提供必要的技术支持和协助。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十六条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包运营者应当强化对个人信息查阅、复制、修改、删除等操作的权限管理，采取加密、去标识化等安全技术措施，防止个人信息泄露、丢失或者未经授权的访问。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">发生个人信息泄露、丢失的，互联网应用程序、软件开发工具包运营者应该将泄露个人信息的种类、原因、可能造成的危害、采取的补救措施等信息及时告知用户，并向履行个人信息保护职责的部门报告。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十七条</span></strong><span leaf=""> 互联网应用程序、软件开发工具包、分发平台运营者和智能终端厂商违反本规定的，履行个人信息保护职责的部门依照《中华人民共和国网络安全法》《中华人民共和国个人信息保护法》《网络数据安全管理条例》等相关法律法规处理；构成犯罪的，依法追究刑事责任。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">第七章 附则</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十八条</span></strong><span leaf=""> 本规定中下列用语的含义：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序（App），是指智能终端预置、下载安装的应用软件，以及基于应用软件开放平台接口开发的、无需安装即可使用的小程序、快应用等。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">互联网应用程序运营者，是指互联网应用程序的开发者、所有者、管理者或者提供者。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">软件开发工具包（SDK），是指协助软件开发的软件库。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">软件开发工具包运营者，是指软件开发工具包的开发者、所有者、管理者或者提供者。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">个人信息主体，是指个人信息所标识或者关联的自然人。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">用户，是指使用互联网应用程序相关功能服务的自然人。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">分发平台，是指通过互联网提供互联网应用程序发布、下载、动态加载等服务提供者，包括应用商店、应用市场、快应用中心、小程序平台等。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">智能终端，是指能够接入公众网络、具有操作系统、可由用户自行安装和卸载应用软件的移动通信终端产品。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">必要个人信息，是指为了保障基本功能服务或者用户所选择使用的功能服务正常运行所必需的个人信息，缺少该信息无法向用户提供相应的功能服务。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">可收集个人信息权限，是指智能终端操作系统向互联网应用程序开放的，具有收集个人信息功能的系统权限，包括日历、通话记录、相机、通讯录、位置、麦克风、电话、短信、存储、身体活动等，简称权限。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三十九条</span></strong><span leaf=""> 本规定自 年 月 日起施行。</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.cac.gov.cn/2026-01/10/c_1769603446094128.htm">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3a172885&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485693%26idx%3D1%26sn%3D08d39c1470d937245d0fd2e44b469124">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 24 Jan 2026 14:44:00 +0800</pubDate>
    </item>
    <item>
      <title>教你如何看懂反病毒报告（三）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485688&amp;idx=1&amp;sn=2c8066f311656a7ed35b411f91fa4953</link>
      <description>今天介绍关于木马的分类和命名</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-11-28 23:09</span> <span style="display: inline-block;">河南</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=09a4f56c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqQREB0G2icIEefTwUdb7z8RAt0Zd5FiaRd1zRWFhiaQogtzYx99StF6N3mpedpEL3q0xnwKJmhgE7KvA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>今天介绍关于木马的分类和命名</p>

<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001946" class="rich_pages wxw-img" data-ratio="0.59921875" data-s="300,640" data-type="jpeg" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=86d01788&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqRSethuSxQeNOyQLADpx5mBFnDq7P8coyQyAmGRo2f4FNpRLz9fXnqT7xTQlox4UqQ1oCyITotbew%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">前情回顾：</span></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在前文《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485377&amp;idx=1&amp;sn=27286d0e0fcf3fbf7ba29460c808d6a2&amp;scene=21#wechat_redirect" textvalue="教你一招，轻松变成反病毒高手" data-itemshowtype="0" linktype="text" data-linktype="2">教你一招，轻松变成反病毒高手</a>》中，我们讲了国际上病毒的命名规则：</span></font></b></p><p data-pm-slice="4 2 []" style="text-align: center;"><b><font face="Tahoma"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">[前缀]：类型（行为）</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: Tahoma;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">.平台.名称.[变种]</span></span></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e&amp;scene=21#wechat_redirect" textvalue="教你如何看懂杀毒软件病毒报告！" data-itemshowtype="0" linktype="text" data-linktype="2">教你如何看懂杀毒软件病毒报告！</a>》中，我们讲了前缀的含义。</span></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485638&amp;idx=1&amp;sn=4a0f0cdff5e8473525cdcd903246ee23&amp;scene=21#wechat_redirect" textvalue="教你如何看懂反病毒软件报告（二）" data-itemshowtype="0" linktype="text" data-linktype="2">教你如何看懂反病毒软件报告（二）</a>》中，我们讲了类型中病毒和蠕虫的命名方式。</span></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">今天，我们接着讲木马。</span></font></b></p><p data-pm-slice="4 2 []"><b><font face="Tahoma"></font></b></p><p data-pm-slice="4 2 []" style="text-align: center;"><b><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">【二、木马】</span></span></font></b><font face="Tahoma"></font></p><p data-pm-slice="3 3 []" style="text-indent: 2em;"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">木马程序</span>是指</span><span leaf="">执行未经用户授权操作的恶意程序：它们删除、阻塞、修改或复制数据，并且破坏计算机或计算机网络的性能，或者利用被害计算机的能力进行恶意或犯罪的目的，比如攻击他人、发送垃圾邮件等。</span></font></p><p data-pm-slice="3 3 []" style="text-indent: 2em;"><font face="Tahoma"><span leaf="">木马与传统的远程管理软件（RMM）从本质上来讲，性质是差不多的，都是可以远程控制对方的电脑，不同的是一个是经过授权的，一个是未经授权的。</span></font></p><p data-pm-slice="3 3 []" style="text-indent: 2em;"><font face="Tahoma"><span leaf="">与病毒和蠕虫不同，属于此类的威胁不能产生自身的副本或执行自我复制的动作。 木马程序根据它们在受感染的计算机上执行的操作类型进行分类。</span></font></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">卡巴将木马按照其主要行为特征分为如下类型</span></font><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">——</span></font><font face="Tahoma"></font></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">1、Backdoor后门木马</span></span><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">。</span></span></font></p><p data-pm-slice="3 2 []" style="text-indent: 2em;"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">这是最危险的木马病毒类型之一。后门程序能让木马作者或操控者远程控制受害者的计算机。与合法远程管理工具不同，这类程序会在用户不知情的情况下悄然安装、启动并运行。一旦植入，后门就能被编程执行发送、接收、执行和删除文件等操作，还能窃取机密数据、记录系统活动日志等等。如：</span></font></p><p data-pm-slice="3 2 []" style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">BackDoor.Win32.xxx</span></p><p data-pm-slice="3 2 []" style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">BackDoor.WinCE.xxx</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">2、Exploit</span></span></p><p style="text-indent: 2em;"><span leaf="">漏洞利用程序是包含数据或可执行代码的程序，其明显出于恶意目的，利用本地或远程计算机上运行的软件的一个或多个漏洞。 恶意用户经常利用漏洞攻击来侵入受害者的计算机，以便随后安装恶意代码（例如，使受感染网站的所有访问者都受到恶意程序的感染）。此外，Net-Worms通常使用漏洞攻击来黑进受害者的计算机，而无需用户采取任何行动。 Nuker程序是值得注意的漏洞之一；此类程序向本地或远程计算机发送精心设计的请求，导致系统崩溃。</span></p><p><span leaf="">Exploit.HTML.xxx ：在HTML网页中利用IE漏洞的工具</span></p><p><span leaf="">Exploit.IFrame.xxx ：利用IE的IFrame漏洞的攻击器</span></p><p><span leaf="">Exploit.IIS.xxx ：利用IIS漏洞的攻击器</span></p><p><span leaf="">Exploit.JS.xxx ：JavaScript写的漏洞利用器</span></p><p><span leaf="">Exploit.Linux.xxx ：Linux系统的漏洞利用器</span></p><p><span leaf="">Exploit.Win32.xxx ：Win32程序的漏洞利用器</span></p><p><span leaf="">Exploit.HTML.xxx ：在HTML网页中利用IE漏洞的工具</span></p><p><span leaf="">Exploit.IFrame.xxx ：利用IE的IFrame漏洞的攻击器</span></p><p><span leaf="">Exploit.IIS.xxx ：利用IIS漏洞的攻击器</span></p><p><span leaf="">Exploit.JS.xxx ：JavaScript写的漏洞利用器</span></p><p><span leaf="">Exploit.Linux.xxx ：Linux系统的漏洞利用器</span></p><p><span leaf="">Exploit.Win32.xxx ：Win32程序的漏洞利用器</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">3、Rootkit</span></span></p><p data-pm-slice="2 1 []"><span leaf="">Rootkit——用来隐藏系统中某些对象或活动的软件工具的程序或集合。一般来说，网络犯罪分子会隐藏恶意对象自动运行的注册表项，以及受感染计算机内存中的文件、文件夹、进程和恶意网络活动。它们可以阻碍文件或注册表项的删除。</span></p><p><span leaf="">该技术本身不会对计算机造成直接伤害。在绝大多数情况下，它们与其他恶意软件一起使用，以防止检测和最大限度地在受害者电脑上的停留时间。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001992" class="rich_pages wxw-img" data-ratio="0.9461538461538461" data-s="300,640" data-type="png" data-w="260" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0cc4d059&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqTdY5TX441TDIoZ6l86L076WibQJkozaFRibticE4Vrhtmr8ODSq1TiaXTeqTuu9cKoXI0cHhFcJp49UA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">4、Trojan</span></p><p data-pm-slice="4 2 []" style="text-indent: 2em;"><span style="font-family: Arial;color: rgb(35, 38, 39);letter-spacing: 0pt;text-transform: none;font-style: normal;font-size: 12pt;background: rgb(255, 255, 255);"><font face="Arial"><span leaf="">木马程序是具有恶意的软件，会执行未经用户授权的操作：删除、拦截、篡改或复制数据，并破坏计算机或网络系统的正常运行。与病毒和蠕虫不同，这类威胁无法自我复制或自我传播。最早出现于</span></font><span leaf="">20世纪80年代末的木马程序，最初伪装成无害程序。当用户误以为这是正常程序并运行时，木马便会植入其恶意代码。在个人电脑恶意软件的早期阶段，由于开发者必须手动分发木马，这类程序相对少见。</span></span></p><p><b><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-AOL.Win32.xxx ：AOL木马，一般表现为偷AOL密码</span></b><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.BAT.xxx ：BAT脚本写的木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.DOS.xxx ：DOS可执行程序木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.JS.xxx ：JavaScript脚本木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.MSWord.xxx ：MS Word宏木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.SymbOS.xxx ：Symbian OS系统上的木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.VBS.xxx ：VBS脚本写的木马</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan.Win32.xxx ：一般的Win32程序木马</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">5、Trojan-ArcBomb 压缩包炸弹</span></span></p><p style="text-indent: 2em;"><span leaf="">“ArcBomb” 是单词 “archive” 和 “bomb.”的组合。</span></p><p style="text-indent: 2em;"><span leaf="">这类特洛伊木马程序设计的目的是冻结或降低系统性能，或在解压存档数据时用大量“空数据”淹没磁盘。当使用自动化处理系统处理传入数据时，所谓的“归档炸弹”对文件和邮件服务器构成特殊威胁——这种恶意程序可能直接导致服务器崩溃。</span></p><p style="text-indent: 2em;"><span leaf="">这种类型的木马使用三种类型的“炸弹”：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">制作不当的存档头：在处理归档内容时，错误的归档头或归档中损坏的数据可能导致特定的封隔器或解包算法崩溃。</span></p></li><li><p><span leaf="">重复[循环]数据：包含重复数据的大尺寸文件使得可以将文件打包到一个小的归档中（例如，5GB的数据可以打包到一个200KB的RAR或一个480KB的ZIP归档中）。</span></p></li><li><p><span leaf="">存档中相同的文件：当使用特殊方法打包大量相同的文件时，它们对归档的大小影响很小（例如，有方法将10100个相同的文件打包到30KB的RAR或230KB的ZIP归档中）。</span></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">6、Trojan-Banker</span></span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">该类恶意程序程序旨在窃取与网上银行系统、电子支付系统和信用卡系统有关的用户账户数据。然后，该数据被传输给控制该木马的恶意用户。可以使用电子邮件、FTP、网络（包括请求中的数据）或其他方法来传输被盗的数据。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">7、Trojan-Clicker</span></span></p><p style="text-indent: 2em;" data-pm-slice="2 2 []"><span leaf="">木马点击器是广告欺诈的一种形式。它反复连接到一个特定的广告支持的网页，授予网站所有者按点击付费广告的收入。</span></p><p style="text-indent: 2em;"><span leaf="">它们被网络罪犯用于：</span></p><ol style="list-style-type: lower-alpha;" class="list-paddingleft-1"><li><p style="text-indent: 0px;"><span leaf="">增加访问数量以增加广告收入。</span></p></li><li><p style="text-indent: 0px;"><span leaf="">引诱潜在的受害者下载病毒或木马。</span></p></li><li><p style="text-indent: 0px;"><span leaf="">从广告网络中虚假增加点击量中获利。</span></p></li></ol><p><span leaf="">Trojan-Clicker.Win32.xxx ：木马体为Win32 PE程序</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">8、Trojan-DDoS</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">这种类型的恶意程序用于对预定义地址的计算机进行DoS攻击。</span></p><p style="text-indent: 2em;"><span leaf="">本质上，DoS攻击涉及向受害者机器发送大量请求；如果受到攻击的计算机没有足够的资源来处理所有传入的请求，这就会导致拒绝服务。</span></p><p style="text-indent: 2em;"><span leaf="">为了成功地进行DoS攻击，恶意用户通常会提前用这种类型的木马感染许多计算机（例如，作为大量垃圾邮件的一部分）。因此，所有受感染的计算机都会攻击受害者的机器。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">9、Trojan-Downloader</span></span></p><p style="text-indent: 2em;" data-pm-slice="2 1 []"><span leaf="">该类程序用于下载并安装恶意程序到受害者的计算机上，包括木马和广告软件等。一旦从互联网上下载，这些程序就会被启动或包含在一个程序列表中，这些程序将在操作系统启动时自动运行。有关被下载的程序的名称和位置的信息在木马代码中，或由木马从一个互联网资源（通常是一个网页）下载。</span></p><p style="text-indent: 2em;"><span leaf="">这种类型的恶意程序经常用于访问者对包含漏洞的网站的初始感染。网页挂马挂的一般都是此类木马。</span></p><p><span leaf="">Trojan-Downloader.Js.xxx ：JavaScript写的木马下载器</span></p><p><span leaf="">Trojan-Downloader.VBS.xxx ：VbScript写的木马下载器</span></p><p><span leaf="">Trojan-Downloader.Win32.xxx ：本身是Win32 PE的木马下载器</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001991" class="rich_pages wxw-img" data-ratio="0.35626535626535627" data-s="300,640" data-type="png" data-w="407" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=312c06cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqTdY5TX441TDIoZ6l86L076ibe5nInC1TicexU5ibibyBuopxBx8YouRGibNuAzwtTp2KBHM3E5WRBwUjw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">10、Trojan-Dropper</span></span></p><p style="text-indent: 2em;" data-pm-slice="2 2 []"><span leaf="">这种类型的恶意程序通常会将一系列文件保存到受害者的驱动器中（通常保存到Windows目录、Windows系统目录、临时目录等），并在没有任何通知（或有存档错误、操作系统版本过时的虚假通知等）的情况下启动它们。类似于木马下载器，不同的是木马下载器需要联网下载额外的恶意软件。而Dropper中则包含恶意安装代码。</span></p><p style="text-indent: 2em;"><span leaf="">这些程序被黑客用于：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">秘密安装木马程序或病毒</span></p></li><li><p><span leaf="">保护已知的恶意程序不被防病毒解决方案检测到；并不是所有的防病毒程序都能够扫描这类木马中的所有组件。</span></p></li></ul><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Dropper.Ichitaro.xxx ：木马本身是一个Ichitaro文件（JTD），Ichitaro是日本最流行的文本编辑器</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Dropper.MSWord.xxx ：木马本身是一个Word宏，被包含在一个Word文档中</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Dropper.JS.xxx ：JavaScript写的木马释放器</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Dropper.VBS.xxx ：VbScript写的木马释放器</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Dropper.Win32.xxx ：本身是Win32 PE程序的木马释放器</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">11、Trojan-FakeAV</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">微软定义为：Rogue security software流氓安全软件</span></p><p style="text-indent: 2em;"><span leaf="">一类模拟杀毒软件或部分操作系统安全模块的活动的恶意程序。这些程序旨在向用户勒索金钱，以换取所谓的检测和消除威胁，而这些威胁实际上是不存在的。一般来说，这个恶意软件显示了许多重复的弹出窗口，试图让用户担心他们的系统的安全，并为假的AV软件付费。此外，Trojan-FakeAV程序可以阻止计算机正常工作，但并不能完全抑制操作系统，以使用户相信该威胁是可信的。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">12、Trojan-GameThief</span></span></p><p style="text-indent: 2em;"><span leaf="">这种类型的恶意程序旨在窃取在线游戏的用户账户信息。然后，这些数据将被传输给控制该木马的恶意用户。可以使用电子邮件、FTP、网络（包括请求中的数据）或其他方法来传输被盗的数据。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">13、Trojan-IM</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">一种恶意程序，旨在窃取即时通信软件中的用户帐户凭证，如Facebook Messenger、Skype和 Telegram。从受感染的计算机中检索到的信息将被发送给网络罪犯。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">14、Trojan-Mailfinder</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">这种类型的恶意程序被设计为从计算机中获取电子邮件地址，然后通过电子邮件、web、FTP或其他方法将它们发送给恶意用户。被盗的地址就会被网络罪犯用来大量发送恶意软件和垃圾邮件。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">15、Trojan-Notifier</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">一种向网络犯罪分子发出受感染设备与网络连接的信号的恶意程序。该消息包含有关计算机或智能手机及其所有者的信息，例如，IP地址、打开的端口号和电子邮件。信号可以通过电子邮件、网络罪犯网站上的特殊电话或即时消息发送。</span></p><p style="text-indent: 2em;"><span leaf="">此类程序在多组件特洛伊木马中用于通知攻击者在目标系统中成功安装恶意程序。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">16、Trojan-Proxy</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">木马代理程序的设计目的是让恶意用户通过受害者的计算机访问各种互联网资源。这些恶意程序通常用于发送大量的垃圾邮件。</span></p><p style="text-indent: 2em;"><span leaf="">Trojan-Proxy.Win32.xxx ：目前只有这一类，木马都是Win32 PE程序</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">17、Trojan-PSW</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">Trojan-PSW程序旨在从受感染的计算机上窃取用户的账户信息，如登录名和密码。PSW是偷密码软件（Password Stealing Ware）的首字母缩写。</span></p><p style="text-indent: 2em;"><span leaf="">当启动时，PSW木马会搜索存储一系列机密数据或注册表的系统文件。如果发现这样的数据，木马将其发送到它的“控制端”。可以使用电子邮件、FTP、网络（包括请求中的数据）或其他方法来传输被盗的数据。</span></p><p style="text-indent: 2em;"><span leaf="">一些这样的木马程序还窃取了某些软件程序的注册信息。</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-PSW.Win32.xxx ：体为Win32 PE程序</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-PSW.VBS.xxx ：VbScript写的偷密码木马</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">18、Trojan-Ransom</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">这种类型的木马会修改受害者计算机上的数据，从而使受害者不能再使用这些数据，或者它会阻止计算机正确运行。一旦数据被“劫持为人质”（被屏蔽或加密），用户将会收到赎金要求。</span></p><p style="text-indent: 2em;"><span leaf="">这种类型的木马会修改受害者计算机上的数据，从而使受害者不能再使用这些数据，或者它会阻止计算机正确运行。一旦数据被“劫持为人质”（被屏蔽或加密），用户将会收到赎金要求。</span></p><p style="text-indent: 2em;"><span leaf="">赎金要求告诉受害者发送恶意用户的金钱；收到这些信息后，网络罪犯将向受害者发送一个程序来恢复数据或恢复计算机的性能。</span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2">如果你被勒索病毒勒索了……</a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485596&amp;idx=1&amp;sn=c9a3b93348577cf5f9ebb011bf8a02ec&amp;scene=21#wechat_redirect" textvalue="勒索软件 — 定义、预防和删除" data-itemshowtype="0" linktype="text" data-linktype="2">勒索软件 — 定义、预防和删除</a></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">19、Trojan-SMS</span></span></p><p data-pm-slice="2 4 []" style="text-indent: 2em;"><span leaf="">短信木马攻击移动设备的消息传递服务，拦截短信。他们还可以向高级费率的短信号码发送短信。卡巴斯基实验室在2010年4月检测到了第一个安卓短信木马。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-SMS.J2ME.xxx ：Java平台手机短消息木马</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-SMS.SymbOS.xxx ：SymbOS平台手机短消息木马</span></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">20、Trojan-Spy</span></span></p><p data-pm-slice="2 4 []" style="text-indent: 2em;"><span leaf="">木马间谍程序用于监视用户的行为（跟踪通过键盘输入的数据，制作屏幕截图，检索正在运行的应用程序列表等）。然后，收集到的信息被传输给控制该木马的恶意用户。可以使用电子邮件、FTP、web（包括请求中的数据）和其他方法来传输数据。</span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Spy.HTML.xxx ：一类利用IE的框架欺骗漏洞（MS04-004）的间谍木马</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Spy.Linux.xxx ：Linux系统的间谍木马</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Spy.Win32.xxx ：Win32 PE程序的间谍木马</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Trojan-Spy.SymbOS.xxx ：SymbOS系统的间谍木马</span></p></li></ul><p><font face="Tahoma"></font></p><p><span leaf="">木马部分介绍完了，下一篇继续，敬请关注</span></p><p><font face="Tahoma"></font></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">敲字不易，如需转载文章：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">1、请先在大兵说安全的公众号后台留言，注明转载的【文章题目】以及转载的平台【您的公众号ID】，我会给您添加白名单授权。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">2、转载公众号文章请在文首备注以下信息：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">公众号：大兵说安全（ID：dabingshuoanquan)</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">作者：大兵</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">历史文章查看：</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e&amp;scene=21#wechat_redirect" textvalue="教你如何看懂杀毒软件病毒报告！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">教你如何看懂杀毒软件病毒报告！</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如果你被勒索病毒勒索了……</span></a></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485596&amp;idx=1&amp;sn=c9a3b93348577cf5f9ebb011bf8a02ec&amp;scene=21#wechat_redirect" textvalue="勒索软件 — 定义、预防和删除" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">勒索软件 — 定义、预防和删除</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">畅X通T+客户注意：又一个客户被加密勒索</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485046&amp;idx=1&amp;sn=bdd35742a878ef193e64143fea4c9d8f&amp;scene=21#wechat_redirect" textvalue="如何测试和选择一款适合的杀毒软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何测试和选择一款适合的杀毒软件</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485008&amp;idx=1&amp;sn=cbf94d2ee7838f5381a1052caef76b1c&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485016&amp;idx=1&amp;sn=1362d2886c2302c8e817e6e99f318789&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范（续）" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范（续）</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484997&amp;idx=1&amp;sn=7401f5b83f80b6fb2633a556cdbcf5e4&amp;scene=21#wechat_redirect" textvalue="从勒索病毒看医院网络安全体系建设" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从勒索病毒看医院网络安全体系建设</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484965&amp;idx=1&amp;sn=4d28dea19edf95387e9c6f594696f7f7&amp;scene=21#wechat_redirect" textvalue="如何构建安全体系防范勒索病毒" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何构建安全体系防范勒索病毒</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484958&amp;idx=1&amp;sn=389445cb6dd330a90d8ee5652d43c526&amp;scene=21#wechat_redirect" textvalue="原来，这才是网络安全中最重要的……" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">原来，这才是网络安全中最重要的……</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484889&amp;idx=1&amp;sn=f325e1a3fdbb5dd6988b88d6fd9cdf2d&amp;scene=21#wechat_redirect" textvalue="其实，预防勒索病毒没那么复杂！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">其实，预防勒索病毒没那么复杂！</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484686&amp;idx=1&amp;sn=66935926172b7f89c7f43abcdacaa769&amp;scene=21#wechat_redirect" textvalue="这一步做好，能减少一半被勒索的机会" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">这一步做好，能减少一半被勒索的机会</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484280&amp;idx=1&amp;sn=04ed1bdf6e1ab53526580d9b4e83997d&amp;scene=21#wechat_redirect" textvalue="又双叒叕一家单位被勒索了！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">又双叒叕一家单位被勒索了！</span></a></span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p><font face="Tahoma"></font></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485688">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0655f64a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485688%26idx%3D1%26sn%3D2c8066f311656a7ed35b411f91fa4953">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Nov 2025 23:09:00 +0800</pubDate>
    </item>
    <item>
      <title>新版《网络安全法》来了，看看变动在哪</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485684&amp;idx=1&amp;sn=b225f54ba99c68ca2e4b9ff8c5283c79</link>
      <description>新修订的《中华人民共和国网络安全法》于2025年10月28号经第十四届全国人民代表大会常务委员会第十八次会议通过。对比老版的，看看区别在哪？</description>
      <content:encoded><![CDATA[<p>
<span>大兵说安全</span> <span>2025-10-29 16:48</span> <span style="display: inline-block;">河南</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5fd1b4ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cgQYgibUKAJnC8FMkOAgcc7Pj2ArCeuH8T8hunibyYGDMfGya5FiaicuwDA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>新修订的《中华人民共和国网络安全法》于2025年10月28号经第十四届全国人民代表大会常务委员会第十八次会议通过。对比老版的，看看区别在哪？</p>

<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002030" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1" data-s="300,640" data-type="jpeg" data-w="800" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=988f68c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9ce208iaVPCPLShMibFmic7DyTOxdON3QTLcEFc50w2EBKqSV4LWo2ic2Yzw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 17px;"> 新修订的《中华人民共和国网络安全法》于2025年10月28号经第十四届全国人民代表大会常务委员会第十八次会议通过。新版的网络安全法共七章81条，较老版的七章79条增加了两条，现将详细对比列示如下：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">绿色为新增，黄色为修改，红色为删除</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;">第一章  总则</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">2016版第一章共14条，新版增加了第三条：</span></span></p><p><span style="color:rgb(0, 0, 0);font-family:等线;font-size:14.72px;font-style:normal;font-variant-ligatures:none;font-variant-caps:normal;font-weight:400;letter-spacing:0.578px;orphans:2;text-align:justify;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:break-spaces;background-color:rgb(255, 255, 255);text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">第三条  网络安全工作坚持中国共产党的领导，贯彻总体国家安全观，统筹发展和安全，推进网络强国建设。</span></span></span></p><p><span style="color:rgb(0, 0, 0);font-family:等线;font-size:14.72px;font-style:normal;font-variant-ligatures:none;font-variant-caps:normal;font-weight:400;letter-spacing:0.578px;orphans:2;text-align:justify;text-indent:0px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:break-spaces;background-color:rgb(255, 255, 255);text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">突出了党的网络安全的领导地位，将网络安全纳入国家安全的一部分。</span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;">第二章 网络安全支持与促进</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">将原来的第18条：</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:12pt;font-family:&#39;宋体&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">国家鼓励开发网络数据安全保护和利用技术，促进公共数据资源开放，推动技术创新和经济社会发展。</span></span></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:12pt;font-family:&#39;宋体&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">国家支持创新网络安全管理方式，运用</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">网络</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">新技术，提升网络安全保护水平。</span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:12pt;font-family:&#39;宋体&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;">调整为第十九条，将原来18第第二款调整为第二十条，并将其中的运用网络新技术，修改为运用人工智能等新技术，同时将增加了关于人工智能的内容：</span></span></span></p><p style="margin-right: 14.15pt;margin-left: 1.15pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">十九</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">国家鼓励开发网络数据安全保护和利用技术，促进公共数据资源开放，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">推动技术创新和经济社会发展。</span></span></font></span></p><p style="margin-right: 2.95pt;margin-left: 1.4pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">二十</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">国家支持人工智能基础理论研究和算法等关键技术研发，推进训</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">练数据</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">资源、算力等基础设施建设，完善人工智能伦</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">理规范，加强风险监测评估和安全监管，促进人工智能应用和健康发展。</span></span></font></span></p><p style="margin-right: 9.05pt;margin-left: 1.25pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">国家支持创新网络安全管理方式，运用</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">人工智能等</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">新技术，提升网络安全保护水</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.5000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">平。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002021" class="rich_pages wxw-img" data-ratio="0.18888888888888888" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d9348b81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cetplVNbrnDV64RdmFKRX6Wv1UqunyjVQvCcPJsLmu6ZweteRicdTaicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-size: 24px;">第四章  网络信息安全</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">原文第四十条：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第四十条  网络运营者应当对共收集的用户信息严格保密，并建立健全用户信息保护制度。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第四十二条，并</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">增加了对于个人信息的法律依据，尤其是是2023年通过的《中华人民共和国个人信息保护法》</span></span><span leaf=""><span textstyle="" style="font-size: 17px;">：</span></span></p><p style="margin-right: 10.85pt;margin-left: 1.35pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">四十二</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者应当对其收集的用户信息严格保密，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">并建立健全用户信息保</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.4000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">护制度。</span></span></font></span></p><p style="margin-right: 9.05pt;margin-left: 1.95pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.3500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">网络运营者处理个人信息，应当遵守本法和《中华人民共和国民法典》、《中华人 </span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">民共和国个人信息保护法》等法律、行政法规的规定。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002022" class="rich_pages wxw-img" data-ratio="0.14074074074074075" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ee41b38d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cfL0EhoI9oSMsbkP0xUibNHBicF7XQGgic1W8s6cTFfUXc15GLoiawBbGNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-size: 24px;">第六章  法律责任</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">这一章是本次法律修订最重要的部分。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">原第五十九条：</span></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:12pt;font-family:&#39;宋体&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者不履行本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">二十一</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">二十五</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条规定的网络安全保护义务的，由有关主管部门责令改正，给予警告；拒不改正或者导致危害网络安全等后果的，</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处一万元以上十万元以下</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚款，对直接负责的主管人员</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处五千元以上五万元以下</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚款。</span></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:12pt;font-family:&#39;宋体&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关键信息基础设施的运营者不履行本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十三</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十四</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十六</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十八条</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">规定的网络安全保护义务的，由有关主管部门责令改正，给予警告；拒不改正或者导致危害网络安全等后果的，处十万元以上一百万元以下罚款，对直接负责的主管人员处一万元以上十万元以下罚款。</span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十一条，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">并增加了造成数据泄露和关基设施功能丧失等后果的处理措施。处罚口径与《数据安全法》保持了一致</span></span><span leaf=""><span textstyle="" style="font-size: 17px;">：</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十一</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者不履行本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">二十三</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">二十七</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">规定的网络安全保护义</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">务的，由有关主管部门责令改正，给予警告，</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">可以处一万元以上五</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">万元以下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">；拒</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">不改正或者导致危害网络安全等后果的，</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处五万元以上五十万元以</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">，对直接负</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">责的主管人员和其他直接责任人员</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处一万元以上十万元以下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">。</span></span></font></span></p><p style="margin-right: 8.95pt;margin-left: 1.2pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关键信息基础设施的运营者不履行本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十五</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十六</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十八</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条、</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">四十</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条规定的网络安全保护义务的，由有关主管部门责令改正，给予警告，</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">可以处</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">五万元以上十万元以下罚款；</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">拒不改正或者导致危害网络安</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">全等后果的，处十万元以</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">上一百万元以下罚款，对直接负责的主管人员和其他直接责</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">任人员处一万元以上十万</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.2000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">元以下罚款。</span></span></font></span></p><p style="margin-right: 8.95pt;margin-left: 1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">有前两款行为，造成大量数据泄露、关键信息基</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">础设施丧失局部功能等严重危害</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">网络安全后果的，由有关主管部门处五十万元以上二百万元以下罚款</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">，对直接负责的</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">主管人员和其他直接责任人员处五万元以上二十万元以下罚款；造成</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">关键信息基础设</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">施丧失主要功能等特别严重危害网络安全后果的，处二百万元以</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">上一千万元以下罚款，对直接负责的主管人员和其他直接责任人员处二十万元以上一百万元以下罚款。</span></span></font></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="margin-right: 8.95pt;margin-left: 1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><br/></span></font></span></p><p><span leaf=""><img data-imgfileid="100002023" class="rich_pages wxw-img" data-ratio="0.48055555555555557" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=738f0890&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cmbkhwyxAsSE2pEqV4uibTegfzqJgBWLia8OBEJQbJbCwzbSa6JcEibzHg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">原第六十条：</span></span></p><p style="margin-left: 1.2pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.2500pt;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.2500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">违反本法第二十二条第一款、第二款和第四十八条第一款规定，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:0.6500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">有下列行为之一的，由有关主管部门责令改正，给予警告；拒不改正或者导致危害网络安全等后果的，处五万元以上五十万元以下罚款，对直接负责的</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.2000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">主管人员</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">处一万元以上十万元以下罚款：</span></span></font></span></p><p style="margin-left: 1.2pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（一）设置恶意程序的；</span></span></font></span></p><p style="margin-right: 1.4pt;margin-left: 1.3pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（二）对其产品、服务存在的安全缺陷、漏洞</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">等风险未立即采取补救措施，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">或者未按照规定及时告知用户并向有关主管部门报告的；</span></span></font></span></p><p style="margin-right: 1.4pt;margin-left: 1.3pt;"><font face="Arial"><span leaf="" style="font-family: 宋体;color: rgb(0, 0, 0);letter-spacing: -0.1pt;font-size: 12pt;"><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（三）擅自终止为其产品、服务提供安全维护的。</span></span></font></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十二条，并增加了关于造成后果的处罚措施：</span></span></font></span></p><p style="margin-right: 8.95pt;margin-left: 1.2pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十二</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条   </span></span></font><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">违反本法第二十二条第一款、第二款和第四十八条第一款规定，有下列</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">行为之一的，由有关主管部门责令改正，给予警告；拒不改</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">正或者导致危害网络安全</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">等后果的，处五万元以上五十万元以下罚款，对直接负责的</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">主管人员处一万元以上十</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.3500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">万元以下罚款：</span></span></font></span></p><p style="margin-right: 8.95pt;margin-left: 1.2pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.3500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（一）设置恶意程序的；</span></span></font></span></p><p style="margin-right: 9.55pt;margin-left: 1.3pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（二）对其产品、服务存在的安全缺陷、漏洞等风险未立即采取补救措施，或者</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">未按照规定及时告知用户并向有关主管部门报告的；</span></span></font></span></p><p style="margin-right: 9.55pt;margin-left: 1.3pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（三）擅自终止为其产品、服务提供安全维护的。</span></span></font></span></p><p style="margin-right: 9.05pt;margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">有前款第一项、第二项行为，造成本法第六十一</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">条第三款规定的后果的，依照该</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.2000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">款规定处罚。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002024" class="rich_pages wxw-img" data-ratio="0.38981481481481484" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eb2e9ac2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cWiabiaHQYIwPcePMbCnfArRica00wvQiaSVJj3s5icseSZ2msxr84CezWTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 2.95pt;margin-left: 1.05pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.4500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;">新增第六十三条：</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;2 4 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">要求销售或提供的网络关键设备和网络安全专用产品必须有安全认证证书或安全检测合格。</span></span></font></span></p><p style="margin-right: 2.95pt;margin-left: 1.05pt;" data-pm-slice="4 4 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">六十三</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">条</span></span></font><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">违反本法第二十五条规定，销售或者提供未经安全认证、安全检</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">测或者</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">安全认证不合格、安全检测不符合要求的网络关键设备和网络安全</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">专用产品的，由有</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">关主管部门责令停止销售或者提供，给予警告，没收违法所得；没</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">有违法所得或者违</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">法所得不足十万元的，并处二万元以上十万元以下罚款；违法所得</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">十万元以上的，并</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">处违法所得一倍以上五倍以下罚款；情节严重的，并可以责令暂停相关业务、停业整</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">顿、吊销相关业务许可证或者吊销营业执照。法律、行政法规另有</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">规定的，依照其规</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.4500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">定。</span></span></font></span></p><p style="margin-right: 2.95pt;margin-left: 1.05pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.4500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"></font></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">原文第六十一条：</span></span></p><p data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;font-weight:bold;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十一条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法第二十四条第一款规定，未要求用户提</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">供真实身份信息，或者对不提供真实身份信息的用户提供相关服务的，由有关主</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1000pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">管部门责令改正；拒不改正或者情节严重的，处五万元以上五十万元以下罚款，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">并可以</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">由有关主管部门</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">责令暂停相关业务、停业整顿、关闭网站、吊销相关业务</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处一万元</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">以上十万元以下罚款。</span></span></font></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十四条，删除了“由有关主管部门”增加了“关闭应用程序”：</span></span></font></span></p><p style="margin-right: 10.85pt;margin-left: 0.9pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十四</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法第二十四条第一款规定，未</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">要求用户提供真实身份</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">信息，或者对不提供真实身份信息的用户提供相关服务的，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">由有关主管部门责令改</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">正；拒不改正或者情节严重的，处五万元以上五十万元以</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">下罚款，并可以责令暂停相</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关业务、停业整顿、关闭网站</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">或者应用程序</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款。</span></span></font></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"></font></span></p><p><span leaf=""><img data-imgfileid="100002025" class="rich_pages wxw-img" data-ratio="0.14444444444444443" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1dce7174&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cp3j1UDAKf0elTSW9yl9Fjg9e2xrBAmibOvUrRVxRmAXzuTaezrqqZVw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;">原第六十二条：</span></span></font></span></p><p style="margin-left: 1.1pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十二条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">违反本法第二十六条规定，开展网络安全认证、检测、风险</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">评估等活动，或者向社会发布系统漏洞、计算机病毒、网络攻击、网络侵入等网</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">络安全信息的，由有关主管部门责令改正，给予警告；拒不改正或者情节严重的，</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:0.5000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">处一万元以上十万元以下罚款，并可以</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">由有关主管部门</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">责令暂停相关业务、停业</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">整顿、关闭网站、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">员和其他直接责任人员处五千元以上五万元以下罚款。</span></span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十五条，修改了处罚金额，增加了处罚措施：</span></span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十五</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条  </span></span></font><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">违反本法第二十八条规定，开展网络安全认证、检测、风险评估等活动，或者向社会发布系统漏洞、计算机病毒、网络</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">攻击、网络侵入等网络安全信息的，由有关主管部门责令改正，给予警告，</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">可以处一万元以上十万元以下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">；拒不</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">改正或者情节严重的，</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处十万元以上一百万元以下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">，并可以责令暂停相关业务、</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">停业整顿、关闭网站</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">或者应用程序</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">、吊销相</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关业务许可证或者吊销营业执照，对直接</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">负责的主管人员和其他直接责任人员处</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">一万元以上十万</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">元以下</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚款。</span></span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">有前款行为，造成本法第六十一条第三款规定的</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">后果的，依照该款规定处罚。</span></span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002026" class="rich_pages wxw-img" data-ratio="0.14537037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4277befb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9c0pT5gr26a5k2VsyTmOysGxnIEgb6SaEWMAB58IzrY1iad843b6Bkf7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 3.15pt;margin-left: 1.15pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"></font></span></p><p style="margin-right: 2.9pt;margin-left: 1.1pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;">原文第六十五条：</span></span></font></span></b></p><p style="margin-right: 2.9pt;margin-left: 1.1pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十五条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关键信息基础设施的运营者违反本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十五</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条规定，使用</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">未经安全审查或者安全审查未通过的网络产品或者服务的，由有关主管部门责令</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">停止使用，处采购金额一倍以上十倍以下罚款；对直接负责的主管人员和其他直</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">接责任人员处一万元以上十万元以下罚款。</span></span></font></span></p><p data-pm-slice="2 4 []"><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十七条，增加了”消除对国家安全的影响“内容：</span></span></p><p style="margin-right: 8.95pt;margin-left: 0.95pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十七</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">关键信息基础设施的运营者违反本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">三十七</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条规定，使用未经安全审</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">查或者安全审查未通过的网络产品或者服务的，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">由有关主管部门责令限期改正、停止</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">使用、</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">消除对国家安全的影响</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">，处采购金额一倍以上十倍以下罚款，对</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">直接负责的主</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">管人员和其他直接责任人员处一万元以上十万元以下罚款。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002028" class="rich_pages wxw-img" data-ratio="0.10185185185185185" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=91fdcb84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cicjP7yfQ6KeARb2QiaIsD0tzK6gjEx0M13H9libIePcaUwTlJfWibfBKqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 2.9pt;margin-left: 1.25pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;">原文第六十八条：</span></span></font></span></p><p style="margin-left: 1.2pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十八条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法第四十七条规定，对法律、行政法规禁</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">止发布或者传输的信息未停止传输、采取消除等处置措施、保存有关记录的，由</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">有关主管部门责令改正，给予警告，</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">没收违法所得</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">；拒不改正或者情节严重的，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">处十万元以上五十万元以下罚款，并可以责令暂停相关业务、停业整顿、关闭网</span></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">站、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">责任人员处一万元以上十万元以下罚款。</span></span></font></span></p><p style="margin-left: 1.2pt;"><font face="Arial"><span leaf="" style="font-family: 宋体;color: rgb(0, 0, 0);letter-spacing: -0.15pt;font-size: 12pt;"><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">电子信息发送服务提供者、应用软件下载服务提供者，不履行本法第四十八</span></span></font><span leaf="" style="font-family: 宋体;color: rgb(0, 0, 0);letter-spacing: -0.15pt;font-size: 12pt;"><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条第二款规定的安全管理义务的，依照前款规定处罚。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第六十九条：</span></span></p><p style="margin-right: 10.85pt;margin-left: 1.15pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">六十九</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法第</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">四十九</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条规定，对法律、</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">行政法规禁止发布或者</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">传输的信息未停止传输、采取消除等处置措施、保存有关</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">记录</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">、向有关主管部门报</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">告，或者违反本法第五十二条规定，不按照有关部</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">门的要求对法律、行政法规禁止发</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">布或者传输的信息停止传输、采取消除等处置措施、保存有</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">关记录</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">的，由有关主管部</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">门责令改正，给予警告、</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">予以通报，可以处五万元以上五十</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">万元以下罚款</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">；拒不改正或者情节严重的，</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">处五十万元以上二百万元以下</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚款，并可以责令暂停相关业务、停业整顿、关闭网站</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">或者应用程序</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">、吊销相关业务许可证或者吊销营业执照，对直接负责的主管人员和其他直接责任人员</span><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">处五万元以上二十万元以下</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚款。</span></span></font></span></p><p style="margin-right: 10.85pt;margin-left: 1.15pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">有前款行为，造成特别严重影响、特别严重后果</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">的，由有关主管部门处二百万元</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">以上一千万元以下罚款，责令暂停相关业务、停业整顿、关闭</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">网站或者应用程序、吊</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">销相关业务许可证或者吊销营业执照，对直接负责的主管人员</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">和其他直接责任人员处</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">二十万元以上一百万元以下罚款。</span></span></font></span></p><p style="margin-right: 9.05pt;margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">电子信息发送服务提供者、应用软件下载服务提供者，不履行本法</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">第五十条</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第二</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">款规定的安全管理义务的，依照前两款规定处罚。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002035" data-ratio="0.41203703703703703" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c42e5e74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cDyhVNQlibRUuWZVhCtZ4OH3o8xFkY2cZ1v0X1o7Dxmy32f8SmE30AzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 9.05pt;margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"></font></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:11.04pt;font-family:&#39;等线&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;">原文第六十九条：</span></span></span></p><p style="margin-right: 1.6pt;margin-left: 1.25pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第六十九条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法规定，有下列行为之一的，由有关主管</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">部门责令改正；拒不改正或者情节严重的，处五万元以上五十万元以下罚款，对</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">直接负责的主管人员和其他直接责任人员，处</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">一万元以上十万元以下罚款：</span></span></font></span></p><p style="margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">（一）不按照有关部门的要求对法律、行政法</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">规禁止发布或者传输的信息，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: underline;">采取停止传输、消除等处置措施的；</span></span></font></span></p><p style="margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（二）拒绝、阻碍有关部门依法实施的监督检查的；</span></span></font></span></p><p style="margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（三）拒不向公安机关、国家安全机关提供技术支持和协助的。</span></span></font></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-size:11.04pt;font-family:&#39;等线&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第七十条，并将第一项合并入第71条：</span></span></span></p><p style="margin-right: 2.95pt;margin-left: 1.05pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">七十</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条</span></span></font><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">网络运营者违反本法规定，有下列行为之一的，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">由有关主管部门责令改</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">正；拒不改正或者情节严重的，处五万元以上五十万元以下罚款，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">对直接负责的主管</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">人员和其他直接责任人员，处一万元以上十万元以下罚款：</span></span></font></span></p><p style="margin-left: 24.8pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（一）拒绝、阻碍有关部门依法实施的监督检查的；</span></span></font></span></p><p style="margin-left: 24.8pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（二）拒不向公安机关、国家安全机关提供技术支持和协助</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">的。</span></span></font></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002034" data-ratio="0.2064814814814815" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=83c7a405&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cqUNzolFCmCialpY70y8c26N5wHVFvnOVnmpmdhLicWF9JS40eUgYMUIw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-left: 24.8pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"></font></span></p><p data-pm-slice="4 4 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;">原文第六十四条、第六十六条、第七十条，合并为新版第71条：</span></span></font></span></p><p style="margin-left: 1.1pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">第六十四条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">网络运营者、网络产品或者服务的提供者违反本法第二十二</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.4000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">条第三款、第四十一条至第四十三条规定，侵害个人信息依法得到保护的权利的，</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">由有关主管部门责令改正，可以根据情节单处或者并处警告、没收违法所得、处</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">违法所得一倍以上十倍以下罚款，没有违法所得的，处一百万元以下罚款，对直</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">接负责的主管人员和其他直接责任人员处一万元以上十万元以下罚款；情节严重</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">的，并可以责令暂停相关业务、停业整顿、关闭网站、吊销相关业务许可证或者</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">吊销营业执照。</span></span></font></span></p><p style="margin-right: 3.15pt;margin-left: 1.15pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">违反本法第四十四条规定，窃取或者以其他非法方式获取、非法出售或者非</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">法向他人提供个人信息，尚不构成犯罪的，由公安机关没收违法所得，并处违法</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">所得一倍以上十倍以下罚款，没有违法所得的</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">，处一百万元以下罚款。</span></span></font></span></p><p data-pm-slice="4 4 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">第六十六条</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">关键信息基础设施的运营者违反本法第三十七条规定，在境</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">外存储网络数据，或者向境外提供网络数据的，由有关主管部门责令改正，给予</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">警告，没收违法所得，处五万元以上五十万元以下罚款，并可以责令暂停相关业</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">务、停业整顿、关闭网站、吊销相关业务许可证或者吊销营业执照；对直接负责</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">的主管人员和其他直接责任人员处一万元以上十万元以下罚款。</span></span></font></span></p><p style="margin-right: 1.7pt;margin-left: 1.35pt;" data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">第七十条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.1500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">发布或者传输本法第十二条第二款和其他法律、行政法规禁止</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">发布或者传输的信息的，依照有关法律、行政法规的规定处罚。</span></span></font></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;">合并为新版第71条：</span></span></p><p style="margin-left: 23.2pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">七十一</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">条有下列行为之一的，依照有关法律、行</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">政法规的规定处理、处罚：</span></span></font></span></p><p style="margin-right: 9.65pt;margin-left: 1.1pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（一）发布或者传输本法第十三条第二款和其他法律、行政法规禁止发布或者传</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.3000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">输的信息的；</span></span></font></span></p><p style="margin-right: 9.5pt;margin-left: 1.2pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（二）违反本法第二十四条第三款、第四十三条至第四十五条规定，侵害个人信</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">息权益的；</span></span></font></span></p><p style="margin-right: 9.5pt;margin-left: 1.2pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">（三）违反本法第三十九条规定，关键信息基础设施的运营者在境外存储个人信</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">息和重要数据，或者向境外提供个人信息和重要</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.1000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">数据的。</span></span></font></span></p><p style="margin-right: 8.95pt;margin-left: 0.95pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">违反本法第四十六条规定，窃取或者以其他非法方</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">式获取、非法出售或者非法向</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">他人提供个人信息，尚不构成犯罪的，由公安机关依照有关法律、行政</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">法规的规定处</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:等线;color:rgb(0,0,0);letter-spacing:-0.4000pt;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="等线"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">罚。</span></span></font></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;">新增第73条：</span></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">第</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">七十三</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">条</span></span></font><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">违反本法规定，但具有《中华人民共和国行政处罚法》规定的从轻、减</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;color:rgb(0,0,0);letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-style: italic;text-decoration: underline;">轻或者不予处罚情形的，依照其规定从轻、减轻或者不予处罚。</span></span></font></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;">关于这一点，可参考9月15号发布的《国家网络安全事件报告管理办法》，里面也有从轻、减轻或者</span></span><span style="color: rgb(0, 0, 0);font-family: Arial;font-size: 14px;font-style: normal;font-variant-ligatures: none;font-variant-caps: normal;font-weight: 400;letter-spacing: -0.0666667px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: break-spaces;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 17px;">不予处罚的内容。</span></span></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-size:11.04pt;font-family:&#39;等线&#39;;color:rgb(0,0,0);"><span leaf=""><span textstyle="" style="font-size: 17px;">原文第七十五条：</span></span></span></p><p data-pm-slice="0 0 []"><b><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;font-weight:bold;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;">第七十五条</span></span></font></span></b><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;">境外的机构、组织、个人从事</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">攻击、侵入、干扰、破坏等</span><span textstyle="" style="font-size: 17px;font-style: italic;">危</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;">害中华人民共和国</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-style: italic;">的关键信息基础设施的活动</span><span textstyle="" style="font-size: 17px;font-style: italic;">，造成严重后果的</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">，依法追究法律</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.1500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;background-color: rgb(255, 172, 170);font-style: italic;text-decoration: line-through;">责任</span><span textstyle="" style="font-size: 17px;font-style: italic;">；国务院公安部门和有关部门并可以决定对该机构、组织、个人采取冻结财</span></span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Arial;mso-fareast-font-family:宋体;letter-spacing:-0.0500pt;font-size:10.5000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: italic;">产或者其他必要的制裁措施。</span></span></font></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">修改为第77条：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">第</span></span><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">七十七</span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">条 </span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">境外的机构、组织、个人从事危害</span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">中华人民共和国</span><span textstyle="" style="font-size: 17px;background-color: rgb(255, 251, 0);font-weight: normal;font-style: italic;text-decoration: underline;">网络安全的活动的</span><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">，</span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;background-color: rgb(115, 250, 121);font-weight: normal;font-style: italic;text-decoration: underline;">依法追究法律责任</span><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">；造成严重后果的，国务院公安部门和有关部门并可以</span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">决定对该机构、组织、个人采取冻结财产或者其他必要的制</span></span></font><font face="等线"><span leaf="" style="font-family: Arial;font-weight: bold;font-size: 10.5pt;"><span textstyle="" style="font-size: 17px;font-weight: normal;font-style: italic;text-decoration: underline;">裁措施。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002033" data-ratio="0.10185185185185185" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=599b8802&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ32UlqGHqRCQ42icR6XVR9cpqaoXupMNsqxTicLDZ8wJfw89EFtkTNqb5t1sls3ExrBmzWaIMy0Gkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><font face="等线"></font></p><p><font face="等线"></font></p><p><span leaf=""><span textstyle="" style="font-size: 24px;">第七章  附则</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">原文第79条：</span></span></p><p data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;">第七十九条</span></span></font></b><font face="宋体"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;">本法自</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;">2017</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;">年</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;">6</span></span><font face="宋体"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;">月</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;">1 日</span><span textstyle="" style="font-style: italic;">起施行。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">修改为：</span></span></p><p data-pm-slice="0 0 []"><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;text-decoration: underline;">第</span></span></font><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;text-decoration: underline;">八十一</span></span></font><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;text-decoration: underline;">条</span></span></font><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;text-decoration: underline;">本法自</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">2026 年</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">1</span></span><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">月</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">1</span></span><font face="等线"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-style: italic;text-decoration: underline;">日</span><span textstyle="" style="font-style: italic;text-decoration: underline;">起施行。</span></span></font></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485684">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=45df7c2a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485684%26idx%3D1%26sn%3Db225f54ba99c68ca2e4b9ff8c5283c79">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Oct 2025 16:48:00 +0800</pubDate>
    </item>
    <item>
      <title>我看《国家网络安全事件报告管理办法》</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485667&amp;idx=1&amp;sn=fb25ec2ebdf4843b74d8475630a6a8eb</link>
      <description>2025年9月15日，网络安全周的第一天，中央网信办和国家互联网信息办公室网站发布了《国家网络安全事件报告管理</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-09-21 08:00</span> <span style="display: inline-block;">河南</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2a222527&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877I4Hhzoa1VxNhrn8v6TI1rrdGI6jN9IOyzf30nZDz9zONfHCeahIWzJQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">2025年9月15日，网络安全周的第一天，中央网信办和</span><span leaf="">国家互联网信息办公室</span><span leaf="">网站发布了<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485654&amp;idx=1&amp;sn=e8659bc6a8fc8e77d5166a4b9367aff5&amp;scene=21#wechat_redirect" textvalue="《国家网络安全事件报告管理办法》" data-itemshowtype="0" linktype="text" data-linktype="2">《国家网络安全事件报告管理办法》</a>（以下简称《办法》），2025年11月1日正式执行。上周一直在忙着给不同单位培训，没顾上仔细看，今天周末，在家看了看这个《办法》，看完之后谈谈自己的一些看法。一家之言，欢迎各位同行探讨。</span></p><p style="text-indent: 2em;"><span leaf="">我在2018年1月29日，曾经写过一篇文章：《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484124&amp;idx=1&amp;sn=b89ebd7997462c1182f5556d78875d83&amp;scene=21#wechat_redirect" textvalue="不能说的秘密！" data-itemshowtype="0" linktype="text" data-linktype="2">不能说的秘密！</a>》，文章中就呼吁，建立网络安全事件报告的管理制度。明确界定安全事件披露、通报和案例分析制度，明确界定安全事件“披露”和“隐瞒”的相应责任，要让隐瞒的代价大于披露的代价，要建立安全事件收集和响应中心，指导受攻击单位进行应急处理。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100002008" class="rich_pages wxw-img" data-ratio="0.37484433374844334" data-s="300,640" data-type="png" data-w="803" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e37a9ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877IT2WZicOFvsr7sE4b0mzHj4UtElSXxqAndqicicY8TlCs8m40VXfUO32icA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">之所以有这个想法，是因为在平时遇到了太多的安全事件，国家在2017年出台了《网络安全法》，其中第二十一条明确了网络运营者有义务保护自己的网络，否则就要承担相应的法律责任（网络安全法第五十九条），这本身也没有问题，这些年，我们国家的网络安全有了长足的进步，《网络安全法》功不可没，让单位的领导意识到网络安全是一个法律问题，大大加快了网络安全建设。</span></p><p style="text-indent: 2em;"><span leaf="">但不得不承认的是，任何单位的网络都不可能做到百分百安全，即使按照等保三级要求做了建设，也不能避免安全事件的发生。而当单位上报安全事件之后，往往得不到什么有益的指导，只会得到一份冰冷的罚单，这也让一些单位出了事之后选择沉默。而这种沉默对于行业的发展来说并不是一件好事。</span></p><p style="text-indent: 2em;"><span leaf="">针对这个《办法》，我比较感兴趣的几点是：</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">一、《办法》明确规定了对采取了合理必要的防护措施的单位，出现安全事件后的减责或免责条款。</span></span></p><p style="text-indent: 2em;"><span leaf="">在新的《办法》第十一条，明确规定了：</span></p><p style="text-indent: 2em;"><strong style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">第十一条</span></span></strong><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;"> 发生网络安全事件时，网络运营者已采取合理必要的防护措施，按照应急预案进行处置、有效降低网络安全事件影响和危害，并按照本办法规定及时报告的，可视情从轻或不予追究相关单位和人员责任。</span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">同时，也规定了如果隐瞒不报所应当承担的责任：</span></span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;" data-pm-slice="0 0 []"><strong><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">第十条</span></span></strong><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;"> 网络运营者未按照本办法规定报告网络安全事件的，有关主管部门按照有关法律、行政法规的规定进行处罚。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">因网络运营者迟报、漏报、谎报或者瞒报网络安全事件，造成重大危害后果的，对网络运营者及有关责任人依法从重处罚。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">承担网络安全事件报告的部门未按照本办法规定报告网络安全事件的，依据有关法律、行政法规和网络安全工作责任制追究相关单位和人员责任。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">这无疑是给那些按规定做了安全防护措施的单位减了压，毕竟网络安全事件是不可能避免的，不能出了事就怪单位没有尽到义务，这对受害单位以及他们的安全管理员来说无疑是不公平的。当然，如果你真的没有尽到保护义务，那该有责任还是要承担的。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;font-style: normal;text-decoration: none;">这就是在鼓励大家出现问题及时上报，不要再藏着掖着了。而且你不报的代价要大于你上报的代价。这样一家单位受到攻击，监管单位就可以快速分析通知其他单位，起到共同免疫的效果。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;font-style: normal;text-decoration: none;">二、《办法》中明确了安全事件标准，并分为了特别重大、重大、较大和一般四级，并明确特别重大和重大安全事件上报的时间和主管单位。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">第四条 网络运营者在发现或获知涉及本单位的网络安全事件时，应当按照《网络安全事件分级指南》（见附件）进行研判，属于较大以上网络安全事件的，按以下程序报告：</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">涉及关键信息基础设施的，网络运营者应当第一时间向保护工作部门、公安机关报告，最迟不得超过1小时。属于重大、特别重大网络安全事件的，保护工作部门在收到报告后，应当第一时间向国家网信部门、国务院公安部门报告，最迟不得超过半小时。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">网络运营者属于中央和国家机关各部门及其直属单位的，应当及时向本部门网信工作机构报告，最迟不得超过2小时。属于重大、特别重大网络安全事件的，各部门网信工作机构在收到报告后，应当第一时间向国家网信部门报告，最迟不得超过1小时。国家网信部门收到报告后及时向有关部门通报。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">其他网络运营者应当及时向属地省级网信部门报告，最迟不得超过4小时。属于重大、特别重大网络安全事件的，省级网信部门在收到报告后，应当第一时间向国家网信部门报告，最迟不得超过1小时，并同时向同级有关部门通报。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">本行业领域有专门规定的，网络运营者还应当按照行业主管监管部门要求报告。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;font-style: italic;text-decoration: underline;">涉嫌违法犯罪的，网络运营者应当及时向公安机关报案。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;">这对单位和运维团队的安全响应提出了较高的要求。我相信目前大多数单位是没有这个能力的。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;">首先有没有工具（如EDR\NDR\XDR等）可以快速检测到攻击事件？</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;">其次，安全人员有没有能力去响应和分析事件？</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;">第三，有没有预案？有没有日常的响应团队和组织？上报的时候不是只报告出事了就完了，是有具体的要求的。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">下一步，各单位的重点是不是应该往应急响应团队建设和能力提升上来了？</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;font-style: normal;text-decoration: none;">三、这个是我比较关注的点，是第七条：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">第七条 报告网络安全事件时，应当包括下列内容：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（一）涉事单位名称及涉事系统或设施基本情况；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（二）网络安全事件发现或发生的时间、地点、类型、级别，以及已造成的影响和危害，已采取的措施及效果；对勒索软件攻击事件，还应当包括要求支付赎金的金额、方式、日期等；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（三）事态发展趋势及可能造成的进一步影响和危害；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（四）网络安全事件原因初步分析意见；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;font-style: italic;text-decoration: underline;">（五）溯源调查工作线索，包括但不限于可能的攻击者信息、攻击路径、存在的漏洞等；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（六）拟进一步采取的应对措施以及请求支援事项；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（七）网络安全事件现场保护情况；</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">（八）其他应当报告的情况。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">对于规定时间内不能判定事发原因、影响或发展趋势等网络安全事件情况的，可先报告第一项、第二项内容，其他情况及时补报。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">网络安全事件报告后出现新的重要情况或调查工作取得阶段性进展的，涉事单位应当及时报告。</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">同时，第五条还规定了：</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: italic;text-decoration: underline;">第五条</span></span></strong><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf=""><span textstyle="" style="font-style: italic;text-decoration: underline;"> 网络运营者应当以合同等形式要求为其提供网络安全、系统运维等服务的组织或个人，及时向其报告监测发现的网络安全事件，并协助其按照本办法规定报告网络安全事件。</span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">这就对网络运营者和运维人员提出了新的要求，如何检测威胁，查找攻击者信息，找到攻击者路径，分析出攻击者的动作和失陷指标(IOC），也会逼着网络运营者和运维团队去提升人员的安全能力，从防范攻击向检测和响应攻击转变。领导者的要求不能再是简单的不出事，而出事后如何应对的问题。这其实也跟我昨天在一个CIO会议上讲的韧性安全是一样的理念，不再强调不能出事，而是出事后如何应对。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002011" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=87ae1e7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877IgPicsMJ4yJr4O89wGuEWrxxgskCH4RYOG2eKYWCxsvb1GvZfHib74luQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0px;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100002009" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=51d6fe8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877IDrGdQpoLpkevJVbRGlLT39SKic2F2xPjF0ejvSvTITVWFERrniaxu29Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002012" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1222dbe6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877IViaicVibQgvpkIfGZFzbEniaEOrzUriauP79LRicM2PtZn4MGSliaiaJiatHsJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002016" data-ratio="0.7308868501529052" data-s="300,640" type="block" data-type="png" data-w="981" src="https://wechat2rss.xlab.app/img-proxy/?k=6575eeb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877In4reawqkzyEYicKUJOxykdsEhk1c92WU7yaNFY7zDBvic40t830846yQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;" data-pm-slice="3 5 []"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">第十一条明确规定：”</span><span textstyle="" style="font-size: 17px;font-weight: bold;font-style: italic;text-decoration: underline;">网络运营者已采取合理必要的防护措施，按照应急预案进行处置、有效降低网络安全事件影响和危害</span><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">，“并且按本《办法》及时上报的，才可以</span></span><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;font-style: italic;text-decoration: underline;">从轻或不予追究相关单位和人员责任。</span></span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">那么，你单位有没有采取合理必要的防护措施？</span></span><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">单位有没有应急响应预案？有没有应急团队和组织？有没有检测攻击和响应能力？有没有事件溯源和取证能力？</span></span></span></span></span></p><p style="text-indent: 2em;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">对于单位来说，可能以后的投资建设方向也该有所转变了。一些EDR\NDR\XDR、威胁狩猎、SIEM平台、威胁情报等威胁可视化工具应该更能发挥作用了。对于那些真正的EDR\NDR\XDR产品来说，应该是一个好消息。</span></span><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;font-style: normal;text-decoration: none;">你所用的EDR是真的还是假的，是骡子是马，总可以拉出来遛遛了。</span></span></span></span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;font-weight: bold;font-style: normal;text-decoration: none;">如果单位没有能力做到上面的提到的要求，购买运维服务或者MDR服务也是一个不错的选择，让专业的安全团队帮你做事件的检测与响应，并出具应急响应报告。</span></span></span></span></span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100002018" data-ratio="8.639814814814814" data-s="300,640" type="block" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=feb86c17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877Inem8Fm9icpibHOVibDT4BmROjNHL35dWs0bugL6676KVkROpctoFhGVVQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">延伸阅读：</span></span></span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485654&amp;idx=1&amp;sn=e8659bc6a8fc8e77d5166a4b9367aff5&amp;scene=21#wechat_redirect" textvalue="《国家网络安全事件报告管理办法》" data-itemshowtype="0" linktype="text" data-linktype="2">《国家网络安全事件报告管理办法》</a></span></span></span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484124&amp;idx=1&amp;sn=b89ebd7997462c1182f5556d78875d83&amp;scene=21#wechat_redirect" textvalue="不能说的秘密！" data-itemshowtype="0" linktype="text" data-linktype="2">不能说的秘密！</a></span></span></span></span></span></p><p style="text-indent: 2em;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span style="color:rgb(51, 51, 51);font-family:&#34;Microsoft YaHei&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color:rgb(51, 51, 51);font-family:\&#34;Microsoft YaHei\&#34;, 微软雅黑;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:justify;text-indent:32px;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;display:inline !important;float:none&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2">如果你被勒索病毒勒索了……</a></span></span></span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485667">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dca1913e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485667%26idx%3D1%26sn%3Dfb25ec2ebdf4843b74d8475630a6a8eb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 21 Sep 2025 08:00:00 +0800</pubDate>
    </item>
    <item>
      <title>《国家网络安全事件报告管理办法》</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485654&amp;idx=1&amp;sn=e8659bc6a8fc8e77d5166a4b9367aff5</link>
      <description>2025年9月15日，网络安全周的第一天，中央网信办的官网发布了《国家网络安全事件报告管理办法》。</description>
      <content:encoded><![CDATA[<p>
<span>大兵说安全</span> <span>2025-09-20 18:37</span> <span style="display: inline-block;">河南</span>
</p>

<p>2025年9月15日，网络安全周的第一天，中央网信办的官网发布了《国家网络安全事件报告管理办法》。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3379cb66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877ITxR0sRHqbwtoTECnQ6Ns5y209ibT2bib8eWcMTJFB1HURGPODI39FhSw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100002003" data-ratio="0.653610771113831" data-s="300,640" type="block" data-type="png" data-w="817" src="https://wechat2rss.xlab.app/img-proxy/?k=07365eed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSsKqDY9R7VZgeEdbu4877IRMmjgsbh7VzIpIp2PVmjjkDzmc3rMVojYYhQ54LPDpga6ncKGcH42Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;" data-pm-slice="0 0 []"><strong><span style="color: rgb(0, 0, 128);"><span leaf="">国家网络安全事件报告管理办法</span></span></strong></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><span leaf="">（2025年9月11日 国家互联网信息办公室）</span></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第一条</span></strong><span leaf=""> 为规范网络安全事件报告管理，及时控制网络安全事件造成的损失和危害，根据《中华人民共和国网络安全法》、《中华人民共和国数据安全法》、《中华人民共和国个人信息保护法》、《关键信息基础设施安全保护条例》等法律法规，制定本办法。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第二条</span></strong><span leaf=""> 在中华人民共和国境内建设、运营网络或者通过网络提供服务的网络运营者，在发生网络安全事件时，应当按照本办法的规定进行报告。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第三条</span></strong><span leaf=""> 国家网信部门负责统筹协调全国网络安全事件报告管理工作。省级网信部门负责统筹协调本行政区域内网络安全事件报告管理工作。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第四条</span></strong><span leaf=""> 网络运营者在发现或获知涉及本单位的网络安全事件时，应当按照《网络安全事件分级指南》（见附件）进行研判，属于较大以上网络安全事件的，按以下程序报告：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">涉及关键信息基础设施的，网络运营者应当第一时间向保护工作部门、公安机关报告，最迟不得超过1小时。属于重大、特别重大网络安全事件的，保护工作部门在收到报告后，应当第一时间向国家网信部门、国务院公安部门报告，最迟不得超过半小时。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">网络运营者属于中央和国家机关各部门及其直属单位的，应当及时向本部门网信工作机构报告，最迟不得超过2小时。属于重大、特别重大网络安全事件的，各部门网信工作机构在收到报告后，应当第一时间向国家网信部门报告，最迟不得超过1小时。国家网信部门收到报告后及时向有关部门通报。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">其他网络运营者应当及时向属地省级网信部门报告，最迟不得超过4小时。属于重大、特别重大网络安全事件的，省级网信部门在收到报告后，应当第一时间向国家网信部门报告，最迟不得超过1小时，并同时向同级有关部门通报。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">本行业领域有专门规定的，网络运营者还应当按照行业主管监管部门要求报告。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">涉嫌违法犯罪的，网络运营者应当及时向公安机关报案。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第五条</span></strong><span leaf=""> 网络运营者应当以合同等形式要求为其提供网络安全、系统运维等服务的组织或个人，及时向其报告监测发现的网络安全事件，并协助其按照本办法规定报告网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第六</span></strong><strong><span leaf="">条</span></strong><span leaf=""> 鼓励社会组织和个人报告所获悉的较大以上网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第七条</span></strong><span leaf=""> 报告网络安全事件时，应当包括下列内容：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（一）涉事单位名称及涉事系统或设施基本情况；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（二）网络安全事件发现或发生的时间、地点、类型、级别，以及已造成的影响和危害，已采取的措施及效果；对勒索软件攻击事件，还应当包括要求支付赎金的金额、方式、日期等；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（三）事态发展趋势及可能造成的进一步影响和危害；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（四）网络安全事件原因初步分析意见；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（五）溯源调查工作线索，包括但不限于可能的攻击者信息、攻击路径、存在的漏洞等；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（六）拟进一步采取的应对措施以及请求支援事项；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（七）网络安全事件现场保护情况；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（八）其他应当报告的情况。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">对于规定时间内不能判定事发原因、影响或发展趋势等网络安全事件情况的，可先报告第一项、第二项内容，其他情况及时补报。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">网络安全事件报告后出现新的重要情况或调查工作取得阶段性进展的，涉事单位应当及时报告。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第八条</span></strong><span leaf=""> 网络安全事件处置工作结束后，网络运营者应当于30日内对相关事件发生原因、应急处置措施、造成的危害、责任追究、完善整改情况、教训等进行全面分析总结，形成事件处置总结报告按照原渠道上报。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第九条</span></strong><span leaf=""> 网信部门建设12387网络安全事件报告热线电话和网站、邮箱、传真等方式，统一接收网络安全事件报告。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十条</span></strong><span leaf=""> 网络运营者未按照本办法规定报告网络安全事件的，有关主管部门按照有关法律、行政法规的规定进行处罚。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">因网络运营者迟报、漏报、谎报或者瞒报网络安全事件，造成重大危害后果的，对网络运营者及有关责任人依法从重处罚。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">承担网络安全事件报告的部门未按照本办法规定报告网络安全事件的，依据有关法律、行政法规和网络安全工作责任制追究相关单位和人员责任。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十一条</span></strong><span leaf=""> 发生网络安全事件时，网络运营者已采取合理必要的防护措施，按照应急预案进行处置、有效降低网络安全事件影响和危害，并按照本办法规定及时报告的，可视情从轻或不予追究相关单位和人员责任。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十二条</span></strong><span leaf=""> 本办法所指网络安全事件是指由于人为原因、网络遭受攻击、网络存在漏洞隐患、软硬件缺陷或故障、不可抗力等因素，对网络和信息系统或其中的数据和业务应用造成危害，对国家、社会、经济造成负面影响的事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">本办法所指网络运营者是指网络的所有者、管理者和网络服务提供者。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">本办法所指《网络安全事件分级指南》参照《信息安全技术 网络安全事件分类分级指南》国家标准（GB/T 20986-2023）制定，以有限枚举的方式给出相关事件的分级定量指标。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十三条</span></strong><span leaf=""> 涉及国家秘密的网络安全事件报告，按照有关部门规定执行。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">第十四条</span></strong><span leaf=""> 本办法自2025年11月1日起施行。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: justify;"><span leaf="">附件</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="color: rgb(0, 0, 128);"><strong><span leaf="">网络安全事件分级指南</span></strong></span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">一、</span></strong><strong><span leaf="">特别重大网络安全事件</span></strong></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">符合下列情形之一的，为特别重大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.重要网络和信息系统遭受特别严重的系统损失，造成系统大面积瘫痪，丧失业务处理能力。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.核心数据、重要数据、海量公民个人信息丢失或被窃取、篡改、假冒，对国家安全和社会稳定构成特别严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.其他对国家安全、社会秩序、经济建设和公众利益构成特别严重威胁、造成特别严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">通常情况下，满足下列条件之一的，可判别为特别重大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.省级以上党政机关门户网站、中央重点新闻网站因攻击、故障，导致24小时以上不能访问。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.关键信息基础设施整体中断运行6小时以上或主要功能中断运行24小时以上。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.影响一个或多个省级行政区50%以上人口，或者1000万人以上用水、用电、用气、用油、取暖、交通出行、就医、购物等工作、生活。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">4.核心数据、重要数据泄露或被窃取、篡改、假冒，对国家安全和社会稳定构成特别严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">5.泄露1亿人以上公民个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">6.省级以上党政机关门户网站、中央重点新闻网站、超大型网络平台等被攻击篡改，导致违法有害信息特大范围传播。以下情况之一，可认定为“特大范围”：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（1）在主页上出现并持续6小时以上，或在其他页面出现并持续24小时以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（2）通过社交平台转发10万次以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（3）浏览或点击次数100万以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（4）省级以上网信部门、公安机关认定为是“特大范围传播”的。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">7.造成1亿元以上的直接经济损失。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">8.其他对国家安全、社会秩序、经济建设和公众利益构成特别严重威胁、造成特别严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">二、</span></strong><strong><span leaf="">重大网络安全事件</span></strong></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">符合下列情形之一且未达到特别重大网络安全事件的，为重大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.重要网络和信息系统遭受严重的系统损失，造成系统长时间中断或局部瘫痪，业务处理能力受到极大影响。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.核心数据、重要数据、大量公民个人信息丢失或被窃取、篡改、假冒，对国家安全和社会稳定构成严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.其他对国家安全、社会秩序、经济建设和公众利益构成严重威胁、造成严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">通常情况下，满足下列条件之一的，可判别为重大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.地市级以上党政机关、企事业单位门户网站，省级以上重点新闻网站因攻击、故障，导致6小时以上不能访问。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.关键信息基础设施整体中断运行1小时以上或主要功能中断运行3小时以上。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.影响一个或多个地市级行政区50%以上人口，或者100万人以上用水、用电、用气、用油、取暖、交通出行、就医、购物等的工作、生活。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">4.核心数据、重要数据泄露或被窃取、篡改、仿冒，对国家安全和社会稳定构成严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">5.泄露1000万人以上公民个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">6.地市级以上党政机关、企事业单位门户网站，省级以上重点新闻网站，大型以上网络平台等被攻击篡改，导致违法有害信息大范围传播。以下情况之一，可认定为“大范围”：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（1）在主页上出现并持续2小时以上，或在其他页面出现并持续12小时以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（2）通过社交平台转发1万次以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（3）浏览或点击次数10万以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（4）省级以上网信部门、公安机关认定为是“大范围传播”的。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">7.造成2000万元以上的直接经济损失。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">8.其他对国家安全、社会秩序、经济建设和公众利益构成严重威胁、造成严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">三、</span></strong><strong><span leaf="">较大网络安全事件</span></strong></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">符合下列情形之一且未达到重大网络安全事件的，为较大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.重要网络和信息系统遭受较大的系统损失，造成系统中断，明显影响系统效率，业务处理能力受到影响。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.重要数据、较大量公民个人信息丢失或被窃取、篡改、假冒，对国家安全和社会稳定构成较严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.其他对国家安全、社会秩序、经济建设和公众利益构成较严重威胁、造成较严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">通常情况下，满足下列条件之一的，可判别为较大网络安全事件：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">1.地市级以上党政机关、企事业单位门户网站，省级以上重点新闻网站因攻击、故障，导致2小时以上不能访问。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">2.关键信息基础设施整体中断运行10分钟以上或主要功能中断运行30分钟以上。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">3.影响一个或多个地市级行政区30%以上人口，或者10万人以上用水、用电、用气、用油、取暖、交通出行、就医、购物等工作、生活。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">4.重要数据泄露或被窃取，对国家安全和社会稳定构成较严重威胁。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">5.泄露100万人以上公民个人信息。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">6.党政机关、企事业单位门户网站，重点新闻网站，网络平台等被攻击篡改，导致违法有害信息较大范围传播。以下情况之一，可认定为“较大范围”：</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（1）在主页上出现并持续30分钟以上，或在其他页面出现并持续2小时以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（2）通过社交平台转发1000次以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（3）浏览或点击次数1万以上；</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">（4）省级以上网信部门、公安机关认定为是“较大范围传播”的。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">7.造成500万元以上的直接经济损失。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">8.其他对国家安全、社会秩序、经济建设和公众利益构成较严重威胁、造成较严重影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><strong><span leaf="">四、</span></strong><strong><span leaf="">一般网络安全事件</span></strong></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span leaf="">除上述网络安全事件外，对国家安全、社会秩序、经济建设和公众利益构成一定威胁、造成一定影响的网络安全事件。</span></p><p style="margin: 0px;outline: none;padding-bottom: 15px;font-size: 16px;line-height: 30px;color: rgb(51, 51, 51);font-family: &#34;Microsoft YaHei&#34;, 微软雅黑;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;text-align: justify;"><span style="font-family: 楷体, 楷体_GB2312, SimKai;color: rgb(127, 127, 127);"><span leaf="">注：本指南中的“以上”均包括本数。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://www.cac.gov.cn/2025-09/15/c_1759583017717009.htm">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c7add039&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485654%26idx%3D1%26sn%3De8659bc6a8fc8e77d5166a4b9367aff5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 20 Sep 2025 18:37:00 +0800</pubDate>
    </item>
    <item>
      <title>从《论持久战》看网络安全建设</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485649&amp;idx=1&amp;sn=0eee1e8bc636a6478a77162b1a9393ce</link>
      <description>最近闲暇时间在重读毛主席的《论持久战》，结合当前网络安全建设中的一些问题，颇有感悟，与大家分享。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-09-02 10:47</span> <span style="display: inline-block;">河南</span>
</p>

<p>最近闲暇时间在重读毛主席的《论持久战》，结合当前网络安全建设中的一些问题，颇有感悟，与大家分享。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9526fc44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqTREW6ALWfibP3g1wXDcnzRc2B0ick69zgxKia15ODVsS0YtZQc0EQolxhb99osRH5R8wupTrvuW2R4g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">这是五月份在一次会议上讲的内容，后来整理成的一篇文章，迟迟没有发表，正好马上到抗战胜利80周年了，拿出来与各位同仁分享，欢迎批评指正。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001997" class="rich_pages wxw-img" data-ratio="0.687037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f0733585&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqTREW6ALWfibP3g1wXDcnzRc65LRsTvkGKqtgZnuwKuibWFgFrGBFKR15D1dJt5koOLngHWwnpNic9tw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;"><span leaf="">最近在跟一些单位的网络负责人聊天时，他们经常说的一个话题就是关于网络安全，有人说：</span></p><p style="text-indent: 2em;"><span leaf="">单位花了这么多钱，购买了大量的安全设备，也按照等保三级要求作了建设，为什么还是防不住这些黑客？还是会被勒索？下一步该怎么走？</span></p><p style="text-indent: 2em;"><span leaf="">正好，最近闲暇时间在重读毛主席的《论持久战》，结合当前网络安全建设中的一些问题，颇有感悟，与大家分享。</span></p><p style="text-indent: 2em;"><span leaf="">《论持久战》是毛主席于1938年5月26日至6月3日在延安抗日战争研究会上的演讲稿,那个时候，全面抗战才刚刚开始，日本人节节胜利，</span><span leaf="">速胜论、亡国论和焦土抗战论都出现了，很多人对于抗战没有信心，毛主席写了这篇文章，把抗战过程做了分析，并给出了具体的战术和走向。</span></p><p style="text-indent: 2em;"><span leaf="">《论持久战》是一篇奇文，有人说这是千古第一阳谋，由于是公开发表，日本人也能看到这部著作。《论持久战》的高明，连对手也为之折服。说白了就是，这场仗该怎么打，我都告诉你，但就算你提前知道了，最终你还是要输给我，只不过是时间的问题。而历史的走向也证实了这一点，《论持久战》就像是对抗日战争的总结复盘，里面准确预言了抗日战争各个时间段的发展，揭露了日本帝国主义必然会失败的事实。</span></p><p style="text-indent: 2em;"><span leaf=""><img data-imgfileid="100001998" class="rich_pages wxw-img" data-ratio="1.333955223880597" data-type="jpeg" data-w="536" src="https://wechat2rss.xlab.app/img-proxy/?k=6d371761&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqTREW6ALWfibP3g1wXDcnzRcP01bV6y3Nsly9xtXHCvOzkP5qegvOhzY3icOq4AJgcZBjOIdOq1EEUA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">我们不能简单的当成是一篇抗日的文章，里面很多的思想，是可以应用到很多领域的，比如网络安全。</span></p><p style="text-indent: 0px;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;">一、要从战略的眼光看网络安全</span></span></p><p style="text-indent: 2em;"><span leaf="">主席说：<span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">抗日战争是一个长期的战争，中国必亡论和中国速胜论都是不对的，是不科学的</span>。同样，</span><span leaf="">网络安全也是一个长期战争，也需要有长远的战略规划。就像《论持久战》中分析战争的三个阶段（战略防御、战略相持、战略反攻）一样，网络安全也需要分阶段、有层次地进行防御和应对。</span></p><p style="text-indent: 2em;"><span leaf="">我们从一个业务系统的生命周期来看，包括</span><span leaf="">论证、设计、建设、运营、退役等几个阶段。假设一个业务系统的生命周期是10年，那么前期的论证设计和建设等只是占整个生命周期的10%-15%左右。占大多数时间的是运营阶段。因此，不是说我的网络安全建设好了就万事大吉了。更多的是要考虑在业务系统的运营阶段如何做好安全，前期购买网络安全设备只是做好的建设，但如何用好，如何在长期的使用过程中，及时的发现威胁并进行响应才是重中之重。</span></p><p style="text-indent: 2em;"><span leaf="">这是很多企业管理者经常会犯的一个错误，以为自己购买了大量的安全设备，已经过了等保三级，就安全了，认为就不应该再有安全事件发生，这是非常错误的想法。建设好只是相当于修好了工事，但在相持阶段跟敌人（黑客）的斗争过程中，需要不断的修补不断的提升。这个阶段的核心是人，而不是设备。</span></p><p style="text-indent: 2em;"><span leaf="">如果对比主席提出的三个阶段，我们现在大多数的企业其实是处于被动防御阶段。被动防御，并不是真的被动，而是指的堡垒政策，在基础架构的基础之上，通过纵深防御构建自己的堡垒，通过堡垒，消耗攻击者的资源和时间，迟滞攻击，最终使得攻击者放弃攻击，防火墙，补丁，入侵防御和入侵检测，都是被动防御的方法。被动防御，随着时间推移，会失效，尤其在对手绝不放弃的决心和拥有丰富的资源的情况下，而且作为防守方，我们要投入更多的精力和资金，因为你不知道攻击者从哪里来，因此只能尽可能的高筑墙。在这个阶段的核心是修补漏洞。认为只要把漏洞补上了，就能抵御外来威胁，从而降低风险。主要特征是安全靠设备，自动化处理，不太需要人的参与。</span></p><p style="text-indent: 2em;"><span leaf="">而在相持阶段，更重要的是检测和响应能力。工事构建好了，下一步就是要如何快速地发现攻击和响应攻击。这个阶段最重要的人的参与。或许有人说，我们单位也购买的有EDR和NDR之类的检测和响应产品啊，是不是已经脱离了被动防御阶段进入你所说的相持阶段了？其实不是，是否脱离了被动防御阶段的重点并不是你有没有检测和响应类的产品，而是有没有人，能利用这些DR产品进行安全事件分析、溯源和响应的人。没有人，买了再多的安全产品仍然是没用的，还是被动防守的阶段。</span></p><p style="text-indent: 2em;"><span leaf="">下一步，我们要考虑的就是如何化被动为主动，在网络安全这个领域，针对大多数企业来讲，不需要进行反攻，因此我用了主动防御这个说法。什么是主动防御？为什么要主动？因为防守是被动的，我们要解决安全问题就不能总是站在防守者的角度是思考问题，要从攻击者的视角去看。只有了解攻击才能先他一步，因此，要具有收集内部情报的能力，建立SIEM系统，对内部数据进行收集，同时也要有外部情报，这样才能进行关联分析，进而准确预警，先发制人。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">这个阶段的核心就是要构建以情报为核心的态势感知系统。</span></p><p style="text-indent: 2em;"><span leaf="">看到这里，有人可能会说了，这不就是态势感知吗？我们已经买了态势感知产品了，是不是可以说已经进入这个阶段了？还是刚才说的，这不是设备的问题，首先你要满足相持阶段的关键要素，你有没有人？能不能分析溯源攻击事件？不仅要知道是不是被攻击了，还要知道是谁在攻击我？为什么攻击我？攻击者的特点是什么？一般用什么工具用什么战术等信息。其次，态势感知是一个能力，不是一个产品。</span></p><p style="text-indent: 2em;"><span leaf="">我曾经写过一篇文章，里面总结过四句话：</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">把态势感知当产品卖的都是在吃政府豆腐；</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">没有大数据支撑的态势感知就是无米之炊；</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">不结合情报系统的态势感知就是在耍流氓；</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 15px;font-style: italic;text-decoration: underline;">没有人才支持的态势感知最终都沦为鸡肋。</span></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485077&amp;idx=1&amp;sn=123ef8c4fb0a4d53db6001cd6387baba&amp;scene=21#wechat_redirect" textvalue="也来聊聊态势感知（上）" data-itemshowtype="0" linktype="text" data-linktype="2">也来聊聊态势感知（上）</a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485078&amp;idx=1&amp;sn=d8fcaaaae6947bf3aba78afd41b2f540&amp;scene=21#wechat_redirect" textvalue="也来聊聊态势感知（中）" data-itemshowtype="0" linktype="text" data-linktype="2">也来聊聊态势感知（中）</a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485080&amp;idx=1&amp;sn=bb2f158fd8b0b158ba9a1cf16003c7fd&amp;scene=21#wechat_redirect" textvalue="也来聊聊态势感知（下）" data-itemshowtype="0" linktype="text" data-linktype="2">也来聊聊态势感知（下）</a></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001905" class="rich_pages wxw-img" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f7e141f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqS5ak6vYA5DspuX2RLV7MtichQ5pB19pV3BlhBebZAKWMjUtEcHKLjSNbk6Gadxuiab23SlUzdLFGxQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;">二、决定战争最终胜利的核心因素</span></span></p><div style="text-indent: 2em;"><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">在《论持久战》， 毛主席列举了取得战争最后胜利的几个核心要素：</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、组织与人</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">主席说：<span textstyle="" style="font-size: 14px;color: rgb(217, 33, 66);font-style: italic;">“武器是战争的重要的因素，但不是决定的因素，决定的因素是人不是物。”</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;color: rgb(217, 33, 66);font-style: italic;">“全国党派，从共产党到国民党；全国人民，从工人农民到资产阶级；全国军队，从主力军到游击队；国际方面，从社会主义国家到各国爱好正义的人民；敌国方面，从某些国内反战的人民到前线反战的兵士。总而言之，所有这些因素，在我们的抗战中都尽了他们各种程度的努力。”</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;color: rgb(217, 33, 66);font-style: italic;">“这个政治上动员军民的问题，实在太重要了。我们之所以不惜反反复复地说到这一点，实在是没有这一点就没有胜利。没有许多别的必要的东西固然也没有胜利，然而这是胜利的最基本的条件。抗日民族统一战线是全军全民的统一战线，决不仅仅是几个党派的党部和党员们的统一战线；动员全军全民参加统一战线，才是发起抗日民族统一战线的根本目的。”</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在文章中，主席多次提到了人的问题，人是决定因素。这里所说的人不是单纯的指共产党的军队，而是方方面面。要想取得胜利，必须全员动员。在网络安全中也一样，网络安全不是信息部门一个部门的事。而是全体人员的事，包括单位领导以及每位员工，甚至还包括外来人员（如第三方运维人员、开发人员等），进行动员，对全体员工进行网络安全意识的培训，领导也要充分认识到网络安全的重要性，技术人员要有克敌制胜的能力。才能上下一心，战胜敌人。习总书记在419讲话也提出建立科学的网络安全观，他说：</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">“网络安全是共同的而不是孤立的。网络安全为人民，网络安全靠人民，维护网络安全是全社会共同责任，需要政府、企业、社会组织、广大网民共同参与，共筑网络安全防线。“</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这个过程中，组织与领导者的作用非常大。主席说：</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">竞赛结果，有胜有败，除了客观物质条件的比较外，胜者必由于主观指挥的正确，败者必由于主观指挥的错误。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在网络安全中，领导者的作用同样重要，领导有没有认识到安全的责任所在，有没有制定安全流程和管理制度的能力，有没有执行的魄力，都是在网络安全斗争中重要的因素，大家都知道，网络安全</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">“</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">三分靠技术，七分靠管理</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">”</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">，这里的管理就是领导者能力的具体体现。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、物资与保障</span></span></p><p><span leaf="">主席说：<span textstyle="" style="font-size: 15px;font-style: italic;">“</span><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">战争就是两军指挥员以军力财力等项物质基础作地盘，互争优势和主动的主观能力的竞赛。”“</span></span><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">除了主要地看中国自己的力量之外，国际间所给中国的援助和日本国内革命的援助也很有关系。”“同时，争取外国的援助，使中国军队的装备逐渐加强起来。</span><span textstyle="" style="font-size: 15px;font-style: italic;">”</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">战争，考验的是领导者的指挥能力和后勤保障。网络安全同样如此。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">要做好网络安全，强有力的后勤保障必不可少，这个保障既包括人员保障，物资的保障，更包括财力的保障。这种保障的来源，一方面是内部，全体人员共同的努力，另一个重要的方面，是来自外部的外国的甚至全世界的援助，包括物资的援助、人的援助和武器的援助。通过外部援助，让我们有可以反击敌人的趁手的武器，同时，也可以迅速提升内部人员的能力。反对日本法西斯的战争不是中日两国的战争，而是世界人民共同的战争，全世界的反法西斯者都要联合起来。习总书记在419讲话中也明确指出，要树立科学的网络安全观，他指出：“</span><span leaf="">网络安全是开放的而不是封闭的。只有立足开放环境，加强对外交流、合作、互动、博弈，吸收先进技术，网络安全水平才会不断提高”，</span></p><p><span leaf="">我们不能只强调自身努力而忽略了外部力量的重要性，甚至抵触外部的援助。这不利于我们取得斗争的胜利。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">三、战略与战法</span></span></p><div style="text-indent: 2em;" data-pm-slice="5 3 []"><p style="margin-right: 2.25pt;margin-left: 2.25pt;padding: 0pt;" data-pm-slice="0 0 []"><span style=""><font face="方正仿宋_GB2312"><span leaf="">毛席提出了对日战争的战法：主动性，灵活性，计划性</span></font></span><span style=""><o:p></o:p></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">主动性：“</span><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">在斗争中，由于主观指导的正确或错误，可以化劣势为优势，化被动为主动；也可以化优势为劣势，化主动为被动。一切统治王朝打不赢革命军，可见单是某种优势还没有确定主动地位，更没有确定最后胜利。主动和胜利，是可以根据真实的情况，经过主观能力的活跃，取得一定的条件，而由劣势和被动者从优势和主动者手里夺取过来的。</span><span textstyle="" style="font-size: 15px;font-style: italic;">”</span></span></p><p><span leaf="">灵活性：“<span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">古人所谓“运用之妙，存乎一心”，这个“妙”，我们叫做灵活性，这是聪明的指挥员的出产品。灵活不是妄动，妄动是应该拒绝的。灵活，是聪明的指挥员，基于客观情况，“审时度势”（这个势，包括敌势、我势、地势等项）而采取及时的和恰当的处置方法的一种才能，即是所谓“运用之妙”</span><span textstyle="" style="font-size: 15px;font-style: italic;">。</span></span></p><p><span leaf="">计划性：<span textstyle="" style="font-size: 15px;font-style: italic;">“</span><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">由于战争所特有的不确实性，实现计划性于战争，较之实现计划性于别的事业，是要困难得多的。然而，“凡事预则立，不预则废” ，没有事先的计划和准备，就不能获得战争的胜利。战争没有绝对的确实性，但不是没有某种程度的相对的确实性。我之一方是比较地确实的。敌之一方很不确实，但也有朕兆可寻，有端倪可察，有前后现象可供思索。这就构成了所谓某种程度的相对的确实性，战争的计划性就有了客观基础。”</span></span></p></div><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">我们承认战争现象是较之任何别的社会现象更难捉摸，更少确实性，即更带所谓“盖然性”。但战争不是神物，仍是世间的一种必然运动，因此，孙子的规律，“知彼知己，百战不殆”，仍是科学的真理。错误由于对彼己的无知，战争的特性也使人们在许多的场合无法全知彼己，因此产生了战争情况和战争行动的不确实性，产生了错误和失败。</span><span textstyle="" style="font-size: 15px;font-style: italic;">”</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在网络安全建设中，现在的我们，人员能力、武器工具、组织管理等各个方面都处于初级阶段，目前的建设体系是以<span textstyle="" style="font-weight: bold;">漏洞修补</span>为核心，通过<span textstyle="" style="font-weight: bold;">防火墙、漏洞扫描、权限管理、防病毒、加密</span>等构建堡垒型防御体系，但这种被动的防守终究是防不住，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">一方面，我们要加强防守，另一方面，我们也要主动出击。</span></p><p><span leaf="">下一步，我们要逐渐加加强人员意识和能力，通过<span textstyle="" style="font-weight: bold;">EDR\NDR\XDR</span>等工具，加强检测与响应能力，构建以<span textstyle="" style="font-weight: bold;">情报</span>为核心的主动防御体系，</span><span leaf="">通过<span textstyle="" style="font-weight: bold;">威胁狩猎</span>（Threat Hunting）主动查找威胁、通过<span textstyle="" style="font-weight: bold;">诱捕系统</span>（蜜罐）主动发现攻击者，通过<span textstyle="" style="font-weight: bold;">渗透测试</span>和<span textstyle="" style="font-weight: bold;">数据足迹服务</span>(Digital Footprint Intelligence)等主动发现泄露的数据和暴露的资产的漏洞，通过<span textstyle="" style="font-weight: bold;">外部威胁情报</span>主动出击先行一步干扰其行动（类似游击战）。</span><span leaf="">加强主动性的前提是我们的能力、意识、保障都达到了一定的程度，攻防易形，逐步进行战略的主动阶段。</span></p><p><span leaf="">“</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">防御必须同时有进攻，而不应是单纯的防御，也是这个道理</span>”。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在具体的做法上，我们要根据当前的实际情况灵活应对，而不能墨守成规。习总书记说：“</span><span leaf="">网络安全是动态的而不是静态的。信息技术变化越来越快，过去分散独立的网络变得高度关联、相互依赖，网络安全的威胁来源和攻击手段不断变化，那种依靠装几个安全设备和安全软件就想永保安全的想法已不合时宜，需要树立动态、综合的防护理念”。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">风险总是不确定的，我们无法预测会发生什么，但我们不能因为不能预测就什么都不做。我们要学会识别风险、分析风险、规避风险，根据风险评估进行有针对性的预案，这样，当安全事件发生的时候，才可以做有从容不迫，比如最重要的安全事件响应流程、业务连续性计划、灾难恢复计划等。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">“<span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">抗日战争应该是有计划的。战争计划即战略战术的具体运用，要带灵活性，使之能适应战争的情况。要处处照顾化劣势为优势，化被动为主动，以便改变敌我之间的形势。</span>”</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">四、主要风险与次要风险</span></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484124&amp;idx=1&amp;sn=b89ebd7997462c1182f5556d78875d83&amp;scene=21#wechat_redirect" textvalue="不能说的秘密！" data-itemshowtype="0" linktype="text" data-linktype="2">不能说的秘密！</a></span></p><p><span leaf="">在网络安全防护中，我们要清楚地知道自己的底线是什么？在资金有限的情况下，我们不可能做到面面俱到，好钢要花在刀刃上，如何将最有限的资金保护最核心的资产，这是安全工作者要考虑的一个问题，这就要求我们要做好风险评估，了解自己公司最核心的资产是什么，是数据？是业务系统？还是其他……对于这些资产而言，保密性更重要？还是完整性更重要?还是可用性最重要？</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">但在实际工作中，我们去问哪些是重要的？客户经常的反应是都重要，问到要求的RTO和RPO，都会告诉我们是零。这样看似很重视，但实际结果却恰恰相反，因为你没有对你的资产做好评估，看似都重要，结果只能是为了全面照顾而忽略对真实核心资产的保护，我们的资金和精力都是有限的，不可能做到全面防护。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">就像主席在文中所说，古今中外，很多以弱胜强的例子，“</span><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">都是以少击众，以劣势对优势而获胜。都是先以自己局部的优势和主动，向着敌人局部的劣势和被动，一战而胜，再及其余，各个击破，全局因而转成了优势，转成了主动</span>”。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在战争中，我们不要在意一城一地的得失，重要核心不是土地，而是军力，因此“</span><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">放弃土地是为了保存军力，也正是为了保存土地；因为如不在不利条件下放弃部分的土地，盲目地举行绝无把握的决战，结果丧失军力之后，必随之以丧失全部的土地，更说不到什么恢复失地了。资本家做生意要有本钱，全部破产之后，就不算什么资本家。赌汉也要赌本，孤注一掷，不幸不中，就无从再赌。事物是往返曲折的，不是径情直遂的，战争也是一样，只有形式主义者想不通这个道理。</span>”</span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);">“留得青山在，不愁没柴烧”“</span></span><span leaf=""><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);">在无可避免的情况下（也仅仅是在这种情况下），只好勇敢地放弃。情况到了这种时候，丝毫也不应留恋，这是以土地换时间的正确的政策。”</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">所以，对于我们网络安全从业人员而言，一定要做好资产梳理，搞清楚哪些资产是你要保护的重点，切不可贪大求全。只要确保核心资产的安全，其他的是可以适当放弃的。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">底线思维的另外一方面是我们梳理出来核心资产之后，一定要对其做好备份工作，不管是系统还是数据，都要定期备份并做好恢复演练，确保其是可以恢复的。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">现在，很多单位往往重视防御工作，而忽视了对于万一防不住的准备，只期待数据不能丢，一点都不能丢，业务不能停，一刻都不能停。但是，万一呢？万一数据丢了，业务停了，你有没有可以快速恢复的措施和手段？</span></p><p><span leaf="">其实安全无非是两件事件：<span textstyle="" style="font-weight: bold;">降低安全事件发生的概率，减少安全事件发生后带来的损失</span>。</span></p><p><span leaf="">但很多领导更强调的不能出事，这当然不错，但是也一定要有最坏的打算。</span></p><p><span leaf="">所以在建设网络安全体系时，我们要的事情，一方面要根据风险评估的结果，构建安全防御体系，另一方面，也要做好防不住的最坏打算，做好数据备份和灾难恢复措施。不仅要有业务连续性计划BCP，也要有灾难恢复计划DRP。一方面防止事件发生影响业务连续性，另一方面，做好DRP，万一安全事件发生了，我们如何降低损失。</span></p><p style="text-indent: 0px;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">三、总结</span></span></p><p><span leaf="">网络安全也是一场持久战，我们要从人员与组织、物资与保障、战略与战术等多个方面进行认真的准备与全面对抗，尤其是人的主观能动性，因此不能只是大量购买产品，而忽略了人的能力的培养。当然购买好的产品也是非常重要的，工欲善其事，必先利其器，说的就是这个道理，没有称手的武器，就会被动挨打而无还手之力。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 15px;color: rgb(217, 33, 66);font-style: italic;">“革新军制离不了现代化，把技术条件增强起来，没有这一点，是不能把敌人赶过鸭绿江的。军队的使用需要进步的灵活的战略战术，没有这一点，也是不能胜利的。”</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">网络安全是一个长期的战争，必亡论和速胜论都是不对的，是不科学的。</span></p></div><p><span leaf="">写在最后：</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">马上就是九三了，纪念抗日战争胜利，牢记民族耻辱、牢记先辈付出，把祖国变得更强大，是每一个中国人都应该做的事，抗战是中国人的胜利，是无数先辈用生命换来的成果，无论是正面战场，还是敌后战场，无论是冲在前线的勇士，还是在支援抗战的百姓，都在为抗战的胜利牺牲自己，才换来我们现在的幸福生活，值得我们永远怀念。</span></span></p><p style="text-indent: 0px;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">向伟大的抗战前辈致敬！！！</span></span></p><div><p style="text-indent: 0px;text-align: center;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0px; text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;font-weight: bold;">向伟大的抗战前辈致敬！！！</span></span></p></div><div><p style="text-indent: 0px;text-align: center;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0px; text-align: center;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;font-weight: bold;">向伟大的抗战前辈致敬！！！</span></span></p></div><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485649">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3ab4c198&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485649%26idx%3D1%26sn%3D0eee1e8bc636a6478a77162b1a9393ce">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 02 Sep 2025 10:47:00 +0800</pubDate>
    </item>
    <item>
      <title>教你如何看懂反病毒软件报告（二）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485638&amp;idx=1&amp;sn=4a0f0cdff5e8473525cdcd903246ee23</link>
      <description>这一期，我们讲一讲病毒和蠕虫的命名规则。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-08-24 09:56</span> <span style="display: inline-block;">河南</span>
</p>

<p>这一期，我们讲一讲病毒和蠕虫的命名规则。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a6a6addf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqRu8X48xn94ibWtpQnAYGRHOw56YN3ODM7L3Vw7LNxj9KVGxfbkd8dhYU52iaiazibMlHG32TItve9Srw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;" data-pm-slice="4 2 []"><font face="Tahoma"></font></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001965" class="rich_pages wxw-img" data-ratio="0.5452196382428941" data-s="300,640" data-w="1161" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f031247e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvWBvygjxQiaxfPwaqFXYiaK6aT3SVzLq18F2xNib7UaiaGHm7yjMwTGlzJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;" data-pm-slice="4 2 []"><font face="Tahoma"></font></p><p style="text-indent: 2em;" data-pm-slice="4 2 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">之前的文章《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485377&amp;idx=1&amp;sn=27286d0e0fcf3fbf7ba29460c808d6a2&amp;scene=21#wechat_redirect" textvalue="教你一招，轻松变成反病毒高手" data-itemshowtype="0" linktype="text" data-linktype="2">教你一招，轻松变成反病毒高手</a>》，我们讲了病毒命名规则：</span></font></p><p style="text-indent: 0px;text-align: center;" data-pm-slice="4 2 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">[前缀]：类型（行为）</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">.平台.名称.[变种]</span></span></font></p><p data-pm-slice="2 2 []"><span leaf="">        前缀描述了检测时所使用的功能模块。</span><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;,&#34;data-pm-slice&#34;:&#34;4 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;font&#34;,&#34;attributes&#34;:{&#34;face&#34;:&#34;Tahoma&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">上一期《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e&amp;scene=21#wechat_redirect" textvalue="教你如何看懂杀毒软件病毒报告！" data-itemshowtype="0" linktype="text" data-linktype="2">教你如何看懂杀毒软件病毒报告！</a>》，我们讲了病毒命名的前缀代表的含义，</span><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;,&#34;data-pm-slice&#34;:&#34;4 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;font&#34;,&#34;attributes&#34;:{&#34;face&#34;:&#34;Tahoma&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">今天，我们接着讲病毒行为和平台。还以卡巴斯基为例，其他产品的命名规则以后再讲。各厂商的命名大同小异，学会了一通百通。</span></font></font></p><p style="text-indent: 2em;" data-pm-slice="3 1 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(0, 0, 0);">卡巴斯基将检测到的程序分为两大类：</span></span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">恶意程序</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 0, 0);">和</span></span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">广告、色情及风险工具</span></span></strong><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 0, 0);">，其中广告、色情及风险工具被归类为：not-a-virus，上期（《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e&amp;scene=21#wechat_redirect" textvalue="教你如何看懂杀毒软件病毒报告！" data-itemshowtype="0" linktype="text" data-linktype="2">教你如何看懂杀毒软件病毒报告！</a><span textstyle="" style="color: rgb(0, 0, 0);">》）已经讲过，今天讲恶意程序。</span></span></font></p><p style="text-indent: 2em;" data-pm-slice="3 1 []"><font face="Tahoma"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><img class="rich_pages wxw-img" data-imgfileid="100001723" data-ratio="0.52421875" data-s="300,640" type="block" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=c9c8b205&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqREfOqQ8Rqaa97XxNmxwFHZQSw9UL0TE4jqrhK9gCdWupicZCJsg4icv9UvFM12XfSKkfPVJQ6YpvJg%2F640%3Fwx_fmt%3Dpng"/></span></font></p><p data-pm-slice="2 2 []"><font face="Tahoma"><font face="Tahoma"></font></font></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">行为特征决定了检测对象的具体表现。</span><font face="Tahoma"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;,&#34;data-pm-slice&#34;:&#34;4 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;font&#34;,&#34;attributes&#34;:{&#34;face&#34;:&#34;Tahoma&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">卡巴斯基将恶意程序又分为四类：病毒和蠕虫、木马、可疑封装程序和恶意工具，在此基础上细化出了几十种行为的恶意程序，如Trojan-downloader是一个下载型木马，在后台执行下载恶意程序，Trojan-Ransom表示是一个勒索型木马。不同类型的分类依据是：</span></span></font></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">针对病毒和蠕虫，其行为特征根据<span textstyle="" style="font-weight: bold;">传播方式</span>确定；</span></p></li><li><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">特洛伊木马和恶意工具则依据<span textstyle="" style="font-weight: bold;">恶意载荷类型</span>选择行为特征；</span></p></li><li><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">可疑打包器的行为特征取决于其<span textstyle="" style="font-weight: bold;">运作模式</span>；</span></p></li><li><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">而广告软件、风险软件及色情软件的行为特征则根据<span textstyle="" style="font-weight: bold;">检测对象的功能特性</span>来设定。</span></p></li></ul><p><span leaf="">      </span></p><p style="text-indent: 2em;"><span leaf="">平台是程序代码执行的环境，可以指软件和硬件。 对于可以在多个平台上运行的检测到的对象，平台定义为“</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Multi</span><span leaf="">”。Virus.Multi.Etapux是一个多平台恶意程序的一个示例。该程序会感染Windows和Linux操作系统的可执行文件。 </span></p><p><span leaf="">      有两个平台支持启发式分析器：Win32和Script（一个用于多种脚本的通用平台）。有一个平台用于主动防御模块：Win32。</span></p><p style="text-indent: 2em;" data-pm-slice="4 2 []"><font face="Tahoma"><span leaf="">先来看第一个类型：病毒和蠕虫</span></font></p><p style="text-indent: 0px;text-align: center;" data-pm-slice="4 2 []"><font face="Tahoma"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 24px;">【一、病毒和蠕虫】</span></span></font><font face="Tahoma"></font></p><p style="text-align: left;text-indent: 2em;"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">病毒和蠕虫是恶意程序，它们在用户不知情的情况下在计算机上或通过计算机网络自我复制；此类恶意程序的每一个后续副本也能够自我复制。 </span></font></p><p style="text-indent: 2em;"><span leaf="">注意：通过网络传播或在“所有者”命令下感染远程计算机的恶意程序（如后门、木马等）或创建多个无法自我复制副本的程序<span textstyle="" style="font-weight: bold;text-decoration: underline;">不属于</span>病毒和蠕虫子类。也就是说病毒（和蠕虫）与木马的显著区别就是<span textstyle="" style="font-weight: bold;">是否具有自我复制性（传染性）。</span></span></p><p style="text-indent: 2em;"><span leaf="">用于确定程序是否被分类为病毒和蠕虫子类中的单独行为的主要特征是<span textstyle="" style="font-weight: bold;">该程序如何传播</span>（即恶意程序如何通过本地或网络资源传播自身的副本）。 </span></p><p style="text-indent: 2em;"><span leaf="">病毒（指的传统病毒）主要通过引导区和文件对计算机和计算机上的文件进行感染，可以根据用于感染计算机的方法对病毒进行分类，包括： 文件病毒 、引导扇区病毒 、宏病毒、脚本病毒 。</span></p><p style="text-indent: 2em;"><span leaf="">大多数已知的蠕虫是通过电子邮件附件发送的文件、通过网络或FTP资源的链接、通过ICQ或IRC消息中的链接、通过P2P文件共享网络等传播的。 有些蠕虫通过网络数据包传播，这些数据包直接进入计算机内存，然后蠕虫代码就激活了。</span></p><p style="text-indent: 2em;"><span leaf="">蠕虫使用以下技术渗透远程计算机并启动自身的副本：社会工程（例如，建议用户打开附件的电子邮件），利用网络配置错误（如复制到完全可访问的磁盘），以及利用操作系统和应用程序安全漏洞。 </span></p><p style="text-indent: 2em;"><span leaf="">当然，此子类中的任何程序也都可以具有其他特洛伊木马功能。这里的分类仅是依据传播方式，并不是按功能分类的。 </span></p><p style="text-indent: 2em;"><span leaf="">还应该注意，许多蠕虫使用不止一种方法通过网络传播副本。 </span></p><p><span leaf="">此恶意程序子类包括以下行为：</span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p><span leaf="">Email-Worm</span></p></li><li><p><span leaf="">IM-Worm</span></p></li><li><p><span leaf="">IRC-Worm</span></p></li><li><p><span leaf="">Net-Worm</span></p></li><li><p><span leaf="">P2P-Worm</span></p></li><li><p><span leaf="">Virus</span></p></li><li><p><span leaf="">Worm</span></p></li></ul><p style="text-align: left;"><font face="Tahoma"></font></p><p style="text-align: left;"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">我们先来说说病毒（virus)：</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">      这里所说的病毒是指传统病毒。</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">病毒利用本地计算机的资源进行复制。 与蠕虫不同，病毒不会使用网络服务来传播或侵入其他计算机。只有当受感染对象由于某些原因在另一台计算机上被激活时，病毒的副本才会到达远程计算机。例如： </span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">当感染可访问的磁盘时，病毒会渗透到位于网络资源上的文件 </span></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">病毒将自身复制到可移动存储设备或感染可移动设备上的文件 </span></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">用户发送带有受感染附件的电子邮件。</span></font></p></li></ul><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">……</span></span></font></p><p data-pm-slice="3 3 []" style="text-indent: 2em;"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">病毒都以VIRUS命名，后面根据感染的方式不同，可以分为引导区（boot)、可执行文件(操作系统）、宏（office或autocad等）、脚本（脚本语言）等。如：</span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">引导区病毒：感染引导区的病毒，感染磁盘引导区，命名为virus.boot，如：</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-imgfileid="100001980" class="rich_pages wxw-img" data-ratio="0.17543859649122806" data-s="300,640" data-type="png" data-w="399" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6afd8989&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvAHVciaTUIx3DZw35CByoZwrXlLEeGCADZPc6unmnopQZ4FzEHSS3s6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">脚本病毒：一般感染使用脚本语言编写的代码，如网页等，后面一般跟脚本语言，如：</span></span></font></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.BAT.xxx ：BAT脚本病毒</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.WinHLP.xxx ：Windows帮助文件脚本病毒</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.JS.xxx ：JavaScript脚本病毒</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.WinINF.xxx：Inf脚本病毒</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.PHP.xxx ：PHP脚本病毒</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Virus.VBS.xxx ：VbScript脚本病毒</span></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">文件病毒：</span><span textstyle="" style="font-weight: normal;">一般感染可执行程序或二进制文件，如.EXE\.COM\.DLL等文件。后面一般跟操作系统，如：</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: normal;">Virus.w32.xxx ：感染32位windows平台</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: normal;">Virus.w64.xxx：感染64位windows平台</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf=""><img data-imgfileid="100001978" class="rich_pages wxw-img" data-ratio="0.21107266435986158" data-s="300,640" data-type="png" data-w="289" style="width:289px;height:60px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqRqfSIJgTicVEGCN12GfQuxvVSYxUIb99cj04Kn2iaXGcC7UHbDSSQx6HZRSRIGaIp7iar98yYZQjMOw/640?wx_fmt=png&amp;from=appmsg" data-cropx2="289" data-cropy1="140" data-cropy2="200" src="https://wechat2rss.xlab.app/img-proxy/?k=b2318c32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqTdY5TX441TDIoZ6l86L076l710OubT4d6oP5lY81w5HwarMeq2FInykQ2JhY8GyXwmlQOlT5rNpw%2F640%3Fwx_fmt%3Djpeg"/></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">宏病毒：利用宏技术的病毒，后面一般跟应用程序名称，如：</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: normal;">virus.MSWord.xxx：感染word的病毒。</span></span></font></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: normal;">virus.MSExcel.xxx：感染excel的病毒。</span></span></font></p><p data-pm-slice="3 3 []"><span leaf=""><span textstyle="" style="font-weight: normal;">virus.Acad.xxx：感染AutoCad的病毒等。</span></span></p><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf=""><img data-imgfileid="100001978" class="rich_pages wxw-img" data-ratio="0.5570934256055363" data-s="300,640" data-type="png" data-w="289" style="width:289px;height:161px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqRqfSIJgTicVEGCN12GfQuxvVSYxUIb99cj04Kn2iaXGcC7UHbDSSQx6HZRSRIGaIp7iar98yYZQjMOw/640?wx_fmt=png&amp;from=appmsg" data-cropx2="289" data-cropy2="161" src="https://wechat2rss.xlab.app/img-proxy/?k=d0f89c61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqTdY5TX441TDIoZ6l86L076VVTw4s3PBvVz6iadcSdpq8ylmPjW0GQuMWtOrq7qKVR2jWyxAppnWbQ%2F640%3Fwx_fmt%3Djpeg"/></span></font></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">再来说说蠕虫（worm):</span></span></p><p style="text-indent: 2em;" data-pm-slice="3 2 []"><font face="Tahoma"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-weight: bold;">蠕虫</span>指通过局域网或</span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Internet传播，具有如下目标的程序——</span><font face="Tahoma"></font></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="text-indent: 2em;" data-pm-slice="3 2 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">渗透远程机器</span></font><font face="Tahoma"></font></p></li><li><p style="text-indent: 2em;" data-pm-slice="3 2 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在受害机器上加载自己的拷贝</span></font><font face="Tahoma"></font></p></li><li><p style="text-indent: 2em;" data-pm-slice="3 2 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">进一步向新的机器传播</span></font></p><p><font face="Tahoma"></font></p></li></ol><p style="text-indent: 2em;" data-pm-slice="3 2 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">蠕虫按照它们的传播途径又分为如下类型</span></font><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">——</span></font><font face="Tahoma"></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">通过</span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Email传播的蠕虫</span><font face="Tahoma"></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">通过及时通讯系统传播的蠕虫</span></font><font face="Tahoma"></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">通过网络（包括局域网和Internet)</span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">传播的蠕虫</span><font face="Tahoma"></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">通过</span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC传播的蠕虫</span><font face="Tahoma"></font></p></li><li><p data-pm-slice="3 3 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">通过文件共享网络传播的蠕虫</span></font></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">Email-Worm：</span>电子邮件蠕虫通过电子邮件传播。该蠕虫将自身的副本作为电子邮件的附件发送，或者发送到网络资源上的其文件的链接（例如，指向受感染的网站或黑客拥有的网站上受感染文件的URL）。 在第一种情况下，蠕虫代码在打开（启动）受感染的附件时激活。在第二种情况下，蠕虫代码在打开受感染文件的链接时激活。在这两种情况下，结果都相同：蠕虫代码被激活。</span></p><p><span leaf="">电子邮件蠕虫使用多种方法发送受感染的电子邮件。最常见的方法是： </span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">使用蠕虫代码中内置的电子邮件目录，直接连接到SMTP服务器 </span></p></li><li><p><span leaf="">使用MS Outlook服务 </span></p></li><li><p><span leaf="">使用Windows MAPI函数。</span></p></li></ul><p style="text-indent: 2em;"><span leaf="">电子邮件蠕虫使用许多不同的来源来查找受感染的电子邮件将被发送到的电子邮件地址： </span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">MS Outlook中的通讯簿 </span></p></li><li><p><span leaf="">WAB地址数据库 </span></p></li><li><p><span leaf="">硬盘驱动器上存储的.txt文件：蠕虫可以识别文本文件中哪些字符串是电子邮件地址 </span></p></li><li><p><span leaf="">收件箱中的电子邮件（某些电子邮件蠕虫甚至会对收件箱中的电子邮件进行“回复”） </span></p></li></ul><p style="text-indent: 2em;"><span leaf="">许多电子邮件蠕虫使用以上列出的一个以上的来源。还有其他电子邮件地址来源，如与基于Web的电子邮件服务关联的通讯簿。</span></p><p><span leaf="">卡巴斯基命名为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">Email-Worm.HTML.xxx ：利用Email传播，但感染方式是在邮件的HTML格式代码中包含可执行的ActiveX对象</span></p></li><li><p><span leaf="">Email-Worm.JS.xxx ：包含在邮件中的恶意代码是Javascript程序</span></p></li><li><p><span leaf="">Email-Worm.VBS.xxx ：包含在邮件中的恶意代码是Vb Script脚本</span></p></li><li><p><span leaf="">Email-Worm.PIF.xxx ：包含在邮件中的病毒体是标准的windows PIF文件</span></p></li><li><p><span leaf="">Email-Worm.Win32.xxx ：以邮件附件的方式传播的32位windows exe病毒</span></p></li><li><p><span leaf="">……</span></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">IM-Worm：</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">能够在即时通讯系统中自我复制的恶意软件，如Facebook Messenger、Skype或WhatsApp。 为此，蠕虫会向受害者的联系人发送带有指向包含蠕虫主体的文件的URL链接的消息。这几乎与电子邮件蠕虫使用的传播方法完全相同。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">卡巴斯基命名为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">IM-Worm.Mac.xxx, IM-Worm.OSX.xxx ：这两类都是感染Mac OS X系统及其上的应用程序。</span></p></li><li><p><span leaf="">IM-Worm.Win32.xxx ：windows系统上的及时通讯蠕虫</span></p></li><li><p><span leaf="">……</span></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">IRC-Worm：</span></span><span leaf="">此类型的蠕虫通过互联网中继聊天（Internet Relay Chat，简称：IRC）传播。 与邮件蠕虫类似，IRC蠕虫通过IRC频道传播主要有两种方式。第一种是发送一个指向蠕虫副本的URL链接。第二种则是将受感染文件发送给IRC频道用户。不过，接收方需要先接受该文件，将其保存到磁盘，然后才能打开（启动）它。</span></p><p><span leaf="">卡巴斯基命名为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC-Worm.Win32.xxx ：病毒体是win32可执行文件，自动向IRC的活动联系人发送带毒链接</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC-Worm.VBS.xxx ：病毒体为VB Script，通过IRC通道传播</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC-Worm.MSWord.xxx ：能够利用IRC传播的Word宏蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC-Worm.IRC.xxx ：在IRC内利用mIRC客户进行传播的蠕虫，本身可能是一个批命令或VBE程序</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">IRC-Worm.DOS.xxx ：病毒体为DOS可执行文件，利用mIRC客户传播</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">……</span></p></li></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">Net-Worm：</span></span><span leaf="">Net-Worms通过计算机网络传播。这种蠕虫的显著特征是<span textstyle="" style="font-weight: bold;">它不需要用户的操作即可传播</span>。 这类蠕虫病毒通常会扫描联网计算机上运行的软件中的关键漏洞。为了感染网络中的计算机，它会发送精心设计的网络数据包（称为“漏洞利用程序”），从而使蠕虫代码（或其部分）渗透并激活目标计算机。有时网络数据包仅包含用于下载并运行主蠕虫模块文件的代码片段。某些网络蠕虫会同时使用多个漏洞利用程序进行传播，从而加快其感染目标的速度。</span></p><p><span leaf="">卡巴斯基命名为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Net-Worm.Win32.xxx ：利用Windows漏洞进行主动攻击并传播的蠕虫，比较著名的像冲击波、Nimda等</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Net-Worm.Linux.xxx ：利用Linux系统漏洞传播的蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Net-Worm.Perl.xxx ：用Perl写的通过某些基于Perl的有漏洞的论坛传播的蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">……</span></p><p data-pm-slice="2 2 []"><span leaf=""><img data-imgfileid="100001976" class="rich_pages wxw-img" data-ratio="0.3057142857142857" data-s="300,640" data-type="png" data-w="350" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d127e8f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxviaTHBKiaqRUaYjXic6Gc3HBWxkgLicTC9awS5b4CT3YHyKic8sNo9eFNxng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"></ul><p><span leaf=""><span textstyle="" style="font-weight: bold;">P2P-Worm：</span></span><span leaf=""><span textstyle="" style="font-weight: normal;">P2P蠕虫通过点对点文件共享网络（如Kazaa、Grokster、EDonkey、FastTrack、Gnutella等）传播。 这类蠕虫的运作机制相对简单：要接入点对点网络，它们只需将自身复制到文件共享目录（通常位于本地计算机上）。剩下的工作由网络自动完成：当用户进行文件搜索时，这些蠕虫会主动通知远程用户存在该文件，并提供下载服务，让用户能够从受感染的计算机中获取文件。 还有更复杂的P2P蠕虫，它们模仿特定文件共享系统的网络协议，并对搜索查询做出积极反应；提供一个P2P蠕虫的副本作为匹配。</span></span></p><p><span leaf=""><span textstyle="" style="font-weight: normal;">卡巴斯基命名为：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">P2P-Worm.Win32.xxx ：目前只有这类，病毒体为Win32 PE文件，将自身拷入p2p系统的共享文件夹，有的会响应p2p请求并将自身传播给每个客户</span></p></li></ul><p data-pm-slice="2 3 []"><span leaf=""><span textstyle="" style="font-weight: bold;">Worm：</span></span><span leaf="">蠕虫通过网络资源在计算机网络上传播。与网络蠕虫</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">Net-Worm</span></span><span leaf="">不同，用户必须启动蠕虫才能激活它（</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;2 4 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">Net-Worm命名的蠕虫无需用户启动蠕虫就可以自动激活）</span></span><span leaf="">。 这类蠕虫会扫描远程计算机网络，并将自身复制到可读写访问的目录中（如果发现的话）。此外，这些蠕虫要么利用内置操作系统功能搜索可访问的网络目录，要么随机搜索互联网上的计算机，连接后试图完全控制这些计算机的磁盘。 此类别还涵盖那些由于某种原因而无法归入上文定义的其他类别的蠕虫（例如，用于移动设备的蠕虫）。</span></p><p><span leaf="">卡巴斯基命名为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.Win32.xxx ：32位windows系统上的蠕虫，病毒体为win PE文件。</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.SymbOS.xxx ：Symbian OS上传播的蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.SunOS.xxx ：Solaris/SunOS 上传播的蠕虫，有一些会攻击IIS Server</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.OSX.xxx ：Mac OSX上的蠕虫，有一些会通过蓝牙传播</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.FreeBSD.xxx ：FreeBSD上传播的蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.Acad.xxx：利用AutoCAD进行传播的蠕虫</span></p></li><li><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Worm.VBS.xxx：利用VBS进行传播蠕虫</span></p></li><li><p><span leaf="">Worm.Python.XXX：利用Python进行传播的蠕虫</span></p></li></ul><p style="text-align: left;"><font face="Tahoma"></font></p><p><span leaf=""><img data-imgfileid="100001975" class="rich_pages wxw-img" data-ratio="1.7191780821917808" data-s="300,640" data-type="png" data-w="292" style="width:299px;height:514px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d3821339&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvHnyCs3RB98r0bHp1eDSzVu6k2HiaEzIAnzZ1LgFDf92ZuC0PNr83vJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Tahoma;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;"><o:p></o:p></span></p><p style="text-indent: 2em;"><b><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">病毒和蠕虫的命名先介绍到这，木马的内容较多，分了19种，我们下一期单独讲。敬请关注。</span></font></b></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">敲字不易，如需转载文章：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">1、请先在大兵说安全的公众号后台留言，注明转载的【文章题目】以及转载的平台【您的公众号ID】，我会给您添加白名单授权。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">2、转载公众号文章请在文首备注以下信息：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">公众号：大兵说安全（ID：dabingshuoanquan)</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">作者：大兵</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">历史文章查看：</span></p><p style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e&amp;scene=21#wechat_redirect" textvalue="教你如何看懂杀毒软件病毒报告！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">教你如何看懂杀毒软件病毒报告！</span></a></span></p><p style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如果你被勒索病毒勒索了……</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485596&amp;idx=1&amp;sn=c9a3b93348577cf5f9ebb011bf8a02ec&amp;scene=21#wechat_redirect" textvalue="勒索软件 — 定义、预防和删除" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">勒索软件 — 定义、预防和删除</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">畅X通T+客户注意：又一个客户被加密勒索</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485046&amp;idx=1&amp;sn=bdd35742a878ef193e64143fea4c9d8f&amp;scene=21#wechat_redirect" textvalue="如何测试和选择一款适合的杀毒软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何测试和选择一款适合的杀毒软件</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485008&amp;idx=1&amp;sn=cbf94d2ee7838f5381a1052caef76b1c&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485016&amp;idx=1&amp;sn=1362d2886c2302c8e817e6e99f318789&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范（续）" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范（续）</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484997&amp;idx=1&amp;sn=7401f5b83f80b6fb2633a556cdbcf5e4&amp;scene=21#wechat_redirect" textvalue="从勒索病毒看医院网络安全体系建设" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从勒索病毒看医院网络安全体系建设</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484965&amp;idx=1&amp;sn=4d28dea19edf95387e9c6f594696f7f7&amp;scene=21#wechat_redirect" textvalue="如何构建安全体系防范勒索病毒" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何构建安全体系防范勒索病毒</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484958&amp;idx=1&amp;sn=389445cb6dd330a90d8ee5652d43c526&amp;scene=21#wechat_redirect" textvalue="原来，这才是网络安全中最重要的……" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">原来，这才是网络安全中最重要的……</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484889&amp;idx=1&amp;sn=f325e1a3fdbb5dd6988b88d6fd9cdf2d&amp;scene=21#wechat_redirect" textvalue="其实，预防勒索病毒没那么复杂！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">其实，预防勒索病毒没那么复杂！</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484686&amp;idx=1&amp;sn=66935926172b7f89c7f43abcdacaa769&amp;scene=21#wechat_redirect" textvalue="这一步做好，能减少一半被勒索的机会" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">这一步做好，能减少一半被勒索的机会</span></a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484280&amp;idx=1&amp;sn=04ed1bdf6e1ab53526580d9b4e83997d&amp;scene=21#wechat_redirect" textvalue="又双叒叕一家单位被勒索了！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">又双叒叕一家单位被勒索了！</span></a></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:Tahoma;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;"><o:p></o:p></span></p><p><span leaf="">欢迎关注：</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p><b><font face="Tahoma"></font></b></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485638">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2827a855&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485638%26idx%3D1%26sn%3D4a0f0cdff5e8473525cdcd903246ee23">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 24 Aug 2025 09:56:00 +0800</pubDate>
    </item>
    <item>
      <title>教你如何看懂杀毒软件病毒报告！</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485631&amp;idx=1&amp;sn=88825202b135d48663d11824a6c1b00e</link>
      <description>防病毒厂商对于病毒的命名都有一套基本规则，读懂了病毒报告便于你清晰的知道病毒类型和处理方法。本文教你如何根据病毒名称看懂病毒。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-08-11 07:00</span> <span style="display: inline-block;">河南</span>
</p>

<p>防病毒厂商对于病毒的命名都有一套基本规则，读懂了病毒报告便于你清晰的知道病毒类型和处理方法。本文教你如何根据病毒名称看懂病毒。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f3ebdf8d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvOCv08BvXGDMWRE473HWtOdXtDeANWQvF60pT03VIgoGI6x8uAdfmYQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;background-color: rgb(214, 214, 214);font-style: italic;">这是一篇迟到的作业，在2023年，我曾写过一篇文章《</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485377&amp;idx=1&amp;sn=27286d0e0fcf3fbf7ba29460c808d6a2&amp;scene=21#wechat_redirect" textvalue="教你一招，轻松变成反病毒高手" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;background-color: rgb(214, 214, 214);font-style: italic;">教你一招，轻松变成反病毒高手</span></a><span textstyle="" style="font-size: 14px;background-color: rgb(214, 214, 214);font-style: italic;">》，里面提到具体的类型下期再讲，结果一下让大家等一年多。废话不多说，开始正文。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 16px;letter-spacing: 0.034em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: 宋体;color: rgb(0, 109, 85);letter-spacing: 0pt;font-size: 13.5pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">我们在使用杀毒软件的时候，经常会看到杀毒软件提示感染了某病毒，我们该如何处理呢？要了解如何处理，首先就要明白这些提示所代表的含义，我们以卡巴斯基为例给大家讲一下如何根据病毒命名判断中了什么病毒以及如何处理。</span></span></strong></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001965" class="rich_pages wxw-img" data-ratio="0.5453703703703704" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f031247e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvWBvygjxQiaxfPwaqFXYiaK6aT3SVzLq18F2xNib7UaiaGHm7yjMwTGlzJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 16px;letter-spacing: 0.034em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: 宋体;color: rgb(0, 109, 85);letter-spacing: 0pt;font-size: 13.5pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">先来回顾一下上期讲的病毒命名规则：</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 16px;text-indent: 0pt;letter-spacing: 0.034em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: 宋体;color: rgb(0, 109, 85);letter-spacing: 0pt;font-size: 13.5pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">  [Prefix:]Behaviour.Platform.Name[.Variant]</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: Arial;color: rgb(0, 109, 85);letter-spacing: 0pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-size: 18px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></o:p></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: 宋体;font-size: 18px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">[前缀:]行为</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: Calibri;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">.</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">平台</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: Calibri;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">.</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">名字[</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: Calibri;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">.</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">变种]</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">其中前缀标识了检测到该对象的子系统。前缀“HEUR：”用于表示启发式分析器检测到的对象，前缀“PDM：”用于表示主动防御模块检测到的对象。</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 17px;letter-spacing: 0.034em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">前缀不是全名的强制性部分，也可能不存在。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Arial;color: rgb(35, 38, 39);letter-spacing: 0pt;font-size: 12pt;"><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></o:p></span><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">卡巴斯基将检测到的程序分为两大类：</span></span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">恶意程序</span></span></strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">和</span></span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">广告、色情及风险工具</span></span></strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">，恶意程序又分为四类：病毒和蠕虫、木马、可疑封装程序和恶意工具，在此基础上细化出了60种行为的恶意程序，如Trojan-downloader是一个下载型木马，在后台执行下载恶意程序，Trojan-Ransom表示是一个勒索型木马。</span></span></o:p><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Arial;color: rgb(35, 38, 39);letter-spacing: 0pt;font-size: 12pt;"><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Arial;color: rgb(35, 38, 39);letter-spacing: 0pt;font-size: 12pt;"><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></o:p></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">在平台方面，定义了操作系统、脚本语言、应用程序等48种运行平台，如W32表示运行在windows32位平台上，VBS表示该恶意程序是使用VBSCRIPT脚本编写的，MSEXCEL是表示该恶意程序是一个运行在EXCEL上的宏病毒。</span></span></span></p><p style="margin-right: 0pt;margin-left: 0pt;padding: 0pt;vertical-align: baseline;background: rgb(247, 247, 247);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Tahoma;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(247,247,247);mso-shading:rgb(247,247,247);"><font face="Tahoma"><span leaf=""><br/></span></font></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001723" class="rich_pages wxw-img" data-ratio="0.52421875" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c9c8b205&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqREfOqQ8Rqaa97XxNmxwFHZQSw9UL0TE4jqrhK9gCdWupicZCJsg4icv9UvFM12XfSKkfPVJQ6YpvJg%2F640%3Fwx_fmt%3Dpng"/></p><p data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p><p data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">那我们今天就来学习一下病毒命名中各代码所代表的含义。先来看看前缀。</span></font></p><p style="text-align: center;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 24px;">【前缀】</span></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">先来看前缀。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">前缀标识了检测到该对象的子系统，</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">卡巴斯基目前常用的前缀有以下几种：</span></font></p><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1、PDM (Proactive Defense Module):</span></span></strong></font></p><ol class="list-paddingleft-1" start="1"><ul class="list-paddingleft-1"><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">含义：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 主动防御模块。</span></font></p></li><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 这是卡巴斯基的行为监控组件。当它检测到一个正在运行的程序表现出</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">恶意行为模式</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">（例如尝试修改系统文件、注入代码、隐藏自身、窃取数据等）时，即使该程序不在病毒库中或未被启发式分析识别，PDM也会触发警报并阻止该行为。</span></font></p><p style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" nodeleaf=""><img data-imgfileid="100001959" class="rich_pages wxw-img" data-ratio="0.2697947214076246" data-s="300,640" data-type="png" data-w="1023" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=92c5d112&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxv0Q0T1z87EvBe4TPMcyHwlYXhdL0kktajvyibXcj6w0p9v3Tz51xOjkw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p></li><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">特点：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 基于</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">运行时行为</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">的检测，对未知威胁（零日漏洞攻击）非常有效。需要说明的是，有恶意行为的不一定是病毒程序，有时候正常的应用程序也可能会有恶意程序才有的恶意行为。这有可能是该程序使用了开源模块，里面包含一些恶意行为。也有可能是程序作者为了达到某些目的而采用了一些恶意动作。也有可能是该程序出于功能性需要而有该动作。需要管理员去判断或者提交给厂商进行进一步的分析。</span></font></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001972" class="rich_pages wxw-img" data-ratio="0.1695464362850972" data-s="300,640" data-type="png" data-w="926" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0e5abc10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvIPJ5xAv5VPBFibM5RaNPGTE36n5TEpVhGcN4QdIKVvoemQ5jf7XNLWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p></li></ul></ol><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2、HEUR (Heuristic Analysis):</span></span></strong></font></p><ol class="list-paddingleft-1" start="1"><ul class="list-paddingleft-1"><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">含义：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 启发式分析。</span></font></p></li><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 这是基于</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">静态和动态特征</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">的通用检测技术。卡巴斯基的引擎分析文件的代码结构、指令序列、API调用模式等，寻找与已知恶意软件家族相似或符合恶意软件典型特征的模式。它可以在没有精确病毒签名的情况下检测</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">新的或变种的恶意软件</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">。如果在扫描设置中开启启发式分析功能，就会触发该报警。</span></font></p><p style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" nodeleaf=""><img data-imgfileid="100001958" class="rich_pages wxw-img" data-ratio="0.6527777777777778" data-s="300,640" data-type="png" data-w="432" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d47faf3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvfFagJKnOBMKFSBWDufrSXLBqcOX8aygcpphMFEu1XaPR2cicjwib6NMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p></li><li><p><font face="Tahoma"><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">说明：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 你可能会看到 </span><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">HEUR:Trojan...</span></code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">, </span><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">HEUR:Backdoor...</span></code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 等，表示启发式引擎判断该文件属于哪一类恶意软件。有时后面还会跟 </span><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">.xx</span></code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> (如 </span><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">HEUR:Trojan.Win32.Generic.xx</span></code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">)，表示检测到的威胁家族或变种，</span><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">xx</span></code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 是家族标识符或内部编号。需要说明的是，有时候在第三方交付的安装中，也经常会出现该报警，说明代码中有与已知恶意软件家族相似或符合特征的代码，也可能该程序使用了某开源代码，其中有恶意代码存在，这也是供应链攻击经常用的一种手法。这时，不要一味的认为是误报（当然也可能有误报的可能），建议发给厂商进行分析。如下例，是在某医院的HIS安装程序中发现的恶意代码。</span></font></p></li></ul></ol><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001968" class="rich_pages wxw-img" data-ratio="0.24814814814814815" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3fe48918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvpfWMyzpk1UYwW4lCg2CMPsziaDqvSgN5BN9318gnrUMh4OYBIZG6JCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001973" class="rich_pages wxw-img" data-ratio="0.648936170212766" data-s="300,640" data-type="png" data-w="940" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7a40828f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvvJ10S58GENcdjiapPVTrILH7rvsVXO99OpZnUSWmMnOYenEhUZh9Xnw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><font face="Tahoma"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></font></p><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3、MEM (Memory Scan):</span></span></strong></p><ol class="list-paddingleft-1" start="1"><ul class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">含义：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 内存扫描。</span></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 表示该威胁是在</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">计算机内存 (RAM)</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 中被检测到的。卡巴斯基的扫描器在内存中发现了一段符合恶意软件特征的代码或注入的恶意模块。</span></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">场景：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 常见于检测文件无文件（Fileless Malware）攻击、恶意软件注入到合法进程中的代码、或解密后直接在内存中执行的恶意载荷。</span></p></li></ul></ol><p style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" nodeleaf=""><img data-imgfileid="100001964" class="rich_pages wxw-img" data-ratio="0.15239477503628446" data-s="300,640" data-type="png" data-w="689" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5f3cdb00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvRYsRSgibjE6aOChoYuOKCwNicWqtX3ABHuYNxjhfJwqBx9PicamERg5TA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4、UDS:</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;"> (Urgent Detection System)，紧急检测系统。</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释：</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这通常代表通过卡巴斯基安全网络 (KSN - Kaspersky Security Network) 进行的云检测。当用户的计算机检测到一个可疑对象时，它会立即查询卡巴斯基的云端数据库。如果云端数据库最近（通常是几小时内）收到了大量关于该对象的报告并确认其恶意性，就会通过 UDS 标记快速下发检测结果（MD5哈希值）。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">当该在本地执行的时候，卡巴斯基会自动将该程序的MD5值送入云端进行对比，发现该HASH被标识为恶意程序后，会自动阻止该文件运行，同时按照云端建议进行处理（响应）动作。从而达到免疫的效果。这也是被大家称为云拉黑功能的意思，就是该程序在云端已经被标记为恶意程序了，该文件已经被拉黑了，进入不了你的系统了。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001960" class="rich_pages wxw-img" data-ratio="0.5811209439528023" data-s="300,640" data-type="png" data-w="1017" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=97bad77e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvia4qNQkN6M3yT8uRTmDSAI9qgsTBjajkteHO6ibyguUf0VItfjV53m0Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">特点：</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">响应速度极快，用于快速拦截正在传播的新爆发威胁（如钓鱼邮件附件、勒索软件、利用新漏洞的恶意软件）。检测名称通常直接包含恶意软件家族名（如 上一篇（<a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485582&amp;idx=1&amp;sn=02edad71e1f926a150d2c4ef02be6ce8&amp;scene=21#wechat_redirect" textvalue="与银狐的一次亲密接触" data-itemshowtype="0" linktype="text" data-linktype="2">与银狐的一次亲密接触</a>）提到的</span><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">UDS:Trojan.W32.poolInject</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">）。UDS 检测最终会被整合到本地病毒库中，后续检测可能就不再显示 UDS 前缀。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001969" class="rich_pages wxw-img" data-ratio="0.2064814814814815" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9fb687d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvXcibG4kiamH0O6pK43xSNP4MqiceQ2PiaWgfsic6CgicZS6ptP2ibQIS8rmww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="2 4 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5、VHO:</span></span><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">（</span></span></span><font color="#ff0000"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">V</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">is</span></span><font color="#ff0000"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">H</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">ash </span></span><font color="#ff0000"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">O</span></span></font><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">ffline）</span></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">定义：VisHash特征，基于局部敏感哈希技术的机器学习检测，VisHash就是一种基于LSH（</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">局部敏感哈希（Locality Sensitive Hashing，LSH）</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">）的技术，一个VisHash可以通杀一批类似的恶意软件，具备一定的抗混淆能力。</span><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这是一个相对较新的前缀，这个比较不常见。</span></span></p><p data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释：主要用于标识那些经过</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">高度混淆或加壳</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">处理的恶意软件样本。</span></p><ul class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">特点：</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 强调检测对象使用了复杂的</span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">反分析技术</span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">。</span></p></li></ul><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6、not-a-virus:不是一个病毒</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">解释： 这是一个非常重要的前缀！它表示卡巴斯基检测到的对象不是传统意义上的病毒、木马、蠕虫等恶意软件，但可能具有潜在的不受欢迎行为或风险。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">关键点： 卡巴斯基默认会检测并报告这类软件，但是否将其移除由用户决定（通常在检测结果中会提供“忽略”或“不处理”选项）。用户需要根据自身情况判断这些软件是否是自愿安装和使用的。客户在设置中需要选择对应选项，才会出现类似报警。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">如果在卡巴斯基设置中<span textstyle="" style="font-weight: bold;">选中了广告软件、自动拨号程序和其他软件</span>，则当检测此类软件时，会出现not-a-virus的提示。</span></p><p data-pm-slice="2 2 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf=""><img data-imgfileid="100001963" class="rich_pages wxw-img" data-ratio="1.1091703056768558" data-s="300,640" data-type="png" data-w="687" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0acf483e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvK0EMBtgHicg3v9xkHZDdPmV0wtY9BwW6mYGCUa0wQ2LpJKT01V0rt6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001970" class="rich_pages wxw-img" data-ratio="0.2740740740740741" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=17847bff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvUZUPIicOf3lWocEqVxu6dqAwFYl1qLUqxOG3j5X6KtA3eAqUkZM2Wrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="2 4 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">主要分为三类：Adware</span><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(68, 68, 68); font-family: \&#34;Microsoft Yahei\&#34;, arial, helvetica, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(广告软件)、</span><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;2 2 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(68, 68, 68);font-family: \&#34;Microsoft Yahei\&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Pornware(色情软件）和</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Riskware (风险软件)。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001982" class="rich_pages wxw-img" data-ratio="1.3397435897435896" data-s="300,640" data-type="png" data-w="468" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d2ac2520&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRyfezOlPD3u5be4egU1obI424oeAcglR8Les5tianKbrpvmwxSNQ6oxVQZZPay5Zq2cfqKeUbBcWQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 4 []" style="line-height: 2em;"><span data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Adware</span><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(68, 68, 68); font-family: \&#34;Microsoft Yahei\&#34;, arial, helvetica, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">(广告软件)： 会显示大量广告、弹窗、修改浏览器设置、收集浏览习惯（通常用于广告目的）</span></span></span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []" style="line-height: 2em;"><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(68, 68, 68); font-family: \&#34;Microsoft Yahei\&#34;, arial, helvetica, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">Pornware(色情软件）：</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">是指向用户显示色情内容的程序。 用户可能有意安装Pornware类中的程序来搜索和获取色情内容。 另一方面，恶意用户也可以利用操作系统或浏览器漏洞，或者使用特洛伊木马程序（如下载器型木马和投放型木马）在用户的计算机上安装同样的程序。其通常目的是推送付费色情网站和服务的广告，而这些网站和服务是普通用户可能根本不会注意到的。包括以下三类：</span></span></p></li></ul><ol style="list-style-type: lower-roman;" class="list-paddingleft-2"><li><p data-pm-slice="3 3 []" style="text-indent: 0px;"><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><span textstyle="" style="font-size: 16px;">not-a-virus:Porn-Dialer     </span></span><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(68, 68, 68); font-family: \&#34;Microsoft Yahei\&#34;, arial, helvetica, sans-serif; font-size: 15px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 16px;"> 成人网站的拨号工具——这类程序会拨打成人内容电话服务、电话号码和 / 或特殊代码，这些内容都包含在程序主体中。与恶意程序不同，拨号程序会将其操作告知用户。</span></span></span></span><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><br/></span></span></p></li><li><p data-pm-slice="3 3 []" style="text-indent: 0px;"><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><span textstyle="" style="font-size: 16px;">not-a-virus:Porn-Downloader    成人网站的下载工具——</span></span><span leaf=""><span textstyle="" style="font-size: 16px;">此行为会从Internet将色情媒体文件下载到用户的计算机。 与恶意程序不同，此类程序会通知用户其操作。</span></span></span><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><br/></span></span></p></li><li><p data-pm-slice="3 3 []" style="text-indent: 0px;"><span style="color: rgb(68, 68, 68);font-family: &#34;Microsoft Yahei&#34;, arial, helvetica, sans-serif;font-size: 15px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><span textstyle="" style="font-size: 16px;">not-a-virus:Porn-Tool       成人软件工具——</span></span><span leaf=""><span textstyle="" style="font-size: 16px;">被归类为Porn-Tool的程序会在用户的计算机上搜索并显示色情内容（例如，用于Internet浏览器的特殊工具栏和特殊视频播放器）。</span></span></span></p></li></ol><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p data-pm-slice="2 2 []"><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Riskware (风险软件)： 合法的软件（如远程管理工具、密码破解工具、下载器、加密货币挖矿程序、拨号软件等），但如果被恶意利用或在用户不知情/非自愿的情况下安装运行，可能对用户的安全、隐私或系统资源构成风险。包括以下类别：</span></span></p><p><span leaf=""><br/></span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Client-IRC      风险软件之IRC客户端</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Dialer          风险软件之拨号程序</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Downloader      风险软件之下载器</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Monitor         风险软件之监视工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:PSWTool         风险软件之口令窃取工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:RemoteAdmin     风险软件之远程管理工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Server-FTP      风险软件之FTP客户端</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Server-Proxy    风险软件之代理程序</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Server-Telnet   风险软件之TELNET工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Server-Web      风险软件之WEB客户端</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:RiskTool        风险软件之风险工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:NetTool         风险软件之网络工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Client-P2P      风险软件之P2P客户端</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Client-SMTP     风险软件之SMTP客户端</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:WebToolbar      风险软件之WEB工具栏</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:FraudTool       风险软件之诈骗工具</span></p></li><li><p style="text-indent: 2em;line-height: 1.75em;"><span leaf="">not-a-virus:Hoax       风险软件之玩笑程序</span></p><p data-pm-slice="2 2 []"><span data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></span></p></li></ul><p style="text-indent: 2em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">以上是卡巴斯基病毒报告中出现的几种常见的前缀。没有标识前缀的，就是传统意义上的恶意程序，是经过工程师识别分析后的准确的恶意程序。当然，也有的有可能有两个前缀，如下例，主动防御模块识别出有恶意行为，是一个黑客工具，因此标识为不是病毒。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001971" class="rich_pages wxw-img" data-ratio="0.06732348111658457" data-s="300,640" data-type="png" data-w="609" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5fb81929&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxv1ibDibiaXvYibRFyZmQ1icxbdOUeHg1KeBUrJ1D2RUpD190ylf1yGEwgibnQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">启发式扫描模块扫描出包含广告代码，标注为不是病毒。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001974" class="rich_pages wxw-img" data-ratio="0.0593311758360302" data-s="300,640" data-type="png" data-w="927" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ac1f245e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqRqfSIJgTicVEGCN12GfQuxvMNKX0IvfI95R1XxqLnYVyn4vfKEhaUic69MbC9vZ9pwNr2ppBfhny3A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><span leaf="">据公司技术人员说，还看到了一个ML开头的，代表机器学习模块的前缀，不过当时没有截图，所以不确定，以后遇到了再补充。</span></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">下期接着讲关于病毒命名中类型的介绍。敬请关注</span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><br/></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">前期文章回顾：</span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485377&amp;idx=1&amp;sn=27286d0e0fcf3fbf7ba29460c808d6a2&amp;scene=21#wechat_redirect" textvalue="教你一招，轻松变成反病毒高手" data-itemshowtype="0" linktype="text" data-linktype="2">教你一招，轻松变成反病毒高手</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132&amp;scene=21#wechat_redirect" textvalue="如果你被勒索病毒勒索了……" data-itemshowtype="0" linktype="text" data-linktype="2">如果你被勒索病毒勒索了……</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485582&amp;idx=1&amp;sn=02edad71e1f926a150d2c4ef02be6ce8&amp;scene=21#wechat_redirect" textvalue="与银狐的一次亲密接触" data-itemshowtype="0" linktype="text" data-linktype="2">与银狐的一次亲密接触</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2">畅X通T+客户注意：又一个客户被加密勒索</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485492&amp;idx=1&amp;sn=c6381e936653651cf534303e386f8c14&amp;scene=21#wechat_redirect" textvalue="世界备份日，今天你备份了吗？" data-itemshowtype="0" linktype="text" data-linktype="2">世界备份日，今天你备份了吗？</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485417&amp;idx=1&amp;sn=ede017c44af0c0a4fab8d2d60a13a617&amp;scene=21#wechat_redirect" textvalue="2025年，杀毒软件要凉了吗？" data-itemshowtype="0" linktype="text" data-linktype="2">2025年，杀毒软件要凉了吗？</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485497&amp;idx=1&amp;sn=d7b45714e9bc24f9a11c7683ca56242f&amp;scene=21#wechat_redirect" textvalue="也来聊聊威胁情报（二）" data-itemshowtype="0" linktype="text" data-linktype="2">也来聊聊威胁情报（二）</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485441&amp;idx=1&amp;sn=c01331076fcd255d6fe3d97749b4ce5e&amp;scene=21#wechat_redirect" textvalue="也来聊聊威胁情报（一）" data-itemshowtype="0" linktype="text" data-linktype="2">也来聊聊威胁情报（一）</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485469&amp;idx=1&amp;sn=1a0c151e8a4e49c9905d4ed771711df1&amp;scene=21#wechat_redirect" textvalue="315，也来打打安全圈的假（二）" data-itemshowtype="0" linktype="text" data-linktype="2">315，也来打打安全圈的假（二）</a></span></font></p><p style="text-indent: 2em;" data-pm-slice="0 0 []"><font face="Tahoma"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485459&amp;idx=1&amp;sn=59ea874337f518c82e5cbccdba782824&amp;scene=21#wechat_redirect" textvalue="315，我们也来打打安全圈的假（一）" data-itemshowtype="0" linktype="text" data-linktype="2">315，我们也来打打安全圈的假（一）</a></span></font></p><p><span leaf=""><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485631">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=01fd09d1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485631%26idx%3D1%26sn%3D88825202b135d48663d11824a6c1b00e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 Aug 2025 07:00:00 +0800</pubDate>
    </item>
    <item>
      <title>如果你被勒索病毒勒索了……</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485604&amp;idx=1&amp;sn=08fc8f81794852dcf94e56b43b6cf132</link>
      <description>最近，又收到好多关于电脑被勒索的消息。本文针对非专业人员，告诉你关于勒索病毒的一些基本常识。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-08-07 15:34</span> <span style="display: inline-block;">河南</span>
</p>

<p>最近，又收到好多关于电脑被勒索的消息。本文针对非专业人员，告诉你关于勒索病毒的一些基本常识。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b8803bf1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSrjk07B3zrrD9hJ3oJnxlIwm2rbiaBWbG7gIfib0wuiaJk6Zqg8vWuXwkYt1C82We0jIBXg7vLaaaZQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">最近，又收到好多关于电脑被勒索的消息。而且有几个共同点：</span></p><p style="text-indent: 2em;"><span leaf="">1、都是财务系统，用的国内某著名的财务软件。</span></p><p style="text-indent: 2em;"><span leaf="">2、都是小微型企业，财务部门只有一两台电脑。</span></p><p style="text-indent: 2em;"><span leaf="">3、没有管理员，老板自己对电脑也是不懂。</span></p><p style="text-indent: 2em;"><span leaf="">虽然之前写过很多关于勒索病毒的文章，比如这篇《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484645&amp;idx=1&amp;sn=c49e968b65f1e2ebb1e653f802a94684&amp;scene=21#wechat_redirect" textvalue="注意：新一轮勒索病毒攻击医院行业" data-itemshowtype="0" linktype="text" data-linktype="2">注意：新一轮勒索病毒攻击医院行业</a>》，阅读量将近七万，解答了关于勒索病毒一些常见的问题，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">但都是针对技术人员的，专业性较强，一些用户反映看不懂。</span></p><p style="text-indent: 2em;"><span leaf="">今天这篇文章针对的是对电脑和病毒一窍不通的普通工作人员和老板。如果你很懂，请跳过。</span></p><p style="text-indent: 2em;"><span leaf=""><img data-imgfileid="100000432" class="rich_pages wxw-img" data-ratio="0.5625" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2155487e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSr72FSWnQeV20BOgMO41v9icX4ngfH6fic7iadEhMadC0ayxeOwJv7pjpkwJhFibUuNSd6tiaJtKoxmTw%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-indent: 2em;"><span leaf="">针对大家提出的几个问题我逐一回答，尽量用通俗的语言。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">一、啥是勒索病毒？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：顾名思义，就是一种病毒，把你电脑上的文件都加密了，打不开了，只有向黑客支付赎金才能继续使用，就跟我们社会上遇到的勒索事件一样，不过这次的人质不是人，是你电脑上的文件。所以叫勒索病毒。</span></p><p style="text-indent: 2em;"><span leaf="">对你来说，是要钱还是要数据？</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001940" class="rich_pages wxw-img" data-ratio="0.7525773195876289" data-s="300,640" data-w="873" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=35fc0a42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSBhpKCDxZBEk7K3aO09WXLFhib4hHib2tSAM5Sia3iceeCwhglrNMz7KEiaYwTWvGGEdaglRNludmjfmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">二、我怎么知道是不是被勒索了？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：被勒索后的一个典型特征就是你的文件打不开了，所有文件后面都增加了一个后缀。黑客还会留下一封勒索信，告诉你要付多少钱以及如何联系黑客。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001012" class="rich_pages wxw-img" data-ratio="0.463768115942029" data-s="300,640" data-type="jpeg" data-w="759" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e31ae647&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqShBAgzDvWLrVUL9qia98Uaxvuvm7kTaeoQH0XeqcdLW8vmJG0vhr2HwibC9fddKNEC6eM84l0X2pUA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000775" class="rich_pages wxw-img" data-ratio="0.7560777957860616" data-s="300,640" data-type="png" data-w="1234" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4aed8b97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqTfEhk540ibd6jP8zz7XWpeIy98U8URYZicSfUJbia7KGkpH0jWNDsD9EsfKWGepBsPZWZwtYIc4kicrQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">三、问：我们是小企业，为啥会勒索我？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：目前，很多电脑上存在漏洞，有操作系统的，也是应用软件的，比如财务软件，《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2">畅X通T+客户注意：又一个客户被加密勒索</a>》，这些漏洞一旦公布出去，就会有大量黑客在互联网上扫描有这些漏洞的主机。就像一个人在走廊里挨个敲门，如果你家的也有这个漏洞，他就进来了。既然进来了，就顺便把你的文件加密一下，你愿意付钱了，就小赚一笔，不愿意就拉倒，对黑客来说也没啥损失。最近小微型企业中招多，有几个原因：</span></p><p style="text-indent: 2em;"><span leaf="">1、因为小微型企业对安全不重视，也没有管理员，老板也不舍得花钱进行安全上的投资。没有任何安全措施，或者使用一些免费的不专业的安全产品。</span></p><p style="text-indent: 2em;"><span leaf="">2、安全意识差，电脑开机没有密码或者很简单，没有安装专业杀毒软件、没有防火墙、没有备份，有的有备份但是备份在同一台电脑上，从来不给电脑和应用程序打补丁、电脑从来不关机等等。</span></p><p style="text-indent: 2em;"><span leaf="">3、对于黑客来说，这样的客户就是一个最佳选择，防护差，又容易赚到钱，还不容易被抓。所以有越来的越多的人铤而走险。</span></p><p style="text-indent: 2em;"><span leaf="">对于这些没有安全措施和意识，又经常上网的电脑来说，就跟家里没门、没锁、大门敞开是一个道理。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">四、这都是偶然现象，被勒索的都是运气不好的。</span></span></p><p style="text-indent: 2em;"><span leaf="">答：人们普遍都有这样的心理，看到好事都想自己也有这样的运气，所以看到别人中彩票，就会去买。看到别人出事就认为是运气问题，跟自己无关。</span></p><p style="text-indent: 2em;"><span leaf="">准确的说，不是被勒索的运气不好。是你运气有点好。对于网络安全来说，就目前大家的安全意识和防护水平，出事是必然的，不出事是偶然的，只是中招时间问题，只是损失大小问题。</span></p><p style="text-indent: 2em;"><span leaf="">只要你的电脑上有有价值的数据，那就一定会受到黑客的觊觎。</span></p><p style="text-indent: 2em;"><span leaf="">普通人吃一堑长一智，聪明人看到别人吃堑自己长智。不要等到出事了再想起来保护，有可能是你无法承受的痛。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">五、既然是勒索，黑客为啥不联系我们，也没有收到黑客的电话啊？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：既然是黑客，干的是见不得人的事，怎么会电话联系你呢？一打电话不就暴露了吗？这是违法的事，被抓了是要被判刑的。再说了，黑客也不知道你是谁，怎么联系你？黑客很大可能也不是国内的。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">六、不打电话怎么收钱呢？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：黑客加密完你的文件，会在你的电脑内留下一封勒索信，上面有黑客的邮箱（这个邮箱也不会是国内的），有的还会有暗网地址，需要你主动跟他联系。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">七、我联系不上黑客，能不能找人解密文件？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：黑客用的是国际上常用的加密方法进行的加密，必须要有密钥（你可以理解为钥匙或者密码）才能解密，没有密钥是解不开的。如果能解开，那就乱套了，因为现在国际上通用的都是这个方法加密的，如果谁能解开，就封神了，世界上所有的加密可能都要失效了。所以说，被加密的文件是无法解密的，除非有密钥。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">八、为什么有人说可以解密文件？也确实有人恢复了数据。</span></span></p><p style="text-indent: 2em;"><span leaf="">答：刚才说了，解密是不可能的，除非你有密钥。但是如果是某些数据库文件有恢复的可能，但这不是解密，也仅仅是可能，并不是所有的都能恢复。而其他文件比如文档文件（DOC\XLS\PPT等）、照片、压缩文件等是不能恢复的。</span></p><p style="text-indent: 2em;"><span leaf="">确实是有人解密了，有几种可能：</span></p><p style="text-indent: 2em;"><span leaf="">1、对方替你联系了黑客，支付了赎金，他从中赚个差价。这是最常见的一种可能。</span></p><p style="text-indent: 2em;"><span leaf="">2、该病毒的密钥已经公布。《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484415&amp;idx=1&amp;sn=71b7031266668ce5a624f8097f7bc57d&amp;scene=21#wechat_redirect" textvalue="来看看你被勒索病毒加密的文件是否可解" data-itemshowtype="0" linktype="text" data-linktype="2">来看看你被勒索病毒加密的文件是否可解</a>》《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484457&amp;idx=1&amp;sn=76194f606bcb9345ab5b8fddcd7b1bc1&amp;scene=21#wechat_redirect" textvalue="号称完美破解GandCrab勒索病毒的某厂商，你真的不会脸红吗？" data-itemshowtype="0" linktype="text" data-linktype="2">号称完美破解GandCrab勒索病毒的某厂商，你真的不会脸红吗？</a>》</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">九、我到底要不要付费给黑客或者恢复数据的人？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：这要看你的数据重要不重要，你认为值，就付费，认为不值，就不付费。但我们不鼓励付费给黑客。这样会鼓励黑客行为。勒索病毒之所以会这么猖狂，就是因为太多人付费给他们，赚钱太容易了，如果大家都不付费，或许就不会有这么多人愿意当黑客去勒索别人了。</span></p><p style="text-indent: 2em;"><span leaf="">恢复数据库是一个技术活，靠能力吃饭，付费是应该的，但付多少合适，你根据你数据的价值自己估计。</span></p><div style="text-indent: 2em;"><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]"><span textstyle="" style="font-weight: bold;">十、恢复数据付多少钱合适？</span></span></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: normal;">答：恢复数据库多少钱划算，这个我不好回答，你可以参考几个金额，一是黑客勒索信中要支付的赎金的金额。当前的比特币汇率是一比特币兑换人民币82.2万人民币。我曾经过见黑客要几十个比特币的。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: normal;">二是放弃这些数据给你带来的损失，包括重建这些数据所需要的人工等因素。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001950" class="rich_pages wxw-img" data-ratio="0.3148496240601504" data-s="300,640" data-type="png" data-w="1064" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8569f3f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSrjk07B3zrrD9hJ3oJnxlIjibSCYEyhlDcC4MP2BjwETkfMqgXXkoXO11GI7z4BTApabbiceEVsMdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p></div><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">十一、如果我要向黑客付费，应该怎么转账？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：黑客不会通过正常的支付渠道让你支付的，这样会被抓。勒索病毒的黑客都是通过数据货币进行收款的，比如比特币，这样可以逃脱警察监控。但我国目前已经禁止了比特币交易，必须得翻墙才可以，所以如果你不懂，可以交给懂的人去（比如一些公司代理），但对方会收取一定的手续费。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">十二、中毒之后我该怎么办？有人说格式化系统就没有病毒了，有人说换个网卡就行了，我该听谁的？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：听到过太多不懂的技术人员给客户瞎指挥，安全和反病毒是个专业活，不是所有会用计算机的都懂，别听那些人瞎说，做为一名专业人士，给你的建议如下：</span></p><p style="text-indent: 2em;"><span leaf="">1、不要急于格式化和重装系统，这样会消除证据。如果不知道你这次为什么为会中毒，那么你下次还会继续中毒被勒索。所以要保留证据，不要格式化和重装，可以联系我们，做一个简单的取证，找到中毒的原因，避免下次中招。</span></p><p style="text-indent: 2em;"><span leaf="">2、跟网卡没关系。</span></p><p style="text-indent: 2em;"><span leaf="">3、检查你的系统，有没有病毒，有没有后门，有没有漏洞。找个专业的人检查并加固你的系统才是正事。</span></p><p style="text-indent: 2em;"><span leaf="">4、找个专业的公司给你做好预防措施和备份措施。这是最根本的解决办法。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">十三、中勒索后，我要不要报警？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：站在官方角度，</span><span leaf="">公司中遭遇勒索病毒攻击时，应当立即报案。勒索病毒攻击属于严重的网络犯罪行为，不仅可能对公司的数据安全造成严重威胁，还可能导致经济损失。及时报案是维护公司合法权益、打击犯罪行为的必要举措。也是每个公民的基本义务。</span><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">站在私人角度，友情提醒：如果报警，请不要自行处理和取证分析，以免担上毁灭证据的嫌疑。报警的同时也请先检查贵单位是否按等保的要求进行了安全建设，有没有采取安全措施。不然，根据网络安全法的规定，报警之后等到的可能是——<span textstyle="" style="font-weight: bold;">一张罚单</span>。因为你没有按照网络安全法的要求做好网络安全建设，这样的案例比比皆是。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001951" data-ratio="0.7086466165413534" data-s="300,640" type="block" data-type="png" data-w="1064" src="https://wechat2rss.xlab.app/img-proxy/?k=b4cebfbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSrjk07B3zrrD9hJ3oJnxlIgqy5OabWnRLkFBzTLqD1UbiaH0AmAGlYmhb0hOC8FQTrC1a9yxl8icNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001952" class="rich_pages wxw-img" data-ratio="0.3763940520446097" data-s="300,640" data-type="png" data-w="1076" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=719512b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSrjk07B3zrrD9hJ3oJnxlIel2WLsiaheicqgagcAGZaqw5nnBKnu6CeUGbcJ4V67F0z9wjmmd8S8icQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001953" class="rich_pages wxw-img" data-ratio="0.8361266294227188" data-s="300,640" data-type="png" data-w="1074" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=de8bc994&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSrjk07B3zrrD9hJ3oJnxlI7PQkichsFks85ibOIZLqCcwolwzMePa8JUcx05Fe01G2OGkgBRUTiaXdQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">十四、我以后该如何做，才能防止下次被勒索？</span></span></p><p style="text-indent: 2em;"><span leaf="">答：做好两件事：</span></p><p style="text-indent: 2em;"><span leaf="">1、<span textstyle="" style="font-weight: bold;">做好预防措施</span>，安装专业的防病毒软件，及时给系统打补丁，给内部员工做做安全培训，提升一下安全意识。</span></p><p style="text-indent: 2em;"><span leaf="">2、<span textstyle="" style="font-weight: bold;">做好备份</span>。<span textstyle="" style="font-weight: bold;">一定要有备份，一定不要备份到本电脑上。</span>看到太多用户，说起来也是有备份，但把数据从C盘备到D盘，那能有啥用嘞？一样会被勒索，一定要备份到另外的地方或者你用移动硬盘每天备份出来一份都行，但千万不要把移动硬盘长时间插到电脑上。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">如果你不懂怎么做，那么请交给专业的人去帮你。</span></span></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">我们有专门的解决方案，也有服务和托管方案，欢迎咨询。</span></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">如需转载文章：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">1、请先在大兵说安全的公众号后台留言，注明转载的【文章题目】以及转载的平台【您的公众号ID】，我会给您添加白名单授权。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">2、转载公众号文章请在文首备注以下信息：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">公众号：大兵说安全（ID：dabingshuoanquan)</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 14px;font-style: italic;">作者：大兵</span></span></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">以前还有一些相对专业的防勒索的文章，可以看看：</span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485596&amp;idx=1&amp;sn=c9a3b93348577cf5f9ebb011bf8a02ec&amp;scene=21#wechat_redirect" textvalue="勒索软件 — 定义、预防和删除" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">勒索软件 — 定义、预防和删除</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">畅X通T+客户注意：又一个客户被加密勒索</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485046&amp;idx=1&amp;sn=bdd35742a878ef193e64143fea4c9d8f&amp;scene=21#wechat_redirect" textvalue="如何测试和选择一款适合的杀毒软件" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何测试和选择一款适合的杀毒软件</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485008&amp;idx=1&amp;sn=cbf94d2ee7838f5381a1052caef76b1c&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485016&amp;idx=1&amp;sn=1362d2886c2302c8e817e6e99f318789&amp;scene=21#wechat_redirect" textvalue="从新型冠状病毒看勒索病毒防范（续）" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从新型冠状病毒看勒索病毒防范（续）</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484997&amp;idx=1&amp;sn=7401f5b83f80b6fb2633a556cdbcf5e4&amp;scene=21#wechat_redirect" textvalue="从勒索病毒看医院网络安全体系建设" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">从勒索病毒看医院网络安全体系建设</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484965&amp;idx=1&amp;sn=4d28dea19edf95387e9c6f594696f7f7&amp;scene=21#wechat_redirect" textvalue="如何构建安全体系防范勒索病毒" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">如何构建安全体系防范勒索病毒</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484958&amp;idx=1&amp;sn=389445cb6dd330a90d8ee5652d43c526&amp;scene=21#wechat_redirect" textvalue="原来，这才是网络安全中最重要的……" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">原来，这才是网络安全中最重要的……</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484889&amp;idx=1&amp;sn=f325e1a3fdbb5dd6988b88d6fd9cdf2d&amp;scene=21#wechat_redirect" textvalue="其实，预防勒索病毒没那么复杂！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">其实，预防勒索病毒没那么复杂！</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484686&amp;idx=1&amp;sn=66935926172b7f89c7f43abcdacaa769&amp;scene=21#wechat_redirect" textvalue="这一步做好，能减少一半被勒索的机会" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">这一步做好，能减少一半被勒索的机会</span></a></span></p><p style="text-indent: 2em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247484280&amp;idx=1&amp;sn=04ed1bdf6e1ab53526580d9b4e83997d&amp;scene=21#wechat_redirect" textvalue="又双叒叕一家单位被勒索了！" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 14px;font-style: italic;">又双叒叕一家单位被勒索了！</span></a></span></p><p><span leaf=""> 欢迎关注：大兵说安全</span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485604">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7bca21c5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485604%26idx%3D1%26sn%3D08fc8f81794852dcf94e56b43b6cf132">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2025 15:34:00 +0800</pubDate>
    </item>
    <item>
      <title>勒索软件 — 定义、预防和删除</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485596&amp;idx=1&amp;sn=c9a3b93348577cf5f9ebb011bf8a02ec</link>
      <description>这几年，勒索软件很火，今天就来聊聊啥是勒索软件？为啥让人闻之色变。勒索软件会对您和您的设备构成威胁，但是什么让这种形式的恶意软件这么特殊？</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-08-04 22:30</span> <span style="display: inline-block;">河南</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=886bdcff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSBhpKCDxZBEk7K3aO09WXLCDkz4wGeFfaPRjFzIypSORjr9DibxZVVhDyIbJia1Bhr8X3qRo5JXHSw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p><span leaf=""><img data-imgfileid="100001938" class="rich_pages wxw-img" data-ratio="0.5633802816901409" data-type="jpeg" data-w="710" src="https://wechat2rss.xlab.app/img-proxy/?k=d2644469&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSBhpKCDxZBEk7K3aO09WXLlqabtDic6LZt0UJUNFNKeic4uKPQCFjXH76EeA1nup2cfhKZqUYrwYWg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">这几年，勒索软件很火，今天就来聊聊啥是勒索软件？为啥让人闻之色变。</span></p><p style="text-indent: 2em;"><span leaf="">勒索软件会对您和您的设备构成威胁，但是什么让这种形式的恶意软件这么特殊？“勒索”这个词就告诉了您需要对这个祸害知道的一切。勒索软件是一种敲诈勒索软件，可以锁定您的计算机，或者加密你的文件，然后要求赎金进行释放。</span></p><p style="text-indent: 2em;"><span leaf="">就像他的名字：Ransomware。勒索和软件两个单词组成，首先他是一个软件，一个程序，其功能是锁定你的计算机或者加密你的文件。是不是觉得很面熟。市面上的加密软件或者以前我们曾经听过说的逻辑锁事件，是不是一回事？原理差不多，只不过性质不同。加密软件是按照文件所有者的意愿对文件进行加密，防止文件的泄露，而勒索软件加密你的文件完全没有经过所有者的同意，加密要要求支付赎金，是一种勒索行为。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001941" class="rich_pages wxw-img" data-ratio="0.6215316315205327" data-s="300,640" data-type="png" data-w="901" style="width:482px;height:299px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqSBhpKCDxZBEk7K3aO09WXLOJIt7SAqbFnOHMTHhOBAIXA7w2HDzibtXXOtWdaI0jjmjBR8T3gSIYg/640?wx_fmt=png&amp;from=appmsg" data-cropx1="104.63667820069205" data-cropx2="1005.2595155709342" data-cropy1="44.844290657439444" data-cropy2="603.5294117647059" src="https://wechat2rss.xlab.app/img-proxy/?k=8d7e52f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqTeXaX3wiaSDR9QyEyCEyJRxRpKO60gN59rhUT0QWcFxFgm1vkqxu9NpZfHzHDqbzHP5vpA8q83ia3w%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-indent: 2em;"><span leaf="">大多数情况下，勒索软件感染发生的步骤如下：</span></p><p style="text-indent: 2em;"><span leaf="">恶意软件首先获得对设备的访问权限。取决于勒索软件类型，整个操作系统或者单个文件会被加密。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001012" class="rich_pages wxw-img" data-ratio="0.463768115942029" data-s="300,640" data-type="jpeg" data-w="759" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e31ae647&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqShBAgzDvWLrVUL9qia98Uaxvuvm7kTaeoQH0XeqcdLW8vmJG0vhr2HwibC9fddKNEC6eM84l0X2pUA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001004" class="rich_pages wxw-img" data-ratio="0.625" data-s="300,640" data-type="jpeg" data-w="1200" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e7fd915d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqShBAgzDvWLrVUL9qia98UaxBSsr0UicZSeibicoonqIQCWREozH9z1AT7h2LNLX8HrTcibc8VuHibNO5LQ%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-indent: 2em;"><span leaf="">然后会向受害者索取赎金。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000775" class="rich_pages wxw-img" data-ratio="0.7560777957860616" data-s="300,640" data-type="png" data-w="1234" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4aed8b97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqTfEhk540ibd6jP8zz7XWpeIy98U8URYZicSfUJbia7KGkpH0jWNDsD9EsfKWGepBsPZWZwtYIc4kicrQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-indent: 2em;"><span leaf="">如果想要最小化勒索软件攻击的风险，您应该依靠高质量的终端安全软件，如XXXX（此处省略N个字）的EDR和反病毒软件。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;">勒索软件：恶意软件家族的一员</span></span></p><p style="text-indent: 2em;"><span leaf="">恶意软件是“恶意”和“软件”两个词的复合体。恶意软件这个词因此覆盖了所有可能对您的计算机有危险的恶意软件。这包括病毒和木马。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;">如何检测勒索软件和防御它</span></span></p><p style="text-indent: 2em;"><span leaf="">谈到防御勒索软件，预防胜于治疗。要做到这点，保持警惕和合适的安全软件至关重要。如果你不知道哪个杀毒软件好，可以参考一些国际上的测试机构的结果，如AVTEST(</span><span leaf=""><a href="https://www.av-test.org/)" target="_blank">https://www.av-test.org/)</a></span><span leaf="">、</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">AV-Comparatives(</span><span leaf="">AV-Comparatives.org)等。</span></p><p style="text-indent: 2em;"><span leaf="">漏洞扫描也可以帮助您发现系统中的侵入者。首先，确保您的计算机不成为勒索软件的理想目标很重要。设备软件应该始终保持最新，以便受益于最新的安全补丁。此外，加强安全意识，尤其是对于流氓网站和电子邮件附件，极其重要。</span></p><p style="text-indent: 2em;"><span leaf="">但是，即使最好的预防措施也可能失败，使得应急预案更加必不可少。就勒索软件而言，应急方案包括备份您的数据。要了解如何正确创建备份和可以采取什么其他措施来保护设备，请阅读我之前的文章。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">打击加密木马 — 您可以做到！</span></span></p><p style="text-indent: 2em;"><span leaf="">最普遍的勒索软件感染路线包括访问恶意网站、下载恶意附件或者下载时通过恶意添加组件。一次不经意就足以成为勒索软件攻击的受害者。由于恶意软件的目的是尽可能长不被检测到，要检测感染很难。</span></p><p style="text-indent: 2em;"><span leaf="">勒索软件攻击行为最有可能被安全软件检测到。</span><span leaf="">显然，文件扩展名变化、CPU 活动增加和计算机上的其它可疑活动可能表明有感染。</span></p><p style="text-indent: 2em;"><span leaf="">移除勒索软件时，基本上有三个选择可用：</span></p><p style="text-indent: 2em;"><span leaf="">第一个是支付赎金，这绝对不建议。</span></p><p style="text-indent: 2em;"><span leaf="">第二个是解密文件，这几乎不可能。</span></p><p style="text-indent: 2em;"><span leaf="">第三个，只剩下最后一步：进行系统和数据恢复，而进行恢复的前提是一定要有备份。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">有什么形式的勒索软件，对您意味着什么？</span></span></p><p style="text-indent: 2em;"><span leaf="">如上所述，勒索软件构成的威胁取决于病毒变种。首先要考虑的是有两种主要类别的勒索软件：锁定勒索软件和加密勒索软件。这些可以区分如下：</span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">锁定（Locker）勒索软件 – 计算机的基本功能会受影响</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">加密（Crypto ）勒索软件 — 单个文件被加密</span></span></p></li></ul><p style="text-indent: 2em;"><span leaf="">当涉及到识别和处理勒索软件时，恶意软件的类型也会产生巨大差异。在这两种主要的类别内，无数其它类型的勒索软件之间也有区别。例如，这些包括 Locky、WannaCry和 Bad Rabbit。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">勒索软件的发展史</span></span></p><p style="text-indent: 2em;"><span leaf="">用这种方式敲诈勒索计算机用户不是21世纪的发明。早在1989年就有人使用原始先驱版的勒索软件。2005 年，俄罗斯报道了首批勒索软件的具体案例。自那时起，勒索软件传遍全球，新类型不断得手。2011年，人们观察到勒索软件攻击急剧增长。在进一步攻击的过程中，反病毒软件制造商日益将病毒扫描程序聚焦于勒索软件，特别是从2016年以来。</span></p><p style="text-indent: 2em;"><span leaf="">经常可以在各种勒索软件攻击中看到地区差异。例如：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">有关未授权应用程序的不正确消息：</span></span></p></li></ul><p style="text-indent: 2em;"><span leaf="">在有些国家，木马程序会通知受害者他们的计算机上安装了未授权的软件。消息然后会提示用户付款。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">有关非法内容的假冒声明：</span></span></p></li></ul><p style="text-indent: 2em;"><span leaf="">在有的国家非法软件下载很普遍，这种做法对于网络犯罪分子来说不是特别成功。相反，勒索软件消息声称他们来自执法部门，在受害者的计算机上发现了儿童色情或其它非法内容。消息中还包含要求支付罚款。</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">最大的勒索软件攻击</span></span></p><p style="text-indent: 2em;"><span leaf="">最大和最严重的一次勒索软件攻击发生在2017年春天，叫作 <span textstyle="" style="color: rgb(217, 33, 66);font-weight: bold;">WannaCry</span>。在攻击过程中，约150个国家的200,000名受害者左右被要求用比特币支付赎金。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000243" class="rich_pages wxw-img" data-ratio="0.75" data-s="300,640" data-type="jpeg" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2732664b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqRIkbdWjkOYBuS0aZoDJJzlmvXhJgibEevmF126r00GAko3zmgwr2icIh3S78vM3B7EEo0Sx31Qiarrg%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000428" class="rich_pages wxw-img" data-ratio="0.708" data-s="300,640" data-type="png" data-w="500" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0820ea94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSr72FSWnQeV20BOgMO41v90SsAa6pcI7ibOsqjIViaMiae5NBdt6IH0iccuPbvBniaUzAaln05N1tSUYQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">结论</span></span></p><p style="text-indent: 2em;"><span leaf="">各种形式和变种的勒索软件对个人用户和公司都构成了巨大威胁。这使得警惕其构成的威胁并尽可能为各种后果做好准备变得更加重要。因此，了解勒索软件、使用设备时高度警惕、并拥有最好的安全软件至关重要。</span></p><p style="text-indent: 2em;"><span leaf="">“工欲善其事，必先利其器”，一个好的工具可以让你事半功倍。欢迎私信咨询。</span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">如需转载文章：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">1、请先在大兵说安全的公众号后台留言，注明转载的【文章题目】以及转载的平台【您的公众号ID】，我会给您添加白名单授权。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">2、转载公众号文章请在文首备注以下信息：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">公众号：大兵说安全（ID：dabingshuoanquan)</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">作者：大兵</span></span></p><p><span leaf=""><br/></span></p><p><span leaf="">历史文章：</span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485582&amp;idx=1&amp;sn=02edad71e1f926a150d2c4ef02be6ce8&amp;scene=21#wechat_redirect" textvalue="与银狐的一次亲密接触" data-itemshowtype="0" linktype="text" data-linktype="2">与银狐的一次亲密接触</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39&amp;scene=21#wechat_redirect" textvalue="畅X通T+客户注意：又一个客户被加密勒索" data-itemshowtype="0" linktype="text" data-linktype="2">畅X通T+客户注意：又一个客户被加密勒索</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485525&amp;idx=1&amp;sn=11976bc53c21ae868d7eaea652b63af3&amp;scene=21#wechat_redirect" textvalue="AV-C第一份EDR测试报告出炉！" data-itemshowtype="0" linktype="text" data-linktype="2">AV-C第一份EDR测试报告出炉！</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485459&amp;idx=1&amp;sn=59ea874337f518c82e5cbccdba782824&amp;scene=21#wechat_redirect" textvalue="315，我们也来打打安全圈的假（一）" data-itemshowtype="0" linktype="text" data-linktype="2">315，我们也来打打安全圈的假（一）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485469&amp;idx=1&amp;sn=1a0c151e8a4e49c9905d4ed771711df1&amp;scene=21#wechat_redirect" textvalue="315，也来打打安全圈的假（二）" data-itemshowtype="0" linktype="text" data-linktype="2">315，也来打打安全圈的假（二）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485417&amp;idx=1&amp;sn=ede017c44af0c0a4fab8d2d60a13a617&amp;scene=21#wechat_redirect" textvalue="2025年，杀毒软件要凉了吗？" data-itemshowtype="0" linktype="text" data-linktype="2">2025年，杀毒软件要凉了吗？</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485366&amp;idx=1&amp;sn=ca0ffb93b872fa7eb312c62c1eebd326&amp;scene=21#wechat_redirect" textvalue="从一次攻击过程看EDR的作用" data-itemshowtype="0" linktype="text" data-linktype="2">从一次攻击过程看EDR的作用</a></span></p><p><span leaf=""><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485596">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2c574c62&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485596%26idx%3D1%26sn%3Dc9a3b93348577cf5f9ebb011bf8a02ec">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 04 Aug 2025 22:30:00 +0800</pubDate>
    </item>
    <item>
      <title>与银狐的一次亲密接触</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485582&amp;idx=1&amp;sn=02edad71e1f926a150d2c4ef02be6ce8</link>
      <description>银狐是近年来比较火的一个病毒，经常有客户中招，今天结合前一段处理的一个银狐的案例来跟大家聊聊如何防治银狐攻击。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-07-27 10:22</span> <span style="display: inline-block;">河南</span>
</p>

<p>银狐是近年来比较火的一个病毒，经常有客户中招，今天结合前一段处理的一个银狐的案例来跟大家聊聊如何防治银狐攻击。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=42b9e501&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2Tialhye6nstO2icszlWSNg7cBrGk1KYPlu2ZpyOGUpqRBECj8L98iakG7xw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">银狐是近年来比较火的一个病毒，很多客户对此束手无策。每次培训，我都会讲到，但仍有不少客户中招，今天结合前一段处理的一个银狐的案例来跟大家聊聊如何防治银狐。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001931" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a11e6b0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2Tiakff5MKe3ghbXLfZMnaT5I9ZT0xLNY9TWJSH8abIv2EtgltyzalejeQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">事件发生</span></span></p><p style="text-indent: 2em;"><span leaf="">2025年4月30日下午四点左右，收到一个曾经的客户的信息中心负责人发来消息。说他单位同事通过微信给他发了一个可执行文件，他感觉有些可疑，但用杀毒软件扫描提示没有病毒。打电话给同事，同事说他没有发，这个文件不是他发的。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,null]">直觉告诉他这个文件有问题，于是打电话求助我们能否帮忙看一下是不是病毒。虽然他现在不是我们的客户，但一直保持的良好的沟通，对我们的产品和技术也一直很信任。</span></p><p><span leaf=""><img data-imgfileid="100001912" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0717488789237668" data-s="300,640" data-type="png" data-w="892" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bd291780&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQbtriavAU0lj7IiblrRA5HVTBg0h1H6GqzTdOiaWfSr42wZCgmyYZ0ZEocJiakm3sxDhXF3wkftgcibeA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">客户的描述来看，这应该又是一次银狐病毒的新变种。</span></p><p style="text-indent: 2em;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">分析过程</span></span></p><p style="text-indent: 2em;"><span leaf="">技术人员拿到样本后，上传到了VIRUSTOTAL网站，发现仅有5个杀毒软件可以发现该文件是病毒，绝大多数还不能识别。</span></p><p><span leaf=""><img data-imgfileid="100001915" class="rich_pages wxw-img" data-ratio="0.5009259259259259" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=aa279cdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaUMdn02XGQ2HPpfs76z9SiaKQJelibIOa38xWmLy3J5VdlsKMKRjtmF6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">用卡巴斯基扫描了一下，发现确实没有提示没有病毒。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001928" class="rich_pages wxw-img" data-ratio="0.5254942767950052" data-s="300,640" data-type="jpeg" data-w="961" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3bc1df99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaK75KsmV3jh8bpFjQZibmH3uSYtic82r3NfnE8iaekqvbia3EFCJIicxk4fA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001930" class="rich_pages wxw-img" data-ratio="0.5185972369819342" data-s="300,640" data-type="jpeg" data-w="941" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=404f6d58&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiasciaGsictEcHibKszN7WEibyrt46TnXslkqicMQsTCt1RiaXLv5NofpYaubA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">但在执行该样本的时候（友情提示，请勿在自己的电脑上执行），卡巴阻止了该程序的运行并删除了该文件。报告中显示的名字为：UDS:Trojan.W32.poolInject。</span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001916" data-ratio="0.5806831566548881" data-s="300,640" type="block" data-type="png" data-w="849" src="https://wechat2rss.xlab.app/img-proxy/?k=6430bce9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaRd6xo02pPE2tWWx2Zpia4EgSjicU5B6rN34FZV7VqOtmhiczFe7cIkcMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">其实，对于普通用户来讲，到这里基本就可以结束了，证明了该文件是一个病毒，卡巴也把他拦截并删除了。前期测试过程如下：</span></p><p class="channels_iframe_wrp" nodeleaf=""><div></div></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf=""><br/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">但做为一个专业的安全公司和一群喜欢研究病毒的技术人员，我们不能止步于此。我们还要进行更详细的分析，这到底是什么病毒？怎么工作的？我该如何防范？</span></p><p data-pm-slice="2 2 []"><span leaf="">下面我们接着分析：</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">首先我们来分析一下这个病毒名称，就能得到很多信息。我之前写过一篇文章，讲</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;2 2 []&#34;,&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">关于病毒的命名，详见（<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485377&amp;idx=1&amp;sn=27286d0e0fcf3fbf7ba29460c808d6a2&amp;scene=21#wechat_redirect" textvalue="教你一招，轻松变成反病毒高手" data-itemshowtype="0" linktype="text" data-linktype="2">教你一招，轻松变成反病毒高手</a>），杀毒软件对病毒的命名是是一个规则的。以卡巴为例，他的病毒命名规则是：</span></p><h3 style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 0px 0pt;padding: 0pt;outline: 0px;font-weight: 400;font-size: 16px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-indent: 0pt;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background: rgb(255, 255, 255);text-align: center;" data-pm-slice="0 0 []"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Arial;color: rgb(0, 109, 85);letter-spacing: 0pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-size: 18px;"><span leaf="">[Prefix:]Behaviour.Platform.Name[.Variant]</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Arial;color: rgb(0, 109, 85);letter-spacing: 0pt;background-image: initial;background-position: initial;background-size: initial;background-repeat: initial;background-attachment: initial;background-origin: initial;background-clip: initial;font-size: 18px;"><o:p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></o:p></span></strong></h3><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: 宋体;font-size: 18px;"><span leaf="">[前缀:]行为</span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Calibri;"><span leaf="">.</span></span><span leaf="">平台</span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Calibri;"><span leaf="">.</span></span><span leaf="">名字[</span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: Calibri;"><span leaf="">.</span></span><span leaf="">变种]</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 2em;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">其中前缀标识了检测到该对象的子系统。前缀“HEUR：”用于表示启发式分析器检测到的对象，前缀“PDM：”用于表示主动防御模块检测到的对象。</span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 17px;letter-spacing: 0.034em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">前缀不是全名的强制性部分，也可能不存在。</span></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;2 2 []&#34;,&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">第二部分是行为，表明了该恶意程序的类型。</span><span leaf=""><br/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">第三部分是平台，表明了该恶意程序运行的平台。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">第四部分是名称，是对该病毒的命名。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">我们看一下这个病毒的名字：</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">UDS:Trojan.W32.poolInject</span><span leaf=""><br/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">熟悉卡巴斯基的同学都知道，如果一个病毒命名被标识为UDS，意味着该病毒是在云端被发现，但还没有具体的特征码，没有被加入病毒库中。UDS，是</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Urgent Detection System的缩写，紧急检测系统，也有人称之为云拉黑功能。这个功能是啥意思呢？</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">如果一个程序被送入卡巴斯基云网络（KSN）或者情报平台(TIP），利用其云沙箱进行分析，一旦检测到该程序是恶意程序，会记录该文件的HASH，如MD5。当该在本地执行的时候，卡巴斯基会自动将该程序的MD5值送入云端进行对比，发现该HASH被标识为恶意程序后，会自动阻止该文件运行，同时按照云端建议进行处理（响应）动作。从而达到免疫的效果。这也是被大家称为云拉黑功能的意思，就是该程序在云端已经被标记为恶意程序了，该文件已经被拉黑了，进入不了你的系统了。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">第二个关键字是Trojan，说明这是一个木马程序，</span><span leaf="">木马通常伪装成合法软件，诱骗用户执行，然后在后台执行恶意操作，</span><span leaf="">既然是木马，一定会有一些木马该有的动作，比如连接远程的服务器、盗窃文件、控制键盘、控制摄像头、打开端口之类的动作。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">第三个关键字是Win32，说明这是一个主要运行在32位Windows平台的恶意程序（当然也有可能会在64位平台上运行）。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">第四个关键字是PoolInject。根据命名规则，如果是技术人员分析过程序，提出了特征码，那么这个命名一般跟特征码有一定关系，而没有经过这个过程的命名，一般跟该程序的技术特征有关。从这个命名来看，有两个关键点，一个是POOL，一个是INJECT。说明该恶意程序使用了内存池注入技术。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf=""><br/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">补充知识点，什么是内存池注入技术：</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">内存池注入技术是一种相对高级且隐蔽性较强的代码注入技术，其目的在逃避传统安全软件的检测。其核心思路如下：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">1、利用合法进程： 木马首先会找到一个正在运行的、受信任的、通常是系统关键或常见的进程（如 explorer.exe, svchost.exe, rundll32.exe 等）。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">2、操作内存池： 恶意代码会利用 Windows 内核中管理内存池的机制或相关的漏洞（可能涉及未公开的 API 调用、利用特定对象类型等），在目标进程的地址空间内分配一块可执行的内存区域。关键在于，这块内存是通过操作内存池管理器获得的，因此不容易被杀毒软件监控。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">3、写入恶意代码： 木马将自己的一部分恶意代码（通常是 Shellcode - 一段能执行特定任务的机器码）写入到这块分配好的内存区域中。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">4、执行恶意代码： 木马通过某种方式（如创建远程线程、利用异步过程调用、劫持线程执行流等）触发目标进程去执行写入到内存池中的那段恶意代码。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">5、隐藏与持久化： 恶意代码在受信进程内部运行，继承了该进程的权限和信任级别。这使得恶意活动看起来像是来自合法进程，大大增加了检测难度。该注入技术本身也使得在内存中定位恶意代码变得困难。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">*以上内容来自网络</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf=""><br/></span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">初步分析：该恶意程序是一个使用内存池注入技术的木马。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">下面我们继续分析。</span></p><p data-pm-slice="2 2 []" style="text-indent: 2em;"><span leaf="">技术人员将该程序丢入卡巴斯基情报平台，发现4月30日凌晨6点已经收录该程序并在沙箱中检测为恶意威胁。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001917" data-ratio="0.4556830031282586" data-s="300,640" type="block" data-type="png" data-w="959" src="https://wechat2rss.xlab.app/img-proxy/?k=4e0e4a24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiahZVUicNzJ9J6YuCfwyUdkEnibicicOgsaCbeUUSJibq7BWh0827JwxRog7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">利用卡巴斯基沙箱进一步分析附件包含的病毒，发现该程序采用诱骗客户点击附件后自动运行的方式植入键盘记录器等后门。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001918" data-ratio="0.4583333333333333" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=39ef19e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaLXU5EQgesnfDtJ9iawuCWG124LycQib2c3MxpBtDZAtakomNVPNBVRpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001919" class="rich_pages wxw-img" data-ratio="0.5605726872246696" data-s="300,640" data-type="png" data-w="908" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=57026e00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiazH1DFyIic29memSvYXugUm42Ee0MW2TN1lS4ElFHPM1ZSnsOxqx7FQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><img data-imgfileid="100001920" class="rich_pages wxw-img" data-ratio="0.6407407407407407" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5d1e4f34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaUvTiciaEMYvDxtNP0BiakDccmU7OCxAVdoomlCaBMnRpx8BEZrkXumcmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">同时，该恶意程序为了逃避沙箱的检测，还有规避措施，检测运行环境是否为虚拟环境。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001921" data-ratio="0.5928571428571429" data-s="300,640" type="block" data-type="png" data-w="420" src="https://wechat2rss.xlab.app/img-proxy/?k=659a0e00&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiafoHCjDFquc6gVuIB18k4a0FOSrvBpJNOgkMKKOibqicViaNJJ8hUQHlgQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">并进行权限提升和访问令牌操作。安装键盘记录器，持续记录相关动作。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001922" data-ratio="1.5140845070422535" data-s="300,640" type="block" data-type="png" data-w="426" src="https://wechat2rss.xlab.app/img-proxy/?k=2905d48c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaqKGuy6uPMH7OdQeobxEwxicYibHpeDVBI8XoKlsMibIaB1M2BYVDvicIRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">除了在情报平台分析之外，技术人员还关闭了卡巴斯基杀毒软件后在本地运行了该程序 ，通过EDR检测到了该程序的动作。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001924" data-ratio="0.45185185185185184" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8bf1883d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2Tiasib8gTu12FIk3Chkfh1WY2bf9YtI0icoLNgepR7z7xjT7o4qSGQgbMJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001923" data-ratio="0.40208333333333335" data-s="300,640" type="block" data-type="png" data-w="960" src="https://wechat2rss.xlab.app/img-proxy/?k=c0d2084f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2Tia3OuHsNibJCVTXLjeMauibrhdGFlIsFbrszEPiaEVHJ2WHibibicg1jpWr2IA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p></div><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001925" data-ratio="0.362962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bad5e4ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2Tia4sSIC5ZicxT0IW8qZiaLVumkK9yQictaKo6SPxXgXx1icmScLdmqujh4UA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">可以清晰地看到该程序注入到了系统的SVCHOST进程。在内存池中写入代码、连接远程主机（124.156.115.170:80），等等动作。更详细的内容就不点开细说了，有兴趣的朋友私下交流。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001926" data-ratio="0.9044776119402985" data-s="300,640" type="block" data-type="png" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=36237711&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqQ89sHPnaoPTZiaZ27eiaD2TiaicdpiaQaXMqvndc36R0OmUibE79FpCBJLSJibfvdrncD02FHFpHQfRjduw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p style="text-indent: 2em;"><span leaf="">关于这个病毒的分析就先到这里。下一期我们来聊聊这个银狐病毒的传播方式及防范难点和要点。敬请关注。</span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">*感谢技术工程师刘西亮同学、崔兴耀同学的处理和分析过程</span></span></p><p><span leaf=""><br/></span></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">欢迎关注：大兵说安全</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0" data-service_type="1" data-verify_status="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485582">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d5afd3ee&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485582%26idx%3D1%26sn%3D02edad71e1f926a150d2c4ef02be6ce8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 27 Jul 2025 10:22:00 +0800</pubDate>
    </item>
    <item>
      <title>2025网络安全人才生态调查</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485559&amp;idx=1&amp;sn=3c55f3ee2775664cc20e572a27083104</link>
      <description>国家网络安全人才与创新基地编制《2025网络安全人才白皮书》，需要对对网信安全从业人员调研，欢迎大家踊跃参与，共同为网络安全人才建设献言献策。</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-07-01 11:53</span> <span style="display: inline-block;">河南</span>
</p>

<p>国家网络安全人才与创新基地编制《2025网络安全人才白皮书》，需要对对网信安全从业人员调研，欢迎大家踊跃参与，共同为网络安全人才建设献言献策。</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2ba22daa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqS1arjymjdlkjDjvHIXO6wwpkvDpfeHVfJyaSHfrne8szT2cCO8OMicicXIsvArKUIP670ULf1UNldA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<div id="js_image_content" class="image_content "><h1 class="rich_media_title ">2025网络安全人才生态调查</h1> <p id="js_image_desc" class="share_notice js_underline_content "></p> <!---->   <!----> <!----> <!----> <!----> <!----> <div id="js_end_poi_area" class="end_poi_area "></div> <!----> <!----> <div class="rich_media_tool "><div class="rich_media_info weui-flex policy_tips js_ad_policy_tips tips_global_primary "><!----></div></div> </div>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=14b35d07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqS1arjymjdlkjDjvHIXO6wwXoym7wyqmPqxk8Q5PQLnfVm1SDLleRdgbnS3tUgnCvHuibakzHQUuuQ%2F0%3Fwx_fmt%3Djpeg"/></p>




<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=54fadccc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485559%26idx%3D1%26sn%3D3c55f3ee2775664cc20e572a27083104">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 01 Jul 2025 11:53:59 +0800</pubDate>
    </item>
    <item>
      <title>网络安全人怎么过520</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485552&amp;idx=1&amp;sn=dc4c718d0a77802ef7824ef9b71e261c</link>
      <description>今天是520，网民们流行的网络情人节，后来被商家加以宣传推广。这是一个标准的中国专属的人造节日。</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-05-20 10:28</span> <span style="display: inline-block;">广东</span>
</p>

<p>今天是520，网民们流行的网络情人节，后来被商家加以宣传推广。这是一个标准的中国专属的人造节日。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6fc5eea5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrswZyiakoibUibUaMyrQf5Pg3dp5Y2odVkDgN5jIoQc4b5pqw4SzjY1pdMg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000009" data-ratio="0.18977272727272726" type="block" data-type="gif" data-w="880" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">今天是520，网民们流行的网络情人节，后来被商家加以宣传推广。</span></p><p style="text-indent: 2em;"><span leaf="">这是一个标准的中国专属的人造节日。</span></p><p style="text-indent: 2em;"><span leaf="">我上网大致搜索了一下他的来历：</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">台湾注音符号：早期台湾网络用语中，数字“520”的注音符号“ㄨˇ（5）”“ㄦˋ（2）”“ㄌㄧㄥˊ（0）”连读近似“我爱你”，成为表达爱意的暗号。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">大陆简化谐音：大陆直接以数字发音“五二零”对应“我爱你”（“五二〇”与“我爱你”发音相近），更易传播。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">1998年范晓萱的《数字恋爱》：歌词中“520是我爱你”首次将数字与爱情绑定，成为标志性事件。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;font-style: italic;">2000年代网络聊天室：QQ等社交平台兴起，年轻人用“520”代替直白的表白，形成网络默契。</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;"><span leaf="">对于我们网络安全人士来讲，520也有独特的含义，要做好网络安全也要做到520：5个到位，2个措施，0信任。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aiimageid="33384128648904704" data-imgfileid="100001903" data-ratio="0.75" data-s="300,640" type="block" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=8a0ddbc7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsuxmfibBwgtQMIpYicWyBQmQxIt4XibXP5VgJ4u7rbgQQVNFUdr5nHZJYA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001897" data-ratio="1" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a17eae70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9Nzrsbd21gyxyd0BnHbAicoJyic8WX6tXqdUHibru5tLia0KY36aFOtpWZ8GCtQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">（本图片使用豆包AI生成)</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">5个到位</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">岗位责任到位：</span>做好安全，必须有组织和人员，并且明确各方责任，奖惩制度、考核办法都要有。</span></p><p><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">后勤保障到位：</span>保障措施包括资金保障、物资保障等。做安全是要有投入的，必须要有资金上的保障。</span></p><p><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">管理流程到位：</span>安全工作“三分技术，七分管理”，制定完善的管理制度和流程是做安全的基础。</span></p><p><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">技术手段到位：</span>“工欲善其事，必先利其器”，技术手段必不可少，要选择好用的武器，能大大加强安全能力。</span></p><p><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">意识能力到位：</span><span textstyle="" style="font-size: 17px;font-weight: normal;">武器很重要，但</span>决定战争胜利的因素一定是人，要加强人员的安全意识培训，包括领导、员工和IT人员的安全意识，要对安全有敬畏之心。<a class="normal_text_link" target="_blank" style="" data-unique-id="mavuemn3-hrgwie" href="https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485300&amp;idx=1&amp;sn=1bd09cb6e74811c617fdd588633d32cc&amp;scene=21#wechat_redirect" textvalue="心存敬畏 安全常在" data-itemshowtype="0" linktype="text" data-linktype="2">心存敬畏 安全常在</a></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001899" data-ratio="1" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=84b52298&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9Nzrsib1hCKMib6mkibX5ttAWrLzLO8iaZJePbXbwODs4jvuctEmQPzG4eYxnkw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span leaf="">(本图片由AI生成)</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">2个措施</span></span></p><p style="text-indent: 2em;"><span leaf="">安全管理就是对风险的管理，我们要做的主要就是两件事：一是如何防止安全事件的发生。二是如果安全事件发生了，如何减少损失？</span></p><p style="text-indent: 2em;"><span leaf="">因此必须要有的两类措施：</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">一个是必须要有防御措施</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: bold;">一个是必须要有恢复措施。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: normal;">防御措施是指为了防止安全事件发生而采取的措施，比如加密措施、身份鉴别和访问控制措施、防病毒措施、网络隔离措施等。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-weight: normal;">恢复措施是指万一安全事件发生了，如何减少损失的措施，如备份与恢复措施、应急响应措施、灾难恢复计划等。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001900" data-ratio="1" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0bda64c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsgfM0yxT3icR5msH9ygG5OVsDBWfIyecyNsricI1C8Feuc172ESfRSNoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span leaf="">（本图片由AI生成，有点错误）</span></p><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">0信任</span></span></p><p style="text-indent: 2em;"><span leaf="">零信任包括技术上的零信任和意识上的零信任。</span></p><p style="text-indent: 2em;"><span leaf="">技术的</span><span leaf="">零信任是一种安全模型，其核心理念是“永不信任，始终验证”。它摒弃了传统基于网络边界的信任模式，假设网络内外都存在潜在威胁，主要的技术包括：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf="">动态身份验证：根据用户的行为、设备状态和访问上下文实时评估信任级别。</span></p></li><li><p><span leaf="">最小权限原则：用户和设备仅被授予完成任务所需的最低权限。</span></p></li><li><p><span leaf="">微隔离技术：将网络划分为多个独立的“信任区”，防止攻击扩散。</span></p></li><li><p><span leaf="">持续监控与威胁检测：实时监控用户行为和设备状态，快速发现并响应异常</span></p></li></ul><p style="text-indent: 2em;"><span leaf="">意识上的零信任是指面对日常工作的邮件、电话等社会工程学常用的手段时，我们要多想，不要轻易相信。</span></p><p style="text-indent: 2em;"><span leaf="">对于邮件中的链接不要轻易点，要想想你看到地址是真实的地址吗？</span></p><p style="text-indent: 2em;"><span leaf="">对于邮件中的附件不要轻易打开执行，万一是病毒呢？</span></p><p style="text-indent: 2em;"><span leaf="">对于要求跟你裸聊的不要同意，对面真的是个小姐姐吗？</span></p><p style="text-indent: 2em;"><span leaf="">对于要求你转款的不要相信，要想想会不会是骗子？</span></p><p style="text-indent: 2em;"><span leaf="">……</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001898" data-ratio="1" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f5c25a91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsMibF2OFN1icjrG3rqfwO0EiaetaRVUZAADojencDH7v6M1uvicUP2buxzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: center;"><span leaf="">（本图片由AI生成)</span></p><p style="text-indent: 2em;"><span leaf="">好了，祝大家度过一个安全的节日！</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000028" data-ratio="0.046511627906976744" type="block" data-type="gif" data-w="430" src="https://wechat2rss.xlab.app/img-proxy/?k=73512e10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSFHBq5tcGYLREEMiavsyuk4Xomhtzmw8BXKp6tdFImNNpfHicEvkNK1kARbWbGkUjla6O8Mhrl6Y9Q%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">欢迎关注：大兵说安全</span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="1" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8a0ddbc7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsuxmfibBwgtQMIpYicWyBQmQxIt4XibXP5VgJ4u7rbgQQVNFUdr5nHZJYA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1ca89a53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9Nzrsbd21gyxyd0BnHbAicoJyic8WX6tXqdUHibru5tLia0KY36aFOtpWZ8GCtQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=86adfac9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9Nzrsib1hCKMib6mkibX5ttAWrLzLO8iaZJePbXbwODs4jvuctEmQPzG4eYxnkw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3ba5c8d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsgfM0yxT3icR5msH9ygG5OVsDBWfIyecyNsricI1C8Feuc172ESfRSNoA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=56126618&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqT5pKKYlPApYIyxofc9NzrsMibF2OFN1icjrG3rqfwO0EiaetaRVUZAADojencDH7v6M1uvicUP2buxzA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=73512e10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSFHBq5tcGYLREEMiavsyuk4Xomhtzmw8BXKp6tdFImNNpfHicEvkNK1kARbWbGkUjla6O8Mhrl6Y9Q%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247485552">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=85fc407c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485552%26idx%3D1%26sn%3Ddc4c718d0a77802ef7824ef9b71e261c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 20 May 2025 10:28:00 +0800</pubDate>
    </item>
    <item>
      <title>畅X通T+客户注意：又一个客户被加密勒索</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MzM0NjcxNw==&amp;mid=2247485541&amp;idx=1&amp;sn=2e7be15edb50ea30b93662213bd40f39</link>
      <description>看一个真实的财务软件客户被勒索的案例</description>
      <content:encoded><![CDATA[<p>
原创 <span>大兵说安全</span> <span>2025-05-13 07:03</span> <span style="display: inline-block;">河南</span>
</p>

<p>看一个真实的财务软件客户被勒索的案例</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=eab5428f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfVxZf8z6tOQSvqQTGg9rAjBuuLFRLaTvKsgRAooGgRTVHl56uA3yia9Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span leaf=""> </span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100000009" class="rich_pages wxw-img" data-ratio="0.18977272727272726" data-type="gif" data-w="880" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-indent: 2em;"><span leaf="">今天临近下班，突然接到客户电话，说他一个朋友公司服务器被勒索了，让我们帮忙看一下。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001890" class="rich_pages wxw-img" data-ratio="0.5601851851851852" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0ceea554&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfHIVFAkRt5he9tLK6CRQn0DYQibkW3kdARXiahE6YFSJKQZeVuNia5N5AQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">技术人员远程连接到该服务器，这是一个很有代表性的情况：</span></p><p style="text-indent: 2em;"><span leaf="">1、服务器上没有安装任何的杀毒软件。</span></p><p style="text-indent: 2em;"><span leaf="">2、使用的畅X通T+财务软件。</span></p><p style="text-indent: 2em;"><span leaf="">3、使用财务软件自带的备份功能将数据库进行了备份，但备份文件在本硬盘的不同分区。</span></p><p style="text-indent: 2em;"><span leaf="">4、客户的数据库密码就以明文方式存储在桌面上。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001879" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0294511378848727" data-s="300,640" data-type="png" data-w="747" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=52e258d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf7kGv43mxgjJ48k94GypfMia1koOomTK32VQW30LcVTVtecJKkIHRpbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">技术人员将日志导了出来，进行分析。通过分析找到了攻击源和攻击路径，黑客利用畅X通的漏洞，对系统进行注入攻击，从远程下载恶意程序后实施加密操作。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001887" data-ratio="0.6642512077294686" data-s="300,640" type="block" data-type="png" data-w="828" src="https://wechat2rss.xlab.app/img-proxy/?k=b8f619e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfc13iafP3laa9KrakG6WbUXIqsUzaqrmsxibRPCgjyPcEhzCa6UArTfLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001888" class="rich_pages wxw-img" data-ratio="0.7377450980392157" data-s="300,640" data-type="png" data-w="816" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7ac38ca5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfZSiaia0Mnzl9Ed3rLQTbibqcnpw7EqHiaFyibFbTmY1FE7KfWQCQHtKWK9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001889" class="rich_pages wxw-img" data-ratio="0.6633663366336634" data-s="300,640" data-type="png" data-w="808" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4e687bbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf6W2iaWDoxQEicgkCmcWtflIxz8DNUw5V0XmgVhpb7aUoFEkgBic3XGMPg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 12px;">注：以上几个图片是用AI分析的结果。</span></span></p><p style="text-indent: 2em;"><span leaf="">根据分析结果，技术人员在服务器上找到了黑客留下的恶意程序。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001880" data-ratio="0.7956043956043956" data-s="300,640" type="block" data-type="png" data-w="910" src="https://wechat2rss.xlab.app/img-proxy/?k=0f488002&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfUe14DYfTz2HVSRYyxwNYYfBSXbY8R5aGic5DS0RGibW5bdX0PZwbCiaiaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;"><span leaf="">将该恶意程序上传到卡巴斯基情报平台，通过后台归因引擎和沙箱分析，得知该病毒属于MALLOX家族，平台给出了该恶意程序的详细报告，包括哈希值 、执行时的具体动作，如修改的注册表、释放的文件等，以及各动作对应在ATT&amp;CK模型中所处的环节。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001881" data-ratio="0.5268518518518519" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0bcf5375&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf2GmUOQLeNkbcRYQ1lN0SeXuicFKvPAlry2b8M3icgZhopSEsRtRBHtSQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001882" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5805555555555556" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=745a01f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfoFhXELicu1q5ibicyZTibmdw2v2kZdnib1Gw58cMDckv4gczgDibe0iahCU4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001883" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5657407407407408" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=505cc681&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfBTpG7AEkdFibYx9CTJaGfpvBRANuL5w6XVfiaRg4ficdGaJXYqNribdicpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span leaf="">*恶意程序哈希值 </span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001884" data-ratio="0.9879629629629629" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=340fbbaa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf8ufQqobwmuQI6B2oMia4MPZ8gjc8ImYSsqhANqB2JdFGxdkJibzcZBRw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span leaf="">恶意程序进入主机后执行的各种动作</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001885" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3861111111111111" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1dbe6345&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfJ09PHSM2iclsDwbzR4LI5t5ia9gX9uCrWGA92IxCKPVBSsznHWK6bfzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 2em;text-align: center;"><span leaf="">该恶意程序攻击对象与ATT&amp;CK模型的映射关系</span></p><p style="text-indent: 2em;text-align: center;"><span leaf=""><span textstyle="" style="font-size: 24px;">应急建议：</span></span></p><p style="text-indent: 2em;"><span leaf="">1、网络隔离，暂时将该主机从网络中隔离出来，在防火墙上限制黑客使用的几个IP地址的访问权限。</span></p><p style="text-indent: 2em;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001886" data-ratio="1.0231660231660231" data-s="300,640" type="block" data-type="png" data-w="518" src="https://wechat2rss.xlab.app/img-proxy/?k=0ddcb9c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfaB2ndb6B0pnEraVd5J5f35ibPXaOFOoWVZT4B44hQmnmicNmUjTJxm4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-indent: 2em;"><span leaf="">2、日志深度排查：检查是否有成功返回200状态的攻击请求（如日志中部分请求返回200）。搜索服务器进程、计划任务中是否存在异常项（如sqlps、wscript.shell相关进程）</span></p><p style="text-indent: 2em;"><span leaf="">3、</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">将分析出的恶意程序的IOC指标，在内网进行威胁狩猎，查找还有没有其他的失陷主机。</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">4、修复漏洞。联系财务软件厂商，升级至最新版本，修补已知漏洞。对KeyInfoList.aspx和keyEdit.aspx接口实施严格的输入过滤，禁止特殊字符（如;、exec）。</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">5、部署专业防病毒和EDR产品，可以有效阻止病毒攻击，并能在需要的时候进行事件溯源和损害评估。</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">6、备份数一定不能放在本机。要遵循32110原则，将备份数据放在不同的存储位置。</span></p><p style="text-indent: 2em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">7、</span><span leaf="">部署WAF（Web应用防火墙），拦截SQL注入和命令注入攻击。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;"><span leaf="">感谢我公司技术总监<span textstyle="" style="font-size: 20px;font-weight: bold;">邵博</span>同学为客户响应处理，并提供素材！感谢卡巴斯基威胁情报平台提供技术支持。</span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">最后再提醒一下大家，出现勒索病毒不要急于重装系统，一定要请专业人士进行溯源分析，找到本次出事的原因，才能更好的做好防范，避免下次更大的伤害。</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-indent: 2em;"><span leaf="">欢迎扫码关注：大兵说安全</span></p><p class="mp_profile_iframe_wrp" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-nickname="大兵说安全" data-alias="dabingshuoanquan" data-from="1" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/M8lZIYZticqThicmRwDMVejWOMdkFlrCt14n93c3scxgeDNsz071dNWRHLcmS28qGHReibpS7ZDFicXicKtkHmgE1vg/0?wx_fmt=png" data-signature="在网络安全打拼二十多年的老兵。CISP认证讲师，中国计算机学会CCF计算机安全专委会执委，网络安全科普专家组成员。和大家聊聊网络安全的那些事。" data-id="MzI2MzM0NjcxNw==" data-is_biz_ban="0"></mp-common-profile></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3e32f538&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz%2FM8lZIYZticqSUBxpojuz0dvFDdU3BkVJ2mNfvorv6uNqHGpL9MAhb4mlh288yS4iaQiarSWUkdK4sBKZsHl77Qx3w%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=48408a5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfHIVFAkRt5he9tLK6CRQn0DYQibkW3kdARXiahE6YFSJKQZeVuNia5N5AQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6f1d8739&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf7kGv43mxgjJ48k94GypfMia1koOomTK32VQW30LcVTVtecJKkIHRpbw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a3990de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfc13iafP3laa9KrakG6WbUXIqsUzaqrmsxibRPCgjyPcEhzCa6UArTfLw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5a4efb36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfZSiaia0Mnzl9Ed3rLQTbibqcnpw7EqHiaFyibFbTmY1FE7KfWQCQHtKWK9A%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=73b8dcbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf6W2iaWDoxQEicgkCmcWtflIxz8DNUw5V0XmgVhpb7aUoFEkgBic3XGMPg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=744b1345&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfUe14DYfTz2HVSRYyxwNYYfBSXbY8R5aGic5DS0RGibW5bdX0PZwbCiaiaQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8a13e5b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf2GmUOQLeNkbcRYQ1lN0SeXuicFKvPAlry2b8M3icgZhopSEsRtRBHtSQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5f18015b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfoFhXELicu1q5ibicyZTibmdw2v2kZdnib1Gw58cMDckv4gczgDibe0iahCU4Q%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dbe8d8a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfBTpG7AEkdFibYx9CTJaGfpvBRANuL5w6XVfiaRg4ficdGaJXYqNribdicpQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=082b6e5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNf8ufQqobwmuQI6B2oMia4MPZ8gjc8ImYSsqhANqB2JdFGxdkJibzcZBRw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=525e9065&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfJ09PHSM2iclsDwbzR4LI5t5ia9gX9uCrWGA92IxCKPVBSsznHWK6bfzg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1f819d43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FM8lZIYZticqSyqqLItqZg8eibyNcIicoMNfaB2ndb6B0pnEraVd5J5f35ibPXaOFOoWVZT4B44hQmnmicNmUjTJxm4Q%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247485541">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=387bbee2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MzM0NjcxNw%3D%3D%26mid%3D2247485541%26idx%3D1%26sn%3D2e7be15edb50ea30b93662213bd40f39%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 13 May 2025 07:03:00 +0800</pubDate>
    </item>
  </channel>
</rss>