{"id":51766,"date":"2017-09-05T09:00:21","date_gmt":"2017-09-05T01:00:21","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=51766"},"modified":"2017-09-05T15:04:42","modified_gmt":"2017-09-05T07:04:42","slug":"defplorex%ef%bc%9a%e5%a4%a7%e8%a6%8f%e6%a8%a1%e9%9b%bb%e5%ad%90%e7%8a%af%e7%bd%aa%e9%91%91%e8%ad%98%e7%94%a8%e7%9a%84%e6%a9%9f%e5%99%a8%e5%ad%b8%e7%bf%92%e5%b7%a5%e5%85%b7","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=51766","title":{"rendered":"DefPloreX\uff1a\u5927\u898f\u6a21\u96fb\u5b50\u72af\u7f6a\u9451\u8b58\u7528\u7684\u6a5f\u5668\u5b78\u7fd2\u5de5\u5177"},"content":{"rendered":"<p>\u8cc7\u5b89\u7522\u696d\u90fd\u5f88\u559c\u6b61\u6536\u96c6\u8cc7\u6599\uff0c\u7814\u7a76\u4eba\u54e1\u4e5f\u4e0d\u4f8b\u5916\u3002\u6709\u4e86\u66f4\u591a\u8cc7\u6599\uff0c\u5c31\u80fd\u5920\u5c0d\u7279\u5b9a\u5a01\u8105\u6240\u767c\u8868\u7684\u8072\u660e\u66f4\u6709\u4fe1\u5fc3\u3002\u4f46\u662f\u5927\u91cf\u8cc7\u6599\u4e5f\u9700\u8981\u66f4\u591a\u7684\u8cc7\u6e90\u9032\u884c\u8655\u7406\uff0c\u8981\u5f9e\u9ad8\u5ea6\u975e\u7d50\u69cb\u5316\u7684\u8cc7\u6599\u4e2d\u63d0\u53d6\u6709\u610f\u7fa9\u548c\u6709\u7528\u7684\u8cc7\u8a0a\u662f\u76f8\u7576\u56f0\u96e3\u7684\u3002\u7d50\u679c\u5f80\u5f80\u5c31\u662f\u5fc5\u9808\u9032\u884c\u624b\u52d5\u5206\u6790\uff0c\u8feb\u4f7f\u8cc7\u5b89\u5c08\u5bb6\uff08\u5982\u8abf\u67e5\u54e1\u3001\u6ef2\u900f\u6e2c\u8a66\u5de5\u7a0b\u5e2b\u3001\u9006\u5411\u5de5\u7a0b\u5e2b\u3001\u5206\u6790\u5e2b\uff09\u5fc5\u9808\u900f\u904e\u7e41\u7463\u4e14\u91cd\u8907\u7684\u64cd\u4f5c\u904e\u7a0b\u4f86\u8655\u7406\u8cc7\u6599\u3002<\/p>\n<p>\u6211\u5011\u958b\u767c\u4e86\u4e00\u5957\u57fa\u65bc\u958b\u653e\u539f\u59cb\u78bc\u8cc7\u6599\u5eab\u7684\u5f48\u6027\u5de5\u5177\u80fd\u5920\u6709\u6548\u5730\u5206\u6790\u6578\u767e\u842c\u7b46\u88ab\u7f6e\u63db\uff08defaced\uff09\u7db2\u9801\u3002\u5b83\u4e5f\u53ef\u4ee5\u88ab\u7528\u5728\u4e00\u822c\u653b\u64ca\u6240\u7522\u751f\u7684\u7db2\u9801\u3002\u9019\u5957\u5de5\u5177\u7a31\u70baDefPloreX\uff08\u4f86\u81ea\u201cDefacement eXplorer\u201d\uff09\uff0c\u7d50\u5408\u4e86\u6a5f\u5668\u5b78\u7fd2\u548c\u8996\u89ba\u5316\u6280\u8853\u5c07\u975e\u7d50\u69cb\u5316\u8cc7\u6599\u8f49\u5316\u6210\u6709\u610f\u7fa9\u7684\u9ad8\u968e\u63cf\u8ff0\u3002\u5c07\u4f86\u81ea\u8cc7\u5b89\u4e8b\u4ef6\u3001\u5165\u4fb5\u3001\u653b\u64ca\u548c\u6f0f\u6d1e\u7684\u5373\u6642\u8cc7\u6599\u6709\u6548\u5730\u8655\u7406\u548c\u6fc3\u7e2e\u6210\u53ef\u700f\u89bd\u7684\u7269\u4ef6\uff0c\u9069\u7528\u65bc\u9ad8\u6548\u7387\u7684\u5927\u898f\u6a21\u96fb\u5b50\u72af\u7f6a\u9451\u8b58\u548c\u8abf\u67e5\u3002<\/p>\n<p>DefPloreX\u53ef\u4ee5\u8f38\u5165\u5305\u542b\u4e86\u5f85\u5206\u6790\u7db2\u8def\u4e8b\u4ef6\u5f8c\u8a2d\u8cc7\u6599\u7d00\u9304\uff08\u5982\u7db2\u5740\uff09\u7684\u7d14\u6587\u5b57\u6a94\u6848\uff08\u5982CSV\u6a94\uff09\uff0c\u7528headless\u700f\u89bd\u5668\uff08\u7121\u4f7f\u7528\u8005\u4ecb\u9762\u7684\u700f\u89bd\u5668\uff09\u700f\u89bd\u5176\u8cc7\u6e90\uff0c\u5f9e\u7f6e\u63db\u7db2\u9801\u63d0\u53d6\u7279\u5fb5\uff0c\u5c07\u7522\u751f\u7684\u8cc7\u6599\u5132\u5b58\u5230Elastic\u7d22\u5f15\u3002\u5206\u6563\u5f0f\u7684headless\u700f\u89bd\u5668\u53ca\u5927\u898f\u6a21\u7684\u8cc7\u6599\u8655\u7406\u64cd\u4f5c\u90fd\u662f\u900f\u904eCelery\uff08\u5206\u6563\u5f0f\u4efb\u52d9\u5354\u4f5c\u7684\u5be6\u969b\u4e0a\u6a19\u6e96\uff09\u4f86\u5354\u8abf\u3002DefPloreX\u4f7f\u7528\u773e\u591aPython\u8cc7\u6599\u5206\u6790\u6280\u8853\u548c\u5de5\u5177\u4f86\u5efa\u7acb\u8cc7\u6599\u7684\u96e2\u7dda\u8996\u5716\uff08view\uff09\uff0c\u53ef\u4ee5\u66f4\u6613\u65bc\u5206\u6790\u548c\u63a2\u7d22\u3002<\/p>\n<p>DefPloreX\u6700\u6709\u8da3\u7684\u5730\u65b9\u662f\u6703\u81ea\u52d5\u5c07\u76f8\u4f3c\u7684\u7f6e\u63db\u7db2\u9801\u5206\u7fa4\uff0c\u4e26\u5c07\u7db2\u8def\u653b\u64ca\u4e8b\u4ef6\u7d44\u6210\u653b\u64ca\u6d3b\u52d5\u3002\u6574\u500b\u904e\u7a0b\u53ea\u9700\u50b3\u905e\u8cc7\u6599\u4e00\u6b21\uff0c\u6211\u5011\u6240\u7528\u7684\u7fa4\u96c6\u6280\u8853\u5728\u672c\u8cea\u4e0a\u662f\u9032\u884c\u5e73\u884c\u8655\u7406\u800c\u4e0d\u53d7\u9650\u65bc\u8a18\u61b6\u9ad4\u3002DefPloreX\u63d0\u4f9b\u6587\u5b57\u548c\u7db2\u9801\u5169\u7a2e\u4f7f\u7528\u8005\u4ecb\u9762\uff0c\u53ef\u4ee5\u7528\u7c21\u55ae\u8a9e\u8a00\u67e5\u8a62\u4ee5\u7528\u5728\u8abf\u67e5\u548c\u9451\u8b58\u4e0a\u3002\u56e0\u70ba\u5b83\u662f\u57fa\u65bcElastic Search\uff0cDefPloreX\u6240\u7522\u751f\u7684\u8cc7\u6599\u53ef\u4ee5\u8f15\u6613\u5730\u8ddf\u5176\u4ed6\u7cfb\u7d71\u6574\u5408\u3002<\/p>\n<p><strong><em>\u4f7f\u7528\u6848\u4f8b<\/em><\/strong><\/p>\n<p>\u4e0b\u9762\u662f\u5206\u6790\u5e2b\u5982\u4f55\u5229\u7528DefPloreX\u4f86\u8abf\u67e5\u4e00\u8d77\u88ab\u7a31\u70ba\u201cOperation France\u201d\uff08\u5728Twitter\u4e0a\u4f7f\u7528\u201c#opfrance\u201d\uff09\u653b\u64ca\u6d3b\u52d5\u7684\u4f8b\u5b50\u3002\u9019\u8d77\u653b\u64ca\u6d3b\u52d5\u662f\u7531\u7db2\u8def\u7a46\u65af\u6797\u6fc0\u9032\u5206\u5b50\u6240\u904b\u4f5c\uff0c\u76ee\u7684\u662f\u652f\u6301\u6fc0\u9032\u4f0a\u65af\u862d\u4e3b\u7fa9\u3002<\/p>\n<p>\u5982\u57161\u6240\u793a\uff0c\u8a72\u653b\u64ca\u6d3b\u52d5\u57284\u5e74\u9593\uff082013-2016\uff09\u653b\u64ca\u4e861,313\u500b\u7db2\u7ad9\uff0c\u4e3b\u8981\u662f\u91dd\u5c0d\u6cd5\u570b\u7db2\u57df\uff08\u57162\uff09\u3002DefPloreX\u63ed\u793a\u4e86\u653b\u64ca\u5206\u5b50\u7684\u7d44\u6210\u4ee5\u53ca\u653b\u64ca\u6240\u7528\u7684\u7f6e\u63db\u7bc4\u672c\uff08\u57163\uff09\u3002\u4e00\u4e9b\u6210\u54e1\u660e\u78ba\u8868\u793a\u652f\u6301\u7531\u4f0a\u65af\u862d\u6975\u7aef\u5206\u5b50\uff08\u5982\u6050\u6016\u4e3b\u7fa9\uff09\u5c0d\u6cd5\u570b\u9032\u884c\u7684\u653b\u64ca\uff08\u57164\uff09\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex-france-1.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex-france-2.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex-france-3.png\" \/><\/p>\n<p><em>\u57161-4<\/em><em>\u3001\u653b\u64ca\u6d3b\u52d5Operation France<\/em><em>\uff08#opfrance<\/em><em>\uff09\u7684\u8abf\u67e5\u7bc4\u4f8b\uff08\u9ede\u64ca\u653e\u5927\uff09<\/em><\/p>\n<p><!--more--><\/p>\n<p><strong><em>\u516c\u958b\u767c\u8868<\/em><\/strong><\/p>\n<p>DefPloreX\u652f\u63f4\u4ee5\u4e0b\u5206\u6790\u64cd\u4f5c\uff1a<\/p>\n<ul>\n<li>\u8f38\u5165\u548c\u8f38\u51fa\u4e00\u822c\u8cc7\u6599\u7d66Elastic\u7d22\u5f15<\/li>\n<li>\u4f7f\u7528\u5404\u7a2e\u5c6c\u6027\u4f86\u5b8c\u5584\u7d22\u5f15<\/li>\n<li>\u4ee5\u81ea\u52d5\u5e73\u884c\u8655\u7406\u65b9\u5f0f\u5b58\u53d6\u7db2\u9801\u4f86\u63d0\u53d6\u6578\u503c\u53ca\u8996\u89ba\u7279\u5fb5\u5448\u73fe\uff0c\u6355\u6349HTML\u9801\u9762\u7d50\u69cb\u548c\u5448\u73fe\u5916\u89c0<\/li>\n<li>\u5f8c\u88fd\u8655\u7406\u6578\u5b57\u548c\u8996\u89ba\u7279\u5fb5\u4f86\u63d0\u53d6\u63cf\u8ff0\u6bcf\u500b\u7db2\u9801\u7684\u7dca\u6e4a\u8868\u793a\uff08compact presentation\uff09\u3002\u6211\u5011\u5c07\u9019\u7a31\u70ba\u201cbucket\u201d<\/li>\n<li>\u4f7f\u7528\u7dca\u6e4a\u8868\u793a\u4f86\u91cd\u65b0\u8abf\u6574\u539f\u59cb\u7db2\u9801\uff0c\u5c07\u5b83\u5011\u5206\u7d44\u6210\u76f8\u4f3c\u7db2\u9801\u7fa4\u96c6<\/li>\n<li>\u57f7\u884cElastic\u7d22\u5f15\u7684\u901a\u7528\u700f\u89bd\u548c\u67e5\u8a62\u3002<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>\u4e0b\u5716\u70baDefPloreX\u67b6\u69cb\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex5.png\" \/><\/p>\n<p><em>\u57165<\/em><em>\u3001DefPloreX<\/em><em>\u529f\u80fd\u6982\u8ff0<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u6211\u5011\u60f3\u5f9e\u6bcf\u500b\u7db2\u9801\u4e2d\u6536\u96c6\u540c\u4e00\u500b\u6545\u4e8b\u7684\u5169\u9762\uff1a\u7db2\u9801\u7684\u201c\u975c\u614b\u201d\u8996\u5716\uff08\u5982\u975e\u89e3\u91cb\u8cc7\u6e90\u3001\u8173\u672c\u3001\u6587\u5b57\uff09\uff0c\u548c\u540c\u4e00\u7db2\u9801\u7684\u201c\u52d5\u614b\u201d\u8996\u5716\uff08\u5982\u7528DOM\u4fee\u6539\u7684\u6e32\u67d3\u9801\u9762\u7b49\uff09\u3002DefPloreX\u5b8c\u6574\u7248\u53ef\u4ee5\u63d0\u53d6\u7db2\u5740\u3001\u96fb\u5b50\u90f5\u4ef6\u5730\u5740\u3001\u793e\u7fa4\u7db2\u8def\u66b1\u7a31\u5e33\u865f\u3001\u4e3b\u984c\u6a19\u7c64\u3001\u5716\u50cf\u3001\u6a94\u6848\u5f8c\u8a2d\u8cc7\u6599\u3001\u6458\u8981\u6587\u5b57\u548c\u5176\u4ed6\u8cc7\u8a0a\u3002\u9019\u4efd\u8cc7\u6599\u64f7\u53d6\u4e86\u7f6e\u63db\u7db2\u9801\u7684\u4e3b\u8981\u7279\u5fb5\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex-1.png\" \/><\/p>\n<p><em>\u57166<\/em><em>\u3001\u5f9e\u7db2\u5740\u6536\u96c6\u7684\u8cc7\u6599<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u6211\u5011\u7684\u505a\u6cd5\u662f\u5c07\u627e\u51fa\u76f8\u95dc\u7f6e\u63db\u7db2\u9801\uff08\u5982\u99ed\u5ba2\u6fc0\u9032\u4e3b\u7fa9\u6d3b\u52d5\uff09\u7576\u4f5c\u4e00\u7a2e\u5178\u578b\u7684\u8cc7\u6599\u63a1\u7926\u554f\u984c\u3002\u6211\u5011\u5047\u8a2d\u9019\u4e9b\u9801\u9762\u6709\u91cd\u8907\u51fa\u73fe\u548c\u76f8\u4f3c\u7684\u7279\u5fb5\u8b93\u6211\u5011\u53ef\u4ee5\u6355\u6349\u548c\u5206\u7fa4\u3002\u6bd4\u65b9\u8aaa\uff0c\u6211\u5011\u5047\u8a2d\u540c\u4e00\u500b\u653b\u64ca\u8005\u6703\u91cd\u8907\u4f7f\u7528\u76f8\u540c\u7684\u7db2\u9801\u7247\u6bb5\uff08\u5118\u7ba1\u6703\u6709\u5fae\u5c0f\u7684\u8b8a\u5316\uff09\u5728\u540c\u4e00\u6ce2\u653b\u64ca\u6d3b\u52d5\u4e2d\u3002\u6211\u5011\u900f\u904e\u5206\u6790\u6bcf\u500b\u9801\u9762\uff08\u975c\u614b\u548c\u52d5\u614b\u8996\u5716\uff09\u6240\u53d6\u5f97\u7684\u8cc7\u6599\u4e2d\u63d0\u53d6\u6578\u5b57\u548c\u5206\u985e\u7279\u5fb5\u4f86\u6355\u6349\u9019\u4e9b\u8cc7\u8a0a\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex-2.png\" \/><\/p>\n<p><em>\u57167<\/em><em>\u3001\u5f9e\u6bcf\u500b\u7db2\u5740\u53d6\u5f97\u7684\u7279\u5fb5<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>DefPloreX\u9084\u6709\u4e00\u500b\u529f\u80fd\u7a31\u70ba\u201c\u8cc7\u6599\u88dd\u6876\uff08data bucketing\uff09\u201d\uff0c\u6211\u5011\u7528\u4f86\u53d6\u5f97\u6bcf\u7b46\u8a18\u9304\u7684\u7dca\u6e4a\u8868\u793a\u3002\u63a5\u8457\u7528\u9019\u7dca\u6e4a\u8868\u793a\u4f86\u9032\u884c\u5feb\u901f\u5206\u7fa4\u3002\u5728\u6211\u5011\u7684\u4f8b\u5b50\u4e2d\uff0c\u4e00\u7b46\u8a18\u9304\u662f\u4e00\u500b\u7f6e\u63db\u7db2\u9801\uff0c\u4f46\u9019\u65b9\u6cd5\u53ef\u4ee5\u61c9\u7528\u5230\u5176\u4ed6\u9818\u57df\u3002\u7576\u4f7f\u7528\u5728\u6578\u503c\u7279\u5fb5\u6642\uff0c\u9019\u500b\u88dd\u6876\uff08bucketing\uff09\u529f\u80fd\u4ee3\u8868\u7528\u4e00\u7d44\u6709\u9650\u5206\u985e\u503c\uff08\u5373\u4f4e\u3001\u4e2d\u3001\u9ad8\uff09\u4f86\u8868\u793a\u4e00\u500b\u5be6\u6578\uff08\u4efb\u610f\u7bc4\u570d\uff09\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>Elastic Search\u672c\u8eab\u652f\u63f4\u8f49\u63db\u6578\u503c\u5230\u5206\u985e\u503c\u6240\u9700\u7684\u7d71\u8a08\u539f\u8a9e\uff08\u5982\u767e\u5206\u4f4d\u6578\uff09\u3002\u5982\u679c\u5b83\u61c9\u7528\u5230\u539f\u672c\u70ba\u985e\u5225\u7684\u7279\u5fb5\uff08\u5982\u7db2\u9801\u4f7f\u7528\u7684\u5b57\u5143\u7de8\u78bc\uff09\uff0c\u9019\u88dd\u6876\uff08bucketing\uff09\u529f\u80fd\u4ee3\u8868\u73fe\u6709\u7684\u6240\u6709\u7de8\u78bc\uff08\u5982\u201cwindows-1250\u201d\uff0c\u201ciso-*\u201d\uff09\uff0c\u9084\u6709\u5e38\u7528\u5728\u7de8\u78bc\u4e0a\u7684\u5730\u7406\u5340\u57df\uff08\u5982\u6b50\u6d32\u3001\u897f\u91cc\u723e\u6587\u3001\u5e0c\u81d8\u6587\uff09\u3002\u540c\u6a23\u4e5f\u53ef\u4ee5\u7528\u5728\u8a9e\u8a00\u3001\u9802\u7d1a\u7db2\u57df\u7b49\u7b49\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u7db2\u9801\u4ecb\u9762\u662f\u7528React\u958b\u767c\uff0c\u7528Flask\u7de8\u5beb\u7684\u8f15\u91cfREST API\u4f86\u88dd\u6876\uff08bucketing\uff09\u3002\u7db2\u9801\u4ecb\u9762\u57fa\u672c\u4e0a\u662f\u8d85\u7d1a\u5f37\u5316\u7684\u96fb\u5b50\u8a66\u7b97\u8868\uff0c\u667a\u6167\u578b\u5206\u9801\u5728\u67d0\u7a2e\u610f\u7fa9\u4e0a\u53ef\u4ee5\u8b93\u5b83\u64f4\u5c55\u5230\u4efb\u610f\u7b46\u7684\u8a18\u9304\u3002\u7db2\u9801\u4ecb\u9762\u7684\u4e3b\u8981\u4efb\u52d9\u662f\u700f\u89bd\u96c6\u7fa4\u548c\u8a18\u9304\u3002\u6bd4\u65b9\u8aaa\uff0c\u8981\u627e\u51fa\u76f8\u540c\uff08\u5c0f\u7bc4\u570d\uff09\u7d44\u7db2\u8def\u72af\u7f6a\u5206\u5b50\u6240\u9032\u884c\u7684\u7db2\u9801\u7f6e\u63db\u653b\u64ca\uff0c\u6211\u5011\u6703\u67e5\u8a62DefPloreX\u4f86\u986f\u793a\u51fa\u6700\u591a\u5305\u542b\u5341\u500b\u653b\u64ca\u8005\u7684\u7fa4\u7d44\u548c\u6aa2\u67e5\u6bcf\u500b\u7fa4\u7d44\u7684\u6642\u9593\u8868\uff0c\u4f86\u767c\u73fe\u9031\u671f\u6027\u6a21\u5f0f\u6216\u6d3b\u52d5\u5c16\u5cf0\uff0c\u627e\u51fa\u5354\u540c\u653b\u64ca\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u5728\u9019\u4e9b\u64cd\u4f5c\u4e2d\uff0cDefPloreX\u80fd\u5920\u5728\u4e0d\u72a7\u7272\u6548\u80fd\u7684\u524d\u63d0\u4e0b\u6700\u5c11\u5316\u8a18\u61b6\u9ad4\u7684\u4f7f\u7528\u3002DefPloreX\u53ef\u4ee5\u5728\u666e\u901a\u7684\u7b46\u8a18\u578b\u96fb\u8166\u4e0a\u904b\u4f5c\u7684\u5f88\u597d\uff0c\u4f46\u5982\u679c\u6709\u66f4\u591a\u904b\u7b97\u8cc7\u6e90\u6642\u4e5f\u53ef\u4ee5\u52a0\u4ee5\u64f4\u5c55\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex1.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex2.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex3.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2017\/07\/defplorex4.png\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><em>\u57168-11<\/em><em>\u3001DefPloreX<\/em><em>\u4f7f\u7528\u7bc4\u4f8b\uff08\u9ede\u64ca\u653e\u5927\uff09<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>\u516c\u958b\u767c\u8868<\/em><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u5982\u540c\u6211\u5011\u4eca\u5e747\u670827\u65e5\u5728\u62c9\u65af\u7dad\u52a0\u65af<a href=\"https:\/\/www.blackhat.com\/us-17\/arsenal.html#defplorex-a-machine-learning-toolkit-for-large-scale-ecrime-forensics\">Black USA Arsenal<\/a>\u4e0a\u7684\u8ac7\u8a71\uff0c\u6211\u5011\u7528FreeBSD\u6388\u6b0a\u5728<a href=\"https:\/\/github.com\/trendmicro\/defplorex\">Github<\/a>\u4e0a\u767c\u8868\u4e86\u90e8\u5206\u7684DefPloreX\u3002\u767c\u8868\u7684\u5de5\u5177\u5305\u62ec\u4e00\u500b\u7528\u65bc\u5927\u898f\u6a21Elasticsearch\u8a18\u9304\u904b\u7b97\u7684\u6846\u67b6\u7a0b\u5f0f\u5eab\u3002\u6211\u5011\u7684\u6295\u5f71\u7247\u53ef\u4ee5<a href=\"https:\/\/www.madlab.it\/slides\/BHArsenal_DefPloreX.pdf\">\u9019\u6b64<\/a>\u53d6\u5f97\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>@\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/defplorex-machine-learning-toolkit-large-scale-ecrime-forensics\/\">DefPloreX: A Machine-Learning Toolkit for Large-scale eCrime Forensics<\/a> \u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/trend-micro-advanced-threats-researchers\/\">\u8da8\u52e2\u79d1\u6280\u8cc7\u6df1\u5a01\u8105\u7814\u7a76\u54e1<\/a>\uff08Marco Balduzzi\u548cFederico Maggi\uff09<\/p>\n<p><a href=\"https:\/\/t.rend.tw\/?i=NTc1NA\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-52256\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-1024x536.jpg\" alt=\"\" width=\"736\" height=\"385\" srcset=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-1024x536.jpg 1024w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-300x157.jpg 300w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-768x402.jpg 768w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-600x314.jpg 600w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD-800x419.jpg 800w, https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2017\/09\/Cloudsec-FB-AD.jpg 1200w\" sizes=\"(max-width: 736px) 100vw, 736px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8cc7\u5b89\u7522\u696d\u90fd\u5f88\u559c\u6b61\u6536\u96c6\u8cc7\u6599\uff0c\u7814\u7a76\u4eba\u54e1\u4e5f\u4e0d\u4f8b\u5916\u3002\u6709\u4e86\u66f4\u591a\u8cc7\u6599\uff0c\u5c31\u80fd\u5920\u5c0d\u7279\u5b9a\u5a01\u8105\u6240\u767c\u8868\u7684\u8072\u660e\u66f4\u6709\u4fe1\u5fc3\u3002\u4f46\u662f\u5927\u91cf\u8cc7\u6599\u4e5f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[3024],"tags":[3454,3453,2961,2047],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/51766"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=51766"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/51766\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=51766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=51766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=51766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}