시가총액: $2.1491T -1.20%
거래량(24시간): $41.4396B 6.74%
  • 시가총액: $2.1491T -1.20%
  • 거래량(24시간): $41.4396B 6.74%
  • 공포와 탐욕 지수:
  • 시가총액: $2.1491T -1.20%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

io.net은 네트워크 보안 침해를 진압하고 네트워크 무결성을 유지하기 위해 단호한 조치를 취합니다.

2024/04/28 19:03

악의적인 공격자가 취약점을 악용하여 그래픽 처리 장치(GPU) 네트워크 장치 메타데이터를 변경한 후 보안 침해로 인해 물리적 인프라 네트워크인 Io.net이 더 엄격한 조치를 취해야 했습니다. 지난 4월 25일 탐지된 이 공격은 SQL 인젝션과 사용자 ID 토큰 노출을 활용했지만 실제 GPU 하드웨어에는 영향을 미치지 않았습니다. Io.net은 강화된 인증, SQL 주입 검사 및 로깅 증가를 구현하여 이에 대응했습니다.

io.net은 네트워크 보안 침해를 진압하고 네트워크 무결성을 유지하기 위해 단호한 조치를 취합니다.

Cybersecurity Breach: Io.net Decisive Action Maintains Network Integrity

사이버 보안 위반: Io.net의 결정적인 조치로 네트워크 무결성 유지

[Date] - Io.net, the decentralized physical infrastructure network (DePIN) provider, swiftly responded to a cybersecurity breach, protecting its network and mitigating potential damage. Malicious users exploited exposed user ID tokens to execute a SQL injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

[날짜] - 분산형 물리적 인프라 네트워크(DePIN) 제공업체인 Io.net은 사이버 보안 침해에 신속하게 대응하여 네트워크를 보호하고 잠재적 피해를 완화했습니다. 악의적인 사용자는 노출된 사용자 ID 토큰을 악용하여 SQL 주입 공격을 실행했고, 이로 인해 GPU(그래픽 처리 장치) 네트워크 내 장치 메타데이터가 무단으로 변경되었습니다.

Upon detection at 1:05 am Pacific Standard Time on April 25, Husky.io, Io.net's chief security officer, initiated immediate remedial actions to safeguard the network. Robust permission layers prevented the attack from compromising the GPUs' actual hardware, ensuring their continued security.

4월 25일 오전 1시 5분(태평양 표준시)에 탐지되자 Io.net의 최고 보안 책임자인 Husky.io는 네트워크를 보호하기 위한 즉각적인 교정 조치를 시작했습니다. 강력한 권한 계층은 공격이 GPU의 실제 하드웨어를 손상시키는 것을 방지하여 지속적인 보안을 보장합니다.

Swift Response and Security Upgrades

신속한 대응 및 보안 업그레이드

Io.net's swift response included implementing SQL injection checks on APIs, enhancing logging for unauthorized attempts, and deploying a user-specific authentication solution using Auth0 with OKTA. These measures effectively addressed vulnerabilities related to universal authorization tokens.

Io.net의 신속한 대응에는 API에 대한 SQL 삽입 검사 구현, 무단 시도에 대한 로깅 강화, OKTA와 함께 Auth0을 사용하는 사용자별 인증 솔루션 배포가 포함되었습니다. 이러한 조치는 범용 인증 토큰과 관련된 취약점을 효과적으로 해결했습니다.

Challenges and Mitigations

과제 및 완화

Coincidentally, the security update overlapped with a snapshot of the rewards program, leading to a temporary decrease in supply-side participants. Legitimate GPUs that did not restart and update encountered difficulties accessing the uptime API, resulting in a drop in active GPU connections from 600,000 to 10,000.

공교롭게도 보안 업데이트가 보상 프로그램의 스냅샷과 겹쳐서 공급측 참여자가 일시적으로 감소했습니다. 다시 시작하고 업데이트하지 않은 합법적인 GPU는 가동 시간 API에 액세스하는 데 어려움을 겪어 활성 GPU 연결이 600,000에서 10,000으로 감소했습니다.

To address these challenges, Io.net initiated Ignition Rewards Season 2 in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.

이러한 문제를 해결하기 위해 Io.net은 공급측 참여를 장려하기 위해 5월에 Ignition Rewards 시즌 2를 시작했습니다. 지속적인 노력에는 공급업체와 협력하여 장치를 네트워크에 업그레이드, 재시작 및 다시 연결하는 작업이 포함됩니다.

Root Cause Analysis and Continuous Improvement

근본 원인 분석 및 지속적인 개선

The breach originated from vulnerabilities introduced during the implementation of a proof-of-work mechanism designed to identify counterfeit GPUs. Aggressive security patches prior to the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.

이번 위반은 위조 GPU를 식별하도록 설계된 작업 증명 메커니즘을 구현하는 동안 발생한 취약점으로 인해 발생했습니다. 사고 이전의 공격적인 보안 패치로 인해 공격 방법이 확대되어 지속적인 보안 검토 및 개선이 필요했습니다.

Attacker Methodology

공격자 방법론

Attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. They compiled this leaked information into a database weeks before the breach.

공격자는 API의 취약점을 악용하여 입력/출력 탐색기에 콘텐츠를 표시했으며, 장치 ID로 검색할 때 실수로 사용자 ID를 노출했습니다. 그들은 유출된 정보를 침해가 발생하기 몇 주 전에 데이터베이스에 정리했습니다.

Using a valid universal authentication token, attackers accessed the "worker-API," enabling them to modify device metadata without requiring user-level authentication.

공격자는 유효한 범용 인증 토큰을 사용하여 "작업자 API"에 액세스하여 사용자 수준 인증 없이 장치 메타데이터를 수정할 수 있었습니다.

Ongoing Security Enhancements

지속적인 보안 강화

Husky.io emphasizes ongoing thorough reviews and penetration tests on public endpoints to proactively detect and neutralize threats. Despite the challenges encountered, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform's integrity while serving tens of thousands of compute hours per month.

Husky.io는 위협을 사전에 감지하고 무력화하기 위해 공개 엔드포인트에 대한 지속적인 철저한 검토 및 침투 테스트를 강조합니다. 직면한 어려움에도 불구하고 공급측 참여를 장려하고 네트워크 연결을 복원하여 매월 수만 시간의 컴퓨팅 시간을 제공하면서 플랫폼의 무결성을 보장하려는 노력이 진행 중입니다.

Future Plans

향후 계획

Io.net plans to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services, underscoring its commitment to providing a secure and performant platform for its users.

Io.net은 인공 지능 및 기계 학습 서비스를 강화하기 위해 3월에 Apple 실리콘 칩 하드웨어를 통합할 계획이며, 사용자에게 안전하고 성능이 뛰어난 플랫폼을 제공하겠다는 약속을 강조합니다.

원본 소스:io

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年08月03日 에 게재된 다른 기사