This page was machine-translated and may differ from the original. View original

New types of cybercrime, such as 'dronejacking' and 'connected car hacking,' are expected to emerge.

Google 우선 소스Published2016.12.06 19:18
Symantec Announces Top 10 Security Predictions for 2017: 'Fileless Malware' on the Rise
Cyber attacks targeting IoT devices and cloud environments are intensifying… Security methods also need to change.

Symantec announced its top 10 security predictions for 2017, titled 'Security in 2017 and Beyond: Symantec's Predictions for the Year Ahead'.

As cybercriminals constantly evolve attack methods aimed at accessing corporate data, the security industry faces new types of security threats every year. With the emergence and proliferation of new IT technologies such as cloud computing, IoT, and connected cars, Symantec anticipates that security threats will intensify further in 2017 and has announced the following 10 security issues to watch out for in 2017.

<Reference Photo: The photo shows a drone on display at the exhibition>

1. Security at a New Turning Point Due to Cloud Expansion
The transition to a smart work environment is expected to continue as companies adopt new technologies such as wearables, virtual reality, and IoT devices into their internal networks, and at the same time support their distributed workforce with cloud applications and solutions. As cloud environments become increasingly widespread, companies will need to shift the focus of their security activities from protecting endpoint devices to protecting users and information across all applications and services.

2. The Era of Connected Cars Becoming 'Hostages'
As connected features begin to be added to automobiles, large-scale automotive hacking is now only a matter of time. For example, new threats targeting vehicles could emerge, such as taking cars hostage and demanding ransom, hacking autonomous vehicles to determine their location for hijacking, unauthorized surveillance, and data collection. This could lead to legal liability issues between software vendors and automakers, which is expected to have a long-term impact on the future of connected cars.

3. Increase in IoT device attacks for corporate internal infiltration
IT security departments must go beyond simply checking for vulnerabilities in computers and mobile devices and carefully monitor thermostats and other connected devices, viewing them as means to infiltrate the corporate network. Just as printer servers were exploited in cyberattacks a few years ago, it is now urgent to establish security measures because almost everything within a company is connected to the Internet.

4. Increase in IoT DDoS attacks
The attack targeting the U.S. internet hosting service provider Dyn last October proved that many IoT devices lacking security features are significantly vulnerable to cyberattacks. As an increasing number of IoT devices are being installed on a large scale, the risk of security breaches is expected to rise. Once insecure IoT devices are distributed, it is nearly impossible to resolve the issue without recalling all devices or installing security updates. As the lack of security in IoT devices is expected to persist for the foreseeable future, attacks targeting these devices appear inevitable.

5. Ransomware that attacks the cloud
Given the large-scale transition to cloud-based storage and services, the cloud is becoming a lucrative target for attacks. Cloud security cannot be addressed solely by firewalls or traditional security policies. Consequently, there will be a shift in the direction of corporate security practices regarding where data should be protected. As cloud attacks can lead to millions of dollars in damages and the loss of critical data, the need to protect the cloud will continue to increase.

6. Increase in 'fileless' malware
'Fileless' infections, which execute directly into a computer's RAM without using any files, are difficult to detect because they cleverly evade intrusion prevention and antivirus programs. This type of attack increased throughout 2016 and is highly likely to continue gaining notoriety in 2017, primarily through PowerShell attacks.

7. Advancement of Security Technology through Machine Learning
In 2017, the fields of machine learning and artificial intelligence (AI) are expected to continue growing within the IT sector. Forrester forecasts that AI investment will increase by a staggering 300% in 2017 alone. As AI grows and evolves, companies will gain new and powerful insights, and collaboration between humans and machines will increase. From a security perspective, this growth will impact enterprises across various aspects, including endpoints and mechanisms in cloud environments. With the continued market launch of new forms of machine learning and AI, companies must adopt solutions capable of collecting and analyzing information from numerous endpoints and attack sensors. The big data analytics capabilities of these solutions will play a key role in leveraging machine learning at the forefront of the real-time changing global market.

8. Increase in phishing sites using HTTPS due to SSL abuse
Coupled with Google's recent policy of labeling HTTP-only sites as unsafe, the popularity of free SSL (Secure Sockets Layer) certificates is expected to weaken security standards and enable spear phishing or malware programs resulting from malicious search engine optimization practices.

9. Drones used for espionage and explosive attacks
There is also speculation that drones could be used for espionage or explosive attacks. While such incidents could occur in 2017, they are more likely to happen thereafter. It is predicted that so-called "dronejacking," in which drone signals are intercepted and the drone's path is redirected as desired by an attacker, could occur by 2025. Considering these possibilities, it is expected that anti-drone hacking technology will also be developed to control the drone's GPS and other critical systems.

10. Rogue countries that fund themselves through online theft
Rogue nation states posing a threat through threats such as missile launches or terrorism will attempt to steal money online. As seen in the SWIFT attacks, there is a dangerous possibility that rogue states could link with organized crime for private gain. Consequently, situations are also anticipated that could disrupt a nation's political, military, or financial systems.

Yoon Kwang-taek, Senior Vice President at Symantec Korea, emphasized, “With the expansion of cloud environments and the emergence of new IoT devices and services, it will become inevitable for companies to revise their established cybersecurity response strategies to adapt. The cloud environment will demand changes in network perimeter defense strategies, and as IoT devices are expected to become new bridgeheads for attackers to infiltrate enterprises, it is necessary to establish security threat analysis and strategies suited to this new environment and to adopt new response technologies.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
신윤오 기자