《幽灵电话:滥用网络会议进行隐蔽指挥与控制.pdf》由会员分享,可在线阅读,更多相关《幽灵电话:滥用网络会议进行隐蔽指挥与控制.pdf(91页珍藏版)》请在三个皮匠报告上搜索。
1、#BHUSA BlackHatEventsGhost Calls:Abusing Web Conferencing for Covert Command&ControlAdam Crosser#BHUSA BlackHatEvents2IntroductionAdam CrosserPraetorianX:https:/ BlackHatEvents3Types of Command-and-Control Channels#BHUSA BlackHatEvents4Types of Command-and-Control Channels#BHUSA BlackHatEvents5Types
2、 of Command-and-Control Channels#BHUSA BlackHatEvents6Types of Command-and-Control Channels#BHUSA BlackHatEvents7Types of Command-and-Control Channels#BHUSA BlackHatEvents8Brainstorming Solutions#BHUSA BlackHatEvents9Ideal Short-Term Command and Control#BHUSA BlackHatEvents10Ideal Short-Term Command
3、 and ControlLATENCY#BHUSA BlackHatEvents11Ideal Short-Term Command and ControlTHROUGHPUTLATENCY#BHUSA BlackHatEvents12Ideal Short-Term Command and ControlTHROUGHPUTLATENCYREACH#BHUSA BlackHatEvents13Ideal Short-Term Command and ControlTHROUGHPUTLATENCYTRUSTREACH#BHUSA BlackHatEvents14Selection Crite
4、ria Focused on services egressing from user devices Must be broadly used across enterprise roles Applicable to non-technical departments(e.g.,HR,sales)Protocols favored by technical users were excluded Thought through common workflows and use-cases#BHUSA BlackHatEvents15DNS over HTTP(DoH)LATENCYTHRO
5、UGHPUTREACHTRUST#BHUSA BlackHatEvents16Cloud File StorageLATENCYTHROUGHPUTREACHTRUST#BHUSA BlackHatEvents17Attacker VM with Classified DomainLATENCYTHROUGHPUTREACHTRUST#BHUSA BlackHatEvents18Email and Messaging ApplicationsLATENCYTHROUGHPUTREACHTRUST#BHUSA BlackHatEvents19Web ConferencingLATENCYTHRO
6、UGHPUTREACHTRUST#BHUSA BlackHatEvents20Microsoft Teams Split Tunneling Guidelineshttps:/ BlackHatEvents21Microsoft Teams TLS Inspectionhttps:/ BlackHatEvents22Zoom Split Tunneling Recommendationshttps:/ BlackHatEvents23Zoom TLS Inspection Recommendationshttps:/ BlackHatEvents24Quick Disclaimer Provi