安全术语表
汇集邮件安全与通用安全领域的常用术语。点击任意条目,即可查看 CEO/CISO 应了解的要点。
攻击类型
피싱 (Phishing)▾冒充可信主体,试图窃取凭证、资金或敏感信息的欺骗性消息。
大多数入侵事件都始于一封邮件,但许多企业过度依赖垃圾邮件过滤器,以为它能挡住一切。技术检测与员工培训任何一方单独存在都不够。 容易被忽视的一点:即使员工产生怀疑,如果没有"举报按钮"和其后的分诊流程,他们也无从下手——务必建立举报→分诊→反馈的闭环。
查看详情 →스피어 피싱 (Spear phishing)▾针对特定个人或组织,利用精心搜集的信息定制而成的高精度定向钓鱼攻击。
攻击目标往往是高管、财务、人事等少数高权限人员,因此全公司平均检测率这类指标反而会掩盖真实风险。攻击者会利用社交媒体和官网上的公开信息来完善攻击细节。 容易被忽视的一点:除了为VIP和财务人员制定专门的保护策略外,还应最小化对外暴露的高管信息(邮箱、职衔等)。
查看详情 →비즈니스 이메일 침해BEC▾冒充高管或供应商,诱导转账、变更账户信息或泄露数据的社会工程欺诈手法,常常不含任何链接或附件。
这是单笔损失金额最大的欺诈手段(单起事件损失可达数千万到数亿韩元)。由于不含恶意软件,杀毒软件和沙箱形同虚设,"人的流程"成为最后一道防线。 容易被忽视的一点:仅靠技术手段无法阻止此类攻击——务必在财务流程中明确规定,超过一定金额的转账或账户变更必须经过独立渠道的双重审批,并培训员工对"紧急""保密"类请求保持警惕,这本身就是危险信号。
查看详情 →공급망 이메일 침해VEC▾供应链型商业邮件欺诈(BEC),攻击者劫持受信任供应商的账户,篡改发票中的收款账户信息。
即便我方安全防护做到万无一失,只要供应商账户被攻破,伪造的发票就会从"真实供应商"账户发出,还常常巧妙地插入已有邮件往来中,难以察觉。 容易被忽视的一点:任何账户变更通知都应通过预先登记的电话号码进行反向核实,而非直接回复邮件确认;同时应单独记录并追踪供应商收款信息的变更历史。
查看详情 →큐싱 (Quishing)▾将恶意链接隐藏在二维码背后,以绕过URL过滤机制的钓鱼手法。
二维码本质上是图片,现有的URL/链接检测机制往往会直接放行。更麻烦的是,用户常常用安全防护较弱的个人手机扫码,完全脱离了企业管控范围。 容易被忽视的一点:务必确认所采用的解决方案是否真正对二维码图片进行解码并检测其中的URL(许多产品其实做不到这一点)。
查看详情 →스미싱 / 비싱 (Smishing / Vishing)▾利用短信(Smishing)或语音电话(Vishing)进行的钓鱼攻击,常与邮件攻击结合使用。
攻击往往跨越多个渠道(邮件→短信→电话逐步建立信任),仅仅守住邮件这一道防线很容易被绕过。 容易被忽视的一点:如果服务台/客服中心的身份核实流程不严谨,一通电话就足以重置密码或MFA——务必检查针对人员的社会工程防范流程是否到位。
查看详情 →스푸핑 (Spoofing)▾伪造发件人地址或显示名称,使邮件看起来像是来自合法发件人的技术手段。
一旦我方域名被冒用,受害的将是客户和合作伙伴,但责任最终会归咎于我方品牌。若没有技术防护措施,任何人都可以以我方名义发送邮件。 容易被忽视的一点:很多企业把DMARC长期停留在"仅监控"(p=none)模式而不再推进——应逐步升级到真正能够拦截的强制拒绝(p=reject)策略。
查看详情 →표시이름 사칭 (Display-name spoofing)▾实际发件地址不变,仅伪造显示名称(例如冒充高管或品牌)的一种冒充手法。
这种手法连DMARC都无法阻止——因为真实域名本身合法,伪造的只是"显示名称"。在地址被隐藏的移动端邮件客户端上,这种手法尤其容易得逞。 容易被忽视的一点:不要只依赖邮件认证(SPF/DKIM/DMARC),还需确认所用方案是否具备检测冒充高管、品牌名义的显示名称伪装能力。
查看详情 →유사 도메인 (Lookalike / Homoglyph)▾外观与正规域名极为相似的仿冒域名(例如以rn仿冒m,以0仿冒o)。
肉眼几乎无法分辨,而且攻击者往往在发起攻击前才刚刚注册域名,从而躲过基于信誉的拦截机制。 容易被忽视的一点:仅靠事后检测已经太迟——应建立主动监测、抢先注册并下架我方品牌仿冒域名的常态化流程。
查看详情 →계정 탈취ATO▾利用窃取的凭证接管真实账户,从而在内部发起攻击的行为。
由于邮件来自一个正常的账户,能顺利通过认证和信誉检测,进而向内部扩散,甚至演变为供应链邮件欺诈(VEC)——这是最危险的"受信任发件人"型攻击。 容易被忽视的一点:不要只关注登录环节的保护(MFA),还应检测账户被接管后的异常行为(不可能的地理位置跳转、批量群发、新建自动转发规则等)。
查看详情 →자격증명 탈취 (Credential harvesting)▾通常通过伪造登录页面等手段收集用户名和密码的行为。
如果员工在公司系统和个人网站上重复使用同一密码,那么任何一处的泄露都可能成为打开公司账户的钥匙。 容易被忽视的一点:仅靠密码策略远远不够——应在全公司范围强制启用MFA,并持续监控暗网中泄露的凭证信息,提前封锁已经暴露的账户。
查看详情 →제로데이 (Zero-day)▾尚无补丁或特征库可用的新型漏洞或攻击手法。
从定义上讲,签名和信誉机制根本无法拦截零日攻击——只会拦截"已知威胁"的防御体系必然会成为第一个受害者。 容易被忽视的一点:应同时具备针对未知威胁的行为与上下文检测能力,并通过快速补丁运维缩短漏洞暴露窗口期。
查看详情 →AI 생성 피싱 (AI-Generated Phishing)▾An attack that uses large language models to mass-produce highly natural, personalized phishing emails free of grammatical errors.
앵글러 피싱 (Angler Phishing)▾A phishing technique using fake customer-support accounts on social media to approach complaining users and steal their information.
베이팅 (Baiting)▾A technique that lures victims into running malware themselves using enticing bait such as infected USB drives or free downloads.
브랜드 사칭 (Brand Impersonation)▾A technique that mimics a well-known brand's logo, design, and domain to deceive users with emails or sites that look authentic.
CEO 사기 (CEO Fraud)▾A common BEC variant in which an attacker impersonates a CEO or top executive to instruct finance staff to make urgent wire transfers.
클론 피싱 (Clone Phishing)▾A phishing technique that copies a legitimate previously delivered email and resends it with attachments or links swapped for malicious ones.
동의 피싱 (Consent Phishing)▾A phishing technique that tricks users into granting permissions to a malicious OAuth app, enabling data access without stealing passwords.
대화 가로채기 (Conversation Hijacking)▾An attack where adversaries monitor an ongoing business email conversation and inject themselves to alter payment details or commit fraud.
딥페이크 피싱 (Deepfake Phishing)▾An attack using AI-generated fake audio or video to impersonate executives in calls or voice messages to induce wire transfers or data leaks.
이메일 계정 탈취 (Email Account Takeover)ATO▾An attack where adversaries steal credentials to seize a legitimate email account and abuse it for internal impersonation or fraud.
기프트카드 사기 (Gift Card Scam)▾A common BEC social-engineering scam that impersonates an executive to urgently ask an employee to buy gift cards and send the codes.
호모그래프 공격 (Homograph Attack)IDN homograph▾An attack using visually identical Unicode characters (e.g., Cyrillic 'a' vs Latin 'a') to create fraudulent domains that look legitimate.
사칭 공격 (Impersonation Attack)▾A general class of attacks that masquerade as trusted persons, brands, or organizations so victims believe requests are legitimate.
송장 사기 (Invoice Fraud)▾A BEC-style financial fraud that sends fake or altered invoices to redirect payments to attacker-controlled accounts.
악성 첨부파일 (Malicious Attachment)▾An attack vector delivering malware or malicious macros hidden in email attachments such as documents or archives that infect upon opening.
악성 스팸 (Malspam)▾Spam email carrying malicious attachments or links, sent in bulk and serving as a primary vector for malware infections.
급여 가로채기 (Payroll Diversion)▾A BEC scam that impersonates an employee to ask HR or payroll to change direct-deposit details, diverting wages to an attacker's account.
파밍 (Pharming)▾An attack that redirects users to fraudulent websites via DNS poisoning or host-file manipulation even when they enter a legitimate address.
PhaaS (Phishing-as-a-Service)PhaaS▾A cybercrime business model that sells phishing infrastructure, kits, and hosting as a subscription service, lowering the barrier to attacks.
피싱 킷 (Phishing Kit)▾A pre-built package bundling fake login pages and collection scripts so non-experts can quickly deploy phishing sites.
프리텍스팅 (Pretexting)▾A social-engineering technique where an attacker fabricates a plausible scenario or false identity to gain a victim's trust and extract information.
퀴드 프로 쿠오 (Quid Pro Quo)▾A social-engineering technique that offers a service or benefit, such as fake tech support, in exchange for credentials or access.
리플라이 체인 공격 (Reply-Chain Attack)▾An email attack that inserts malicious links or attachments into an existing reply chain from a compromised account so recipients open them without suspicion.
섹스토션 이메일 (Sextortion Email)▾An extortion scam email that threatens to release supposed compromising sexual material unless the victim pays money such as Bitcoin.
스미싱 (Smishing)▾A phishing attack delivered via SMS text messages using malicious links or fraudulent prompts to deceive users.
사회공학 (Social Engineering)▾The manipulation of human psychology and trust, rather than technical vulnerabilities, to induce information disclosure or security bypass.
스팸 (Spam)▾Unsolicited bulk email sent without recipient consent, often abused as a vector for phishing or malware distribution.
스팸 폭탄 (Spam Bombing)email bombing▾An attack that floods a victim's inbox with massive email volume in a short time to bury legitimate security or fraud-alert notifications, often as a precursor to follow-on scams.
테일게이팅 (Tailgating)▾A physical social-engineering technique of following an authorized person into a restricted area without credentials, also known as piggybacking.
스레드 하이재킹 (Thread Hijacking)▾An attack that replies into an existing conversation thread from a compromised mailbox to insert malicious content while exploiting established trust.
타이포스쿼팅 (Typosquatting)▾Registering misspelled variants of popular domains to capture users who make typing errors and redirect them to malicious sites.
URL 리디렉션 피싱 (Open Redirect Phishing)▾A technique abusing open-redirect vulnerabilities on trusted sites so links appear legitimate but forward victims to malicious destinations.
보이스 피싱 (Vishing)▾A social-engineering attack that uses phone or voice calls to deceive victims into divulging personal or financial information.
음성 복제 사기 (Voice Cloning Fraud)▾A fraud technique where AI clones a target's voice from short samples to impersonate family or superiors and demand urgent money transfers.
워터링 홀 공격 (Watering Hole Attack)▾A targeted attack that compromises websites frequently visited by a target group to infect their visitors.
무기화된 문서 (Weaponized Document)▾An Office or PDF document manipulated with macros, exploits, or embedded objects to execute malware merely upon opening.
웨일링 (Whaling)▾A form of spear phishing that targets high-profile executives such as CEOs or CFOs to exploit their authority and access to funds.
电子邮件验证
SPF▾通过DNS记录声明允许代表某域名发送邮件的邮件服务器的认证机制。
没有SPF,任何人都可以冒用我方域名发送邮件,甚至连我方正常发出的邮件也可能被误判为垃圾邮件——它是DMARC生效的前提条件。 容易被忽视的一点:SPF存在10次DNS查询的上限,随着接入的SaaS发信工具增多,记录会在不知不觉中失效——每新增一个发信工具都应重新核查SPF记录。
查看详情 →DKIM▾为邮件附加加密签名以验证其内容未被篡改的认证机制。
它是邮件送达率和防篡改能力的核心,未签名的邮件在接收方看来更容易被怀疑。 容易被忽视的一点:许多企业长期使用较短的密钥(1024位)且从不轮换——应将2048位密钥与定期轮换纳入常态化运维事项。
查看详情 →DMARC▾依据SPF/DKIM的验证结果强制执行策略(拒绝/隔离)并接收报告的标准协议。
这是防范域名仿冒最有效的单一举措,并且正日益成为业务往来和邮件发送事实上的必备条件。 容易被忽视的一点:大多数企业长期停留在p=none(仅监控)阶段,实际上什么都拦不住——应先利用报告数据梳理合法发信来源,再逐步升级到隔离乃至拒绝策略。
查看详情 →ARC▾在邮件经过中继服务器转发时,保留并重新签名认证结果以便传递下去的验证链机制。
邮件经过邮件列表或转发后,SPF/DKIM验证往往会失效,导致正常邮件被拦截,而ARC能够降低这类误判,减少业务协作中的摩擦。 容易被忽视的一点:将DMARC策略升级为拒绝(reject)之前,如果不测试转发场景,可能会导致大量正常协作邮件被误拦——上线前务必先测试各类转发路径。
查看详情 →MX 레코드 (MX record)▾指向某域名收件邮件服务器的DNS记录;内联网关类方案会改动这条记录。
引入内联(网关式)安全方案后,所有邮件流量都要经过该安全系统,这套系统本身也就成了单点故障隐患。 容易被忽视的一点:在签约与方案设计阶段就应确认其高可用性(冗余)以及故障时的邮件排队/放行策略——一旦安全系统卡顿,全公司邮件都可能随之停摆。
查看详情 →BIMI (Brand Indicators for Message Identification)BIMI▾A standard that displays a brand's verified logo next to authenticated messages in the inbox for domains passing DMARC, with the logo validated via DNS and a Verified Mark Certificate.
DANE (DNS-based Authentication of Named Entities)DANE▾A protocol that binds TLS certificates or public keys to DNS names using DNSSEC-protected TLSA records, enabling verification of server certificates for protocols such as SMTP without relying solely on CAs.
DKIM 셀렉터 (DKIM Selector)▾An identifier used to distinguish among multiple DKIM keys for a domain; the corresponding public key is published at the DNS location selector._domainkey.domain.
DMARC 집계 리포트 (DMARC Aggregate Report / RUA)RUA▾A periodic XML report sent by receiving servers to a domain owner, summarizing statistics on SPF, DKIM, and DMARC authentication results for the domain's mail.
DMARC 정렬 (DMARC Alignment)▾The core DMARC requirement that the domain authenticated by SPF or DKIM match the domain in the message's From header, evaluated in strict or relaxed mode.
DNSSEC (Domain Name System Security Extensions)DNSSEC▾Extensions that add digital signatures to DNS responses to provide data integrity and origin authentication, preventing DNS spoofing and cache poisoning and underpinning DANE.
순방향 비밀성 (Forward Secrecy)PFS▾A TLS property using ephemeral per-session keys so that even if a long-term private key is later compromised, previously recorded encrypted traffic cannot be decrypted.
MTA-STS (SMTP MTA Strict Transport Security)MTA-STS▾A mechanism letting a domain publish, over HTTPS, a policy requiring TLS encryption and certificate validation for inbound SMTP connections, defending against downgrade and man-in-the-middle attacks.
OpenPGP▾An open standard for email encryption derived from PGP (RFC 4880 and successors) that defines message and key formats so implementations like GnuPG can interoperate.
PGP (Pretty Good Privacy)PGP▾A public-key cryptography program for encrypting and signing email and files, using a web-of-trust model to validate keys.
리턴 패스 (Return-Path)▾The envelope sender (MAIL FROM) address of an email, where bounce messages are returned, and whose domain is the basis for SPF verification and DMARC alignment.
S/MIME (Secure/Multipurpose Internet Mail Extensions)S/MIME▾A standard for end-to-end signing and encryption of email messages using X.509 certificate-based public-key cryptography, providing message integrity, authentication, and confidentiality.
SMTP (Simple Mail Transfer Protocol)SMTP▾The standard internet protocol for transmitting email between mail servers and from clients to servers; plaintext by default, it is secured with STARTTLS or SMTPS.
SMTPS (SMTP over TLS)SMTPS▾A method of encrypting SMTP with TLS from the start of the connection (implicit TLS, typically port 465), encrypting from the outset rather than via the opportunistic upgrade of STARTTLS.
SPF 레코드 (SPF Record)▾A DNS TXT record listing a domain's authorized sending mail servers, beginning with v=spf1 and composed of mechanisms like include, a, mx, ip4 and qualifiers such as -all.
STARTTLS▾A command that opportunistically upgrades an existing plaintext protocol connection to a TLS-encrypted one, used in SMTP, IMAP, and POP3 to secure the transport while keeping standard ports.
TLS-RPT (SMTP TLS Reporting)TLS-RPT▾A standard that lets domains using MTA-STS or DANE receive daily aggregate reports from sending mail servers about TLS negotiation successes and failures.
VMC (Verified Mark Certificate)VMC▾A digital certificate issued by an authority that verifies a brand's trademark rights to a logo, used in BIMI to display a validated logo in the inbox.
架构与部署
보안 이메일 게이트웨이SEG▾部署在MX记录前端、在邮件送达前进行过滤的传统内联式方案。
送达前拦截效果强大,但具有一定侵入性,而且对已经进入收件箱的内部邮件(内部→内部)以及账户被劫持后发起的攻击完全无能为力。 容易被忽视的一点:很容易误以为部署了SEG就万事无忧,但BEC和内部横向扩散恰恰是它的盲区——应核实是否配合基于API的(ICES)可见性方案加以补充。
查看详情 →통합 클라우드 이메일 보안ICES▾通过API接入M365/Workspace,在邮件送达后进行扫描与修复的现代化方案(无需更改MX记录)。
无需更改MX记录、五分钟即可部署且不中断业务,价值实现速度快,还能覆盖内部邮件——这是当前市场的主流发展方向。 容易被忽视的一点:由于是"送达后"处理,存在用户可能先行打开邮件的短暂时间窗口——应确认自动召回(clawback)的速度以及针对高风险邮件的拦截策略。
查看详情 →저널링 (Journaling)▾将所有邮件的副本发送至安全系统,以实现不中断业务的监控与审计。
由于完全不影响邮件流转,部署风险几乎为零,非常适合作为价值验证(PoC)或审计工作的切入点。 容易被忽视的一点:日志复制方式只能"查看",无法"拦截"——不要止步于监控,应同时规划在价值得到验证后转向内联拦截的路径。
查看详情 →샌드박스 (Sandbox)▾在隔离环境中运行可疑附件或链接,以观察其恶意行为的动态分析技术。
对未知的恶意附件行之有效,但分析需要耗费时间,而且高级恶意软件能够识别沙箱环境并隐藏其真实行为。 容易被忽视的一点:沙箱主要针对附件和链接,对不含附件的BEC攻击完全无效——不要误以为部署了沙箱就等于完成了邮件安全建设。
查看详情 →콘텐츠 무해화·재구성CDR▾从附件中剥离宏等主动内容元素,并安全重构后再行传递的技术。
它不是"分析后判断",而是"直接消除风险",因此对零日附件攻击也同样有效。 容易被忽视的一点:剥离宏或嵌入功能可能导致正常业务文档损坏——应提前与依赖宏功能的部门(财务、研发等)沟通影响范围并约定例外策略。
查看详情 →데이터 주권 (Data sovereignty)▾使数据始终处于其所在司法辖区的法律与管控之下,通常通过本地部署或区域内部署实现。
这是合规(如个人信息保护法)与客户信任的核心要素,在公共部门和金融行业的合作中往往是决定成交与否的关键。 容易被忽视的一点:即便标榜"云端安全"的产品,也可能将邮件正文发送至境外LLM或他国数据中心处理——务必核实数据(尤其是AI推理环节)实际的处理与存储地点。
查看详情 →백스캐터 (Backscatter)▾Collateral spam in which bounce messages or auto-replies to spam with forged sender addresses flood innocent third parties.
외부 발신 배너 경고 (External Sender Banner)▾A security control that inserts a warning banner at the top of messages from outside the organization to raise user awareness.
사후 회수·교정 (Post-Delivery Remediation)▾A core ICES capability that automatically retracts or removes messages already delivered to inboxes once they are found malicious, via API (clawback).
연결 제한 (Connection Throttling)▾A mail server control that limits SMTP connection or send rates per source IP or domain to mitigate spam, abuse, and overload.
이메일 연속성 (Email Continuity)▾An availability and disaster-recovery capability ensuring users can send and receive email even during a primary mail system outage.
이메일 데이터 유출 방지 (Email Data Loss Prevention)DLP▾A technology that inspects outbound email content to detect, block, or encrypt unauthorized transmission of sensitive data.
이메일 암호화 게이트웨이 (Email Encryption Gateway)▾A gateway solution that automatically encrypts outbound email according to policy to protect sensitive information.
이메일 격리 (Email Quarantine)▾A feature that holds suspected spam, malware, or phishing email in a separate quarantine area instead of the inbox for admin or user review.
이메일 샌드박스 (Email Sandbox)▾A technology that detonates suspicious attachments or URLs in an isolated virtual environment to dynamically analyze malicious behavior.
이메일 스풀링 (Email Spooling)▾A capability that temporarily stores mail on a backup server when the destination is down and re-delivers it after recovery to prevent loss.
그레이리스팅 (Greylisting)▾A technique that temporarily rejects email from unknown senders, relying on legitimate MTAs to retry, thereby filtering out spambots.
인터넷 메시지 접근 프로토콜 (Internet Message Access Protocol)IMAP▾An email retrieval protocol that keeps messages on the server and allows synchronized access across multiple devices.
인라인 대 API 배포 (Inline vs API Deployment)▾The two email security deployment models: inline, which sits in the mail flow to block in transit, versus API-based, which integrates with mailbox APIs to act post-delivery.
메일 큐 (Mail Queue)▾A queue within an MTA that temporarily holds email that cannot be delivered immediately and manages retries.
메일 배달 에이전트 (Mail Delivery Agent)MDA▾Software that delivers email received from an MTA into the recipient's mailbox.
메일 제출 에이전트 (Mail Submission Agent)MSA▾A server that receives outgoing mail from clients, applies authentication and policy checks, and hands it to an MTA, typically over port 587.
메일 전송 에이전트 (Mail Transfer Agent)MTA▾Software that transfers and routes email between mail servers using SMTP.
메일 사용자 에이전트 (Mail User Agent)MUA▾Client software that lets users compose, read, and manage email, commonly known as an email client.
포스트 오피스 프로토콜 3 (Post Office Protocol 3)POP3▾An email retrieval protocol that downloads messages from the server to a local client, typically removing them from the server.
실시간 블랙홀 목록 (Realtime Blackhole List)RBL▾A reputation-based blocklist of IP addresses known to send spam, queried via DNS to reject mail.
평판 필터링 (Reputation Filtering)▾A filtering technique that uses reputation scores based on the historical behavior of sending IPs or domains to block or allow mail.
스마트호스트 (Smarthost)▾A designated external relay server through which a mail server routes all outbound email instead of delivering directly to destinations.
SMTP 릴레이 (SMTP Relay)▾The process by which one mail server forwards email through another, which if misconfigured can be abused as an open relay.
SMTP 스머글링 (SMTP Smuggling)▾An attack technique that exploits differing interpretations of message-end sequences between sending and receiving servers to inject spoofed email.
SMTP TLS (STARTTLS)TLS▾Encrypting an SMTP connection via the STARTTLS command to protect message content in transit.
SMTPS 포트 465 (Implicit TLS SMTP)SMTPS▾An SMTP submission port using implicit TLS where encryption applies from the start of the connection.
제출 포트 587 (Submission Port 587)▾The standard SMTP submission port used by authenticated clients to submit mail, distinct from port 25 used for relaying.
클릭 시점 보호 (Time-of-Click Protection)▾A protection that re-evaluates a link's safety at the moment a user clicks it, catching URLs weaponized after delivery.
전송 규칙 (Mail Flow/Transport Rule)▾A mail flow policy rule that evaluates conditions on email and automatically applies actions such as blocking, redirecting, adding headers, or encryption.
URL 재작성 (URL Rewriting)▾A technique that rewrites links in email to point to a security proxy so their safety is checked in real time at click time.
运维与 SOC
SIEM▾对安全事件与日志进行汇总、关联分析的平台(如Splunk、Sentinel等)。
它是安全可视化与合规应对(审计日志)的核心枢纽,将邮件安全判定结果接入其中,可以让整个攻击链条的全貌汇聚一处。 容易被忽视的一点:只堆积日志却无人查阅只会白白耗费预算——必须明确哪类告警由谁、以何种方式响应(规则、责任人、SLA),SIEM才能真正发挥作用。
查看详情 →SOAR▾对告警响应动作进行自动化编排的体系。
在告警数量激增的环境中,它能够替代人工完成重复性响应工作,在人力节省和响应速度上带来显著的投资回报。 容易被忽视的一点:如果对未经甄别的告警直接自动化处置,错误也会被一并自动化放大——应从高置信度场景开始,循序渐进,并保留人工确认环节(human-in-the-loop)。
查看详情 →침해 지표IOC▾提示发生入侵的痕迹线索(如恶意IP、域名、文件哈希等)。
它是威胁情报共享与拦截的基本单位,但IOC本质上反映的是"已知的过去",对于新型攻击往往慢了一步。 容易被忽视的一点:不要只依赖IOC拦截,应同时具备基于行为与意图(TTP)的检测能力,以捕获从未出现过的新型攻击。
查看详情 →격리 (Quarantine)▾将判定为高风险的邮件从收件箱中隔离(移动或封锁)的补救措施。
这是切实有效的防御行动,但若因误判而隔离了正常邮件,则会造成业务摩擦并动摇员工对安全团队的信任。 容易被忽视的一点:如果缺乏用户自助释放、审核队列、释放SLA等运营机制,隔离功能很容易演变成"我的邮件不见了"的投诉——应同步设计好配套的运营流程。
查看详情 →다중요소 인증MFA▾在密码之外要求额外认证要素,以缓解账户被接管风险的机制。
这是投入产出比最高的单项安全控制措施,应将其在全公司范围内的推广列为最优先事项。 容易被忽视的一点:短信或推送类MFA可能被中间人钓鱼(AiTM)和MFA疲劳攻击攻破——应优先为高风险账户升级至抗钓鱼MFA(通行密钥/FIDO2)。
查看详情 →지능형 지속 위협 (Advanced Persistent Threat)APT▾A targeted adversary that uses sophisticated techniques to maintain stealthy, long-term access. It is often associated with nation-state actors.
경보 피로 (Alert Fatigue)▾The desensitization of analysts caused by an overwhelming volume of alerts, leading to missed critical threats. It is a major challenge in SOC operations.
감사 로그 (Audit Log)▾A chronological record of activities and changes within a system. It is essential for accountability and post-incident investigation.
블루팀 (Blue Team)▾A defensive team responsible for protecting assets and detecting and responding to attacks. They are the core staff of SOC operations.
침해 통지 (Breach Notification)▾The mandatory process of informing regulators and affected individuals when a data breach occurs. It is required under regulations such as GDPR and data protection laws.
증거 연속성 (Chain of Custody)▾The documented chronological handling of digital evidence to ensure its integrity. It is essential for legal admissibility.
명령제어 (Command and Control)C2▾The communication channel and infrastructure attackers use to remotely control compromised systems. It is used for data exfiltration and issuing further commands.
침해사고대응팀 (Computer Emergency Response Team)CERT▾A specialized organization that receives, coordinates, and responds to security incidents. They operate at national, sector, and organizational levels.
컴퓨터보안사고대응팀 (Computer Security Incident Response Team)CSIRT▾A dedicated team responsible for handling security incidents within an organization. It performs detection, analysis, recovery, and post-incident activities.
사이버 킬 체인 (Cyber Kill Chain)▾A model defined by Lockheed Martin describing the stages of a cyberattack. It breaks an attack into seven phases from reconnaissance to actions on objectives.
데이터 유출 (Data Exfiltration)▾The unauthorized transfer of data from inside an organization to an external destination. It is often the ultimate goal of an attack.
디지털 포렌식·사고대응 (Digital Forensics and Incident Response)DFIR▾A field combining forensic investigation with incident response. It simultaneously determines root cause and drives rapid remediation.
디지털 포렌식 (Digital Forensics)▾The discipline of collecting, preserving, and analyzing digital evidence to determine the cause and course of an incident. It emphasizes legal admissibility.
엔드포인트 탐지·대응 (Endpoint Detection and Response)EDR▾A solution that continuously monitors endpoint activity to detect, investigate, and respond to threats. It uses behavioral analysis to identify advanced attacks.
오탐 (False Positive)FP▾An alert that incorrectly flags benign activity as a threat. Excessive false positives cause analyst fatigue and alert dismissal.
일반 개인정보보호법 (General Data Protection Regulation)GDPR▾The European Union's regulation on personal data protection and processing. It includes breach notification obligations and strong penalties.
거버넌스·위험·컴플라이언스 (Governance, Risk and Compliance)GRC▾An integrated approach to managing an organization's governance, risk management, and regulatory compliance. It aligns security decisions with business objectives.
사고대응 (Incident Response)IR▾The structured process of detecting, containing, eradicating, and recovering from security incidents. Its goal is to minimize damage and restore normal operations.
공격지표 (Indicator of Attack)IOA▾Indicators that reveal an attacker's intent and behavioral patterns. They focus on detecting an attack in progress before compromise completes.
ISO/IEC 27001ISO 27001▾An international standard for information security management systems (ISMS). It requires risk-based controls and continual improvement.
횡적 이동 (Lateral Movement)▾A technique where an attacker expands access from a compromised system to others within the network. It is used to reach target assets.
로그 관리 (Log Management)▾The practice of collecting, storing, analyzing, and retaining system and application logs. It underpins detection, forensics, and compliance.
평균 탐지 시간 (Mean Time to Detect)MTTD▾The average time taken to detect a security incident after it occurs. It is a key metric for SOC detection performance.
평균 대응 시간 (Mean Time to Respond)MTTR▾The average time taken to respond to and remediate an incident after detection. It measures response efficiency.
MITRE ATT&CKATT&CK▾A globally accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. It serves as a common framework for detection and defense.
네트워크 탐지·대응 (Network Detection and Response)NDR▾A solution that analyzes network traffic to detect and respond to anomalous behavior and threats. It excels at identifying lateral movement and stealthy attacks.
NIST 사이버보안 프레임워크 (NIST Cybersecurity Framework)NIST CSF▾A cybersecurity management framework from the U.S. NIST organized around Identify, Protect, Detect, Respond, and Recover functions. It provides a common language for risk management.
PCI DSSPCI DSS▾A security standard that organizations handling payment card data must comply with. It governs the storage, transmission, and processing of cardholder data.
지속성 (Persistence)▾Techniques that allow an attacker to maintain access across reboots or credential changes. It is one of the key tactics in MITRE ATT&CK.
플레이북 (Playbook)▾A standardized set of procedures for responding to a specific type of incident. It forms the basis for SOAR automation.
권한 상승 (Privilege Escalation)▾An attack technique for gaining higher privileges from a lower-privileged context. It is a key step toward system control and persistence.
퍼플팀 (Purple Team)▾An exercise that has offensive (red team) and defensive (blue team) collaborate to improve detection and response. It integrates feedback from both sides.
레드팀 (Red Team)▾An offensive team that emulates real adversaries to test an organization's defenses. It exposes gaps in detection and response.
런북 (Runbook)▾A step-by-step guide documenting operational tasks or response procedures. It ensures consistency and repeatability.
보안관제센터 (Security Operations Center)SOC▾A centralized team and facility that continuously monitors, detects, and responds to security events. It combines analysts, processes, and technology to manage threats.
시그마 룰 (Sigma Rule)▾A generic, vendor-agnostic format for log-based detection rules. It allows a rule to be written once and converted for multiple SIEM platforms.
SOC 2SOC 2▾An AICPA audit report attesting to a service organization's adherence to trust principles such as security, availability, and confidentiality. It is widely used by SaaS firms to demonstrate trustworthiness.
STIXSTIX▾A standardized language for representing structured cyber threat intelligence. It supports consistent sharing of threat information.
시스로그 (Syslog)▾A standard protocol used by network devices and systems to send log messages. It is widely used for centralized log collection.
테이블탑 훈련 (Tabletop Exercise)▾A discussion-based exercise that walks through a hypothetical incident scenario. It surfaces gaps in procedures and communication beforehand.
전술·기법·절차 (Tactics, Techniques and Procedures)TTP▾A concept describing adversary behavior at the levels of tactics, techniques, and procedures. It serves as the basis for threat analysis and detection.
TAXIITAXII▾A transport protocol for exchanging STIX-based threat intelligence. It enables automated sharing of threat information.
위협 행위자 (Threat Actor)▾An individual or group responsible for causing a security incident. They are classified by motivation, capability, and resources.
탐지 룰 (Detection Rule)▾A rule defining specific malicious patterns or conditions that trigger alerts. It is the basic unit of SIEM and EDR detection logic.
위협 헌팅 (Threat Hunting)▾The proactive, hypothesis-driven search for threats that evade existing detection tools. Analysts actively look for signs of compromise.
위협 인텔리전스 (Threat Intelligence)CTI▾Collected and analyzed information about threat actors and attacks. It supports defensive decision-making and proactive response.
사용자·엔티티 행위 분석 (User and Entity Behavior Analytics)UEBA▾Technology that learns baselines of normal user and entity behavior to detect anomalies. It is effective at spotting insider threats and account takeover.
확장 탐지·대응 (Extended Detection and Response)XDR▾A solution that unifies detection and response across endpoints, network, cloud, and email layers. It provides visibility beyond isolated security silos.
YARA▾A tool and rule language for identifying and classifying malware based on patterns. It is widely used in malware hunting and forensics.
AI 与检测引擎
LLM / sLLM▾大型语言模型(LLM)以及可自主部署的小型模型(sLLM),用于意图识别与分类。
它在捕捉自然语言中细微的意图信号(如冒充、催促转账等)方面能力突出,但托管式LLM实质上意味着邮件正文会被发送到外部。 容易被忽视的一点:比"搭载了AI"这句话更重要的是数据流向何方——如果对数据主权有要求,应确认是否提供sLLM/本地部署选项以及成本控制(分层)机制。
查看详情 →인공신경망 (ANN)▾基于连续值与密集运算的标准神经网络,包括属于此类的Transformer架构LLM(当前主流检测引擎)。
这是当前的主流技术,准确率高,但GPU与推理成本、能耗是运营中的关键变量。 容易被忽视的一点:如果让每一封邮件都经过模型处理,成本会急剧攀升——应确认是否具备先用规则过滤、仅将疑难案例交给模型处理的成本分层设计。
查看详情 →스파이킹 신경망 (SNN)▾以离散脉冲信号运作的第三代神经网络,具有超低功耗和流式处理优势(尚处研究阶段)。
在低功耗与边缘推理场景中潜力巨大,但目前仍处于研究阶段,尚不构成当下的采购决策因素。 容易被忽视的一点:若供应商宣传其产品"搭载SNN/类脑计算",应仔细核实这究竟是已经落地的产品功能,还是仅停留在研究或路线图阶段(警惕夸大宣传)。
查看详情 →검색증강생성 (RAG)▾通过检索外部知识(如威胁情报)来为模型判断提供依据支撑的技术。
它为模型判断补充了最新的威胁信息和依据,提升了可解释性与可信度。 容易被忽视的一点:如果被检索的知识库(威胁情报)已经过时,RAG的效果也会随之打折——应同时核查情报更新频率与来源可信度。
查看详情 →에이전트형 AI (Agentic AI)▾由多个专职智能体协同拼接线索、共同判断意图的类分析师式自动化系统。
它能弥补安全人力的不足,像人类分析师一样综合多重线索来识别定向攻击。 容易被忽视的一点:能否建立信任的关键在于"为何做出此判断"的可解释性——应确认产品是能够追溯推理依据,还是仅给出一个黑箱式的评分。
查看详情 →적대적 예제 (Adversarial Example)▾An input subtly perturbed to be misclassified by a model while appearing normal to humans. A core threat in ML security.
적대적 머신러닝 (Adversarial Machine Learning)AML▾The study of attacks that deceive or subvert machine learning models, and the defenses against them.
AI 에이전트 (AI Agent)▾An autonomous LLM-based system that invokes tools and reasons over multiple steps to accomplish goals.
AI 정렬 (AI Alignment)▾The research field of steering AI systems' goals and behavior toward human intent and values. Central to safe LLM operation.
이상 탐지 (Anomaly Detection)▾A technique for identifying data or behavior that deviates from normal patterns. Central to intrusion and fraud detection.
어텐션 메커니즘 (Attention Mechanism)▾A neural network technique that weights the most relevant parts of an input sequence. A key component of the Transformer.
백도어 공격 (Backdoor Attack)▾An attack that implants a hidden function in a model so it behaves maliciously only when a specific trigger is present.
분류기 (Classifier)▾A model that assigns inputs to one of a set of predefined categories. Used for spam/ham and malicious/benign decisions.
혼동 행렬 (Confusion Matrix)▾An evaluation table that cross-tabulates a classifier's predictions versus true labels, showing TP, FP, TN, and FN.
데이터 포이즈닝 (Data Poisoning)▾An attack that injects malicious samples into training data to manipulate a model's performance or behavior.
딥러닝 (Deep Learning)DL▾A subfield of machine learning using multi-layer neural networks to learn complex representations. Applied to image- and text-based threat detection.
임베딩 (Embedding)▾A dense vector representation that captures the semantic meaning of words or documents. Forms the basis of similarity search and RAG.
설명 가능한 AI (Explainable AI)XAI▾Techniques and a field for making AI model predictions interpretable to humans. Important for trusting detection outcomes.
F1 점수 (F1 Score)▾The harmonic mean of precision and recall, summarizing classification performance in a single value.
거짓양성률 (False Positive Rate)FPR▾The rate at which actual negatives are incorrectly classified as positive. Directly linked to alert fatigue in detection systems.
특징 공학 (Feature Engineering)▾The process of transforming and selecting raw data into features suitable for a model. Greatly impacts detection performance.
파인튜닝 (Fine-tuning)▾The process of further training a pre-trained model on task- or domain-specific data. Used to specialize security classifiers.
생성적 적대 신경망 (Generative Adversarial Network)GAN▾A neural architecture where a generator and discriminator compete during training. Used to create deepfakes and synthetic attack data.
그래디언트 부스팅 (Gradient Boosting)▾An ensemble technique that sequentially combines weak learners to reduce error. Used in detection models such as XGBoost.
가드레일 (Guardrails)▾Safety controls that inspect and constrain LLM inputs/outputs to block harmful or policy-violating content.
환각 (Hallucination)▾The phenomenon where an LLM plausibly generates false or unsupported content. Treated as a reliability threat.
탈옥 (Jailbreak)▾A technique that bypasses safety guardrails to make an LLM produce prohibited content. Carried out through prompt manipulation.
머신러닝 (Machine Learning)ML▾A branch of AI where systems learn patterns from data to make predictions or classifications without explicit programming. Widely used in security for spam and malware detection.
멤버십 추론 공격 (Membership Inference Attack)MIA▾A privacy attack that infers whether a specific data point was part of a model's training set.
모델 컨텍스트 프로토콜 (Model Context Protocol)MCP▾An open protocol that standardizes how LLM applications connect to external tools and data sources.
회피 공격 (Evasion Attack)▾An attack that manipulates inputs at inference time to evade a detection model. Common in malware detection bypass.
모델 추출 공격 (Model Extraction Attack)▾An attack that replicates a target model's functionality or parameters through repeated query-response probing.
모델 역전 공격 (Model Inversion Attack)▾A privacy attack that reconstructs sensitive training inputs by analyzing a model's outputs.
나이브 베이즈 (Naive Bayes)▾A probabilistic classifier based on Bayes' theorem assuming feature independence. A standard for early spam filtering.
자연어 처리 (Natural Language Processing)NLP▾The AI field enabling computers to understand and generate human language. Applied to phishing text analysis.
인공신경망 (Neural Network)NN▾A computational model of interconnected nodes inspired by biological neurons. Forms the basis of pattern recognition and anomaly detection.
과적합 (Overfitting)▾When a model fits the training data too closely and fails to generalize to new data.
OWASP LLM Top 10▾An OWASP list cataloging the ten most critical security risks for large language model applications.
정밀도와 재현율 (Precision and Recall)▾Precision is the fraction of positive predictions that are correct; recall is the fraction of actual positives detected. Key evaluation metrics.
랜덤 포레스트 (Random Forest)▾A machine learning algorithm that ensembles many decision trees for prediction. Frequently used for malicious traffic classification.
AI 레드팀 (AI Red Teaming)▾An adversarial evaluation that deliberately probes an AI model for vulnerabilities and harmful outputs.
강화 학습 (Reinforcement Learning)RL▾Learning an action policy by optimizing for reward signals. Researched for automated defense and penetration simulation.
인간 피드백 강화학습 (RLHF)RLHF▾A reinforcement learning method that aligns models using human preference feedback as reward. Used to suppress harmful LLM outputs.
ROC AUCAUC▾The area under the true-positive-rate vs false-positive-rate curve across thresholds, measuring classifier performance.
지도 학습 (Supervised Learning)▾Learning an input-output mapping from labeled data. Used for label-based detection such as spam/ham classification.
서포트 벡터 머신 (Support Vector Machine)SVM▾A classification algorithm that finds a hyperplane maximizing the margin between classes. Used in classic spam filters.
토큰화 (Tokenization)▾The preprocessing step of splitting text into smaller units called tokens for model input.
전이 학습 (Transfer Learning)▾A machine learning approach that reuses knowledge learned on one task for a related task. Useful in data-scarce security domains.
트랜스포머 (Transformer)▾A neural network architecture based on the self-attention mechanism, the core of modern LLMs. Excels at processing sequential data.
비지도 학습 (Unsupervised Learning)▾Learning structure or patterns from unlabeled data. Used in clustering-based anomaly detection.
벡터 데이터베이스 (Vector Database)▾A database that stores embedding vectors and performs approximate nearest-neighbor search. Used in RAG and semantic search.
一般安全与最新趋势
랜섬웨어 / RaaS▾对数据进行加密并勒索赎金的恶意软件;RaaS(勒索软件即服务)是将其以订阅制形式对外贩卖的犯罪生态。
由于大多数攻击都始于钓鱼或凭证窃取,邮件安全实际上就是第一道预防防线。RaaS降低了犯罪门槛,使攻击目标不再局限于大型企业。 容易被忽视的一点:即便有备份,如果备份也一并被加密或删除,同样毫无用处——应确保离线/不可篡改(immutable)备份、进行真实的恢复演练,并为数据泄露式勒索(双重勒索)做好应对预案。
查看详情 →중간자 피싱 (AiTM)AiTM▾利用实时代理拦截登录会话令牌,从而绕过MFA的一种快速蔓延中的钓鱼手法。
这种攻击打破了"开了MFA就安全"的固有认知,且正在迅速增多——一旦令牌被窃取,即便密码和MFA均完好无损,账户依然会被打开。 容易被忽视的一点:普通MFA无法阻止此类攻击——必须叠加抗钓鱼MFA(通行密钥/FIDO2)以及异常会话/设备检测能力。
查看详情 →MFA 피로 공격 (MFA fatigue)▾反复发送MFA推送验证请求,诱使用户在疲劳之下无意间批准的攻击手法。
这类攻击瞄准的不是技术漏洞,而是人的疲劳与失误,因此仅仅启用MFA并不意味着高枕无忧。 容易被忽视的一点:应转向数字匹配式验证或抗钓鱼MFA,并培训员工对"意外收到的MFA通知一律拒绝并上报"。
查看详情 →딥페이크 (Deepfake)▾利用AI合成的语音或视频,常用于伪造高管的声音或面容,以强化BEC和语音钓鱼攻击的效果。
如今已进入"连电话语音和视频通话都无法完全信任"的时代,现实中已有巨额转账诈骗的真实案例——曾被视为最后信任堡垒的声音和面容也已不再可靠。 容易被忽视的一点:对于大额交易,"打电话直接确认"已不再安全——应建立跨渠道、跨要素分离验证的机制,如预先约定的暗号、回拨号码、多方联合审批等。
查看详情 →프롬프트 인젝션 (Prompt injection)▾向AI模型注入隐藏指令,诱使其做出偏离预期意图行为的攻击手法(LLM时代出现的新型威胁)。
随着AI被更多引入业务与产品之中,一个全新的攻击面随之出现(例如通过邮件或文档中隐藏的指令操控AI助手)。 容易被忽视的一点:这类风险尚未被纳入传统的安全检查清单——应将AI输入的信任边界、输出护栏机制,以及AI自身权限的最小化原则,新增纳入安全评审范畴。
查看详情 →섀도 AI (Shadow AI)▾员工在未经批准的AI工具中输入敏感信息而产生的数据泄露风险。
出于提升效率的诉求,员工很可能已经在把代码、客户信息、合同文本粘贴到未经授权的AI工具中。 容易被忽视的一点:一刀切地全面禁止只会让此类行为转入地下——应同时提供安全的内部替代方案、明确的AI使用政策以及DLP手段,共同防止敏感信息泄露。
查看详情 →제로 트러스트 (Zero Trust)▾"永不信任,始终验证"——依据身份与上下文而非网络位置来管控访问权限的安全模型。
随着远程办公与云化时代"内网即安全"的假设不再成立,它已成为事实上的安全基线标准。 容易被忽视的一点:零信任是一段持续演进的旅程,而非一次性采购的产品——不要试图一次性全面部署,应从MFA、最小权限、网络分段、设备信任等环节循序渐进地落地。
查看详情 →공급망 공격 (Supply chain attack)▾通过入侵受信任的合作伙伴、软件或更新渠道,一次性波及大量目标的攻击手法。
即便我方内部安全无懈可击,只要受信任的外部环节(合作伙伴、开源组件、更新渠道)被攻破,防线便随之失守。 容易被忽视的一点:很容易把安全防护范围局限于自身边界之内——应将合作伙伴安全尽职调查、软件物料清单(SBOM)以及最小权限集成纳入正式政策。
查看详情 →EDR / XDR▾终端检测与响应(EDR),以及将其能力扩展至邮件、云端、网络层面的检测响应方案(XDR)。
打通邮件、终端与云端的可视化能力,能够追溯攻击的完整链路(点击邮件→终端感染→横向扩散)。 容易被忽视的一点:仅部署工具而缺乏7×24小时监控响应人力,只会让告警不断堆积——应确认自有运营能力是否充足,或是否配套MDR(托管检测响应)方案。
查看详情 →데이터 유출 방지DLP▾检测并阻止敏感信息通过邮件、上传等途径外泄的控制机制。
这是合规要求与商业机密保护的核心环节,而外发邮件正是最常见的信息泄露渠道。 容易被忽视的一点:规则过严会妨碍正常业务,过松则可能造成泄露——应同步设计分类标准、例外流程与员工培训,并将误发邮件等无心之失也纳入防护范围。
查看详情 →내부자 위협 (Insider threat)▾由内部人员(无论恶意还是疏忽)导致的信息泄露或损害;被劫持的账户也会表现出与内部人员相似的行为。
过度专注外部防御,容易忽视拥有最大访问权限的内部人员——而被劫持的账户,最终表现得也与"正常的内部人员"无异。 容易被忽视的一点:除了最小权限原则与行为监控外,务必落实员工离职或岗位调动时立即回收访问权限的流程(离职交接)——这是最常见的失守环节。
查看详情 →피싱 저항 MFA (Passkey / FIDO2)▾能够抵御钓鱼和中间人攻击(AiTM)的认证方式(通行密钥、FIDO2安全密钥),代表了无密码化的发展方向。
这是目前应对AiTM和凭证窃取最有效的手段——令牌拦截这一攻击方式在此彻底失效。 容易被忽视的一点:全公司范围的迁移需要时间,应优先为高管、管理员、财务等高风险账户率先部署,并同步建立丢失/恢复应急流程。
查看详情 →초기 침투 브로커IAB▾专门从事出售入侵后所获访问权限给其他攻击者(如勒索软件团伙)的犯罪专业化环节。
这标志着网络犯罪已走向分工专业化——一个团伙负责入侵并出售"钥匙",另一个团伙则通过勒索软件将其变现,一次微小的入侵便可能演变为重大安全事故。 容易被忽视的一点:很容易把看似"无关紧要"的钓鱼或凭证泄露事件不当回事——务必牢记,阻断初始入侵与迅速吊销失效凭证,本身就是防范勒索软件攻击的关键举措。
查看详情 →공격 표면 관리ASM▾持续发现并管理暴露在外部的资产、域名与服务,以缩小攻击路径的一项安全活动。
无法保护自己都不知道存在的资产,而被遗忘的服务器、测试域名、闲置的SaaS账户恰恰是最常见的入侵突破口。 容易被忽视的一点:一次性的资产清点很快就会过时——应将持续自动化发现、以及对本品牌仿冒域名和暴露服务的监控纳入常态化运营。
查看详情 →