Techday
This page was machine-translated and may differ from the original. View original

2019 Security Threats "Must Be Responded to with Automation"

Google 우선 소스Published2019.01.09 09:01
Cyber threat response, by applying automation features
Point products built on a distributed network
Efforts to integrate into one are absolutely necessary.

FortiGuard Labs announced its 2019 security threat outlook.

On the 7th, Fortinet Korea announced the '2019 Security Threat Outlook' researched by FortiGuard Labs.

The 2019 Security Threat Outlook describes important strategic changes for companies to prepare for attacks, along with methods and strategies predicted to be used by cybercriminals in the near future.


Cyber attacks becoming more intelligent and sophisticated
Many criminal organizations evaluate attack techniques from multiple angles, considering not only their efficiency but also the costs involved in their development, modification, and implementation. Companies can neutralize a significant portion of attack strategies by examining cybercriminals' economic models. Strategically changing users, processes, and technologies can force cybercriminals to reconsider the economic value they target.

One approach companies can take is to adopt new technologies and strategies, such as machine learning and automation, to reduce the time and activities required for high levels of human intervention and supervision. These defensive strategies influence cybercrime attack strategies, increasing the time and effort they spend switching and developing attack methods. As companies increasingly adopt machine learning and automation, the cybercrime community is expected to adopt the following strategies.

AI Fuzzing and Its Vulnerabilities / Fuzzing is a technique originally used by threat researchers in laboratory settings to discover vulnerabilities in hardware and software interfaces and applications. Threat researchers input semi-random data into interfaces or programs and monitor for events such as crashes, code assertion errors, and potential memory leaks. This technology was previously only accessible to a small number of skilled engineers working in laboratory environments. However, as machine learning models were applied to this process, the technology became more efficient and customizable, making it available to a wide range of general users who are not technical experts. As cybercriminals began utilizing machine learning to develop automated fuzzing programs, they were able to accelerate the zero-day vulnerability discovery process, resulting in an increase in zero-day attacks targeting various programs and platforms.

Zero-Day Mining Using AIF // AIF can detect code intended to mine zero-day exploits within a controlled environment. This will accelerate the development speed of zero-day exploits. As this process is streamlined, Zero-Day Mining as a Service becomes active, enabling customized attacks against individual targets. Consequently, it becomes difficult to predict the location of zero-days or formulate appropriate defense strategies, making changes to organizations' security approaches inevitable. Today, there are limitations to defending against this with the isolated existing security tools that many organizations have deployed on their networks.

The Cost of Zero Days // Zero-day exploits have historically been very expensive due to the significant time, effort, and technical expertise required to discover them. However, with the application of AI technology, zero-days will transform into a common type of attack. More general exploits, such as ransomware and botnets, have already become widespread. As a result, many traditional security solutions have reached their limits. Zero-day exploits will be produced rapidly and utilized as a service; as the types and number of vulnerabilities and exploits increase significantly, this is expected to impact the types and costs of services offered on the dark web.

As sophisticated attacks based on Swarm-as-a-Service (SaaS) and swarm-based intelligence technologies evolve, swarm-based botnets known as hivenets are becoming commonplace. This rapidly emerging threat is expected to be used to generate large-scale swarms of intelligent bots that operate collaboratively and autonomously. These swarm networks not only raise the technical level required for organizational defense but also impact cybercrime business models, much like zero-day mining.

The current criminal ecosystem is people-driven. Professional hackers use custom paid exploits, and in the case of Ransomware-as-a-Service, criminal engineers must handle various tasks such as backend C2 server management and exploit testing. However, Swarms-as-a-Service, as an autonomous and self-learning service, significantly reduces the amount of direct interaction between hackers and customers and makes it easier to use.

Machine Learning is one of the most promising tools in defensive security toolkits. Security devices and systems can be trained to autonomously perform specific tasks, such as identifying sophisticated threats, tracking devices, and analyzing behaviors for patching. However, this process can be exploited by cybercriminals. Cybercriminals can train devices or systems to avoid applying patches or updates to specific devices, ignore certain types of applications or behaviors, or refrain from logging specific traffic to evade detection. This will have a significant impact on the future of machine learning and AI technologies.


Defense methods that need to become more sophisticated
To prevent the evolution of crime, companies must continuously raise their defenses against cybercriminals. The following defense strategies influence cybercrime organizations, inducing them to change tactics, modify attacks, and develop new ways to assess opportunities. As the cost of launching attacks increases, criminal developers will either invest more resources to achieve the same results or seek out more accessible networks.

Integrating 'trick techniques' into security strategies to introduce sophisticated deception tactics or misinformation-based network variants forces attackers to spend time and resources continuously verifying threat intelligence and detecting false positives. Additionally, they must verify whether network resources are actually legitimate. If attacks on network resources are immediately detected and countermeasures are automatically executed, attackers are forced to exercise caution even when carrying out basic tactics such as network scanning.

Integrated Collaboration / The easiest way for cybercriminals to maximize the effectiveness of existing attacks and evade detection is to change basics, such as IP addresses. The way to counter these tactics is to share threat intelligence. Through continuously updated threat intelligence, security vendors and customers can proactively respond to the latest threat landscape. Open collaboration efforts among threat research agencies, industry alliances, security manufacturers, and law enforcement agencies can shorten the time required to detect new threats by exposing and sharing the tactics used by attackers. However, rather than simply reacting, open collaboration efforts apply behavioral analysis to real-time data feeds, enabling defenders to predict malware behavior and bypass cybercriminals' methods of repeatedly utilizing existing malware.

Future defense strategies powered by machine learning and automation require means to collect, process, and execute threat intelligence in an integrated manner to elicit intelligent responses. As threats become more sophisticated, enterprises must integrate all security elements into a security fabric to rapidly detect and respond to threats.

To reduce the windows required for detection and enable rapid response, advanced threat intelligence must be automated, connecting all security elements to share information. To effectively defend against increasingly sophisticated and automated cyber attacks, efforts are needed to integrate point products deployed across distributed networks into a single system, along with strategic segmentation.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자