	{"id":1790,"date":"2013-07-03T17:33:57","date_gmt":"2013-07-03T10:33:57","guid":{"rendered":"http:\/\/science-technology.vn\/?p=1790"},"modified":"2013-07-03T17:33:57","modified_gmt":"2013-07-03T10:33:57","slug":"an-ninh-he-thong","status":"publish","type":"post","link":"https:\/\/science-technology.vn\/?p=1790","title":{"rendered":"An ninh h\u1ec7 th\u1ed1ng"},"content":{"rendered":"<p><span style=\"font-size: 14px;\">M\u1ed9t ng\u01b0\u1eddi ch\u1ee7 c\u00f4ng ti vi\u1ebft: \u201cT\u00f4i l\u00e0 m\u1ed9t ng\u01b0\u1eddi doanh nghi\u1ec7p, kh\u00f4ng ph\u1ea3i l\u00e0 ng\u01b0\u1eddi k\u0129 thu\u1eadt. Doanh nghi\u1ec7p c\u1ee7a t\u00f4i ph\u1ee5 thu\u1ed9c v\u00e0o c\u00f4ng ngh\u1ec7 th\u00f4ng tin (CNTT) cho n\u00ean t\u00f4i hi\u1ec3u r\u1eb1ng an ninh l\u00e0 quan tr\u1ecdng. G\u1ea7n \u0111\u00e2y t\u00f4i \u0111\u00e3 thu\u00ea v\u00e0i chuy\u00ean vi\u00ean an ninh nh\u01b0ng t\u00f4i kh\u00f4ng bi\u1ebft h\u1ecd gi\u1ecfi \u0111\u1ebfn m\u1ee9c n\u00e0o? H\u1ecd c\u00f3 ch\u1ee9ng ch\u1ec9 an ninh nh\u01b0ng g\u1ea7n \u0111\u00e2y t\u00f4i bi\u1ebft r\u1eb1ng c\u00f3 &#8220;ch\u1ee9ng ch\u1ec9 gi\u1ea3&#8221; m\u00e0 m\u1ecdi ng\u01b0\u1eddi c\u00f3 th\u1ec3 mua \u0111\u01b0\u1ee3c, c\u00f3 &#8220;gian l\u1eadn thi c\u1eed&#8221; \u1edf n\u01b0\u1edbc t\u00f4i. L\u00e0m sao t\u00f4i bi\u1ebft li\u1ec7u chuy\u00ean vi\u00ean an ninh c\u1ee7a t\u00f4i c\u00f3 gi\u1ecfi hay kh\u00f4ng?&#8221;<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>\u0110\u00e1p: An ninh h\u1ec7 th\u1ed1ng l\u00e0 v\u1ea5n \u0111\u1ec1 r\u1ea5t h\u00f3c b\u00faa cho m\u1ecdi c\u00f4ng ti. Trong nhi\u1ec1u n\u0103m qua, ki\u1ec3u v\u00e0 t\u1ea5n xu\u1ea5t c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng xi be \u0111\u00e3 t\u0103ng l\u00ean kh\u00e1 nhi\u1ec1u. Ng\u00e0y nay, m\u1ecdi c\u00f4ng ti \u0111\u1ec1u l\u00e0 ch\u1ee7 th\u1ec3 cho vi\u1ec7c x\u00e2m nh\u1eadp ph\u1ee9c t\u1ea1p mang t\u00ednh ph\u00e1 hu\u1ef7 nhi\u1ec1u h\u01a1n v\u00e0 ranh ma h\u01a1n tr\u01b0\u1edbc \u0111\u00e2y. Nh\u1eefng c\u00f4ng ngh\u1ec7 m\u1edbi h\u01a1n nh\u01b0 t\u00ednh to\u00e1n m\u00e2y, m\u1ea1ng x\u00e3 h\u1ed9i v\u00e0 thi\u1ebft b\u1ecb di \u0111\u1ed9ng c\u0169ng \u0111\u00e3 cung c\u1ea5p nh\u1eefng c\u01a1 h\u1ed9i m\u1edbi cho hackers t\u1ea5n c\u00f4ng.<\/p>\n<p>N\u1ebfu b\u1ea1n kh\u00f4ng th\u1ec3 &#8220;tin c\u1eady&#8221; \u0111\u01b0\u1ee3c tri th\u1ee9c v\u00e0 k\u0129 n\u0103ng c\u1ee7a ng\u01b0\u1eddi ri\u00eang c\u1ee7a b\u1ea1n th\u00ec b\u1ea1n c\u00f3 th\u1ec3 c\u1ea7n c\u00f3 c\u00f4ng ti an ninh CNTT cung c\u1ea5p t\u01b0 v\u1ea5n cho b\u1ea1n. C\u00e1c chuy\u00ean vi\u00ean n\u00e0y c\u0169ng c\u00f3 th\u1ec3 th\u1ea9m tra li\u1ec7u &#8220;chuy\u00ean vi\u00ean c\u00f3 ch\u1ee9ng ch\u1ec9 c\u1ee7a b\u1ea1n&#8221; c\u00f3 tri th\u1ee9c v\u00e0 k\u0129 n\u0103ng hi\u1ec7n th\u1eddi nh\u1ea5t hay c\u1ea7n \u0111\u00e0o t\u1ea1o th\u00eam. C\u00f3 c\u00e1ch \u0111\u01a1n gi\u1ea3n \u0111\u1ec3 t\u00ecm ra \u0111i\u1ec1u \u0111\u00f3 n\u1eefa. L\u00e0 ng\u01b0\u1eddi ch\u1ee7 c\u00f4ng ti, b\u1ea1n c\u00f3 th\u1ec3 h\u1ecfi m\u1ed9t s\u1ed1 c\u00e2u h\u1ecfi m\u1ee9c cao \u0111\u1ec3 x\u00e1c \u0111\u1ecbnh t\u1ed5 an ninh m\u1ea1ng c\u1ee7a b\u1ea1n gi\u00e1m s\u00e1t t\u1ed1t th\u1ebf n\u00e0o m\u1ea1ng c\u1ee7a b\u1ea1n. N\u1ebfu h\u1ecd kh\u00f4ng bi\u1ebft c\u00e2u tr\u1ea3 l\u1eddi, h\u1ecd c\u00f3 th\u1ec3 kh\u00f4ng hi\u1ec3u c\u00e1i g\u00ec \u0111ang x\u1ea3y ra trong m\u1ea1ng c\u1ee7a b\u1ea1n. Sau \u0111\u00e2y l\u00e0 m\u1ed9t s\u1ed1 c\u00e2u h\u1ecfi b\u1ea1n c\u00f3 th\u1ec3 h\u1ecfi:<\/p>\n<p>1)\u00a0\u00a0\u00a0 L\u01b0u th\u00f4ng trung b\u00ecnh trong m\u1ea1ng l\u00e0 g\u00ec?<\/p>\n<p>2)\u00a0\u00a0\u00a0 \u1ee8ng d\u1ee5ng n\u00e0o \u0111\u01b0\u1ee3c d\u00f9ng nhi\u1ec1u nh\u1ea5t trong c\u00f4ng ti ch\u00fang ta?<\/p>\n<p>3)\u00a0\u00a0\u00a0 C\u00f3 \u1ee9ng d\u1ee5ng kh\u00f4ng \u0111\u01b0\u1ee3c bi\u1ebft n\u00e0o ch\u1ea1y trong m\u1ea1ng kh\u00f4ng?<\/p>\n<p>4)\u00a0\u00a0 Bao nhi\u00eau virus \u0111\u01b0\u1ee3c g\u1eedi t\u1edbi c\u00f4ng ti ch\u00fang ta h\u00f4m nay? Ch\u00fang ta c\u00f3 th\u1ec3 \u0111o \u0111\u01b0\u1ee3c \u0111i\u1ec1u \u0111\u00f3 kh\u00f4ng? N\u1ebfu c\u00f4ng ti c\u00f3 ph\u1ea7n m\u1ec1m ch\u1ed1ng virus \u0111\u01b0\u1ee3c c\u00e0i \u0111\u1eb7t, n\u00f3 c\u00f3 th\u1ec3 sinh ra b\u00e1o c\u00e1o cho b\u1ea1n.<\/p>\n<p>5)\u00a0\u00a0\u00a0 C\u00f3 virus n\u00e0o m\u00e0 ph\u1ea7n m\u1ec1m ch\u1ed1ng virus c\u1ee7a ch\u00fang ta kh\u00f4ng bi\u1ebft kh\u00f4ng? Ch\u00fang ta c\u00f3 c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m ch\u1ed1ng virus tr\u00ean c\u01a1 s\u1edf th\u01b0\u1eddng xuy\u00ean kh\u00f4ng? Bao l\u00e2u &#8211; h\u00e0ng ng\u00e0y, h\u00e0ng tu\u1ea7n hay h\u00e0ng th\u00e1ng?<\/p>\n<p>6)\u00a0\u00a0\u00a0 C\u00f3 ho\u1ea1t \u0111\u1ed9ng m\u1ea1ng n\u00e0o x\u1ea3y ra sau gi\u1edd l\u00e0m vi\u1ec7c kh\u00f4ng?<\/p>\n<p>7)\u00a0\u00a0\u00a0 Ch\u00fang ta c\u00f3 lu\u1ed3ng \u0111i ra n\u00e0o t\u1edbi c\u00e1c n\u01b0\u1edbc hay c\u00e1c tr\u1ea1m b\u1ea5t th\u01b0\u1eddng kh\u00f4ng?<\/p>\n<p>8)\u00a0\u00a0\u00a0 Ch\u00fang ta c\u00f3 ng\u01b0\u1eddi n\u00e0o t\u1ea3i xu\u1ed1ng PDF v\u1edbi n\u1ed9i dung c\u00f3 flash \u0111\u01b0\u1ee3c nh\u00fang kh\u00f4ng?<\/p>\n<p>Cho d\u00f9 t\u1ed5 an ninh c\u1ee7a b\u1ea1n l\u00e0 gi\u1ecfi, h\u1ecd kh\u00f4ng th\u1ec3 b\u1ea3o v\u1ec7 cho c\u00f4ng ti c\u1ee7a b\u1ea1n kh\u1ecfi m\u1ecdi ph\u1ea7n m\u1ec1m \u0111\u1ed9c hay virus v\u00e0 c\u00e1c lo\u1ea1i t\u1ea5n c\u00f4ng kh\u00e1c. B\u1ea1n ph\u1ea3i gi\u1ea3 \u0111\u1ecbnh r\u1eb1ng c\u00f4ng ti c\u1ee7a b\u1ea1n \u0111ang b\u1ecb t\u1ea5n c\u00f4ng tr\u00ean c\u01a1 s\u1edf th\u01b0\u1eddng xuy\u00ean cho n\u00ean n\u1ebfu b\u1ea1n v\u1eabn kh\u00f4ng c\u1ea3m th\u1ea5y tho\u1ea3i m\u00e1i, b\u1ea1n c\u00f3 th\u1ec3 c\u1ea7n l\u00e0m h\u1ee3p \u0111\u1ed3ng v\u1edbi c\u00f4ng ti an ninh CNTT \u0111\u1ec3 cung c\u1ea5p d\u1ecbch v\u1ee5 an ninh th\u00eam.<\/p>\n<p>Trong qu\u00e1 kh\u1ee9, t\u01b0\u1eddng l\u1eeda l\u00e0 vi\u1ec7c ph\u00f2ng th\u1ee7 t\u1ed1t nh\u01b0ng ng\u00e0y nay c\u00f4ng ti kh\u00f4ng th\u1ec3 d\u1ef1a tr\u00ean t\u01b0\u1eddng l\u1eeda th\u00eam n\u1eefa. C\u00f4ng ngh\u1ec7 thay \u0111\u1ed5i y\u00eau c\u1ea7u c\u00f4ng ti l\u1ea5y c\u00e1ch ti\u1ebfp c\u1eadn t\u00edch c\u1ef1c v\u00e0 c\u00f3 l\u1ebd c\u1ea7n c\u00e0i \u0111\u1eb7t c\u00f4ng ngh\u1ec7 m\u1edbi \u0111\u1ec3 \u00edt nh\u1ea5t c\u0169ng \u0111i tr\u01b0\u1edbc m\u1ed9t b\u01b0\u1edbc so v\u1edbi hacker. Ph\u1ea7n l\u1edbn c\u00e1c c\u00f4ng ti an ninh c\u00f3 th\u1ec3 cung c\u1ea5p c\u00e1ch ti\u1ebfp c\u1eadn \u0111\u1ea7u cu\u1ed1i t\u1edbi \u0111\u1ea7u cu\u1ed1i cho an ninh xi be. Thay v\u00ec ch\u1ec9 thi\u1ebft l\u1eadp v\u00e0i c\u00f4ng c\u1ee5 an ninh, h\u1ecd c\u00f3 th\u1ec3 t\u00ecm gi\u1ea3i ph\u00e1p \u0111\u1ea7u cu\u1ed1i t\u1edbi \u0111\u1ea7u cu\u1ed1i bao g\u1ed3m m\u1ecdi th\u1ee9 t\u1eeb ki\u1ec3m \u0111\u1ecbnh \u0111\u1ea7y \u0111\u1ee7 m\u1ea1ng d\u1eef li\u1ec7u t\u1edbi an ninh k\u1ebft c\u1ea5u n\u1ec1n CNTT. H\u1ecd c\u00f3 th\u1ec3 ti\u1ebfn h\u00e0nh ki\u1ec3m \u0111\u1ecbnh an ninh \u0111\u1ec3 nh\u1eadn di\u1ec7n s\u1ef1 mong manh, v\u00e0 nh\u1eadn di\u1ec7n v\u1ec1 qu\u1ea3n l\u00ed, v\u00e0 vi\u1ec7c l\u1ecdc h\u00e0nh vi n\u1eefa.<\/p>\n<p>Nh\u1eadn di\u1ec7n qu\u1ea3n l\u00ed \u0111\u1ea3m b\u1ea3o r\u1eb1ng ng\u01b0\u1eddi d\u00f9ng c\u00f3 th\u1ec3 truy nh\u1eadp ch\u1ec9 v\u00e0o d\u1eef li\u1ec7u v\u00e0 \u1ee9ng d\u1ee5ng h\u1ecd c\u00f3 th\u1ea9m quy\u1ec1n truy nh\u1eadp l\u00e0 c\u00f4ng ngh\u1ec7 m\u1ecdi c\u00f4ng ti n\u00ean c\u00f3. N\u00f3 ph\u00e2n c\u00f4ng vai tr\u00f2 cho ng\u01b0\u1eddi d\u00f9ng tr\u00ean h\u1ec7 th\u1ed1ng; t\u1eebng vai tr\u00f2 c\u00f3 m\u1ee9c \u0111\u1ed9 truy nh\u1eadp c\u00f3 th\u1ea9m quy\u1ec1n kh\u00e1c nhau t\u1edbi n\u1ed9i dung v\u00e0 khu v\u1ef1c c\u1ee7a m\u1ea1ng. N\u00f3 c\u0169ng l\u00e0m cho vi\u1ec7c d\u00f9ng k\u00e9o d\u00e0i c\u00e1c ch\u1ee9ng ch\u1ec9 s\u1ed1 th\u1ee9c v\u00e0 t\u1ed5 h\u1ee3p t\u00ean ng\u01b0\u1eddi d\u00f9ng\/m\u1eadt kh\u1ea9u. B\u1ed9 l\u1ecdc d\u1ef1a tr\u00ean h\u00e0nh vi l\u00e0 c\u00e1ch kh\u00e1c \u0111\u1ec3 gi\u00fap ng\u0103n ng\u1eeba c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng xi be. V\u1ec1 c\u0103n b\u1ea3n, n\u00f3 l\u00e0 c\u00e1ch theo d\u00f5i h\u00e0nh vi c\u1ee7a nh\u1eefng ng\u01b0\u1eddi truy nh\u1eadp v\u00e0o n\u1ed9i dung. N\u1ebfu m\u1ed9t ng\u01b0\u1eddi d\u00f9ng \u0111\u1eb7c bi\u1ec7t c\u00f3 xu h\u01b0\u1edbng truy nh\u1eadp v\u00e0o m\u1ed9t t\u1ec7p \u0111\u1eb7c bi\u1ec7t ba hay b\u1ed1n l\u1ea7n trong m\u1ed9t th\u1eddi k\u00ec \u0111\u00e3 cho nh\u01b0ng m\u1ed9t h\u00f4m n\u00e0o \u0111\u00f3 c\u1ed1 truy nh\u1eadp n\u00f3 h\u01a1n 20 l\u1ea7n, h\u1ec7 th\u1ed1ng s\u1ebd l\u1ea9y c\u00f2 l\u01b0u \u00fd b\u00e1o \u0111\u1ed9ng.<\/p>\n<p>Kh\u00f4ng g\u00ec t\u1ed1t h\u01a1n ph\u00f2ng ng\u1eeba v\u00ec khi \u0111i\u1ec1u x\u1ea5u x\u1ea3y ra, th\u01b0\u1eddng l\u00e0 qu\u00e1 tr\u1ec5.<\/p>\n<p>&nbsp;<\/p>\n<p>&#8212;-English version&#8212;-<\/p>\n<p>&nbsp;<\/p>\n<p>System Security<\/p>\n<p>A company owner wrote: \u201cI am a business person, not a technical person. My business depends on information technology (IT) so I understand that security is important. Recently I hired several security specialists but I do not know how good they are? They have security certificates but recently I learned that there are \u201cphony certificates\u201d that people can buy, there are \u201ccheating on exams\u201d in my country. How do I know if my security specialists are good or not?&#8221;<\/p>\n<p>&nbsp;<\/p>\n<p>Answer: System security is a very tough issue for every company. In the past several years, the type and frequency of cyber-attacks have increased dramatically. Today, every company is subject to sophisticated intrusion that is more destructive and malicious than ever before. Newer technologies such as cloud computing, social networking and mobile devices also have provided new opportunities for hackers to attack.<\/p>\n<p>If you cannot \u201ctrust\u201d the knowledge and skills of your own people than you may need to have an IT security company to provide consultation to you. These specialists can also verify if your \u201ccertificated specialists\u201d have the most current knowledge or skills or need more trainings. There is a simple way to find out too. As company owner, you may ask some high level questions to determine how well your network security team is monitoring your networks. If they do not know the answer, they may not understand what is happening in your networks. Following are some questions that you may ask:<\/p>\n<p>1)\u00a0\u00a0\u00a0 What is the average traffic in the network?<\/p>\n<p>2)\u00a0 \u00a0\u00a0What are the most used applications in our company?<\/p>\n<p>3)\u00a0\u00a0\u00a0 Are there any unknown applications running in the network?<\/p>\n<p>4)\u00a0\u00a0\u00a0 How many viruses were sent to our company today? Can we measure that? If the company has an anti-virus software installed, it can generate a report to you.<\/p>\n<p>5)\u00a0\u00a0\u00a0 Are there any viruses that our anti-virus software does not know? Are we updating the anti-virus software on frequent basis? How often &#8211; daily, weekly or monthly?<\/p>\n<p>6)\u00a0\u00a0\u00a0 Is there any network activity happening after work hours?<\/p>\n<p>7)\u00a0\u00a0\u00a0 Do we have any outgoing traffic going out to uncommon countries or sites?<\/p>\n<p>8)\u00a0\u00a0\u00a0 Do we have any people download PDF with flash content embebbed?<\/p>\n<p>Even your security team is good. They cannot protect your company from every single malware or virus and other kind of attacks. You must assume that your company is under attack on a frequent basis so if you still do not feel comfortable, you may need to contract with an IT security company to provide security services instead.<\/p>\n<p>In the past, firewall is a good defense but today company cannot rely on firewall anymore. The changing technology requires companies to take an active approach and perhaps implement new technology to be at least one step ahead of hackers. Most security companies could provide an end-to-end approach to cyber-security. Rather than just set up several security tools, they can get an end-to-end solution that includes everything from a complete audit of the data network to IT infrastructure security. They can conduct a security audit to identify vulnerability, and identity management, and behavioral filtering too.<\/p>\n<p>Identity management ensures that users can access only the data and applications they have authorized to access is a technology every company should have. It assigns roles to users on the system; each role has a different level of authorized access to content and areas of the network. It also makes extensive use of digital certificates and user name\/password combinations. Behavior-based filtering is another way to help prevent cyber-attacks. Basically, it is a way to track the behavior of people who are accessing content. If a particular user tends to access a particular file three or four times in a given period of time but on one day tries to access it more than 20 times, the system would trigger an alarm notification.<\/p>\n<p>Nothing is better than prevention because when bad thing happens, it is usually too late.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t ng\u01b0\u1eddi ch\u1ee7 c\u00f4ng ti vi\u1ebft: \u201cT\u00f4i l\u00e0 m\u1ed9t ng\u01b0\u1eddi doanh nghi\u1ec7p, kh\u00f4ng ph\u1ea3i l\u00e0 ng\u01b0\u1eddi k\u0129 thu\u1eadt. Doanh nghi\u1ec7p c\u1ee7a t\u00f4i ph\u1ee5 thu\u1ed9c v\u00e0o &hellip; <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31,26],"tags":[],"class_list":["post-1790","post","type-post","status-publish","format-standard","hentry","category-cac-van-de-khac","category-xu-huong-cong-nghe"],"_links":{"self":[{"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/posts\/1790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/science-technology.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1790"}],"version-history":[{"count":1,"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/posts\/1790\/revisions"}],"predecessor-version":[{"id":1791,"href":"https:\/\/science-technology.vn\/index.php?rest_route=\/wp\/v2\/posts\/1790\/revisions\/1791"}],"wp:attachment":[{"href":"https:\/\/science-technology.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/science-technology.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/science-technology.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}