2024-11-16-Elasticsearch-2024年全球网络风险报告_81页_6mb
报告摘要
Global Threat Report Summary
Introduction
The Global Threat Report by Elastic Security Labs highlights the evolving security landscape, emphasizing the dynamic and reactive nature of threat ecosystems. It underscores the importance of transparency, knowledge sharing, and the role of the security community in identifying and mitigating threats. Elastic Security Labs relies on data from its users and open sources to provide insights and protections, and this report serves as a tool for accountability and progress in the field of cybersecurity.
Generative AI
Threat Overview
Generative AI has introduced new capabilities for threat actors, particularly in augmented phishing and social engineering. These AI-powered tools allow for the creation of highly personalized and sophisticated phishing campaigns that are difficult to distinguish from legitimate communications. Additionally, deepfake-based scams have been used in political elections and extortion cases, though their impact on cybersecurity remains limited.
Malware Development
AI is being used to create more adaptive malware, though this technology is not yet widely adopted. The availability of AI-driven malware is a growing concern, and as models and services become more accessible, this trend is expected to continue. Security teams must stay updated on threats and maintain a robust, regularly updated protections library.
Augmenting Defenders
Generative AI offers significant benefits to defenders as well. It enhances cybersecurity tooling by enabling automatic threat detection, automated security testing, and realistic training simulations. These capabilities allow for more efficient threat response and better preparedness. Elastic Security Labs has integrated these functions into its solution to support defenders in their daily operations.
Malware Detections
Distribution by Operating System
- Windows: 66.12% of all malware detections
- Linux: 32.20%
- macOS: 1.68%
While Windows remains the most targeted OS, the report notes that macOS and Linux have seen an increase in malware activity, likely due to growing interest in exploiting vulnerabilities in these systems.
Malware Categories
| Malware Category | Percentage |
|---|---|
| Trojan | 82.03% |
| Generic | 8.03% |
| Cryptominer | 4.39% |
| Ransomware | 2.10% |
| Backdoor | 1.01% |
| Other | 2.44% |
Trojans dominate malware detections due to their ability to masquerade as legitimate software and deliver additional payloads. Cryptominer activity has decreased significantly, possibly due to increased awareness and mitigation efforts. Ransomware remains a critical threat due to its impact on extortion, theft, and reputational damage.
Malware Families
The most common malware families detected include:
- Cobalt Strike: 27.02%
- Metasploit variants: 18.2%
- Meterpreter: 5.1%
- Sliver: 8.71%
- DONUTLoader: 6.62%
These families are often associated with offensive security tools (OSTs), which are increasingly being abused by threat actors. The report emphasizes the importance of monitoring and mitigating these families throughout the intrusion lifecycle.
Endpoint Behaviors
Distribution by Operating System
- Windows: 92.73%
- Linux: 3.30%
- macOS: 3.97%
Windows remains the most common platform for endpoint behaviors, though macOS and Linux have shown slight increases, indicating a growing interest in these systems from adversaries.
Distribution by Tactic
| Tactic | Percentage |
|---|---|
| Persistence | ~8% |
| Defense Evasion | 38% |
| Execution | ~16% |
Defense Evasion is the most prevalent tactic, with techniques such as Process Injection and System Binary Proxy Execution being widely used. Process Injection detections increased by 31%, now accounting for 53.39% of all Defense Evasion alerts. This tactic is often used to bypass security controls.
System Binary Proxy Execution also remains common, with rund1132.exe being a frequently abused tool. Adversaries often use mshta.exe for similar purposes, which is more prevalent than rund1132.exe.
Linux Defense Evasion
- Impair Defenses: 57.01%
- File and Directory Permission Modifications: 31.03%
- Indicator Removal: 3.37%
Adversaries frequently attempt to disable iptables and firewall services using native tools. They also manipulate Linux kernel modules and modify file permissions in writable directories like /dev/shm and /var/tmp.
macOS Defense Evasion
- Reflective Code Loading: 34.19%
- Subverting Trust Controls: 12.87%
- Indicator Removal: ~60%
Reflective Code Loading is a technique used by advanced threats to load payloads into compromised processes. Indicator Removal involves deleting logs and command-line history to obscure adversary activity.
Threat Profiles
The report outlines several threat profiles, including:
- REF5961 — BLOODALCHEMY, RUDEBIRD, EAGERBEE, DOWNTOWN
- REF8207 — GHOSTPULSE
- REF4578 — GHOSTENGINE (includes a cryptomining application)
- REF7001 — KANDYKORN (linked to DPRK activity)
- REF6127 — WARMCOokie
These profiles represent some of the most significant threats observed this year, with GHOSTENGINE and KANDYKORN being particularly noteworthy due to their advanced capabilities and potential for damage.
Responding to 2023 Forecasts
The report acknowledges the importance of preparing for the threats that emerged in 2023. It highlights the need for continuous monitoring, adaptation, and proactive defense strategies.
Forecasts and Recommendations
The report suggests that the use of generative AI will continue to evolve and pose new challenges. It recommends:
- Implementing AI-focused cybersecurity training to help users identify AI-generated threats.
- Maintaining up-to-date protections libraries and YARA signatures to detect and mitigate malware effectively.
- Enhancing endpoint visibility and instrumentation to identify and respond to malicious activity.
- Strengthening information sharing and collaboration within the security community to stay ahead of emerging threats.
Conclusion
The report concludes that while the security environment is stronger due to technological advancements and increased awareness, threat ecosystems are still thriving. It reaffirms Elastic Security Labs' commitment to transparency, collaboration, and innovation in the cybersecurity space. The report also emphasizes the need for vigilance, adaptability, and the responsible use of AI in both offensive and defensive contexts.
试读结束,高清完整版pdf/doc/ppt,请点下载