Techday
This page was machine-translated and may differ from the original. View original

7 Cyber Security Issues in 2019 You Should Watch Out For

Google 우선 소스Published2018.12.17 10:10
Double-edged sword AI, aiding both offense and defense
The spread of 5G and the popularization of IoT trigger new attacks
Increased frequency and impact of supply chain exploit attacks

Major Cyber Attack Cases in 2018

The major cybersecurity and privacy trends of 2019 can be inferred from those of 2018.

Cyber hacking of major corporate systems and websites continued in 2018, and this is expected to repeat itself without fail in 2019. Many globally renowned companies suffered serious security breaches this year.

The industry believes that the leak of a database containing approximately 340 million records of personal information at Exactis, a marketing and data collection company, is likely the largest single data breach incident.

In addition to common corporate attacks, threat activities targeting a wide range of targets and victims accelerated in 2018. In the social media sector, it is estimated that hackers have stolen the information of approximately 30 million Facebook users.

Government-backed attack groups are using cyber scouting and attacks to access everything from corporate secrets to sensitive government and infrastructure systems, and the number of such groups is increasing.

From the perspective of individual users, personal data of 150 million people was stolen due to an account leak on Under Armour's MyFitnessPal app.

Symantec 2019 Security Outlook

Accordingly, Symantec announced its 2019 cybersecurity outlook on the 17th as follows.


First, attackers will exploit AI systems and support attacks through AI.
The commercial potential of AI has begun to be realized in recent years. AI-based systems are already being used in many business operations. These AI systems help automate manual tasks and improve decision-making and other human activities. However, because many AI systems contain vast amounts of data, they are being viewed as promising targets by attackers.

In addition, concerns are gradually rising among research personnel that these AI systems are vulnerable to the influx of malware that can compromise system logic and affect operations. In 2019, concerns about the vulnerabilities of some AI technologies will grow. The targeting of critical AI systems would mean repeating the series of events observed when the Internet emerged 20 years ago. In particular, at that time, the Internet rapidly attracted the attention of cybercriminals and hackers following the explosive growth of internet-based e-commerce.

Attackers will not target only AI systems. They will leverage the power of AI technology itself to further intensify their attack activities. AI-based automated systems can scour networks and systems to identify undiscovered vulnerabilities that could be exploited. Furthermore, AI can be used to make phishing and other social engineering attacks more sophisticated by creating highly realistic videos and audio, or well-crafted emails, to deceive targeted individual users. In addition, AI can be utilized in disinformation campaigns that appear factual.

For example, AI can generate plausible fake videos in which a company's CEO announces massive financial losses, serious security breaches, or other significant news. If such fake videos spread widely, they can have a major impact on the company before the truth is revealed.

As attack toolkits are sold online, attackers can now generate new threats relatively easily. Eventually, AI-based attack tools will emerge that enable even petty criminals to carry out sophisticated targeted attacks. In the past, developing highly personalized attacks was labor-intensive and costly. By using AI-based toolkits along with tools that automate the development of such attacks, the marginal cost required to develop each additional targeted attack can be effectively reduced to zero.

AI will empower both attackers and defenders with new capabilities.

Second, protection programs will also rely on AI for counterattacks and vulnerability identification.
There are also positive aspects regarding AI for security. Threat identification systems are already using machine learning techniques to identify entirely new types of threats. Furthermore, it is not only attackers who use AI systems to investigate exposed vulnerabilities. Security personnel can also utilize AI to strengthen defenses against attacks. For example, AI-based systems can conduct a series of simulated attacks on a corporate network over a period of time to accidentally discover vulnerabilities through repeated attacks, allowing for corrective measures to be taken before they are discovered by attackers.

At home, AI and other technologies will help better protect individuals' digital security and personal information. AI will be built into mobile phones to warn users if certain behaviors are risky. For example, when setting up a new email account, the phone could automatically warn users to enable two-factor authentication. Over time, such security-based AI can help people better understand the gains and losses associated with giving up personal information in exchange for using applications or obtaining other incidental benefits.


Third, the attack surface will increase due to the deployment and introduction of 5G.
In December 2018, commercial 5G services were launched in Korea for the first time in the world. 2019 will be a year of explosive growth for 5G networks worldwide. While it will take time for 5G networks, phones, and other devices to be widely utilized, they will certainly grow rapidly.

For attackers, 5G is a bigger target than LTE.

IDG predicted that 2019 would be a significant year for 5G. It projected that the market for 5G and 5G-related network infrastructure would grow from approximately $528 million in 2018 to $26 billion in 2022, recording an average annual growth rate of 118%.

While most of the interest in 5G is focused on smartphones, the number of 5G-enabled mobile phones will be limited in 2019. As 5G mobile networks become more widespread, some carriers will offer fixed 5G mobile hotspots and 5G-enabled home routers. Given that the maximum data transmission speed of 5G networks is 10 Gbps, the transition to 5G will facilitate new operating models, new architectures, and consequently the emergence of new vulnerabilities.

Over time, there will be an increasing number of 5G IoT devices connecting directly to 5G networks rather than going through Wi-Fi routers. Due to this trend, 5G IoT devices will become more vulnerable to direct attacks. For home users, monitoring all devices will become more difficult as all IoT devices bypass the central router.

Broadly speaking, the ability to easily back up or transfer large amounts of data to cloud-based storage will provide attackers with a wealth of new attack targets.


Fourth, IoT-based events will evolve beyond large-scale DDoS attacks into more dangerous and new forms of attack.
For several years, large-scale botnet-based DDoS attacks have utilized tens of thousands of infected IoT devices to generate traffic sufficient to paralyze target websites. Although these attacks do not receive much media attention, they continue to occur and will remain a threat in the future.

The security of IoT devices will now be linked to national security.

At the same time, it is expected that IoT devices with weak security will be used for other harmful purposes. The biggest concern will be attacks targeting IoT devices that connect the digital and real worlds. Among these IoT devices, some, such as automobiles, are powered by electricity, while others control critical systems.

Attacks on IoT devices controlling critical infrastructure, such as power distribution and communication networks, are expected to increase daily. Furthermore, as home IoT devices become more commonplace, there may be attempts to weaponize these devices in the future. For instance, during a harsh winter, a country could shut down home thermostats in an enemy nation.


Fifth, attackers will capture more data being transmitted.
There is a possibility that attacks exploiting vulnerable consumer IoT devices, such as home Wi-Fi routers, in new ways may emerge. Cases of large-scale crypto-jacking attacks involving the aggregation of numerous IoT devices for cryptocurrency mining have already appeared.

Attempts to intercept data in transit are expected to increase.

Since 2019, attempts to access these devices to steal some data passing through home routers and other IoT hubs are expected to increase. Malware inserted into these routers can display malicious fake web pages to steal bank account information, capture credit card numbers, or leak confidential information.

Sensitive data tends to be more securely protected today when stored without moving. For example, since e-commerce merchants do not store credit card CVV numbers, it is more difficult for attackers to steal credit card information from e-commerce databases. Therefore, there is no doubt that attack techniques to steal consumers' data in transit will continue to evolve.

From a corporate perspective, there were numerous instances of data in transit being leaked in 2018. An attack group called Magecart stole credit card numbers and other sensitive consumer information from e-commerce sites by planting malicious scripts directly on target websites or by infecting third-party vendors used by the sites.

Recently, the websites of numerous global companies have been damaged by such 'formjacking' attacks. In another attack targeting corporate data in transit, VPN filter malware infected multiple routers and NAS (network-attached storage) devices to steal account information, alter network traffic, decrypt data, and provide entry points for other malicious activities within the targeted organization.

Because network-based corporate attacks provide visibility into the target company's operational status and infrastructure, cyber attackers are expected to continue focusing on network-based corporate attacks in 2019.


Sixth, the frequency and impact of supply chain exploit attacks will increase.
Attacks targeting the software supply chain are becoming increasingly common, such as attackers embedding malware into legitimate software packages at routine distribution locations. These attacks can occur during the manufacturing phase of software vendors or third-party suppliers.

Companies must now actively prevent software supply chain intrusions.

A typical attack scenario involves attackers replacing legitimate software updates with malicious versions to distribute them quickly and stealthily to targeted audiences. Any user who receives the software update has their computer automatically infected, providing the attacker with a foothold to infiltrate the infected environment. This type of attack is on the rise and becoming increasingly sophisticated.

In the future, it is predicted that there will also be attempts to infect the hardware supply chain. For example, attackers could infect or modify chips, or add source code to the UEFI/BIOS firmware before components such as UEFI/BIOS are installed in millions of computers. This type of threat is very difficult to remove and may remain even after rebooting the infected computer or reformatting the hard disk.

Attackers will continuously seek new and more sophisticated opportunities to infiltrate the software supply chains of targeted organizations.


Seventh, laws and regulations will increase due to security and privacy concerns.
With the European Union (EU) implementing the General Data Protection Regulation (GDPR) in 2018, it appears that various security and privacy policies will be implemented in countries outside the EU. Canada has already implemented a law similar to the GDPR, and Brazil recently passed a new personal data protection bill similar to the GDPR, which is scheduled to be implemented in 2020.

Major countries around the world are creating laws modeled after the EU's GDPR.

Australia and Singapore have enacted a 72-hour notification system for breaches influenced by the GDPR, and India is considering legislation inspired by the GDPR. In addition, many countries around the world have GDPR adequacy or are discussing adequacy assessments.

Immediately after the implementation of the GDPR, the United States passed a privacy law in California that is considered the strictest in U.S. history. Consequently, the impact of the GDPR on the global stage is expected to become more evident in 2019.

The U.S. Congress is already looking more deeply into the areas of security and privacy protection. These laws are gaining momentum and are likely to materialize in 2019. Consequently, interest in election system security in the United States will continue to increase as the 2020 presidential election campaign takes place.

While it is almost certain that legal and regulatory activities to address security and privacy demands will increase, some requirements are likely to be counterproductive rather than helpful. For example, overly broad regulations can prevent security companies from sharing even general information to identify and respond to attacks.

If security and privacy regulations are poorly established, new vulnerabilities can be created even if other vulnerabilities are resolved.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자