<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
	<channel>
		<title> </title>
		<link>http://3w.2ns.org/rss.php/index.php</link>
		<description><![CDATA[]]></description>
		<copyright>Copyright 2026, Admin</copyright>
		<managingEditor>Admin</managingEditor>
		<language>en-US</language>
		<generator>SPHPBLOG 0.6.0</generator>
		<item>
			<title>在 FortiGate 上自動封鎖或隔離 IPS（入侵防禦系統）事件的來源 IP，</title>
			<link>http://3w.2ns.org/rss.php/index.php?entry=entry260405-231851</link>
			<description><![CDATA[ <P ALIGN=CENTER><A NAME="Bookmark"></A><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT COLOR="#0000cc"><FONT SIZE=4 STYLE="font-size: 16pt">FortiGate	
Automation	QUARANTINE IP	From	FAZ Log</FONT></FONT></SPAN></FONT></P>
<P STYLE="widows: 2; orphans: 2">在 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">FortiGate
</FONT></SPAN></FONT>上封鎖或隔離 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IPS</FONT></SPAN></FONT>（入侵防禦系統）事件的來源
<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IP</FONT></SPAN></FONT>，</P>
<P>使用 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">FAZ
</SPAN></FONT>連動自動化腳本 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">(Automation
Stitches)</SPAN></FONT><B>自動隔離</B>攻擊的來源<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IP</FONT></SPAN></FONT>，另也可以把來源<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IP</FONT></SPAN></FONT>加入<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">deny
policy</FONT></SPAN></FONT>的來源<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IP</FONT></SPAN></FONT>群組，以下使用<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">ban
ip</FONT></SPAN></FONT>方式。</P>
<br /><br /><P STYLE="widows: 2; orphans: 2"><FONT SIZE=4><B>第一步：在
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>FortiAnalyzer
</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>建立事件處理程序
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>(</B></FONT></FONT><FONT COLOR="#00b050"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>Event
Handler</B></FONT></FONT></FONT><FONT FACE="新細明體, serif"><FONT SIZE=4><B>)</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>，</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>(</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>觸發告警時機</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>)</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>。</B></FONT></P>
<OL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	進入 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>FortiSoC</B></FONT><FONT FACE="新細明體, serif">
	&gt; </FONT><FONT FACE="新細明體, serif"><B>Event
	Handlers(</B></FONT></SPAN></FONT><FONT COLOR="#808080"><B>舊版</B><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>FOS</B></FONT></FONT></SPAN></FONT><FONT COLOR="#808080"><B>在</B><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>Event
	Handlers</B></FONT></FONT><FONT FACE="新細明體, serif"><B>)</B></FONT></SPAN></FONT>。</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	建立新的 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">Handler</FONT></SPAN></FONT>，並定義過濾條件（例如：<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif">Log
	Type: IPS</FONT><FONT FACE="新細明體, serif">, </FONT><FONT FACE="細明體, serif">Severity:
	Critical</FONT></SPAN></FONT>）。</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	勾選啟用 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>FortiGate
	Automation Stitch</B></FONT></SPAN></FONT>。<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">(IPS</FONT></SPAN></FONT>事件訊息</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	傳回給連接的 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">FortiGate</FONT></SPAN></FONT>。<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">)</FONT></SPAN></FONT></P>
</OL>
<P STYLE="margin-left: 1.27cm; margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
<IMG SRC="2026QUARANTINE-IP/2ns.org_html_3c1dd23d.png" ALIGN=BOTTOM WIDTH=637 HEIGHT=274 BORDER=0>&nbsp;</P>
<P STYLE="margin-left: 1.27cm; margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
新增<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">rule</FONT></SPAN></FONT></P>
<P STYLE="margin-left: 1.27cm; margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
<IMG SRC="2026QUARANTINE-IP/2ns.org_html_m52d9c84b.png" ALIGN=BOTTOM WIDTH=629 HEIGHT=331 BORDER=0></P>
<P STYLE="widows: 2; orphans: 2"><FONT SIZE=4><B>第二步：在
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>FortiGate
</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>建立觸發條件
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>(</B></FONT></FONT><FONT COLOR="#0070c0"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>Trigger</B></FONT></FONT></FONT><FONT FACE="新細明體, serif"><FONT SIZE=4><B>)</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>，</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>FGT</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>接收來自
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>FAZ
</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>的訊息。</B></FONT></P>
<OL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	進入 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>Security
	Fabric</B></FONT><FONT FACE="新細明體, serif"> &gt; </FONT><FONT FACE="新細明體, serif"><B>Automation</B></FONT><FONT FACE="新細明體, serif">
	&gt; </FONT><FONT FACE="新細明體, serif"><B>Trigger</B></FONT></SPAN></FONT>。</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	建立新的 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">Trigger</FONT></SPAN></FONT>，類型選擇
	<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>FortiAnalyzer
	Event Handler</B></FONT></SPAN></FONT>。</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	在選單中選取剛才在 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">FAZ
	</FONT></SPAN></FONT>建立的 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT COLOR="#00b050"><FONT FACE="新細明體, serif">Event
	Handler</FONT></FONT></SPAN></FONT>名稱。&nbsp;</P>
</OL>
<P STYLE="margin-left: 1.27cm; margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
<IMG SRC="2026QUARANTINE-IP/2ns.org_html_m45b194ef.png" ALIGN=BOTTOM WIDTH=616 HEIGHT=339 BORDER=0></P>
<P STYLE="widows: 2; orphans: 2"><FONT SIZE=4><B>第三步：在
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>FortiGate
</B></FONT></FONT></SPAN></FONT><FONT SIZE=4><B>建立封鎖動作
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>(</B></FONT></FONT><FONT COLOR="#ff0000"><FONT FACE="新細明體, serif"><FONT SIZE=4><B>Action</B></FONT></FONT></FONT><FONT FACE="新細明體, serif"><FONT SIZE=4><B>)</B></FONT></FONT></SPAN></FONT></P>
<P STYLE="widows: 2; orphans: 2"><BR>
</P>
<P STYLE="widows: 2; orphans: 2">定義接收到訊息後隔離封鎖<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif">IP</FONT></SPAN></FONT>。</P>
<P STYLE="margin-left: 1.27cm; widows: 2; orphans: 2"><B>使用</B><FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><B>CLI
Script</B></FONT></SPAN></FONT>：<FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT COLOR="#ffffff"><FONT FACE="細明體, serif"><SPAN STYLE="background: #000000">diagnose
user banned-ip add src4 %%log.srcip%% 3600 admin</SPAN></FONT></FONT></SPAN></FONT></P>
<P STYLE="margin-left: 1.27cm; margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
<IMG SRC="2026QUARANTINE-IP/2ns.org_html_662d024.png" ALIGN=BOTTOM WIDTH=602 HEIGHT=574 BORDER=0></P>
<P STYLE="margin-left: 1.27cm; widows: 2; orphans: 2"> <FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><I>(</I></FONT></SPAN></FONT><I>註：</I><FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><I>3600
</I></FONT></SPAN></FONT><I>為秒數，</I><FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif">%%log.srcip%%</FONT></SPAN></FONT><FONT FACE="細明體">為</FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif">IPS</FONT></SPAN></FONT><FONT FACE="細明體">事件的來源</FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif">IP</FONT><FONT FACE="新細明體, serif"><I>)</I></FONT><FONT FACE="新細明體, serif">&nbsp;</FONT></SPAN></FONT></P>
<P><BR>
</P>
<P><BR>
</P>
<P><BR>
</P>
<P>檢視<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">FortiGate</SPAN></FONT>隔離清單，已有<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">IPS</SPAN></FONT>入侵事件的<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">IP</SPAN></FONT>被封鎖。</P>
<P><IMG SRC="2026QUARANTINE-IP/2ns.org_html_m2ec45fdc.png" ALIGN=BOTTOM WIDTH=679 HEIGHT=343 BORDER=0></P>
<P><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">Event
log</SPAN></FONT>查找<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">Log
ID 43776</SPAN></FONT>，可以在 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">Log</SPAN></FONT>中看到被封鎖
<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">IP </SPAN></FONT>的日誌：</P>
<P><IMG SRC="2026QUARANTINE-IP/2ns.org_html_31df8dd0.png" ALIGN=BOTTOM WIDTH=565 HEIGHT=377 BORDER=0>
</P>
<P><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US">Log id</SPAN></FONT>參考
<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><A HREF="https://docs-fortinet-com.translate.goog/document/fortigate/7.2.2/fortios-log-message-reference/43776/43776-log-id-event-nac-quarantine?_x_tr_sl=en&amp;_x_tr_tl=zh-TW&amp;_x_tr_hl=zh-TW&amp;_x_tr_pto=sc">https://docs-fortinet-com.translate.goog/document/fortigate/7.2.2/fortios-log-message-reference/43776/43776-log-id-event-nac-quarantine?_x_tr_sl=en&amp;_x_tr_tl=zh-TW&amp;_x_tr_hl=zh-TW&amp;_x_tr_pto=sc</A></SPAN></FONT></P><br /><iframe src='2026QUARANTINE-IP/2ns.org.html' width=747 height=11></iframe><br /><br /><font color=0000ff>Download</font><br />自動新增位址物件加入位址群組&quot;CLI指令&quot;<br />config firewall address<br />    edit &quot;ips_%%log.srcip%%&quot;<br />        set subnet %%log.srcip%% 255.255.255.255<br />    next<br />end<br /><br />config firewall addrgrp<br />    edit &quot;ipsGroup&quot;<br />        append member &quot;ips_%%log.srcip%%&quot;<br />    next<br />end<br /><br />需有一條阻擋來源IP為ipsGroup的deny policy<br /><br /><br /><br /><center><a href="#top" >TOP</a></center>]]></description>
			<category>Fortinet</category>
			<guid isPermaLink="true">http://3w.2ns.org/rss.php/index.php?entry=entry260405-231851</guid>
			<author>Admin</author>
			<pubDate>Sun, 05 Apr 2026 15:18:51 GMT</pubDate>
			<comments>http://3w.2ns.org/rss.php/comments.php?y=26&amp;m=04&amp;entry=entry260405-231851</comments>
		</item>
		<item>
			<title>IP攻擊事件處理流程(完整紀錄處理過程)</title>
			<link>http://3w.2ns.org/rss.php/index.php?entry=entry260311-230135</link>
			<description><![CDATA[ <br /><font color=0000ff>Download</font> <a href="http://3w.2ns.org" target="_blank" >filename</a><br /><P STYLE="margin-bottom: 0cm">在資安設備（如圖中）攔截到惡意攻擊後，進行「<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">Abuse</SPAN></FONT></SPAN></FONT>（濫用）申訴」是指向該攻擊源
<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">IP
</SPAN></FONT></SPAN></FONT>的所屬單位（通常是 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">ISP
</SPAN></FONT></SPAN></FONT>或雲端服務商）。</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><BR>
</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">以下是這次的
</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>Abuse
</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>申訴流程</B></FONT><FONT FACE="新細明體">：</FONT></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><BR>
</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">1.
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">蒐集證據
</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">(Evidence
Collection)</SPAN></FONT></SPAN></FONT></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">在進行申訴前，需要從
資安設備或伺服器匯出或截圖關鍵證據：</FONT></P>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>攻擊源 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>IP</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
	<FONT FACE="新細明體">如圖中的 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif"><SPAN LANG="en-US">165.227.132.28</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>攻擊時間：</B></FONT>
	<FONT FACE="新細明體">包含日期、時間與時區（</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">UTC
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">或在地時區）。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>攻擊類型：</B></FONT>
	<FONT FACE="新細明體">說明是掃描、暴力破解還是大量連線（圖中顯示
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif"><SPAN LANG="en-US">blocked-connection</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">）。</FONT></P>
</UL>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">從這張圖表來看，安全設備的監控介面，顯示網路中存在大量的</FONT><FONT FACE="新細明體"><B>被拒絕連線
</B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>(blocked-connection)</B></SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">事件。 </FONT></P>
<P STYLE="margin-bottom: 0cm"><IMG SRC="20260312www.2ns.org/2ns_html_2e527fdb.png" NAME="圖形1" ALIGN=BOTTOM WIDTH=554 HEIGHT=227 BORDER=0></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">"blocked-connection"</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
<FONT FACE="新細明體">這通常代表流量因為觸發了防火牆的
</FONT><FONT FACE="新細明體"><B>拒絕策略 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>(Deny
Policy)</B></SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">而被阻擋。</FONT></P>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>威脅 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>ID
	131072</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
	<FONT FACE="新細明體">在 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">Fortinet
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">日誌中，這是一個特定的編號，用來標記被防火牆策略直接阻斷（而非被掃毒或入侵檢測系統阻斷）的流量。</FONT></P>
</UL>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>常見原因：</B></FONT>
	<FONT FACE="新細明體">可能是未授權的存取嘗試、過期的連線請求，或者是使用者未通過入口網頁
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">(Captive
	Portal) </SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">認證就嘗試連網。 </FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>威脅分數 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>(Threat
	Score)</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
	<FONT FACE="新細明體">數值高達 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT COLOR="#ff0000"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">212,030</SPAN></FONT></FONT></SPAN></FONT><FONT FACE="新細明體">。這是根據「風險等級
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">×
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">事件次數」累加而成的。由於單次阻斷的預設權重通常很高，大量阻斷會導致分數飆升。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>來源 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>IP
	(165.227.132.28)</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
	<FONT FACE="新細明體">此 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">產生了
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">2,385
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">次事件，貢獻了大部分的威脅分數。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>來源介面 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>(wan2)</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>：</B></FONT>
	<FONT FACE="新細明體">顯示這些流量是從外部網際網路
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">(WAN)
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">嘗試進入。 </FONT></P>
</UL>
<P STYLE="margin-bottom: 0cm">查詢每小時高達降將近2500次攻擊
</P>
<P STYLE="margin-bottom: 0cm"><IMG SRC="20260312www.2ns.org/2ns_html_6e7bc487.png" NAME="圖形2" ALIGN=BOTTOM WIDTH=554 HEIGHT=327 BORDER=0></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">2.
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">查詢申訴管道
</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">(Finding
the Abuse Contact)</SPAN></FONT></SPAN></FONT></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">找出該
</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">歸誰管。可以使用</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">whois</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">工具查詢：</FONT></P>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>Whois
	</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體"><B>查詢：</B></FONT>
	<FONT FACE="新細明體">使用 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">ARIN</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">、</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">APNIC
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">或 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IPinfo
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">搜尋該 </FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<B>尋找 </B><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US"><B>Abuse
	Email</B></SPAN></FONT></SPAN></FONT><B>：</B> 在查詢結果中尋找
	<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US">abuse-mailbox</SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
	</SPAN></FONT></SPAN></FONT>或 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US">abuse@...</SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
	</SPAN></FONT></SPAN></FONT>的電子郵件位址。</P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	查詢結果<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US">:
	IP 165.227.132.28</SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
	</SPAN></FONT></SPAN></FONT>屬於 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US">DigitalOcean</SPAN></FONT></SPAN></FONT>，該組織有提供<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="serif"><SPAN LANG="en-US">ABUSE</SPAN></FONT></SPAN></FONT><SPAN LANG="zh-TW">申訴</SPAN>網址。</P>
</UL>
<P STYLE="margin-bottom: 0cm"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">Whois:</SPAN></FONT></P>
<TABLE WIDTH=100% BORDER=1 CELLPADDING=4 CELLSPACING=3>
	<COL WIDTH=256*>
	<TR>
		<TD WIDTH=100% VALIGN=TOP BGCOLOR="#eeeeee">
			<P STYLE="margin-bottom: 0cm"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">NetRange:
			165.227.0.0 - 165.227.255.255<BR>CIDR: 165.227.0.0/16<BR>NetName:
			DIGITALOCEAN-165-227-0-0<BR>NetHandle: <A HREF="https://www.whois365.com/tw/ip/NET-165-227-0-0-1">NET-165-227-0-0-1</A><BR>Parent:
			NET165 (<A HREF="https://www.whois365.com/tw/ip/NET-165-0-0-0-0">NET-165-0-0-0-0</A>)<BR>NetType:
			Direct Allocation<BR>OriginAS: <BR>Organization: DigitalOcean, LLC
			(DO-13)<BR>RegDate: 2016-10-06<BR>Updated: 2020-04-03<BR>Comment:
			Routing and Peering Policy can be found at <A HREF="https://www.as14061.net/">https://www.as14061.net</A></SPAN></FONT></SPAN></FONT></P>
			<P STYLE="margin-bottom: 0cm"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">Comment:
			<BR>Comment: Please submit abuse reports at
			<A HREF="https://www.digitalocean.com/company/contact/#abuse">https://www.digitalocean.com/company/contact/#abuse</A></SPAN></FONT></SPAN></FONT></P>
			<P><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">Ref:
			<A HREF="https://rdap.arin.net/registry/ip/165.227.0.0">https://rdap.arin.net/registry/ip/165.227.0.0</A></SPAN></FONT></SPAN></FONT></P>
		</TD>
	</TR>
</TABLE>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">3.
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">開啟</FONT><FONT FACE="新細明體"><SPAN LANG="zh-TW">申訴網址</SPAN></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">abuse
reports at
<A HREF="https://www.digitalocean.com/company/contact/#abuse">https://www.digitalocean.com/company/contact/#abuse</A></SPAN></FONT></SPAN></FONT>，<FONT FACE="新細明體">提交申訴</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">(Submitting
the Report)</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">。</FONT></P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">若查詢結果無</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">abuse</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">網址，需撰寫一封簡單明瞭的英文郵件（大部分國際
</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">ISP
</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">僅收英文申訴），內容包含：</FONT></P>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>主旨：</B></FONT> <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif"><SPAN LANG="en-US">Abuse
	Report: [</SPAN></FONT></SPAN></FONT><FONT FACE="細明體">攻擊類型</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif"><SPAN LANG="en-US">]
	from IP [</SPAN></FONT></SPAN></FONT><FONT FACE="細明體">來源</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="細明體, serif"><SPAN LANG="en-US">IP]</SPAN></FONT></SPAN></FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>內文：</B></FONT></P>
	<UL>
		<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
		<FONT FACE="新細明體">說明您的系統在什麼時間偵測到來自該
		</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP
		</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">的惡意行為。</FONT></P>
		<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
		<FONT FACE="新細明體">附上攔截次數（如圖顯示已攔截
		</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">2,385
		</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">次）。</FONT></P>
		<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
		<FONT FACE="新細明體">貼上原始日誌作為佐證。</FONT></P>
	</UL>
</UL>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm">提交申訴之後，</P>
<P STYLE="margin-bottom: 0cm">收到系統回覆案件已成立，並且有<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">ticket</SPAN></FONT></SPAN></FONT>號碼<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">11790601</SPAN></FONT></SPAN></FONT>。</P>
<P STYLE="margin-bottom: 0cm"><IMG SRC="20260312www.2ns.org/2ns_html_b884edd.png" NAME="圖形3" ALIGN=BOTTOM WIDTH=554 HEIGHT=368 BORDER=0></P>
<TABLE WIDTH=100% BORDER=1 BORDERCOLOR="#000000" CELLPADDING=4 CELLSPACING=0>
	<COL WIDTH=256*>
	<TR>
		<TD WIDTH=100% VALIGN=TOP BGCOLOR="#eeeeee">
			<P STYLE="margin-bottom: 0cm">感謝您的提交。安全營運中心
			<FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">(SOC)
			</SPAN></FONT></SPAN></FONT>的成員將盡快審核詳細資訊。
						</P>
			<P STYLE="margin-bottom: 0cm">您的工單號碼為 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">11790601</SPAN></FONT></SPAN></FONT>。
						</P>
			<P STYLE="margin-bottom: 0cm">此致， 
			</P>
			<P STYLE="margin-bottom: 0cm"><BR>
			</P>
			<P>安全營運中心 <FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">DigitalOcean</SPAN></FONT></SPAN></FONT></P>
		</TD>
	</TR>
</TABLE>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm"><IMG SRC="20260312www.2ns.org/2ns_html_4b549d78.png" NAME="圖形4" ALIGN=BOTTOM WIDTH=554 HEIGHT=373 BORDER=0></P>
<P STYLE="margin-bottom: 0cm">申訴送出後很快收到處理<SPAN LANG="zh-TW">回信</SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">:</SPAN></FONT></SPAN></FONT></P>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<TABLE WIDTH=100% BORDER=1 BORDERCOLOR="#000000" CELLPADDING=4 CELLSPACING=0>
	<COL WIDTH=256*>
	<TR>
		<TD WIDTH=100% VALIGN=TOP BGCOLOR="#eeeeee">
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">感謝您提交此報告。</SPAN></P>
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">我們已查明並終止了此次事件的責任用戶。
			</SPAN>
			</P>
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">此致， </SPAN>
			</P>
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">安全營運中心
			</SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">DigitalOcean
			</SPAN></SPAN></FONT>
			</P>
			<P STYLE="margin-bottom: 0cm"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">2026-03-11
			08:53:06 </SPAN></SPAN></FONT>
			</P>
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">新的 </SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">DDoS
			</SPAN></SPAN></FONT><SPAN LANG="zh-TW">攻擊報告提交 </SPAN>
			</P>
			<P STYLE="margin-bottom: 0cm"><SPAN LANG="zh-TW">攻擊類型：</SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">DDoS
			</SPAN></SPAN></FONT>
			</P>
			<P><SPAN LANG="zh-TW">攻擊證據：此 </SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">IP
			</SPAN></SPAN></FONT><SPAN LANG="zh-TW">位址 </SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">(165.227.132.28)
			</SPAN></SPAN></FONT><SPAN LANG="zh-TW">每小時發動約 </SPAN><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><SPAN LANG="zh-TW">2,500
			</SPAN></SPAN></FONT><SPAN LANG="zh-TW">次攻擊。</SPAN> 
			</P>
		</TD>
	</TR>
</TABLE>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm">這次處理對方處理效率很快，從申訴到完成處理並回覆大約五個半小時。</P>
<P STYLE="margin-bottom: 0cm"><BR>
</P>
<P STYLE="margin-bottom: 0cm; widows: 2; orphans: 2"><FONT FACE="新細明體">後續再觀察以下兩點來確認風險是否解除：</FONT></P>
<UL>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2"><A NAME="Bookmark"></A>
	<FONT FACE="新細明體"><B>流量趨勢：</B></FONT><FONT FACE="新細明體">明顯下降趨勢，說明攻擊力道正在減弱。</FONT></P>
	<LI><P STYLE="margin-top: 0.18cm; margin-bottom: 0.18cm; widows: 2; orphans: 2">
	<FONT FACE="新細明體"><B>持續監控：</B></FONT> <FONT FACE="新細明體">雖然
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">已被阻斷，但若該
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US">IP
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">仍持續產生數千次請求，建議在防火牆最頂端加入一條
	</FONT><FONT FACE="新細明體"><B>黑名單策略 </B></FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>(Blacklist)</B></SPAN></FONT><FONT FACE="Calibri, serif"><SPAN LANG="en-US">
	</SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">或使用
	</FONT><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><FONT FACE="新細明體, serif"><SPAN LANG="en-US"><B>Local-in
	Policy</B></SPAN></FONT></SPAN></FONT><FONT FACE="新細明體">，直接在底層丟棄流量，以減輕防火牆處理日誌與分數計算的效能負擔。</FONT></P>
</UL>
<P STYLE="margin-bottom: 0cm"><FONT FACE="Times New Roman, serif"><SPAN LANG="en-US"><A HREF="http://www.2ns.org/" TARGET="_blank"><FONT FACE="Calibri, serif"><SPAN LANG="en-US">Http://www.2ns.org/</SPAN></FONT></A></SPAN></FONT></P><br /><iframe src='20260312www.2ns.org/2ns.html' width=747 height=5></iframe><br /><br /><br /><br /><br /><center><a href="#top" >TOP</a></center>]]></description>
			<category>資安通報</category>
			<guid isPermaLink="true">http://3w.2ns.org/rss.php/index.php?entry=entry260311-230135</guid>
			<author>Admin</author>
			<pubDate>Wed, 11 Mar 2026 15:01:35 GMT</pubDate>
			<comments>http://3w.2ns.org/rss.php/comments.php?y=26&amp;m=03&amp;entry=entry260311-230135</comments>
		</item>
	</channel>
</rss>
