论文部分内容阅读
本文通过使用最低有效位算法,发现了一种存在于物理隔离网络中的数据导出方法。该数据导出方法基于浏览器可执行本地HTML脚本文件的特性,利用HTML5 Canvas标签在图像像素中嵌入信息,能绕过物理隔离网络对可执行文件的管控措施实现隐蔽通信。该数据导出方法具有操作简单、不易察觉的特点,能有效绕过人工或机器内容审查和反病毒软件查杀,具有高度隐蔽性。本文提出综合利用管理和技术手段,结合机器检查和人工分析,有效防范该数据导出方法带来的威胁。
In this paper, by using the least significant bit algorithm, we found a data export method exists in the physical isolated network. The data export method based on the characteristics of the browser executable local HTML script file, the use of HTML5 Canvas tags embed information in the image pixels, can bypass the physical isolation network for executable file management measures to achieve covert communication. The data export method has the characteristics of simple operation and imperceptibility, and can be highly concealed by effectively bypassing manual or machine content screening and anti-virus software killing. This paper presents a comprehensive utilization of management and technical means, combined with machine inspection and manual analysis, to effectively prevent the data derived from the threat posed.