攻击即服务或漏洞利用即服務()簡稱EaaS,是一种网络犯罪分子将零日漏洞的利用服务出租给其他黑客的方式。EaaS通常作为云服务提供。到 2021 年底,EaaS 已成为勒索软件团伙的新动向。
过去,零日漏洞通常在暗网上出售,但通常售价高昂,每个可达数百万美元。这些零日漏洞可以在被高价出售之前租用一段时间。并且租用的零日漏洞可能会被发现并可于进行逆向工程。
目前尚不确定其商业模式的盈利能力如何。如果它被认为收益可观的,那么提供这类服务的参与者可能会增加。
参见
- (as a service)
- 计算机安全
- 计算机病毒
- 犯罪软件
*
*
- Metasploit
- Shellcode
- w3af
- 詐騙即服務
- 勒索軟件即服務
参考资料
外部链接
*
- [https://web.archive.org/web/20211123034031/https://portswigger.net/daily-swig/exploit-as-a-service-cybercriminals-exploring-potential-of-leasing-out-zero-day-vulnerabilities Exploit-as-a-service: Cybercriminals exploring potential of leasing out zero-day vulnerabilities as saved in the Internet Archive]
- [https://web.archive.org/web/20211128180425/https://www.cybertalk.org/2021/11/17/exploit-as-a-service-high-rollers-and-zero-day-criminal-tactics/ Exploit-as-a-Service, high rollers and zero-day criminal tactics as saved in the Internet Archive]
- [https://web.archive.org/web/20210811091611/https://whatis.techtarget.com/definition/hacking-as-a-service-HaaS Hacking as a Service as saved in the Internet Archive]
评论 (0)