마이크로칩 8월
This page was machine-translated and may differ from the original. View original

EMC, 'Warning Must Be Wary of Widespread Security Threats and Data Manipulation'

Google 우선 소스Published2016.01.13 11:42
2016 'Cyber Security Outlook' Announcement
Security threats intensify due to the commercialization of cyber attack tools, and the objectives of cyber terrorism are also diversifying.



(Image source: EMC website)

EMC Korea has released the '2016 Cyber Security Outlook' report from RSA, EMC's security business unit. This report, authored by Amit Yoran, President of EMC's security business unit RSA, covers cyber security issues from 2015 and trends to watch in 2016.

According to President Amit Yoran, many companies that previously focused solely on 'intrusion prevention' began shifting their focus starting in 2015 toward acquiring a balanced range of security capabilities, such as intrusion detection, monitoring, and incident response. Malware and exploits, which were considered 'sophisticated' threats until recently, are now becoming more common due to cheap tools traded on the cyber black market. Moreover, as cyber attacks targeting specific companies or institutions often involve a combination of multiple backdoors and vulnerability attacks rather than a single method, there are frequent instances where security incidents go unrecognized.

It was also pointed out that while numerous security solution providers emphasize the excellence of their products and claim they can prevent security incidents, it is virtually impossible to block highly evolved cyber threats because most of these solutions are based on existing technologies and methodologies.

We must prepare for data manipulation, cloud service attacks, and industrial infrastructure attacks.

CEO Amit identified five key issues to watch in the cybersecurity sector in 2016: disruption caused by data manipulation, an increase in attacks on applications in the cloud, diversification of the objectives of cyber attacks by activist hacker groups, peak security risks for industrial infrastructure, and restructuring of the security solution industry.

1. Intentional data forgery and alteration

Future cyber attacks will not only involve illegal access to data but also an increasing number of attempts to manipulate or falsify it. Accordingly, the report states that if data goes wrong, critical decision-making systems can be thrown into significant chaos, explaining that the input of incorrect data into infrastructure control systems, manufacturers' production processes, or the ingredients of food and beverages could lead to catastrophic consequences.

2. Attacks on application services in the cloud

With cloud service models such as SaaS (Software as a Service) and IaaS (Infrastructure as a Service) becoming commonplace, sensitive information and critical applications are now often operated on the cloud. Such data is a truly "precious" target for cybercrime or espionage. This highlights the need for a deep understanding of security issues within cloud services.

3. Activist Hacker Groups and Diversification of Cyber Attack Objectives

As tools used in cyber attacks become increasingly common, the objectives of attacks are diversifying beyond being limited to financial gain. While skilled hacktivists like the hacker group Anonymous execute attacks based on political and social beliefs, smaller hacker groups with relatively lower technical or organizational capabilities sometimes pursue mere fun or fame. Therefore, the report stated that security operators and crisis managers must understand the diverse backgrounds and behaviors of cyber attacks going forward.

4. Security risks to industrial infrastructure at their peak

Cyber attacks targeting large-scale infrastructure, such as chemical plants, power generation facilities, water and sewage facilities, and transportation systems, have increased by a staggering 17-fold over the past three years. With the advent of the Internet of Things (IoT) era, this problem is becoming even more serious as the deployment of networked automatic sensors in industrial sites grows. In 2016, as cyber terrorism and hacktivism spread, greater caution is required regarding the security systems of industrial control systems.

5. Restructuring of the security solution industry

With the recent increase in venture capital investment and startups in the IT industry, numerous security solutions have come into competition. However, a significant number of these have resulted in flawed strategies and unwise investments. Fortunately, as understanding of security has grown in recent years, customers are realizing that there is no panacea for cyber threats. This perception is expected to spread further as the security solution market matures, eventually accelerating the restructuring of the security solution industry.

"Security threats, such as the rapidly changing IT environment, the rising value of corporate data, and increasingly affordable, sophisticated attack programs, will be a major issue for almost all companies in 2016," said Kim Kyung-jin, President of EMC Korea. "It is important to properly understand the security threats mentioned and to secure integrated visibility by collecting and analyzing all internal and external data."
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.