2023-03-27-enisa-ENISA网络威胁图谱2022_150页_4mb
报告摘要
ENISA Threat Landscape 2022 Summary
Core Content
The ENISA Threat Landscape 2022 (ETL 2022) report provides an in-depth analysis of the cybersecurity threat landscape from July 2021 to July 2022. It highlights the most significant threats, trends, and mitigation strategies, offering insights for both strategic and technical audiences. The report is based on open-source intelligence (OSINT) and cyber threat intelligence (CTI) sources, and it uses a structured methodology to ensure transparency and systematic analysis.
Main Threats
The following are the prime threats identified in the report:
- Ransomware
- Malware
- Social Engineering
- Threats against data
- Threats against availability: Denial of Service (DoS/DDoS)
- Threats against availability: Internet threats
- Disinformation and Misinformation
- Supply Chain Attacks
These threats are further explored in dedicated chapters, each providing detailed information on attack techniques, notable incidents, and mitigation strategies.
Key Trends
-
Geopolitical Impact: The Russia-Ukraine conflict significantly influenced the cybersecurity threat landscape. It led to an increase in hacktivist activities, cyber operations aligned with kinetic military actions, and state-sponsored cyberattacks. Disinformation was also used as a preparatory tool for the invasion.
-
Threat Actor Capabilities: Threat actors are enhancing their capabilities, using 0-day exploits to bypass advanced defenses. Ransomware groups are adopting rebranding and retirement strategies to evade detection and sanctions. The hacker-as-a-service model is becoming more common, especially since 2021.
-
Ransomware and Availability Threats: Ransomware and availability threats, particularly DDoS attacks, have increased in frequency and complexity. The war has driven the rise in these attacks, which are now being used in cyberwarfare contexts.
-
Sophistication of Social Engineering: Phishing remains the most common initial access vector. The sophistication of phishing attacks has increased, with targeted, context-based lures becoming more prevalent. Consent phishing is also on the rise, allowing attackers to gain access through user consent.
-
Malware Trends: Malware saw a resurgence after a decline linked to the COVID-19 pandemic, indicating a return to traditional attack patterns.
-
Emerging Threats: Disinformation and deepfakes, powered by AI, are becoming more sophisticated and impactful. They can disrupt rulemaking processes and community interactions. Machine Learning (ML) models are increasingly targeted by attackers due to their critical role in modern systems.
-
Supply Chain Attacks: These attacks are becoming more common and sophisticated. They exploit the relationship between organizations and their suppliers, often involving multiple stages of attacks. The SolarWinds incident is a notable example.
Threat Actor Categories
ENISA categorizes threat actors into four main types:
- State-sponsored actors
- Cybercrime actors
- Hacker-for-hire actors
- Hacktivists
These categories help in understanding the motivations and targets of different threat actors, which is essential for developing targeted mitigation strategies.
Proximity Classification
ENISA classifies cyber threats based on their proximity to the EU, which helps in assessing the relevance and impact of threats on EU entities:
| Proximity | Concerns |
|---|---|
| NEAR | Threats affecting networks and systems within the EU, impacting the EU population. |
| MID | Threats targeting systems vital for the EU's digital single market and NISD sectors, but controlled by non-EU authorities. |
| FAR | Threats that could significantly impact the EU's operational objectives, but are not directly affecting EU networks. |
| GLOBAL | Threats that affect all the aforementioned areas. |
Sectorial Impact
The report includes an analysis of the impact of threats by sector, based on OSINT data. Key sectors affected include:
- Public administration and government
- Digital service providers
- Finance
- Health
These sectors are particularly vulnerable due to their cybersecurity maturity levels, popularity, and critical infrastructure roles.
Conclusion
The ETL 2022 highlights the increased complexity and sophistication of cyber threats, driven by geopolitical tensions and technological advancements. It underscores the need for enhanced cybersecurity measures, improved incident reporting, and awareness raising to mitigate the risks posed by these threats. The report also serves as a basis for policy development and sector-specific threat analysis.
Appendices
The report includes the following appendices:
- Annex A: Mapping to MITRE ATT&CK framework
- Annex B: Indicative list of incidents
- Annex C: CVE landscape
- Annex D: Recommendations for mitigating the identified threats
These appendices provide additional insights and actionable strategies for addressing the threats discussed in the report.
试读结束,高清完整版pdf/doc/ppt,请点下载