인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Security difficulties due to vulnerable security infrastructure, lax networks, and slow threat detection

Google 우선 소스Published2016.09.05 14:36
Cisco Releases '2016 Mid-Year Cybersecurity Report'
Ransomware Evolving by Releasing Various Variants to Maximize Profits


Cisco has released the 'Cisco 2016 Midyear Cybersecurity Report,' which contains recent security threat trends and solutions.

According to the report, ransomware is evolving by releasing various variants to maximize profits. Many companies cited vulnerable security infrastructure, lax networks, and slow threat detection speeds as the primary reasons for struggling with the increasing number of ransomware variants.

Ransomware is currently the most profitable type of malware. New ransomware variants are rapidly shifting their tactics to maximize the efficiency of their attacks. Recently, attackers have been shifting their focus from clients to servers. Furthermore, it is predicted that more destructive ransomware variants will continue to emerge, capable of self-replicating and spreading to take over entire networks and hold companies hostage. For example, future ransomware attacks may bypass detection by limiting CPU usage or evade command and control (C&C) measures.


▲ Refer to the Cisco blog homepage

To minimize damage from ransomware variants, it is important to secure visibility across the network and endpoints. Cisco emphasized reducing 'Time to Detection (TTD)' as a solution to ransomware variants. Reducing TTD restricts attackers' operational space and minimizes damage from intrusions. Currently, the average time it takes for companies to identify new threats is about 200 days. For the six-month period from October 2015 to April 2016, Cisco's median TTD was 13 hours. This represents a reduction of approximately 26% compared to the 17.5 hours measured in October 2015.

Recently, targets have become increasingly broad, regardless of industry or region. Studies have shown that healthcare, charities, non-governmental organizations (NGOs), and IT companies have also experienced an increase in attacks. Conflicting cybersecurity policies across nations and the complexity of national regulations are among the geopolitical concerns. In the face of complex threats, the need for data control or access is highly likely to lead to friction in international trade.

Marty Roesch, Vice President of Cisco’s Security Business Group, stated, “Security must be a priority to seize new business opportunities arising from digital transformation. Attacks are becoming more sophisticated to evade detection, and the duration of attacks is increasing. Therefore, enterprises must strengthen their security capabilities, such as improving network visibility and replacing aging infrastructure.” He added, “Cisco’s security organization collaborates with customers to block sophisticated attacks and provides security services with superior control and visibility.”

The key contents of the 'Cisco 2016 Mid-Year Cyber Security Report' include ransomware trends, attack vectors (PDF, Java, Flash, Tor), threat protection (patching, infrastructure obsolescence, encryption, TLS, time to detection, ransomware medical attack cases), and global trends and recommendations, which can be downloaded from this page. In addition, more details about the ransomware highlighted in this report can be found on the official Cisco Korea blog.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김수지 기자