資安詞彙表
彙整電子郵件與一般資安領域的重要術語。點選任一項目,即可檢視 CEO/CISO 觀點的重點摘要。
攻擊類型
피싱 (Phishing)▾冒充可信任對象以竊取憑證、金錢或機敏資料的詐騙訊息。
大多數資安事件都始於一封電子郵件,但許多企業卻過度依賴垃圾郵件過濾器。技術偵測與員工教育訓練,單靠其中一項都不夠。 常被忽略的一點:若沒有「檢舉按鈕」及其後續的分流處理流程,即使員工察覺可疑郵件也無從應對——務必建立「檢舉→分流→回饋」的完整迴路。
閱讀更多 →스피어 피싱 (Spear phishing)▾針對特定個人或組織,運用蒐集而來的詳細資訊精心設計的目標式網路釣魚攻擊。
攻擊目標通常是少數擁有高權限的人員(高階主管、財務、人資),因此全公司平均的偵測指標往往掩蓋了真正的風險。攻擊者會利用社群媒體與官網等公開資訊來強化攻擊情境的真實性。 常被忽略的一點:除了為 VIP、財務人員等制定專屬防護政策外,也應同步將高階主管對外曝光的資訊(電子郵件、職稱等)降到最低。
閱讀更多 →비즈니스 이메일 침해BEC▾冒充高階主管或往來廠商的社交工程詐騙,誘騙受害者匯款、變更帳戶或外洩資料;此類攻擊通常不含連結或附件,而是濫用職權、急迫感與信任關係達成目的。
這是造成金錢損失最大宗的單一攻擊手法(單一案件損失可達數千萬甚至上億元)。由於不涉及惡意程式,防毒軟體與沙箱形同虛設,「人為流程」才是最後一道防線。 常被忽略的一點:光靠技術無法擋下此類攻擊——務必將「超過一定金額的匯款或帳戶變更需經雙管道核准」明訂於財務流程中,並訓練員工提高警覺:「緊急且保密」的要求本身就是危險訊號。
閱讀更多 →공급망 이메일 침해VEC▾一種供應鏈型的 BEC 攻擊,攻擊者入侵受信任廠商的帳號,藉此竄改發票上的付款帳戶資訊。
即使公司內部資安做得再完善,只要往來廠商的帳號遭入侵,偽造的發票就會從「真實帳號」寄出,甚至巧妙地插入既有的郵件對話串中,難以察覺。 常被忽略的一點:任何帳戶變更通知都應致電「事先登記」的電話號碼進行反向查證(切勿直接回覆郵件確認),並針對廠商付款資訊的變更建立稽核紀錄。
閱讀更多 →큐싱 (Quishing)▾將惡意連結隱藏於 QR Code 之中,藉此繞過網址過濾機制的網路釣魚手法。
QR Code 本質上是一張圖片,現有的網址/連結檢測機制會直接放行;再加上使用者往往用防護較弱的個人手機掃描,完全脫離企業的管控範圍。 常被忽略的一點:務必確認導入的解決方案是否真的能「解碼」QR Code 圖片並檢查其中的網址(許多產品其實做不到)。
閱讀更多 →스미싱 / 비싱 (Smishing / Vishing)▾透過簡訊(Smishing)或電話語音(Vishing)進行的網路釣魚攻擊,經常與電子郵件攻擊搭配使用。
攻擊手法會跨越多種管道進行(電子郵件 → 簡訊 → 電話,逐步建立信任),若只防範電子郵件,攻擊者仍可從其他管道繞過防線。 常被忽略的一點:若客服中心或服務台的身分驗證程序不夠嚴謹,一通電話就可能重設密碼或多因子驗證——務必檢視並強化這類針對「人」的社交工程防護流程。
閱讀更多 →스푸핑 (Spoofing)▾偽造寄件者地址或顯示名稱,使郵件看起來像來自合法寄件者的手法。
一旦公司網域遭到冒用,受害的往往是客戶與合作夥伴,而責任最終仍會歸咎於企業品牌;若沒有技術防護,任何人都能以貴公司名義發送郵件。 常被忽略的一點:許多企業的 DMARC 政策長期停留在「僅監控(p=none)」階段——務必逐步將政策提升至真正能夠攔截的「拒絕(p=reject)」層級。
閱讀更多 →표시이름 사칭 (Display-name spoofing)▾只偽造顯示名稱(例如高階主管或品牌名稱),但實際寄件地址並不相同的冒充手法。
DMARC 對此無能為力——因為真實網域完全正常,遭偽造的只是「顯示名稱」,在手機介面上地址常被隱藏,這種手法特別容易得逞。 常被忽略的一點:不要只仰賴 SPF、DKIM、DMARC 等驗證機制——務必確認所採用的解決方案能否偵測冒充高階主管或品牌的顯示名稱。
閱讀更多 →유사 도메인 (Lookalike / Homoglyph)▾外觀與正常網域極為相似的偽冒網域(例如以 rn 混淆 m、以 0 混淆 o),藉此矇騙使用者的視覺判斷。
這類網域幾乎難以用肉眼分辨,加上攻擊者通常在發動攻擊前才剛註冊網域,藉此規避以信譽為基礎的攔截機制。 常被忽略的一點:事後偵測往往為時已晚——應建立主動監控、預先註冊乃至下架處理的流程,防範仿冒貴公司品牌的相似網域。
閱讀更多 →계정 탈취ATO▾利用竊取的憑證掌控真實帳號,並從內部發動攻擊的手法。
由於郵件是從真實帳號寄出,能順利通過驗證與信譽檢查,並可能在內部擴散、演變成 VEC 攻擊——這是最危險的「受信任寄件者」型攻擊。 常被忽略的一點:除了登入防護(MFA)之外,也須偵測帳號遭入侵後的異常行為(如不可能的登入地點跳轉、大量寄送、新增自動轉寄規則等)。
閱讀更多 →자격증명 탈취 (Credential harvesting)▾通常透過假冒的登入頁面,蒐集使用者帳號與密碼的行為。
若員工在公司與個人網站重複使用相同密碼,任何一處外洩的憑證都可能成為打開公司帳號的鑰匙。 常被忽略的一點:僅靠密碼政策並不足夠——應全公司強制導入多因子驗證,並監控暗網外洩的憑證資料,及早封鎖已經曝光的帳號。
閱讀更多 →제로데이 (Zero-day)▾尚未有修補程式或特徵碼可辨識的全新漏洞或攻擊手法。
就定義而言,特徵碼與信譽機制都無法攔截零時差攻擊——只會攔截「已知威脅」的防禦措施,反而會成為第一個受害者。 常被忽略的一點:應同時具備針對未知威脅的行為/情境式偵測能力,並建立快速修補流程,縮短漏洞暴露的時間窗口。
閱讀更多 →AI 생성 피싱 (AI-Generated Phishing)▾An attack that uses large language models to mass-produce highly natural, personalized phishing emails free of grammatical errors.
앵글러 피싱 (Angler Phishing)▾A phishing technique using fake customer-support accounts on social media to approach complaining users and steal their information.
베이팅 (Baiting)▾A technique that lures victims into running malware themselves using enticing bait such as infected USB drives or free downloads.
브랜드 사칭 (Brand Impersonation)▾A technique that mimics a well-known brand's logo, design, and domain to deceive users with emails or sites that look authentic.
CEO 사기 (CEO Fraud)▾A common BEC variant in which an attacker impersonates a CEO or top executive to instruct finance staff to make urgent wire transfers.
클론 피싱 (Clone Phishing)▾A phishing technique that copies a legitimate previously delivered email and resends it with attachments or links swapped for malicious ones.
동의 피싱 (Consent Phishing)▾A phishing technique that tricks users into granting permissions to a malicious OAuth app, enabling data access without stealing passwords.
대화 가로채기 (Conversation Hijacking)▾An attack where adversaries monitor an ongoing business email conversation and inject themselves to alter payment details or commit fraud.
딥페이크 피싱 (Deepfake Phishing)▾An attack using AI-generated fake audio or video to impersonate executives in calls or voice messages to induce wire transfers or data leaks.
이메일 계정 탈취 (Email Account Takeover)ATO▾An attack where adversaries steal credentials to seize a legitimate email account and abuse it for internal impersonation or fraud.
기프트카드 사기 (Gift Card Scam)▾A common BEC social-engineering scam that impersonates an executive to urgently ask an employee to buy gift cards and send the codes.
호모그래프 공격 (Homograph Attack)IDN homograph▾An attack using visually identical Unicode characters (e.g., Cyrillic 'a' vs Latin 'a') to create fraudulent domains that look legitimate.
사칭 공격 (Impersonation Attack)▾A general class of attacks that masquerade as trusted persons, brands, or organizations so victims believe requests are legitimate.
송장 사기 (Invoice Fraud)▾A BEC-style financial fraud that sends fake or altered invoices to redirect payments to attacker-controlled accounts.
악성 첨부파일 (Malicious Attachment)▾An attack vector delivering malware or malicious macros hidden in email attachments such as documents or archives that infect upon opening.
악성 스팸 (Malspam)▾Spam email carrying malicious attachments or links, sent in bulk and serving as a primary vector for malware infections.
급여 가로채기 (Payroll Diversion)▾A BEC scam that impersonates an employee to ask HR or payroll to change direct-deposit details, diverting wages to an attacker's account.
파밍 (Pharming)▾An attack that redirects users to fraudulent websites via DNS poisoning or host-file manipulation even when they enter a legitimate address.
PhaaS (Phishing-as-a-Service)PhaaS▾A cybercrime business model that sells phishing infrastructure, kits, and hosting as a subscription service, lowering the barrier to attacks.
피싱 킷 (Phishing Kit)▾A pre-built package bundling fake login pages and collection scripts so non-experts can quickly deploy phishing sites.
프리텍스팅 (Pretexting)▾A social-engineering technique where an attacker fabricates a plausible scenario or false identity to gain a victim's trust and extract information.
퀴드 프로 쿠오 (Quid Pro Quo)▾A social-engineering technique that offers a service or benefit, such as fake tech support, in exchange for credentials or access.
리플라이 체인 공격 (Reply-Chain Attack)▾An email attack that inserts malicious links or attachments into an existing reply chain from a compromised account so recipients open them without suspicion.
섹스토션 이메일 (Sextortion Email)▾An extortion scam email that threatens to release supposed compromising sexual material unless the victim pays money such as Bitcoin.
스미싱 (Smishing)▾A phishing attack delivered via SMS text messages using malicious links or fraudulent prompts to deceive users.
사회공학 (Social Engineering)▾The manipulation of human psychology and trust, rather than technical vulnerabilities, to induce information disclosure or security bypass.
스팸 (Spam)▾Unsolicited bulk email sent without recipient consent, often abused as a vector for phishing or malware distribution.
스팸 폭탄 (Spam Bombing)email bombing▾An attack that floods a victim's inbox with massive email volume in a short time to bury legitimate security or fraud-alert notifications, often as a precursor to follow-on scams.
테일게이팅 (Tailgating)▾A physical social-engineering technique of following an authorized person into a restricted area without credentials, also known as piggybacking.
스레드 하이재킹 (Thread Hijacking)▾An attack that replies into an existing conversation thread from a compromised mailbox to insert malicious content while exploiting established trust.
타이포스쿼팅 (Typosquatting)▾Registering misspelled variants of popular domains to capture users who make typing errors and redirect them to malicious sites.
URL 리디렉션 피싱 (Open Redirect Phishing)▾A technique abusing open-redirect vulnerabilities on trusted sites so links appear legitimate but forward victims to malicious destinations.
보이스 피싱 (Vishing)▾A social-engineering attack that uses phone or voice calls to deceive victims into divulging personal or financial information.
음성 복제 사기 (Voice Cloning Fraud)▾A fraud technique where AI clones a target's voice from short samples to impersonate family or superiors and demand urgent money transfers.
워터링 홀 공격 (Watering Hole Attack)▾A targeted attack that compromises websites frequently visited by a target group to infect their visitors.
무기화된 문서 (Weaponized Document)▾An Office or PDF document manipulated with macros, exploits, or embedded objects to execute malware merely upon opening.
웨일링 (Whaling)▾A form of spear phishing that targets high-profile executives such as CEOs or CFOs to exploit their authority and access to funds.
電子郵件驗證
SPF▾透過 DNS 紀錄宣告哪些郵件伺服器可代表該網域寄送郵件的驗證機制。
若未設定 SPF,任何人都能冒用貴公司網域寄送郵件,甚至連正常郵件也可能被誤判為垃圾郵件;SPF 更是導入 DMARC 的前提條件。 常被忽略的一點:SPF 有「10 次查詢」的限制,隨著採用的 SaaS 發信工具增加,設定可能在不知不覺中失效——每次新增發信工具時都應重新檢視 SPF 紀錄。
閱讀更多 →DKIM▾為郵件加上加密簽章,用以驗證郵件內容未遭竄改的驗證機制。
DKIM 是提升郵件送達率與防止竄改的核心機制,未簽章的郵件容易被收件方視為可疑郵件。 常被忽略的一點:許多企業長期使用過短(1024 位元)的金鑰且從未輪換——應統一採用 2048 位元金鑰,並將定期輪換納入標準維運項目。
閱讀更多 →DMARC▾依 SPF/DKIM 驗證結果強制執行政策(拒絕/隔離)並產生報告的機制層。
DMARC 是防範網域遭冒用最有效的單一措施,如今也逐漸成為對外發信與商業合作的事實標準要求。 常被忽略的一點:多數企業長期停留在 p=none(僅監控)階段,實際上並未攔截任何郵件——應運用報告資料修正合法寄件來源的設定,再逐步提升至 quarantine(隔離)乃至 reject(拒絕)。
閱讀更多 →ARC▾在郵件經過中繼或轉寄伺服器時,保存並重新簽署驗證結果的驗證鏈機制。
郵件在經過郵件群組或轉寄服務時,SPF/DKIM 驗證常會失效,導致正常郵件遭到退回;ARC 能降低此類誤判,減少因此造成的作業困擾。 常被忽略的一點:若未先測試轉寄流程就將 DMARC 政策提升至 reject(拒絕),可能會大量攔截正常的協作郵件——務必先完整測試相關轉寄路徑。
閱讀更多 →MX 레코드 (MX record)▾指向該網域收信伺服器的 DNS 紀錄;導入行內(inline)閘道時會需要變更此紀錄。
導入行內(閘道式)資安防護後,所有郵件都必須經過該系統,這也使其成為單一故障點。 常被忽略的一點:務必在簽約與架構設計階段確認系統的可用性(備援機制)及故障時的處理方式(容錯放行/郵件佇列)——一旦資安系統當機,全公司郵件都可能因此中斷。
閱讀更多 →BIMI (Brand Indicators for Message Identification)BIMI▾A standard that displays a brand's verified logo next to authenticated messages in the inbox for domains passing DMARC, with the logo validated via DNS and a Verified Mark Certificate.
DANE (DNS-based Authentication of Named Entities)DANE▾A protocol that binds TLS certificates or public keys to DNS names using DNSSEC-protected TLSA records, enabling verification of server certificates for protocols such as SMTP without relying solely on CAs.
DKIM 셀렉터 (DKIM Selector)▾An identifier used to distinguish among multiple DKIM keys for a domain; the corresponding public key is published at the DNS location selector._domainkey.domain.
DMARC 집계 리포트 (DMARC Aggregate Report / RUA)RUA▾A periodic XML report sent by receiving servers to a domain owner, summarizing statistics on SPF, DKIM, and DMARC authentication results for the domain's mail.
DMARC 정렬 (DMARC Alignment)▾The core DMARC requirement that the domain authenticated by SPF or DKIM match the domain in the message's From header, evaluated in strict or relaxed mode.
DNSSEC (Domain Name System Security Extensions)DNSSEC▾Extensions that add digital signatures to DNS responses to provide data integrity and origin authentication, preventing DNS spoofing and cache poisoning and underpinning DANE.
순방향 비밀성 (Forward Secrecy)PFS▾A TLS property using ephemeral per-session keys so that even if a long-term private key is later compromised, previously recorded encrypted traffic cannot be decrypted.
MTA-STS (SMTP MTA Strict Transport Security)MTA-STS▾A mechanism letting a domain publish, over HTTPS, a policy requiring TLS encryption and certificate validation for inbound SMTP connections, defending against downgrade and man-in-the-middle attacks.
OpenPGP▾An open standard for email encryption derived from PGP (RFC 4880 and successors) that defines message and key formats so implementations like GnuPG can interoperate.
PGP (Pretty Good Privacy)PGP▾A public-key cryptography program for encrypting and signing email and files, using a web-of-trust model to validate keys.
리턴 패스 (Return-Path)▾The envelope sender (MAIL FROM) address of an email, where bounce messages are returned, and whose domain is the basis for SPF verification and DMARC alignment.
S/MIME (Secure/Multipurpose Internet Mail Extensions)S/MIME▾A standard for end-to-end signing and encryption of email messages using X.509 certificate-based public-key cryptography, providing message integrity, authentication, and confidentiality.
SMTP (Simple Mail Transfer Protocol)SMTP▾The standard internet protocol for transmitting email between mail servers and from clients to servers; plaintext by default, it is secured with STARTTLS or SMTPS.
SMTPS (SMTP over TLS)SMTPS▾A method of encrypting SMTP with TLS from the start of the connection (implicit TLS, typically port 465), encrypting from the outset rather than via the opportunistic upgrade of STARTTLS.
SPF 레코드 (SPF Record)▾A DNS TXT record listing a domain's authorized sending mail servers, beginning with v=spf1 and composed of mechanisms like include, a, mx, ip4 and qualifiers such as -all.
STARTTLS▾A command that opportunistically upgrades an existing plaintext protocol connection to a TLS-encrypted one, used in SMTP, IMAP, and POP3 to secure the transport while keeping standard ports.
TLS-RPT (SMTP TLS Reporting)TLS-RPT▾A standard that lets domains using MTA-STS or DANE receive daily aggregate reports from sending mail servers about TLS negotiation successes and failures.
VMC (Verified Mark Certificate)VMC▾A digital certificate issued by an authority that verifies a brand's trademark rights to a logo, used in BIMI to display a validated logo in the inbox.
架構與部署
보안 이메일 게이트웨이SEG▾部署於 MX 之前,於郵件送達前進行過濾的傳統行內式(inline)防護架構。
在郵件送達前就加以攔截的效果強大,但屬於高度侵入式的架構,且對已送達收件匣的內部郵件,以及帳號遭入侵後的攻擊完全無法察覺。 常被忽略的一點:導入 SEG 容易讓人產生虛假的安全感,但 BEC 攻擊與內部擴散正是其防護死角——應確認是否有以 API 為基礎的(ICES)可視性作為補強。
閱讀更多 →통합 클라우드 이메일 보안ICES▾透過 API 整合 M365/Workspace,於郵件送達後進行掃描與修復的現代化防護方式,無需變更 MX 紀錄。
無需變更 MX、五分鐘即可完成部署且不影響現有郵件流程,能快速展現導入成效,並可涵蓋內部郵件——這也是目前市場發展的主流方向。 常被忽略的一點:由於屬於「送達後」偵測,使用者仍可能在系統處理前就先行開啟郵件——應確認自動回收(claw-back)的速度,以及針對高風險郵件的攔截政策。
閱讀更多 →저널링 (Journaling)▾將所有郵件副本傳送至資安系統,以進行不影響郵件流程的監控與稽核。
由於完全不影響郵件流程,導入風險極低,非常適合作為概念驗證(PoC)或稽核導入的起點。 常被忽略的一點:日誌記錄(Journaling)只能「觀察」,無法「攔截」——不應止步於監控階段,應規劃在驗證成效後,進一步導入行內攔截機制。
閱讀更多 →샌드박스 (Sandbox)▾在隔離環境中執行可疑檔案或連結,藉此觀察其惡意行為的動態分析技術。
沙箱對於未知的惡意附件有相當效果,但分析需要時間,而且高階惡意程式能夠偵測到沙箱環境並隱藏其惡意行為。 常被忽略的一點:沙箱的防護重點在於附件與連結,對於不含附件的 BEC 攻擊完全無力——切勿將沙箱視為完整的電子郵件資安防護方案。
閱讀更多 →콘텐츠 무해화·재구성CDR▾移除附件中的可執行內容(如巨集等),並重新建構出安全版本的技術。
CDR 的做法是直接「移除」風險,而非「判斷」風險,因此即使面對零時差的惡意附件也依然有效。 常被忽略的一點:移除巨集或內嵌功能可能導致業務文件無法正常使用——應事先與依賴巨集功能的部門(如財務、工程等)協調評估影響範圍與例外處理方式。
閱讀更多 →데이터 주권 (Data sovereignty)▾使資料始終處於所屬管轄權的法律與控制之下,通常透過地端(on-prem)或本地(in-region)部署方式達成。
資料主權是法規遵循(如個資法)與客戶信任的核心要素,在公部門與金融產業的交易中,更往往是成敗的關鍵。 常被忽略的一點:即使標榜「雲端資安」的產品,仍可能將郵件內容傳送至境外的 LLM 或其他地區處理——務必確認資料實際的處理與儲存位置(尤其是 AI 推論的部分)。
閱讀更多 →백스캐터 (Backscatter)▾Collateral spam in which bounce messages or auto-replies to spam with forged sender addresses flood innocent third parties.
외부 발신 배너 경고 (External Sender Banner)▾A security control that inserts a warning banner at the top of messages from outside the organization to raise user awareness.
사후 회수·교정 (Post-Delivery Remediation)▾A core ICES capability that automatically retracts or removes messages already delivered to inboxes once they are found malicious, via API (clawback).
연결 제한 (Connection Throttling)▾A mail server control that limits SMTP connection or send rates per source IP or domain to mitigate spam, abuse, and overload.
이메일 연속성 (Email Continuity)▾An availability and disaster-recovery capability ensuring users can send and receive email even during a primary mail system outage.
이메일 데이터 유출 방지 (Email Data Loss Prevention)DLP▾A technology that inspects outbound email content to detect, block, or encrypt unauthorized transmission of sensitive data.
이메일 암호화 게이트웨이 (Email Encryption Gateway)▾A gateway solution that automatically encrypts outbound email according to policy to protect sensitive information.
이메일 격리 (Email Quarantine)▾A feature that holds suspected spam, malware, or phishing email in a separate quarantine area instead of the inbox for admin or user review.
이메일 샌드박스 (Email Sandbox)▾A technology that detonates suspicious attachments or URLs in an isolated virtual environment to dynamically analyze malicious behavior.
이메일 스풀링 (Email Spooling)▾A capability that temporarily stores mail on a backup server when the destination is down and re-delivers it after recovery to prevent loss.
그레이리스팅 (Greylisting)▾A technique that temporarily rejects email from unknown senders, relying on legitimate MTAs to retry, thereby filtering out spambots.
인터넷 메시지 접근 프로토콜 (Internet Message Access Protocol)IMAP▾An email retrieval protocol that keeps messages on the server and allows synchronized access across multiple devices.
인라인 대 API 배포 (Inline vs API Deployment)▾The two email security deployment models: inline, which sits in the mail flow to block in transit, versus API-based, which integrates with mailbox APIs to act post-delivery.
메일 큐 (Mail Queue)▾A queue within an MTA that temporarily holds email that cannot be delivered immediately and manages retries.
메일 배달 에이전트 (Mail Delivery Agent)MDA▾Software that delivers email received from an MTA into the recipient's mailbox.
메일 제출 에이전트 (Mail Submission Agent)MSA▾A server that receives outgoing mail from clients, applies authentication and policy checks, and hands it to an MTA, typically over port 587.
메일 전송 에이전트 (Mail Transfer Agent)MTA▾Software that transfers and routes email between mail servers using SMTP.
메일 사용자 에이전트 (Mail User Agent)MUA▾Client software that lets users compose, read, and manage email, commonly known as an email client.
포스트 오피스 프로토콜 3 (Post Office Protocol 3)POP3▾An email retrieval protocol that downloads messages from the server to a local client, typically removing them from the server.
실시간 블랙홀 목록 (Realtime Blackhole List)RBL▾A reputation-based blocklist of IP addresses known to send spam, queried via DNS to reject mail.
평판 필터링 (Reputation Filtering)▾A filtering technique that uses reputation scores based on the historical behavior of sending IPs or domains to block or allow mail.
스마트호스트 (Smarthost)▾A designated external relay server through which a mail server routes all outbound email instead of delivering directly to destinations.
SMTP 릴레이 (SMTP Relay)▾The process by which one mail server forwards email through another, which if misconfigured can be abused as an open relay.
SMTP 스머글링 (SMTP Smuggling)▾An attack technique that exploits differing interpretations of message-end sequences between sending and receiving servers to inject spoofed email.
SMTP TLS (STARTTLS)TLS▾Encrypting an SMTP connection via the STARTTLS command to protect message content in transit.
SMTPS 포트 465 (Implicit TLS SMTP)SMTPS▾An SMTP submission port using implicit TLS where encryption applies from the start of the connection.
제출 포트 587 (Submission Port 587)▾The standard SMTP submission port used by authenticated clients to submit mail, distinct from port 25 used for relaying.
클릭 시점 보호 (Time-of-Click Protection)▾A protection that re-evaluates a link's safety at the moment a user clicks it, catching URLs weaponized after delivery.
전송 규칙 (Mail Flow/Transport Rule)▾A mail flow policy rule that evaluates conditions on email and automatically applies actions such as blocking, redirecting, adding headers, or encryption.
URL 재작성 (URL Rewriting)▾A technique that rewrites links in email to point to a security proxy so their safety is checked in real time at click time.
維運與 SOC
SIEM▾彙整並關聯分析資安事件與日誌資料的平台(如 Splunk、Sentinel 等)。
SIEM 是資安可視性與法規遵循(稽核日誌)的核心樞紐;將電子郵件的判定結果納入其中,有助於拼湊出攻擊的完整全貌。 常被忽略的一點:若只是堆積日誌卻無人檢視,等於白白浪費預算——必須明確定義哪些警示應觸發何種應變(規則、負責人、SLA),SIEM 才能真正發揮價值。
閱讀更多 →SOAR▾將事件應變作業自動化與流程化整合的機制。
在警示量龐大的環境中,SOAR 能將重複性的應變作業自動化,在人力節省與應變速度上都有顯著的投資報酬率。 常被忽略的一點:若將雜訊過多、未經篩選的警示直接自動化處理,錯誤也會一併被自動放大——應先從信心水準較高的應變劇本(Playbook)開始,並保留「人工確認」的檢核關卡。
閱讀更多 →침해 지표IOC▾顯示遭受入侵跡象的鑑識線索(如惡意 IP、網域、檔案雜湊值等)。
IOC 是威脅情資共享與攔截的基本單位,但其本質上描述的是「已知的過去」,對於全新攻擊往往慢了一步。 常被忽略的一點:不應僅依賴 IOC 攔截——應搭配以行為與意圖為基礎的偵測(TTP),才能捕捉前所未見的新型攻擊。
閱讀更多 →격리 (Quarantine)▾將判定為高風險的郵件移出或攔阻於收件匣之外的補救措施。
隔離是一項實質有效的防禦行動,但若因誤判而將正常郵件隔離,反而會造成作業困擾,並降低員工對資安團隊的信任。 常被忽略的一點:若缺乏使用者自行解除隔離、審核佇列、解除 SLA 等配套機制,隔離很容易演變成「我的郵件不見了」之類的抱怨——應同步設計完整的營運處理流程。
閱讀更多 →다중요소 인증MFA▾要求在密碼之外提供額外的驗證因子,以降低帳號遭盜用風險的驗證機制。
MFA 是投資報酬率最高的單一資安控管措施,全公司導入應列為最優先事項。 常被忽略的一點:簡訊或推播式 MFA 仍可能被 AiTM(中間人)攻擊或 MFA 疲勞攻擊突破——應優先為高風險帳號升級至具備抗釣魚能力的 MFA(如金鑰/FIDO2)。
閱讀更多 →지능형 지속 위협 (Advanced Persistent Threat)APT▾A targeted adversary that uses sophisticated techniques to maintain stealthy, long-term access. It is often associated with nation-state actors.
경보 피로 (Alert Fatigue)▾The desensitization of analysts caused by an overwhelming volume of alerts, leading to missed critical threats. It is a major challenge in SOC operations.
감사 로그 (Audit Log)▾A chronological record of activities and changes within a system. It is essential for accountability and post-incident investigation.
블루팀 (Blue Team)▾A defensive team responsible for protecting assets and detecting and responding to attacks. They are the core staff of SOC operations.
침해 통지 (Breach Notification)▾The mandatory process of informing regulators and affected individuals when a data breach occurs. It is required under regulations such as GDPR and data protection laws.
증거 연속성 (Chain of Custody)▾The documented chronological handling of digital evidence to ensure its integrity. It is essential for legal admissibility.
명령제어 (Command and Control)C2▾The communication channel and infrastructure attackers use to remotely control compromised systems. It is used for data exfiltration and issuing further commands.
침해사고대응팀 (Computer Emergency Response Team)CERT▾A specialized organization that receives, coordinates, and responds to security incidents. They operate at national, sector, and organizational levels.
컴퓨터보안사고대응팀 (Computer Security Incident Response Team)CSIRT▾A dedicated team responsible for handling security incidents within an organization. It performs detection, analysis, recovery, and post-incident activities.
사이버 킬 체인 (Cyber Kill Chain)▾A model defined by Lockheed Martin describing the stages of a cyberattack. It breaks an attack into seven phases from reconnaissance to actions on objectives.
데이터 유출 (Data Exfiltration)▾The unauthorized transfer of data from inside an organization to an external destination. It is often the ultimate goal of an attack.
디지털 포렌식·사고대응 (Digital Forensics and Incident Response)DFIR▾A field combining forensic investigation with incident response. It simultaneously determines root cause and drives rapid remediation.
디지털 포렌식 (Digital Forensics)▾The discipline of collecting, preserving, and analyzing digital evidence to determine the cause and course of an incident. It emphasizes legal admissibility.
엔드포인트 탐지·대응 (Endpoint Detection and Response)EDR▾A solution that continuously monitors endpoint activity to detect, investigate, and respond to threats. It uses behavioral analysis to identify advanced attacks.
오탐 (False Positive)FP▾An alert that incorrectly flags benign activity as a threat. Excessive false positives cause analyst fatigue and alert dismissal.
일반 개인정보보호법 (General Data Protection Regulation)GDPR▾The European Union's regulation on personal data protection and processing. It includes breach notification obligations and strong penalties.
거버넌스·위험·컴플라이언스 (Governance, Risk and Compliance)GRC▾An integrated approach to managing an organization's governance, risk management, and regulatory compliance. It aligns security decisions with business objectives.
사고대응 (Incident Response)IR▾The structured process of detecting, containing, eradicating, and recovering from security incidents. Its goal is to minimize damage and restore normal operations.
공격지표 (Indicator of Attack)IOA▾Indicators that reveal an attacker's intent and behavioral patterns. They focus on detecting an attack in progress before compromise completes.
ISO/IEC 27001ISO 27001▾An international standard for information security management systems (ISMS). It requires risk-based controls and continual improvement.
횡적 이동 (Lateral Movement)▾A technique where an attacker expands access from a compromised system to others within the network. It is used to reach target assets.
로그 관리 (Log Management)▾The practice of collecting, storing, analyzing, and retaining system and application logs. It underpins detection, forensics, and compliance.
평균 탐지 시간 (Mean Time to Detect)MTTD▾The average time taken to detect a security incident after it occurs. It is a key metric for SOC detection performance.
평균 대응 시간 (Mean Time to Respond)MTTR▾The average time taken to respond to and remediate an incident after detection. It measures response efficiency.
MITRE ATT&CKATT&CK▾A globally accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. It serves as a common framework for detection and defense.
네트워크 탐지·대응 (Network Detection and Response)NDR▾A solution that analyzes network traffic to detect and respond to anomalous behavior and threats. It excels at identifying lateral movement and stealthy attacks.
NIST 사이버보안 프레임워크 (NIST Cybersecurity Framework)NIST CSF▾A cybersecurity management framework from the U.S. NIST organized around Identify, Protect, Detect, Respond, and Recover functions. It provides a common language for risk management.
PCI DSSPCI DSS▾A security standard that organizations handling payment card data must comply with. It governs the storage, transmission, and processing of cardholder data.
지속성 (Persistence)▾Techniques that allow an attacker to maintain access across reboots or credential changes. It is one of the key tactics in MITRE ATT&CK.
플레이북 (Playbook)▾A standardized set of procedures for responding to a specific type of incident. It forms the basis for SOAR automation.
권한 상승 (Privilege Escalation)▾An attack technique for gaining higher privileges from a lower-privileged context. It is a key step toward system control and persistence.
퍼플팀 (Purple Team)▾An exercise that has offensive (red team) and defensive (blue team) collaborate to improve detection and response. It integrates feedback from both sides.
레드팀 (Red Team)▾An offensive team that emulates real adversaries to test an organization's defenses. It exposes gaps in detection and response.
런북 (Runbook)▾A step-by-step guide documenting operational tasks or response procedures. It ensures consistency and repeatability.
보안관제센터 (Security Operations Center)SOC▾A centralized team and facility that continuously monitors, detects, and responds to security events. It combines analysts, processes, and technology to manage threats.
시그마 룰 (Sigma Rule)▾A generic, vendor-agnostic format for log-based detection rules. It allows a rule to be written once and converted for multiple SIEM platforms.
SOC 2SOC 2▾An AICPA audit report attesting to a service organization's adherence to trust principles such as security, availability, and confidentiality. It is widely used by SaaS firms to demonstrate trustworthiness.
STIXSTIX▾A standardized language for representing structured cyber threat intelligence. It supports consistent sharing of threat information.
시스로그 (Syslog)▾A standard protocol used by network devices and systems to send log messages. It is widely used for centralized log collection.
테이블탑 훈련 (Tabletop Exercise)▾A discussion-based exercise that walks through a hypothetical incident scenario. It surfaces gaps in procedures and communication beforehand.
전술·기법·절차 (Tactics, Techniques and Procedures)TTP▾A concept describing adversary behavior at the levels of tactics, techniques, and procedures. It serves as the basis for threat analysis and detection.
TAXIITAXII▾A transport protocol for exchanging STIX-based threat intelligence. It enables automated sharing of threat information.
위협 행위자 (Threat Actor)▾An individual or group responsible for causing a security incident. They are classified by motivation, capability, and resources.
탐지 룰 (Detection Rule)▾A rule defining specific malicious patterns or conditions that trigger alerts. It is the basic unit of SIEM and EDR detection logic.
위협 헌팅 (Threat Hunting)▾The proactive, hypothesis-driven search for threats that evade existing detection tools. Analysts actively look for signs of compromise.
위협 인텔리전스 (Threat Intelligence)CTI▾Collected and analyzed information about threat actors and attacks. It supports defensive decision-making and proactive response.
사용자·엔티티 행위 분석 (User and Entity Behavior Analytics)UEBA▾Technology that learns baselines of normal user and entity behavior to detect anomalies. It is effective at spotting insider threats and account takeover.
확장 탐지·대응 (Extended Detection and Response)XDR▾A solution that unifies detection and response across endpoints, network, cloud, and email layers. It provides visibility beyond isolated security silos.
YARA▾A tool and rule language for identifying and classifying malware based on patterns. It is widely used in malware hunting and forensics.
AI 與偵測引擎
LLM / sLLM▾大型語言模型(LLM)與可自行架設的小型語言模型(sLLM),用於意圖分類判讀。
LLM/sLLM 在捕捉細膩的攻擊意圖(如身分冒充、匯款施壓等)上效果卓越,但使用外部代管的 LLM,等同於將郵件內容傳送至外部。 常被忽略的一點:比起「是否搭載 AI」,資料流向何處才是重點——若涉及資料主權考量,應確認是否提供 sLLM/地端部署選項,以及成本控管(分級處理)機制。
閱讀更多 →인공신경망 (ANN)▾以連續數值與密集運算為基礎的標準人工神經網路,Transformer 架構的 LLM 即屬此類(目前實際部署的偵測引擎)。
這是目前的主流技術,準確度高,但 GPU、推論成本與耗電量是營運上的關鍵變數。 常被忽略的一點:若每一封郵件都直接送入模型分析,成本將大幅飆升——應確認是否有成本分級機制(先以規則過濾,僅將模糊案例送交模型判讀)。
閱讀更多 →스파이킹 신경망 (SNN)▾以離散脈衝訊號運作的第三代神經網路,具備超低功耗與適合串流處理的特性(目前仍處於研究階段)。
SNN 在低功耗與邊緣運算推論方面具有很大的未來潛力,但目前仍屬研究階段,尚不構成現階段的採購考量因素。 常被忽略的一點:若供應商以「搭載 SNN/類神經型晶片」作為行銷賣點,務必查證這究竟是已實際上線的產品功能,還是僅止於研發藍圖(留意過度宣傳的情形)。
閱讀更多 →검색증강생성 (RAG)▾檢索外部知識(如威脅情資)作為佐證,強化模型判斷依據的技術。
RAG 能為模型判斷補充最新的威脅資訊與依據,提升結果的可解釋性與可信度。 常被忽略的一點:若所檢索的知識(威脅情資)本身已經過時,RAG 的效果也會隨之打折——應同時檢視情資更新頻率與來源的可信度。
閱讀更多 →에이전트형 AI (Agentic AI)▾由多個專責代理協同運作、如同資安分析師般整合線索以判斷意圖的自動化技術。
Agentic AI 能彌補資安人力的不足,如同人類分析師一般綜合多項線索,以捕捉目標式攻擊。 常被忽略的一點:導入信任的關鍵在於「為何做出此判斷」的可解釋性——應確認產品是否能追溯其判斷依據,而非僅僅給出一個黑箱式的分數。
閱讀更多 →적대적 예제 (Adversarial Example)▾An input subtly perturbed to be misclassified by a model while appearing normal to humans. A core threat in ML security.
적대적 머신러닝 (Adversarial Machine Learning)AML▾The study of attacks that deceive or subvert machine learning models, and the defenses against them.
AI 에이전트 (AI Agent)▾An autonomous LLM-based system that invokes tools and reasons over multiple steps to accomplish goals.
AI 정렬 (AI Alignment)▾The research field of steering AI systems' goals and behavior toward human intent and values. Central to safe LLM operation.
이상 탐지 (Anomaly Detection)▾A technique for identifying data or behavior that deviates from normal patterns. Central to intrusion and fraud detection.
어텐션 메커니즘 (Attention Mechanism)▾A neural network technique that weights the most relevant parts of an input sequence. A key component of the Transformer.
백도어 공격 (Backdoor Attack)▾An attack that implants a hidden function in a model so it behaves maliciously only when a specific trigger is present.
분류기 (Classifier)▾A model that assigns inputs to one of a set of predefined categories. Used for spam/ham and malicious/benign decisions.
혼동 행렬 (Confusion Matrix)▾An evaluation table that cross-tabulates a classifier's predictions versus true labels, showing TP, FP, TN, and FN.
데이터 포이즈닝 (Data Poisoning)▾An attack that injects malicious samples into training data to manipulate a model's performance or behavior.
딥러닝 (Deep Learning)DL▾A subfield of machine learning using multi-layer neural networks to learn complex representations. Applied to image- and text-based threat detection.
임베딩 (Embedding)▾A dense vector representation that captures the semantic meaning of words or documents. Forms the basis of similarity search and RAG.
설명 가능한 AI (Explainable AI)XAI▾Techniques and a field for making AI model predictions interpretable to humans. Important for trusting detection outcomes.
F1 점수 (F1 Score)▾The harmonic mean of precision and recall, summarizing classification performance in a single value.
거짓양성률 (False Positive Rate)FPR▾The rate at which actual negatives are incorrectly classified as positive. Directly linked to alert fatigue in detection systems.
특징 공학 (Feature Engineering)▾The process of transforming and selecting raw data into features suitable for a model. Greatly impacts detection performance.
파인튜닝 (Fine-tuning)▾The process of further training a pre-trained model on task- or domain-specific data. Used to specialize security classifiers.
생성적 적대 신경망 (Generative Adversarial Network)GAN▾A neural architecture where a generator and discriminator compete during training. Used to create deepfakes and synthetic attack data.
그래디언트 부스팅 (Gradient Boosting)▾An ensemble technique that sequentially combines weak learners to reduce error. Used in detection models such as XGBoost.
가드레일 (Guardrails)▾Safety controls that inspect and constrain LLM inputs/outputs to block harmful or policy-violating content.
환각 (Hallucination)▾The phenomenon where an LLM plausibly generates false or unsupported content. Treated as a reliability threat.
탈옥 (Jailbreak)▾A technique that bypasses safety guardrails to make an LLM produce prohibited content. Carried out through prompt manipulation.
머신러닝 (Machine Learning)ML▾A branch of AI where systems learn patterns from data to make predictions or classifications without explicit programming. Widely used in security for spam and malware detection.
멤버십 추론 공격 (Membership Inference Attack)MIA▾A privacy attack that infers whether a specific data point was part of a model's training set.
모델 컨텍스트 프로토콜 (Model Context Protocol)MCP▾An open protocol that standardizes how LLM applications connect to external tools and data sources.
회피 공격 (Evasion Attack)▾An attack that manipulates inputs at inference time to evade a detection model. Common in malware detection bypass.
모델 추출 공격 (Model Extraction Attack)▾An attack that replicates a target model's functionality or parameters through repeated query-response probing.
모델 역전 공격 (Model Inversion Attack)▾A privacy attack that reconstructs sensitive training inputs by analyzing a model's outputs.
나이브 베이즈 (Naive Bayes)▾A probabilistic classifier based on Bayes' theorem assuming feature independence. A standard for early spam filtering.
자연어 처리 (Natural Language Processing)NLP▾The AI field enabling computers to understand and generate human language. Applied to phishing text analysis.
인공신경망 (Neural Network)NN▾A computational model of interconnected nodes inspired by biological neurons. Forms the basis of pattern recognition and anomaly detection.
과적합 (Overfitting)▾When a model fits the training data too closely and fails to generalize to new data.
OWASP LLM Top 10▾An OWASP list cataloging the ten most critical security risks for large language model applications.
정밀도와 재현율 (Precision and Recall)▾Precision is the fraction of positive predictions that are correct; recall is the fraction of actual positives detected. Key evaluation metrics.
랜덤 포레스트 (Random Forest)▾A machine learning algorithm that ensembles many decision trees for prediction. Frequently used for malicious traffic classification.
AI 레드팀 (AI Red Teaming)▾An adversarial evaluation that deliberately probes an AI model for vulnerabilities and harmful outputs.
강화 학습 (Reinforcement Learning)RL▾Learning an action policy by optimizing for reward signals. Researched for automated defense and penetration simulation.
인간 피드백 강화학습 (RLHF)RLHF▾A reinforcement learning method that aligns models using human preference feedback as reward. Used to suppress harmful LLM outputs.
ROC AUCAUC▾The area under the true-positive-rate vs false-positive-rate curve across thresholds, measuring classifier performance.
지도 학습 (Supervised Learning)▾Learning an input-output mapping from labeled data. Used for label-based detection such as spam/ham classification.
서포트 벡터 머신 (Support Vector Machine)SVM▾A classification algorithm that finds a hyperplane maximizing the margin between classes. Used in classic spam filters.
토큰화 (Tokenization)▾The preprocessing step of splitting text into smaller units called tokens for model input.
전이 학습 (Transfer Learning)▾A machine learning approach that reuses knowledge learned on one task for a related task. Useful in data-scarce security domains.
트랜스포머 (Transformer)▾A neural network architecture based on the self-attention mechanism, the core of modern LLMs. Excels at processing sequential data.
비지도 학습 (Unsupervised Learning)▾Learning structure or patterns from unlabeled data. Used in clustering-based anomaly detection.
벡터 데이터베이스 (Vector Database)▾A database that stores embedding vectors and performs approximate nearest-neighbor search. Used in RAG and semantic search.
一般資安與最新趨勢
랜섬웨어 / RaaS▾將資料加密以勒索贖金的惡意程式;RaaS(勒索軟體即服務)則是將其以訂閱模式販售的犯罪生態系統。
勒索軟體攻擊大多始於網路釣魚或憑證竊取,因此電子郵件資安是第一道防線;RaaS 更大幅降低了犯罪門檻,使攻擊目標不再侷限於大型企業。 常被忽略的一點:若備份也一併遭到加密或刪除,備份就形同虛設——務必確保有離線/不可竄改(immutable)備份、實際演練過的復原流程,並針對資料外洩勒索(雙重勒索)預先擬定對策。
閱讀更多 →중간자 피싱 (AiTM)AiTM▾透過即時代理攔截登入工作階段權杖,藉此繞過多因子驗證的網路釣魚手法(案例正快速增加)。
中間人式(AiTM)釣魚攻擊打破了「開啟 MFA 就安全」的既有認知,且案例數量正快速攀升——只要竊得工作階段權杖,即便密碼與 MFA 都完好無損,帳號依然會被開啟。 常被忽略的一點:一般的 MFA 無法擋下此類攻擊——務必加裝具抗釣魚能力的 MFA(如金鑰/FIDO2),並搭配異常工作階段與裝置的偵測機制。
閱讀更多 →MFA 피로 공격 (MFA fatigue)▾大量發送 MFA 推播請求,誘使使用者在不勝其擾之下誤觸「核准」的攻擊手法。
這類攻擊瞄準的是「人的疲勞與疏忽」,而非技術漏洞——因此啟用 MFA 並非防護的終點。 常被忽略的一點:應改用「數字比對」或具抗釣魚能力的 MFA,並訓練員工養成「收到非預期的 MFA 通知一律拒絕並回報」的習慣。
閱讀更多 →딥페이크 (Deepfake)▾以 AI 合成的語音或影像,用於冒充高階主管身分,大幅提升 BEC 與電話語音詐騙的殺傷力。
我們正進入一個「連電話語音與視訊通話都無法完全信任」的時代,實際發生的鉅額匯款詐騙案例已有所報導——聲音與臉孔這最後一道信任堡壘正逐漸瓦解。 常被忽略的一點:對於高額交易而言,「打電話確認」已不再安全——應建立跨管道、跨要素分離的驗證機制(如事先約定的暗語、回撥電話號碼、多方共同核准等)。
閱讀更多 →프롬프트 인젝션 (Prompt injection)▾在 AI 模型中植入隱藏指令,誘使其做出違背原意行為的攻擊手法(LLM 時代的新興威脅)。
企業在業務流程與產品中導入 AI 的同時,也開啟了一個全新的攻擊面(例如:藏在郵件或文件中的隱藏指令,可能挾持 AI 助理的行為)。 常被忽略的一點:這類風險並未列在傳統的資安檢核項目中——應將「AI 輸入的信任邊界」「輸出防護(Guardrails)」「AI 權限最小化」納入資安審查範疇。
閱讀更多 →섀도 AI (Shadow AI)▾員工將機敏資訊輸入未經核准的 AI 工具,因而引發資料外洩的風險。
出於提升效率的需求,員工很可能早已將程式碼、客戶資料、合約文件等貼到未經核准的 AI 工具中使用。 常被忽略的一點:一味全面禁止只會讓使用行為轉入地下——應同時提供安全的內部替代方案、訂立明確的 AI 使用政策,並搭配 DLP 防止機敏資料外洩。
閱讀更多 →제로 트러스트 (Zero Trust)▾「絕不信任、持續驗證」——以身分與情境(而非網路位置)作為存取控管依據的安全模型。
在遠距辦公與雲端化的時代,「身處企業內網=安全」的假設已不再成立,零信任因而成為事實上的資安基準。 常被忽略的一點:零信任是一段持續推進的旅程,而非一次性採購的產品——不應試圖一次到位,應從 MFA、最小權限、網路區隔、裝置信任等項目循序漸進地導入。
閱讀更多 →공급망 공격 (Supply chain attack)▾入侵受信任的廠商、軟體或更新管道,藉此一次性攻擊大量目標的手法。
即使企業內部資安做得再完善,只要受信任的第三方(廠商、開源專案、更新機制)遭到入侵,攻擊依然能長驅直入。 常被忽略的一點:容易將資安範疇僅侷限於自身的防護邊界內——應將供應商資安盡職調查、軟體物料清單(SBOM)、最小權限整合等項目正式納入政策規範。
閱讀更多 →EDR / XDR▾針對端點的偵測與應變(EDR),並延伸至電子郵件、雲端、網路等範疇的整合式偵測應變方案(XDR)。
串連電子郵件、端點與雲端的可視性,能讓企業追溯攻擊的完整路徑(從點擊郵件連結→裝置遭感染→擴散蔓延)。 常被忽略的一點:若只是導入工具卻沒有 24 小時全天候監控與應變人力,警示只會不斷堆積——應確認企業本身具備相應人力,或搭配 MDR(委外代管偵測應變服務)方案。
閱讀更多 →데이터 유출 방지DLP▾偵測並攔阻機敏資料透過電子郵件、上傳等管道外流的控管機制。
DLP 是法規遵循與營業機密保護的核心機制,而外寄電子郵件正是最常見的資料外洩管道。 常被忽略的一點:規則過於嚴格會妨礙正常作業,過於寬鬆則會導致外洩——應同步設計資料分類標準、例外處理機制與教育訓練,並將「誤寄郵件」等無心之過造成的外洩也納入防範範圍。
閱讀更多 →내부자 위협 (Insider threat)▾由內部人員(惡意或疏忽所致)造成的資訊外洩或損害;遭入侵的帳號其行為模式也如同內部人員一般。
企業往往專注於防範外部威脅,卻忽略了擁有最大存取權限的正是內部人員——而遭入侵的帳號,最終的行為模式其實也與正常內部人員無異。 常被忽略的一點:除了最小權限原則與行為監控之外,務必落實員工離職或部門異動時「立即回收存取權限」的離職/異動處理流程——這正是最常出問題的環節。
閱讀更多 →피싱 저항 MFA (Passkey / FIDO2)▾具備抗網路釣魚與中間人攻擊能力的驗證方式(金鑰、FIDO2 安全金鑰),是邁向無密碼化的方向。
這是目前對抗中間人攻擊(AiTM)與憑證竊取最有效的方式——攔截權杖的手法在此完全失效。 常被忽略的一點:全公司導入需要時間,應優先從高風險帳號(高階主管、系統管理員、財務人員等)開始,並同步建立遺失或復原的處理流程。
閱讀更多 →초기 침투 브로커IAB▾入侵企業後,將取得的存取權限轉售給其他攻擊者(如勒索軟體集團)的犯罪專門化角色。
這反映出網路犯罪已走向分工專業化——一個犯罪集團負責入侵並販售「鑰匙」,另一個集團則透過勒索軟體將其變現,使一次小規模的入侵最終演變為重大資安事件。 常被忽略的一點:容易輕忽「看似輕微」的網路釣魚或憑證外洩事件——事實上,阻斷初期入侵並迅速撤銷外洩憑證,本身就是防範勒索軟體攻擊最有效的手段。
閱讀更多 →공격 표면 관리ASM▾持續發現並管理對外曝露的資產、網域與服務,藉此縮小攻擊路徑的資安維運活動。
企業無法保護自己不知道存在的資產,而被遺忘的伺服器、測試用網域、閒置未清理的 SaaS 帳號,正是最常見的入侵切入點。 常被忽略的一點:僅做一次性的資產盤點很快就會過時——應納入持續性的自動化資產發現機制,並同步監控仿冒品牌的相似網域與對外曝露的服務。
閱讀更多 →