為達最佳瀏覽效果,建議使用 Chrome、Firefox 或 Microsoft Edge 的瀏覽器。

關閉此視窗 請至Edge官網下載 請至FireFox官網下載 請至Google官網下載
晴時多雲

    限制級
    您即將進入之新聞內容 需滿18歲 方可瀏覽。
    根據「電腦網路內容分級處理辦法」修正條文第六條第三款規定,已於網站首頁或各該限制級網頁,依台灣網站分級推廣基金會規定作標示。 台灣網站分級推廣基金會(TICRF)網站:http://www.ticrf.org.tw

    《TAIPEI TIMES》 Agencies are lacking in cybersecurity, MODA says

    
The word “cyber” is displayed on a computer motherboard in an illustration photograph taken on Oct. 26, 2017.Photo: Reuters
Photo: Reuters

    The word “cyber” is displayed on a computer motherboard in an illustration photograph taken on Oct. 26, 2017.Photo: Reuters Photo: Reuters

    2025/01/19 03:00

    By Jake Chung / Staff writer, with CNA

    Government agencies have weak encryption methods, inadequate screening against injection attacks and experience broken access controls, according to the latest report published by the Ministry of Digital Affairs’ (MODA) Administration for Cyber Security.

    Each year, the agency selects one government Web site that is publicly accessible for a live security exercise. After the exercise, it compiles a report detailing the information security risks found.

    There were 83,105 thwarted cyberattack incidents last month, down 13,070 compared with the previous month, the report said.

    The top threats were information gathering probes, comprising 52 percent of attacks, invasive attacks at 21 percent and attempts at system invasion at 16 percent, according to the report.

    Hackers have used third-party e-mail services to bombard certain government agencies with phishing e-mails containing files that read like petitions, with the malware creating backdoors for hackers and allowing them access to sensitive information, it said.

    Forty information security incidents were reported last month, down 13 from the previous month, the report said.

    About 47.5 percent of incidents were caused by agency equipment connecting to rogue relay stations, users downloading malware using agency networks, or connections to applications that would steal data or insert malware, it said.

    Only a portion of government agency employees are screening sensitive data by converting the files using built-in masking functions from PDF software, it added.

    The Administration for Cyber Security said such efforts are easily cracked, and users should “scrub” their files before converting them to an image file.

    The report said government Web sites exhibited a weakness against injection attacks and posed a possible breakthrough point for hackers.

    Government agencies should identify and remove such vulnerabilities, the report said, adding that special characters should be included in a filter list to prevent injection attacks.

    Injection attacks are instances where hackers manipulate vulnerabilities in coding to inject malware or trick systems into allowing them to access data that should not be available to ordinary users.

    Government Web sites are vulnerable to broken access controls, allowing some users to access files previously inaccessible via path traversal attacks, the report said.

    Government agencies must implement access controls for files and data, and ensure that users cannot access files via path traversal attacks, which use an affected application to access files and system folders higher in the directory hierarchy than the Web root folder on the server, it said.

    新聞來源:TAIPEI TIMES

    不用抽 不用搶 現在用APP看新聞 保證天天中獎  點我下載APP  按我看活動辦法

    圖
    焦點今日熱門
    看更多!請加入自由時報粉絲團

    網友回應

    載入中
    此網頁已閒置超過5分鐘,請點擊透明黑底或右下角 X 鈕。