Fahmo injineernimada bulshada - Ka-hortagga jabsiga Aadanaha

Qayb ka mid ah wararka dhawaanahan ayaa iga dhigay inaan garwaaqsado sida shucuurta bini'aadamka iyo fikradaha ay u noqon karaan (ama,) loogu isticmaali karo faa'iidooyinka kuwa kale. Ku dhawaad ​​qof kasta oo idinka mid ah wuu garanayaa Edward Snowden , oo ah qofka sirta u sheega ee NSA ku dhex dhuumanaya adduunka oo dhan. Reuters ayaa ku warantay in uu helay ilaa 20-25 qof oo NSA ah si ay ugu wareejiyaan furaha sirta ah isaga oo dib u helay xog uu faafiyay markii dambe [1]. Bal qiyaas(Imagine) sida ay u jilicsan tahay shabakadaada shirkadeed, xitaa iyada oo leh kan ugu xoogan uguna wanaagsan software-ka amniga!

bulsheed_ingineering

Waa maxay injineernimada bulshada

Daciifnimada aadanaha(Human) , xiisaha, shucuurta, iyo sifooyin kale ayaa inta badan loo adeegsaday soo saarista xogta si sharci darro ah - ha ahaato warshad kasta. Warshadaha IT(IT Industry) ayaa, si kastaba ha ahaatee, siiyay magaca injineernimada bulshada. Waxaan u qeexay injineernimada bulshada sida:

“The method whereby an external person gains control over one or more employees of any organization by any means with intention to obtain the organization’s data illegally”

Halkan waxaa ah sadar kale oo isla sheekadaas [1] ah oo aan rabo inaan soo qaato - " Hay'adaha ammaanku waxay ku adag tahay fikradda ah in ninka ku jira qolalka soo socda aan la isku halleyn karin(Security agencies are having a hard time with the idea that the guy in the next cubicle may not be reliable) ". Waxaan wax ka beddelay weedha si aan ugu waafajiyo macnaha guud ee halkan. Waxaad ku akhrin kartaa warka oo dhan adigoo isticmaalaya isku xirka qaybta Tixraaca(References) .

Si kale haddii loo dhigo, ma haysatid koontarool dhammaystiran oo ku saabsan amniga ururradaada iyadoo injineernimada bulsheed uu u kobcayo si ka dhaqso badan farsamooyinka lagula qabsanayo. Injineernimada bulshadu(Social) waxa ay noqon kartaa wax la mid ah in aad wacdo qof ku leh waxaad tahay taageero tignoolajiyad oo waydiiso aqoonsigooda gelitaanka. Waa inaad heshay iimaylo phishing ah oo ku saabsan bakhtiyaa-nasiibka, dadka hodanka ah ee Bariga Dhexe(Mid East) iyo Afrika(Africa) oo doonaya la-hawlgalayaasha ganacsiga, iyo soo jeedinta shaqo si ay ku weydiiyaan faahfaahintaada.

Si ka duwan weerarrada phishing-ka, injineernimada bulshadu waa inta badan isdhexgalka tooska ah ee qof-ka-qof. Kii hore (phishing) wuxuu shaqaaleeyaa sed - taas oo ah, dadka "kalluumeysiga" waxay ku siinayaan wax rajo ah inaad ku dhici doonto. Injineerinka bulshadu(Social) waa wax badan oo ku saabsan ku guuleysiga kalsoonida shaqaalaha gudaha si ay u sheegaan faahfaahinta shirkadda aad u baahan tahay.

Akhri: (Read:) Hababka caanka ah ee injineernimada bulshada .

Farsamooyinka Injineerinka Bulshada ee la yaqaan

Way badan yihiin, oo dhammaantood waxay isticmaalaan rabitaannada aasaasiga ah ee aadanaha si ay u galaan xogta urur kasta. Farsamada injineernimada bulsheed ee aadka loo isticmaalo (malaha duugoobay) waa in la waco oo lala kulmo dadka oo la rumaysto inay ka yimaadeen taageero farsamo oo u baahan inay hubiso kumbuyuutarkaaga. Waxay kaloo abuuri karaan kaarar aqoonsi oo been abuur ah si ay kalsooni u abuuraan. Xaaladaha qaarkood, dambiilayaasha ayaa iska dhigaya mas'uuliyiin dowladeed.

Farsamo kale oo caan ah ayaa ah inaad u shaqaaleysiiso qofkaaga shaqaale ahaan hay'adda bartilmaameedka ah. Hadda, maadaama uu con-kani yahay saaxiibkaaga, waxaa laga yaabaa inaad ku kalsoonaato faahfaahinta shirkadda. Shaqaalaha dibadda ayaa laga yaabaa inay wax kaa caawiyaan, si aad dareento waajib, waana marka ay ogaan karaan inta ugu badan.

Waxaan sidoo kale akhriyay warbixinno ku saabsan dadka isticmaala hadiyadaha elegtarooniga ah. Usha USB(USB) ee quruxda badan oo lagugu keeno ciwaanka shirkadaada ama qalin ku dhex jiifa gaarigaaga ayaa cadeyn kara masiibooyinka. Xaalad ahaan, qof ayaa uga tagay qaar ka mid ah darawallada USB-ga(USB) si ula kac ah goobta baarkinka si ay wax uga qabtaan [2].

Haddii shabakadaada shirkadu ay leedahay tillaabooyin ammaan oo wanaagsan oo ku yaal meel kasta, waad barakaysan tahay. Haddii kale, qanjidhadani waxay bixiyaan marin sahlan oo loogu talagalay malware - hadiyaddaas ama "la hilmaamay" qalinleyda - nidaamyada dhexe.

Sidan oo kale ma bixin karno liis dhamaystiran oo hababka injineernimada bulshada. Waa cilmi xudunta u ah, oo lagu daray fanka xagga sare. Oo waxaad ogtahay in midkoodna uusan lahayn xuduud. Wiilasha injineernimada bulshadu(Social) waxay sii wataan hal-abuurnimada iyagoo horumarinaya software-ka oo sidoo kale si xun u isticmaali kara aaladaha wireless-ka si ay u helaan shirkadda Wi-Fi .

Akhriso: (Read:) Waa maxay bulsheed Ingineered Malware .

Kahortagga injineernimada bulshada

Shakhsi ahaan, uma maleynayo inay jirto wax aragti ah oo maamulayaashu u isticmaali karaan si ay uga hortagaan jabsiga injineernimada bulshada. Farsamooyinka injineernimada bulsheed ayaa isbeddelaya, markaa way ku adkaanaysaa maamulayaasha IT-ga inay la socdaan waxa dhacaya.

Dabcan, waxaa loo baahan yahay in la ilaaliyo wararka injineernimada bulshada si qofka loogu wargeliyo ku filan si uu u qaado tallaabooyinka amniga ku habboon. Tusaale ahaan, marka laga hadlayo aaladaha USB , maamulayaashu waxay xannibi karaan darawallada USB-ga(USB) ee noodhadhka shakhsi ahaaneed iyagoo u oggolaanaya kaliya server-ka leh nidaam ammaan oo wanaagsan. Sidoo kale(Likewise) , Wi-Fi wuxuu u baahan doonaa sir ka wanaagsan inta badan ISP(ISPs) -yada maxalliga ah .

Tababbarka shaqaalaha iyo samaynta imtixaannada aan kala sooca lahayn ee kooxaha shaqaalaha ee kala duwan waxay gacan ka geysan karaan in la aqoonsado meelaha daciifka ah ee ururka. Way sahlanaan lahayd in la tababaro oo laga digtoonaado shakhsiyaadka daciifka ah. Feejignaantu(Alertness) waa difaaca ugu fiican. Cadaadisku waa inuu noqdaa in macluumaadka gelitaanka aan lala wadaagin xitaa hoggaamiyeyaasha kooxda - iyadoon loo eegin cadaadiska. Haddii hogaamiyaha kooxdu u baahan yahay inuu galo xubinta galkiisa, isaga/iyada waxay isticmaali karaan furaha sirta ah. Taasi waa hal talo oo kaliya si aad u badbaado oo aad uga fogaato jabsiga injineernimada bulshada.

Khadka ugu hooseeya ayaa ah, marka laga reebo malware-ka iyo tuugada khadka tooska ah, dadka IT-ga waxay u baahan yihiin inay daryeeshaan injineernimada bulshada sidoo kale. Iyadoo la aqoonsanayo hababka jebinta xogta (sida qorista ereyada sirta ah iwm.), maamulayaashu waa inay sidoo kale hubiyaan in shaqaalahooda ay caqli badan yihiin si ay u aqoonsadaan farsamada injineernimada bulshada si looga fogaado gebi ahaanba. Maxay kula tahay hababka ugu fiican ee looga hortagi karo injineernimada bulshada? Haddii aad la kulanto arrin xiiso leh, fadlan nala wadaag.

Soo deji buuggan ebook-ka ah ee weerarrada injineernimada bulshada ee ay soo saartay Microsoft oo baro sida aad u ogaan karto ugana hortagi karto weerarradan oo kale ee ururkaaga.(Download this ebook on Social Engineering Attacks released by Microsoft and learn how you can detect and prevent such attacks in your organization.)

Tixraacyo(References)

[1] Reuters , Snowden wuxuu ku(Snowden) qanciyay shaqaalaha NSA inay (NSA Employees Into)helaan(Info) macluumaadka galitaanka

[2] Boing Net , Qalinleyda(Pen) loo isticmaalo in lagu faafiyo Malware(Spread Malware) .



About the author

Waxaan ahay injineer sare oo software ah iyo sawirro & horumariye app iPhone oo leh khibrad 10 sano ka badan. Xirfadahayga hardware-ka iyo software-ka ayaa iga dhigaya mid ku habboon shirkad kasta ama mashruuca casriga ah ee macaamiisha. Waxaan haystaa faham qoto dheer oo ku saabsan sida loo abuuro sawirro tayo sare leh iyo awood aan kula shaqeeyo dhammaan qaababka sawirada kala duwan. Intaa waxaa dheer, waxaan aqaannaa horumarinta Firefox iyo iOS.



Related posts