<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Secologies</title><description>探索資安的科學與實務</description><link>https://secologies.com/</link><language>zh</language><copyright>Copyright © 2026 黃宏勝 | Hong-Sheng Huang</copyright><managingEditor>黃宏勝 | Hong-Sheng Huang</managingEditor><webMaster>黃宏勝 | Hong-Sheng Huang</webMaster><lastBuildDate>Tue, 11 Aug 2026 03:49:48 GMT</lastBuildDate><generator>Astro RSS</generator><docs>https://www.rssboard.org/rss-specification</docs><ttl>60</ttl><item><title>對稱式密碼系統</title><link>https://secologies.com/posts/symmetric-key-encryption/</link><guid isPermaLink="true">https://secologies.com/posts/symmetric-key-encryption/</guid><description>那我為什麼還想談對稱式密碼系統呢？因為這些加解密演算法在硬體上或軟體上執行速度都是最快的，更何況進入 PQC 時代後，雖說量子電腦有辦法降低安全性，但是國外一些團隊認為設計更大的 key size 來防禦就行，所以有些研究員還是持續研究對稱式加密機制，因此這類系統很適合加密大量資料</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><keyword>對稱式密碼系統</keyword><category>block-cipher</category><category>stream-cipher</category><category>單一金鑰</category><category>對射</category><category>對稱式密碼系統</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>密碼學協定</title><link>https://secologies.com/posts/cryptographic-protocols/</link><guid isPermaLink="true">https://secologies.com/posts/cryptographic-protocols/</guid><description>隨著現代資訊系統跟資料型態越來越複雜，單一的密碼元件已經無法解決某些問題，所以我們會嘗試將不同的元件做組合，用一系列的操作來完成整個任務，這類定義好的步驟就被稱作密碼學協定(Cryptographic Protocol)</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><keyword>密碼學協定</keyword><category>challenge-and-response</category><category>cryptographic-primitives</category><category>cryptographic-protocol</category><category>公開金鑰簽章系統</category><category>密碼學元件</category><category>密碼學協定</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>認識網路釣魚之惡意 Payload、誤導以及障礙</title><link>https://secologies.com/posts/phishing-payloads-misdirection-and-speedbumps/</link><guid isPermaLink="true">https://secologies.com/posts/phishing-payloads-misdirection-and-speedbumps/</guid><description>當我們針對目標的前置研究全部都完成之後，我們就可以專注在要構成何種 Payload 來進行攻擊了，惡意組織跟攻擊者會使用不同的方法來傳送釣魚 payloads</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><keyword>網路釣魚之惡意 Payload</keyword><category>browser-in-the-middle</category><category>csrf</category><category>cve-2017-11882</category><category>cve-2022-41091</category><category>cve-2023-21608</category><category>cve-2023-21716</category><category>lapsus</category><category>mark-of-the-web</category><category>office-巨集</category><category>多因子驗證</category><category>惡意連結</category><category>網路釣魚</category><category>電子信箱</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>IACR RWC 2026 參與心得</title><link>https://secologies.com/posts/iacr-rwc-2026-experience/</link><guid isPermaLink="true">https://secologies.com/posts/iacr-rwc-2026-experience/</guid><description>很幸運本次可以在台灣參與由國際密碼研究學會 (International Association for Cryptologic Research, IACR) 所組織的真實世界密碼學研討會 (The Real World Crypto Symposium)</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate><keyword>IACR RWC 2026</keyword><category>diffie-hellman</category><category>iacr</category><category>international-association-for-cryptologic-research</category><category>real-world-cryptography-symposium</category><category>tamarin</category><category>tee</category><category>trusted-execution-environment</category><category>可信執行環境</category><category>國際密碼研究學會</category><category>真實世界密碼學研討會</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>密碼學的目標</title><link>https://secologies.com/posts/the-objectives-of-cryptography/</link><guid isPermaLink="true">https://secologies.com/posts/the-objectives-of-cryptography/</guid><description>我們使用密碼學技術的隱私性並非唯一的原因，尤其密碼研究已經很多年了，自然也提供許多種特性來幫助網路環境更加的安全，可以說密碼學應用在最後一道防線</description><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate><keyword>密碼學目標</keyword><category>mac</category><category>不可否認性</category><category>完整性</category><category>數位簽章</category><category>隱私性</category><category>驗證性</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>基礎密碼分析攻擊</title><link>https://secologies.com/posts/cryptanalysis-attakcs/</link><guid isPermaLink="true">https://secologies.com/posts/cryptanalysis-attakcs/</guid><description>我們在密碼學中最關注的目標是保護明文在網路上傳輸時，即使所有密文資訊都被攻擊者竊聽走，他們也解不開來，以及無法從獲得的資訊找出跟明文之間的關聯，那麼，我們假設的這個敵人到底會嘗試做什麼呢？</description><pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate><keyword>密碼分析</keyword><category>唯密文攻擊</category><category>密碼分析</category><category>已知明文攻擊</category><category>自適應選定密文攻擊</category><category>自適應選定明文攻擊</category><category>選定密文攻擊</category><category>選定明文攻擊</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>基礎網路釣魚攻擊</title><link>https://secologies.com/posts/phishing-basics/</link><guid isPermaLink="true">https://secologies.com/posts/phishing-basics/</guid><description>我們時常聽到的網路釣魚 (Phishing) 除了有著技術性細節，同時也有社會操控的因素包含在內，專業的組織會將其考慮為一項策略，並且精確的針對目標進行網路犯罪攻擊，通常我們會將網路釣魚攻擊分成兩類：普遍性網路釣魚 (大規模的攻擊)以及魚叉式網路釣魚 (目標導向的攻擊)</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><keyword>網路釣魚攻擊</keyword><category>deepfake</category><category>llm</category><category>rag</category><category>生成式-ai</category><category>社交工程</category><category>簡訊釣魚</category><category>網路釣魚攻擊</category><category>語音釣魚</category><category>通訊軟體釣魚</category><category>電子郵件釣魚</category><category>魚叉式網路釣魚</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>2026 Real World Crypto 研討會 於 臺北舉辦 活動日期：2026年3月9號至11號</title><link>https://secologies.com/posts/2026-real-world-crypto-symposium-in-taiwan/</link><guid isPermaLink="true">https://secologies.com/posts/2026-real-world-crypto-symposium-in-taiwan/</guid><description>Real World Crypto 研討會是由國際密碼研究學會 (The International Association for Cryptologic Research, IACR) 所組織的其中一場活動，該研討會宗旨是將學界與工程界之間建立橋樑，共同探討在現實世界實作密碼系統上會遇到哪些問題</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate><keyword>Real World Crypto 研討會</keyword><category>iacr</category><category>real-world-cryptography-symposium</category><category>the-international-association-for-cryptologic-research</category><category>workshop</category><category>國際密碼研究學會</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>自動化 SQL Injection 漏洞執行</title><link>https://secologies.com/posts/manual-and-automated-code-execution-in-sql-injection/</link><guid isPermaLink="true">https://secologies.com/posts/manual-and-automated-code-execution-in-sql-injection/</guid><description>取決於作業系統、服務的權限以及檔案系統的存取範圍，SQL Injection 漏洞可以被用來讀寫目標作業系統下的檔案，當我們做出一份包含 PHP 程式碼的檔案，並且放進網頁伺服器裡的 root 路徑時，我們可以利用該檔案來獲得完整的隨意程式執行</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate><keyword>SQL Injection</keyword><category>mssql</category><category>mysql</category><category>sqlmap</category><category>sql注入</category><category>xp_cmdshell</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>手動 SQL Injection 漏洞利用</title><link>https://secologies.com/posts/manual-sql-injection-exploitation/</link><guid isPermaLink="true">https://secologies.com/posts/manual-sql-injection-exploitation/</guid><description>在背景介紹中我們介紹了 SQL 基本指令以及兩個主要的關聯式資料庫，接著我們可以來看如何識別 SQL 注入漏洞後並進行利用，SQL Injection vulnerability 經常被 sqlmap 這個自動化工具發現，或者在操作時誤用觸發到</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><keyword>SQL Injection manual</keyword><category>boolean-based</category><category>sql-injection</category><category>time-based</category><category>union-based</category><category>盲-sql-injection</category><category>錯誤導向-payload</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>量子錯誤更正發展工作坊 參與心得</title><link>https://secologies.com/posts/workshop-on-advances-in-quantum-error-correction-reflections-on-participation/</link><guid isPermaLink="true">https://secologies.com/posts/workshop-on-advances-in-quantum-error-correction-reflections-on-participation/</guid><description>於2025年底由賴青沂教授 hosting 的這場量子錯誤更正碼 (Quantum Error-Correction Codes, QEC) 工作坊，原本預期以 Advances 為核心，展示最新前沿研究內容</description><pubDate>Mon, 29 Dec 2025 00:00:00 GMT</pubDate><keyword>量子錯誤更正碼</keyword><category>qldpc</category><category>qubit</category><category>workshop</category><category>量子容錯計算</category><category>量子輔助位元</category><category>量子錯誤更正碼</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>MITRE ATT&amp;CK 框架</title><link>https://secologies.com/posts/mitre-attack-framework/</link><guid isPermaLink="true">https://secologies.com/posts/mitre-attack-framework/</guid><description>MITRE 於 2013 年啟動 ATT&amp;CK 架構，旨在建立全球可結構化查詢的網路攻擊戰術和技術知識庫，反應出駭客發起攻擊生命週期的各個階段以及已知的目標平台，該架構重點關注外部惡意者如何入侵與操作電腦資訊，其知識庫被用作民營部門、政府部門、企業和個人開發特定威脅模型和方法的基礎</description><pubDate>Thu, 25 Dec 2025 00:00:00 GMT</pubDate><keyword>MITRE ATT&amp;CK</keyword><category>mitre-attck</category><category>stix格式</category><category>戰術</category><category>技術</category><category>程序</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>《量子錯誤更正發展工作坊》於 陽明交通大學 光復校區 工程四館 219 活動日期：2025年12月29日</title><link>https://secologies.com/posts/workshop-on-advances-in-quantum-error-correction-in-nycu/</link><guid isPermaLink="true">https://secologies.com/posts/workshop-on-advances-in-quantum-error-correction-in-nycu/</guid><description>Workshop on Advances in Quantum Error Correction（量子錯誤更正發展工作坊）是一場聚焦於量子錯誤更正碼（Quantum Error-Correcting Codes, QEC）與容錯量子計算（Fault-Tolerant Quantum Computing, FTQC）的全天研討會，同時兼具教育推廣與學術發展的目標</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate><keyword>量子錯誤更正碼</keyword><category>belief-propagation</category><category>qldpc</category><category>workshop</category><category>容錯量子計算</category><category>量子錯誤更正碼</category><category>陽明交通大學</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>SQL注入漏洞之背景介紹</title><link>https://secologies.com/posts/sql-injection-vulnerability-theory-and-database/</link><guid isPermaLink="true">https://secologies.com/posts/sql-injection-vulnerability-theory-and-database/</guid><description>SQL注入(SQL Injection, SQLi)攻擊在網頁應用服務當中是很主要的漏洞之一，普遍到被OWASP這個組織蒐錄在OWASP Top 10應用服務安全清單裡，其中在2025年版本清單中名列第五</description><pubDate>Sun, 07 Dec 2025 00:00:00 GMT</pubDate><keyword>SQL Injection</keyword><category>impacket</category><category>mysql</category><category>owasp</category><category>sql注入</category><category>微軟sql</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>指令注入漏洞</title><link>https://secologies.com/posts/command-injection-vulnerability/</link><guid isPermaLink="true">https://secologies.com/posts/command-injection-vulnerability/</guid><description>說到指令，讀者會想像到何種情境呢？ 通常我們在Windows上可以用命令提示字元，而在Mac跟Linux上有內建的終端機可以讓我們輸入指令，而這些功能都植基在系統上，所以指令注入最基本就是針對系統提供的指令進行操作</description><pubDate>Sat, 29 Nov 2025 00:00:00 GMT</pubDate><keyword>指令注入</keyword><category>archive</category><category>petserai</category><category>powercat</category><category>url編碼</category><category>指令注入</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>常見網頁應用服務攻擊之檔案上傳漏洞</title><link>https://secologies.com/posts/file-upload-vulnerabilities-executable-and-non-executable-files/</link><guid isPermaLink="true">https://secologies.com/posts/file-upload-vulnerabilities-executable-and-non-executable-files/</guid><description>通常只要網頁需要跟使用者進行互動，都會提供檔案上傳的功能，但這也會出現問題，我們可以利用檔案上傳漏洞(File Upload Vulnerability)來存取伺服器系統或者執行惡意code，通常檔案上傳漏洞可以被分成三個種類</description><pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate><keyword>檔案上傳漏洞</keyword><category>php</category><category>web-shell</category><category>檔案上傳</category><category>目錄遍歷漏洞</category><category>相對路徑</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>常見網頁應用服務攻擊之檔案引用漏洞 LFI&amp;RFI</title><link>https://secologies.com/posts/file-inclusion-vulnerabilities-lfi-and-rfi/</link><guid isPermaLink="true">https://secologies.com/posts/file-inclusion-vulnerabilities-lfi-and-rfi/</guid><description>常見的網頁應用服務漏洞攻擊系列除了我們提到目錄遍歷漏洞攻擊之外，再來談檔案引用漏洞，我們會分析這個漏洞跟目錄遍歷之間的差異，並且向各位介紹本地檔案引用(Local File Inclusion, LFI)以及遠端檔案引用(Remote, File Inclusion, RFI)</description><pubDate>Sun, 02 Nov 2025 00:00:00 GMT</pubDate><keyword>LFI &amp; RFI</keyword><category>lfi</category><category>php封裝器</category><category>rfi</category><category>wrapper</category><category>本地檔案引用</category><category>遠端檔案引用</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>常見網頁應用服務攻擊之目錄遍歷漏洞 Directory Traversal</title><link>https://secologies.com/posts/directory-traversal-vulnerability/</link><guid isPermaLink="true">https://secologies.com/posts/directory-traversal-vulnerability/</guid><description>網頁開發在LLM盛行之前的需求非常廣泛，到了諸多MCP可以使用的時代之後，我覺得深刻了解網頁應用服務開發的需求又更加重要了，雖然小型的專案各位可以透過各大線上LLM服務產出內容，但如果缺乏網頁開發者的背景知識、專案的時間壓力以及日新月異的框架新技術變更</description><pubDate>Sat, 25 Oct 2025 00:00:00 GMT</pubDate><keyword>Directory Traversal</keyword><category>字元編碼</category><category>目錄遍歷</category><category>相對路徑</category><category>絕對路徑</category><category>網頁應用服務攻擊</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>利用 XSS 提權</title><link>https://secologies.com/posts/privilege-escalation-via-xss/</link><guid isPermaLink="true">https://secologies.com/posts/privilege-escalation-via-xss/</guid><description>在前一篇介紹 Cross-Site Scripting (XSS) 之後，讓我們來實驗一下在 Wordpress 上如何運作基本的 XSS 攻擊</description><pubDate>Sat, 18 Oct 2025 00:00:00 GMT</pubDate><keyword>XSS</keyword><category>user-agent</category><category>visitors</category><category>wordpress</category><category>xss</category><category>提權</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Cross-Site Scripting (XSS) 跨網站腳本漏洞</title><link>https://secologies.com/posts/cross-site-scripting-xss-introduction/</link><guid isPermaLink="true">https://secologies.com/posts/cross-site-scripting-xss-introduction/</guid><description>在網頁安全當中，資料消毒，是其中一種最重要的功能，其目的在於處理使用者輸入的內容，將有問題的字元或字串等移除掉或做變換處理，如果一個網站的輸入欄位不做任何的檢查，勢必會讓攻擊者進行注入的動作，最終可以在讀者的網頁服務上執行惡意的行為</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><keyword>Cross-Site Scripting</keyword><category>cross-site-scripting</category><category>html編碼</category><category>reflected</category><category>stored</category><category>url編碼</category><category>xss</category><category>資料消毒</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>APT27 ProxyLogon 攻擊行為對安全的影響評估與防禦對策</title><link>https://secologies.com/posts/assessment-of-proxylogon-of-apt27-attack-behaviors/</link><guid isPermaLink="true">https://secologies.com/posts/assessment-of-proxylogon-of-apt27-attack-behaviors/</guid><description>本文想要讓讀者了解的是以下三點，首先是希望能讓大家認識APT27這個惡意組織以及這個組織常用的攻擊手法為何，其次就是針對前述提到的攻擊方法將會帶給讀者一些防禦的策略，最後就是想讓各位認識的是APT27這個組織對於企業或產業會產生什麼影響</description><pubDate>Sun, 12 Oct 2025 00:00:00 GMT</pubDate><keyword>APT27 ProxyLogon</keyword><category>apt27</category><category>cyber-kill-chain</category><category>exchange</category><category>proxylogon</category><category>stix</category><category>ttps</category><category>zero-day</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>錯誤更正碼之數位資料通訊及儲存</title><link>https://secologies.com/posts/error-correction-codes-digital-data-communication-and-storage/</link><guid isPermaLink="true">https://secologies.com/posts/error-correction-codes-digital-data-communication-and-storage/</guid><description>我們每天一早醒來的生活中充斥著各種數位通訊系統，最常見的就是手機、透過衛星或光纖傳輸的數位電視、數位廣播、Wi-Fi無線網路、WiMax以及光纖數據機轉送無線網路設備等等</description><pubDate>Sat, 11 Oct 2025 00:00:00 GMT</pubDate><keyword>錯誤更正碼</keyword><category>c-e-shannon</category><category>channel</category><category>channel-capacity</category><category>encoder</category><category>modulator</category><category>source</category><category>錯誤更正碼</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網頁應用服務枚舉</title><link>https://secologies.com/posts/web-application-enumeration/</link><guid isPermaLink="true">https://secologies.com/posts/web-application-enumeration/</guid><description>現今存在數種技巧可以直接從瀏覽器取得相關的資訊，現代瀏覽器裡的開發者工具可以協助我們進行枚舉，雖說開發者工具如其名應該是給網頁開發者使用的，但也很適合給我們在做滲透測試時取得目標服務的一些資訊</description><pubDate>Fri, 10 Oct 2025 00:00:00 GMT</pubDate><keyword>網頁應用服務</keyword><category>api</category><category>curl</category><category>debugger</category><category>http-header</category><category>rest-api</category><category>sitemap</category><category>標頭檔</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網頁應用服務安全性評估</title><link>https://secologies.com/posts/web-application-security-assessment/</link><guid isPermaLink="true">https://secologies.com/posts/web-application-security-assessment/</guid><description>網頁，一個你我每天都會使用到的應用服務或程式，可以說是每天醒來後第一個接觸的系統了，現代許多框架或主機服務都可以部署成網頁應用服務了，但在網路安全的世界中，方便即是安全的反面</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><keyword>網頁應用服務安全</keyword><category>burp-suite</category><category>gobuster</category><category>nmap</category><category>wappalyzer</category><category>灰箱測試</category><category>白箱測試</category><category>網頁安全</category><category>黑箱測試</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Nmap 弱點掃描</title><link>https://secologies.com/posts/vulnerability-scanning-with-nmap/</link><guid isPermaLink="true">https://secologies.com/posts/vulnerability-scanning-with-nmap/</guid><description>在主動式資料搜集之DNS枚舉與Port掃描章節我們提到了Nmap這款port掃描工具，以及它強大的客製化Nmap腳本引擎(Nmap Scripting Engine, NSE)，有時候在時間的限制下我們不適合使用Nessus這款商業化強大但耗時的工具，這時一些輕量級的漏洞掃描工具就是很好的選擇</description><pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate><keyword>Nmap</keyword><category>cve</category><category>nmap</category><category>nmap-scripting-engine</category><category>弱點掃描</category><category>漏洞掃描</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Nessus 弱點掃描</title><link>https://secologies.com/posts/vulnerability-scanning-with-nessus/</link><guid isPermaLink="true">https://secologies.com/posts/vulnerability-scanning-with-nessus/</guid><description>Nessus - 在Kali Linux內漏洞掃描著名的工具之一，蒐錄超過67000份CVE以及超過168000個插件可以使用，有基本款以及專業款兩個差異</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><keyword>Nessus</keyword><category>cve</category><category>nessus</category><category>tenable</category><category>弱點掃描</category><category>漏洞掃描</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>漏洞掃描理論</title><link>https://secologies.com/posts/vulnerability-scanning-theory/</link><guid isPermaLink="true">https://secologies.com/posts/vulnerability-scanning-theory/</guid><description>找出漏洞是安全性評估裡不可或缺的一環，針對軟體、系統或者網路嘗試探索攻擊層面的流程就稱作漏洞掃描(Vulnerability Scanning)，市面上有許多的漏洞掃描工具，從基本單一腳本搜索單獨的漏洞，到能夠複雜搜索大範圍的商業工具</description><pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate><keyword>漏洞掃描</keyword><category>common-vulnerabilities-and-exposures</category><category>common-vulnerability-scoring-system</category><category>cve</category><category>cvss</category><category>false-negative</category><category>false-positive</category><category>national-vulnerability-database</category><category>nvd</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>LLM主動式資料搜集</title><link>https://secologies.com/posts/llm-powered-active-information-gathering/</link><guid isPermaLink="true">https://secologies.com/posts/llm-powered-active-information-gathering/</guid><description>在LLM被動式資料搜集一章我們提到現今的LLM可以如何的幫助我們，同樣的角度我們也可以來看LLM如何在主動式枚舉上幫助我們發現目標機器裡沒注意到的線索，例如DNS枚舉找出DNS server裡子網域、信件server以及name server等資訊，配上LLM，我們可以讓這項功能更強大</description><pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate><keyword>LLM 主動式資料蒐集</keyword><category>chatgpt</category><category>dns枚舉</category><category>gobuster</category><category>主動式資料搜集</category><category>大語言模型</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>主動式資料搜集之SMB、SMTP、SNMP枚舉</title><link>https://secologies.com/posts/active-information-gathering-smb-smtp-snmp-enumeration/</link><guid isPermaLink="true">https://secologies.com/posts/active-information-gathering-smb-smtp-snmp-enumeration/</guid><description>在主動式資料搜集之DNS枚舉與Port掃描一章我們提及針對目標機器的DNS與Port掃描來建立攻擊劇本(LOLBAS)，而現代設備中不只有這兩種方法，我們將於本章說明其他可以搜集的資訊，包括SMB、SMTP以及SNMP的枚舉，找出更多資訊能讓我們縮小下一次的範圍</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><keyword>SMB 枚舉, SMTP 枚舉, SNMP 枚舉</keyword><category>netcat</category><category>nmap</category><category>smb</category><category>snmp</category><category>主動式資料搜集</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>主動式資料搜集之DNS枚舉與Port掃描</title><link>https://secologies.com/posts/active-information-gathering-dns-enumeration-and-port-scanning/</link><guid isPermaLink="true">https://secologies.com/posts/active-information-gathering-dns-enumeration-and-port-scanning/</guid><description>不同於被動式，在主動式資料搜集時我們將直接與目標服務進行互動，目標的機器上肯定有著無數的服務可以接觸</description><pubDate>Sat, 13 Sep 2025 00:00:00 GMT</pubDate><keyword>主動式資料蒐集</keyword><category>dns</category><category>dns枚舉</category><category>lolbas</category><category>lolbins</category><category>nmap</category><category>tcp-udp</category><category>主動式資料搜集</category><category>端口掃描</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>LLM被動式資料搜集</title><link>https://secologies.com/posts/llm-powered-passive-information-gathering/</link><guid isPermaLink="true">https://secologies.com/posts/llm-powered-passive-information-gathering/</guid><description>在現今這個AI Agent的時代，我們可以利用大語言模型(Large Language Models, LLMs)強化我們的被動偵查，協助我們更有效率的搜集、處理以及合成資料</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate><keyword>LLM 被動式資料蒐集</keyword><category>chatgpt</category><category>llm</category><category>osint</category><category>大語言模型</category><category>被動式資料搜集</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>被動式資料搜集</title><link>https://secologies.com/posts/passive-information-gathering/</link><guid isPermaLink="true">https://secologies.com/posts/passive-information-gathering/</guid><description>被動式的收集資料有時候稱為開源情報(Open-Source Intelligence, OSINT)，是針對目標機器搜集一套對外開放服務的資訊，通常不需要跟目標機器用command互動，這也是讓我們的行為不會被目標機器錄下來，在開始介紹工具前，我們對於被動式搜集的情境先介紹一下兩種不同解釋</description><pubDate>Sun, 07 Sep 2025 00:00:00 GMT</pubDate><keyword>被動式資料蒐集</keyword><category>google-hacking</category><category>netcraft</category><category>open-source-code</category><category>osint</category><category>security-headers</category><category>shodan</category><category>ssl-tls</category><category>whois</category><category>被動式資料搜集</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>資訊搜集簡介</title><link>https://secologies.com/posts/information-gathering-introduction/</link><guid isPermaLink="true">https://secologies.com/posts/information-gathering-introduction/</guid><description>從客戶端的攻擊層面學習被動式與主動式資訊搜集技術取得的資料可以利用在整個滲透測試生命週期，為了讓組織內的安全意識盡可能地保持最新</description><pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate><keyword>資料蒐集</keyword><category>主動式</category><category>偵察</category><category>被動式</category><category>資訊搜集</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>剖析網路安全結構</title><link>https://secologies.com/posts/anatomy-of-cybersecurity/</link><guid isPermaLink="true">https://secologies.com/posts/anatomy-of-cybersecurity/</guid><description>基本上網路安全其目的就是為了組織的風險管理而存在的，探討網路科技所帶來的威脅是如何影響到公司資產，這些系統能為公司帶來商業價值，同樣也可以造成等值的商業損失，所以我們才需要想控管機制來管理風險，我們利用網路安全的方法來解析數種元素之間的關係</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><keyword>網路安全</keyword><category>iso27000</category><category>nist網路安全框架</category><category>架構</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路安全從業職位</title><link>https://secologies.com/posts/career-opportunities-in-cybersecurity/</link><guid isPermaLink="true">https://secologies.com/posts/career-opportunities-in-cybersecurity/</guid><description>隨著網路技術越來越發達，越來越多的網路安全職業出現，許多公司也出現不同職稱的角色，每個角色需要的技能都不太相同，畢竟技術越來越細節且複雜，不過讀者還是可以記住一些的工作職位，以及這些職缺的人員每天都做些什麼工作</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><keyword>網路安全</keyword><category>安全架構</category><category>架構</category><category>滲透測試員</category><category>紅隊</category><category>網路安全職業</category><category>藍隊</category><category>資安長</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>資安標準與框架簡介</title><link>https://secologies.com/posts/cybersecurity-standards-and-frameworks-introduction/</link><guid isPermaLink="true">https://secologies.com/posts/cybersecurity-standards-and-frameworks-introduction/</guid><description>遵照已經審查過的標準與框架可以加快我們在組織內施行相關安全政策的速度，尤其PCI DSS、CIS Top 18、NIST網路安全框架、MITRE ATT&amp;CK跟D3FEND、ISA/IEC 62443、Cyber Kill Chain、FedRAMP等經過審查的標準與框架更是值得參考</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><keyword>資安標準與框架</keyword><category>cis-top-18</category><category>cyber-kill-chain</category><category>fedramp</category><category>isa-iec-62443</category><category>mitre</category><category>mitre-attck</category><category>mitre-d3fend</category><category>nist網路安全框架</category><category>pci-dss</category><category>框架</category><category>標準</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>資安法規簡介</title><link>https://secologies.com/posts/cybersecurity-laws-and-regulations-introduction/</link><guid isPermaLink="true">https://secologies.com/posts/cybersecurity-laws-and-regulations-introduction/</guid><description>目前世上有一些資安法規根據國家或者地區管轄權所制定出來的，大部分可以遵守的是美國的法規，但也有一些可以應用到國際法庭上，作為資安專業學習人我們也應該要很注重法規的制定及應用範圍，才不會在這條路上迷失自己</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><keyword>資安法規</keyword><category>ccpa</category><category>ferpa</category><category>gdpr</category><category>glba</category><category>hipaa</category><category>歐盟</category><category>美國</category><category>金鑰揭露法案</category><category>隱私性</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Log 檔與混沌測試</title><link>https://secologies.com/posts/logging-and-chaos-testing/</link><guid isPermaLink="true">https://secologies.com/posts/logging-and-chaos-testing/</guid><description>組織把非常細節的資訊紀錄起來以利之後搜尋是非常重要的，尤其是所有技術型操作的紀錄更是安全設計上關鍵的一環，保持資料的一致、標準的規格以及足夠的細節能夠讓資安團隊在遇到事件時快速處理問題，能夠及早偵測出入侵路徑</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><keyword>Log</keyword><category>log-檔</category><category>log紀錄</category><category>商業持續規劃</category><category>混沌測試</category><category>災害復原</category><category>資源註冊</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路安全的加密策略</title><link>https://secologies.com/posts/cybersecurity-encryption/</link><guid isPermaLink="true">https://secologies.com/posts/cybersecurity-encryption/</guid><description>比起追蹤軟體的修補進度，眾多公司更仰賴於加密技術，加密比起任何一種安全性控管機制還來的更安全，但卻無法成為所有問題的解決方法，所以還是需要與多層的安全性控管合作創造更強大的保護</description><pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate><keyword>網路安全加密</keyword><category>tls</category><category>加密</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>備份策略</title><link>https://secologies.com/posts/backups/</link><guid isPermaLink="true">https://secologies.com/posts/backups/</guid><description>備份 (Backup)，適時地將資料複製起來，能夠幫助我們將被篡改或刪除的資料復原回來，尤其這個時代資料被刪除或篡改都有好幾種方法</description><pubDate>Sun, 31 Aug 2025 00:00:00 GMT</pubDate><keyword>備份</keyword><category>cold</category><category>differential</category><category>full</category><category>hot</category><category>incremental</category><category>備份</category><category>異地備份</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>持續性修復及供應鏈驗證</title><link>https://secologies.com/posts/continuous-patching-and-supply-chain-validation/</link><guid isPermaLink="true">https://secologies.com/posts/continuous-patching-and-supply-chain-validation/</guid><description>其中一項防禦策略則是持續性自動修復技術，取得最上游的開發商所發佈出來的最新版code內容複寫至最底層的開發環境裡，接著如果取得的內容測試都有成功就放進產品內</description><pubDate>Sun, 31 Aug 2025 00:00:00 GMT</pubDate><keyword>持續性修復與供應鏈</keyword><category>sbom</category><category>供應鏈驗證</category><category>持續性修復</category><category>軟體物料清單</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>檯面策略</title><link>https://secologies.com/posts/table-top-tactics/</link><guid isPermaLink="true">https://secologies.com/posts/table-top-tactics/</guid><description>組織如果已經接收到一些重要或威脅情報資訊的話，可以安排跨部門的討論，其中一種就是檯面討論(Table-top)，基本上可以找工程師、架構師以及資安專業的員工一起討論目前公司可能會遇到的危害或攻擊可能性</description><pubDate>Sun, 31 Aug 2025 00:00:00 GMT</pubDate><keyword>Table top tactics</keyword><category>table-top</category><category>ttps</category><category>技術</category><category>檯面策略</category><category>流程</category><category>策略</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>硬體木馬簡介</title><link>https://secologies.com/posts/hardware-trojan-introduction/</link><guid isPermaLink="true">https://secologies.com/posts/hardware-trojan-introduction/</guid><description>何謂木馬硬體？基本上就是在現有電路元件上加入惡意的元件或變更舊有的功能，實現在原本的電路中製造木馬或者後門給攻擊者，硬體木馬可以改變原有的功能行為</description><pubDate>Sat, 30 Aug 2025 00:00:00 GMT</pubDate><keyword>硬體木馬</keyword><category>ic晶片</category><category>ip設計</category><category>side-channel攻擊</category><category>密碼模組</category><category>硬體木馬</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>威脅模型及威脅情報</title><link>https://secologies.com/posts/threat-modeling-threat-intelligence/</link><guid isPermaLink="true">https://secologies.com/posts/threat-modeling-threat-intelligence/</guid><description>在針對組織內部研究是否有潛在漏洞之前，更重要的是對公司內部的資產有更詳細的調查</description><pubDate>Fri, 29 Aug 2025 00:00:00 GMT</pubDate><keyword>威脅模型</keyword><category>威脅情報</category><category>威脅模型</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>管理員權限分割</title><link>https://secologies.com/posts/administrative-segmentation/</link><guid isPermaLink="true">https://secologies.com/posts/administrative-segmentation/</guid><description>在一個系統內管理員基於身份及功能權限可以直接繞過安全控管機制似乎是很合理的，但我們真的能信任這個系統管理員嗎？</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><keyword>管理員身份權限分割</keyword><category>shamirs-secret-sharing</category><category>權限分割</category><category>系統管理員</category><category>身份驗證資料</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>左移安全 Shift-Left Security</title><link>https://secologies.com/posts/shift-left-security/</link><guid isPermaLink="true">https://secologies.com/posts/shift-left-security/</guid><description>雖說有許多的機制或技術可以幫助使用者防禦攻擊，不過比起使用更多的軟體或服務，最能夠避免這些麻煩跟影響可用性的方法大概只有設計系統時從底層就把安全架構給考量進去，在設計安全的系統時左移安全是最有效率的方法之一</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><keyword>Shift-Left Security</keyword><category>shift-left-security</category><category>左移安全</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>安全性模型</title><link>https://secologies.com/posts/security-models/</link><guid isPermaLink="true">https://secologies.com/posts/security-models/</guid><description>安全性模型屬於一種在系統內實作安全性控管的架構，很少指定要特別用哪種控管方法，通常是用理論型的框架或者一些條件建議實作方向來符合某些情境，許多模型針對的都是Access Control，而有些則特別注重隱私性及完整性</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><keyword>安全性模型</keyword><category>attribute-based</category><category>bell-lapadula</category><category>biba</category><category>brewer-and-nash</category><category>clark-wilson</category><category>role-based</category><category>安全性模型</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>安全性管控及策略</title><link>https://secologies.com/posts/security-control-strategies/</link><guid isPermaLink="true">https://secologies.com/posts/security-control-strategies/</guid><description>為了完美的滿足安全性原則，策略是不可或缺的，像是：24/7警戒系統、威脅模型、沙盤討論、持續針對攻擊手法、流程及步驟進行更新訓練、持續自動修補漏洞、安全性設計系統撰寫、每日查看系統Log、多層實現安全性控管</description><pubDate>Sat, 16 Aug 2025 00:00:00 GMT</pubDate><keyword>安全性控管</keyword><category>24-7警戒</category><category>威脅模型</category><category>安全性控管</category><category>成本</category><category>投資</category><category>策略</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>安全性原則</title><link>https://secologies.com/posts/security-principles/</link><guid isPermaLink="true">https://secologies.com/posts/security-principles/</guid><description>最小權限原則:此概念認為系統內各個元件只需要取得能完成任務的最小存取權限即可，不論是使用者在機器上可使用的功能，或是程式裡顯示多少行code，嚴格遵守這項信念從過去的經驗來看可以減少許多攻擊面</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate><keyword>安全性原則</keyword><category>公開性安全</category><category>最小權限原則</category><category>防禦深度</category><category>零信任</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>CIA安全三角</title><link>https://secologies.com/posts/the-cia-triad/</link><guid isPermaLink="true">https://secologies.com/posts/the-cia-triad/</guid><description>在探索紅隊技術之前我們需要了解防禦方遵守哪些原則，如此才能快速找出藍隊人員的弱點，反之優秀的防禦方擁有攻擊者的視角，能夠針對死角提高防禦讓攻擊成本提高，使得惡意組織放棄攻擊</description><pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate><keyword>CIA Triad</keyword><category>availability</category><category>cia</category><category>confidentiality</category><category>integrity</category><category>可用性</category><category>完整性</category><category>平衡</category><category>責任</category><category>隱私性</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>現代常見的網路安全攻擊</title><link>https://secologies.com/posts/cybersecurity-attack-breaches/</link><guid isPermaLink="true">https://secologies.com/posts/cybersecurity-attack-breaches/</guid><description>在網路威脅角色分類中我們提及了有哪些攻擊者存在於網路上，而此篇我們就針對近期所發生過的攻擊事件提現代常用的手法，對於企業、個人及受害者會造成哪些損害，再想想有哪些方法可以避免這些攻擊</description><pubDate>Sun, 27 Jul 2025 00:00:00 GMT</pubDate><keyword>網路安全</keyword><category>勒索軟體</category><category>攻擊</category><category>社交工程</category><category>網路釣魚</category><category>身份驗證資訊濫用</category><category>驗證繞過</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路威脅角色分類</title><link>https://secologies.com/posts/threat-actor-classifications/</link><guid isPermaLink="true">https://secologies.com/posts/threat-actor-classifications/</guid><description>在網路威脅種類章節我們提到了現有的網路存在哪些威脅，而資安專家通常對於其中的威脅角色更感興趣</description><pubDate>Sun, 13 Jul 2025 00:00:00 GMT</pubDate><keyword>網路威脅角色</keyword><category>威脅角色</category><category>網路威脅</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路威脅種類</title><link>https://secologies.com/posts/cybersecurity-risk-threat-vulnerability-exploit/</link><guid isPermaLink="true">https://secologies.com/posts/cybersecurity-risk-threat-vulnerability-exploit/</guid><description>威脅也隨之而來，並不是所有的資料或服務要給隨意一個人觀看/使用，有時候必須讓不同權限人士觀看不同資料的需求也衍生出來</description><pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate><keyword>網路威脅</keyword><category>威脅</category><category>弱點</category><category>漏洞</category><category>風險</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路安全的挑戰</title><link>https://secologies.com/posts/challenges-in-cybersecurity/</link><guid isPermaLink="true">https://secologies.com/posts/challenges-in-cybersecurity/</guid><description>時至今日，學術界跟公部門常說資訊安全或者業界常講的網路安全已經成為一種獨立的專業，雖然大部分公司也只能請網管兼職做相關的設定，然而隨著網路攻擊面向越來越多，已經無法將其單純視為軟體工程或者系統設計裡的一種子領域</description><pubDate>Sat, 10 May 2025 00:00:00 GMT</pubDate><keyword>網路安全</keyword><category>弱點</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>網路攻防：知己知彼，百戰不殆</title><link>https://secologies.com/posts/emulating-minds-of-opponents/</link><guid isPermaLink="true">https://secologies.com/posts/emulating-minds-of-opponents/</guid><description>作為公司的網管平常也是值得停下來思考攻擊層面的安全性，為的是透過駭客的角度更深入的挖掘防禦手段</description><pubDate>Sat, 10 May 2025 00:00:00 GMT</pubDate><keyword>網路攻防</keyword><category>滲透測試</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>PQCrypto 2025 參加心得</title><link>https://secologies.com/posts/pqcrypto-2025-conference-experience/</link><guid isPermaLink="true">https://secologies.com/posts/pqcrypto-2025-conference-experience/</guid><description>2025年的PQCrypto研討會選擇辦在台灣，剛好是由中研院資科所的老師們當Co-Chairs來組織，有這個機會就來參加一下</description><pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate><keyword>PQCrypto 2025</keyword><category>nist</category><category>pqcrypto</category><category>中研院</category><category>後量子密碼學</category><category>研討會</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>全球供應鏈IC之設計威脅</title><link>https://secologies.com/posts/global-supply-chain-ic-threat/</link><guid isPermaLink="true">https://secologies.com/posts/global-supply-chain-ic-threat/</guid><description>硬體的安全問題其實主要來自於兩個方面 1. 不同設計層級舊有的問題被整合時所繼承 2.目前電子廠商沒有考慮設計robust的硬體元件來支援軟體或系統安全 上述兩點其實也點出了硬體的信任問題其實就出在IC製造過程中可能引入了不可信任的元件</description><pubDate>Sun, 30 Mar 2025 00:00:00 GMT</pubDate><keyword>全球供應鏈 IC 威脅</keyword><category>ic設計</category><category>ip設計</category><category>全球供應鏈</category><category>威脅模型</category><category>硬體威脅</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>完美保密性</title><link>https://secologies.com/posts/perfect-secrecy/</link><guid isPermaLink="true">https://secologies.com/posts/perfect-secrecy/</guid><description>在1978年Ralph C. Merkle提出了一篇&quot;Secure communications over insecure channels&quot;想法之後，人們開始意識到在網路上傳輸資料時其實存在著攻擊者(adversary)在監聽我們的溝通，從而開始發展要混淆傳輸的資料使得在不安全的環境中也可以安心傳輸</description><pubDate>Sun, 26 Jan 2025 00:00:00 GMT</pubDate><keyword>Perfect Secrecy</keyword><category>perfect-secrecy</category><category>完美隱密</category><category>密文空間</category><category>明文空間</category><category>機率分布</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>PUF 晶片上的物理不可複製功能</title><link>https://secologies.com/posts/physical-unclonable-function/</link><guid isPermaLink="true">https://secologies.com/posts/physical-unclonable-function/</guid><description>物理不可複製功能(Physical Unclonable Function, PUF)屬於一種裝置讓晶片可以繼承從製造出來後產生的隨機性質，每一顆封裝過後的晶片所呈現的物理性質都是特定的，我們可以將其視為這是屬於那顆晶片的指紋(fingerprint)或者安全錨(trust anchor)，於本文章中跟各位介紹主流的兩種Strong PUF以及Weak PUF，而這個領域持續還有新興的方法正在被設計當中，在未來隨著資料的安全隱私性越來越重要，針對嵌入式裝置內的晶片資料流提出更優秀的安全演算法必定是需要的</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate><keyword>PUF</keyword><category>black-box-challenge-response</category><category>challenge-response-pairs</category><category>puf</category><category>root-of-trust</category><category>旁道攻擊</category><category>物理不可複製功能</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>FrostyGoop/BUSTLEBERM 工控惡意軟體解析</title><link>https://secologies.com/posts/frostygoop-bustleberm-industry-malware/</link><guid isPermaLink="true">https://secologies.com/posts/frostygoop-bustleberm-industry-malware/</guid><description>於2024年四月，烏克蘭的Cyber Security Situation Center (CSSC)因為國內停電的情形而記錄到這隻新型針對烏克蘭能源公司進行工控攻擊的惡意軟體FrostyGoop/BUSTLEBERM，是目前為止回報第19隻被開發用來針對工控裝置的malware，透過Modbus TCP port攻擊成功後影響了超過600家烏克蘭國內公司的電力供應，如果工控裝置有連網的話這隻malware可以透過攻擊周邊的元件或者外部的系統進去，接著送Modbus指令去讀寫或變更Industrial control system (ICS)裝置的資料，造成能源上的災害。</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><keyword>FrostyGoop/BUSTLEBERM</keyword><category>bustleberm</category><category>frostygoop</category><category>工控安全</category><category>工業控制系統</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>對稱加密函式必要的混淆以及擴散特性</title><link>https://secologies.com/posts/cryptology-confusion-diffusion/</link><guid isPermaLink="true">https://secologies.com/posts/cryptology-confusion-diffusion/</guid><description>在密碼理論研究當中有兩個特性對於安全的密碼系統來說是不可或缺的，分別是混淆(confusion)以及擴散(diffusion)這兩種特性，由Claude Shannon提出利用這兩種特性是想要抵抗密碼分析上被統計出明文的情況，confusion應用在對稱式密碼系統當中想要讓明文以及輸出密文之間的局部關聯性隱藏起來，其實就是用密鑰來對要加密的資料做影響，而diffusion則是要防止攻擊者能夠利用密文的統計性質找出對應的明文。</description><pubDate>Mon, 11 Nov 2024 00:00:00 GMT</pubDate><keyword>加密函式混淆與擴散</keyword><category>密碼學</category><category>對稱式加密</category><category>擴散</category><category>混淆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>亂數產生器 硬體篇</title><link>https://secologies.com/posts/random-number-generator-hardware/</link><guid isPermaLink="true">https://secologies.com/posts/random-number-generator-hardware/</guid><description>為什麼我們需要亂數？在密碼理論的研究領域當中，我們非常注重random number的來源，計算過程以及運算完成後的亂度性質，不管從數學性(mathematical)、隨機性(stochastic)、以及量子性(quantum)，另外蒙地卡羅系列的計算、數值分析、統計研究、隨機演算法</description><pubDate>Sun, 03 Nov 2024 00:00:00 GMT</pubDate><keyword>亂數產生器</keyword><category>亂數產生器</category><category>偽亂數產生器</category><category>真亂數產生器</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>環論</title><link>https://secologies.com/posts/ring-theory/</link><guid isPermaLink="true">https://secologies.com/posts/ring-theory/</guid><description>一個環 (Ring) 必須是存在一組非空集合R，擁有兩組binary運算</description><pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate><keyword>Ring</keyword><category>環論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>群之可解性</title><link>https://secologies.com/posts/solvable-groups/</link><guid isPermaLink="true">https://secologies.com/posts/solvable-groups/</guid><description>首先讓我們定義 G 為一個群，我們說 G 是 solvable/soluble (可解)的話代表存在 filtration</description><pubDate>Sun, 15 Sep 2024 00:00:00 GMT</pubDate><keyword>Solvable Groups</keyword><category>可解</category><category>群理論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>威脅情報指標</title><link>https://secologies.com/posts/indicators-of-compromise/</link><guid isPermaLink="true">https://secologies.com/posts/indicators-of-compromise/</guid><description>我們在搜集惡意APT(Advanced Persistent Threats)事件時會需要一些有關聯性的資訊，透過這些資訊能夠指示出系統或網路中可能已經受到侵害的特定特徵或跡象，包括檔案特徵、網路特徵、主機特徵、電子郵件特徵、使用者行為特徵、 日誌特徵以及應用程式特徵等等</description><pubDate>Fri, 13 Sep 2024 00:00:00 GMT</pubDate><keyword>Indocators of Compromise</keyword><category>cyber-security</category><category>威脅情報指標</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆URL過濾與應用服務頁面封鎖功能</title><link>https://secologies.com/posts/palo-alto-firewall-url-filtering-application-block-page/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-url-filtering-application-block-page/</guid><description>在Palo Alto防火牆要兩項功能一個是Application Block Page另外一個是URL Filtering and Category Match Block Page到Device→Response Pages找到Application Block Page可以使用</description><pubDate>Thu, 25 Apr 2024 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>palo-alto</category><category>url過濾</category><category>應用程式封鎖</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>群論</title><link>https://secologies.com/posts/group-theory/</link><guid isPermaLink="true">https://secologies.com/posts/group-theory/</guid><description>在數論當中群(Group)是其中一種重要的概念，代數最基本由三種結構組成：群 Group, 環 Ring, 體 Field，而群作為最基本的代數結構，也是我們在密碼系統中常常使用的，故需要先了解群的定義對於後續密碼系統分析會比較方便</description><pubDate>Wed, 24 Apr 2024 00:00:00 GMT</pubDate><keyword>Group Theory</keyword><category>乘法群</category><category>加法群</category><category>數論</category><category>群</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>NP完備</title><link>https://secologies.com/posts/np-completeness/</link><guid isPermaLink="true">https://secologies.com/posts/np-completeness/</guid><description>首先需要一個問題叫做布林公式(Boolean formula)會像：$$\phi=(\bar{x} \wedge y) \vee (x \wedge \bar{z})$$，裡面的每一個符號稱作variable，每一個variable可以給0或1的值</description><pubDate>Fri, 15 Mar 2024 00:00:00 GMT</pubDate><keyword>NP-Completeness</keyword><category>cook-levin理論</category><category>np完備</category><category>布林可滿足性問題</category><category>漢米爾頓路徑</category><category>計算複雜度</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>異常檢測的問題分類</title><link>https://secologies.com/posts/anomaly-detection-problem/</link><guid isPermaLink="true">https://secologies.com/posts/anomaly-detection-problem/</guid><description>Supervised Anomaly Detection將所有的訓練資料以及測試資料集都進行標記標準的機器學習都會使用這種方法(SVM, 神經網路)Semi-supervised Anomaly Detection標記少量的訓練資料，其中把所有正常的資料點都看成同一個class</description><pubDate>Thu, 14 Mar 2024 00:00:00 GMT</pubDate><keyword>異常檢測</keyword><category>機器學習</category><category>異常檢測</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>異常檢測的方法評估</title><link>https://secologies.com/posts/evaluating-anomaly-detection/</link><guid isPermaLink="true">https://secologies.com/posts/evaluating-anomaly-detection/</guid><description>當我們在進行異常檢測時，通常會需要注意三個條件：正確的偵測：檢測到的異常資料需要與流程設計想要找到的異常資料是一致的False Positives：檢測過程都是正常的</description><pubDate>Thu, 14 Mar 2024 00:00:00 GMT</pubDate><keyword>異常檢測</keyword><category>機器學習</category><category>混淆矩陣</category><category>異常檢測</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>異常檢測簡介</title><link>https://secologies.com/posts/introduction-to-anomaly-detection/</link><guid isPermaLink="true">https://secologies.com/posts/introduction-to-anomaly-detection/</guid><description>在資料分析當中，異常檢測(Anomaly Detection)(或是稱作&quot;異常值檢測(Outlier Detection)&quot;)用來辨識在資料集內非常稀少的項目、事件或者觀測到屬於別種類型資料集的資料等等</description><pubDate>Mon, 26 Feb 2024 00:00:00 GMT</pubDate><keyword>異常檢測</keyword><category>機器學習</category><category>深度學習</category><category>異常檢測</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>高斯消去法</title><link>https://secologies.com/posts/linear-algebra-gaussian-elimination/</link><guid isPermaLink="true">https://secologies.com/posts/linear-algebra-gaussian-elimination/</guid><description>為了解決上述的聯立方程系統，使用高斯消去法減少不同variable的係數來求出我們需要的結果</description><pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate><keyword>高斯消去法</keyword><category>矩陣</category><category>線性代數</category><category>高斯消去法</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>線性向量</title><link>https://secologies.com/posts/linear-algebravector/</link><guid isPermaLink="true">https://secologies.com/posts/linear-algebravector/</guid><description>在整個線性代數中，最基本的單位就是一個向量，假設一個擁有兩個值的向量像是</description><pubDate>Thu, 01 Feb 2024 00:00:00 GMT</pubDate><keyword>線性向量</keyword><category>乘法計算</category><category>加法計算</category><category>向量</category><category>矩陣</category><category>線性代數</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>時間複雜度</title><link>https://secologies.com/posts/time-complexity/</link><guid isPermaLink="true">https://secologies.com/posts/time-complexity/</guid><description>通長在測量複雜度的時候會使用兩種分析方法：Worst-case analysisAverage-case analysis定義一個M是Deterministic Turing Machine並且會根據輸入決定停止規範M的執行時間或者時間複雜度可以表示成一個function</description><pubDate>Tue, 07 Nov 2023 00:00:00 GMT</pubDate><keyword>時間複雜度</keyword><category>時間複雜度</category><category>計算理論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>其他種圖靈機</title><link>https://secologies.com/posts/other-type-turing-machine/</link><guid isPermaLink="true">https://secologies.com/posts/other-type-turing-machine/</guid><description>讓Turing Machine擁有多組tape</description><pubDate>Sun, 05 Nov 2023 00:00:00 GMT</pubDate><keyword>圖靈機</keyword><category>圖靈機</category><category>枚舉機</category><category>計算理論</category><category>非確定性</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>圖靈機</title><link>https://secologies.com/posts/turing-machine/</link><guid isPermaLink="true">https://secologies.com/posts/turing-machine/</guid><description>圖靈機是由Alan Turing在1936年提出的概念，現今世界上所有的計算機不管是多複雜的架構都可以使用圖靈機的概念設計出來，其主要核心精神如下圖</description><pubDate>Sat, 04 Nov 2023 00:00:00 GMT</pubDate><keyword>圖靈機</keyword><category>圖靈機</category><category>計算理論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>消息理論中的熵</title><link>https://secologies.com/posts/entropy-information-theory/</link><guid isPermaLink="true">https://secologies.com/posts/entropy-information-theory/</guid><description>我們在消息理論測量一段資訊所包含的資訊量其中一種會使用Entropy來計算</description><pubDate>Tue, 31 Oct 2023 00:00:00 GMT</pubDate><keyword>Entropy</keyword><category>entropy</category><category>熵</category><category>資訊理論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>消息理論的資訊測量符號</title><link>https://secologies.com/posts/information-theory-information-measures/</link><guid isPermaLink="true">https://secologies.com/posts/information-theory-information-measures/</guid><description>測量一組資訊的方法有好幾種，例如像是使用entropy, mutual information, relative entropy等等方法，另外需要了解這些方法之間的交互作用</description><pubDate>Tue, 31 Oct 2023 00:00:00 GMT</pubDate><keyword>消息理論</keyword><category>消息理論</category><category>自然對數</category><category>隨機變數</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>消息理論之相互消息</title><link>https://secologies.com/posts/information-theory-mutual-information/</link><guid isPermaLink="true">https://secologies.com/posts/information-theory-mutual-information/</guid><description>Mutual Information 用來測量兩個random variables之間的關係，主要是有多少資訊量被傳輸過去。其中一個random variable會告訴我有多少資訊量從另一個random variable傳過來</description><pubDate>Tue, 01 Aug 2023 00:00:00 GMT</pubDate><keyword>Mutal Information</keyword><category>消息理論</category><category>相互消息</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆政策設定</title><link>https://secologies.com/posts/palo-alto-firewall-policy/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-policy/</guid><description>對於防火牆很重要的功能之一就是透過policy去控管使用者或外部存取者的連線控制，若使用者有不當的連線行為，也能夠透過防火牆的log查看到紀錄，而存取控管限制使用者不能夠連線哪種類型的網站，或者封鎖特定服務都可以透過policy來做控制</description><pubDate>Sat, 01 Jul 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>palo-alto</category><category>封鎖</category><category>政策</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆指令介面顯示過往指令操作</title><link>https://secologies.com/posts/palo-alto-firewall-show-all-configure-command-and-insert-command/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-show-all-configure-command-and-insert-command/</guid><description>有時候實體機器跟虛擬機的計算資源比較少，此時無法花太多運算能力給網頁介面時會變得怪怪的，而這時我們直接在指令介面操作會比較順暢，首先我們開啟防火牆的 shell</description><pubDate>Fri, 30 Jun 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>palo-alto</category><category>指令介面</category><category>過往指令</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆清除使用者快取</title><link>https://secologies.com/posts/palo-alto-firewall-clear-user-cache/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-clear-user-cache/</guid><description>因為我們在進行測試能不能抓取 LDAP Server 的同時測試不需要指定 DNS 也可以指向內部的 Active Directory 主機，所以我們嘗試把 Palo Alto VM 內的所有 user 只要有快取的都先清除掉</description><pubDate>Thu, 29 Jun 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>cache</category><category>palo-alto</category><category>快取</category><category>清除</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆高可用性 High Availability 設定</title><link>https://secologies.com/posts/palo-alto-firewall-high-availability/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-high-availability/</guid><description>本次實驗中我們準備兩台 Palo Alto 虛擬機，為了完成防火牆高可用性 High Availability (HA) 的設定，必須讓這兩台機器都在同一個網段，高可用性作為現代次世代防火牆應對流量越發增益的 DDoS 攻擊是必不可少的功能，故本篇文章想跟讀者介紹 PA HA 設定</description><pubDate>Wed, 28 Jun 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>ha</category><category>high-availability</category><category>palo-alto</category><category>防火牆</category><category>高可用性</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Palo Alto 防火牆網路位址轉譯(NAT)設定</title><link>https://secologies.com/posts/palo-alto-firewall-nat-setup/</link><guid isPermaLink="true">https://secologies.com/posts/palo-alto-firewall-nat-setup/</guid><description>在網路上我們不可能直接將內網的服務IP揭露出去，而防火牆就會提供網路位址轉譯成能夠對外的IP，一來是內網服務IP數量有限所以需要轉譯出去，二來是不想讓攻擊者知道內網服務的IP位址，故需要透過Network Address Translation(NAT)來轉址</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆 NAT</keyword><category>nat</category><category>palo-alto</category><category>網路位址轉譯</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>中國餘式定理與同構特性</title><link>https://secologies.com/posts/chinese-remainder-theorem-isomorphism/</link><guid isPermaLink="true">https://secologies.com/posts/chinese-remainder-theorem-isomorphism/</guid><description>中國餘式定理Chinese Remainder Theorem(CRT)在密碼理論當中屬於重要的概念，尤其在RSA密碼系統裡也扮演重要的角色，而符合CRT的聯立方程式具有同構的特性</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><keyword>中國餘式定理</keyword><category>中國餘式定理</category><category>同構</category><category>數論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>密碼系統 RSA 攻防</title><link>https://secologies.com/posts/rsa-cryptosystem-attack/</link><guid isPermaLink="true">https://secologies.com/posts/rsa-cryptosystem-attack/</guid><description>NIST美國國家標準與科技機構發起的Public Key公開金鑰加解密系統競賽，RSA (Rivest–Shamir–Adleman)加密演算法由三位密碼學家共同研究出來在1973年發表，最終獲選最早為公開金鑰系統標準之一，雖然後來英國Government Communications Headquarters(GCHQ)國家通訊總部說他們的英國密碼學家早在1970年就已經研究出Non-Secret Encryption這種非對稱式加解密系統，但不管怎麼說，RSA在當時算是非常突破性的成果</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><keyword>RSA</keyword><category>rsa</category><category>密碼系統</category><category>攻擊</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>Square and Multiply 演算法</title><link>https://secologies.com/posts/square-and-multiply-algorithm/</link><guid isPermaLink="true">https://secologies.com/posts/square-and-multiply-algorithm/</guid><description>此演算法主要是針對 $a^{b} \&gt;\&gt; mod \&gt;\&gt; n$ 在b很大而計算機通常算不太出來的時候使用的方法</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><keyword>Square and Multiply Algorithm</keyword><category>平方乘</category><category>數論</category><category>模運算</category><category>演算法</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>整數複雜度量測</title><link>https://secologies.com/posts/complexity-measure-in-computing-numbers/</link><guid isPermaLink="true">https://secologies.com/posts/complexity-measure-in-computing-numbers/</guid><description>我們在密碼理論(Theory of Cryptology)又或者計算理論(Theory of Computation)裡需要去測量輸入的整數複雜度，通常會用整數的長度(bits)當作標準</description><pubDate>Fri, 02 Jun 2023 00:00:00 GMT</pubDate><keyword>整數複雜度</keyword><category>密碼理論</category><category>複雜度</category><category>計算理論</category><category>量測</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>尤拉函數</title><link>https://secologies.com/posts/euler-totient-function/</link><guid isPermaLink="true">https://secologies.com/posts/euler-totient-function/</guid><description>最大公因數 gcd(a, b)，可以利用gcd判斷兩個整數是不是互質, gcd(a, b) = 1，若兩數互質代表兩數的最大公因數就是1</description><pubDate>Fri, 02 Jun 2023 00:00:00 GMT</pubDate><keyword>Euler Totient Function</keyword><category>尤拉函數</category><category>數論</category><author>黃宏勝 | Hong-Sheng Huang</author></item><item><title>如何 安裝 Palo Alto VM</title><link>https://secologies.com/posts/how-to-setup-palo-alto-firewall-vm/</link><guid isPermaLink="true">https://secologies.com/posts/how-to-setup-palo-alto-firewall-vm/</guid><description>先在實體機器或虛擬機上安裝Palo Alto OVA檔案 PA-VM-ESX-xxxx，安裝好後直接啟動，啟動時需要設定PA-VM的interface，通常有兩種 1. DHCP 2. Static</description><pubDate>Fri, 26 May 2023 00:00:00 GMT</pubDate><keyword>Palo Alto 防火牆</keyword><category>palo-alto</category><category>安裝</category><category>教學</category><category>資訊安全</category><category>防火牆</category><author>黃宏勝 | Hong-Sheng Huang</author></item></channel></rss>