2021年数据泄露调查报告(英文版)_119页_16mb
报告摘要
2021 Data Breach Investigations Report (DBIR) Summary
Core Content
The 2021 Data Breach Investigations Report (DBIR) is a comprehensive analysis of data breaches and security incidents, utilizing a robust framework of classification and visualization techniques. The report highlights the evolving nature of cyber threats and the importance of understanding both common and rare attack patterns to improve organizational security.
Main Points
- Data Collection: The report analyzed 79,635 incidents, of which 29,207 met quality standards and 5,258 were confirmed breaches, spanning 88 countries.
- Classification Framework: It uses the VERIS framework to categorize threats into Action, Actor, Asset, and Attribute types, enabling consistent and detailed reporting.
- Data Visualization: Uncertainty is represented through various charts such as slanted bar charts, spaghetti charts, dot plots, and violin charts. These charts emphasize the distribution and frequency of different attack types and their impact.
- Key Trends:
- Phishing remains a top threat, appearing in 36% of breaches, up from 25% in 2020.
- Ransomware increased significantly, appearing in 10% of breaches, more than doubling from the previous year.
- Financially motivated attacks continue to be the most common, with organized crime as the leading actor type.
- State-sponsored actors have also shown a growing interest in financial motives, with their percentage fluctuating between 6% and 16%.
- Secondary Motives: These include attacks that leverage the victim's access or infrastructure for further incidents. Though the percentage has slightly decreased, they remain a significant concern.
- Error Actions: The percentage of breaches attributed to Error actions decreased this year to 17% from 22%, but they are still a notable category in the overall dataset.
- Insider Threats: The report notes that Internal actors are included in the analysis, often involving Misuse and Error actions.
Key Information
Incident vs. Breach
- Incident: A security event that compromises the integrity, confidentiality, or availability of an information asset.
- Breach: An incident that results in confirmed data disclosure to an unauthorized party.
Industry Classification
- Industries are classified using the NAICS codes, with the report analyzing 11 main industries and the SMB section.
- The Financial and Insurance sector is highlighted as one of the most affected.
Data Uncertainty
- The DBIR acknowledges the inherent uncertainty in cybersecurity data and uses various visualizations to represent this.
- The Gini coefficient is used to measure inequality in the distribution of breach types, with a score of 0.94 indicating a high degree of inequality in the data.
Threat Actor Motives
- Financial Motive is the most common, with Organized Crime as the leading actor type.
- Secondary Motive breaches are also common, often involving the use of compromised systems for further attacks.
Action Varieties
- Phishing and Use of stolen credentials are still prevalent.
- Ransomware has become more common, possibly due to changes in tactics by threat actors.
- Malware and Social Engineering are also major categories, with Malware showing a strong correlation with Exfiltration.
Visualization Techniques
- Slanted Bar Charts: Represent uncertainty at a 95% confidence level.
- Dot Plots: Each dot represents 0.5% of organizations, helping to visualize the distribution of incidents.
- Spaghetti and Violin Charts: Used to show trends over time and proportions of changes, respectively.
- Heatmaps: Highlight how different actions lead to specific outcomes, such as Infiltration or Exfiltration.
Conclusion
- The report emphasizes the importance of focusing on probable threats rather than trying to predict every possible scenario.
- It suggests that organizations should prioritize solving the norm and training for the exception, leveraging the insights from the report to optimize their security strategies.
- The DBIR team encourages feedback and engagement, especially regarding new visualization techniques.
Appendices and Resources
- Appendix A: Methodology of data collection and analysis.
- Appendix B: Controls and recommendations based on the Center for Internet Security (CIS) Controls.
- Appendix C: U.S. Secret Service information.
- Appendix D: List of contributing organizations.
- VERIS Resources: Available for deeper understanding of the classification framework and its use in incident reporting.
References
- VERIS Community Database: A public database of breaches, accessible via github.com/vz-risk/vcdb.
- DBIR Facts and Figures: Available at github.com/vz-risk/dbir/tree/gh-pages/2021.
- VERIS Web App: A tool to record and analyze incidents, available at veriscommunity.net/veris_webapp_min.html.
Contributors and Team
The report is a collaborative effort involving 83 contributors, both new and old, and is authored by:
- Gabriel Bassett
- C. David Hylander
- Philippe Langlois
- Alexandre Pinto
- Suzanne Widup
The DBIR team is committed to improving the understanding and preparedness of organizations against cyber threats, while being transparent about the limitations and uncertainties in their data.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载