時価総額: $2.1564T -0.83%
ボリューム(24時間): $39.3565B 2.43%
  • 時価総額: $2.1564T -0.83%
  • ボリューム(24時間): $39.3565B 2.43%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.1564T -0.83%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

io.net は、ネットワーク セキュリティ侵害を鎮め、ネットワークの完全性を維持するために断固たる措置を講じます

2024/04/28 19:03

物理インフラストラクチャ ネットワークである Io.net は、悪意のある攻撃者が脆弱性を悪用してグラフィックス プロセッシング ユニット (GPU) ネットワーク デバイスのメタデータを変更したため、セキュリティ侵害によりより厳格な措置を講じることを余儀なくされました。 4 月 25 日に検出されたこの攻撃では、SQL インジェクションとユーザー ID トークンの漏洩が利用されていましたが、実際の G​​PU ハードウェアには影響しませんでした。 Io.net は、強化された認証、SQL インジェクション チェック、およびログ記録の強化を実装することで対応しました。

io.net は、ネットワーク セキュリティ侵害を鎮め、ネットワークの完全性を維持するために断固たる措置を講じます

Cybersecurity Breach: Io.net Decisive Action Maintains Network Integrity

サイバーセキュリティ侵害: Io.net の断固たる行動によりネットワークの完全性が維持される

[Date] - Io.net, the decentralized physical infrastructure network (DePIN) provider, swiftly responded to a cybersecurity breach, protecting its network and mitigating potential damage. Malicious users exploited exposed user ID tokens to execute a SQL injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

[日付] - 分散型物理インフラストラクチャ ネットワーク (DePIN) プロバイダーである Io.net は、サイバーセキュリティ侵害に迅速に対応し、ネットワークを保護し、潜在的な損害を軽減しました。悪意のあるユーザーは公開されたユーザー ID トークンを悪用して SQL インジェクション攻撃を実行し、グラフィックス プロセッシング ユニット (GPU) ネットワーク内のデバイス メタデータを不正に変更しました。

Upon detection at 1:05 am Pacific Standard Time on April 25, Husky.io, Io.net's chief security officer, initiated immediate remedial actions to safeguard the network. Robust permission layers prevented the attack from compromising the GPUs' actual hardware, ensuring their continued security.

太平洋標準時の 4 月 25 日午前 1 時 5 分にこれを発見すると、Io.net の最高セキュリティ責任者である Husky.io は、ネットワークを保護するために直ちに是正措置を開始しました。堅牢な権限レイヤーにより、GPU の実際のハードウェアが攻撃によって侵害されるのを防ぎ、継続的なセキュリティを確保します。

Swift Response and Security Upgrades

迅速な対応とセキュリティのアップグレード

Io.net's swift response included implementing SQL injection checks on APIs, enhancing logging for unauthorized attempts, and deploying a user-specific authentication solution using Auth0 with OKTA. These measures effectively addressed vulnerabilities related to universal authorization tokens.

Io.net の迅速な対応には、API への SQL インジェクション チェックの実装、不正な試行のログ記録の強化、OKTA で Auth0 を使用したユーザー固有の認証ソリューションの展開などが含まれます。これらの対策により、ユニバーサル認証トークンに関連する脆弱性に効果的に対処できました。

Challenges and Mitigations

課題と緩和策

Coincidentally, the security update overlapped with a snapshot of the rewards program, leading to a temporary decrease in supply-side participants. Legitimate GPUs that did not restart and update encountered difficulties accessing the uptime API, resulting in a drop in active GPU connections from 600,000 to 10,000.

偶然にも、セキュリティ アップデートが特典プログラムのスナップショットと重なったため、供給側の参加者が一時的に減少しました。再起動も更新も行わなかった正規の GPU では、アップタイム API へのアクセスが困難になり、アクティブな GPU 接続が 600,000 から 10,000 に減少しました。

To address these challenges, Io.net initiated Ignition Rewards Season 2 in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.

これらの課題に対処するために、Io.net は 5 月に Ignition Rewards シーズン 2 を開始し、サプライサイドの参加を促進しました。継続的な取り組みには、サプライヤーと協力してデバイスをアップグレード、再起動、ネットワークに再接続することが含まれます。

Root Cause Analysis and Continuous Improvement

根本原因の分析と継続的改善

The breach originated from vulnerabilities introduced during the implementation of a proof-of-work mechanism designed to identify counterfeit GPUs. Aggressive security patches prior to the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.

この侵害は、偽造 GPU を識別するために設計されたプルーフ・オブ・ワーク・メカニズムの実装中に導入された脆弱性に起因しました。インシデント前の積極的なセキュリティ パッチによって攻撃手法がエスカレートし、継続的なセキュリティのレビューと改善が必要になりました。

Attacker Methodology

攻撃者の手法

Attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. They compiled this leaked information into a database weeks before the breach.

攻撃者は API の脆弱性を悪用して入出力エクスプローラーにコンテンツを表示し、デバイス ID による検索時に誤ってユーザー ID を明らかにしてしまいました。彼らは、この漏洩情報を侵害の数週間前にデータベースにまとめました。

Using a valid universal authentication token, attackers accessed the "worker-API," enabling them to modify device metadata without requiring user-level authentication.

攻撃者は有効なユニバーサル認証トークンを使用して「ワーカー API」にアクセスし、ユーザーレベルの認証を必要とせずにデバイスのメタデータを変更できるようにしました。

Ongoing Security Enhancements

継続的なセキュリティ強化

Husky.io emphasizes ongoing thorough reviews and penetration tests on public endpoints to proactively detect and neutralize threats. Despite the challenges encountered, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform's integrity while serving tens of thousands of compute hours per month.

Husky.io は、脅威を積極的に検出して無力化するために、パブリック エンドポイントに対する継続的な徹底的なレビューと侵入テストを重視しています。直面する課題にもかかわらず、サプライサイドの参加を奨励し、ネットワーク接続を回復し、月あたり数万時間のコンピューティング時間を提供しながらプラットフォームの整合性を確保する取り組みが進行中です。

Future Plans

今後の計画

Io.net plans to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services, underscoring its commitment to providing a secure and performant platform for its users.

Io.net は、人工知能と機械学習サービスを強化するために 3 月に Apple シリコン チップ ハードウェアを統合する予定であり、ユーザーに安全でパフォーマンスの高いプラットフォームを提供するという同社の取り組みを強調しています。

オリジナルソース:io

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年08月04日 に掲載されたその他の記事