Techday
This page was machine-translated and may differ from the original. View original

Fortinet Urges Enterprises to Develop New Security Strategies Based on Global Threat Trends

Google 우선 소스Published2018.10.15 07:03
96% of businesses have experienced at least one exploit attack.
Each security element for extended attack surface protection
We need to build an integrated security fabric

Cybercriminals are getting smarter and faster.

Fortinet Korea examined the global threat landscape and urgent security challenges, while also offering solutions for companies to intelligently protect themselves against the expanding digital attack surface.

“Cybercriminals are getting smarter and faster at leveraging exploits,” said Derek Manky, Fortinet’s global security strategist who visited Korea. “Furthermore, attackers are targeting an expanding attack surface and evolving their attack methodologies through continuous software development to maximize the effectiveness of their attacks.”

He added, "Cyber attackers are becoming more aggressive, with more and more attackers automating their tool sets and creating variants of well-known exploits. Furthermore, they are targeting more precisely, rather than targeting a large number of victims. Companies must develop new security strategies to counter these attacker tactics. Additionally, they must address the challenges of rapid attack velocity and scale by leveraging automated, integrated defenses, leveraging high-performance behavior-based detection techniques, and focusing on patching critical vulnerabilities through AI-driven threat intelligence insights,” he said.

The main contents of the 'Global Threat Outlook Report' published by FortiGuard Labs, Fortinet's security research lab, are as follows.

▲Few organizations have been spared from serious exploit attacks. Our research found that 96% of companies have experienced at least one serious exploit. Few companies remain unaffected by this evolving attack trend. Furthermore, nearly a quarter of companies reported cryptojacking malware attacks, with six malware variants reaching more than 10% of organizations. FortiGuard Labs also discovered 30 new zero-day vulnerabilities this quarter.

Cryptojacking is moving into home IoT devices. Cybercriminals are targeting IoT devices, such as home media devices, for cryptocurrency mining. These devices are attractive targets for attackers due to their abundant computing power and resources, and they can be fully exploited for malicious purposes. Because these devices are always connected, attackers can inject malware into them and use them for mining. Furthermore, the interfaces of these devices can be exploited as web browsers, expanding vulnerabilities and serving as attack vectors. This trend is expected to continue. Therefore, segmentation is necessary to effectively protect devices connected to corporate networks.

▲Botnet trends demonstrate the remarkable creativity of cybercriminals. Based on botnet trend data, we can understand how cybercriminals maximize their influence through malicious activities. A new Mirai botnet variant, WICKED, targets unpatched IoT devices and adds at least three exploits to its arsenal. VPNFilter, which targets SCADA/ICS environments by monitoring Modbus SCADA protocols, has also emerged as a significant threat. VPNFilter is particularly dangerous because it not only exfiltrates data but also disables devices, either individually or in groups, completely. The Anubis variant of Bankbot adds several innovative features, including ransomware, a keylogger, RAT functionality, SMS interception, screen locking, and call forwarding. As attackers become more creative, countering morphing attacks based on actionable threat intelligence becomes increasingly important.

Malware developers are becoming more agile in their development. Malware authors have long relied on polymorphism to evade detection. Recent attack trends are characterized by malware authors adopting more agile development practices to make their malware more difficult to detect and to effectively counter the latest strategies of anti-malware products. Multiple versions of GandCrab have been released this year, and its developers are continuously and rapidly updating the malware. Malware attacks are becoming more automated and agile in their development, incorporating new evasion techniques. To counter this agility, companies must have advanced threat protection and detection capabilities that can accurately identify these vulnerabilities.

▲Effective targeting of vulnerabilities is underway. Attackers are meticulously selecting the vulnerabilities they target. Examining prevalence and related exploit detections reveals that only 5.7% of known vulnerabilities are actually exploited. Given that attackers don't exploit most vulnerabilities, organizations should take a more proactive and strategic approach to vulnerability remediation.

▲The education and government sectors are using applications. When comparing application usage by industry, the government's SaaS application usage rate was 108% higher than the average. The education industry also had a 69% higher daily application usage rate than the average. Higher usage rates in these two industries can lead to greater application diversity. Organizations in these sectors need a security approach that eliminates silos between these applications, including multi-cloud environments, to ensure transparent visibility and security controls.

In South Korea, the most commonly reported exploits targeted known vulnerabilities in enterprise web systems running Apache Struts (CVE-2017-5638), Oracle WebLogic Server (CVE-2017-10271, CVE-2017-3506), and legacy IIS 6.0 web servers (CVE-2017-7269), as well as JavaScript-based cryptojacking. Exploits targeting vulnerabilities in D-Link and Linksys devices were next reported. Password stealing malware, Windows-based backdoors, and malware leveraging a known MS Office exploit (CVE 2017-11882) were also reported. Furthermore, the Gh0st.RAT botnet, which has been around for several years, remains the most active.

As highlighted in this report, of the 103,786 vulnerabilities listed on the CVE list, only 5,898 (5.7%) were actually targeted. These 5.7% included the well-known exploits described above. Attackers are constantly looking for easy targets with known vulnerabilities, and failing to address these vulnerabilities in a timely manner can expose your organization to risk.

Fortinet is taking responsibility for enterprise network security by continuously strengthening the Fortinet Security Fabric, which connects existing security devices to share and respond to each other, enabling integrated management of security previously handled separately across distributed networks such as the cloud, IoT, and remote devices at the core of the network infrastructure. The Fortinet Security Fabric is an automated, integrated security framework designed to protect today's dynamic networks. It supports the continuous assessments required to protect digital businesses, as well as comprehensive visibility, integrated detection of advanced threats, and automated response.

“As this global security outlook suggests, enterprises must build a security fabric that integrates each security element to effectively protect their assets from threats. This approach enables the rapid and accurate sharing of actionable threat intelligence, and provides automated remediation methods that can effectively respond to today’s multi-vector exploits,” said Won-Kyun Cho, CEO of Fortinet Korea. “Based on the security fabric, Fortinet Korea will provide domestic enterprises with seamless protection and actionable threat intelligence at every point of the network, from IoT to the cloud, and will fulfill its role as a security vendor that suggests optimal security strategies amidst rapidly changing threat trends.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자