akamai-2017年3季度互联网国家安全报告(英文)-2017-24页-5mb
报告摘要
2017 Q3 Internet Security Report Summary
Core Content
The Q3 2017 State of the Internet / Security Report provides an overview of the cybersecurity landscape, highlighting the increasing threat of web application attacks and DDoS activity. It emphasizes the importance of collaboration among organizations, researchers, and security professionals to address the growing vulnerabilities in software and the Internet infrastructure.
Key Findings
Web Application Attacks
- Overall Increase: There was a 30% increase in total web application attacks from Q2 2017 to Q3 2017, and a 69% increase year-over-year (Q3 2016 to Q3 2017).
- U.S. Activity: The number of attacks originating from the U.S. increased by 48% from Q2 2017 and 217% from Q3 2016.
- SQLi Dominance: SQL injection (SQLi) attacks remained the most common vector, accounting for 47% of all web application attacks in Q3 2017, up from 44% in Q1 2017, but down from 51% in Q2 2017.
- Vulnerability Prevalence: Three out of every four applications have at least one vulnerability, with 12% having high or very high severity issues. Only less than a third of applications passed the OWASP Top 10 policy on the initial scan.
- Open Source Risks: 88% of Java applications with components had at least one flaw in the component, showing the ongoing risk of unpatched open source software.
DDoS Attacks
- Overall Increase: Total DDoS attacks increased by 8% from Q2 2017 to Q3 2017, and by 69% from Q3 2016 to Q3 2017.
- Attack Types:
- Infrastructure Layer (Layers 3 & 4): These attacks accounted for 99% of all DDoS traffic in Q3 2017.
- Reflection Attacks: These increased by 4% from Q2 2017 to Q3 2017.
- Top Attack Vectors:
- UDP Fragment, DNS, and NTP were the top three DDoS attack vectors in Q3 2017.
- CLDAP rose to third place in reflection attacks, pushing CHARGEN to fourth.
- Top Source Countries:
- Germany had the largest number of unique IP addresses involved in DDoS attacks in Q3 2017, with 58,746 IPs, representing 22% of the global total.
- U.S. remained the second-largest source country, with 14% of attack traffic.
- India, China, and Mexico were also among the top source countries.
- Gaming Industry Targeted: The gaming industry was the most targeted, with 86% of volumetric DDoS attacks directed at them. One gaming company experienced 612 attacks in Q3 2017 alone.
Major Cybersecurity Events
- Mirai Botnet: The Mirai botnet, which exploits insecure IoT devices, continued to be a significant threat. It was responsible for attacks peaking at 109 Gbps in Q3 2017.
- WireX Malware: A new Android-based botnet, WireX, was dismantled through cross-organizational cooperation, with Akamai researchers collaborating with multiple entities, including competitors.
- DDoS Extortion: DDoS extortion was noted as on the rise, indicating a growing trend of cybercriminals using DDoS as a tool for extortion.
Key Recommendations
- Collaboration and Information Sharing: The report stresses the importance of collaboration across organizations, especially through ISACs and security partnerships, to combat evolving threats.
- Secure Configuration: System administrators are urged to regularly review and patch exposed services to reduce the risk of DDoS and other attacks.
- Risk Management: Organizations should re-evaluate their defenses based on the changing threat landscape and consider their risk appetite when planning security measures.
- Proactive Security Measures: The report highlights the need for proactive measures to secure software, as reactive approaches have failed to prevent major incidents like WannaCry and Petya.
Conclusion
The report underscores the increasing sophistication and frequency of cyber attacks, particularly web application and DDoS attacks. It calls for a shift from reactive to preventative strategies, emphasizing the role of collaboration, secure coding, and regular patching in safeguarding the Internet. The ongoing threat of insecure IoT devices and the persistence of malware like Mirai and WireX further highlight the urgency of addressing these vulnerabilities.
试读结束,高清完整版pdf/doc/ppt,请点下载