2016年-数据局_Verizon:2016年网络安全调查报告_en_85页_3mb
报告摘要
2016 Data Breach Investigations Report Summary
Core Content
The 2016 Data Breach Investigations Report (DBIR) provides an in-depth analysis of real-world data breaches and information security incidents from the prior year. It includes data from over 100,000 incidents, with 3,141 confirmed data breaches. The report emphasizes the persistent nature of data breaches and the importance of understanding both the motivations behind them and the methods used to execute them.
Main Points
-
Breach Motives:
- 89% of breaches had a financial or espionage motive.
- Financial motives remain dominant, even when not directly tied to monetary gain.
- Espionage is the second most common motive, but still far behind financial gain.
-
Threat Actors:
- The majority of breaches are initiated by external actors.
- Phishing and Point-of-Sale (POS) attacks are the most common threat actions.
- The report acknowledges the role of internal actors and collusion, though these are less frequent.
-
Breach Trends:
- Phishing is a primary method for attackers to gain initial access.
- The "Dridex" campaign significantly influenced the data, as it often starts with phishing to steal credentials.
- Breach detection times are generally short, with many breaches being discovered within days or even minutes.
-
Victim Demographics:
- Breaches affected organizations in 82 countries and across a wide range of industries.
- Retail and Accommodation industries accounted for a significant percentage of confirmed breaches due to the high value of their data.
- Public sector organizations were heavily represented in the incident data, but this is largely due to reporting requirements.
-
Breach Discovery Methods:
- External notification, such as from law enforcement or fraud detection, is increasingly common.
- The detection deficit continues to grow, indicating that many breaches go unnoticed for a long time.
Key Information
-
Incident Classification Patterns:
- The nine incident classification patterns identified in the 2014 report remain prevalent.
- These patterns include Web App Attacks, Point-of-Sale Intrusions, Insider and Privilege Misuse, and others.
-
Vulnerabilities:
- Older vulnerabilities are still heavily targeted, suggesting that attackers prefer known exploits.
- A methodical and consistent patching approach is more effective than expedient patching.
- Vulnerability management is a continuous process, and not all vulnerabilities can be fixed due to business constraints or incompatibilities.
-
CVE Data:
- The report highlights the lack of detailed CVE data in the dataset, which is either not measured or not identified.
- The top 10 vulnerabilities account for 85% of successful exploit traffic, indicating a need to focus on these critical issues.
-
Time to Exploitation:
- The median time from vulnerability publication to first-known exploitation is about 30 days.
- Adobe vulnerabilities are exploited more quickly than Mozilla ones, showing variability in how quickly vulnerabilities are used.
-
Remediation and Mitigation:
- Enterprises are not effectively closing the gap between new vulnerabilities and their exploitation.
- Mitigation strategies, such as configuration changes or isolation, are as important as remediation.
Recommendations
-
Targeted Remediation:
- Focus on vulnerabilities that are actively being exploited.
- Prioritize those with known exploits or proof-of-concept code.
-
Plan B:
- For systems that cannot be patched, implement alternative risk mitigations like configuration changes or isolation.
-
Vulnerability Scanning:
- Use vulnerability scanning to identify new devices and services.
- Monitor scan-to-scan changes to detect deviations from standard configurations.
-
Phishing Mitigation:
- Phishing remains a significant threat, with 13% of people tested clicking on phishing attachments.
- The median time to click on a phishing attachment is very short, emphasizing the need for user education and awareness.
Conclusion
The report underscores the importance of proactive and consistent security measures. Despite the growing awareness and some improvements in detection, the data suggests that breaches are still common and that the financial and espionage motives continue to drive cyberattacks. The report encourages organizations to focus on both remediation and mitigation strategies, and to stay vigilant against the persistent threat of phishing and other attack vectors.
试读结束,高清完整版pdf/doc/ppt,请点下载