美国官员商讨是否为勒索软件交赎金?
日期:2021-06-29 09:43

(单词翻译:单击)

L^=Q|K8Zi(vuqI

听力文本

S~=gp1sIvG

1dV*BMY_HHyyj

XZj=_jOTf%,fdGKU*

*JypcdhUVQ0-p&UI

M@vm;gkdu!Y6Pp+fYi

]A3M8bHx;h|Y%

a7Wrr[V0O!Y-U+S+lK

ocBzU(w_%bWJm#

Nbcpk!8.V!_u

e-6C8G_@vpUgBx~Xh

rseRN|YMRF

3gU;lc6@6*duHu^

aIbc[ErH8nlT=!f,,)=j

138*gBvKmp

^B(V=fi4DEXzl_xj!

D#tG[gWsMnO],

t&bp3tsF(7=0,s

~V*K5tBl6#*sy

q*9d.xft~Vh&Qq^.UL

HcY[N1|w*o%MPSV#R

,1)UiWrIHqj

1~lZR(ZNlM_

fIY[rw1qx)

PMseaSxjTe

y^udzPZrV=[A&h&

IjWJ(o]4yJASiOdRAH%

dKh(F9orpbe(u[xjfom

US Officials Considering How to Deal with Ransomware Payments

(Xl8szY@|ISa9[,O

American business leaders are looking for advice on how to deal with ransomware - a kind of software designed to seize a computer system until money is paid.

n|oyac#2J4g*q#W46#wF

The question is whether payments should be made for ransomware attacks. But the U.S. government has not yet given clear rules or policies on the issue.

eB7*LeXK#V(~1m[

How to respond?

7_V09JA_lE,

Eric Goldstein is a top cybersecurity official in the Department of Homeland Security. Goldstein told a congressional hearing last week, "It is the position of the U.S. government that we strongly discourage the payment of ransoms." Discourage means to try to make people not want to do something.

[DL6=R_H&Q

Goldstein told lawmakers that paying a ransom does not guarantee that you will get your data back or that stolen files will be safe. He added even if the criminals keep their word, the money will be used to pay for the next round of attacks.

Qs|wsinEpff

But current laws do not punish business for making ransomware payments. Refusing to make the payments would be bad for businesses, however, especially for small and medium-sized companies. And the effect of non-payment could be serious for the U.S. itself.

oZ)h1tf5kTQpOo

Recent well-known ransomware attacks led to a shortage and high gas prices in the eastern U.S. and threatened the nation's meat supplies. The issue has left public officials searching for an answer.

cb(k@ggeIzC3

美国官员商讨是否为勒索软件交赎金?.jpg

Sid|;4e,wt4R4U|R.f

Congress is now looking at legislation requiring immediate reporting of ransomware attacks to federal officials. The idea is that such reporting would help identify those responsible and even help get back some of the ransom money.

b45+kk9#TK&xi5Lf3O

Recently, U.S. law enforcement recovered most of the $4.4 million that Colonial Pipeline paid to a gang of criminal hackers called DarkSide. That was the first time the U.S. government has said that it had recovered money from the Russia-based gang.

21X5S~ZPyY%i)

Last week, U.S. President Joe Biden met with Russian President Vladimir Putin in Geneva to talk about several issues including cybersecurity. Biden said he gave Putin a list of 16 "critical infrastructure" items, including energy and water systems, that are considered off-limits to criminal activities.

m#9H]]gBXOU@f[^#j*%

Without additional action soon, however, experts say ransomware attacks will continue to increase.

_CYR8cv]vl~S5)f=~wxE

Cybersecurity experts

9nf,0,i|@f

U.S. Energy Secretary Jennifer Granholm said this month that she supports banning payments. But she did not know whether Congress or the president would.

k+Gs7]kBd1ah)pdQWKb

Some of the strongest supporters of a payment ban are those who know ransomware criminals best — cybersecurity experts.

Tz_RJ[)GT5v-;]n5@

Lior Div is the head of Boston-based Cybereason. He compared ransomware criminals to digital-age terrorists. "It is terrorism in a different form, a very modern one," Div said.

F|IPdx=q5S]guKP

A 2015 British law forbids United Kingdom-based insurance firms from paying back companies for terrorism ransom payments. Some believe this idea should be applied to ransomware payments.

hed8V*c7@a;6e

Adrian Nish is the threat intelligence chief at BAE Systems. Nish noted that "terrorists stopped kidnapping people because they realized that they weren't going to get paid."

MTWap)IlgM+8@oSyL[

U.S. law forbids material support for terrorists, but the Justice Department in 2015 waived the threat of criminal prosecution for citizens who pay terrorist ransoms.

Z;oMauukrzy939%d

Standing up against attacks

UVT[oM,8[RFBH9

Some ransomware victims have refused to make payments at a high cost.

Fx#P!e[0NohQ

One is the University of Vermont Health Network, where the bill for recovery and lost services after an October attack was around $63 million.

3#%WEDN@6M)|jv

Ireland, too, refused to negotiate when its national healthcare service was hit last month. Five weeks later, healthcare information technology in the nation of 5 million remains badly damaged.

!EPm]y_TM@#g82

Most ransomware victims end up paying. Insurance company Hiscox says over 58 percent of its affected customers pay the ransom. And leading cyber insurance company Marsh McLennan says about 60 percent of its affected U.S. and Canadian customers pay theirs.

E4Qo~b!t+*=##efh=U*

But paying does not guarantee anything near full recovery. In a study of 5,400 technology decision-makers from 30 countries, the cybersecurity company Sophos found that on average, ransom-payers got back just 65 percent of the encrypted data.

Llbl(-5526]F

In a separate study of nearly 1,300 security professionals, cybersecurity company Cybereason found that 4 in 5 businesses that chose to pay ransoms suffered a second ransomware attack.

H%)SLiMyewi

I'm John Russell.

重点解析

重点讲解:
1. deal with 处理;应付

MAomnH(JS0xNe

He's happy that I deal with it myself.

Pktat]=jKGCd=QK

他对我自己处理这件事感到很满意9.gsEjv&+2l-Iy8V

2. get back 恢复

.cOnz_^nBDx

I really need to get back in form.

8LrW&U*gM@zdp_qkI[z

我实在需要恢复状态gAift07Ri6=%PH+PX

3. end up doing sth 终止做某事

45^D|R~yadniZO-

p!@_Jh6(0v0SmIgq

3#JTK;%Xl3D)|6fX

In the great effort not to offend, we end up saying nothing.

8m6cbeIk*^@4cv6=-YF

为了尽量不冒犯人,我们最终什么也没说a;R;]Si&hR-+s

4. get paid 得到报酬;领工资

IjdKW3G@ikPpGUCS)2_

*VZ.8^-2KA-9T8Twa

esA#S;EbPtcI

.k^,rR+tht

She didn't get paid much but it was all good experience.

q4u.AEfO*QyGO

她得到的报酬虽然不高,但有极好的体验tLqXUxu_CqX

参考译文

Rjm%@r%3d#u%XX272sav

K[HfYeOk@H_3#

%bH&oqh05-ba=Dlr^

is2|HQgpd0r;^b9t,xT

GYaR(7bax||P

,M&P#b@_CZYO(

Nl!@!F+zu.

ExHB3&APS6y%*qmN

]BbEX_nFyh

@gFnN4YQ)elIkTs91PV5

dg2]0pwHGrpW*Nq

r;ZGio~_Q(_lK;@Ye#P

92^OtbrgYS87P

M(bt~!hT3@R^G^Oc0Xe

rH7TY^r^];SE^#*LK6lN

_yuY3G(~U#9i[!|W0!O

z9]i|D#2Yw

R^jw*ZlOA6WS|DPSNwn

&vK6s5)t@liA7C*-h

ISdlq0Y|!rt

2fAMl@Qacz

v)D*Wy6%;X;i58

1)pt+qJu_%dI=p;rU*^I

jNuhqszuzwuoVYi3

N-9~D47Av~ngo

A]hRiK7M.D;ofWGh.0c

[Pb|7GXtX3g

-y%c,]Z,uWm

美国官员商讨是否为勒索软件交赎金?

z#@y+-G#JSZQfD.+

美国商界领袖正在寻求有关如何应对勒索软件的建议,勒索软件是一种用来侵占计算机系统直到用户缴纳赎金的软件*RXL+*IL%Ak

g7zP]LO@qMd4)XC

问题在于是否应该为勒索软件的攻击付赎金mBUgu3rYOS。但是美国政府尚未就这一问题出台明确规定或政策o7&hIc=Q1MuLFia

F]LAyv18bQmOQf0&m

如何回应?

Cda7|BSaFH(,gu)@

埃里克·戈德斯坦(Eric Goldstein)是美国国土安全部的高级网络安全官员3Kq7*@~4c#。戈德斯坦上周在国会听证会上表示:“美国政府的立场是,我们强烈反对支付赎金[x5sWaf-Tr)prB。”“Discourage”指设法让人不想做某事+|_44=Ou2Bc!FpL[g

od%vpBS+8(3-aLwoWC

戈德斯坦对议员表示,支付赎金无法保证拿回数据或确保被盗文件的安全=IW6XQY6F5x|Yq+Qu;L,。他还表示,即使犯罪分子信守承诺,这笔钱也将被用于下一轮的攻击NAEv=#|&.|!IS

dbvTTjR)NGSy

但是现有法律并不会对支付勒索软件赎金的企业实施惩罚moMr%QZ!v6U2ARNz.g)。然而,拒绝支付赎金对企业不利,尤其是对中小企业而言L%mIRmEy%dm7C(y。对美国自身而言,不付赎金也可能会面临严重影响Ed4)jY]TwF0vV

&jgbU(5@W8W*T9cvLx

近来著名的勒索软件攻击导致美国东部地区出现石油短缺和高油价,以及威胁到美国的肉类供应)n#b^Ayq)iDbp=.XiE[m。这个问题迫使政府官员一直在寻求解决方案01l#x!_@C]S~U#

W#iv3[lQw+5hZny]

美国国会现在正在考虑立法,要求立即向联邦官员报告勒索软件攻击bi_1AwcZscDKRt&2。他们的初衷是报告将有助于确定责任人,甚至有助于追回部分赎金*nmk5e4H6Vn~F[]

m=~.4D*XL.9dxS)g]lj!

最近,美国执法官员追回了科洛尼尔管道公司支付给一家名为DarkSide的黑客犯罪团伙的440万美元中的大部分资金@_ef6+Hiw9)~-[j@e。这是美国政府首次声称从这个俄罗斯团伙手中追回资金3iV6~!~5Hm-z.Ws

[eA=wgj%8h84,87

上周,美国总统拜登在日内瓦会见了俄罗斯总统普京,讨论了包括网络安全在内的几大问题_x8AQEIFkDw。拜登称,他给普京提供了一份名单,其中有16个包括能源和供水系统在内的关键基础设施项目,这些项目被视为犯罪活动禁区lK1o#VtKCaO.wIz

-#4+_gqL7HDr~l

然而专家表示,如果不立即采取其他行动,勒索软件攻击将会继续增加l!KdfRO^ccrwQX

RApM&G^RN3YR2^YC~IF

网络安全专家

BV14@IGap!.|hoI5^

美国能源部长詹妮弗·格兰霍姆(Jennifer Granholm)本月表示,她支持禁止支付赎金_o]g9MJS5Un58^DD7l5。但是她不知道国会和总统的想法是否一致AV(m*2NkRrbJ

VzwA7xm^[3tvW^

一些坚定地支持赎金禁令的人士是最了解勒索软件犯罪分子的网络安全专家3~YOpxT1UX8FhLMC

X()lu.Kc,Gu

Lior Div 是总部位于波士顿的Cybereason公司的负责人&+rVgeW%zubK-!MU。他将勒索软件犯罪分子比作数字时代的恐怖分子h1-[1OO9a&TXopK。他说:“这是一种另类的、非常现代的恐怖主义Qly^,iksu^mb。”

6z9zaI&LOk(za

一项2015年出台的英国法律禁止总部位于英国的保险公司为支付恐怖主义赎金的公司进行理赔;SP;MG;hb7r;Z5。有人认为这一法律应该也适用于勒索软件赎金6OEV[+G(b!gG

#GNONqCDL*Dc.CTuZY#

埃德里安·尼斯(Adrian Nish)是BAE Systems公司的威胁情报主管DS1AqQx+dvaoCBmi。尼斯指出,“恐怖分子不再绑架人质,因为他们意识到此举拿不到赎金Inb4,2|F)9n7O[K。”

d-w.G2juBulk[()Dfs;

美国法律禁止向恐怖分子提供物质支持,但是美国司法部在2015年撤回了对支付恐怖主义赎金的公民提起刑事诉讼的威胁]1NHyGV%Q1m9m

fA+f_MJSqtHEo-E%=Y

勇敢拒绝

x9AS.oHDE)A

一些勒索软件受害人拒绝支付高额赎金P^@~(!@%mR+KYHA

5]ek#~#C8d.M

其中一位受害者是佛蒙特大学健康网络,在10月份遭受攻击后,恢复服务和丢失服务的总损失约为6300万美元%rpx)Y-LIKL^T

-7l)^An-[=+fCw

爱尔兰国家医疗保健服务在上个月受到攻击后也拒绝进行谈判qoU96I)*tcFmWj%dIPF。5周后,这个拥有500万人口的国家的医疗保健信息技术仍然严重受损3vM;|bII|hxnG8wLQly

s&-xX9RH)B1;O1J6-

大多数勒索软件受害者最终会支付赎金y+mbd8oVW%JYfbWbnkUj。Hiscox保险公司表示,超过58%的受影响客户支付了赎金8H;e+I^f;%N[8Y4。领先的网络保险公司Marsh McLennan表示,其受影响的美国和加拿大客户中约有60%付了赎金4Y[*oP3AreX

r%B!8wS3p*EVG*IBk

但是支付赎金并不能保证服务能完全恢复(|4|E2bxK|NH!gx(。网络安全公司 Sophos 对来自30个国家的5400名技术决策者进行了研究,他们发现,支付赎金者平均只拿回了 65% 的加密数据A3,f+^DJ*+[2QC[NF&9H

K]#zs#x|#|3Y

网络安全公司 Cybereason 在一项针对近1300名安全专家的另一项研究中发现,有五分之四选择支付赎金的企业遭受了第二次勒索软件攻击G8+0OUp2JkCMiSF4c5]7

tI6aPB@R~QcBd..O

约翰·罗塞尔为您播报+Xx#r+QzAO=HI5cjud@O

译文为可可英语翻译,未经授权请勿转载!

u*o[]A=@G[WjoGKicleb6OD(2AS,CqdNLsYQ|iF,Se|
分享到