Acceleratedlulzsec
lulzsec 时间:2021-03-27 阅读:(
)
SecurityTrends2012Hackingisinherentlyinnovative.
Thismeanssecurityteams,likeMr.
Gretzky,needtokeeptheireyeonwherethingsaregoing–notjustonwherethey'vebeen.
As2012approaches,securityhasevolveddramaticallyfromjustoneyearago.
Theword"hacktivism,"forexample,isalmostahouseholdterm.
Likewise,thegroupAnonymousisanythingbut.
Indeed,cybersecurityremainsoneofthemostdynamicandfluiddisciplinesworldwide.
Imperva'sApplicationDefenseCenter(ADC),ledbyImpervaCTOAmichaiShulman,isexclusivelyfocusedonadvancingthepracticeofdatasecuritytohelpcompaniesshieldthemselvesfromthethreatofhackersandinsiders.
For2012,theADChasassembledacomprehensivesetofpredictionsdesignedtohelpsecurityprofessionalspreparefornewthreatsandattacksincyberspace.
HackerIntelligenceInitiative,MonthlyTrendReport#6December2011Trend#9:SSLGetsHitintheCrossfireTrend#8:HTML5GoesLiveTrend#7:DDoSMovesUptheStackTrend#6:InternalCollaborationMeetsItsEvilTwinTrend#5:NoSQL=NoSecurityTrend#4:TheKimonoComesOffofConsumerizedITTrend#3:Anti-SocialMediaTrend#2:TheRiseoftheMiddleManTrend#1:Security(Finally)TrumpsComplianceAgoodhockeyplayerplayswherethepuckis.
Agreathockeyplayerplayswherethepuckisgoingtobe.
–WayneGretzky2Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#9:SSLGetsHitintheCrossfireWhileagrowingnumberofwebapplicationsaredeliveredovertheHTTPSprotocol(HTTPoverSSL),attackersareincreasinglyfocusingtheirattacksagainstthevariouscomponentsofSSL.
WeareseeingariseinattackswhichtargettheworldwideinfrastructurethatsupportsSSL.
Weexpecttheseattackstoreachatippingpointin2012which,inturn,willinvokeaseriousdiscussionaboutrealalternativesforsecurewebcommunications.
Ironicallyenough,whileattackersarekeepingbusyattackingSSL,theyarealsoabusingitsprivacyfeaturesinordertoconcealtheirownmischievousdeeds.
WethereforeexpecttoseemoregeneralpurposewebattacksbeinglaunchedoverSSLconnections.
First,alittlebackgrounder.
TheSecureSocketsLayer(SSL)1cryptographicprotocolisthedefactostandardforprovidingdataintegrityandconfidentialityforwebtransactionsovertheInternet(sometimesSSLisusedinterchangeablywiththetermHTTPSwhichistheapplicationofSSLprotocoltoHTTPtraffic).
SSLencryptspiecesofapplicationlayerdataoverTCPconnectionsprovidingconfidentiality.
Itcanalsobeusedtotestfortheidentityoftheserver,theclientorboth.
SSLusesanefficientcryptographicalgorithmforencryptingdataandacomputationalintensiveprotocolforauthenticationandkeyexchange(thekeyisusedbytheencryptionalgorithm).
ThekeyexchangeprotocolemploysasymmetriccryptographyamethodologythatrequirestheexistenceofaworldwidePublicKeyInfrastructure(PKI).
PKIdefinesaprocedureforbindingdigitalcertificateswithrespectivewebsitesbymeansofachainofCertificateAuthorities(CA).
Thebindingisestablishedthrougharegistrationandissuanceprocessthatensuresnon-repudiation.
Inthelastcoupleofyears,wehaveseenagrowingawarenessforattacksagainstconfidential(e.
g.
Firesheep)andauthenticity(ManintheMiddleattacks,Phishing).
Asaresult,webapplicationownersareconstantlyextendingtheuseofSSLtomoreapplications,andtomorepartsoftheirapplications.
AgoodexampleistheevolutionoftheGoogleinterface.
Atfirst,onlytheloginpagewasencrypted.
Inthenextstage,thewholeGmailservicesupportedencryption–bydefault.
GooglehasnowevenaddedthesearchfunctionalitytobeaccessedviaHTTPS.
WiththegrowingusageofSSL,attackersareincreasinglytargetingtheSSLlayer.
Unfortunately,mostoftheresearchcommunityisfocusedonpointingoutinherentprotocolvulnerabilities,orcommonimplementationmistakesthatcouldpotentiallybeattacked.
While,theattackercommunityisfocusedonother,morepracticaltypesofattacks:AttacksagainstPKI.
Overthepastyear,attackershaverepeatedlycompromisedvariousCAorganizations.
Theseinclude,DigiNotar,GlobalSign,StartSSL,ComodoandDigicertMalaysia.
Theseattackswereadirectconsequenceofthecommoditizationofcertificates,wheresmaller,lesscompetentorganizationshavestartedtoobtainabiggershareintheCertificateAuthoritymarket.
Asitstandsnow,anyCAcanissueadigitalcertificateforanyapplication–withoutanyrequiredconsentfromapplicationowner.
Ahacker,whogainscontrolonanyCA,canthenuseittoissuefraudulentcertificatesandimpersonateanywebsite.
Additionally,thereareconcernsthatsomerootCAs(whosetrustishardcodedintobrowsersoftware)areinherentlydubious(e.
g.
controlledbyunfriendlygovernments).
SomeeffortsaremadetoamendPKIissuesbuttheyarefarfrombroadacceptance2.
Thetheftofissuedcertificates.
Webelievethisattackwillprevailoverthenextyearasapplicationcertificatesarenolongerlimitedtobeingstoredbytheapplication.
ThisistheconsequenceofthemonolithicnatureofSSL.
WhileSSLpreventsaccesstotrafficbyattackersithasnobuilt-inmechanismsthatrestrictaccesstoitbycollaborative3rdparties.
Forexample,proxies,loadbalancers,contentdeliverynetworks(CDNs)needtoaccessthecertificate'sprivatekeyinordertoaccessapplicationdata.
AlsoDLPandWAFsolutionsrequiresimilarkeyaccess.
Inthesecases,itwouldbepreferablethattheintermediateproxieswouldbeabletolookatmessageheaders,ortobeabletoreadtrafficwithoutchangingit.
However,thisgranularityisnotsupportedbySSL.
Asaresult,thedigitalcertificateisnowstoredinmanylocations–someresidingoutsideofthesite'sphysicalenvironmentandoutoftheapplication'sownercontrol.
Theseopenupadditionalattackpointswhichprovidehighersuccessratesforattackers.
1SSLperseisnowobsoleteandreplacedbytheTransportLayerSecurity(TLS)protocol.
HoweverSSLisstillthecommonlyusedterm.
2Anotherworthyexampleistheconvergenceprojecthttp://convergence.
io/3Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportDenialofServiceattacks.
TheheavycomputationalburdenincurredbytheSSL-handshakeprocessleavesSSL-protectedresourcesprimecandidatesforeffectiveDenialofService(DoS)attacks.
Togetherwithanincreasedconsumptionofcomputerresourcespersession,amultitudeofsimpleattackscanbedevisedveryefficiently.
InadditiontotheattacksagainstSSLanditsinfrastructure,hackerswillleverageSSLtocarryouttheirattackswithincreasedconfidentiality.
Forexample,intermediateproxiescannotaddheaderstoindicateoriginalsenderIPaddress–leadingtothelossoftraceability.
AnotherproblemisthelossofinformationwhenfollowingalinkfromanSSLpagetoanon-SSLpage.
AnattackercanexploitthisimplementationinordertocoverthetracksofvariousWebattacks.
Furthermore,manysecuritydeviceswhichrequireinspectionoftheWebtrafficlosethissortofvisibilityduetotheencryptionofthetraffic.
Trend#8:HTML5GoesLiveOverthelastfewyearsvulnerabilitiesinbrowsers'add-ons(thirdpartycomponentssuchasadobe'sFlashPlayerorOracle'sJava)werethemaincausefor"zero-day"exploits.
Theseareun-patchedapplicationvulnerabilitiesthatareexploitedinordertoinstallmalwareonwebusers'machines.
Wepredictin2012hackerswillshifttheirfocustoexploitingvulnerabilitiesinthebrowsersthemselvesinordertoinstallmalware.
Thereasonisduetorecentlyaddedbrowserfunctionality–mainlydrivenbytheadoptionofHTML5standard.
TheHTML5standardwascreatedtoenablebrowserstosupportaricherenduserexperienceinastandardizedway.
Mostnotably,HTML5addssupportforaudio,video,2Dgraphics(SVG),3Dgraphics(WebGL)thatpreviouslyrequiredtheendusertoinstalladedicatedadd-on.
(e.
g.
AdobeFlashPlayertowatchonlinevideo).
Whilethenewfeaturesareattractivetowebdevelopers,theyarealsoverybeneficialforhackers.
Weseesecurityrepercussionsforthefollowingreasons:1.
Newcodeisgenerallymorevulnerable.
Whenyouwritecodeyouaredoomedtocreatebugsandsecurityvulnerabilitiesalongwithit.
Whenyouaddalotofnewcode–youaredoomedtocreatealotofnewvulnerabilities.
2.
Compressedmediatypesaremorevulnerable.
Modernmediatypes(suchasvideo)areusuallyhighlycompressedandoptimizedtoensuretheefficiencyoftheirtransmissionanddisplay.
Decompressinginvolvesalotofbuffermanipulationswhicharenotoriouslyvulnerable.
3.
Hardwareaccess.
Manybrowsersusetheassistanceofhardwarecomponents3–mainlyforJavascriptandgraphicsacceleration–inordertoachievehigherefficiencyandcreateasmootheruserexperience.
Sincehardwareisrununderhighpermissionaccesslevels,andusuallycannotbeprotectedbytheoperatingsystems,exploitstargetingthehardwarecomponentsareveryattractivetoattackers.
Thistypeofprivilegedaccessprovidestheattackerswithamethodtoexploitbuggyhardwaredriversstraightfromawebpage.
4.
Enduserscontrol.
Currently,mostbrowserscontainamechanismwhichturnsoffavulnerablebrowseradd-on.
InthecaseofHTML5,theimplementationisembeddedwithinthebrowsersothatavulnerableadd-onmightnotnecessarilybeturnedoff.
Attheveryleast,itchangesthesecuritymodelfrom"optin"model(activelydownloadanaddon)to"optout"(disableanexistingcomponent.
)5.
Javascriptcontrol.
NewHTML5featurescanbecontrolledandmanipulatedviaJavascript.
ThisgivesrisetonewvectorsofJavascript-relatedattacks(mainly,buttonotlimitedto,XSS).
Thesenewattackvectorswillusethenewelements,andtheinteractionsbetweenthem,inordertobreakthealreadyfragileSameOriginPolicy(SOP).
FormoreonSOP,clickhere.
6.
Ubiquity.
It'smuchmorecost-effectivetocreateacrossbrowserexploitthantocreateanexploitaimedataspecificone.
TheubiquityofHTML5providesthemwithjustthat.
3MicrosoftAnnouncesHardware-AcceleratedHTML5http://www.
microsoft.
com/presspass/press/2010/mar10/03-16mix10day2pr.
mspx4Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#7:DDoSMovesUptheStackDistributedDenialofService(DDoS)attacksaregainingpopularityandwerepartofhighprofilehackingcampaignsin2011,suchastheAnonymousattacks4.
Wepredictthatin2012attackerswillincreasethesophisticationandeffectivenessofDDoSattacksbyshiftingfromnetworklevelattackstoapplicationlevelattacks,andevenbusinesslogiclevelattacks.
ADenialofService(DoS)isarelativelyoldattackaimedatdataavailabilitybyexhaustingtheserver'scomputingandnetworkresources.
Consequently,legitimateusersaredeniedservice.
ADistributedDenialofService(DDoS)isanamplifiedvariationoftheDoSattack,wheretheattackerinitiatestheassaultfrommultiplemachinestomountamorepowerfulandcoordinatedattack.
Today,DoSattacksrequiretheattackertoinvestinamassivelydistributednetworkwhichcancreateenoughtraffictoeventuallyoverwhelmthevictim'sresources.
AttheotherendoftheDoSspectrum,there'stheSQLshutdowncommand.
Anattackerexploitinganapplicationvulnerabilitycanusethisparticularcommandtoshutdowntheserviceusingjustasinglerequest,initiatedfromasinglesource,which,fromtheattacker'sperspective,provescheaperandisjustaseffective.
Historically,wehaveseenDoSattacksgraduallyclimbuptheprotocolstack.
FromthemostbasicNetworklayer(layer3)attacks,suchastheUDPFlood,throughtheTransportlayer(layer4)withSYNfloodattacks.
Inthelastyears,wealsosawtheHTTPlayer(layer7)beingtargetedwithsuchattacksastheSlowloris5(in2009)andRUDY6(2010)attack.
Wepredictthatin2012wewillseehackersadvanceonemorerung.
ThismeanscreatingDDoSattacksbyexploitingwebapplicationvulnerabilities,oreventhroughwebapplicationbusinesslogic7attacks.
Indicationsforthistrendarealreadyemerging.
Forexample,the#RefReftool8,introducedinSeptember2011,exploitsSQLinjectionvulnerabilitiesusedtoperformDoSattacks.
Thereareseveralreasonsattackersaremovingupthestack:1.
Decreasingcosts.
Inthepast,attackershavetakenthe"brawnoverbrains"attitude.
Thismeantthattheysimplyinundatedtheapplicationwithgarbage-likerequests.
However,thesetypeofattacksrequirealargeinvestmentontheattacker'sside,whichincludedistributingtheattackbetweenmultiplessources.
Intime,hackershavediscoveredthattheycanadd"brains"totheirattacktechniques,significantlyloweringtheheavycostsassociatedwiththe"brawn"requirements.
2.
TheDoSsecuritygap.
Traditionally,thedefenseagainst(D)DoSwasbasedondedicateddevicesoperatingatlowerlayers(TCP/IP).
Thesedevicesareincapableofdetectinghigherlayersattacksduetotheirinherentshortcomings:theydon'tdecryptSSL,theydonotunderstandtheHTTPprotocol,andgenerallyarenotawareofthewebapplication.
Consequently,theattackercanevadedetectioninthesedevicesbymovinguptheprotocolstack.
3.
TheubiquitousDDoSattacktool.
WorkingovertheHTTPlayerallowstheattackertowritecodeindependentoftheoperatingsystem.
Forexample,byusingjavascript.
Theattackerthengainstheadvantageofhavingeverywebenableddeviceparticipateintheattack,regardlessofitsoperatingsystem–beitWindows,MacorLinux.
Moreso,itallowsmobiledevices-runningiOS,Android,oranyothermobileoperatingsystem–toparticipateinsuchattacks.
Thegoodnewsisthatenterprisescanpreparethemselvesagainsttheseapplication-targetedDoSattacks.
HowByaddingapplication-awaresecuritydevices,suchasWebApplicationFirewalls(WAFs).
ThesedevicescandecryptSSL,understandHTTPandalsounderstandtheapplicationbusinesslogic.
TheycanthenanalyzethetrafficandsiftouttheDoStrafficsothateventually,thebusinessreceives–andserves–onlylegitimatetraffic.
4http://thelede.
blogs.
nytimes.
com/2010/12/08/operation-payback-attacks-visa/partner=rss&emc=rss5http://ha.
ckers.
org/slowloris/6http://www.
slideshare.
net/AlesJohn/owasp-universalhttpdo-s-92072897Webapplicationlogicattackcanbeperformedbyprofilingthevictimwebapplicationforresourceconsumingoperations(suchassearchingalargedatabase)andthenconstantlyapplyingthatoperationtodepletethevictimserverresources.
8http://www.
refref.
org/5Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#6:InternalCollaborationMeetsItsEvilTwinWeexpecttoseeagrowingnumberofdatabreachesfrominternalcollaborationplatformsusedexternally.
WhyInternalcollaborationsuitesarebeingdeployedin"eviltwin"mode,i.
e.
,thesesuitesgetusedexternally.
Asaresult,organizationwilllookfortoolstoprotectandcontrolaccesstosuchplatforms.
Weestimatethatin2012thenumberofInternetsitesbasedonsuchplatformswillincreasedramatically.
Asaconsequence,thenumberofsecurityincidentsduetoinadvertentpublicexposureofconfidentialdatawillgrow.
Thepastcoupleofyearsbroughtupanextensiveincreaseintheuseofcollaborationsuiteswithinorganizations.
PlatformssuchasMicrosoftSharePointandJivearenowusedbymanyorganizationstoshareinformationandmanagecontent.
Whilemostenterprisesusetheseapplicationswithintheorganization,somehavealsoextendedtheusetopartnersandeventothepublicthroughaninternetfacingwebsite.
Infact,basedonForresterresearch,SharePointislistedasthenumberoneportalproduct(source:http://www.
topsharepoint.
com/about)andwiththelatestreleaseofSharePoint2010,italsooffersagreatplatformforbuildingcollaborationsiteswithexternalpartnersorrobustexternally-facingsites.
Extendinganinternalplatformtoexternalusealwayscomeswithapricetagtobepaidinsecurity.
AnexampleofsuchsecuritybreachtookplacewhentheMississippinationalguardaccidentallyexposedpersonalinformationofnearly3000soldiersontheirexternalMicrosoftSharePointwebsite(source:http://www.
itbusinessedge.
com/cm/community/news/sec/blog/national-guard-data-exposed-in-accidental-security-breach/cs=43893)Therearetwomajorfactorsthatimpacttheriskofextendinganinternalplatformtoexternaluse:1.
Datasegregation.
Datasegregationhastwomanifestationswithrespecttoexternalizinginternalsystems.
Ensuringthatthestoredsensitivedatadoesnotbecomeaccessiblethroughthelessrestrictedinterfacesoftheplatformisnotaneasytask.
Fortheentirelifetimeofthesystems,controlsshouldbeputinplacetoallowcollaborationandsharingofsensitiveinformationwithintheorganizationwhilekeepingitoutofthereachofthegeneralpublic.
2.
Threatprofile.
Threatprofileisrelatedtothedifferencebetweeninternalandexternalthreats.
Thesizeofpotentialattackerpopulationincreasesinstantaneouslyaswellasthetechnicalandhackerskillsofit.
Atthesametime,theimpactofadisclosureorabreachincreasesdramaticallyoverthatofaninternalbreach.
Tomakethingsevenworse,searchengineslikeGoogleconstantlycrawlandupdatetheirindexingpoliciessothatthepublicinterfaceoftheapplication,aswellasanybreachesormis-configuredentrypointsarequicklyapparenttothewholeworld.
Forexample,anupdatedGooglepolicytoindexFTPserversresultedinabreachaffecting43,000Yale-affiliatedindividuals.
Googlehackingtools,suchasSharePointGoogleDiggityandSharePointURLBrute,caneasilybeusedtoidentifyinsecureconfigurations.
Organizationsaimedatreducingtheriskofmassiveexposuresshouldstartbudgetingandplanningforthenextgenerationofcollaborationsuitemonitoringandgovernancetools.
Someofthecharacteristicstolookforare:Policiestomonitorandprotectinternetandintranetfacingsites.
Flexibledeploymentthatdoesn'timpacttheuseofapplicationorthenetworkarchitecture.
Theabilitytoidentifyexcessiveuserrightstocontent.
6Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#5:NoSQL=NoSecurityTheITworldisquicklyembracingBigData.
Hugedatastoresarethenextbigstepinanalyzingthemassiveamountsofdatathatisbeingcollectedinordertoidentifytrends.
Forexample,newstartupsusethesesystemstoanalyzetrillionsofDNAstripstogainanunderstandingofourgenealogy.
Towell-establishedcompanieswhoareadoptingthetechnologytomapandtimetransportationsystemsacrosstheworldtomakeourtravelingeasierandcheaper.
WhileBigDataisbecomingabuzzwordininformationsystems,therehasnotbeenmuchinvestigationintothesecurityimplications.
Manypredictthatin2012we'llseeagrowinginterestinBigDataandit'sunderlyingtechnology,NoSQL.
Wepredictthattheinadequatesecuritymechanismsofthesesystemswillinhibitenterprisesfromfullyintegratingthesesystemsasthirdpartycomponentswithinthecorporation.
NoSQLisacommontermtodescribedatastoresthatstorealltypesofdata–fromstructuredtounstructured.
Duetothisdiversity,thesedatastoresarenotaccessedthroughthestandardSQLlanguage.
Upuntilrecently,wecategorizedourconceptionofdatastoresintwogroups:relationaldatabases(RDBMS)andfileservers.
Thenewkidintown,NoSQL,openedourmindstoadatabasethat,unliketheconventionalrelationalconcepts,doesnotfollowastructuralform.
TheadvantageScalabilityandavailability.
Withatechnologywhereeachdatastoreismirroredacrossdifferentlocationsinordertoguaranteeconstantup-timeandnolossofdata,thesesystemsarecommonlyusedtoanalyzetrends.
Thesesystemsarenotsuitableforfinancialtransactionsrequiringareal-timeupdate,butcouldbeemployedatafinancialinstitutiontoanalyzethemostefficientorbusiestbranch.
However,asapplicationsusingNoSQLarebeingrolledout,littletimehasbeentakentothinkorre-thinksecurity.
Ironically,securityindatabaseandfileservershaveseentheirshareofproblemsovertheyears.
Andthesearesystemsthathavegainedmileageovertheyearswhichallowedthistypeofsecurityinspection.
WecannotsaythesameaboutNoSQL.
ManymayclaimthatthedevelopersofdifferentNoSQLsystemshavepurposefullypushedoutsecurityaspectsfromtheirsystems.
Forinstance,Cassandrahasonlybasicbuilt-inauthenticationprocedures.
Thislackofsecurityisconsideredtheirfeatureandbuiltinmindthatdatabaseadministratorsdonotneedtotroublethemselveswithsecurityaspects.
Security,then,shouldbeanoffloadedprocesstobedealtwithbyadedicatedteam.
WebelievetheNoSQLsystemswillsufferfromanumberofissues:Lackofexpertise.
Currently,therearehardlyenoughexpertswhounderstandthesecurityaspectsofNoSQLtechnologies.
WhenbuildingaNoSQLsystem,thereisnoobvioussecuritymodelthatfits.
Thelackofsuchamodelmakestheimplementationofsecurityanon-trivialprocessandrequiresextensivedesign.
Asaresult,securityfeaturesthatneedtobeconsideredgetpushedoutoverandoveragain.
Buggyapplications.
Untilthirdpartysolutionsrollouttoprovidethenecessarysecuritysolutions,itistheNoSQLapplicationsthatwillcarrythesecurityload.
Issuesinclude:Addingauthenticationandauthorizationprocessestotheapplication.
Thisrequiresmoresecurityconsiderationswhichmaketheapplicationmuchmorecomplex.
Forexample,theapplicationwouldneedtodefineusersandroles.
Basedonthistypeofdata,theapplicationcandecidewhethertogranttheuseraccesstothesystem.
Inputvalidation.
OnceagainweareseeingissuesthathavehauntedRDBMSapplicationscomebackandhauntNoSQLdatabases.
Forexample,inBlackhat2011,researchersshowedhowahackercanusea"NoSQLInjection"toaccessrestrictedinformation.
Forexample,"TheWebApplicationHacker'sHandbook:FindingandExploitingSecurityFlaws"containsanewseparatechapterfocusedsolelyonthesecurityofprogrammingframeworksusedforNoSQL.
Applicationawareness.
Inthecasewhereeachapplicationneedstomanagethesecurity,itwillhavetobeawareofeveryotherapplication.
Thisisrequiredinordertodisableaccesstoanynon-applicationdata.
Whennewdatatypesareaddedtothedatastore,thedatastoreadministratorwouldhavetofigureoutandensurewhatapplicationcannotaccessthatspecificdata.
Vulnerability-pronecode.
ThereareacertainamountofNoSQLproducts,butamagnitudemoreofapplicationsandapplicationserverproducts.
Themoreapplications,themorecodeingeneralpronetobugs.
7Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportDataDuplicity.
InNoSQLsystems,dataisnotstrictlysavedinparticulartables.
Instead,thedataisduplicatedtomanytablesinordertooptimizequeryprocessing.
Asaresult,itisnotpossibletoclassifycreditcardsaccordingtoaparticularsensitivetable.
Onthecontrary,thistypeofdatacanbefoundindifferentplaces:transactionlogs,personaldetails,specifictableswhichrepresentsallcreditcards,andotherlocationswhichmayhavenotevenbeenconsidered.
Privacy.
Althoughourfocusisonsecurity,privacyconcernscannotbeignored.
Takeforexampleahealthcareplatformwhereprovidersgettogetherandsharepatientdata.
Apatientmightaccessthesystemforgeneticinformation,andlateraccessitinrespecttodruginfo.
Anapplicationwhichanalyzesthisdatacancorrelatetheinformationtofindpurchasingtrendsrelatingtogeneticsandhealth.
Theproblemisthatthistypeofcorrelationwasnotconsideredwhenthedatawasinitiallyinserted.
Asaresult,thedatawasneveranonymizedallowinganyonetoidentifyspecificindividualsfromthebiggerpicture.
NoSQLisstillinitsinfancy.
Itwilltakeawhileuntilwewillseethesesystemsfullydeployedatthemajorityofenterprises.
Forthisprecisereasonitissoimportanttoinvestintheinthesecurityofthesesystems.
Trend#4:TheKimonoComesOffofConsumerizedITAfterbeingcaughtoff-guardbytheprocessofconsumerizationofIT,professionalsaretryingtoregaincontrolofcorporatedata.
Theproblemisthattheyaredoingitthewrongway.
Insteadoftryingtocontroldataatthesource,ITorganizationstrytoregulatetheusageofend-userdevicesandde-clouddataaccess.
Weexpectorganizationstospendalotoftime,moneyandeffortonthesetechniquesandtechnologiesnextyear–withverypoorresults.
TheconsumerizationofITreferstotheprocessinwhichcorporatedataisincreasinglybeingprocessedbyend-userdevicesandapplicationschosenandprovidedbytheend-usersthemselves.
Smartphones,tabletsandcustompersonallaptopsareleadingthistrendwiththeirincreasingprocessingpowerandstoragecapabilities,combinedwiththeirgrowingdiversityofavailableapplications.
Theseareaugmentedbytheincreaseofaremoteworkforceandindividualswhousehomecomputersandhomenetworksonaregularbasistoaccesscorporateresources.
Thisprocessbyitselfpossesmanychallengestoanorganizationthatarerelatedtothecompromiseofinformationonthedevice(eitherphysicallythroughlossandtheftofthedevice,ordigitallythroughmalware),aswellasthecompromiseofenterprisenetworksthroughacompromiseddevice.
Coupledwiththemoveofcorporatedataintothecloud–wherecorporatedataisstoredoutsideoftheorganization–anevenamoredifficultproblememerges.
Withtheseissuesinmind,theorganizationcompletelylosescontrolovertheentireinteractionbetweenend-usersandcorporatedata.
ThereisagrowingtrendamongITprofessionalstotryandregainthecontrolofend-userdevices.
Throughdifferentmeans,organizationsaretryingtoenforce"proper"usageandsettingsofnon-corporatedevices.
ITdepartmentsareattemptingtoenforcepoliciessuchaspasswordstrength,devicelockupandevenremotewipinginthecaseofdeviceloss.
Forexample,accessthroughtheActiveSyncprotocoltoMicrosofteMailserverscanberestrictedtodevicesthatimplementaspecificsecuritypolicy.
Someenterprisesalsogoasfarastotryandregulatethedevicesthatareallowedtoaccessenterprisedatatothosemodelswhopossescertainsecuritycapabilities.
Weanticipatethatthenextstepwillbetorequirethatcertainsecuritysolutionsbeinstalledonthosedevicesthatareallowedtoconnecttothenetwork(e.
g.
LookoutoranyothermobileAV).
Inordertoreducetheriskofdevicecompromise,enterprisesarealsotryingtoenforceanywebaccessfromthedevicetoberelayedthroughtheenterprisenetworkwhereitcanbemonitoredandcontrolled(which,ofcourse,hassevereimplicationsinthecaseofSSLprotectedwebresources–asexplainedinadifferenttrend).
Further,thisapproachhopestobridgegapthatexistsbetweenuserdevicesandcloudapplicationsthatholdenterprisedata.
Theapproachdescribedaboveisboundtofailforquiteafewreasons.
Mostofthemstemfromoverlookingpastexperienceandhumannature:8Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReport1.
Pastisprologue.
Thepastcoupleofyearshaveshownthatenterprisesarefailingtopreventthecompromiseofenterprisecomputingequipment.
Extendingthescopeoftheproblemtoalargervarietyofdevicesonlymagnifiestheproblem:2.
Maintainingavailability.
Organizationsthatdelegateinformationavailabilityandnetworkaccessibilityissuestothecloudandthentaketheapproachoftunnelingalluserdevicetraffic,aregoingtofacemajornetworkingissues.
Consequently,theywillfindthemselvesspendingtimeandmoneyoncreatingandmaintainingthehighlevelofworldwideavailabilitywhichtheywantedtoavoidinthefirstplace.
3.
Userprivacy.
Thereareunsolvedissuesregardingtheimpacttouser'sprivacyandtheliabilityoftheenterprisetopersonalinformationstoredonthesedevices.
Forinstance,remotewipe-outtoolscannotdifferentiatebetweencorporateandpersonalinformation.
Thisupcomingyear,organizationsaregoingtospendquitealotofmoneyandeffortbeforerealizinghowlittleimprovementthisapproachbringstoenterprisedatasecurity.
Whentheydorealizethefailureofthesemeasures,theyaregoingtolookforadifferentsetofsolutionsthataregoingtobemoretightlycoupledtothedataitself.
Suchsolutionsincludemonitoringrequirementsforaccesstothedatastoresandstrictcontrolofthataccess.
Trend#3:Anti-SocialMediaAsmanymoreorganizationsaremakingtheirwayintothesocialmediaspace,weexpecttoseeagrowingimpacttotheintegrityandconfidentialityoftheenterprise'sinformation.
Moreover,hackerswillcontinuetoautomatesocialmediaattacks,furtherexacerbatingthesituation.
Theheartoftheproblemresidesinthreeseparateissuesinherenttosocialnetworks:1.
Sharing–Themostimportantthingtounderstandaboutsocialnetworksandthetoolsbuiltontopofthemisthattheyaredesignedforsharinginformation–notrestrictingaccesstoit.
Enterprisesthattrytousesocialmediaascollaborationsuitesforinternal,sensitivebusinessdata–whichrequiredifferentlevelsofaccessprivileges–areboundtoencountermassivedatabreaches.
Thereasonisnotduetoflawedaccesscontrolsandprivacymechanisms.
Rather,therestrictionofinformationthroughthesechannelsisincompletecontrasttotheconceptofsuchenvironmentswhichis,infact,allaboutsharing.
Consequently,organizationsshouldkeepanoperationalcopyofalltheirdatainabusinesssystemthatcanprovidedecentaccesscontrols.
Datathatcanbemadepubliccanbeexportedoutofthissystemandpostedtothesocialnetwork.
Thisway,restrictedinformationiskeptinsidebusinesssystems(regardlessofwhethertheyareonpremiseorinthecloud),whilepublicinformationcanberetrievedtopublicationonthesocialplatform.
2.
Control–Organizationsneedtounderstandthatthereisnearlyanabsolutelackofcontroloverinteractionswithmembersofthesocialplatform.
Intherealworldweattempttocontrolthetypesofsocialinteractionsweexperiencebycarefullychoosingoursocialcirclesaswellastheplaceswehangout.
Thisisnotpossibleinthecyberworld.
Commentspam,defamation,falseclaimsandbadlanguagearethenorm.
Keepingyoursocialcyberenvironmentcleanoftheseisadifficulttask.
Further,cybercleansingclaimsresourcesinamannerproportionaltothepopularityoftheenterprise.
Measuresrangefromsiftingandsanitizingcommentstoengagingcloselywiththesocialnetworksincaseofdefamation.
Enterpriseswhofailtoinvesttheseresourceswillquicklyfindthattruefollowersarefleeingthescene.
Inthemeanwhile,thebrandnameerodes–defeatingthepurposeofenteringthesocialnetworkscene.
3.
LackofTrustandProperIdentification–Thereisnorealwayforenterprisestoavoidcopy-cats.
Intoday'ssocialplatforms,thereisnosolidwaytotellaparttherealownerofabrandfromimpostorsandcopy-catswhoaretryingtotakeadvantageofthepopularityofaspecificbrand,toabuseitortoerodeit.
Theidentityofmessageposterscannotbeverifiedinanywayandtherearenorealtoolstoevaluatethetrustworthinessofmessagesandtheircontent.
9Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTheconsequencescouldbegeneralbranderosionorattackcampaignstargetedtowardsenterprise'ssocialcircle.
Mixthesethreeconceptswiththegrowinguseofautomationandyougetsocialnetworkmayhem.
Inthepastcoupleofyearswehavewitnessedtheimpactofthepowerofautomationwhenappliedtosocialnetworks:InFebruary2011,theLovely-Faces.
comwebsiteshowcasedhundredsofthousandsofscrapedFacebookuserprofiles.
InSeptember2011,anothergroupdemonstratedanapplicationthatautomatestheprocessof"friending".
Basedonthisprocess,theapplicationcreatesacollectionofallpersonalinformation,includingphotos,fromthosewhoacceptedthefriendshiprequest.
Recentlyagroupofresearchersdemonstratedthepowerof"socialbotnets".
Thesearefakeprofiles.
However,theseaccountscanautomaticallygrowanetworkoffriendsofactualrealaccounts.
Theresearchprovedthattheflawed"friendofafriend"trustmodelenabledthistypeofbotnetproliferation.
Further,theirresearchfoundthatindividualswerethreetimesmorereceptivetoacceptingafriendshiprequestiftherequesteralreadysharedamutualfriendwiththem.
Softwareautomatingaccountgenerationandvariousdataminingresearchprojectsexist.
ThisFall,DHSstartedsettinguppoliciestomonitorFacebookandTwitter.
Automatingthisprocesswillbeatheartofthisprojectinordertosiftthroughtheincrediblyhighvolumeoftraffic.
Unfortunately,wedonotseeanymarketsolutionsreadytohandletheaboveissues.
Facebookaswellasothersocialmediaplatformprovidersarecurrentlykeepingfullcontrolandareattemptingtofightsomeoftheissues(mainlyautomationandfakeaccounts)fromwithin.
OnesuchinitiativeisFacebook'sImmuneproject.
Thishasproventobemostlyfutilesofar(forinstance,there'saclearconflictofinterestsbetweenFacebook'sattempttoremovefakeaccountsanditsattempttoshowconstantunbelievablegrowth).
Rather,thesolutionsmustbeincorporatedintoexistingplatformsbyenterprisesthemselves.
Thesesolutionswillhavetorelyonthirdpartiesthatoffertrustanddatacontrolservicesoverthesocialmediaplatform.
Currently,wearenotawareofanysuchexistingsolutions,leavingavoidspaceripeforresearch.
Trend#2:TheRiseoftheMiddleManIn2010,wepredictedtheindustrializationofhacking.
Whatistheimpactofindustrializationtohacker'sbusinessmodelsIn2012,withtheincreasedsupplyanddemandforcompromisedmachines,aswellasforsensitivecorporateinfo,wepredicttherisetoanewcybercrimejobrole:thebroker.
Thisindividualisresponsibletomatchthebuyersofstolendata,orcompromisedmachines(aka"bots"),withthesellersofthedata(orbotrenters).
Inthesamewaystocksandinvestorsgaverisetostockmarkets,hackersneedamiddleman.
Thesuccessofbotherdingopenedupalargemarketwherelotsofhackershavemanycorporatemachinesundertheircontrol,eachpotentiallyholdingavastamountofdata.
However,waitingforindividualstoapproachandbuythistypeofdatafromthemissimplytoomuchofaslowandineffectiveapproach–causingthehackerstobeavictimoftheirownsuccess.
Instead,weareseeingthatthissituationactuallyopensupthewholesaleopportunityforamiddlemantobridgethisgap.
10Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#1:Security(Finally)TrumpsComplianceIn2012weexpecttoseesecuritydecisionsdrivennotbycompliancebutforthesimplereasonof.
.
.
security.
Itsoundssimpleenough,butinpreviousyearswehaveseentheinfluxoflawsandregulationswhichdrovethebudgetandsecuritysolutions.
PCI,SOxandworld-wideDataPrivacyActswereallusedasthereasonstofeedthesecuritybudget.
Butthisapproachoftenbackfired.
Anecdotally,whenoneCIOwasaskedaboutthekeylessonfromamajorbreachhisfirmexperiencedanswered,"Securityisnotaboutsurvivingtheaudit.
"Smartcompaniesusedtheseregulationsasspringboardstoenforcethecaseofsecurity.
Infact,botha2011Ponemonsurveyandthe2010VerizonDataBreachReportshowedthatPCIdidimprovetheorganization'ssecuritystance.
However,regulatorycomplianceisnotequivalentanddoesnotconfersecurity.
ItisenoughtoturntoHeartlandPaymentSystemsforsuchanexample.
ThecompanypasseditsPCIevaluation,andyet,theyhadsufferedoneofthebiggestbreachesinhistory.
Thispastyearwehaveseenashiftinthecorporateattitudeforseveralreasons:1.
Breachesarecostly.
SecuritybreachessuchasthosesufferedbyEpsilon,RSAandSonydominatedfrontpagenews.
Thehighprofilebreacheshighlightedtheimpactofsecurity.
Branddamage,lossinbrand,legalcosts,notificationcosts,serviceoutagesandlossinshareholdervalueallbecamenewsoftheday.
Infact,thedayafterSony'sbreachannouncement,thestockpricedroppedsteeply.
DigiNotar,aCAcompanywasbreachedinSeptember(seeSSLtrend)wentunderbellylaterthatmonth.
Whileactualassessmentsofthecostofthesepastyearbreacheshavenotyetbeenmadepublic,wecanreturntotheHeartlandPaymentSystemsbreachforalesson.
FornearlytwoyearsfinancialanalystswatchedaslargelegalpaymentsfordamagesweresettledbeforethemarketcouldfeelcomfortableaboutHeartland'sabilitytostabilizerevenues.
2.
Companieswithanonlinepresence,regardlessofsize,aretargeted.
Notonlywerelargecorporationsaffectedbybreachesinthepastyear.
Hackershavebecomeveryadeptatautomatingattacks.
Accordingtothe2011VerizonDataBreachInvestigationRepot,hackershave"createdeconomiesofscalebyrefiningstandardized,automated,andhighlyrepeatableattacksdirectedatsmaller,vulnerable,andlargelyhomogenoustargets".
Inotherwords,inaworldofautomatedattacks,everyoneis–orwillbe–atarget.
ThispointwasexemplifiedinAugust2011whenUSATodaypublishedthat8millionwebsiteswereinfectedbymalware.
Ourownresearchhighlightshowapplicationsarelikelytobeprobedonceeverytwominutesandattackedseventimesasecond.
3.
Hacktivismbrings(in)securitytothefrontlines.
HackinggroupssuchasAnonymousandLulzsechavereceivedheadlineswhentheyrepeatedlyhackedintodifferentcorporations,largeandsmall.
Visa,Paypal,SonyPictures,Fox.
com,PBS.
orgaswellascountriessuchasTunisia,andgovernmentagenciessuchasInfragardallfeltthehackitivistwrathwhoseattackstargetedapplicationsandinfrastructure.
4.
APTbecomesanactualthreat.
AdvancedPersistentThreats(APT)attacksaresophisticatedattackswhichrelentlesslytargetcorporationsandgovernmentsforespionageanddestruction.
However,withgoodbrandingfromworldwideMarketingandPRteams,thistermhasbecomethealternativedescriptiontoacompromisefollowingacorporate-phishingattack.
Thefearofsuchanattackisboostingthesecuritybudget.
ArecentsurveybyESGindicatedthatduetoAPTconcerns,32%ofrespondentsareincreasingsecurityspendingby6-10%.
5.
Intellectualpropertyrequiresprotection.
Organizationsarebeginningtounderstandtheriskandconsequencesofacompromiseoftheirbreadandbutter.
Thebiggestriskofexposureofintellectualpropertyisactuallycausedunintentionally.
Forexample,throughanemployeeleavingthecompanywithcorporateinfoobtainedrightfullyovertime.
Or,throughamis-configuredserverholdingconfidentialdocuments(seetrendsontheexternalizationofcollaborationplatforms).
Organizationsalsofacetheriskthedeliberatetheftofdatafromvengefulormaliciousemployees.
Forinstance,thispastyearaformerGoldmanSachsemployeereceivedaneightyearsentenceforstealingproprietarysoftwarecode.
Compromiseofintellectualpropertymayevenbeperformedbythehandsofexternalhackers.
Inthepastwesawhowhackersweresolelyfocusedoncreditcardnumbers,logincredentialsandothersuchgenericcommodities.
Althoughthistypeofdataisstillontheattacker'sradar,wearestartingtoseehackersfocusingalsoonintellectualproperty.
Asapointincase,considertheRSAattackwhichinvolvedthedatarelatingtotheSecureIDtokens.
HackerIntelligenceInitiative,MonthlyTrendReportImperva3400BridgeParkway,Suite200RedwoodCity,CA94065Tel:+1-650-345-9000Fax:+1-650-345-9004www.
imperva.
comCopyright2011,ImpervaAllrightsreserved.
Imperva,SecureSphere,and"ProtectingtheDataThatDrivesBusiness"areregisteredtrademarksofImperva.
Allotherbrandorproductnamesaretrademarksorregisteredtrademarksoftheirrespectiveholders.
#HII-DECEMBER-2011-1211rev16.
Shareholdersarenowinvolved.
TheSEChasrecognizedtheimpactofasecuritybreachtoacompany.
Asaresult,recentupdatedSECregulationsrequirereportinginformationsecuritybreachestoshareholders.
Ifinthepastbreachescouldhavebeensweptunderthecarpet,thisregulationwillmakeithardertodoso.
Forthesereasons,wewillincreasinglyseehowcompanieswillperformwisesecuritydecisionsbasedonactualsecurityreasoning.
Furthermore,theabundanceofregulations–whichultimatelytrytosetaminimalbarofsecurity–willmakeittoocostlyfororganizationstohandleonaregulation-by-regulationbasis.
Instead,enterpriseswillimplementsecurityandthenassesswhethertheyhavedoneenoughinthecontextofeachregulation.
ConclusionHowdidwecomeupwiththesetrendsTherewereseveralfactors:Hackers–AsapartofImperva'shackerintelligenceinitiative,wemonitorhackerstounderstandmanyofthetechnicalandbusinessaspectsofhacking.
Theinsightsprovidedfromourinvestigationshelpusseewhathackersaredoingorinthiscase,plantodo.
Insomecases,hackersmakesmalltweakstoexistingattacksorcomeupaltogethernewones.
Thegoodguys–Manyofourcustomersaresmart,reallysmart.
Wemeetwiththemregularlytounderstandtheirchallengesandconcernstounderstandemergingtrends.
Weatherballoons–Wemonitortrafficincyberspace.
Thishelpsusunderstandstatisticallyhowhackersmaybeshiftingfocusregardingattacks.
Intuition–ManyintheADChavebeeninsecurityformanyyearsintheprivatesector,themilitaryandacademia.
We'veseenalotinthoseyears.
Ourhopeistogivesecurityteamsacomprehensive,substantivesetofpredictionstohelpyouprioritizeyoursecurityactivitiesforthecomingyear.
Besafe!
HackerIntelligenceInitiativeOverviewTheImpervaHackerIntelligenceInitiativegoesinsidethecyber-undergroundandprovidesanalysisofthetrendinghackingtechniquesandinterestingattackcampaignsfromthepastmonth.
ApartofImperva'sApplicationDefenseCenterresearcharm,theHackerIntelligenceInitiative(HII),isfocusedontrackingthelatesttrendsinattacks,Webapplicationsecurityandcyber-crimebusinessmodelswiththegoalofimprovingsecuritycontrolsandriskmanagementprocesses.
轻云互联成立于2018年的国人商家,广州轻云互联网络科技有限公司旗下品牌,主要从事VPS、虚拟主机等云计算产品业务,适合建站、新手上车的值得选择,香港三网直连(电信CN2GIA联通移动CN2直连);美国圣何塞(回程三网CN2GIA)线路,所有产品均采用KVM虚拟技术架构,高效售后保障,稳定多年,高性能可用,网络优质,为您的业务保驾护航。官方网站:点击进入广州轻云网络科技有限公司活动规则:1.用户购...
bgp.to在对日本东京的独立服务器进行6.5折终身优惠促销,低至$120/月;对新加坡独立服务器进行7.5折终身优惠促销,低至$93/月。所有服务器都是直连国内,速度上面相比欧洲、美国有明显的优势,特别适合建站、远程办公等多种用途。官方网站:https://www.bgp.to/dedicated.html主打日本(东京、大阪)、新加坡、香港(CN)、洛杉矶(US)的服务器业务!日本服务器CPU...
韩国云服务器哪个好?韩国云服务器好用吗?韩国是距离我国很近的一个国家,很多站长用户在考虑国外云服务器时,也会将韩国云服务器列入其中。绝大部分用户都是接触的免备案香港和美国居多,在加上服务器确实不错,所以形成了习惯性依赖。但也有不少用户开始寻找其它的海外免备案云服务器,比如韩国云服务器。下面云服务器网(yuntue.com)就推荐最好用的韩国cn2云服务器,韩国CN2云服务器租用推荐。为什么推荐租用...
lulzsec为你推荐
permissiondeniedpermission denied是什么意思啊?sonicchat深圳哪里有卖汽车模型?杨紫别祝我生日快乐祝自己生日快乐内涵丰富的话硬盘的工作原理简述下硬盘的工作原理?地图应用什么地图导航最好用最准确mathplayerjavascript 如何判断document.body.innerHTML是否为空www.765.com有没好的学习网站www.kknnn.com求有颜色的网站!要免费的杨丽晓博客杨丽晓哪一年出生的?99nets.com99nets网游模拟娱乐社区怎么打不开了?????????谁能告诉我 ???、
站群服务器 天猫双十一秒杀 万网优惠券 lighttpd 一点优惠网 ibrs 福建天翼加速 申请网页 香港亚马逊 空间租赁 路由跟踪 东莞服务器托管 全能空间 php服务器 godaddy空间 大化网 杭州电信 北京主机托管 电信主机托管 美国服务器 更多