Hubert Lin
Hubert Lin
Netskope
Threat Labs Sr. Staff Threat Researcher

Hubert Lin is an offensive security expert, specializing in remote vulnerability exploitation, honeypots, and penetration testing. He previously led the signature team for network threat defense and was a senior staff engineer on the Red Team at Trend Micro. In his roles, he assessed network intrusion prevention systems and conducted sanctioned red team exercises to enhance corporate security. Hubert holds certifications as a Red Hat Certified Engineer (RHCE) and an Offensive Security Certified Professional (OSCP). Currently, he works at Netskope as a Sr. Staff Threat Researcher.

SPEECH
演講議程
5/16 (四) 16:30 - 17:00 4F 4B 資安威脅研究室
明修棧道 暗渡陳倉的 DNS

除了被廣泛利用的 HTTP 之外,DNS 協議在網路通訊中也扮演著至關重要的角色,它能夠繞過企業常使用的 L4 防火牆限制。本次簡報將探討 DNS 被濫用以建立隱蔽隧道、繞過第四層防火牆的情境。我們將探索幾種隧道工具和命令與控制 (C2) 框架,以及說明攻擊者如何利用 DNS 進行未經授權的網路存取。我們的分析顯示,持續的濫用 DNS 是惡意組織長期採用的有效攻擊媒介。本議程將歸納出加強 DNS 安全的實用策略,以提供具體步驟來減輕潛在的威脅。