2017年-数据局_Verizon:2017年数据泄露调查报告_76页_2mb
报告摘要
2017 Data Breach Investigations Report Summary
Core Content
The 2017 Data Breach Investigations Report (DBIR) is the 10th edition of Verizon's annual analysis of data breaches and security incidents. It highlights the evolving nature of cyber threats and provides insights into the patterns, motivations, and industries most affected by breaches.
Main Findings
Breach Overview
- 75% of breaches were caused by outsiders, while 25% involved internal actors.
- 18% of breaches were attributed to state-affiliated actors.
- 51% of breaches were financially motivated, with 21% linked to espionage.
- 3% of breaches involved multiple parties, and 2% involved partners.
- 62% of breaches involved hacking, and 51% involved malware.
- 81% of hacking-related breaches used stolen or weak passwords.
- 43% of breaches were social attacks, and 14% were caused by errors or privilege misuse.
- 8% of breaches involved physical actions.
Breach Discovery
- 27% of breaches were discovered by third parties.
- Employee notifications were the most common internal discovery method.
- Breaches discovered in minutes or hours increased due to the reduction in botnet and POS breaches.
Breach Timeline
- 98% of breaches were compromised in minutes or less.
- Breaches that took months to discover are likely to fall under Point of Sale Intrusions, Privilege Misuse, Everything Else, or Cyber-Espionage.
Breach Types
- Ransomware is a growing concern, with organized criminal groups using it to extort money.
- Malware is primarily installed via malicious email attachments (66%).
- Payment card skimmers and point of sale intrusions are still significant threats.
Industry-Specific Insights
Industry Comparison
- The Information and Financial and Insurance industries were the most affected in terms of breaches.
- Healthcare and Retail also had a significant share of breaches.
- Accommodation and Food Services had 96% external breaches and 99% financial motives.
- Education and Manufacturing had lower breach numbers and higher percentages of internal breaches.
Breach Patterns by Industry
- Point of Sale Intrusions were the most common in Accommodation.
- Privilege Misuse and Everything Else were also prevalent in this sector.
- Phishing was a major vector across all industries, with email-based attacks being the most common method.
- Malware was frequently delivered through Office documents and executables.
Key Trends and Analysis
Breach Trends Over Time
- There was a downtick in the percentage of breaches involving external actors and a corresponding increase in internal actors.
- Financial and espionage motives combined for 93% of breaches in 2016.
- Ransomware is not reflected in breach motive statistics due to unconfirmed data disclosure.
Data Sources and Methodology
- The report is based on real-world data from 65 contributors.
- It includes non-incident datasets from security vendors to enrich findings.
- Some bias remains, which is discussed in Appendix D.
Recommendations and Actions
- Track internal metrics such as time-to-exfiltration and time-to-discovery to improve response.
- Understand your organization's vulnerabilities and patching cycles.
- Use the VERIS framework for incident response and analysis.
- Leverage the DBIR findings to enhance security awareness and incident preparedness.
- Review the cybercrime case studies in the Verizon Data Breach Digest for deeper insights into breach scenarios.
Conclusion
The DBIR remains a crucial tool for understanding the landscape of data breaches and security incidents. While it does not provide a comprehensive view of all security efforts, it offers actionable insights that can be combined with internal knowledge to improve organizational security. The report encourages a realistic approach to risk management and hopeful outlook for the future of cybersecurity.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载