verizon-2019年数据泄露调查报告(英文)-2019.7-78页_7mb
报告摘要
2019 Data Breach Investigations Report Summary
Core Content
The 2019 Verizon Data Breach Investigations Report (DBIR) is a comprehensive analysis of 41,686 security incidents, of which 2,013 were confirmed data breaches. The report explores the evolving threat landscape, focusing on threat actors, actions, and affected assets, and provides actionable insights to help organizations improve their security posture.
Main Points
Definitions
- Incident: A security event that compromises the integrity, confidentiality, or availability of an information asset.
- Breach: An incident that results in the confirmed disclosure of data to an unauthorized party.
- VERIS Framework: Used to categorize and analyze security incidents with standardized terminology such as "threat actions," "threat actors," "varieties," and "vectors."
Threat Actors
- External Actors: Responsible for 69% of breaches, with organized criminal groups accounting for 39% and nation-state or state-affiliated actors for 23%.
- Internal Actors: Accounted for 34% of breaches, often due to human error rather than malicious intent.
- Partners and Multiple Parties: Represented 2% and 5% of breaches, respectively.
Threat Actions
- Hacking: The most common threat action (52%), including SQL injection, brute force, and use of stolen credentials.
- Social Engineering: Responsible for 33% of breaches, with phishing (32%) being a major subset.
- Malware: 28% of breaches involved malware, with ransomware and backdoor/C2 malware being prominent.
- Misuse: 15% of breaches involved misuse, primarily due to privilege abuse or data mishandling.
- Errors: 21% of breaches were caused by errors, such as misconfigurations or accidental data exposure.
Affected Assets
- Workstations, web applications, and mail servers were the most commonly affected assets.
- Server - Mail was the most frequently impacted asset in hacking and phishing breaches.
- User Dev - Desktop was the most affected in malware and social engineering incidents.
Motives
- Financial Motivation: 71% of breaches were financially motivated.
- Espionage: 25% of breaches were driven by strategic advantage.
- Other Motives: Included fun, grudge, convenience, ideology, fear, and secondary motives.
Key Information
Breach Trends
- Small Businesses: 43% of breaches involved small businesses, indicating a growing threat to this sector.
- Time to Discovery: 56% of breaches took months or longer to discover, highlighting the need for better detection mechanisms.
- Phishing: Remains a prevalent attack vector, with click rates decreasing to 3% in sanctioned phishing exercises.
- Mobile Devices: Increasingly targeted by social engineering attacks due to design limitations and user behavior.
Malware Insights
- Email as a Vector: Email was the most common method of malware delivery, with over 90% of detected malware arriving via this channel.
- Cryptomining Malware: Not as prevalent as expected, with only a small fraction appearing in the top malware varieties.
Incident Analysis
- Patching Behavior: Organizations tend to have a surge in patching efforts after initial discovery, followed by a steady increase in fixed vulnerabilities.
- Patching Metrics: The Area Under the Curve (AUC) and Completed-on-Time (COT) metrics help assess the effectiveness of patching strategies.
Industry Analysis
The report aligns with the NAICS classification system to categorize industries. Key findings include:
- Public Sector: 16% of breaches.
- Healthcare: 15% of breaches.
- Financial and Insurance: 10% of breaches.
- Small Business: 43% of breaches involved small businesses.
Conclusion
The DBIR aims to provide insights into common tactics and motivations behind data breaches, offering a data-driven perspective to enhance security awareness and response strategies. The report emphasizes the importance of understanding the evolving threat landscape and the role of human error, social engineering, and malware in breaches.
Figures and Data
- Figure 1: Breach victims by industry.
- Figure 2: Breach tactics over time.
- Figure 3: Breach motives over time.
- Figure 4: Threat actors over time.
- Figure 5: Commonalities in breaches.
- Figure 6-8: Threat actor trends and motives.
- Figure 9-10: Threat actions and affected assets from 2013 to 2018.
- Figure 11-19: Threat action varieties, malware types, and delivery methods.
- Figure 20-25: Social engineering, misuse, and error trends.
Additional Resources
This report serves as a critical resource for understanding and mitigating the risks associated with data breaches.
试读结束,高清完整版pdf/doc/ppt,请点下载