Acceleratedlulzsec

lulzsec  时间:2021-03-27  阅读:()
SecurityTrends2012Hackingisinherentlyinnovative.
Thismeanssecurityteams,likeMr.
Gretzky,needtokeeptheireyeonwherethingsaregoing–notjustonwherethey'vebeen.
As2012approaches,securityhasevolveddramaticallyfromjustoneyearago.
Theword"hacktivism,"forexample,isalmostahouseholdterm.
Likewise,thegroupAnonymousisanythingbut.
Indeed,cybersecurityremainsoneofthemostdynamicandfluiddisciplinesworldwide.
Imperva'sApplicationDefenseCenter(ADC),ledbyImpervaCTOAmichaiShulman,isexclusivelyfocusedonadvancingthepracticeofdatasecuritytohelpcompaniesshieldthemselvesfromthethreatofhackersandinsiders.
For2012,theADChasassembledacomprehensivesetofpredictionsdesignedtohelpsecurityprofessionalspreparefornewthreatsandattacksincyberspace.
HackerIntelligenceInitiative,MonthlyTrendReport#6December2011Trend#9:SSLGetsHitintheCrossfireTrend#8:HTML5GoesLiveTrend#7:DDoSMovesUptheStackTrend#6:InternalCollaborationMeetsItsEvilTwinTrend#5:NoSQL=NoSecurityTrend#4:TheKimonoComesOffofConsumerizedITTrend#3:Anti-SocialMediaTrend#2:TheRiseoftheMiddleManTrend#1:Security(Finally)TrumpsComplianceAgoodhockeyplayerplayswherethepuckis.
Agreathockeyplayerplayswherethepuckisgoingtobe.
–WayneGretzky2Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#9:SSLGetsHitintheCrossfireWhileagrowingnumberofwebapplicationsaredeliveredovertheHTTPSprotocol(HTTPoverSSL),attackersareincreasinglyfocusingtheirattacksagainstthevariouscomponentsofSSL.
WeareseeingariseinattackswhichtargettheworldwideinfrastructurethatsupportsSSL.
Weexpecttheseattackstoreachatippingpointin2012which,inturn,willinvokeaseriousdiscussionaboutrealalternativesforsecurewebcommunications.
Ironicallyenough,whileattackersarekeepingbusyattackingSSL,theyarealsoabusingitsprivacyfeaturesinordertoconcealtheirownmischievousdeeds.
WethereforeexpecttoseemoregeneralpurposewebattacksbeinglaunchedoverSSLconnections.
First,alittlebackgrounder.
TheSecureSocketsLayer(SSL)1cryptographicprotocolisthedefactostandardforprovidingdataintegrityandconfidentialityforwebtransactionsovertheInternet(sometimesSSLisusedinterchangeablywiththetermHTTPSwhichistheapplicationofSSLprotocoltoHTTPtraffic).
SSLencryptspiecesofapplicationlayerdataoverTCPconnectionsprovidingconfidentiality.
Itcanalsobeusedtotestfortheidentityoftheserver,theclientorboth.
SSLusesanefficientcryptographicalgorithmforencryptingdataandacomputationalintensiveprotocolforauthenticationandkeyexchange(thekeyisusedbytheencryptionalgorithm).
ThekeyexchangeprotocolemploysasymmetriccryptographyamethodologythatrequirestheexistenceofaworldwidePublicKeyInfrastructure(PKI).
PKIdefinesaprocedureforbindingdigitalcertificateswithrespectivewebsitesbymeansofachainofCertificateAuthorities(CA).
Thebindingisestablishedthrougharegistrationandissuanceprocessthatensuresnon-repudiation.
Inthelastcoupleofyears,wehaveseenagrowingawarenessforattacksagainstconfidential(e.
g.
Firesheep)andauthenticity(ManintheMiddleattacks,Phishing).
Asaresult,webapplicationownersareconstantlyextendingtheuseofSSLtomoreapplications,andtomorepartsoftheirapplications.
AgoodexampleistheevolutionoftheGoogleinterface.
Atfirst,onlytheloginpagewasencrypted.
Inthenextstage,thewholeGmailservicesupportedencryption–bydefault.
GooglehasnowevenaddedthesearchfunctionalitytobeaccessedviaHTTPS.
WiththegrowingusageofSSL,attackersareincreasinglytargetingtheSSLlayer.
Unfortunately,mostoftheresearchcommunityisfocusedonpointingoutinherentprotocolvulnerabilities,orcommonimplementationmistakesthatcouldpotentiallybeattacked.
While,theattackercommunityisfocusedonother,morepracticaltypesofattacks:AttacksagainstPKI.
Overthepastyear,attackershaverepeatedlycompromisedvariousCAorganizations.
Theseinclude,DigiNotar,GlobalSign,StartSSL,ComodoandDigicertMalaysia.
Theseattackswereadirectconsequenceofthecommoditizationofcertificates,wheresmaller,lesscompetentorganizationshavestartedtoobtainabiggershareintheCertificateAuthoritymarket.
Asitstandsnow,anyCAcanissueadigitalcertificateforanyapplication–withoutanyrequiredconsentfromapplicationowner.
Ahacker,whogainscontrolonanyCA,canthenuseittoissuefraudulentcertificatesandimpersonateanywebsite.
Additionally,thereareconcernsthatsomerootCAs(whosetrustishardcodedintobrowsersoftware)areinherentlydubious(e.
g.
controlledbyunfriendlygovernments).
SomeeffortsaremadetoamendPKIissuesbuttheyarefarfrombroadacceptance2.
Thetheftofissuedcertificates.
Webelievethisattackwillprevailoverthenextyearasapplicationcertificatesarenolongerlimitedtobeingstoredbytheapplication.
ThisistheconsequenceofthemonolithicnatureofSSL.
WhileSSLpreventsaccesstotrafficbyattackersithasnobuilt-inmechanismsthatrestrictaccesstoitbycollaborative3rdparties.
Forexample,proxies,loadbalancers,contentdeliverynetworks(CDNs)needtoaccessthecertificate'sprivatekeyinordertoaccessapplicationdata.
AlsoDLPandWAFsolutionsrequiresimilarkeyaccess.
Inthesecases,itwouldbepreferablethattheintermediateproxieswouldbeabletolookatmessageheaders,ortobeabletoreadtrafficwithoutchangingit.
However,thisgranularityisnotsupportedbySSL.
Asaresult,thedigitalcertificateisnowstoredinmanylocations–someresidingoutsideofthesite'sphysicalenvironmentandoutoftheapplication'sownercontrol.
Theseopenupadditionalattackpointswhichprovidehighersuccessratesforattackers.
1SSLperseisnowobsoleteandreplacedbytheTransportLayerSecurity(TLS)protocol.
HoweverSSLisstillthecommonlyusedterm.
2Anotherworthyexampleistheconvergenceprojecthttp://convergence.
io/3Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportDenialofServiceattacks.
TheheavycomputationalburdenincurredbytheSSL-handshakeprocessleavesSSL-protectedresourcesprimecandidatesforeffectiveDenialofService(DoS)attacks.
Togetherwithanincreasedconsumptionofcomputerresourcespersession,amultitudeofsimpleattackscanbedevisedveryefficiently.
InadditiontotheattacksagainstSSLanditsinfrastructure,hackerswillleverageSSLtocarryouttheirattackswithincreasedconfidentiality.
Forexample,intermediateproxiescannotaddheaderstoindicateoriginalsenderIPaddress–leadingtothelossoftraceability.
AnotherproblemisthelossofinformationwhenfollowingalinkfromanSSLpagetoanon-SSLpage.
AnattackercanexploitthisimplementationinordertocoverthetracksofvariousWebattacks.
Furthermore,manysecuritydeviceswhichrequireinspectionoftheWebtrafficlosethissortofvisibilityduetotheencryptionofthetraffic.
Trend#8:HTML5GoesLiveOverthelastfewyearsvulnerabilitiesinbrowsers'add-ons(thirdpartycomponentssuchasadobe'sFlashPlayerorOracle'sJava)werethemaincausefor"zero-day"exploits.
Theseareun-patchedapplicationvulnerabilitiesthatareexploitedinordertoinstallmalwareonwebusers'machines.
Wepredictin2012hackerswillshifttheirfocustoexploitingvulnerabilitiesinthebrowsersthemselvesinordertoinstallmalware.
Thereasonisduetorecentlyaddedbrowserfunctionality–mainlydrivenbytheadoptionofHTML5standard.
TheHTML5standardwascreatedtoenablebrowserstosupportaricherenduserexperienceinastandardizedway.
Mostnotably,HTML5addssupportforaudio,video,2Dgraphics(SVG),3Dgraphics(WebGL)thatpreviouslyrequiredtheendusertoinstalladedicatedadd-on.
(e.
g.
AdobeFlashPlayertowatchonlinevideo).
Whilethenewfeaturesareattractivetowebdevelopers,theyarealsoverybeneficialforhackers.
Weseesecurityrepercussionsforthefollowingreasons:1.
Newcodeisgenerallymorevulnerable.
Whenyouwritecodeyouaredoomedtocreatebugsandsecurityvulnerabilitiesalongwithit.
Whenyouaddalotofnewcode–youaredoomedtocreatealotofnewvulnerabilities.
2.
Compressedmediatypesaremorevulnerable.
Modernmediatypes(suchasvideo)areusuallyhighlycompressedandoptimizedtoensuretheefficiencyoftheirtransmissionanddisplay.
Decompressinginvolvesalotofbuffermanipulationswhicharenotoriouslyvulnerable.
3.
Hardwareaccess.
Manybrowsersusetheassistanceofhardwarecomponents3–mainlyforJavascriptandgraphicsacceleration–inordertoachievehigherefficiencyandcreateasmootheruserexperience.
Sincehardwareisrununderhighpermissionaccesslevels,andusuallycannotbeprotectedbytheoperatingsystems,exploitstargetingthehardwarecomponentsareveryattractivetoattackers.
Thistypeofprivilegedaccessprovidestheattackerswithamethodtoexploitbuggyhardwaredriversstraightfromawebpage.
4.
Enduserscontrol.
Currently,mostbrowserscontainamechanismwhichturnsoffavulnerablebrowseradd-on.
InthecaseofHTML5,theimplementationisembeddedwithinthebrowsersothatavulnerableadd-onmightnotnecessarilybeturnedoff.
Attheveryleast,itchangesthesecuritymodelfrom"optin"model(activelydownloadanaddon)to"optout"(disableanexistingcomponent.
)5.
Javascriptcontrol.
NewHTML5featurescanbecontrolledandmanipulatedviaJavascript.
ThisgivesrisetonewvectorsofJavascript-relatedattacks(mainly,buttonotlimitedto,XSS).
Thesenewattackvectorswillusethenewelements,andtheinteractionsbetweenthem,inordertobreakthealreadyfragileSameOriginPolicy(SOP).
FormoreonSOP,clickhere.
6.
Ubiquity.
It'smuchmorecost-effectivetocreateacrossbrowserexploitthantocreateanexploitaimedataspecificone.
TheubiquityofHTML5providesthemwithjustthat.
3MicrosoftAnnouncesHardware-AcceleratedHTML5http://www.
microsoft.
com/presspass/press/2010/mar10/03-16mix10day2pr.
mspx4Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#7:DDoSMovesUptheStackDistributedDenialofService(DDoS)attacksaregainingpopularityandwerepartofhighprofilehackingcampaignsin2011,suchastheAnonymousattacks4.
Wepredictthatin2012attackerswillincreasethesophisticationandeffectivenessofDDoSattacksbyshiftingfromnetworklevelattackstoapplicationlevelattacks,andevenbusinesslogiclevelattacks.
ADenialofService(DoS)isarelativelyoldattackaimedatdataavailabilitybyexhaustingtheserver'scomputingandnetworkresources.
Consequently,legitimateusersaredeniedservice.
ADistributedDenialofService(DDoS)isanamplifiedvariationoftheDoSattack,wheretheattackerinitiatestheassaultfrommultiplemachinestomountamorepowerfulandcoordinatedattack.
Today,DoSattacksrequiretheattackertoinvestinamassivelydistributednetworkwhichcancreateenoughtraffictoeventuallyoverwhelmthevictim'sresources.
AttheotherendoftheDoSspectrum,there'stheSQLshutdowncommand.
Anattackerexploitinganapplicationvulnerabilitycanusethisparticularcommandtoshutdowntheserviceusingjustasinglerequest,initiatedfromasinglesource,which,fromtheattacker'sperspective,provescheaperandisjustaseffective.
Historically,wehaveseenDoSattacksgraduallyclimbuptheprotocolstack.
FromthemostbasicNetworklayer(layer3)attacks,suchastheUDPFlood,throughtheTransportlayer(layer4)withSYNfloodattacks.
Inthelastyears,wealsosawtheHTTPlayer(layer7)beingtargetedwithsuchattacksastheSlowloris5(in2009)andRUDY6(2010)attack.
Wepredictthatin2012wewillseehackersadvanceonemorerung.
ThismeanscreatingDDoSattacksbyexploitingwebapplicationvulnerabilities,oreventhroughwebapplicationbusinesslogic7attacks.
Indicationsforthistrendarealreadyemerging.
Forexample,the#RefReftool8,introducedinSeptember2011,exploitsSQLinjectionvulnerabilitiesusedtoperformDoSattacks.
Thereareseveralreasonsattackersaremovingupthestack:1.
Decreasingcosts.
Inthepast,attackershavetakenthe"brawnoverbrains"attitude.
Thismeantthattheysimplyinundatedtheapplicationwithgarbage-likerequests.
However,thesetypeofattacksrequirealargeinvestmentontheattacker'sside,whichincludedistributingtheattackbetweenmultiplessources.
Intime,hackershavediscoveredthattheycanadd"brains"totheirattacktechniques,significantlyloweringtheheavycostsassociatedwiththe"brawn"requirements.
2.
TheDoSsecuritygap.
Traditionally,thedefenseagainst(D)DoSwasbasedondedicateddevicesoperatingatlowerlayers(TCP/IP).
Thesedevicesareincapableofdetectinghigherlayersattacksduetotheirinherentshortcomings:theydon'tdecryptSSL,theydonotunderstandtheHTTPprotocol,andgenerallyarenotawareofthewebapplication.
Consequently,theattackercanevadedetectioninthesedevicesbymovinguptheprotocolstack.
3.
TheubiquitousDDoSattacktool.
WorkingovertheHTTPlayerallowstheattackertowritecodeindependentoftheoperatingsystem.
Forexample,byusingjavascript.
Theattackerthengainstheadvantageofhavingeverywebenableddeviceparticipateintheattack,regardlessofitsoperatingsystem–beitWindows,MacorLinux.
Moreso,itallowsmobiledevices-runningiOS,Android,oranyothermobileoperatingsystem–toparticipateinsuchattacks.
Thegoodnewsisthatenterprisescanpreparethemselvesagainsttheseapplication-targetedDoSattacks.
HowByaddingapplication-awaresecuritydevices,suchasWebApplicationFirewalls(WAFs).
ThesedevicescandecryptSSL,understandHTTPandalsounderstandtheapplicationbusinesslogic.
TheycanthenanalyzethetrafficandsiftouttheDoStrafficsothateventually,thebusinessreceives–andserves–onlylegitimatetraffic.
4http://thelede.
blogs.
nytimes.
com/2010/12/08/operation-payback-attacks-visa/partner=rss&emc=rss5http://ha.
ckers.
org/slowloris/6http://www.
slideshare.
net/AlesJohn/owasp-universalhttpdo-s-92072897Webapplicationlogicattackcanbeperformedbyprofilingthevictimwebapplicationforresourceconsumingoperations(suchassearchingalargedatabase)andthenconstantlyapplyingthatoperationtodepletethevictimserverresources.
8http://www.
refref.
org/5Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#6:InternalCollaborationMeetsItsEvilTwinWeexpecttoseeagrowingnumberofdatabreachesfrominternalcollaborationplatformsusedexternally.
WhyInternalcollaborationsuitesarebeingdeployedin"eviltwin"mode,i.
e.
,thesesuitesgetusedexternally.
Asaresult,organizationwilllookfortoolstoprotectandcontrolaccesstosuchplatforms.
Weestimatethatin2012thenumberofInternetsitesbasedonsuchplatformswillincreasedramatically.
Asaconsequence,thenumberofsecurityincidentsduetoinadvertentpublicexposureofconfidentialdatawillgrow.
Thepastcoupleofyearsbroughtupanextensiveincreaseintheuseofcollaborationsuiteswithinorganizations.
PlatformssuchasMicrosoftSharePointandJivearenowusedbymanyorganizationstoshareinformationandmanagecontent.
Whilemostenterprisesusetheseapplicationswithintheorganization,somehavealsoextendedtheusetopartnersandeventothepublicthroughaninternetfacingwebsite.
Infact,basedonForresterresearch,SharePointislistedasthenumberoneportalproduct(source:http://www.
topsharepoint.
com/about)andwiththelatestreleaseofSharePoint2010,italsooffersagreatplatformforbuildingcollaborationsiteswithexternalpartnersorrobustexternally-facingsites.
Extendinganinternalplatformtoexternalusealwayscomeswithapricetagtobepaidinsecurity.
AnexampleofsuchsecuritybreachtookplacewhentheMississippinationalguardaccidentallyexposedpersonalinformationofnearly3000soldiersontheirexternalMicrosoftSharePointwebsite(source:http://www.
itbusinessedge.
com/cm/community/news/sec/blog/national-guard-data-exposed-in-accidental-security-breach/cs=43893)Therearetwomajorfactorsthatimpacttheriskofextendinganinternalplatformtoexternaluse:1.
Datasegregation.
Datasegregationhastwomanifestationswithrespecttoexternalizinginternalsystems.
Ensuringthatthestoredsensitivedatadoesnotbecomeaccessiblethroughthelessrestrictedinterfacesoftheplatformisnotaneasytask.
Fortheentirelifetimeofthesystems,controlsshouldbeputinplacetoallowcollaborationandsharingofsensitiveinformationwithintheorganizationwhilekeepingitoutofthereachofthegeneralpublic.
2.
Threatprofile.
Threatprofileisrelatedtothedifferencebetweeninternalandexternalthreats.
Thesizeofpotentialattackerpopulationincreasesinstantaneouslyaswellasthetechnicalandhackerskillsofit.
Atthesametime,theimpactofadisclosureorabreachincreasesdramaticallyoverthatofaninternalbreach.
Tomakethingsevenworse,searchengineslikeGoogleconstantlycrawlandupdatetheirindexingpoliciessothatthepublicinterfaceoftheapplication,aswellasanybreachesormis-configuredentrypointsarequicklyapparenttothewholeworld.
Forexample,anupdatedGooglepolicytoindexFTPserversresultedinabreachaffecting43,000Yale-affiliatedindividuals.
Googlehackingtools,suchasSharePointGoogleDiggityandSharePointURLBrute,caneasilybeusedtoidentifyinsecureconfigurations.
Organizationsaimedatreducingtheriskofmassiveexposuresshouldstartbudgetingandplanningforthenextgenerationofcollaborationsuitemonitoringandgovernancetools.
Someofthecharacteristicstolookforare:Policiestomonitorandprotectinternetandintranetfacingsites.
Flexibledeploymentthatdoesn'timpacttheuseofapplicationorthenetworkarchitecture.
Theabilitytoidentifyexcessiveuserrightstocontent.
6Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#5:NoSQL=NoSecurityTheITworldisquicklyembracingBigData.
Hugedatastoresarethenextbigstepinanalyzingthemassiveamountsofdatathatisbeingcollectedinordertoidentifytrends.
Forexample,newstartupsusethesesystemstoanalyzetrillionsofDNAstripstogainanunderstandingofourgenealogy.
Towell-establishedcompanieswhoareadoptingthetechnologytomapandtimetransportationsystemsacrosstheworldtomakeourtravelingeasierandcheaper.
WhileBigDataisbecomingabuzzwordininformationsystems,therehasnotbeenmuchinvestigationintothesecurityimplications.
Manypredictthatin2012we'llseeagrowinginterestinBigDataandit'sunderlyingtechnology,NoSQL.
Wepredictthattheinadequatesecuritymechanismsofthesesystemswillinhibitenterprisesfromfullyintegratingthesesystemsasthirdpartycomponentswithinthecorporation.
NoSQLisacommontermtodescribedatastoresthatstorealltypesofdata–fromstructuredtounstructured.
Duetothisdiversity,thesedatastoresarenotaccessedthroughthestandardSQLlanguage.
Upuntilrecently,wecategorizedourconceptionofdatastoresintwogroups:relationaldatabases(RDBMS)andfileservers.
Thenewkidintown,NoSQL,openedourmindstoadatabasethat,unliketheconventionalrelationalconcepts,doesnotfollowastructuralform.
TheadvantageScalabilityandavailability.
Withatechnologywhereeachdatastoreismirroredacrossdifferentlocationsinordertoguaranteeconstantup-timeandnolossofdata,thesesystemsarecommonlyusedtoanalyzetrends.
Thesesystemsarenotsuitableforfinancialtransactionsrequiringareal-timeupdate,butcouldbeemployedatafinancialinstitutiontoanalyzethemostefficientorbusiestbranch.
However,asapplicationsusingNoSQLarebeingrolledout,littletimehasbeentakentothinkorre-thinksecurity.
Ironically,securityindatabaseandfileservershaveseentheirshareofproblemsovertheyears.
Andthesearesystemsthathavegainedmileageovertheyearswhichallowedthistypeofsecurityinspection.
WecannotsaythesameaboutNoSQL.
ManymayclaimthatthedevelopersofdifferentNoSQLsystemshavepurposefullypushedoutsecurityaspectsfromtheirsystems.
Forinstance,Cassandrahasonlybasicbuilt-inauthenticationprocedures.
Thislackofsecurityisconsideredtheirfeatureandbuiltinmindthatdatabaseadministratorsdonotneedtotroublethemselveswithsecurityaspects.
Security,then,shouldbeanoffloadedprocesstobedealtwithbyadedicatedteam.
WebelievetheNoSQLsystemswillsufferfromanumberofissues:Lackofexpertise.
Currently,therearehardlyenoughexpertswhounderstandthesecurityaspectsofNoSQLtechnologies.
WhenbuildingaNoSQLsystem,thereisnoobvioussecuritymodelthatfits.
Thelackofsuchamodelmakestheimplementationofsecurityanon-trivialprocessandrequiresextensivedesign.
Asaresult,securityfeaturesthatneedtobeconsideredgetpushedoutoverandoveragain.
Buggyapplications.
Untilthirdpartysolutionsrollouttoprovidethenecessarysecuritysolutions,itistheNoSQLapplicationsthatwillcarrythesecurityload.
Issuesinclude:Addingauthenticationandauthorizationprocessestotheapplication.
Thisrequiresmoresecurityconsiderationswhichmaketheapplicationmuchmorecomplex.
Forexample,theapplicationwouldneedtodefineusersandroles.
Basedonthistypeofdata,theapplicationcandecidewhethertogranttheuseraccesstothesystem.
Inputvalidation.
OnceagainweareseeingissuesthathavehauntedRDBMSapplicationscomebackandhauntNoSQLdatabases.
Forexample,inBlackhat2011,researchersshowedhowahackercanusea"NoSQLInjection"toaccessrestrictedinformation.
Forexample,"TheWebApplicationHacker'sHandbook:FindingandExploitingSecurityFlaws"containsanewseparatechapterfocusedsolelyonthesecurityofprogrammingframeworksusedforNoSQL.
Applicationawareness.
Inthecasewhereeachapplicationneedstomanagethesecurity,itwillhavetobeawareofeveryotherapplication.
Thisisrequiredinordertodisableaccesstoanynon-applicationdata.
Whennewdatatypesareaddedtothedatastore,thedatastoreadministratorwouldhavetofigureoutandensurewhatapplicationcannotaccessthatspecificdata.
Vulnerability-pronecode.
ThereareacertainamountofNoSQLproducts,butamagnitudemoreofapplicationsandapplicationserverproducts.
Themoreapplications,themorecodeingeneralpronetobugs.
7Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportDataDuplicity.
InNoSQLsystems,dataisnotstrictlysavedinparticulartables.
Instead,thedataisduplicatedtomanytablesinordertooptimizequeryprocessing.
Asaresult,itisnotpossibletoclassifycreditcardsaccordingtoaparticularsensitivetable.
Onthecontrary,thistypeofdatacanbefoundindifferentplaces:transactionlogs,personaldetails,specifictableswhichrepresentsallcreditcards,andotherlocationswhichmayhavenotevenbeenconsidered.
Privacy.
Althoughourfocusisonsecurity,privacyconcernscannotbeignored.
Takeforexampleahealthcareplatformwhereprovidersgettogetherandsharepatientdata.
Apatientmightaccessthesystemforgeneticinformation,andlateraccessitinrespecttodruginfo.
Anapplicationwhichanalyzesthisdatacancorrelatetheinformationtofindpurchasingtrendsrelatingtogeneticsandhealth.
Theproblemisthatthistypeofcorrelationwasnotconsideredwhenthedatawasinitiallyinserted.
Asaresult,thedatawasneveranonymizedallowinganyonetoidentifyspecificindividualsfromthebiggerpicture.
NoSQLisstillinitsinfancy.
Itwilltakeawhileuntilwewillseethesesystemsfullydeployedatthemajorityofenterprises.
Forthisprecisereasonitissoimportanttoinvestintheinthesecurityofthesesystems.
Trend#4:TheKimonoComesOffofConsumerizedITAfterbeingcaughtoff-guardbytheprocessofconsumerizationofIT,professionalsaretryingtoregaincontrolofcorporatedata.
Theproblemisthattheyaredoingitthewrongway.
Insteadoftryingtocontroldataatthesource,ITorganizationstrytoregulatetheusageofend-userdevicesandde-clouddataaccess.
Weexpectorganizationstospendalotoftime,moneyandeffortonthesetechniquesandtechnologiesnextyear–withverypoorresults.
TheconsumerizationofITreferstotheprocessinwhichcorporatedataisincreasinglybeingprocessedbyend-userdevicesandapplicationschosenandprovidedbytheend-usersthemselves.
Smartphones,tabletsandcustompersonallaptopsareleadingthistrendwiththeirincreasingprocessingpowerandstoragecapabilities,combinedwiththeirgrowingdiversityofavailableapplications.
Theseareaugmentedbytheincreaseofaremoteworkforceandindividualswhousehomecomputersandhomenetworksonaregularbasistoaccesscorporateresources.
Thisprocessbyitselfpossesmanychallengestoanorganizationthatarerelatedtothecompromiseofinformationonthedevice(eitherphysicallythroughlossandtheftofthedevice,ordigitallythroughmalware),aswellasthecompromiseofenterprisenetworksthroughacompromiseddevice.
Coupledwiththemoveofcorporatedataintothecloud–wherecorporatedataisstoredoutsideoftheorganization–anevenamoredifficultproblememerges.
Withtheseissuesinmind,theorganizationcompletelylosescontrolovertheentireinteractionbetweenend-usersandcorporatedata.
ThereisagrowingtrendamongITprofessionalstotryandregainthecontrolofend-userdevices.
Throughdifferentmeans,organizationsaretryingtoenforce"proper"usageandsettingsofnon-corporatedevices.
ITdepartmentsareattemptingtoenforcepoliciessuchaspasswordstrength,devicelockupandevenremotewipinginthecaseofdeviceloss.
Forexample,accessthroughtheActiveSyncprotocoltoMicrosofteMailserverscanberestrictedtodevicesthatimplementaspecificsecuritypolicy.
Someenterprisesalsogoasfarastotryandregulatethedevicesthatareallowedtoaccessenterprisedatatothosemodelswhopossescertainsecuritycapabilities.
Weanticipatethatthenextstepwillbetorequirethatcertainsecuritysolutionsbeinstalledonthosedevicesthatareallowedtoconnecttothenetwork(e.
g.
LookoutoranyothermobileAV).
Inordertoreducetheriskofdevicecompromise,enterprisesarealsotryingtoenforceanywebaccessfromthedevicetoberelayedthroughtheenterprisenetworkwhereitcanbemonitoredandcontrolled(which,ofcourse,hassevereimplicationsinthecaseofSSLprotectedwebresources–asexplainedinadifferenttrend).
Further,thisapproachhopestobridgegapthatexistsbetweenuserdevicesandcloudapplicationsthatholdenterprisedata.
Theapproachdescribedaboveisboundtofailforquiteafewreasons.
Mostofthemstemfromoverlookingpastexperienceandhumannature:8Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReport1.
Pastisprologue.
Thepastcoupleofyearshaveshownthatenterprisesarefailingtopreventthecompromiseofenterprisecomputingequipment.
Extendingthescopeoftheproblemtoalargervarietyofdevicesonlymagnifiestheproblem:2.
Maintainingavailability.
Organizationsthatdelegateinformationavailabilityandnetworkaccessibilityissuestothecloudandthentaketheapproachoftunnelingalluserdevicetraffic,aregoingtofacemajornetworkingissues.
Consequently,theywillfindthemselvesspendingtimeandmoneyoncreatingandmaintainingthehighlevelofworldwideavailabilitywhichtheywantedtoavoidinthefirstplace.
3.
Userprivacy.
Thereareunsolvedissuesregardingtheimpacttouser'sprivacyandtheliabilityoftheenterprisetopersonalinformationstoredonthesedevices.
Forinstance,remotewipe-outtoolscannotdifferentiatebetweencorporateandpersonalinformation.
Thisupcomingyear,organizationsaregoingtospendquitealotofmoneyandeffortbeforerealizinghowlittleimprovementthisapproachbringstoenterprisedatasecurity.
Whentheydorealizethefailureofthesemeasures,theyaregoingtolookforadifferentsetofsolutionsthataregoingtobemoretightlycoupledtothedataitself.
Suchsolutionsincludemonitoringrequirementsforaccesstothedatastoresandstrictcontrolofthataccess.
Trend#3:Anti-SocialMediaAsmanymoreorganizationsaremakingtheirwayintothesocialmediaspace,weexpecttoseeagrowingimpacttotheintegrityandconfidentialityoftheenterprise'sinformation.
Moreover,hackerswillcontinuetoautomatesocialmediaattacks,furtherexacerbatingthesituation.
Theheartoftheproblemresidesinthreeseparateissuesinherenttosocialnetworks:1.
Sharing–Themostimportantthingtounderstandaboutsocialnetworksandthetoolsbuiltontopofthemisthattheyaredesignedforsharinginformation–notrestrictingaccesstoit.
Enterprisesthattrytousesocialmediaascollaborationsuitesforinternal,sensitivebusinessdata–whichrequiredifferentlevelsofaccessprivileges–areboundtoencountermassivedatabreaches.
Thereasonisnotduetoflawedaccesscontrolsandprivacymechanisms.
Rather,therestrictionofinformationthroughthesechannelsisincompletecontrasttotheconceptofsuchenvironmentswhichis,infact,allaboutsharing.
Consequently,organizationsshouldkeepanoperationalcopyofalltheirdatainabusinesssystemthatcanprovidedecentaccesscontrols.
Datathatcanbemadepubliccanbeexportedoutofthissystemandpostedtothesocialnetwork.
Thisway,restrictedinformationiskeptinsidebusinesssystems(regardlessofwhethertheyareonpremiseorinthecloud),whilepublicinformationcanberetrievedtopublicationonthesocialplatform.
2.
Control–Organizationsneedtounderstandthatthereisnearlyanabsolutelackofcontroloverinteractionswithmembersofthesocialplatform.
Intherealworldweattempttocontrolthetypesofsocialinteractionsweexperiencebycarefullychoosingoursocialcirclesaswellastheplaceswehangout.
Thisisnotpossibleinthecyberworld.
Commentspam,defamation,falseclaimsandbadlanguagearethenorm.
Keepingyoursocialcyberenvironmentcleanoftheseisadifficulttask.
Further,cybercleansingclaimsresourcesinamannerproportionaltothepopularityoftheenterprise.
Measuresrangefromsiftingandsanitizingcommentstoengagingcloselywiththesocialnetworksincaseofdefamation.
Enterpriseswhofailtoinvesttheseresourceswillquicklyfindthattruefollowersarefleeingthescene.
Inthemeanwhile,thebrandnameerodes–defeatingthepurposeofenteringthesocialnetworkscene.
3.
LackofTrustandProperIdentification–Thereisnorealwayforenterprisestoavoidcopy-cats.
Intoday'ssocialplatforms,thereisnosolidwaytotellaparttherealownerofabrandfromimpostorsandcopy-catswhoaretryingtotakeadvantageofthepopularityofaspecificbrand,toabuseitortoerodeit.
Theidentityofmessageposterscannotbeverifiedinanywayandtherearenorealtoolstoevaluatethetrustworthinessofmessagesandtheircontent.
9Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTheconsequencescouldbegeneralbranderosionorattackcampaignstargetedtowardsenterprise'ssocialcircle.
Mixthesethreeconceptswiththegrowinguseofautomationandyougetsocialnetworkmayhem.
Inthepastcoupleofyearswehavewitnessedtheimpactofthepowerofautomationwhenappliedtosocialnetworks:InFebruary2011,theLovely-Faces.
comwebsiteshowcasedhundredsofthousandsofscrapedFacebookuserprofiles.
InSeptember2011,anothergroupdemonstratedanapplicationthatautomatestheprocessof"friending".
Basedonthisprocess,theapplicationcreatesacollectionofallpersonalinformation,includingphotos,fromthosewhoacceptedthefriendshiprequest.
Recentlyagroupofresearchersdemonstratedthepowerof"socialbotnets".
Thesearefakeprofiles.
However,theseaccountscanautomaticallygrowanetworkoffriendsofactualrealaccounts.
Theresearchprovedthattheflawed"friendofafriend"trustmodelenabledthistypeofbotnetproliferation.
Further,theirresearchfoundthatindividualswerethreetimesmorereceptivetoacceptingafriendshiprequestiftherequesteralreadysharedamutualfriendwiththem.
Softwareautomatingaccountgenerationandvariousdataminingresearchprojectsexist.
ThisFall,DHSstartedsettinguppoliciestomonitorFacebookandTwitter.
Automatingthisprocesswillbeatheartofthisprojectinordertosiftthroughtheincrediblyhighvolumeoftraffic.
Unfortunately,wedonotseeanymarketsolutionsreadytohandletheaboveissues.
Facebookaswellasothersocialmediaplatformprovidersarecurrentlykeepingfullcontrolandareattemptingtofightsomeoftheissues(mainlyautomationandfakeaccounts)fromwithin.
OnesuchinitiativeisFacebook'sImmuneproject.
Thishasproventobemostlyfutilesofar(forinstance,there'saclearconflictofinterestsbetweenFacebook'sattempttoremovefakeaccountsanditsattempttoshowconstantunbelievablegrowth).
Rather,thesolutionsmustbeincorporatedintoexistingplatformsbyenterprisesthemselves.
Thesesolutionswillhavetorelyonthirdpartiesthatoffertrustanddatacontrolservicesoverthesocialmediaplatform.
Currently,wearenotawareofanysuchexistingsolutions,leavingavoidspaceripeforresearch.
Trend#2:TheRiseoftheMiddleManIn2010,wepredictedtheindustrializationofhacking.
Whatistheimpactofindustrializationtohacker'sbusinessmodelsIn2012,withtheincreasedsupplyanddemandforcompromisedmachines,aswellasforsensitivecorporateinfo,wepredicttherisetoanewcybercrimejobrole:thebroker.
Thisindividualisresponsibletomatchthebuyersofstolendata,orcompromisedmachines(aka"bots"),withthesellersofthedata(orbotrenters).
Inthesamewaystocksandinvestorsgaverisetostockmarkets,hackersneedamiddleman.
Thesuccessofbotherdingopenedupalargemarketwherelotsofhackershavemanycorporatemachinesundertheircontrol,eachpotentiallyholdingavastamountofdata.
However,waitingforindividualstoapproachandbuythistypeofdatafromthemissimplytoomuchofaslowandineffectiveapproach–causingthehackerstobeavictimoftheirownsuccess.
Instead,weareseeingthatthissituationactuallyopensupthewholesaleopportunityforamiddlemantobridgethisgap.
10Report#6,December2011HackerIntelligenceInitiative,MonthlyTrendReportTrend#1:Security(Finally)TrumpsComplianceIn2012weexpecttoseesecuritydecisionsdrivennotbycompliancebutforthesimplereasonof.
.
.
security.
Itsoundssimpleenough,butinpreviousyearswehaveseentheinfluxoflawsandregulationswhichdrovethebudgetandsecuritysolutions.
PCI,SOxandworld-wideDataPrivacyActswereallusedasthereasonstofeedthesecuritybudget.
Butthisapproachoftenbackfired.
Anecdotally,whenoneCIOwasaskedaboutthekeylessonfromamajorbreachhisfirmexperiencedanswered,"Securityisnotaboutsurvivingtheaudit.
"Smartcompaniesusedtheseregulationsasspringboardstoenforcethecaseofsecurity.
Infact,botha2011Ponemonsurveyandthe2010VerizonDataBreachReportshowedthatPCIdidimprovetheorganization'ssecuritystance.
However,regulatorycomplianceisnotequivalentanddoesnotconfersecurity.
ItisenoughtoturntoHeartlandPaymentSystemsforsuchanexample.
ThecompanypasseditsPCIevaluation,andyet,theyhadsufferedoneofthebiggestbreachesinhistory.
Thispastyearwehaveseenashiftinthecorporateattitudeforseveralreasons:1.
Breachesarecostly.
SecuritybreachessuchasthosesufferedbyEpsilon,RSAandSonydominatedfrontpagenews.
Thehighprofilebreacheshighlightedtheimpactofsecurity.
Branddamage,lossinbrand,legalcosts,notificationcosts,serviceoutagesandlossinshareholdervalueallbecamenewsoftheday.
Infact,thedayafterSony'sbreachannouncement,thestockpricedroppedsteeply.
DigiNotar,aCAcompanywasbreachedinSeptember(seeSSLtrend)wentunderbellylaterthatmonth.
Whileactualassessmentsofthecostofthesepastyearbreacheshavenotyetbeenmadepublic,wecanreturntotheHeartlandPaymentSystemsbreachforalesson.
FornearlytwoyearsfinancialanalystswatchedaslargelegalpaymentsfordamagesweresettledbeforethemarketcouldfeelcomfortableaboutHeartland'sabilitytostabilizerevenues.
2.
Companieswithanonlinepresence,regardlessofsize,aretargeted.
Notonlywerelargecorporationsaffectedbybreachesinthepastyear.
Hackershavebecomeveryadeptatautomatingattacks.
Accordingtothe2011VerizonDataBreachInvestigationRepot,hackershave"createdeconomiesofscalebyrefiningstandardized,automated,andhighlyrepeatableattacksdirectedatsmaller,vulnerable,andlargelyhomogenoustargets".
Inotherwords,inaworldofautomatedattacks,everyoneis–orwillbe–atarget.
ThispointwasexemplifiedinAugust2011whenUSATodaypublishedthat8millionwebsiteswereinfectedbymalware.
Ourownresearchhighlightshowapplicationsarelikelytobeprobedonceeverytwominutesandattackedseventimesasecond.
3.
Hacktivismbrings(in)securitytothefrontlines.
HackinggroupssuchasAnonymousandLulzsechavereceivedheadlineswhentheyrepeatedlyhackedintodifferentcorporations,largeandsmall.
Visa,Paypal,SonyPictures,Fox.
com,PBS.
orgaswellascountriessuchasTunisia,andgovernmentagenciessuchasInfragardallfeltthehackitivistwrathwhoseattackstargetedapplicationsandinfrastructure.
4.
APTbecomesanactualthreat.
AdvancedPersistentThreats(APT)attacksaresophisticatedattackswhichrelentlesslytargetcorporationsandgovernmentsforespionageanddestruction.
However,withgoodbrandingfromworldwideMarketingandPRteams,thistermhasbecomethealternativedescriptiontoacompromisefollowingacorporate-phishingattack.
Thefearofsuchanattackisboostingthesecuritybudget.
ArecentsurveybyESGindicatedthatduetoAPTconcerns,32%ofrespondentsareincreasingsecurityspendingby6-10%.
5.
Intellectualpropertyrequiresprotection.
Organizationsarebeginningtounderstandtheriskandconsequencesofacompromiseoftheirbreadandbutter.
Thebiggestriskofexposureofintellectualpropertyisactuallycausedunintentionally.
Forexample,throughanemployeeleavingthecompanywithcorporateinfoobtainedrightfullyovertime.
Or,throughamis-configuredserverholdingconfidentialdocuments(seetrendsontheexternalizationofcollaborationplatforms).
Organizationsalsofacetheriskthedeliberatetheftofdatafromvengefulormaliciousemployees.
Forinstance,thispastyearaformerGoldmanSachsemployeereceivedaneightyearsentenceforstealingproprietarysoftwarecode.
Compromiseofintellectualpropertymayevenbeperformedbythehandsofexternalhackers.
Inthepastwesawhowhackersweresolelyfocusedoncreditcardnumbers,logincredentialsandothersuchgenericcommodities.
Althoughthistypeofdataisstillontheattacker'sradar,wearestartingtoseehackersfocusingalsoonintellectualproperty.
Asapointincase,considertheRSAattackwhichinvolvedthedatarelatingtotheSecureIDtokens.
HackerIntelligenceInitiative,MonthlyTrendReportImperva3400BridgeParkway,Suite200RedwoodCity,CA94065Tel:+1-650-345-9000Fax:+1-650-345-9004www.
imperva.
comCopyright2011,ImpervaAllrightsreserved.
Imperva,SecureSphere,and"ProtectingtheDataThatDrivesBusiness"areregisteredtrademarksofImperva.
Allotherbrandorproductnamesaretrademarksorregisteredtrademarksoftheirrespectiveholders.
#HII-DECEMBER-2011-1211rev16.
Shareholdersarenowinvolved.
TheSEChasrecognizedtheimpactofasecuritybreachtoacompany.
Asaresult,recentupdatedSECregulationsrequirereportinginformationsecuritybreachestoshareholders.
Ifinthepastbreachescouldhavebeensweptunderthecarpet,thisregulationwillmakeithardertodoso.
Forthesereasons,wewillincreasinglyseehowcompanieswillperformwisesecuritydecisionsbasedonactualsecurityreasoning.
Furthermore,theabundanceofregulations–whichultimatelytrytosetaminimalbarofsecurity–willmakeittoocostlyfororganizationstohandleonaregulation-by-regulationbasis.
Instead,enterpriseswillimplementsecurityandthenassesswhethertheyhavedoneenoughinthecontextofeachregulation.
ConclusionHowdidwecomeupwiththesetrendsTherewereseveralfactors:Hackers–AsapartofImperva'shackerintelligenceinitiative,wemonitorhackerstounderstandmanyofthetechnicalandbusinessaspectsofhacking.
Theinsightsprovidedfromourinvestigationshelpusseewhathackersaredoingorinthiscase,plantodo.
Insomecases,hackersmakesmalltweakstoexistingattacksorcomeupaltogethernewones.
Thegoodguys–Manyofourcustomersaresmart,reallysmart.
Wemeetwiththemregularlytounderstandtheirchallengesandconcernstounderstandemergingtrends.
Weatherballoons–Wemonitortrafficincyberspace.
Thishelpsusunderstandstatisticallyhowhackersmaybeshiftingfocusregardingattacks.
Intuition–ManyintheADChavebeeninsecurityformanyyearsintheprivatesector,themilitaryandacademia.
We'veseenalotinthoseyears.
Ourhopeistogivesecurityteamsacomprehensive,substantivesetofpredictionstohelpyouprioritizeyoursecurityactivitiesforthecomingyear.
Besafe!
HackerIntelligenceInitiativeOverviewTheImpervaHackerIntelligenceInitiativegoesinsidethecyber-undergroundandprovidesanalysisofthetrendinghackingtechniquesandinterestingattackcampaignsfromthepastmonth.
ApartofImperva'sApplicationDefenseCenterresearcharm,theHackerIntelligenceInitiative(HII),isfocusedontrackingthelatesttrendsinattacks,Webapplicationsecurityandcyber-crimebusinessmodelswiththegoalofimprovingsecuritycontrolsandriskmanagementprocesses.

SpinServers(月89美元) 2*e5-2630L v2,美国独立服务器

SpinServers服务商也不算是老牌的服务商,商家看介绍是是2018年成立的主机品牌,隶属于Majestic Hosting Solutions LLC旗下。商家主要经营独立服务器租用和Hybrid Dedicated服务器等,目前包含的数据中心在美国达拉斯、圣何塞机房,自有硬件和IP资源等,商家还自定义支持用户IP广播到机房。看到SpinServers推出了美国独服的夏季优惠促销活动,最低月...

无忧云:洛阳BGP云服务器低至38.4元/月起;雅安高防云服务器/高防物理机优惠

无忧云怎么样?无忧云,无忧云是一家成立于2017年的老牌商家旗下的服务器销售品牌,现由深圳市云上无忧网络科技有限公司运营,是正规持证IDC/ISP/IRCS商家,主要销售国内、中国香港、国外服务器产品,线路有腾讯云国外线路、自营香港CN2线路等,都是中国大陆直连线路,非常适合免备案建站业务需求和各种负载较高的项目,同时国内服务器也有多个BGP以及高防节点。一、无忧云官网点击此处进入无忧云官方网站二...

7月RAKsmart独立服务器和站群服务器多款促销 G口不限量更低

如果我们熟悉RAKsmart商家促销活动的应该是清楚的,每个月的活动看似基本上一致。但是有一些新品或者每个月还是有一些各自的特点的。比如七月份爆款I3-2120仅30美金、V4新品上市,活动期间5折、洛杉矶+硅谷+香港+日本站群恢复销售、G口不限流量服务器比六月份折扣力度更低。RAKsmart 商家这个月依旧还是以独立服务器和站群服务器为主。当然也包括有部分的低至1.99美元的VPS主机。第一、I...

lulzsec为你推荐
汇通物流汇通快运 这是怎么回事?摩拜超15分钟加钱摩拜共享单车要交多少钱押金?硬盘工作原理数据存储的原理是什么今日油条油条每周最多能吃多少关键字数据库:什么是关键字?rawtoolsRAW是什么衣服牌子罗伦佐娜罗拉芳娜 (西班牙小姐)谁可以简单的介绍以下seo优化工具想找一个效果好的SEO优化软件使用,在网上找了几款不知道哪款好,想请大家帮忙出主意,用浙江哪款软件效果好javbibibibi直播是真的吗www.idanmu.com新开奇迹SF|再创发布网|奇迹SF|奇迹mu|网通奇迹|电信奇迹|
北京域名注册 备案未注册域名 域名备案只选云聚达 edgecast 嘉洲服务器 150邮箱 权嘉云 qingyun 91vps adroit 网络空间租赁 免费申请网站 天翼云盘 中国电信宽带测速器 太原联通测速 湖南idc 中国联通宽带测速 网站防护 mteam hdchina 更多