마이크로칩 8월
This page was machine-translated and may differ from the original. View original

Fortinet Releases 2018 Security Threat Outlook

Google 우선 소스Published2018.01.02 12:19
Attacks using cutting-edge technologies like artificial intelligence will accelerate in 2018.

Fortinet Korea announced the '2018 Security Threat Outlook' researched by its threat research institute, FortiGuard Labs.

The attack surface is expected to continue to expand over the next two years, significantly weakening visibility and control over infrastructure. The cybercrime market is rapidly adopting cutting-edge technologies, such as artificial intelligence (AI), to launch more effective attacks. This trend is expected to accelerate further in 2018.

The rise of self-learning hivenets and swarmbots: Building on sophisticated attacks like Hajime, Devil's Ivy, and Reaper, cybercriminals will replace botnets with intelligent clusters of compromised devices called "hivenets." Hivenets utilize self-learning technology to more effectively attack vulnerable systems. They can exchange information with each other and launch attacks based on shared local information.

Additionally, zombies will become smarter and will be able to carry out commands without the botnet herder's guidance. Hivenets can grow exponentially in swarms, attacking multiple victims simultaneously and significantly weakening mitigation and response efforts. Attackers will use 'swarms of compromised devices', or swarmbots, to identify and target different attack vectors at incredible scale and speed.

However, the sheer speed of attack can eliminate even the predictability essential for defense. FortiGuard Labs detected 2.9 billion botnet communication attempts in the first quarter of this year, and has previously highlighted the potential threat of hivenets and swarmbots.

• Ransomware Commercial Services Business Scale Grows: Ransomware and other attacks have increased the ransomware threat by 35 times over the past year. However, this threat scale is expected to grow even further. The next target for ransomware seeking to increase revenue will be cloud service providers and other commercial services. The complex, hyperconnected networks developed by cloud providers create single points of failure (SPOF) for hundreds of enterprises, government agencies, critical infrastructure, healthcare organizations, and more.

Cybercriminals will apply AI technologies to multi-vector attack methods to search for, detect, and exploit vulnerabilities in cloud environments. Attackers could incur significant costs to criminal organizations and potentially disrupt services for hundreds, thousands, or even millions of customers.

• Next-Generation Morphic Malware: Beyond 2018, machine-generated malware based on automated vulnerability detection and complex data analysis will emerge. Polymorphic malware is not new. However, this malware is novel in that it uses AI to create sophisticated new code that mimics the "routines" of machines, enabling it to evade detection.

As existing tools evolve, attackers will develop optimal exploits for each unique vulnerability. Malware can leverage learning models to evade security, and over a million virus variants can be created daily. However, until now, these have been algorithm-based, with little sophistication or control over the output.

FortiGuard Labs detected 62 million malware samples in the first quarter of 2017. Furthermore, among the millions of malware detections, the company identified 16,582 variants from 2,534 malware families, with one in five organizations reporting malware targeting mobile devices. As malware automation proliferates, this threat landscape is expected to worsen in the coming year.

• Critical Infrastructure at the Front Line of Threats: Critical infrastructure providers are currently the most vulnerable due to strategic and economic threats from attackers. These organizations operate critical networks that protect essential services and information. However, most critical infrastructure and operational technology networks are inherently designed to be air-gapped and isolated, making them more vulnerable.

Because attacks on critical networks can have devastating consequences, intelligent security is essential. Critical infrastructure providers are striving to gain a technological edge against criminal and terrorist organizations. The combination of attacker tactics and operational and information technology capabilities will make securing critical infrastructure an increasingly critical security challenge in 2018 and beyond.

• The Dark Web and Cybercrime Economy Offer New Services Through Automation: As the cybercrime world evolves, the Dark Web is also evolving. Crime-as-a-Service (CaaS) organizations will leverage new automation technologies to offer new services on the Dark Web. We have discovered that intelligent services leveraging machine learning are already being offered in Dark Web marketplaces.

For example, a service known as FUD (Fully Undetectable) is already available on marketplaces. This service allows criminal developers to upload attack code and malware, backed by a paid analysis service. They then receive reports on whether or not their code is detectable by security tools from other vendors. Attackers actively use machine learning to learn what and how their labs detect, and then immediately modify their code to make their cybercrime and infiltration tools undetectable.

However, sandbox tools with machine learning can quickly identify previously undetectable threats and provide dynamic protection.

• Threat Response: Advances in automation and AI have expanded the opportunities for sophisticated cybercriminals to develop and deploy tools that pose a significant threat to the digital economy. Security solutions must be built around integrated security technologies, actionable threat intelligence, and a dynamically configurable security fabric. Security can operate at the speed of digital when attack responses are automated and intelligence and self-learning empower networks to make effective, autonomous decisions.

This enables expanded visibility and centralized control. Furthermore, strategic segmentation allows for thorough protection of network infrastructure by neutralizing threats across the network ecosystem, from endpoint devices and local network resources to the cloud, and quickly identifying, isolating, and remediating compromised devices. Furthermore, it's crucial to maintain basic security hygiene as part of your security protocols. While often overlooked by enterprises, this practice is crucial to preventing serious consequences.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김지혜 기자