Sunday, October 23, 2016

The Weak Links of Security in the Enterprise

Discussion for EA874 Topic 5 > Enterprise Security Architecture
Post # 3

In March 2015,  Cisco’s Talos Threat Intelligence and Research Team also reported a rise in tax-related phishing attempts in the US as the tax reporting season gets into full swing.  Some of these attempts are incredibly sophisticated and are very hard to spot as being fraudulent. We now also have cybercrime gangs placing adverts on legitimate websites and use them to inject malware into unsuspecting people browsing the ad. Cisco's 2015 Annual Security Report (CASR) suggested compromised users are often infected with malicious browser add-ons through the installation of bundled software (software distributed with another software package or product) via these sorts of malvertisments and usually without clear user consent. The CASR also highlighted how users’ careless behaviour when using the Internet, combined with targeted campaigns by adversaries, places many industry verticals at higher risk of web malware exposure. In 2014, the pharmaceutical and chemical industry emerged as the number one sectors to be targeted in this way.


In the case of the 2013 data breach at Target, the initial intrusion into its systems was traced back to network credentials that were stolen from a third party vendor which did contractual HVAC work at a number of locations at Target and other top retailers.

The reconnaissance that hackers conduct goes beyond mapping a company’s IT network, and would also be interested in gathering as much information as possible on their target, especially around how the business and its key personnel operate. These details will help attackers navigate around any technological or human barriers during an attack. To collect these details, hackers will use social media to learn where key members of your security team worked or went to college. Once an attack has penetrated your network, file access can be executed to review emails and calendar entries to learn when key security personnel are on vacation and attack when there’s a staffing gap. Hacking teams can also be specialized: usually one group dedicated to deception that creates a campaign that distracts the security team from the main attack operation. The distraction is meant to mitigate the risk of the campaign being discovered. DDoS attacks are usually employed as distractions that can be a challenge but can easily be detected. These decoy threats mask the real threat which can escape detection during the distraction.



Thus, these scenarios show that visibility across the whole corporate network is critical to managing security. It is not enough to just defend the threat coming into and out of the network; you have to be able to manage the threat across the whole continuum, before, during and after the attack. While better security technologies and solutions are needed, we should not discount the human factor as a key vulnerability that must be seriously considered when developing the enterprise security architecture.


Reference:
Graham Welch. (2015 Mar 11). People Remain the Weakest Link in Security.  http://www.cio.com/article/2895404/cybercrime/people-remain-the-weakest-link-in-security.html

No comments:

Post a Comment