[](https://www.paloaltonetworks.com/?ts=markdown) * CN * [USA (ENGLISH)](https://www.paloaltonetworks.com/) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca) * CHINA (简体中文) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it) * [JAPAN (日本語)](https://www.paloaltonetworks.jp) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk) * ![magnifying glass search icon to open search field](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * [联系我们](https://www.paloaltonetworks.cn/contact?ts=markdown) * [资源](https://www.paloaltonetworks.cn/resources?ts=markdown) * [获得支持](https://support.paloaltonetworks.com/support) * [遭遇攻击?](https://start.paloaltonetworks.com/contact-unit42.html) ![x close icon to close mobile navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/x-black.svg) [![Palo Alto Networks logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)](https://www.paloaltonetworks.com/?ts=markdown) ![magnifying glass search icon to open search field](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * [](https://www.paloaltonetworks.com/?ts=markdown) * 产品 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 产品 [人工智能驱动的网络安全平台](https://www.paloaltonetworks.cn/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.cn/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.cn/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.cn/sase/ai-access-security?ts=markdown) * [云交付的安全服务](https://www.paloaltonetworks.cn/network-security/security-subscriptions?ts=markdown) * [高级威胁预防](https://www.paloaltonetworks.cn/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.cn/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.cn/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.cn/network-security/advanced-dns-security?ts=markdown) * [企业数据丢失防护](https://www.paloaltonetworks.cn/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.cn/network-security/enterprise-device-security?ts=markdown) * [医疗物联网安全](https://www.paloaltonetworks.cn/network-security/medical-iot-security?ts=markdown) * [工业 OT 安全](https://www.paloaltonetworks.cn/network-security/industrial-ot-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.cn/sase/saas-security?ts=markdown) * [新一代防火墙](https://www.paloaltonetworks.cn/network-security/next-generation-firewall?ts=markdown) * [硬件防火墙](https://www.paloaltonetworks.cn/network-security/hardware-firewall-innovations?ts=markdown) * [软件防火墙](https://www.paloaltonetworks.cn/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.cn/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.cn/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.cn/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.cn/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.cn/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.cn/sase?ts=markdown) * [应用加速](https://www.paloaltonetworks.cn/sase/app-acceleration?ts=markdown) * [自主数字体验管理](https://www.paloaltonetworks.cn/sase/adem?ts=markdown) * [企业 DLP](https://www.paloaltonetworks.cn/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.cn/sase/access?ts=markdown) * [Prisma 浏览器](https://www.paloaltonetworks.cn/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.cn/sase/sd-wan?ts=markdown) * [远程浏览器隔离](https://www.paloaltonetworks.cn/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.cn/sase/saas-security?ts=markdown) [基于 AI 的安全运营平台](https://www.paloaltonetworks.cn/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.cn/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.cn/cortex/cloud?ts=markdown) * [应用安全](https://www.paloaltonetworks.cn/cortex/cloud/application-security?ts=markdown) * [云态势安全](https://www.paloaltonetworks.cn/cortex/cloud/cloud-posture-security?ts=markdown) * [云运行时安全](https://www.paloaltonetworks.cn/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.cn/prisma/cloud?ts=markdown) * [Unit 42 托管检测和响应](https://www.paloaltonetworks.cn/cortex/managed-detection-and-response?ts=markdown) * [人工智能驱动的 SOC](https://www.paloaltonetworks.cn/cortex?ts=markdown) * [Cortex Advanced Email Security](https://www.paloaltonetworks.cn/cortex/advanced-email-security?ts=markdown) * [Cortex Exposure Management](https://www.paloaltonetworks.cn/cortex/exposure-management?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.cn/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.cn/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.cn/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.cn/cortex/cortex-xpanse?ts=markdown) * [托管 XSIAM](https://www.paloaltonetworks.cn/cortex/managed-xsiam?ts=markdown) * 解决方案 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 解决方案 AI 安全 * [安全的人工智能生态系统](https://www.paloaltonetworks.cn/prisma/prisma-ai-runtime-security?ts=markdown) * [安全使用 GenAI](https://www.paloaltonetworks.cn/sase/ai-access-security?ts=markdown) 网络安全 * [云网络安全](https://www.paloaltonetworks.cn/network-security/software-firewalls?ts=markdown) * [数据中心安全](https://www.paloaltonetworks.cn/network-security/data-center?ts=markdown) * [DNS Security](https://www.paloaltonetworks.cn/network-security/advanced-dns-security?ts=markdown) * [入侵检测和防御](https://www.paloaltonetworks.cn/network-security/advanced-threat-prevention?ts=markdown) * [IoT Security](https://www.paloaltonetworks.cn/network-security/enterprise-device-security?ts=markdown) * [5G 安全](https://www.paloaltonetworks.cn/network-security/5g-security?ts=markdown) * [确保所有应用、用户和位置的安全](https://www.paloaltonetworks.cn/sase/secure-users-data-apps-devices?ts=markdown) * [确保分支机构转型的安全](https://www.paloaltonetworks.cn/sase/secure-branch-transformation?ts=markdown) * [确保任何设备上的工作安全](https://www.paloaltonetworks.cn/sase/secure-work-on-any-device?ts=markdown) * [VPN 替代](https://www.paloaltonetworks.cn/sase/vpn-replacement-for-secure-remote-access?ts=markdown) * [Web 和网络钓鱼安全](https://www.paloaltonetworks.cn/network-security/advanced-url-filtering?ts=markdown) 云安全 * [应用安全态势管理 (ASPM)](https://www.paloaltonetworks.cn/cortex/cloud/application-security-posture-management?ts=markdown) * [软件供应链安全](https://www.paloaltonetworks.cn/cortex/cloud/software-supply-chain-security?ts=markdown) * [代码安全](https://www.paloaltonetworks.cn/cortex/cloud/code-security?ts=markdown) * [云安全态势管理 (CSPM)](https://www.paloaltonetworks.cn/cortex/cloud/cloud-security-posture-management?ts=markdown) * [云基础架构权限管理 (CIEM)](https://www.paloaltonetworks.cn/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [数据安全态势管理 (DSPM)](https://www.paloaltonetworks.cn/cortex/cloud/data-security-posture-management?ts=markdown) * [AI 安全态势管理 (AI-SPM)](https://www.paloaltonetworks.cn/cortex/cloud/ai-security-posture-management?ts=markdown) * [云检测与响应 (CDR)](https://www.paloaltonetworks.cn/cortex/cloud-detection-and-response?ts=markdown) * [云工作负载保护 (CWP)](https://www.paloaltonetworks.cn/cortex/cloud/cloud-workload-protection?ts=markdown) * [Web 应用及 API 安全 (WAAS)](https://www.paloaltonetworks.cn/cortex/cloud/web-app-api-security?ts=markdown) 安全运营 * [云检测和响应](https://www.paloaltonetworks.cn/cortex/cloud-detection-and-response?ts=markdown) * [网络安全自动化](https://www.paloaltonetworks.cn/cortex/network-security-automation?ts=markdown) * [事件案例管理](https://www.paloaltonetworks.cn/cortex/incident-case-management?ts=markdown) * [SOC 自动化](https://www.paloaltonetworks.cn/cortex/security-operations-automation?ts=markdown) * [威胁情报管理](https://www.paloaltonetworks.cn/cortex/threat-intel-management?ts=markdown) * [托管的检测和响应](https://www.paloaltonetworks.cn/cortex/managed-detection-and-response?ts=markdown) * [攻击面管理](https://www.paloaltonetworks.cn/cortex/cortex-xpanse/attack-surface-management?ts=markdown) * [合规性管理](https://www.paloaltonetworks.cn/cortex/cortex-xpanse/compliance-management?ts=markdown) * [互联网运营管理](https://www.paloaltonetworks.cn/cortex/cortex-xpanse/internet-operations-management?ts=markdown) 端点安全 * [端点防护](https://www.paloaltonetworks.cn/cortex/endpoint-protection?ts=markdown) * [扩展的检测和响应](https://www.paloaltonetworks.cn/cortex/detection-and-response?ts=markdown) * [勒索软件防护](https://www.paloaltonetworks.cn/cortex/ransomware-protection?ts=markdown) * [数字取证](https://www.paloaltonetworks.cn/cortex/digital-forensics?ts=markdown) [行业](https://www.paloaltonetworks.cn/industry?ts=markdown) * [公共部门](https://www.paloaltonetworks.com/industry/public-sector) * [金融服务](https://www.paloaltonetworks.com/industry/financial-services) * [制造](https://www.paloaltonetworks.com/industry/manufacturing) * [医疗保健](https://www.paloaltonetworks.com/industry/healthcare) * [中小型企业解决方案](https://www.paloaltonetworks.com/industry/small-medium-business-portfolio) * 服务 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 服务 [威胁情报和事件响应服务](https://www.paloaltonetworks.cn/unit42?ts=markdown) * [评估](https://www.paloaltonetworks.cn/unit42/assess?ts=markdown) * [AI 安全评估](https://www.paloaltonetworks.cn/unit42/assess/ai-security-assessment?ts=markdown) * [攻击面评估](https://www.paloaltonetworks.cn/unit42/assess/attack-surface-assessment?ts=markdown) * [防泄露准备工作审核](https://www.paloaltonetworks.cn/unit42/assess/breach-readiness-review?ts=markdown) * [BEC 准备情况评估](https://www.paloaltonetworks.com/bec-readiness-assessment) * [云安全评估](https://www.paloaltonetworks.com/unit42/assess/cloud-security-assessment) * [入侵评估](https://www.paloaltonetworks.cn/unit42/assess/compromise-assessment?ts=markdown) * [网络风险评估](https://www.paloaltonetworks.cn/unit42/assess/cyber-risk-assessment?ts=markdown) * [并购网络尽职调查](https://www.paloaltonetworks.cn/unit42/assess/mergers-acquisitions-cyber-due-dilligence?ts=markdown) * [渗透测试](https://www.paloaltonetworks.cn/unit42/assess/penetration-testing?ts=markdown) * [紫队演习](https://www.paloaltonetworks.cn/unit42/assess/purple-teaming?ts=markdown) * [勒索软件就绪评估](https://www.paloaltonetworks.cn/unit42/assess/ransomware-readiness-assessment?ts=markdown) * [SOC 评估](https://www.paloaltonetworks.com/unit42/assess/soc-assessment) * [供应链风险评估](https://www.paloaltonetworks.cn/unit42/assess/supply-chain-risk-assessment?ts=markdown) * [桌面演习](https://www.paloaltonetworks.cn/unit42/assess/tabletop-exercise?ts=markdown) * [Unit 42 顾问人员](https://www.paloaltonetworks.cn/unit42/retainer?ts=markdown) * [响应](https://www.paloaltonetworks.cn/unit42/respond?ts=markdown) * [云事故响应](https://www.paloaltonetworks.cn/unit42/respond/cloud-incident-response?ts=markdown) * [数字取证](https://www.paloaltonetworks.cn/unit42/respond/digital-forensics?ts=markdown) * [事件响应](https://www.paloaltonetworks.cn/unit42/respond/incident-response?ts=markdown) * [托管检测与响应](https://www.paloaltonetworks.cn/unit42/respond/managed-detection-response?ts=markdown) * [托管威胁追踪](https://www.paloaltonetworks.cn/unit42/respond/managed-threat-hunting?ts=markdown) * [托管 XSIAM](https://www.paloaltonetworks.cn/cortex/managed-xsiam?ts=markdown) * [Unit 42 顾问人员](https://www.paloaltonetworks.cn/unit42/retainer?ts=markdown) * [转型](https://www.paloaltonetworks.cn/unit42/transform?ts=markdown) * [事故响应计划制定与审核](https://www.paloaltonetworks.cn/unit42/transform/incident-response-plan-development-review?ts=markdown) * [安全计划设计](https://www.paloaltonetworks.cn/unit42/transform/security-program-design?ts=markdown) * [虚拟 CISO](https://www.paloaltonetworks.cn/unit42/transform/vciso?ts=markdown) * [零信任咨询](https://www.paloaltonetworks.com/unit42/transform/zero-trust-advisory) [全球客户服务](https://www.paloaltonetworks.cn/services?ts=markdown) * [教育与培训](https://www.paloaltonetworks.com/services/education) * [专业服务](https://www.paloaltonetworks.com/services/consulting) * [成功工具](https://www.paloaltonetworks.com/services/customer-success-tools) * [支持服务](https://www.paloaltonetworks.com/services/solution-assurance) * [客户成功](https://www.paloaltonetworks.com/services/customer-success) [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-unit-42.svg) Unit 42 顾问人员 为满足企业的需求而定制,您可以选择将顾问人员工时数分配给我们的任意产品,包括主动网络风险管理服务。了解如何一键呼叫世界一流的 Unit 42 事故响应团队。 了解更多](https://www.paloaltonetworks.cn/unit42/retainer?ts=markdown) * 合作伙伴 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 合作伙伴 NextWave 合作伙伴 * [NextWave 合作伙伴社区](https://www.paloaltonetworks.com/partners) * [云服务提供商](https://www.paloaltonetworks.com/partners/nextwave-for-csp) * [全球系统集成商](https://www.paloaltonetworks.com/partners/nextwave-for-gsi) * [技术合作伙伴](https://www.paloaltonetworks.com/partners/technology-partners) * [服务提供商](https://www.paloaltonetworks.com/partners/service-providers) * [解决方案提供商](https://www.paloaltonetworks.com/partners/nextwave-solution-providers) * [托管安全服务提供商](https://www.paloaltonetworks.com/partners/managed-security-service-providers) 采取行动 * [门户网站登录](https://www.paloaltonetworks.com/partners/nextwave-partner-portal) * [管理的服务计划](https://www.paloaltonetworks.com/partners/managed-security-services-provider-program) * [成为合作伙伴](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=becomepartner) * [请求访问](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=requestaccess) * [查找合作伙伴](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerlocator) [CYBERFORCE CYBERFORCE 代表了因其安全专业知识而值得信赖的前 1% 的合作伙伴工程师。 了解更多](https://www.paloaltonetworks.com/cyberforce) * 公司 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 公司 Palo Alto Networks * [关于我们](https://www.paloaltonetworks.cn/about-us?ts=markdown) * [管理团队](https://www.paloaltonetworks.com/about-us/management) * [投资者关系](https://investors.paloaltonetworks.com/) * [地点](https://www.paloaltonetworks.com/about-us/locations) * [道德与合规性](https://www.paloaltonetworks.com/company/ethics-and-compliance) * [企业责任](https://www.paloaltonetworks.com/about-us/corporate-responsibility) * [军人和退伍军人](https://jobs.paloaltonetworks.com/military) [为什么选择 Palo Alto Networks?](https://www.paloaltonetworks.cn/why-paloaltonetworks?ts=markdown) * [Precision AI 安全](https://www.paloaltonetworks.cn/precision-ai-security?ts=markdown) * [我们的平台方法](https://www.paloaltonetworks.cn/why-paloaltonetworks/platformization?ts=markdown) * [加速网络安全转型](https://www.paloaltonetworks.com/why-paloaltonetworks/nam-cxo-portfolio) * [获得的奖项与表彰](https://www.paloaltonetworks.com/about-us/awards) * [客户案例](https://www.paloaltonetworks.cn/customers?ts=markdown) * [全球认证](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance) * [全方位信任计划](https://www.paloaltonetworks.com/resources/whitepapers/trust-360) 职业生涯 * [概述](https://jobs.paloaltonetworks.com/) * [文化与福利](https://jobs.paloaltonetworks.com/culture) [《新闻周刊》评选出的最受欢迎的工作场所 善待员工的企业 阅读更多](https://www.paloaltonetworks.com/company/press/2021/palo-alto-networks-secures-top-ranking-on-newsweek-s-most-loved-workplaces-list-for-2021) * 更多内容 ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) 更多内容 资源 * [博客](https://www.paloaltonetworks.com/blog/?lang=zh-hans) * [Unit 42 威胁研究博客](https://unit42.paloaltonetworks.com/) * [社区](https://www.paloaltonetworks.com/communities) * [内容库](https://www.paloaltonetworks.cn/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.cn/cyberpedia?ts=markdown) * [技术内幕](https://techinsider.paloaltonetworks.com/) * [知识库](https://knowledgebase.paloaltonetworks.com/) * [Palo Alto Networks 频道](https://tv.paloaltonetworks.com/) * [领导者的视角](https://www.paloaltonetworks.com/perspectives/) * [《网络视角》杂志](https://www.paloaltonetworks.com/cybersecurity-perspectives/cyber-perspectives-magazine) * [区域云位置](https://www.paloaltonetworks.cn/products/regional-cloud-locations?ts=markdown) * [技术文档](https://docs.paloaltonetworks.com/) * [安全态势评估](https://www.paloaltonetworks.cn/security-posture-assessment?ts=markdown) * [威胁载体播客](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/) 联系 * [在线社区](https://live.paloaltonetworks.com/) * [活动资讯](https://events.paloaltonetworks.com/) * [高管简报中心](https://www.paloaltonetworks.com/about-us/executive-briefing-program) * [演示](https://www.paloaltonetworks.cn/demos?ts=markdown) * [联系我们](https://www.paloaltonetworks.cn/company/contact-sales?ts=markdown) [博客 了解行业趋势和全球最大网络安全公司的最新创新 了解更多](https://www.paloaltonetworks.com/blog/?lang=zh-hans) * CN ![black arrow pointing left to go back to main navigation](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/arrow-right-black.svg) Language * [USA (ENGLISH)](https://www.paloaltonetworks.com/) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca) * CHINA (简体中文) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it) * [JAPAN (日本語)](https://www.paloaltonetworks.jp) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk) * [联系我们](https://www.paloaltonetworks.cn/contact?ts=markdown) * [资源](https://www.paloaltonetworks.cn/resources?ts=markdown) * [获得支持](https://support.paloaltonetworks.com/support) * [遭遇攻击?](https://start.paloaltonetworks.com/contact-unit42.html) * [立即开始](https://www.paloaltonetworks.cn/get-started?ts=markdown) 搜索 Close search modal [](https://www.paloaltonetworks.com/?ts=markdown) 1. [Cyberpedia](https://www.paloaltonetworks.cn/cyberpedia?ts=markdown) 2. [Threats](https://www.paloaltonetworks.com/cyberpedia/threat?ts=markdown) 3. [恶意软件 | 什么是恶意软件以及如何抵御恶意软件攻击](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware?ts=markdown) 目录 * 恶意软件 | 什么是恶意软件以及如何抵御恶意软件攻击 * [什么是恶意软件?](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#what?ts=markdown) * [恶意软件攻击的类型](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#types?ts=markdown) * [如何防止恶意软件:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#how?ts=markdown) * [恶意软件检测:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#malware?ts=markdown) * [恶意软件去除:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#removal?ts=markdown) * [恶意软件防护](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#protection?ts=markdown): * [SunOrcal 新型恶意软件变种的目标不断扩大](https://www.paloaltonetworks.com/cyberpedia/expanding-targets-for-new-sunorcal-malware-variant?ts=markdown) * [如何使用](https://www.paloaltonetworks.cn/cyberpedia/expanding-targets-for-new-sunorcal-malware-variant#howto?ts=markdown) * [如何防范](https://www.paloaltonetworks.cn/cyberpedia/expanding-targets-for-new-sunorcal-malware-variant#prevent?ts=markdown) * [一般电子邮件最佳实践:](https://www.paloaltonetworks.cn/cyberpedia/expanding-targets-for-new-sunorcal-malware-variant#email?ts=markdown) # 恶意软件 | 什么是恶意软件以及如何抵御恶意软件攻击 目录 * * [什么是恶意软件?](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#what?ts=markdown) * [恶意软件攻击的类型](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#types?ts=markdown) * [如何防止恶意软件:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#how?ts=markdown) * [恶意软件检测:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#malware?ts=markdown) * [恶意软件去除:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#removal?ts=markdown) * [恶意软件防护](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#protection?ts=markdown): 1. 什么是恶意软件? * * [什么是恶意软件?](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#what?ts=markdown) * [恶意软件攻击的类型](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#types?ts=markdown) * [如何防止恶意软件:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#how?ts=markdown) * [恶意软件检测:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#malware?ts=markdown) * [恶意软件去除:](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#removal?ts=markdown) * [恶意软件防护](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware#protection?ts=markdown): ## 什么是恶意软件? 作为旨在干扰计算机正常运行的软件,恶意软件是病毒、特洛伊木马和其他破坏性计算机程序的总称,威胁行为者利用这种软件来感染系统和网络以获取敏感信息。 #### 恶意软件定义 恶意软件(即 Malware,"malicious software"的简称)是一种文件或代码,通常通过网络投放,可以感染、探测、窃取或实施攻击者想要的任何行为。而且由于恶意软件呈现出多种变体,感染计算机系统的方法也层出不穷。尽管恶意软件的类型和功能各不相同,但通常带着以下目标之一: * 为攻击者提供远程控制以使用受感染的计算机。 * 从受感染的计算机向毫无戒心的目标发送垃圾邮件。 * 调查受感染用户的本地网络。 * 窃取敏感数据。 ![恶意软件是一种恶意文件或一段代码,通常通过网络投放,可以感染、探测、窃取或实施攻击者想要的任何行为。](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/what-is-malware.png "恶意软件是一种恶意文件或一段代码,通常通过网络投放,可以感染、探测、窃取或实施攻击者想要的任何行为。") #### 恶意软件类型: 恶意软件是所有类型恶意的软件的总称。恶意软件示例、恶意软件攻击定义和传播恶意软件的方法包括: 广告软件 -- 虽然某些形式的广告软件可能被认为是合法的,但其他形式的广告软件会在未经授权的情况下访问计算机系统,对用户造成极大的干扰。 [僵尸网络](https://www.paloaltonetworks.com/cyberpedia/what-is-botnet)-- Botnet 是"机器人网络 robot network"的简称,指受感染计算机的网络,由使用命令和控制服务器的单个攻击方控制。僵尸网络具有高度通用性和适应性,能够通过冗余服务器和使用受感染的计算机中继流量来保持弹性。僵尸网络往往是当今 [分布式拒绝服务 (DDoS) 攻击](https://www.paloaltonetworks.com/cyberpedia/what-is-a-ddos-attack)背后的部队。 加密劫持 -- 是一种恶意加密挖矿(使用计算能力验证区块链网络上的交易并通过提供这种服务赚取加密货币的过程),当网络犯罪分子侵入企业和个人计算机、笔记本电脑和移动设备安装软件时就会发生。 恶意广告 -- 恶意广告是"恶意软件 + 广告"的合成词,描述了通过在线广告传播恶意软件的做法。它通常涉及将恶意代码或载有恶意软件的广告注入合法的在线广告网络和网页。 多态恶意软件 -- 上述任何类型的恶意软件,能够定期"变形",改变代码的外观,同时保留内部的算法。软件表面外观的改变破坏了以传统病毒签名为基础的检测。 [![获取 XDR for Dummies 指南](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/XDR-for-dummies-guide-banner-55.png)](https://start.paloaltonetworks.cn/xdr-for-dummies.html) [勒索软件](https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware) -- 是一种犯罪商业模式,使用 [恶意软件](https://www.paloaltonetworks.cn/cyberpedia/what-is-malware?ts=markdown)扣留有价值的文件、数据或信息以索取赎金。勒索软件攻击可能会使受害者的经营严重恶化甚至停业。 远程管理工具 (RAT) -- 允许远程操作员控制系统的软件。这些工具最初是为合法用途而构建的,但现在被威胁行为者使用。RAT 支持管理控制,允许攻击者在受感染的计算机上为所欲为。它们很难被检测到,因为通常不会出现在正在运行的程序或任务列表中,并且操作经常被误认为是合法程序的操作。 Rootkits -- 提供对计算机的特权(root 级别)访问的程序。Rootkits 各有不同,隐藏在操作系统中。 [间谍软件](https://www.paloaltonetworks.com/cyberpedia/what-is-spyware) -- 收集有关受感染计算机的使用信息并将其传回给攻击者的恶意软件。术语包括僵尸网络、广告软件、后门行为、键盘记录程序、数据盗窃和网络蠕虫。 特洛伊木马恶意软件 -- 伪装成合法软件的恶意软件。一旦被激活,特洛伊木马恶意软件就会执行其编程设定的任何操作。与病毒和蠕虫不同,特洛伊木马不会通过感染进行复制或繁殖。"特洛伊木马"暗指一个神话故事:希腊士兵被藏在一匹木马里送给敌方特洛伊城。 病毒恶意软件 -- 通过计算机或网络进行自我复制的程序。恶意软件病毒搭载在现有程序上,并且只能在用户打开程序时被激活。在最坏的情况下,病毒可能会损坏或删除数据、使用用户的电子邮件进行传播或擦除硬盘上的一切。 蠕虫恶意软件 -- 利用安全漏洞自动在计算机和网络中自行传播的自我复制病毒。与许多病毒不同,恶意软件蠕虫不会附加到现有程序或更改文件。它们通常不会被注意到,直到复制达到消耗大量系统资源或网络带宽的规模。 ## 恶意软件攻击的类型 恶意软件还使用各种方法将自身传播到初始攻击媒介之外的其他计算机系统。恶意软件攻击定义可以包括: * 包含恶意代码的电子邮件附件可以被毫无戒心的用户打开并随后执行。如果这些电子邮件被转发,恶意软件可能会更深入地传播到企业中,从而进一步损害网络。 * 文件服务器,例如基于常见 Internet 文件系统 (SMB/CIFS) 和网络文件系统 (NFS) 的文件服务器,可以使恶意软件在用户访问和下载受感染文件时快速传播。 * 文件共享软件可以允许恶意软件将自身复制到可移动介质上,然后复制到计算机系统和网络。 * 点对点 (P2P) 文件共享可能会通过共享看似无害的文件(例如音乐或图片)来引入恶意软件。 * 可远程利用的漏洞使黑客能够访问系统,无论其地理位置如何,而几乎不需要或不需要计算机用户的参与。 了解如何使用 Palo Alto Networks 新一代 [威胁防御](https://www.paloaltonetworks.cn/resources/datasheets/threat-prevention-datasheet?ts=markdown) 功能和 [WildFire® 基于云的威胁分析](https://www.paloaltonetworks.cn/resources/datasheets/wildfire?ts=markdown) 服务来保护您的网络免受已知和未知的各类恶意软件的攻击。 ## 如何防止恶意软件: 使用各种安全解决方案来检测和 [防止恶意软件](https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/threat-prevention)。其中包括防火墙、新一代防火墙、网络入侵防御系统 (IPS)、深度数据包检测 (DPI) 功能、统一威胁管理系统、防病毒和反垃圾邮件网关、虚拟专用网络、内容过滤和数据泄露防御系统。为了防止恶意软件,所有安全解决方案都应使用各种基于恶意软件的攻击进行测试,以确保它们正常工作。必须使用强大的、最新的恶意软件签名库来确保针对最新攻击完成测试 Cortex XDR 代理在攻击生命周期的关键阶段将 [多种预防方法](https://www.paloaltonetworks.com/resources/whitepapers/cortex-xdr-endpoint-protection-overview)结合在一起,叫停恶意程序的执行并停止合法应用程序的利用,而不考虑操作系统、终端的在线或离线状态,以及终端是连接到企业网络还是正在漫游。由于 Cortex XDR 代理不依赖于签名,因此它可以通过组合预防方法来防止零日恶意软件和未知漏洞利用。 ## 恶意软件检测: 存在先进的恶意软件分析和检测工具,例如防火墙、入侵防御系统 (IPS) 和沙箱解决方案。某些恶意软件类型更容易检测,例如 [勒索软件](https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware),它会在加密您的文件后立即暴露出来。其他恶意软件(例如间谍软件)可能会默默地保留在目标系统上,允许对手保持对系统的访问。无论恶意软件类型或恶意软件含义是什么,其可检测性如何或部署者是谁,恶意软件使用的意图始终是恶意的。 当您在端点安全策略中启用行为威胁防护时,Cortex XDR 代理还可以持续监视端点活动,以发现 Palo Alto Networks 识别的恶意事件链。 ## 恶意软件去除: 防病毒软件可以清除大多数标准感染类型,而且有许多现成的解决方案可供选择。Cortex XDR 可在警报或调查之后对端点进行补救,让管理员可以选择开始各种缓解步骤,首先是隔离端点,禁用受害端点上的所有网络访问(与 Cortex XDR 控制台的流量除外),终止进程以阻止任何运行中的恶意软件继续在端点上执行恶意活动,并拦截其他执行,然后隔离恶意文件并将其从工作目录中移除(如果 Cortex XDR 代理尚未这样做)。 ## [恶意软件防护](https://www.paloaltonetworks.com/cyberpedia/what-is-malware-protection): 为了保护您的企业免受恶意软件的侵害,您需要一个全面的企业级恶意软件防护战略。一般威胁是指不那么复杂的漏洞利用,结合了防病毒、防间谍软件和漏洞防护功能以及防火墙上的 URL 过滤和应用程序识别功能,更容易检测和预防。 有关恶意软件、其变体以及如何保护企业免受恶意软件侵害的更多信息,请下载我们的资源之一: * [什么是恶意软件防护?](https://www.paloaltonetworks.com/cyberpedia/what-is-malware-protection) * [什么是无文件恶意软件攻击以及"就地取材"](https://www.paloaltonetworks.com/cyberpedia/what-are-fileless-malware-attacks) * [勒索软件威胁报告](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report.html) * [什么是勒索软件?](https://www.paloaltonetworks.com/cyberpedia/what-is-ransomware) * [勒索软件:常见攻击方法](https://www.paloaltonetworks.com/cyberpedia/ransomware-common-attack-methods) * [恶意软件对比漏洞利用](https://www.paloaltonetworks.com/cyberpedia/malware-vs-exploits) * [什么是基于有效负载的签名?](https://www.paloaltonetworks.com/cyberpedia/what-is-a-payload-based-signature) * [用于检测和响应的 Cortex XDR](https://www.paloaltonetworks.com/cortex/detection-and-response-10-must-haves) * [Threat Prevention](https://www.paloaltonetworks.cn/network-security/advanced-threat-prevention?ts=markdown) * [WildFire 恶意软件分析引擎](https://www.paloaltonetworks.cn/network-security/wildfire?ts=markdown) ![Share page on facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/facebook-circular-icon.svg) ![Share page on linkedin](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/linkedin-circular-icon.svg) [![Share page by an email](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/email-circular-icon.svg)](mailto:?subject=%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%20%7C%20%E4%BB%80%E4%B9%88%E6%98%AF%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%E4%BB%A5%E5%8F%8A%E5%A6%82%E4%BD%95%E6%8A%B5%E5%BE%A1%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%E6%94%BB%E5%87%BB&body=%E4%BD%9C%E4%B8%BA%E6%97%A8%E5%9C%A8%E5%B9%B2%E6%89%B0%E8%AE%A1%E7%AE%97%E6%9C%BA%E6%AD%A3%E5%B8%B8%E8%BF%90%E8%A1%8C%E7%9A%84%E8%BD%AF%E4%BB%B6%EF%BC%8C%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%E6%98%AF%E7%97%85%E6%AF%92%E3%80%81%E7%89%B9%E6%B4%9B%E4%BC%8A%E6%9C%A8%E9%A9%AC%E5%92%8C%E5%85%B6%E4%BB%96%E7%A0%B4%E5%9D%8F%E6%80%A7%E8%AE%A1%E7%AE%97%E6%9C%BA%E7%A8%8B%E5%BA%8F%E7%9A%84%E6%80%BB%E7%A7%B0%EF%BC%8C%E5%A8%81%E8%83%81%E8%A1%8C%E4%B8%BA%E8%80%85%E5%88%A9%E7%94%A8%E8%BF%99%E7%A7%8D%E8%BD%AF%E4%BB%B6%E6%9D%A5%E6%84%9F%E6%9F%93%E7%B3%BB%E7%BB%9F%E5%92%8C%E7%BD%91%E7%BB%9C%E4%BB%A5%E8%8E%B7%E5%8F%96%E6%95%8F%E6%84%9F%E4%BF%A1%E6%81%AF%E3%80%82%20at%20https%3A//www.paloaltonetworks.com/cyberpedia/what-is-malware) 返回页首 [下一页](https://www.paloaltonetworks.cn/cyberpedia/expanding-targets-for-new-sunorcal-malware-variant?ts=markdown) SunOrcal 新型恶意软件变种的目标不断扩大 {#footer} ## 产品和服务 * [实时人工智能驱动的网络安全](https://www.paloaltonetworks.cn/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.cn/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.cn/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.cn/sase/ai-access-security?ts=markdown) * [云交付的安全服务](https://www.paloaltonetworks.cn/network-security/security-subscriptions?ts=markdown) * [高级威胁预防](https://www.paloaltonetworks.cn/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.cn/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.cn/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.cn/network-security/advanced-dns-security?ts=markdown) * [企业数据丢失防护](https://www.paloaltonetworks.cn/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.cn/network-security/enterprise-iot-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.cn/network-security/medical-iot-security?ts=markdown) * [工业 OT 安全](https://www.paloaltonetworks.cn/network-security/industrial-ot-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.cn/sase/saas-security?ts=markdown) * [新一代防火墙](https://www.paloaltonetworks.cn/network-security/next-generation-firewall?ts=markdown) * [硬件防火墙](https://www.paloaltonetworks.cn/network-security/hardware-firewall-innovations?ts=markdown) * [软件防火墙](https://www.paloaltonetworks.cn/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.cn/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.cn/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.cn/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.cn/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.cn/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.cn/sase?ts=markdown) * [应用加速](https://www.paloaltonetworks.cn/sase/app-acceleration?ts=markdown) * [自主数字体验管理](https://www.paloaltonetworks.cn/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.cn/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.cn/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.cn/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.cn/sase/sd-wan?ts=markdown) * [远程浏览器隔离](https://www.paloaltonetworks.cn/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.cn/sase/saas-security?ts=markdown) * [基于 AI 的安全运营平台](https://www.paloaltonetworks.cn/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.cn/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.cn/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.cn/cortex/cloud/application-security?ts=markdown) * [云态势安全](https://www.paloaltonetworks.cn/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.cn/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.cn/prisma/cloud?ts=markdown) * [人工智能驱动的 SOC](https://www.paloaltonetworks.cn/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.cn/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.cn/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.cn/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.cn/cortex/cortex-xpanse?ts=markdown) * [Unit 42 托管检测和响应](https://www.paloaltonetworks.cn/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.cn/cortex/managed-xsiam?ts=markdown) * [威胁情报和事件响应服务](https://www.paloaltonetworks.cn/unit42?ts=markdown) * [主动评估](https://www.paloaltonetworks.cn/unit42/assess?ts=markdown) * [事故响应](https://www.paloaltonetworks.cn/unit42/respond?ts=markdown) * [安全策略转型](https://www.paloaltonetworks.cn/unit42/transform?ts=markdown) * [发现威胁情报](https://www.paloaltonetworks.cn/unit42/threat-intelligence-partners?ts=markdown) ## 公司 * [关于我们](https://www.paloaltonetworks.cn/about-us?ts=markdown) * [人才招聘](https://jobs.paloaltonetworks.com/en/) * [联系我们](https://www.paloaltonetworks.cn/company/contact-sales?ts=markdown) * [企业责任](https://www.paloaltonetworks.com/about-us/corporate-responsibility) * [客户](https://www.paloaltonetworks.cn/customers?ts=markdown) * [投资者关系](https://investors.paloaltonetworks.com/) * [位置](https://www.paloaltonetworks.com/about-us/locations) * [新闻资讯](https://www.paloaltonetworks.cn/company/newsroom?ts=markdown) ## 热门链接 * [博客](https://www.paloaltonetworks.com/blog/?lang=zh-hans) * [社区](https://www.paloaltonetworks.com/communities) * [内容库](https://www.paloaltonetworks.cn/resources?ts=markdown) * [网络百科](https://www.paloaltonetworks.com/cyberpedia) * [事件中心](https://events.paloaltonetworks.com/) * [管理电子邮件首选项](https://start.paloaltonetworks.com/preference-center) * [产品清单](https://www.paloaltonetworks.cn/products/products-a-z?ts=markdown) * [产品认证](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance) * [报告漏洞](https://www.paloaltonetworks.com/security-disclosure) * [网站地图](https://www.paloaltonetworks.cn/sitemap?ts=markdown) * [技术文档](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [请勿出售或分享我的个人信息](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [隐私](https://www.paloaltonetworks.com/legal-notices/privacy) * [信任中心](https://www.paloaltonetworks.com/legal-notices/trust-center) * [使用条款](https://www.paloaltonetworks.com/legal-notices/terms-of-use) * [文档](https://www.paloaltonetworks.com/legal) 版权所有 © 2025 Palo Alto Networks。保留所有权利 * [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/) * CN Select your language