Malwarebytes-2019年网络医疗犯罪报告(英文)36页_3mb
报告摘要
Summary of Cybercrime Tactics and Techniques in the Healthcare Industry (2019)
Core Content
This report analyzes the state of cybersecurity in the healthcare industry during 2019, focusing on the most common threat categories, attack vectors, and regional trends. It highlights the increasing sophistication and prevalence of cybercriminal activities targeting healthcare organizations and underscores the urgent need for improved security measures.
Key Takeaways
- Healthcare is the 7th-most targeted industry globally, with a significant rise in malware detections over the past year.
- Threat detections increased by 45% from Q2 to Q3 2019, showing a growing trend in cyberattacks against the sector.
- Trojan malware dominates the threat landscape, with TrickBot becoming the most dangerous threat in the second half of 2019.
- Ransomware is increasingly being used as a payload in attacks, often delivered via Trojans like Emotet and TrickBot.
- US regional differences exist in the frequency and type of attacks, with the West and Midwest being the most targeted areas.
Global Healthcare Threats
- Malware detections in healthcare increased by 60% from 2018 to early 2019, indicating a sharp rise in cybercriminal activities.
- Trojan malware saw the most dramatic increase, with a 82% surge in Q3 2019.
- Emotet and TrickBot were the leading threats, with Emotet initially dominating before TrickBot took over.
- Ransomware is often delivered as part of these Trojan attacks, highlighting the multi-stage nature of cyber threats in healthcare.
- Exploits are also a major vector, with many targeting unpatched systems and leveraging known vulnerabilities.
US Regional Healthcare Threats
- West region had the highest number of detections, accounting for 42% of total US healthcare threats.
- Midwest followed closely with 36% of US healthcare threats.
- South and Northeast had 15% and 7% of total US healthcare threats, respectively.
- Key states in the West: Idaho, California, New Mexico, Nevada, and Colorado.
- Key states in the Midwest: Illinois, Ohio, Wisconsin, Michigan, and Kansas.
- Key states in the South: Texas, Kentucky, Florida, Virginia, and Georgia.
- Key states in the Northeast: New York, New Hampshire, Massachusetts, New Jersey, and Connecticut.
Top Attack Vectors
- Third-party vendor software vulnerabilities are a common entry point for cybercriminals.
- Exploits targeting unpatched systems are frequently used to gain access.
- Social engineering (phishing, spear phishing) is a prevalent method for delivering malicious payloads.
Why Healthcare is a Target
- Large databases of patient information make healthcare an attractive target for cybercriminals.
- Weak security postures and lack of advanced security models leave systems vulnerable.
- High number of endpoints and legacy systems increase the attack surface.
- Sensitivity of data and potential for high return on investment for attackers.
- Budget constraints in healthcare organizations often lead to neglect of cybersecurity.
Consequences of a Breach
- Disruption of critical procedures and operations.
- Ransomware attacks can lock out medical devices, leading to potential patient harm or death.
- Data theft can result in privacy violations and loss of trust.
Future Concerns
- Emerging biotech innovations, such as cloud-based biometrics and Internet of Thoughts, pose new security risks if not properly integrated with security measures.
- Security must be baked into the design of these technologies to prevent future vulnerabilities.
- Ongoing threat evolution suggests that the healthcare industry must remain vigilant and proactive in its security strategies.
Conclusion
The healthcare industry is facing a rising tide of cyber threats, with Trojans and ransomware being the most significant concerns. The West and Midwest regions are particularly vulnerable, and TrickBot has emerged as the dominant threat. The increase in malware detections underscores the need for enhanced security measures and proactive threat management. As new technologies continue to evolve, security should be a foundational consideration in their development and deployment to mitigate future risks.
试读结束,高清完整版pdf/doc/ppt,请点下载