Butat this time, intentstayingadvantageunitedSt. PaulBankto becomeonegrouprandomly.
而此时,意呆利联合圣保罗银行内部已经乱成了一团。Beforetwohours, intheirsystemspresentedmassiveunauditedaccountinformationamendment record, evenwhether there is the fund of instructioninstigates.
就在两小时之前,他们的系统里出现了大量未经审核的账户信息修改记录,其中甚至有无指令的资金调拨。So long asis engaged in the person of banking industry, knows that thismeansanything.
只要是从事银行业的人,都知道这意味着什么。
Obviously, theycame under the seriousattack, but the issueis, the technologies division of entirebankhad been transferred, actuallydiscovered the source that theyattackcould not find.
很显然,他们受到了严重的攻击,但问题是,整个银行的技术部门都已经被调动起来,却发现他们连攻击的源头都找不到。Theoretically, ifmustinvade a banking system, firstat least needs byoutside, butinvisitapplication, butinthistwohours, allvisitsissafe, afterexamination.
理论上来说,如果要侵入一家银行系统,首先至少要有由外而内的访问申请,但就在这个两個小时内,所有的访问都是安全的、经过审批的。In other words, oris the attackercamouflages the normalvisitor who definitelyis unable to be distinguishedoneself, eitheris the attack came from the interiordirectly.
也就是说,要么是攻击者把自己伪装成了一个完全无法被识别的正常访问者、要么是攻击直接来自于内部。
Any situation, had broken through the technicalupper limit of unitingSt. PaulBank.
无论是哪一种情况,都已经突破了联合圣保罗银行的技术上限。Theylook likealreadybyTroy that the wooden horseinvades, actuallycould not find that onlyinvisiblewooden horse.
他们就像是已经被木马入侵的特洛伊城,却找不到那只隐形的木马。„Situationhow? Is the instructionstill continue produce?”
“情况怎么样?指令还在继续产生吗?”
Before a banktechnologyexecutive'sis askingtobodytechnical personnel.
一名银行技术高管对着身前的技术人员问道。„No, wehad shut off the network connections of central serverurgently, at present the newattackhas not produced, that's good, but also is the bad news.”First roundwebsiteps://
“没有,我们已经紧急切断了中央服务器的网络连接,目前已经没有新的攻击产生了,这是个好消息,但也是坏消息。”首发网址ps://„Iunderstand,breaksonetimeunites the broughtlossis inestimable----Butis goodbecause ofushassafe, should theycompensate?”
“我明白,一次断联所带来的损失是不可估量的----但好在我们有保险,他们应该会赔偿吧?”„Perhapswill compensatepart.......not to needto count on that theyshow the kindness of heartgreatly, when theyindamagesurelycertainlywill keep prices downruthlessly.”
“也许会赔偿一部分.......不用指望他们大发善心,他们在定损时一定会狠狠压价的。”„The bad news that butIsaynowis notthis, butsaid,thisis a clearsignal, wereceive the evidence of attack.”
“但我现在说的坏消息不是这个,而是说,这是一个明确的信号,一个我们受到攻击的证据。”„Obviously, the attackis conductedthrough the networkvery much, so long asourlinked network, will continueto be attackedagain, byability that theyshowat present, theyevencandirectlyouraccountresets.”
“很显然,攻击是通过网络进行的,只要我们重新连接网络,就会继续受到攻击,以他们目前所表现出来的能力,他们甚至可以直接把我们的账户清零。”„Thisis how possible! Ourallinformationconnected to the swiftsystem, musttamper with some data, theymustdecode the entireSwiftsystemcompletely, inthisworld can somepeopleachieve?”
“这怎么可能!我们的所有信息都接入了swift系统,要篡改这部分数据,他们就必须把整个Swift系统全部破解,这世界上有人能做到吗?”
The tone of executiveis somewhat unbelievable, hetrulycanfeel the situationstern, butis separated fromarea of technologytoolonghim, trulydoes not have the extremelydirect-viewingjudgment.
高管的语气有些难以置信,他确实能感受到情况的严峻,但脱离技术领域太久的他,也确实没有太过直观的判断。Hefeltsubconsciously,thistime is just the provocation of hackersin the worldsomecornera handfullovesdazzle the technique, theydo not dareto startto the banking systemdirectly, even ifin the shorttimecanescapetraces, so long asnational strengthinvolvement, inuses the social workermethodinmassively the situation, how longtheycannot ramble.
他下意识地觉得,这次只不过是世界上某个角落一小撮爱炫技的黑客们的一次挑衅罢了,他们是不敢直接对银行系统下手的,哪怕短时间内能逃过追查,但只要国家力量介入,在大规模使用社工手段的情况下,他们逍遥不了多久。Sinceisthis, multipleencryption that the swiftsystemusesto them, was still together the natural moat.
既然是这样,那么,swift系统所使用的多重加密对他们来说,就仍然是一道天堑。
The RSAencryption and ovalencryption...... thesewere useddozensyears of technologyto be timelesstotodaybyhuman, was still protecting the humanmost importantasset, butitalsoneverdisplays the sign that mustbe broken through.
RSA加密、椭圆加密......这些被人类使用了数十年的技术到今天历久弥新,仍然守护着人类最重要的资产,而它也从未表现出来过要被攻破的迹象。Butnow, oneselftechnicianhand/subordinatesaidunexpectedly,theycanbreak the limit of SWIFTsystem, tampers with the transactiondatadirectly?
而现在,自己手下的技术员居然说,他们能够突破SWIFT系统的限制,直接篡改交易数据?Looksfacial expression that the executivequestioned, technicianhesitantmoment, replied:
看着高管质疑的神情,技术员犹豫了片刻,回答道:„...... Good, perhapstheywill not tamper with the accountthrough the way that Swiftsettles accounts, butIaffirmedvery much,theycan certainlymake the balance in oursystemdemonstratingenull.”
“......好吧,也许他们并不会通过Swift结算的方式去篡改账户,但是我很肯定,他们一定能让我们系统中所显示的余额归零。”„Like thismakes the createdinjuryslightlylowersandtampers with the transaction, words that butwantsto restore, needs the extremelyhighcost.”
“这样做所造成的伤害略低与篡改交易,但想要恢复的话,也需要极高的成本。”„In brief, wehad been compelledin the corner----Whatmore difficultofficeis, onusdoes not even knowthose wholaunch the attackis, alsohaswhatgoal.”
“总之,我们已经被逼到角落里了----更难办的是,我们上甚至都不知道发起进攻的是谁、又有什么目的。”„It is not ableto start, at presentallsecuritypersonnelhave entered the post, the informationare also reportedtoICSPA, theywill provide the necessaryaidtous.”
“无从下手,目前所有安防人员都已经进入岗位,信息也已经被上报给了ICSPA,他们会向我们提供必要的援助。”
„ Butat presentlooks like, allwork that wedoare pursuing the spirit that cannot see unable to feel.......even the goalnot to have,
“但目前看来,我们所做的所有工作都是在追逐一个看不见摸不着的幽灵.......连目标都没有,Thatso-calledkingnetwork securitymethodnaturallyalsofallson the vacancy. ” The brow of executivecloselywrinkles, he himself is also the technical personnelfamily background, naturallycanunderstandlogic that the opposite party stated that but, hedid not have the means.
那所谓的王网络安全手段自然也是落在空处的。”高管的眉头紧紧皱起,他自己也是技术人员出身,自然能理解对方所陈述的逻辑,但是,他对此却也毫无办法。
To shoot at the target, at leastmusthave a target.
要想打靶,起码得有个靶子。
The presentissuelooks like, 10000 km away, somepeoplewith a missile raiding of unclearoriginone's own side, but all counter-attackmethods of one's own sideonly haveseveralrifles.
现在的问题就像是,在10000公里之外,有人用一颗不明来源的导弹袭击了己方,而己方的所有反击手段却只有几把步枪。
To createkillingto the enemy, is having a dreampurely.
想要对敌人造成杀伤,纯粹是在做梦。It seems like that when the technologywalksdoes not pass, can only towardsocial workerconsider.
看来,当技术走不通时,就只能往社工方面考虑了。Thought deeply about the momentsilent, hesays:
沉默地思索了片刻,他开口说道:„Youcontinueto attempt, Irelateotherdepartmentsto hold the emergency meetingnow, ifthere is latest progress, Iinformyouimmediately.”
“你们继续尝试,我现在去联系其他部门召开紧急会议,如果有最新的进展,我会立刻通知你们。”„Got it.”
“明白了。”
The techniciansnodto reply, butin fact, heregardedconventionalbeing perfunctory the words of executive.
技术员点头回答,但实际上,他只是把高管的话当成了一种惯例性的敷衍而已。
......
......However, unlikecompletely, aftera halfhour that hethinks, the bank managementfocused onattackmerely.
然而,与他所想的完全不同,仅仅在半小时之后,银行管理层就锁定了攻击的方向。Becausethisactually nottheirabilitiesstrong, rather, from the perspective of topoverall situation, the clue that the opposite partyleft behind is really obvious----Or the opposite partyhas not plannedto hideownidentityfrom the start.
这倒不是因为他们的能力有多强,而是,从顶层全局的角度来看,对方所留下的线索实在是太明显了----或者说对方压根就没有打算隐藏自己的身份。In the technology, theycandois very perfect, butlogically, theymost basicconcealingdisdainsindoes.
技术上,他们可以做的很完美,但在逻辑上,他们连最基本的掩饰都不屑于去做。
The clue that the executivesgainaltogetherhasseveral.
高管所获取到的线索总共有几条。
Article 1, becausepreviouslyone's own sideexerted pressure on the account number of suspensionorfreezeis defrostedcompletely, the involvedbankrepliedthemnot to conduct the defrostingoperationexplicitly.
第一条,此前因为己方施压所暂停或者冻结的账号全部被解冻,涉及的银行明确回复他们并没有进行解冻操作。
Article 2, attacks the account number that aims is the diplomats of one's own side, the attack logicwith the freeze and limit of previousone's own side has almost not distinguishedcompletely.
第二条,攻击所针对的账号全部是己方的驻外人员,攻击逻辑跟此前己方的冻结和限制几乎没有区别。
Article 3, before the attack, Chinajustlearnedseveralnationalmainrepresentativesstationed abroadare restricted the news.
第三条,在攻击发生之前,华夏刚刚获知了几个国家主要驻外代表受到限制的消息。Perhapseachclueis independent unable to be telling, when butit happened simultaneously, allbecameunderstandclearly.
也许每一条线索独立出来都不能说明问题,但当它同时发生时,一切就都变得清晰明了了。Theseare restricted the small countryabsolutelynot to havethisability, the status of opponentis then obvious.
那些受到限制的小国是绝对没有这个能力的,那么,对手的身份已经昭然若揭。IsChinese.
是华夏人。Chineselaunchedtheiroffensive, the goalisasto limit the response of small countrydiplomatsbanking transactiontoone's own side.华夏人发动了他们的攻势,目的是作为对己方限制小国驻外人员银行交易的回应。Found the instigator, the issuesolvedhalf, butanothermore importantissuesurfaced:
找到了始作俑者,问题算是解决了一半,可另一个更重要的问题又浮出了水面:How do theyachieve?
他们是怎么做到的?
The technicalmanagerassociatedto get upa series ofsuddenlyheonceto notice, detail that buthas not actually cared, silenta moment later, hesaid:
技术主管突然联想起了一系列他曾经注意到,但是却没有放在心上的细节,沉默了片刻之后,他开口说道:„Everyone.”
“各位。”„Ihave not a very goodguess.”
“我有一个非常不好的猜测。”„Ifthisguessis true, then, itto the attack that wecreate, will bedestructive.”
“如果这个猜测属实的话,那么,它对我们造成的打击,将是毁灭性的。”Everyone'svisioncentralizedtohisbody, hedeeplyinspires, latersays:
所有人的目光都集中到了他的身上,他深深吸了口气,随后开口说道:„Modernbank systemlivelihoodRSAcryptographic system, likely, had been broken through.”
“现代银行体系赖以生存的RSA加密系统,很可能,已经被攻破了。”
To display comments and comment, click at the button