2017安全威胁报告(英文版)_47页_4mb
报告摘要
McAfee Labs Threats Report Summary - April 2017
Core Content
The McAfee Labs Threats Report for April 2017 provides an in-depth analysis of current and emerging cybersecurity threats, focusing on two key topics: threat intelligence sharing and the Mirai IoT botnet. It also includes updated threat statistics and insights into McAfee's strategic direction.
Key Topics
1. Threat Intelligence Sharing: What You Don't Know Can Hurt You
- Background and Drivers: Threat intelligence sharing is becoming increasingly important as the cybersecurity landscape evolves. Traditional security models are no longer sufficient due to the complexity of modern threats and the need for real-time, contextually rich data.
- Components and Sources: Threat intelligence is categorized into three types: tactical, operational, and strategic. Tactical intelligence includes indicators like file hashes and IP addresses, operational intelligence provides context about attacks, and strategic intelligence informs organizational security policies.
- Sharing Models: Various models exist, including ISACs, ISAOs, CERTs/IRTs, and threat exchanges. These models vary in scope, structure, and purpose, from nonprofit industry groups to for-profit exchanges.
- Challenges: Five critical challenges are identified:
- Volume: The sheer amount of data makes triage and analysis difficult.
- Validation: Ensuring the authenticity and reliability of shared data is essential.
- Quality: Duplicated or irrelevant data reduces the effectiveness of intelligence.
- Speed: Timely sharing is crucial to prevent attacks.
- Correlation: Linking data to detect patterns and threats is the most critical step.
- Improvement Areas: To enhance threat intelligence sharing, three areas are emphasized:
- Simplify event triage and provide better environments for security practitioners.
- Improve relationships between indicators of compromise to understand attack campaigns.
- Enhance methods for sharing threat intelligence internally and externally.
2. Mirai, the IoT Botnet
- Overview: The Mirai botnet was responsible for a massive DDoS attack on Dyn in October 2016, which reached a peak of 1.2 Tbps.
- Mechanism: Mirai exploits weakly secured IoT devices, turning them into bots that can be used for large-scale attacks.
- Impact: The release of Mirai's source code has led to the creation of derivative bots and the emergence of "DDoS-as-a-service" offerings.
- Analysis: The report examines Mirai's architecture, attack vectors, and evolution, highlighting the growing threat posed by insecure IoT devices.
Threat Statistics (Q4 2016)
- McAfee GTI Queries: 49.6 billion per day.
- Malicious URLs Blocked: Increased to 66 million per day from 57 million.
- Malicious Files Blocked: Decreased to 71 million per day from 150 million due to enhanced download blocking.
- Potentially Unwanted Programs Detected: Increased to 37 million per day from 32 million.
- Risky IP Addresses Detected: Increased to 35 million per day from 27 million.
Strategic Direction
- McAfee as an Independent Entity: Intel Security is expected to become an independent company known as McAfee, with Chris Young as CEO. This change aims to enhance focus, innovation, and growth.
- New Technologies:
- Real Protect: Detects zero-day malware in near real time using cloud-based machine learning.
- McAfee Cloud Threat Detection: Identifies unknown malware using cloud-based analytics and produces analysis reports.
- Threat Landscape Dashboard: A new feature in the Intel Security Threat Center that provides insights into top threats across categories like ransomware and exploit kits.
Cyber Threat Alliance (CTA)
- Formation and Purpose: The CTA was established in 2014 as a consortium for threat intelligence sharing. Its members include Intel Security, Symantec, Palo Alto Networks, Fortinet, Cisco, and Check Point.
- Platform: The CTA platform enables automated sharing and scoring of threat intelligence using Adversary Playbooks.
- Benefits: This platform helps organizations better protect their customers by providing actionable intelligence and improving detection and response effectiveness.
- Trust and Automation: The CTA aims to create a dynamic, real-time trust market, using industry best practices to enhance data sharing and collaboration.
Conclusion
The report underscores the importance of threat intelligence sharing in the face of increasingly sophisticated cyber threats. It highlights the growing risks associated with IoT devices and the need for better data processing, correlation, and automation in security operations. McAfee is actively contributing to these efforts through new technologies and partnerships, including the CTA, to enhance protection and response capabilities.
试读结束,高清完整版pdf/doc/ppt,请点下载