This page was machine-translated and may differ from the original. View original
8 points announced, including the need for cloud system data protection
Emphasis on maintaining security management, including preventing potential threats and cybercriminals.
Palo Alto Networks announced its 2018 cybersecurity outlook.
Palo Alto Networks identified the need for data protection on cloud systems, the importance of data integrity management, the continued prevalence of ransomware, the need for security management regarding potential security threats from IoT devices, the advent of the era of attacks through the software supply chain, the need for automated threat response for operational technology environments, and the advancement of machine learning technology to enhance cybersecurity as key points to watch in the security industry in 2018.

Choi Won-sik, President of Palo Alto Networks Korea, said, “As interconnectedness is becoming increasingly deep, we must assume that cyberattacks are inevitable events and make every effort to prepare.” “In order to leverage new technologies such as IoT and artificial intelligence as business opportunities, it is necessary to identify not only current but also potential threats, determine what preparations are needed to mitigate them, and maintain a high level of cybersecurity management to stay one step ahead of cybercriminals,” he said.
Need for data protection on cloud systems
AWS S3 (Simple Storage Service) is a representative third-party cloud service, and AWS assumes responsibility for the security of the cloud and infrastructure through a shared responsibility model. However, since the scope of this security includes networks, storage, and computing resources, and the responsibility for the security of data stored in the cloud lies with the user, the importance of responses related to this is expected to increase.
AWS S3 uses 'buckets,' which are containers for online data storage in the cloud, and if user errors occur regarding the bucket configuration, the data can be freely accessed over the internet. In fact, over the past few months, incidents have occurred in which sensitive files, passwords, home addresses, customer databases, and information regarding 180 million U.S. voters were exposed.
Particular caution must be exercised when configuring buckets regarding data that can be overwritten. This is because if an attacker identifies a modifiable bucket, they could upload malware to it and overwrite the files. In addition, if code is stored in such a repository, it can also be changed.
Data is the driving force of new industries , the importance of data integrity management
Data is emerging as a new oil field in the era of the Fourth Industrial Revolution. As the damage caused by data loss and theft to businesses and governments grows, the demand for ensuring data integrity is expected to increase.
If data integrity is compromised, it can deal a fatal blow to financial markets. It becomes possible to inflate corporate stock prices by manipulating sales figures, and for public institutions promoting smart cities, serious disruptions could result if data from IoT systems—ranging from traffic lights to water supply systems—is altered.
To ensure data integrity, it is necessary to identify what data is held, how it was collected and generated, and where the most sensitive parts of that data are located. Additionally, multi-factor authentication (MFA) should be utilized to provide an extra layer of security in cases where usernames or passwords fail to provide security. Along with this, sensitive data must be protected through encryption, and the effectiveness of encryption depends on the key management strategy adopted.
Ransomware fever continues
Ransomware attackers, having gained experience in generating successful profits last year, are expected to cause continued damage in 2018 with more sophisticated techniques and increased scale. This is because ransomware attacks, which have evolved into high-profit business models, can be executed with only limited technology, and attacks have become easier with the emergence of Ransomware as a Service.
In addition, it is predicted that in 2018, there will be more ransomware aimed at political issues rather than financial gain. Even in 2017, the ransomware 'RanRan,' which originated in the Middle East, demanded that users create websites to send messages to politicians instead of demanding money.
Given that legacy security solutions are inevitably becoming more vulnerable to ransomware, the most effective countermeasure is to secure a platform based on prevention policies that enables endpoints and firewalls to communicate automatically and share threat intelligence in real time, regardless of where the attack occurs.
Security management is necessary for potential security threats to IoT devices.
While the positive impact of Internet of Things technology on daily life is increasing, security threats are also rising behind the convenience, and in particular, it is becoming possible for attackers to cross corporate networks through personal devices.
Even if personal devices are not company assets, CISOs should include measures for managing these devices within their corporate security strategies. In addition, regular training for employees on application settings and device security settings must be conducted.
The Arrival of the Era of Attacks via the Software Supply Chain
Over the past two years, there have been instances of cyber attacks occurring through software supply networks that provide trusted software and updates. XcodeGhost, KeRanger, and NotPetya are examples of this; instead of directly attacking targets using phishing and vulnerabilities, these attacks exploited the 'trust' granted by users to developers to access other networks by targeting software developers. In 2018, such attacks are expected to become even more rampant in terms of frequency and severity.
Attacks through the software supply chain suggest the need to build a network capable of securing visibility into every point of the attack lifecycle and detecting and blocking behaviors that deviate from typical patterns. To prepare for this new era of attacks, it is necessary to secure technologies and processes that can prevent trusted software from suddenly transforming into malware through automatic updates.
Automated threat response needed for Operational Technology (OT) environments
The demand for Automated Threat Response (ATR) technology is increasing. Recent malicious activities are employing predefined actions to counter new technologies such as behavioral analysis and artificial intelligence. ATR is a technology designed to automate threat detection processes and closed-system defense mechanisms, offering the advantage of reducing the burden on SecuOps and shortening response times. As the frequency and scale of sophisticated attacks continue to evolve, it is essential to secure ATR technology based on behavioral analysis and intelligent security threat analysis environments.
In particular, 2018 is expected to be the year when the effects of adopting ATR in the OT domain become visible. This is because large-scale deployments for Industrial Control System (ICS) security in critical infrastructure and manufacturing environments are projected to begin. In fact, major companies in the field have completed Proof of Concept (PoC) and entered the refinement phase, and behavioral analysis and anomaly detection technologies are being added to strengthen security in OT environments. These solutions include dedicated sensors and modules to supplement SIEM (Security Information and Event Management). Initially built as independent individual detection tools, these ICS network monitoring solutions will gradually be integrated into equipment such as next-generation firewalls to effectively respond to threats.
Advancement of machine learning technology to enhance cybersecurity
In the past, many companies responded to cyber attacks using signature-based security products on endpoints, networks, or the cloud; however, signature-based malware detection capabilities are becoming ineffective as cyber attackers automate malware generation. While machine learning technology cannot be definitively called a groundbreaking solution for cyber security, its impact on defense approaches against cyber attacks continues to grow. Palo Alto Networks also uses machine learning to predict user and device behavior and detect anomalous behaviors that suggest signs of an attack, such as Traps, an intelligent endpoint security product, and LightCyber, a behavioral analysis solution for network security.
In 2018, it is projected that an increasing number of CISOs will incorporate machine learning technology into their cybersecurity strategies. In fact, in the healthcare sector, where vast amounts of data are generated, the use of machine learning for intelligent malware detection is already on the rise, and applications for machine learning are expected to continue growing.
Emphasis on maintaining security management, including preventing potential threats and cybercriminals.
Palo Alto Networks announced its 2018 cybersecurity outlook.
Palo Alto Networks identified the need for data protection on cloud systems, the importance of data integrity management, the continued prevalence of ransomware, the need for security management regarding potential security threats from IoT devices, the advent of the era of attacks through the software supply chain, the need for automated threat response for operational technology environments, and the advancement of machine learning technology to enhance cybersecurity as key points to watch in the security industry in 2018.
Choi Won-sik, President of Palo Alto Networks Korea, said, “As interconnectedness is becoming increasingly deep, we must assume that cyberattacks are inevitable events and make every effort to prepare.” “In order to leverage new technologies such as IoT and artificial intelligence as business opportunities, it is necessary to identify not only current but also potential threats, determine what preparations are needed to mitigate them, and maintain a high level of cybersecurity management to stay one step ahead of cybercriminals,” he said.
Need for data protection on cloud systems
AWS S3 (Simple Storage Service) is a representative third-party cloud service, and AWS assumes responsibility for the security of the cloud and infrastructure through a shared responsibility model. However, since the scope of this security includes networks, storage, and computing resources, and the responsibility for the security of data stored in the cloud lies with the user, the importance of responses related to this is expected to increase.
AWS S3 uses 'buckets,' which are containers for online data storage in the cloud, and if user errors occur regarding the bucket configuration, the data can be freely accessed over the internet. In fact, over the past few months, incidents have occurred in which sensitive files, passwords, home addresses, customer databases, and information regarding 180 million U.S. voters were exposed.
Particular caution must be exercised when configuring buckets regarding data that can be overwritten. This is because if an attacker identifies a modifiable bucket, they could upload malware to it and overwrite the files. In addition, if code is stored in such a repository, it can also be changed.
Data is the driving force of new industries , the importance of data integrity management
Data is emerging as a new oil field in the era of the Fourth Industrial Revolution. As the damage caused by data loss and theft to businesses and governments grows, the demand for ensuring data integrity is expected to increase.
If data integrity is compromised, it can deal a fatal blow to financial markets. It becomes possible to inflate corporate stock prices by manipulating sales figures, and for public institutions promoting smart cities, serious disruptions could result if data from IoT systems—ranging from traffic lights to water supply systems—is altered.
To ensure data integrity, it is necessary to identify what data is held, how it was collected and generated, and where the most sensitive parts of that data are located. Additionally, multi-factor authentication (MFA) should be utilized to provide an extra layer of security in cases where usernames or passwords fail to provide security. Along with this, sensitive data must be protected through encryption, and the effectiveness of encryption depends on the key management strategy adopted.
Ransomware fever continues
Ransomware attackers, having gained experience in generating successful profits last year, are expected to cause continued damage in 2018 with more sophisticated techniques and increased scale. This is because ransomware attacks, which have evolved into high-profit business models, can be executed with only limited technology, and attacks have become easier with the emergence of Ransomware as a Service.
In addition, it is predicted that in 2018, there will be more ransomware aimed at political issues rather than financial gain. Even in 2017, the ransomware 'RanRan,' which originated in the Middle East, demanded that users create websites to send messages to politicians instead of demanding money.
Given that legacy security solutions are inevitably becoming more vulnerable to ransomware, the most effective countermeasure is to secure a platform based on prevention policies that enables endpoints and firewalls to communicate automatically and share threat intelligence in real time, regardless of where the attack occurs.
Security management is necessary for potential security threats to IoT devices.
While the positive impact of Internet of Things technology on daily life is increasing, security threats are also rising behind the convenience, and in particular, it is becoming possible for attackers to cross corporate networks through personal devices.
Even if personal devices are not company assets, CISOs should include measures for managing these devices within their corporate security strategies. In addition, regular training for employees on application settings and device security settings must be conducted.
The Arrival of the Era of Attacks via the Software Supply Chain
Over the past two years, there have been instances of cyber attacks occurring through software supply networks that provide trusted software and updates. XcodeGhost, KeRanger, and NotPetya are examples of this; instead of directly attacking targets using phishing and vulnerabilities, these attacks exploited the 'trust' granted by users to developers to access other networks by targeting software developers. In 2018, such attacks are expected to become even more rampant in terms of frequency and severity.
Attacks through the software supply chain suggest the need to build a network capable of securing visibility into every point of the attack lifecycle and detecting and blocking behaviors that deviate from typical patterns. To prepare for this new era of attacks, it is necessary to secure technologies and processes that can prevent trusted software from suddenly transforming into malware through automatic updates.
Automated threat response needed for Operational Technology (OT) environments
The demand for Automated Threat Response (ATR) technology is increasing. Recent malicious activities are employing predefined actions to counter new technologies such as behavioral analysis and artificial intelligence. ATR is a technology designed to automate threat detection processes and closed-system defense mechanisms, offering the advantage of reducing the burden on SecuOps and shortening response times. As the frequency and scale of sophisticated attacks continue to evolve, it is essential to secure ATR technology based on behavioral analysis and intelligent security threat analysis environments.
In particular, 2018 is expected to be the year when the effects of adopting ATR in the OT domain become visible. This is because large-scale deployments for Industrial Control System (ICS) security in critical infrastructure and manufacturing environments are projected to begin. In fact, major companies in the field have completed Proof of Concept (PoC) and entered the refinement phase, and behavioral analysis and anomaly detection technologies are being added to strengthen security in OT environments. These solutions include dedicated sensors and modules to supplement SIEM (Security Information and Event Management). Initially built as independent individual detection tools, these ICS network monitoring solutions will gradually be integrated into equipment such as next-generation firewalls to effectively respond to threats.
Advancement of machine learning technology to enhance cybersecurity
In the past, many companies responded to cyber attacks using signature-based security products on endpoints, networks, or the cloud; however, signature-based malware detection capabilities are becoming ineffective as cyber attackers automate malware generation. While machine learning technology cannot be definitively called a groundbreaking solution for cyber security, its impact on defense approaches against cyber attacks continues to grow. Palo Alto Networks also uses machine learning to predict user and device behavior and detect anomalous behaviors that suggest signs of an attack, such as Traps, an intelligent endpoint security product, and LightCyber, a behavioral analysis solution for network security.
In 2018, it is projected that an increasing number of CISOs will incorporate machine learning technology into their cybersecurity strategies. In fact, in the healthcare sector, where vast amounts of data are generated, the use of machine learning for intelligent malware detection is already on the rise, and applications for machine learning are expected to continue growing.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)












