인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Symantec Announces Top 10 Security Predictions for 2018

Google 우선 소스Published2017.12.07 10:57
Bitcoin-Targeting Crime Emerges, Attacks Using Artificial Intelligence to Appear

Symantec has announced its "Top 10 Security Predictions for 2018."

Cybercriminals continue to attempt various attack methods targeting enterprises and individuals in line with the changing IT environment. Symantec forecasts that while threats such as ▲ransomware attacking cloud infrastructure ▲increased file-less malware ▲IoT devices becoming a new revenue source for cybercriminals that emerged this year will persist, new patterns will emerge in 2018 including ▲the emergence of cybercriminals targeting Bitcoin ▲the beginning of cyber attacks utilizing artificial intelligence and machine learning.

Prediction 1. Financial Malware Damage Scale to Increase More Than Ransomware
Financial malware was one of the earliest types of malware from which cybercriminals could gain financial benefit. Financial malware has evolved from a simple credential collection tool to sophisticated attack methods that target multiple banks and banking systems while employing techniques to evade detection. Financial malware has been confirmed as a highly profitable technique for cybercriminals. As today's financial services transition to mobile application-based platforms, the effectiveness of existing attacks diminishes, and cybercriminals are increasingly shifting their attack targets to mobile platforms. As a result, the revenue cybercriminals can obtain from malware targeting the financial sector is expected to increase further, and this is forecasted to exceed the damage scale of ransomware.

Prediction 2. Bitcoin Receiving Attention as a New Attack Target
Blockchain is now beginning to be used not only for digital currency but also for inter-bank settlement and Internet of Things (IoT) applications. Such uses are still in their early stages and are not yet major targets of most cybercriminals. Rather than attacking blockchain itself, cybercriminals will focus on bitcoin transactions or intercepting users' bitcoin wallets, which are relatively easier to attack and more profitable. Cybercriminals will deceive victims into installing coin-miners on their computers or mobile devices and will gain access to computer resources such as CPUs.

Prediction 3. Cyber Crime Using Artificial Intelligence and Machine Learning to Emerge
Today, cyber security cannot be discussed without artificial intelligence (AI) and machine learning (ML). Of course, in most cases, AI and machine learning technologies in cyber security are being deployed with emphasis on protection and detection techniques. However, in 2018, the possibility has significantly increased that artificial intelligence and machine learning will be used maliciously by cybercriminals, such as to evade detection. 2018 may be the first year we witness a confrontation between artificial intelligences in the cyber security domain. After network infiltration, cybercriminals are forecasted to utilize artificial intelligence for network attacks and reconnaissance, which typically require the most labor.

Prediction 4. Ransomware Targeting High-Value Home Smart Devices
Ransomware, where cybercriminals hold users' files and systems hostage and demand large sums for ransom to generate revenue, is a serious problem today and one of the most representative criminal acts born of the internet society. A gold rush phenomenon seeking high profits is occurring, causing increased ransomware distribution, and in the underground cybercrime world, professional ransomware business models including Ransomware-As-A-Service are being detected. These cybercriminals are considering ways to expand their attack targets in light of the increase in expensive home smart devices. Various smart devices including smart TVs and smart toys command high prices of thousands of dollars, and most general users are unaware of the security threats these smart devices face, which increases their attractiveness as attack targets for cybercriminals.

Prediction 5. Increased Cyber Attacks Exploiting the Convenience of IoT Devices
In 2017, cases emerged of large-scale DDoS attacks using tens of thousands of IoT devices in home and work environments. Since cybercriminals seek to exploit weak security settings and inadequate management of home IoT devices, this trend will continue. Furthermore, attackers are expected to steal input information or sensors from IoT devices and input forged voice or images, allowing attackers who have compromised IoT devices rather than legitimate users to control them as desired.

Prediction 6. Home IoT Devices Exploited as Footholds for Network Penetration
Cybercriminals are now expected to use home IoT devices not only for DDoS and ransomware attacks but also as footholds for continued access to victims' networks. Generally, users do not consider home IoT devices from a cyber security perspective, so unlike PCs, they often remain without regular updates and with initial settings unchanged. Cybercriminals are expected to exploit these vulnerable environments to secure a kind of backdoor that allows them continuous access to victims' networks and systems, regardless of victims' repeated attempts to clean up and protect their IoT devices or PCs.

Prediction 7. Supply Chain Attacks Emerging as a New Attack Trend
Supply chain attacks are a key component of classic espionage and signals-intelligence activities, targeting contractors, systems, enterprises, and suppliers. State-sponsored cyber attackers utilize intelligence capabilities to exploit vulnerabilities in the supply chain, making attacks highly effective. Such attacks are expanding into the cybercrime domain and emerging as a new trend. Attackers use publicly available information regarding suppliers, contractors, partners, and key individuals to identify attack targets in the supply chain and attack the most vulnerable points. Since numerous high-profile attacks succeeded this year and last year, attacks targeting the supply chain by attackers are forecast to continue in 2018.

Prediction 8. Explosion in File-less and File-light Malware
From 2016 to 2017, file-less and file-light malware increased steadily, and attackers have targeted organizations lacking adequate defenses against these new types of malware threats. Such attacks have characteristics of few indicators of compromise (IoC), use tools commonly used by victims, and involve unrelated complex behaviors, making them more difficult to disrupt, track, and defend against. Just as early ransomware success by a small number of cybercriminals triggered a gold rush, other cybercriminals are gathering to utilize such new attack techniques. Therefore, an explosion in file-less and file-light malware is expected in 2018, and while numerically less than traditional malware, they are expected to pose serious threats.

Prediction 9. Continued Conflict with Software-as-a-Service (SaaS) Security
As enterprises pursue agility and digital transformation, adoption of Software-as-a-Service (SaaS) is increasing exponentially. Within this change and adoption, enterprises face various security challenges. These security challenges are not new problems and are already well known, yet enterprises continue to struggle with them. Access control, data control, user behavior, and data encryption vary significantly across SaaS applications, and enterprises will continue to grapple with resolving these issues in 2018. As new regulations on personal information and data protection are expected to be introduced globally, enterprises face increased risk not only of fines but also potential damage to corporate reputation.

Prediction 10. Increased Data Leakage Due to Infrastructure-as-a-Service (IaaS)
Infrastructure-as-a-Service (IaaS) is completely transforming how enterprises operate while providing benefits in terms of agility, scalability, innovation, and security. However, IaaS can leak enormous amounts of data through simple mistakes and can shut down entire systems. Having security controls above the IaaS layer level is actually the responsibility of customers, but traditional control methods do not fit well in practice. Ineffective or inappropriate security controls result in confusion, errors, and design issues, while new controls may be overlooked. As a result, more data leakage may occur in 2018, and enterprises will struggle to make their security programs effective for IaaS.

Yun Kwang-taek, CTO (Chief Technology Officer) of Symantec Korea, stated, "In 2018, artificial intelligence (AI) and machine learning, which are currently in the spotlight as advanced technologies, will be adversarially used by cybercriminals, and IoT devices that enrich our lives will become new targets for attackers, being exploited as footholds for network penetration in enterprises or homes," and added, "While cyber attacks continue to evolve to circumvent existing security technologies that have been invested, enterprises must establish strategies and security systems capable of responding to new threats, and individual users must make security checks of mobile smart devices and home IoT devices a routine practice."
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
김지혜 Reporter