Sunday, December 15, 2013

Paper: BMP 隱寫工具之嵌入簽章與安全分析

這是我們發表在 2013 全國計算機會議 (National Computer Symposium) 的論文:

BMP 隱寫工具之嵌入簽章與安全分析
Embedding Signature and Staganalysis of BMP Steganographic Tools
李慧娟、李遠坤、蔡振揚
銘傳大學資工系

中文摘要

本論文針對可從網路下載的 BMP 影像隱寫工具進行安全性檢測。首先,針對隱寫工具所產生的 BMP 偽裝影像進行嵌入簽章的萃取實驗。接著,針對嵌入簽章的所在位置與檔頭格式進行比對,提出各個隱寫工具所使用的特定輸出模式。最後,再透過簽章驗證實驗來評估特定輸出模式對安全性的影響。

實驗結果顯示 10 個隱寫工具只有 3 個隱寫工具沒有在檔頭留下任何簽章;其中 2 個隱寫工具是將機密訊息藏在檔案尾端,偽裝影像很容易被辨識出來。因此,只有 1 個隱寫工具所使用的輸出模式是真正安全的。所萃取出的 7 組嵌入簽章,透過簽章驗證實驗結果歸納出當隱寫工具所採用的輸出模式愈特殊時,透過嵌入簽章來篩選偽裝影像的正確率也會愈高。因此,隱寫工具除了將機密訊息嵌入到數位媒體內容之外,在輸出偽裝媒體時,絕對不可採用特定的輸出模式,以避免在檔案標頭區域留下簽章,成為安全漏洞。



投影片下載

Saturday, February 09, 2013

News: 錯字也抄 論文抄襲去年 23 件

中國時報 2013-02-09 李宗祐、胡清暉/台北報導
原始新聞連結

國科會昨日公布歷年涉及研究論文抄襲、或未適當引註等違反學術倫理案件統計,從民國八十八年到去年為止,共有一百件被裁定違反學術倫理,不但出現逐漸攀升趨勢,去年更以廿三件創下歷年新高,凸顯國內學術界「文抄公」越來越多,抄襲歪風日益猖獗!

面對學術抄襲歪風日盛,國科會昨日修訂《學術倫理案件處理及審議要點》,也頒布《研究人員學術倫理規範》,以負面表列把造假、變造、抄襲、與研究成果發表及作者定義相關之不當行為、自我抄襲和一稿多投等,列為學術研究「不該有的行為」,讓學者明確瞭解什麼事情可以做、什麼事情不能做。

國科會副主委孫以瀚解釋,指導教授把學生做的研究據為已有、發表論文,沒有讓學生掛名「共同作者」,就是與研究成果發表及作者定義相關之不當行為。

至於性騷擾、師生關係和經費使用(不實發票報銷)等則被列為一般生活或工作倫理,因另有主管機關或相關規範處理,被列為學術倫理無關。孫以瀚舉例,不實發票核銷研究經費,國科會另設有《專題研究計畫經費浮報虛報處理作業要點》處理,不在學術倫理規範內。

教育部長蔣偉寧表示,若違反學術規範,應有適當處置,教育部支持國科會訂定學術倫理規範的做法,也會加強宣導,杜絕抄襲、造假等爭議。

孫以瀚直言,去年被裁定違反學術倫理的案件,有幾件真的抄得很嚴重,「不但滿大篇幅的抄襲,連錯字都沒改」;還有人在個人著作目錄列了一堆根本不是他的論文,卻把自己的名字加到別人的論文裡面,甚至連論文引註頁數都寫錯;有的則是把別人的研究背景說明整段抄過來。

相較於民國九十八年以前,每年違反學術倫理案件僅個位數,去年增加到廿三件,大幅成長二.八三倍。國科會綜合業務處長陳宗權指出,案件明顯增加,最主要是因為過去都是被動靠人家檢舉,近幾年多數由審查委員在審查研究計畫時主動發現。

不過國科會昨日以《個人資料保護法》為由,拒絕公布「文抄公」名單,僅透露廿三件被裁定案件,有一名學者被裁定停權五年、不得申請國科會研究計畫經費補助;被罰停權三年和二年者各有一名和三名,其餘十八人均被停權一年。

News: 抓研究造假 學術倫理規範出爐

【聯合報╱記者劉盈慧/台北報導 原始新聞連結】
2013.02.09 02:46 am

國科會昨天首度公布「研究人員學術倫理規範」,國科會副主委孫以瀚表示,這是國內第一次對學術研究領域的學術倫理下規範,造假、變造、抄襲等行為都違反學術倫理。他期盼透過這項明文規定,讓學研單位都有所遵循,避免做出違反倫理的事。

國科會訂定的學術倫理規範中,將造假、變造、抄襲、重複發表、作者定義不清、一稿多投、自我抄襲列為學術研究倫理的不良態樣。像是引述他人著述卻又沒註明出處,視為抄襲,或是明明有五名學者共同做研究,出處上卻只寫出其中三名,沒標出其他兩名的貢獻,就屬於作者定義不清。

孫以瀚表示,這次的學術倫理規範將最常見的狀況逐一列出,也有部分說明與定義。只要是有向國科會申請研究計畫的教授、研究助理、博士後研究員都屬於規範對象。

學者若觸犯,學術倫理審議會將依情節輕重,輕者被告誡,重者要停止在國科會申請的研究計畫一至十年,並追回部分或全部的研究補助費與獎勵。最嚴重的還會被處以終身停權。

孫以瀚指出,國科會近年處理違反學術倫理的案子,件數逐年增加;民國九十七年有七件,九十九年有十四件,去年有廿三件。他說,以去年的為例,八成的案件都涉及抄襲。去年最嚴重的一件是某學者在著作目錄裡,「把別人的文章也加到自己的名下」,因此處以停權五年。另有一件被停權三年、三件被停權一年。

而先前的教授浮報、虛報發票案件,並沒有列入學術倫理規範中;他回答,學術倫理針對的是研究內容,浮報及假發票不屬於這個層面。這項學術倫理規範,昨天公布後立即生效。

Wednesday, May 16, 2012

Friday, May 11, 2012

Talk: digital steganography & steganalysis



今天晚上應元智大學資工系 王任瓚教授的邀請, 到元智資工和研究生聊什麼是數位隱寫術與隱寫分析(digital steganography & steganalysis), 主要是談論基本觀念與一些有趣的故事, 順便把自己這兩三年的研究成果的原始構想介紹出來。

前幾天, 剛好有一位蓋達組織的成員被逮, 藏在內褲的記憶卡被搜了出來。記憶卡中色情影片被分析後, 找到一百多份蓋達組織的機密文件。因此, 演講剛好就可以用這個故事開場, 時間還配合的剛剛好呢! 而 CNN 網站長達10分鐘的影片, 剛好可以在等待演講前, 在會場播放給早到的研究生觀看。

故事用蓋達最近的新聞開場, 但我真正想表達的是這樣的技術在學術界早就公開教人怎麼藏了, 所以我拍了一張 2003 年 Min Wu 在 IEEE 所發表的兩篇論文的照片, 主題就是 Data Hiding in Image and Video, 希望表達 steganography 並不是什麼新技術; 而且, Jack Kelly 在 911 事件發生之前, 就在 USA Today 新聞網站上發表了 2 篇文章, 指出恐怖組織可能使用隱寫技術進行秘密通訊。

接下來, 演講主題進入 steganography 專業術語的解說, 並且藉著與 cryptography 術語的異同比較, 指出這兩個領域其實是可以互相搭配與結合, 讓秘密通訊的安全性可以進一步獲得提升。演講中, 提到梅鐸新聞集團的醜聞, 除了指出密碼技術的新運用之外, 也點出密碼技術是可能被破解的。密碼與破解密碼的故事, 在許多書上都有精彩的描述, 在演講中, 順便介紹了一些我覺得可以閱讀的中英文相關書籍。沒錯! 其中還包含一本漫畫書。

其實這是一個有長達 2500 年歷史的研究領域。

Friday, May 04, 2012

News: Documents reveal al Qaeda's plans for seizing cruise ships, carnage in Europe

By Nic Robertson, Paul Cruickshank and Tim Lister, CNN
May 1, 2012 -- Updated 0930 GMT (1730 HKT)

CNN's Original Link



Editor's note: This story is based on internal al Qaeda documents, details of which were obtained by CNN. Hundreds of documents were discovered by German cryptologists embedded inside a pornographic movie on a memory disk belonging to a suspected al Qaeda operative arrested in Berlin last year. The German newspaper Die Zeit was the first to report on the documents.

(CNN) -- On May 16 last year, a 22-year-old Austrian named Maqsood Lodin was being questioned by police in Berlin. He had recently returned from Pakistan via Budapest, Hungary, and then traveled overland to Germany. His interrogators were surprised to find that hidden in his underpants were a digital storage device and memory cards.

Buried inside them was a pornographic video called "Kick Ass" -- and a file marked "Sexy Tanja."

Several weeks later, after laborious efforts to crack a password and software to make the file almost invisible, German investigators discovered encoded inside the actual video a treasure trove of intelligence -- more than 100 al Qaeda documents that included an inside track on some of the terror group's most audacious plots and a road map for future operations.

Future plots include the idea of seizing cruise ships and carrying out attacks in Europe similar to the gun attacks by Pakistani militants that paralyzed the Indian city of Mumbai in November 2008. Ten gunmen killed 164 people in that three-day rampage.

Terrorist training manuals in PDF format in German, English and Arabic were among the documents, too, according to intelligence sources.

U.S. intelligence sources tell CNN that the documents uncovered are "pure gold;" one source says that they are the most important haul of al Qaeda materials in the last year, besides those found when U.S. Navy SEALs raided Osama bin Laden's compound in Abbottabad, Pakistan, a year ago and killed the al Qaeda leader.

One document was called "Future Works." Its authorship is unclear, but intelligence officials believe it came from al Qaeda's inner core. It may have been the work of Younis al Mauretani, a senior al Qaeda operative until his capture by Pakistani police in 2011.

The document appears to have been the product of discussions to find new targets and methods of attack. German investigators believe it was written in 2009 -- and that it remains the template for al Qaeda's plans.

Investigative journalist Yassin Musharbash, a reporter with the German newspaper Die Zeit, was the first to report on the documents. One plan: to seize passenger ships. According to Musharbash, the writer "says that we could hijack a passenger ship and use it to pressurize the public."

Musharbash takes that to mean that the terrorists "would then start executing passengers on those ships and demand the release of particular prisoners."

The plan would include dressing passengers in orange jump suits, as if they were al Qaeda prisoners at Guantanamo Bay, and then videotaping their execution.

Lodin and a man called Yusuf Ocak, who allegedly traveled back to Europe with him, are now on trial in Berlin where they are pleading not guilty. Ocak was detained in Vienna two weeks after Lodin's arrest.

According to a senior Western counterterrorism official, their names were on a watch list, and when they handed over documents at a European border crossing, their names registered with counterterrorism agencies.

Both men have pleaded not guilty to terrorism charges. Ocak is also charged with helping to form a group called the German Taliban Mujahedeen, and is alleged to have made a video for the group threatening attacks in Germany.

Prosecutors believe the pair met at a terrorist training camp in Pakistan's tribal territories and were sent back to Europe to recruit a network of suicide bombers.

"We do not know what those men were up to but there are certain files of information that would make it plausible that they were probably thinking of a Mumbai-style attack," says Musharbash.
In the fall of 2010, a year after the document was written, European intelligence agencies were scrambling to investigate a Mumbai-style plot involving German and other European militants -- which sparked an unprecedented U.S. State Department travel warning for Americans in Europe.

"I think it is plausible to think that the 'Future Works' document is part of that particular project," says Musharbash.

"Future Works" suggests al Qaeda was an organization under great pressure, without a major attack to its name in several years, harried by Western intelligence. If anything, its predicament is even more dire today.

"The document delivers very clearly the notion that al Qaeda knows it is being followed very closely," Musharbash tells CNN. "It specifically says that Western intelligence agencies have become very good at spoiling attacks, that they have to come up with new ways and better plotting."

Part of the response, according to the document, should be to train European jihadists quickly and send them home -- rather than use them as fighters in Afghanistan and Pakistan -- with instructions on how to keep in secret contact with their handlers.

What emerges from the document is a twin-track strategy -- with the author apparently convinced that al Qaeda needs low-cost, low-tech attacks (perhaps such as the recent gun attacks in France carried out by Mohammed Merah) to keep security services preoccupied while it plans large-scale attacks on a scale similar to 9/11.

Those already under suspicion in Europe and elsewhere would be used as decoys, while others would prepare major attacks.

That is yet to materialize, but Musharbash believes a complex gun attack in Europe is still on al Qaeda's radar.

"I believe that the general idea is still alive and I believe that as soon as al Qaeda has the capacities to go after that scenario, they will immediately do it," he says.

While "Future Works" does not include dates or places, nor specific plans, it appears to be a brainstorming exercise to seize the initiative -- and reinstate al Qaeda on front pages around the world.

Wednesday, May 02, 2012

News: Al Qaeda ship secret plans encrypted in porn movie

Written by Nick Farrell
Wednesday, 02 May 2012 09:59

Original Link

Spooks didn’t see that one coming

Al Qaeda has been distributing its top secret plans across the internet embedded and encrypted within a file of a porn movie.

According to the German newspaper Die Zeit the file was discovered on a 22-year-old Austrian named Maqsood Lodin. When he was questioned his interrogators were surprised to find that hidden in his underpants were a digital storage device and memory cards. Buried inside them was a pornographic video called "Kick Ass" and a file marked "Sexy Tanja."

These are not the usual thing you expect to find on a Muslim fundamentalist, although it was viable for a Christian fundamentalist politician, so the investigators smelt a rat. It took several weeks to crack the a password and software to make the file visible and it turned out that there were more than 100 al Qaeda documents included inside the file. These included some plans for taking over cruise ships and carrying out attacks in Europe similar to the gun attacks by Pakistani militants in Mumbai in November 2008.

There were terrorist training manuals in PDF format in German, English and Arabic were among the documents, too, according to intelligence sources. Investigative journalist Yassin Musharbash, a reporter with the German newspaper Die Zeit said that one plan was to hijack a passenger ship. They would dress passengers in orange jump suits, as if they were al Qaeda prisoners at Guantanamo Bay, and then videotape their execution. That was before the idea of travelling on a cruise ship turned out to be such dangerous exercise, particularly if it was piloted by an Italian.

News: 'Sexy Tanja' Porn Movie Hid al Qaida's Plot for Mumbai-style Attack on Europe

By EWAN PALMER, May 1, 2012 12:08 PM GMT
Original Link

Hundreds of al-Qaida documents have been discovered embedded inside a pornographic movie, including a plot to carry out an attack in Europe similar to the 2008 Mumbai attacks.

The documents were found after 22-year-old Austrian Maqsood Lodin was detained and searched by investigators in Berlin after flying from Pakistan via Budapest.

The investigators discovered a storage device and a memory card hidden in Lodin's underwear which contained a pornographic film called Kick Ass and a file marked Sexy Tanja.

Several weeks later, investigators decoded the device and found more than 100 al-Qaida documents embedded in the video, including terrorist training manuals and plans to seize cruise ships to launch an attack on Europe similar to the 2008 Mumbai attacks in which 10 gunmen killed 164 people.

US intelligence told CNN the materials discovered are the most important since the trove which were discovered during the killing of Osama Bin Laden last year.

One of the documents, entitled Future Works, was reported to appear to show discussions by al-Qaida to find new targets and methods of attacks. German investigators believe the document was written in 2009 and still forms a large part of al-Qaida's plans.

A year after the document was written; European intelligence agencies investigated a Mumbai-style plot involving Germany which sparked a US State Department travel warning for Americans in Europe.
Investigative journalist Yassin Musharbash, a reporter with theGerman newspaper Die Zeit, was the first to report on the documents. He was quoted as saying: "I think it is plausible to think that the 'Future Works' document is part of that particular project."

Musharbash told CNN: "The document delivers very clearly the notion that al Qaeda knows it is being followed very closely.

"It specifically says that Western intelligence agencies have become very good at spoiling attacks, that they have to come up with new ways and better plotting."

Lodin and alleged compatriot Yusuf Ocak, who was detained in Vienna two weeks later, was stopped in Berlin, are currently on trial in the German capital.

They have pleaded not guilty to terrorism charges. The men, who reportedly met in a terrorist training camp in Pakistan, were both listed on a watch list. Prosecutors said they believe the men were sent back to Germany to recruit others to take part in the attacks outlined in the documents.

News: 賓拉丹遭斃週年 解碼情色片藏攻擊訊息

賓拉丹遭斃週年 解碼情色片藏攻擊訊息

(自由時報 即時新聞 2012/5/1 17:42 原始新聞連結)

台灣時間5月2日,是911事件主謀賓拉丹(Osama bin Laden)遭美軍擊斃屆滿週年的日子,現在傳出,當時賓拉丹住處擁有大量色情片,經過情報人員解碼後,這批色情片原來藏有恐怖攻擊的訊息。

賓拉丹的住處遭搜出大量色情片,其中一支叫「Kick Ass」的片子,裡面藏有「Sexy Tanja」的資料夾,恰巧與德國警方去年逮捕的一名恐部分子所擁有的內容相同,經交叉比對後,色情片原來暗藏恐怖攻擊計畫,包括炸彈攻擊與劫持郵輪等。

「Sexy Tanja」的資料夾裡共有上百個開打恐怖組織(Al-Qaeda)檔案,檔案顯示開打欲以殺死乘客為籌碼,逼迫美國或德國當局釋放特定囚犯,若不從,將錄製殺害乘客的過程,寄給有關當局。

美國情報人員表示,種種資料顯示,這份資料可能是在2009年完成,雖然未真實發生類似事件,但攻擊的手法,已經成為日後恐怖組織進行攻擊活動時,主要的模仿方式。


暗藏基地情報 A片變恐怖片

(中時電子報 2012/5/2 5:30 am 記者陳文和 綜合報導 原始新聞連結)

德國當局破解恐怖分子嫌犯偽製成色情影片的數位檔案後赫然發現,裡頭竟隱藏「基地」國際恐怖組織上百份內部文件,宛如挖出一座情報寶庫。而基地組織一些膽大包天的攻擊計畫也因而曝光,其中包括劫持遊輪,以及在歐洲地區重演二○○八年印度最大城市孟買傷亡慘重的連環恐怖攻擊。

德國警方去年五月十六日在柏林盤問廿二歲奧地利籍恐怖活動嫌犯洛汀,意外查獲他內衣褲裡藏匿數位儲存裝置和記憶卡,而裡面存有一部名為《Kick Ass》的成人影片,以及一個標示為「性感坦雅」(Sexy Tanja)的檔案。

洛汀與籌組「德國塔里班人民聖戰士」組織的另一名嫌犯歐卡克都到過巴基斯坦,在恐怖分子訓練營相識,並奉派返回歐洲召募人員準備發動自殺式炸彈攻擊。洛汀被捕後兩周,歐卡克也在維也納落網,兩人正接受法庭審判。

洛汀所持有檔案的真實內容經編碼加密,且有保護程式使其隱而不見,德國調查人員經數周努力才成功破解。據美國情報界描述,裡面所暗藏的基地內部文件如同「高純度黃金」,和美軍擊殺基地首腦賓拉登後斬獲的情資等量齊觀。

該批文件內含德文、英文與阿拉伯文版PDF格式的恐怖分子訓練手冊,以及基地組織未來的運作計畫,其中包括劫持客輪,讓乘客換穿如同關達那摩灣美軍基地監獄恐怖嫌犯的橙色囚服,以殺害乘客為要脅,甚至將他們處決並公布相關錄影,以迫使有關當局釋放特定囚犯。
此外,基地也計畫在歐洲發動連環恐怖攻擊,手法近似二○○八年的孟買事件。當年十一月廿六日到廿九日,來自巴基斯坦的恐怖分子接連襲擊孟買十多處地點,以槍械和炸彈奪走一百六十四人的生命,並造成逾三百人受傷。

而一份名為「未來工作」的文件明確顯示,基地組織自知受到嚴密監控,西方國家情報機構對偵破其攻擊計畫越來越得心應手,因此亟欲「構想新攻擊方式並進行更完善規畫」,包括訓練歐洲的伊斯蘭聖戰士並派遣他們回國執行任務,以及運用低成本且低科技的攻擊,讓歐洲各國安全單位疲於奔命,再趁機擘劃「九一一事件」規模的攻擊行動。

Wednesday, April 18, 2012

News: 31 篇論文造假 女教授判囚 1.5 年

【 蘋果日報 2012/04/18 許淑惠 台中報導 】

逢甲大學自動控制系前女教授陳OO,被控為了升等,六年來謊稱在國際期刊發表三十一篇論文著作,以致校方誤認而陸續給予升等副教授、教授,檢方認定她因此騙得升等薪資近三十萬元,台中地院昨依詐欺罪判她一年六月徒刑。

稱無不法「將上訴」

至今無業的陳OO(四十一歲)昨透過友人表示:「論文升等這是身分上(指教授、副教授)的取得,她並未因此獲得經濟上的不法利益,不符詐欺罪構成要件,會再上訴。」陳女友人表示,判決結果讓陳女很難過。

陳OO是成功大學航太所博士,曾獲救國團青年獎章、亞洲傑出青年科學家獎,二○○○年進入逢甲擔任助理教授,二○○四年升副教授、二○○八年底升教授,其間還赴美國聖路易市華盛頓大學擔任訪問學者,但隔年即遭檢舉她提出升等送審的論文涉嫌偽造、變造,校方逐一清查屬實,撤銷她的教授及副教授資格,且十年不得再提升等,陳女則主動離職。

未在國際期刊發表

開庭時,陳女主張三十一篇論文都是她的作品,其中有十二篇已確認公開發表過,其餘陸續確認中,而校方曾將她的論文送外審單位審核通過,即代表具升等實力,並未詐騙校方。

但檢察官為查明陳女的論文究竟有無在《Journal of Guidance, Control, and Dynamics》等期刊發表,曾函轉外交部,將陳女申請升等的論文送到美國,經追查、比對認定陳女所寫多篇論文並未在國際期刊發表,因此將她依詐欺罪起訴。

Saturday, January 21, 2012

Package: File Camouflage

Want to save a copy of your personal file on a usb pendrive but you are worried that, in case of theft, someone will be able to access your data?

With Free File Camouflage you can hide your files inside a jpeg image!

The software can be used with the main interface or via the explorer "send to" context menu (the first time you only need to select a directory with some images).

All the files are encrypted using AES and hidden inside an image.

What happens if someone tries to open a camouflaged image? Well... nothing! He will only see the image.

Download

中文網頁介紹

Wednesday, September 28, 2011

News: 中國佈「網」 電子監控商務客

〔自由時報 2011/09/28 編譯陳成良、記者陳炳宏 綜合報導 原始新聞連結〕

華盛頓郵報二十七日報導,中國是美國第二大貿易夥伴,不過許多美國企業商務旅客越來越擔心遭到中國精密且無孔不入的電子監控。儘管俄羅斯、以色列與法國過去也都有竊聽商務客的前例,但都不像中國這般明目張膽。中國為協助發展該國經濟,往往鎖定企業進行網路監控。

中國不擇手段 鎖定企業監控

專家表示,儘管美國企業界也有工業間諜活動,但不像中國那樣誇張,而且美國政府據報導不會替美國產業執行經濟間諜活動。一般經濟間諜是為了取得工商業的競爭優勢,但只有中國的經濟間諜是由政府支持,因為許多中國企業都是國營企業。

報導援引白宮國安會亞洲政策前資深主任、美國智庫布魯金斯研究所學者李侃如(Kenneth Lieberthal)的話稱:「我被告知,如果你使用一支iPhone或黑莓機,手機裡的所有資料,包括通訊錄、行事曆、電郵等,都能在瞬間被下載。這一切只要有人在地鐵內坐在你附近,等著你打開手機就可以了,而且他們得手了。」

開手機、電腦 中國就得手了

在中國的商務旅客經常攜帶拋棄型手機以及已清除敏感資料的替代筆電,一些美國官員則完全不帶電子裝備,有些企業主管則寧願繞道到澳洲,也不願冒著在中國旅館房間遭竊聽的風險;還有些旅客將檔案藏在隨身碟,隨時帶在身上,只在離線的電腦上使用;一位擔心引來中國政府審查而要求匿名的安全專家說,他每次到中國,都使用新買的iPad平板電腦,而且用過就不會再用。二○○七年,當時美國商務部長古提瑞茲訪問北京時,他的筆記型電腦就遭中國官員盜拷檔案,裡頭資訊之後還被用來入侵美國商務部電腦。

專家表示,商務旅客數年前就針對中國採取這種安全措施。二○○八年北京奧運前夕,當時中情局國家反情報辦公室主任伯納,首度對商務旅客發布政府的安全指導方針,其中列入「能不帶的設備就不要帶」等竅門。雖然沒有點名哪個國家,伯納最近受訪時表示,當時就是針對中國及俄羅斯等國家。

伯納當年發出警告的依據,是發生了幾起中國惡意程式從遠端植入手機,進而感染在美國的電腦伺服器的案例。他指出,中國所有大飯店的電腦網路,都受到中國安全機構監控。

安全專家提供幾招防監控的措施,包括:假設所有無線裝置都有危險;定期更換密碼;不接受隨身碟當禮物;別以為自己不重要就不會被監控;不需聯絡時,把電池自手機移除,以防被遠端啟動或追蹤,這也是西方記者在中國與異議人士會面時的必用招數。

資深3C、電腦玩家董福興表示,如果是手機通訊時被中途攔截還有可能,但如果是手機內所有資料一下子被複製,那就不太可能,尤其黑莓機資料傳輸甚嚴謹,之前還有傳聞中東某國家想要請RIM公司提供技術監聽,都被婉拒,這麼嚴密的防護要被破解實在很難。

Wednesday, August 17, 2011

News: 論文維國格 禁納入 China

(中央社記者林思宇台北16日電)原始新聞連結

教育部今天表示,只要是代表台灣在國際上發表論文,禁止把國籍寫成「China」,使用「China」作為國籍發表的論文都不會承認,只能用「Taiwan」或「ROC」。

自由時報報導,中國北京大學教授饒毅無理要求共同發表學術論文的台灣清華大學教授江安世,通訊地名必須改為「中國台灣(Taiwan, China)」,還寫信恐嚇行政院國家科學委員會,要求放棄「Taiwan」或「Taiwan, R.O.C.」政策,否則將阻礙兩岸學術合作。清華大學副校長葉銘泉表示,國際論文發表時,都要寫作者的任職機構或是學校,這部分會提到國籍;台灣學者都會寫「Taiwan」,他認為,這是個個案,並不會影響到兩岸學術交流。

教育部次長林聰明表示,台灣學者發表論文時,會提到國籍的部分,都要使用「Taiwan」或是「ROC」,使用「China」教育部一概不會承認,教師在升等、點數等,都不會考量。林聰明說,「我們是中華民國,不是中華人民共和國,國格要非常強調」。林聰明說,學者如果發現「Taiwan」被改成「China」,一定要去函更正。

清大教授江安世:會堅守台灣立場

(自由時報 2011/08/16 記者洪美秀竹市報導) 原始新聞連結

以果蠅為研究標的、建構出「腦內嗅覺神經網路地圖」而蜚聲國際的清華大學腦科學研究中心主任江安世,與中國北京大學教授饒毅聯名發表論文,卻被饒毅要求通訊地名必須改為「中國台灣(Taiwan, China)」。江安世昨受訪表示,「China」不是台灣在國際學術發表上慣用的名稱,他已在兩星期前寫信給饒毅,要求尊重台灣立場,如果不尊重,就不要將他與研究團隊列為共同作者,但他也期許科學歸科學、政治歸政治,仍希望在科學領域彼此善意合作。

江安世以果蠅「腦內嗅覺神經網路地圖」而名揚國際,被喻為諾貝爾獎得主熱門人選。許多國家和生物研究團隊都曾向他取經,饒毅與江安世在美國研究時就認識,四年多前,江安世團隊協助饒毅研究團隊進行果蠅哪些分子與神經網絡影響的研究。

江安世說,饒毅團隊在幾個月前就發表果蠅神經網絡的相關研究,將他與研究團隊列為共同作者,不過,卻以「China」做為地址,他認為極為不妥,曾表達台灣學術期刊在國際都是以「Taiwan, R.O.C」或是「Taipei, Taiwan」發表,從沒用過「China」,要求饒毅尊重台灣立場,否則就不要將他與研究團隊列為共同作者。

江安世說,幾個星期前他在審查 Science 相關稿件時,又發現饒毅仍使用「China」,便立即寫信給饒毅要求撤回,並表達他的立場與堅守的原則,強調饒毅如果無法尊重,就不要將他與研究團隊列為共同作者。

江安世團隊的果蠅「腦內嗅覺神經網路地圖」研究,是全球第一個用分子層次的腦神經網路基因,表現 3D 影像虛擬實境系統,研究成果多次登上國際頂尖學術期刊「細胞」及「自然」和「科學」等雜誌。

江安世的研究超前哈佛大學、史丹佛大學、維也納大學等競爭對手,因此很多大學都曾邀約他共同研究,或提供研究資源與協助,饒毅也是其中之一。江安世說,這種合作研究模式在科學界很常見,透過彼此合作與發表論文,可以打開知名度。

江安世不諱言台灣的研究環境條件不佳且經費不足,與國際知名大學共同合作研究可增加知名度,被列為共同貢獻者或共同作者的情況常有,但他都堅守原則,就是列為共同作者應以「Taiwan」為名。

Friday, August 05, 2011

News: 最大規模駭客攻擊 指向中國

(自由時報 2011/08/04 編譯陳成良、記者羅添斌 綜合報導 原始新聞連結)

美國資安業者「邁克菲」(McAfee)發現史上最大規模連環網路攻擊,這項代號為「暗鼠行動」的駭侵,包括聯合國、台灣等國政府、國防承包商、多家國際企業等七十二個機構的網路都遭駭客攻擊。專家認為,中國極可能是幕後黑手!

包括台灣 全球 72 機構遇襲

台灣軍方資訊將領則指出,中國網軍每每在研發新式網路攻擊戰法時,對台灣發動實驗式攻擊,藉以驗證新戰法效果,因此台灣常首當其衝。這些攻擊行動能量都很大,背後一定有國家力量支撐。

McAfee 三日公布的十四頁報告中指出,據信這些攻擊背後有「國家角色」主導。雖然 McAfee 不願一語道破,但聽過相關簡報的美國國際戰略研究中心網路專家路易斯指出,所有證據都指向中國,例如一直到北京舉辦奧運前,台灣與一些國家的奧委會都是攻擊重點,顯示中國就是幕後黑手。

路易斯表示,很多受害目標都擁有與中國特殊利益相關的資訊,比如國際奧委會及一些國家奧委會的電腦系統,就是在北京申辦奧運期間被駭侵。

駭侵已五年 證據指向中國

連環駭侵行動歷時五年,目標鎖定美國、台灣、南韓、印度、越南、加拿大等國政府,聯合國、東南亞國協、國際奧委會、世界反禁藥組織等國際組織,還有英美兩國國防承包商、營建、保險、能源、太陽能產業、衛星通訊高科技公司等多家企業。

美聯社香港、紐約辦事處也遭殃。專家說,美聯社記者不疑有他,點擊了電郵中遭感染的連結。紐約辦事處前年九月遭駭侵持續八個月,香港辦事處持續二十一個月。

攻擊行動代號為「暗鼠行動」(Operation Shady RAT),RAT為英文「遠端存取工具」(Remote Access Tool)縮寫,一語雙關。據 McAfee 指出,在聯合國遇襲個案中,駭客二○○八年侵入聯合國日內瓦秘書處的電腦系統,潛伏近兩年,暗中搜括秘密資料。

McAfee 實驗室的威脅研究副總裁阿爾佩洛維奇說,很多企業和政府機構每天都被肆意攻擊和掠奪。他們面對這些不擇手段的競爭者,喪失了經濟優勢、國家機密。這是知識產權史上最大的財富轉移,規模相當駭人。

今年三月被英特爾併購的 McAfee 已通知七十二個受駭機構,但未透露細節。據了解,有四十九個在美國。

三月間,McAfee 研究人員對曾出現安全漏洞的國防企業進行調查,在一部「控管伺服器」中發現一些襲擊痕跡。最早的安全缺口發生於二○○六年中,有些襲擊只持續一個月,但對某一亞洲國家的奧委會襲擊持續二十八個月。

北京尚未對相關報導置評。儘管過去中國一貫強調指控皆「子虛烏有」,但據「維基解密」披露的美國國務院外交機密電文,駐北京的美國外交使節認為,中國 Google(當地稱中國谷歌)去年初首遭駭客入侵,是中共中央政治局策動。

Google 六月初也曾透露,疑似來自中國的駭客又試圖入侵數百名 Gmail 用戶的帳戶,目標包括美國高層政府官員、軍方人員、中國異議人士、記者,以及南韓等數個亞洲國家官員。駭客來源是山東濟南以及該市由解放軍資助成立的藍翔高級技工學校。



網路安全專家揭露迄今為止最大規模網路攻擊,包括聯合國和國際奧委會在內的全球七十二個機構成為駭客攻擊目標,甚至台灣也難逃網路攻擊的魔爪。

圖為美國國土安全部的分析師在「國家網路安全暨通訊整合中心」(NCCIC)坐鎮。
NCCIC 位於華府近郊阿靈頓,是協調美國網安管理的中樞。 (路透檔案照)

中國網攻新戰法 拿台灣試刀
(自由時報 2011/08/04 記者羅添斌 綜合報導 原始新聞連結)

美國資安業者「邁克菲」(McAfee)發現歷來最大規模連環網路攻擊,台灣政府也是受害者,專家並認為中國極可能是幕後黑手。軍方資訊將領昨對此指出,中國網軍每每在研發新式網路攻擊戰法時,會對台灣發動實驗式攻擊,藉以驗證新戰法是否有效,「他們無時無刻都在設法侵入台灣各機關電腦」。

將領指出,中國網軍每年試圖侵入我國官方網站的能量都很大,這些駭客或是網軍,背後一定有國家力量在支撐。

國安局長蔡得勝去年在立法院報告時曾說出驚人數字,指國安局網站從去年一至十月,每分鐘被駭客攻擊達十一點五六次,每個月被攻擊將近五十萬次。網軍的攻擊方式通常會透過第三地迂迴的進攻,中國大陸就是主要攻擊來源。

中國解放軍在去年七月設立直屬於總參謀部的「信息保障基地」,儘管中國官方撇清這個基地並非外界指稱的「網軍司令部」,但國際間仍認為中國網軍不僅實質存在,位階也不斷提升,已成司令部層級。

我建立防駭機制 防不勝防

台灣軍方早在十餘年前,就針對反制來自內部及外部的「駭客」入侵行為,建立資訊安全機制實驗室、構建防火牆及防毒、應變等安全機制,及建立入侵偵測機制,以模擬駭客攻防及電腦病毒危機應變能力,強化資訊安全。

資訊將領表示,中國駭客及網軍侵入台灣網站,意圖癱瘓或是竊取我方機密資料的量實在是太大了,真是防不勝防,例如在二○○四年七月間,軍方軍聞社網站就曾遭到疑似是中國駭客的入侵,將各新聞標題改貼「二○二○統一台灣!」等字眼。

通資將領表示,二○○三年期間,我國有八十八家政府機構與企業同時遭到駭客入侵的事件,經資安單位聯手調查後發現,對方最上層主機位於中國湖北和福建兩地,判斷可能為中國軍方所發動,目的就是在竊取資料及擾亂台灣社會秩序。

通資將領說,中國軍方在二○○一年與美軍發生EP3軍機擦撞事件後,中國網軍就大量對包括美國等國家實施網路攻擊,由於收穫豐碩,讓中國網軍及駭客對資訊攻擊作戰信心大增,中國軍方也將此做為重點發展項目,「台灣更成為各項新戰法的實驗對象」。
 

Monday, May 02, 2011

News: 歐巴馬:賓拉登被美軍槍擊死亡

新頭殼 newtalk 2011.05.02 林禾寧 綜合外電 原始新聞連結

美國總統歐巴馬在美東時間星期日(1日)晚間(台灣時間 2 日早上 11 時 30 分左右)宣佈, 蓋達組織領導人賓拉登(Osama bin Laden)已經在巴基斯坦被美軍擊斃。

歐巴馬在美國白宮的這場電視演說中表示,美軍依據情報單位所提供的消息,在上週和賓拉登藏身地的巴基斯坦當局合作,發動地面攻擊將賓拉登擊斃。歐巴馬也證實,目前賓拉登的遺體在美國的掌握之中。

歐巴馬指出,美國情報單位和軍方在去年 8 月首次向他通報獲得賓拉登下落的消息,發現賓拉登藏身於巴基斯坦境內;他在上星期批准美軍對賓拉登藏身地點所展開的攻擊行動。

歐巴馬強調,美國人民已容忍賓拉登 10 年了,這次賓拉登被狙擊死亡,可說是「正義的制裁」,但美國的反恐行動尚未結束。


新頭殼網站圖片來源:達志影像/路透社。

賓拉登被擊斃的消息傳開後,有不少美國民眾聚集在美國白宮外高喊「美國!美國!」的口號,慶祝恐怖組織蓋達領導人遭美軍擊斃的消息。

據 BBC 報導,前美國總統布希表示,賓拉登被擊斃是一項「重大成就」。前總統柯林頓也認為,賓拉登的死訊,對全世界渴望和平、自由的人士來說,都是重要的時刻。

2001 年美國遭受 911 恐怖攻擊以來,美國一直在追捕賓拉登等基地組織領導人。美國官員始終相信賓拉登藏身在阿富汗和巴基斯坦邊界的崇山峻嶺中。經過近 10 年的追補,終於在上星期擊斃賓拉登。


Monday, March 07, 2011

News: 中國論文量世界第一 濫竽充數

【中央社 2011-03-07 原始新聞連結】

  中國大陸論文數量世界第一,但引用率極低,排在全球 100 名外。大陸國家統計局前局長李德水呼籲,盡快改革大陸科研體制和對科研人員評價考核機制,絕不能以發表多少論文去論英雄。綜合大陸媒體報導,全國政協經濟委員會副主任李德水在大陸全國政協11屆4次會議記者會上,提出上述呼籲。

  李德水說,「我想跟大家說兩個第一,中國大陸現在有兩個世界第一。一個是研發人員,到2009 年年底,我們有 318 萬 4000 名研發人員、科技人員,這是世界第一,超過美國;一個是近年來我們科研人員發表的期刊、論文數量已經超過美國,居世界第一。」李德水進一步說,「但是這些論文平均引用率卻排在世界 100 位之後。」

  此外,也有人大代表指出,中國目前尤其缺乏高品質的自然科學論文,應當注意到中國「SCI」(科學引文索引)數字光環背後,存在數據造假、剽竊、抄襲等諸多問題。「大躍進」般發表「SCI」論文和「跑獎」,是一種惡劣的學術生態,科研品質和可信度堪憂。他們呼籲提高品質,去除對論文發表的崇拜。「我國現在論文數量世界領先,引用率排名很低。尤其高質量的自然科學方面論文還很少。」中國電子科技集團第五十四研究所副總工程師張學慶說。

  「學術造假之所以屢禁不止,和現行的科研評價體制和管理機制有關。」安徽師範大學生命科學學院教研室主任朱國萍說,當前「SCI」論文數量是很多科研機構和大學考核評價學術成果的主要標準,與職稱評定、科研經費等掛鉤。

  近年來,論文抄襲、學術造假、剽竊在中國大陸屢禁不止:上海交大被曝「漢芯造假門」;井岡山大學講師鐘華和劉濤發表在國際學術期刊「晶體學報」的 70 篇論文存在造假現象,全部遭到撤銷;「浙江大學學報(英文版)」接到的投稿有31%涉及抄襲;而今年西安交大李連生所獲國家科技進步二等獎也因涉及 30 多處造假剽竊被撤銷。

  中國科協書記處書記馮長根曾經發表文章批評,中國學術論文存在 6 個問題:引言籠統、不介紹同行工作、參考文獻太少、缺乏研究過程、缺乏原創、不介紹已有成果。中國學術論文引用率低的4大原因是浮躁風、傳統文化的影響、科學歷史、科學技術上不成熟。

  長江日報 2010 年一篇報導引述一項研究顯示,包括非法期刊在內,買賣論文在大陸已形成產業,2009 年規模達人民幣 10 億元。武漢大學資訊管理學院副教授瀋陽和他的團隊展開 3 年多的買賣論文與非法學術期刊專題研究,用反剽竊軟體查詢,2007 年的樣本數據中,72% 的文章是全文抄襲,24% 的論文部分抄襲,只有 4% 的文章不存在抄襲。

  在美國國家實驗室的大陸訪問學者孫博士告訴電視台,中國大陸學術界充斥著種種亂象,論文剽竊抄襲只是腐敗的冰山一角。

  「北京青年報」今天刊登署名李然的評論,指出寫論文在中國寫成了一個產業,這大概也是世界第一的,可是,這個產業再繁榮,也與學術科研水準關係不大,改變這種現象的呼聲已經存在多年,但一直都沒有看到什麼轉變,

  評論說,當賈伯斯(Steve Jobs)的蘋果 (AppleInc)公司依靠科技創新一輪又一輪地收割世界的時候,「我們不能靠堆積成山的論文和山寨手機來證明自己在努力,解放創新能力勢在必行,不能再以科研的名義發展論文產業了。」
 

Thursday, February 17, 2011

FBI: Spies Hid Secret Messages on Public Websites

[Wired Original Link]
# By Noah Shachtman
# June 29, 2010 1:11 pm
# Categories: Spies, Secrecy and Surveillance



Moscow communicated with a ring of alleged spies in America by encoding instructions in otherwise innocent-looking images on public websites. It’s a process called steganography. And it’s one of a slew of high-tech and time-tested methods that the deep-cover agents and their Russian handlers used to pass information — from private Wi-Fi networks to buried paper bags.

Steganography is simultaneously one of the oldest methods for secret communications, and one of the more advanced. The process dates back to the fifth century B.C., when the Greek tyrant Histiaeus shaved the head of one of his servants, tattooed a message on his head, and waited for his hair to grow back before sending the messenger out. When the courier arrived, his head was shaved and the missive was read, giving information about upcoming Persian attacks. Later on, secret inks were used on couriers’ backs. Morse code messages were woven into a sweater that was worn by a courier.

As information went digital, steganography changed. Messages could be hidden in the 1s and 0s of electronic files — pictures, audio, video, executables, whatever. The hidden communications could even be slowly dribbled into the torrent of IP traffic. Compression schemes — like JPEG for images or MP3 for audio — introduce errors into the files, making a message even easier to hide. New colors or tones can be subtly added or removed, to cover up for the changes. According to the FBI, the image above contains a hidden map of the Burlington, Vermont, airport.

Both before and after Sept. 11, there were rumors in the media that al-Qaida had begun hiding messages in digital porn. That speculation was never confirmed, as far as I can tell.

The accused Russian spy network started using steganography as early as 2005, according to the Justice Department’s criminal complaint against the conspirators, unsealed yesterday in Manhattan. In that year, law enforcement agents raided the home of one of the alleged spies. There, they found a set of password-protected disks and a piece of paper, marked with “alt,” “control,” “e,” and a string of 27 characters. When they used that as a password, the G-Men found a program that allowed the spies “to encrypt data, and then clandestinely to embed the data in images on publicly available websites.”

The G-Men also found a hard drive. On it was an address book with website URLs, as well as the user’s web traffic history. “These addresses, in turn, had links to other websites,” the complaint notes. “Law-enforcement agents visited some of the referenced websites, and many others as well, and have downloaded images from them. These images appear wholly unremarkable to the naked eye. But these images (and others) have been analyzed using the Steganography Program. As a result of this analysis, some of the images have been revealed as containing readable text files.”

These messages were used to arrange meetings, cash drops, deliveries of laptops and further information exchanges. One of the steganographically hidden messages also directed the conspirators to use radiograms — a decades-old method to pass information, long discredited in spooky circles.

“The FBI must have been clapping its collective hands when it discovered the primitive radio techniques the Russians were using: high-speed ‘burst transmissions,’” writes SpyTalk’s Jeff Stein. “The Cold War-era technique requires the sending party to record a coded Morse code message on a tape, then shoot it through the air in a millisecond. They were easy picking for the FBI, once it knew where to listen.”

According to the FBI, bugs in the spies’ homes picked up “the irregular electronic clicking sounds associated with the receipt of coded radio transmissions.”

“Likewise, you’d think the Russians would have moved beyond buried paper bags to pay their agents. Moscow Center did supply them with ATM cards, according to the FBI's affidavit. But it also seems stuck with the old ways,” SpyTalk adds.

But maybe not. “METSOS secretly buried some of the money in upstate New York,” the FBI affidavit says, referring to one of the defendants, “and two years later, in 2006, the Seattle Conspirators flew to New York and dug it up.”

Tuesday, November 30, 2010

MP3 Frame Size and Frame Length

最近在閱讀有關 MP3stego 的相關論文, 由於 MP3stego 基本上是將機密藏在 Frame Length 之中, 因此上 Google 搜尋了一些 MP3 規格書的相關訊息。由於 MP3 規格書 (MPEG I Audio: ISO/IEC 11172-3, MPEG II Audio: ISO/IEC 13818-3) 必須要付費購買才拿得到, 所以只好從其他網頁中尋求相關訊息。

在 MPEG AUDIO FRAME HEADER 這個網頁之中, 有一段文章非常值得參考, 如下:
How to calculate frame length

First, let's distinguish two terms frame size and frame length. Frame size is the number of samples contained in a frame. It is constant and always 384 samples for Layer I and 1152 samples for Layer II and Layer III. Frame length is length of a frame when compressed. It is calculated in slots. One slot is 4 bytes long for Layer I, and one byte long for Layer II and Layer III. When you are reading MPEG file you must calculate this to be able to find each consecutive frame. Remember, frame length may change from frame to frame due to padding or bitrate switching.

從上文中, 我們知道一個 MP3 frame 中, 固定有 1152 個 samples。

接下來, 如果我們從 Header 中讀到 Audio 的 BitRate = 128000 Bit/Sec, SampleRate = 44100 Sample/Sec. 我們就可以去大概計算出平均一個 frame 被壓縮成多少個 byte?
每秒取樣 44100 個 samples, 每個 frame 有 1152 個 samples,
所以, 一秒鐘有 44100 / 1152 = 38.28125 個 frame。
每秒鐘只能壓縮成 128000 bits = 16000 bytes。
因此, 每個 frame 平均可以分配到 16000 Bytes / 38.28125 frames = 417.96 Bytes。
Frame Length = 417.96 Bytes。
化成公式的模樣就是:
FrameLengthInBytes = 144 * BitRate / SampleRate + Padding
有關公式中的 Padding, 指的是額外加的一些 Bytes, 目的是使得 Frame Length 剛好符合 BitRate 的設定。在 網頁 中有一段說明如下:
Padding is used to fit the bit rates exactly.
For an example: 128k 44.1kHz layer II uses a lot of 418 bytes and some of 417 bytes long frames to get the exact 128k bitrate.
For Layer I slot is 32 bits long, for Layer II and Layer III slot is 8 bits long.

 
 

Wednesday, November 17, 2010

MP3stego Offical Website

MP3stego 是一套能將文字檔 (副檔名為 .txt) 藏入音訊檔 (副檔名為 .wav) 的隱藏工具, 藏有機密訊息的音訊檔儲存為 MP3 格式(MPEG Audio Layer III format)。

官方網站: http://www.petitcolas.net/fabien/steganography/mp3stego/
發表日期: August 1998


作者: Fabien Petitcolas,
畢業於 the University of Cambridge,
指導教授是 Prof. Ross Anderson。

F. Petitcolas 也是第一本有關 steganography 書籍 "INFORMATION HIDING techniques for steganography and digital watermarking" 的共同作者。

目前在 Microsoft Research 工作。

Friday, October 01, 2010

News: Google 發表影像壓縮新技術 取代過時的 JPEG

數位時代網站新聞精選 原始連結
撰文者: 戴佳慧 日期:2010/10/01

一向以完美網頁瀏覽體驗為己任的 Google 再出新招!今天 Google 在 Chromium 官方部落格上發表了一種全新影像格式 WebP,能大幅改善網頁圖檔的傳輸效能。經過 WebP 壓縮的影像,檔案大小比常見的 JPEG、GIF、PNG 格式平均減少了 39%,色調和色彩演繹相較之下也毫不遜色。

Chromium 部落格指出,今日的網頁傳輸有 65% 用在影像和照片下載。在行動網路和頻寬有限的情況下,使用者點開網頁之後,還要耐心等待圖片緩緩展開。為了提供使用者更順暢、更愉快的網頁瀏覽經驗,Google 利用全新壓縮技術 VP8 設計了一套新的影像壓縮格式 WebP,大幅減少圖檔大小,讓網頁下載更迅速。

VP8 原本是由美國上市科技公司 On2 所開發出來的視訊壓縮格式,Google 在今年年初收購了On2,接著在五月開放 VP8 技術原始碼。Google 看出 VP8 技術在圖像失真壓縮上也大有可為,足以取代過時的 JPEG、GIF 格式等早年研發成果,因此將 VP8 稍加改編之後推出了新的 WebP 影像格式。

Google 隨機在網路上找了一百萬張圖片作測試,比較 WebP 和傳統格式的壓縮效能和畫質,並分享了幾中幾張圖片讓網友們參考。Google 網站上也提供了轉換軟體,能夠將各種格式的圖片輕鬆轉換成 WebP 檔,歡迎網友們一同試用比較。