This page was machine-translated and may differ from the original. View original
[2017 Security Outlook] Respond with an Intelligent Next-Generation Security Platform
Palo Alto Networks Announces 2017 Security Outlook
Increase and evolution of phishing attacks, rising risk of medical data loss incidents
Palo Alto Networks announced its 2017 security outlook.
Palo Alto Networks identified the following as key points to watch in the security industry in 2017: the increase and evolution of phishing attacks; the need to secure effective security strategies based on threat intelligence capable of automated and rapid response; the introduction of a 'playbook' sharing model containing information on specific attack methods; the increased risk of medical data loss incidents due to the spread of SaaS app usage; and the growing importance of security due to the expansion of the public cloud.

Palo Alto Homepage
René Bonvanie, Chief Marketing Officer at Palo Alto Networks, stated, “Not only is the damage caused by evolving cyber attacks increasing, but new, unknown security threats are also continuously emerging. Furthermore, with expanding connectivity, web or email security alone can no longer keep enterprises safe from future cyber attackers.” "It is time to analyze the lifecycle of how cybercriminals infiltrate and execute attacks to gain an accurate understanding of this and to equip ourselves with an optimal intelligent next-generation security platform capable of responding to it," he said.
Phishing methods are still a welcome attack method for hackers
Phishing, a method that has caused various damages over a long period, is expected to remain a welcome attack tool for hackers. According to the 2016 Verizon Data Breach Report, 30% of phishing messages sent to targets are opened, and the average time taken to click on a malicious attachment is within 3 minutes and 45 seconds. These figures demonstrate that it is a highly effective and high-success-rate attack method. According to the Anti-Phishing Working Group (APWG)'s Q2 2016 Phishing Trends Report, 466,065 phishing sites were discovered during the second quarter of 2016, representing a 61% increase compared to the first quarter. Attackers are expected to be even more active in 2017, using increasingly realistic emails and landing pages as weapons.
Actionable intelligence measures must be taken
Security vendors and conscientious white-hat hackers are making continuous efforts to identify new indicators that signal a breach has occurred. Once these indicators are identified, they switch to defensive mechanisms to explore ways to control the attack and apply them to security tools, thereby taking measures to terminate the attack's lifecycle as quickly as possible. This process is referred to as actionable intelligence. In the past, it took network security companies anywhere from a few days to several weeks or even months to execute this entire process. Automation is necessary to shorten this process. Instead of analysts reading and analyzing intelligence reports to apply appropriate defense mechanisms and directly controlling the system, an automated system at the network level replaces this entire process, thereby enhancing network stability and securing effective security strategies.
Introduction of a 'playbook' sharing model containing information on specific attack methods
In the past, the network security community established best practices by sharing indicators of compromise. However, this approach has limitations in that, in many cases, it fails to identify situational correlations between the collected indicators. Typically, network security vendors have collected malicious IPs, URLs, and file hashes to block, but this data is limited to specific points in an attacker's lifecycle. Configuring blocking systems based on these indicators leaves room for bypassing them using other methods. As an alternative to this methodology, some network security communities share indicators through playbooks targeting specific attack groups.
Playbooks contain all indicators related to specific attack methods, and based on this, network security vendors can build defense mechanisms for every stage of an attack rather than blocking a single point in the attack's entire lifecycle. Previously, once an attacker discovered a blocking point, they could continue to attempt methods to bypass it; however, the playbook model leaves no room for the attacker to choose other options. To succeed in an attack, an entirely new attack must be redesigned. By adopting a playbook model, network security companies can establish defense mechanisms for all points an attacker might attempt, rather than simply defending a single point.
Increased risk of medical data loss due to the spread of SaaS app usage
As the use of cloud-based SaaS applications by various medical institutions to effectively share information increases, the likelihood of security incidents during this process is also expected to rise. This is because data can be leaked through users with file access permissions when sharing Personal Health Information (PHI). While some of these services allow free version users to access their enterprise versions, they also support administrators in strictly managing permissions. Even if medical institutions provide file sharing services to internal and external users through legal means and prohibit the use of unauthenticated sites, the risk of medical data leakage due to excessive information sharing remains high.
Increased importance of security due to the proliferation of public cloud
The financial market is reportedly at the final threshold of public cloud computing adoption. While most financial institutions remain hesitant to use public clouds due to concerns about information security, successive adoption cases of Amazon Web Services (AWS) and Microsoft Azure by financial institutions are being revealed. It is known that throughout 2016, various projects such as testing, evaluation, and PoC were conducted with a focus on cybersecurity cases, and 2017 will be a year in which the financial industry's challenge regarding cloud computing bears fruit.
It is analyzed that while the initial phase will focus on applications with minimal use of sensitive data, concerns regarding cloud usage in the financial market are expected to gradually diminish. With the benefits of cloud computing—such as resilience, scalability, and cost-efficiency—becoming established, the use of public cloud is projected to increase as security technologies are integrated into the architecture rather than merely added to services.
Increase and evolution of phishing attacks, rising risk of medical data loss incidents
Palo Alto Networks announced its 2017 security outlook.
Palo Alto Networks identified the following as key points to watch in the security industry in 2017: the increase and evolution of phishing attacks; the need to secure effective security strategies based on threat intelligence capable of automated and rapid response; the introduction of a 'playbook' sharing model containing information on specific attack methods; the increased risk of medical data loss incidents due to the spread of SaaS app usage; and the growing importance of security due to the expansion of the public cloud.
Palo Alto Homepage
René Bonvanie, Chief Marketing Officer at Palo Alto Networks, stated, “Not only is the damage caused by evolving cyber attacks increasing, but new, unknown security threats are also continuously emerging. Furthermore, with expanding connectivity, web or email security alone can no longer keep enterprises safe from future cyber attackers.” "It is time to analyze the lifecycle of how cybercriminals infiltrate and execute attacks to gain an accurate understanding of this and to equip ourselves with an optimal intelligent next-generation security platform capable of responding to it," he said.
Phishing methods are still a welcome attack method for hackers
Phishing, a method that has caused various damages over a long period, is expected to remain a welcome attack tool for hackers. According to the 2016 Verizon Data Breach Report, 30% of phishing messages sent to targets are opened, and the average time taken to click on a malicious attachment is within 3 minutes and 45 seconds. These figures demonstrate that it is a highly effective and high-success-rate attack method. According to the Anti-Phishing Working Group (APWG)'s Q2 2016 Phishing Trends Report, 466,065 phishing sites were discovered during the second quarter of 2016, representing a 61% increase compared to the first quarter. Attackers are expected to be even more active in 2017, using increasingly realistic emails and landing pages as weapons.
Actionable intelligence measures must be taken
Security vendors and conscientious white-hat hackers are making continuous efforts to identify new indicators that signal a breach has occurred. Once these indicators are identified, they switch to defensive mechanisms to explore ways to control the attack and apply them to security tools, thereby taking measures to terminate the attack's lifecycle as quickly as possible. This process is referred to as actionable intelligence. In the past, it took network security companies anywhere from a few days to several weeks or even months to execute this entire process. Automation is necessary to shorten this process. Instead of analysts reading and analyzing intelligence reports to apply appropriate defense mechanisms and directly controlling the system, an automated system at the network level replaces this entire process, thereby enhancing network stability and securing effective security strategies.
Introduction of a 'playbook' sharing model containing information on specific attack methods
In the past, the network security community established best practices by sharing indicators of compromise. However, this approach has limitations in that, in many cases, it fails to identify situational correlations between the collected indicators. Typically, network security vendors have collected malicious IPs, URLs, and file hashes to block, but this data is limited to specific points in an attacker's lifecycle. Configuring blocking systems based on these indicators leaves room for bypassing them using other methods. As an alternative to this methodology, some network security communities share indicators through playbooks targeting specific attack groups.
Playbooks contain all indicators related to specific attack methods, and based on this, network security vendors can build defense mechanisms for every stage of an attack rather than blocking a single point in the attack's entire lifecycle. Previously, once an attacker discovered a blocking point, they could continue to attempt methods to bypass it; however, the playbook model leaves no room for the attacker to choose other options. To succeed in an attack, an entirely new attack must be redesigned. By adopting a playbook model, network security companies can establish defense mechanisms for all points an attacker might attempt, rather than simply defending a single point.
Increased risk of medical data loss due to the spread of SaaS app usage
As the use of cloud-based SaaS applications by various medical institutions to effectively share information increases, the likelihood of security incidents during this process is also expected to rise. This is because data can be leaked through users with file access permissions when sharing Personal Health Information (PHI). While some of these services allow free version users to access their enterprise versions, they also support administrators in strictly managing permissions. Even if medical institutions provide file sharing services to internal and external users through legal means and prohibit the use of unauthenticated sites, the risk of medical data leakage due to excessive information sharing remains high.
Increased importance of security due to the proliferation of public cloud
The financial market is reportedly at the final threshold of public cloud computing adoption. While most financial institutions remain hesitant to use public clouds due to concerns about information security, successive adoption cases of Amazon Web Services (AWS) and Microsoft Azure by financial institutions are being revealed. It is known that throughout 2016, various projects such as testing, evaluation, and PoC were conducted with a focus on cybersecurity cases, and 2017 will be a year in which the financial industry's challenge regarding cloud computing bears fruit.
It is analyzed that while the initial phase will focus on applications with minimal use of sensitive data, concerns regarding cloud usage in the financial market are expected to gradually diminish. With the benefits of cloud computing—such as resilience, scalability, and cost-efficiency—becoming established, the use of public cloud is projected to increase as security technologies are integrated into the architecture rather than merely added to services.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













