2018卡巴斯基实验室威胁预测(英文版)-9mb
报告摘要
2018 Cybersecurity Predictions Summary
Introduction
In 2017, sophisticated cyber threats, particularly APTs (Advanced Persistent Threats), continued to dominate headlines. These threats, often politically motivated, were not only more complex but also more destructive, with ransomware attacks causing significant financial losses. The report highlights the growing need for enterprises to understand and prepare for cyber threats specific to their industries. It outlines predictions based on Kaspersky Lab's research and experience, aiming to provoke awareness and action.
Core Predictions for 2018
1. More Supply Chain Attacks
- Trend: Attackers are increasingly targeting supply chain components to infiltrate more secure systems.
- Reason: Supply chain attacks can bypass the defenses of a well-protected enterprise by exploiting third-party software.
- Examples:
- Shadowpad: Trojanized software from Netsarang was used to compromise numerous organizations.
- CCleaner: Over 2 million devices were infected through a malicious update.
- Expectation: More supply chain attacks will be discovered and executed in 2018, especially in specialized software used in certain regions and sectors.
2. More High-End Mobile Malware
- Trend: Sophisticated mobile malware targeting high-value assets will increase.
- Reason: Mobile platforms, particularly iOS and Android, are becoming more attractive for APT groups due to their advanced capabilities.
- Examples:
- Pegasus: A mobile espionage platform sold by an Israeli company, capable of remote jailbreaks with persistence.
- Chrysaor: The Android version of Pegasus.
- Expectation: More high-end APT malware for mobile will be discovered as attacks increase and security technologies improve.
3. More BeEF-like Compromises with Web Profiling
- Trend: Web profiling techniques will be used more frequently by APT groups.
- Reason: The cost of zero-day exploits has risen due to increased interest and better security measures.
- Examples:
- BeEF: A popular profiling toolkit used by APT groups like Turla and Sofacy.
- Newsbeef: Known for their custom profiling frameworks.
- Expectation: The use of profiling toolkits like BeEF will increase in 2018, with more groups adopting or developing their own.
4. More UEFI and BIOS Attacks
- Trend: UEFI-based malware will become more prevalent.
- Reason: UEFI offers advanced capabilities that make it an attractive target for attackers, allowing malware to execute before the OS starts.
- Examples:
- Hacking Team: Discovered UEFI modules in 2015.
- Shamoon: A destructive wiper that has been dormant for years but is expected to re-emerge.
- Expectation: More UEFI-based malware will be discovered in 2018 due to its increasing use and the need to protect such advanced tools.
5. Destructive Attacks Continue
- Trend: Destructive attacks, including wiper malware, will persist.
- Reason: These attacks are seen as a visible form of cyber warfare, and their impact is significant.
- Examples:
- Shamoon 2.0: Targeted critical sectors in Saudi Arabia.
- ExPetr/NotPetya: Initially thought to be ransomware, it was later identified as a wiper.
- Expectation: Destructive attacks will continue to rise in 2018, with more severe threats and potential for greater damage.
6. More Subversion of Cryptography
- Trend: Cryptographic vulnerabilities will be found and patched.
- Reason: The discovery of flaws in encryption standards and implementations raises concerns about the security of everyday digital interactions.
- Examples:
- NSA's Dual_EC: Used by Juniper and others, with potential for subverting encryption.
- Infineon RSA Prime Flaw: A flaw in a cryptographic library used in hardware chips.
- Expectation: More severe cryptographic vulnerabilities will be found and patched in 2018.
7. Identity Crisis in E-Commerce
- Trend: Identity theft and fraud will become more critical issues.
- Reason: Large-scale breaches of PII (Personally Identifiable Information) are becoming more common, undermining trust in e-commerce.
- Examples:
- Equifax Breach: Affecting 145.5 million Americans.
- Expectation: E-commerce will face a crisis in identity management, with a need for stronger multi-factor authentication solutions.
8. More Router and Modem Hacks
- Trend: Routers and modems will become more targeted by attackers.
- Reason: These devices are often unpatched and run proprietary software, making them easy targets.
- Examples:
- Home and Enterprise Routers: Vulnerable to attacks and used as entry points for larger networks.
- Expectation: Increased scrutiny of these devices will lead to more findings and potential vulnerabilities.
9. Social Media as a Medium for Social Chaos
- Trend: Social media platforms will be used more for political manipulation and misinformation.
- Reason: The use of bots and fake users is increasing, and these platforms have little incentive to remove them.
- Examples:
- Facebook and Twitter: Under scrutiny for their role in spreading misinformation.
- Expectation: Greater backlash against social media will occur, with users seeking alternatives.
Industry and Technology Predictions
Automotive Sector
- Trend: The connected-car market is growing rapidly, with more vehicles being connected to the Internet.
- Risk Factors:
- Lack of Manufacturer Attention: Leads to vulnerabilities in connected mobility services.
- Complexity of Systems: Increases the attack surface and potential for exploitation.
- Third-Party Apps: May be compromised, leading to control of critical vehicle components.
- Expectation:
- More Connected Vehicles: By 2020, over 250 million connected cars are expected.
- Security Measures: First cyber-secure devices for telematics and diagnostics will emerge.
- Regulatory Changes: Cybersecurity will become a mandatory requirement for all connected vehicles.
Connected Health Sector
- Trend: The healthcare sector will face more threats due to the increasing number of connected devices and web applications.
- Risk Factors:
- Unprotected Medical Devices: Many devices are accessible online without proper security measures.
- Data Vulnerability: Medical information and patient data are highly valuable and can be exploited for extortion or blackmail.
- Expectation:
- More Targeted Attacks: Aimed at stealing sensitive medical data.
- Increased Awareness: Will lead to better security practices and regulations.
Conclusion
The report emphasizes that cybersecurity threats are evolving and becoming more sophisticated. The key to mitigating these risks lies in the integration of security as a standard, the development of robust threat intelligence, and the implementation of clear industry standards. The 2018 predictions reflect the growing complexity and scale of cyber threats across various sectors, urging organizations to prepare and adapt.
试读结束,高清完整版pdf/doc/ppt,请点下载