2021年企业网络安全报告(英)-32页_6mb
报告摘要
"EXPOSED" Report Summary
Core Content
The "EXPOSED" report is the first of its kind to analyze the global attack surface of corporate networks. It highlights the increasing exposure of businesses due to the rise of remote work, cloud adoption, and the reliance on the internet for connectivity. The report analyzed data from 1,500 organizations to identify trends in vulnerabilities, exposed servers, and public cloud instances across various company sizes, geographies, and industries.
Main Findings
Overall Attack Surface
- 202,316 potential CVE vulnerabilities were found globally.
- 49% of these CVEs are classified as "Critical" or "High" severity.
- 95,742 web servers support outdated and vulnerable SSL/TLS protocols.
- 47% of these protocols are outdated, including SSLv3, SSLv2, TLSv1, and TLSv1.1.
- 392,298 servers were exposed to the internet, with an average of 262 per organization.
- 214,230 ports were exposed, with Port 443 (HTTPS) being the most common (56.8%).
- 60,572 public cloud instances were exposed, with an average of 40 per company.
- 85,380 namespaces were exposed.
Attack Surface by Company Size
- Major companies (20,000+ employees) have the highest exposure, with 468 exposed servers and 77 public cloud instances on average.
- Large enterprises (6,000-20,000 employees) are second, with 312 servers and 40 cloud instances.
- Enterprise (2,000-6,000 employees) and Commercial (<2,000 employees) have lower exposure.
- 51% increase in CVE count and 104% increase in outdated SSL/TLS protocols from large enterprises to major companies.
Attack Surface by Geography
- EMEA (Europe, Middle East, Africa) leads in both CVE and SSL/TLS vulnerabilities.
- EMEA has 164 average CVE vulnerabilities and 71 SSL/TLS vulnerable servers.
- AMS (North and South America) follows with 132 CVEs and 56 SSL/TLS vulnerable servers.
- APAC (Asia, Australia, Pacific Islands) has the lowest exposure with 80 CVEs and 45 SSL/TLS vulnerable servers.
- EMEA also has the highest average of 283 exposed servers and 52 public cloud instances.
Attack Surface by Industry
- Telecommunications has the highest exposure with 319 CVEs and 106 SSL/TLS vulnerable servers.
- Manufacturing follows with 222 CVEs and 87 SSL/TLS vulnerable servers.
- High Tech has 175 CVEs and 94 SSL/TLS vulnerable servers.
- Financial Services has 84 CVEs and 65 SSL/TLS vulnerable servers.
- Government has the lowest exposure, with 111 CVEs and 44 SSL/TLS vulnerable servers.
Key Vulnerabilities
Top CVEs Discovered
- CVE-2018-1312 (CRITICAL) – Vulnerability in Apache HTTP Server related to HTTP Digest authentication.
- CVE-2017-7679 (CRITICAL) – Buffer overflow in Apache HTTP Server’s mod_mime.
- CVE-2019-0220 (MEDIUM) – Handling of multiple slashes in URLs.
- CVE-2016-4975 (MEDIUM) – CRLF injection in mod_userdir.
- CVE-2018-17199 (HIGH) – Session expiry time not being respected in mod_session.
SSL/TLS Risks
- 95,742 web servers support outdated SSL/TLS protocols.
- 64 outdated web servers per company on average.
- 47% of SSL/TLS protocols are outdated.
- EMEA has the highest number of SSL/TLS vulnerable servers (71), followed by Hong Kong (107), Finland (98), and Switzerland (91).
Exposed Servers and Ports
- Port 443 (HTTPS) is the most exposed port (56.8%).
- Port 80 (HTTP) is the second most exposed (38.8%).
- Port 22 (SFTP) is the third most exposed (1.98%).
- Web applications account for 96% of exposed ports.
Public Cloud Exposure
- AWS, Microsoft Azure, and Google Cloud Platform (GCP) are the main cloud platforms with exposure.
- AWS has the highest number of exposed instances (50% of total), followed by Azure (35%) and GCP (13%).
- Major companies have more than double the exposure compared to other segments.
- EMEA has the highest average of 22 Azure instances, while AMS has 14 and APAC has 17.
Takeaways
- Larger companies have a significantly larger attack surface due to more users, servers, and applications.
- EMEA companies have the highest risk of both CVE and SSL/TLS vulnerabilities.
- Telecommunications and Manufacturing are the most vulnerable industries.
- Financial Services has average CVE exposure but higher server exposure than expected.
- Government has the lowest exposure but is still a frequent target of cybercrime.
- Cloud misconfigurations and server exposure are major contributors to the attack surface.
- Zero trust security and regular software patching are recommended for reducing exposure.
Methodology
The report analyzed the attack surface of 1,500 organizations from February 2020 through April 2021, focusing on the impact of remote work and digital transformation on network exposure. It identified exposed servers, ports, CVEs, and SSL/TLS vulnerabilities across different segments of company size, geography, and industry.
试读结束,高清完整版pdf/doc/ppt,请点下载