2016-04-27-NTT-2016年全球威胁情报报告_74页_7mb
报告摘要
2016 NTT Group Global Threat Intelligence Report Summary
Core Content Overview
The NTT Group 2016 Global Threat Intelligence Report provides a comprehensive analysis of global cyber threats, focusing on attack trends, vulnerabilities, and the effectiveness of security controls. It emphasizes the importance of a holistic approach to cybersecurity and the role of threat intelligence in improving incident response and overall organizational resilience.
Key Findings
Geographic and Vertical Market Trends
- Retail sector experienced the most attacks per client, with 2.7 times more attacks than finance clients.
- U.S. was the largest source of hostile IP addresses, accounting for 65% of all attacks detected in 2015.
- Non-U.S. attacks were primarily from the United Kingdom, Turkey, and China, which together made up 38% of non-U.S. attacks.
- Education sector had a 94% decrease in malware volume from 2014 to 2015, likely due to changes in network management focus.
- Top five sectors by attack volume were: retail, hospitality, leisure and entertainment, insurance, and government.
Vulnerabilities, Attacks and Exploitation
- 21% of vulnerabilities were more than three years old, with some as old as 16 years.
- Adobe Flash was the most targeted software by exploit kits in 2015, with 312% increase in publicized vulnerabilities from 2014.
- Brute force attacks increased by 135% from 2014 levels, with SSH being a common target.
- DDoS attacks decreased by 39% in 2015, attributed to improved mitigation techniques and reduced attack frequency.
- Web application attacks accounted for 24% of all attacks, with injection-based attacks (e.g., SQL, PHP command injection) being the most common.
Incident Response and Case Studies
- Retail and finance sectors were the most common sources of incident response engagements.
- Only 23% of organizations were capable of responding effectively to cyber incidents, with 77% lacking the ability and often purchasing services post-incident.
- Spear phishing attacks increased significantly from <2% in 2014 to 17% in 2015.
- PCI-compliant clients observed 57% less C2 traffic compared to non-PCI clients, indicating better security practices in this group.
Cyber Kill Chain and Security Controls
- The report applies the Lockheed Martin Cyber Kill Chain (CKC) model to identify effective security controls at each stage of the attack lifecycle.
- A dedicated section and case study explore the practical application of these controls, emphasizing how they can disrupt attacks and improve defense mechanisms.
- The CKC is integrated with threat intelligence, enabling organizations to anticipate and mitigate threats more effectively.
Threat Intelligence and Cyber Kill Chain
- The Role of the Cyber Kill Chain in Threat Intelligence highlights the synergy between the two concepts.
- A well-structured threat intelligence program can significantly enhance an organization’s ability to respond to cyber threats.
- The report includes a glossary and methodology to support understanding of the data and security concepts discussed.
Global Honeynet Analysis
- 3.5 trillion logs and 6.2 billion attacks were analyzed.
- U.S. remained the largest source of attacks, but attackers often use U.S. infrastructure to evade IP blocking.
- Top five source countries accounted for 81% of all attacks in 2015.
- Injection attacks were the most common web application attack type, aligning with the OWASP Top Ten list.
Anti-Sandbox Techniques
- Attackers increasingly use anti-sandbox techniques to evade detection, making sandbox environments less effective.
- These techniques include IP address spoofing, behavioral analysis, and environmental checks.
- The report provides case studies and recommendations to improve detection and response capabilities.
Malware and Exploit Kits
- Malware detection increased across most industries, with the government sector leading the rise.
- Exploit kits target a wide range of technologies, including Adobe Flash, Java, and Microsoft Windows.
- The top 10 exploit kits included a variety of attacks, with Adobe Flash being the most frequently exploited.
Incident Response Trends
- Organizations are not well-prepared for cyber incidents, with 77% lacking effective response capabilities.
- DDoS and malware related incidents required less response support in 2015, due to both reduced attack volume and improved mitigation.
Vulnerability Summary
- Top 10 external vulnerabilities accounted for 52% of all identified external vulnerabilities.
- Top 10 internal vulnerabilities were all related to outdated patch levels, representing 78% of internal vulnerabilities.
- Older vulnerabilities (3+ years) remained a concern, with >12% being over 5 years old.
Recorded Future Observations
- Heartbleed (CVE-2014-0160) and POODLE (CVE-2014-3566) were among the top exploited vulnerabilities in the finance sector.
- Dyreza malware used CVE-2015-0057 and CVE-2013-3660 to target banking customers through spam campaigns.
Conclusion
The report underscores the need for comprehensive security programs that integrate threat intelligence and security controls across the entire infrastructure. It highlights the persistent threat landscape, the evolving nature of malware and attacks, and the importance of proactive incident response. The retail, hospitality, government, and manufacturing sectors were most affected, with Adobe Flash and Java being the most exploited technologies. The U.S. remains a major source of attacks, but non-U.S. attackers often use U.S. infrastructure to avoid detection. Overall, the report provides actionable insights for improving cybersecurity resilience and response capabilities.
试读结束,高清完整版pdf/doc/ppt,请点下载