2018年-SWIFT环球同业银行金融电讯_The_Evolving_Cyber_Threat_to_the_Banking_Community_16页_5mb
报告摘要
Summary of the Evolving Cyber Threat to the Banking Community
Core Content
The document outlines the increasing sophistication and complexity of cyber threats targeting the global banking community, emphasizing the need for a robust, multi-layered security strategy. It highlights the evolution of attack techniques, the importance of proactive defense, and the role of collaboration and information sharing in mitigating risks.
Main Points
- Advanced Threats: Cyber adversaries have significantly improved their capabilities over the last 18 months, using increasingly sophisticated methods to bypass security controls and access critical banking systems.
- Attack Sophistication: Attackers are now using techniques such as:
- Gaining administrator rights to control systems.
- Manipulating software in memory to avoid detection.
- Bypassing multi-factor authentication through custom malware.
- Deploying fileless malware and encrypted payloads to remain stealthy.
- Covert Operations: Attackers often conduct long-term reconnaissance, sometimes for over a year, to understand internal processes before executing attacks.
- Evidence Erasure: Malware is designed to erase logs and other traces, making forensic investigations difficult. Some attacks include ransomware as a smokescreen.
- Stealth and Anonymity: Attackers use proxy chains and false flags to obscure their identity and operations, making attribution and response challenging.
- Watering Hole Tactics: Attackers infect legitimate websites to compromise users, often targeting bank employees who access these sites.
- Exploitation of Vulnerabilities: Attackers exploit even the smallest security weaknesses, such as unpatched systems or weak access controls, to gain entry and control over networks.
- Need for Defence in Depth: A single layer of security is insufficient. Multiple, layered defenses are required to protect against these complex threats.
- Importance of Cyber Hygiene: Basic security measures, such as strong password policies, regular updates, and access control, are essential to prevent attacks.
- Community Collaboration: Cybersecurity is a shared responsibility. The SWIFT Customer Security Programme (CSP) plays a key role in reinforcing the security of the financial ecosystem by promoting best practices and information sharing.
Key Information
- Case Study: A customer's system was compromised through an unknown initial vector. Attackers used custom malware to bypass authentication, submit fraudulent messages, and erase evidence, resulting in a major incident.
- Threat Intelligence: Sharing information on known threats and indicators of compromise (IOCs) is critical to protecting the entire ecosystem.
- Security Controls: SWIFT has published a set of mandatory security controls and an assurance framework to help users secure their infrastructure.
- Incident Response: Having clear policies and procedures for responding to incidents is vital. Customers should be able to cancel fraudulent transactions quickly and ensure that cancellation messages are prioritized.
- SWIFT's Role: SWIFT is actively working to improve the security of the financial ecosystem by sharing intelligence, publishing security bulletins, and supporting the implementation of security controls.
Best Practices and Recommendations
- Secure Your Environment:
- Embed security in network architecture.
- Implement physical and logical security measures.
- Harden host machines and ensure software is up to date.
- Know and Limit Access:
- Restrict administrator privileges.
- Use two-factor authentication for critical systems.
- Clearly define and manage access rights based on roles.
- Detect and Respond:
- Monitor network and system activity for unusual behavior.
- Use intrusion detection systems and respond promptly to alerts.
- Threat Intelligence:
- Regularly review security bulletins and indicators from SWIFT ISAC.
- Stay informed about emerging threats and update defenses accordingly.
- Limit Exposures:
- Maintain relationships only with trusted counterparties.
- Use SWIFT's RMA tools to manage and monitor these relationships.
- Security Controls:
- Conduct regular security audits and benchmarking.
- Implement and maintain the mandatory security controls provided by SWIFT.
- Know Your Counterparts:
- Integrate cyber risk assessments into KYC processes.
- Request self-attestations from counterparties to ensure they meet security standards.
- Other Business Controls:
- Filter outgoing messages to detect unusual or illicit flows.
- Perform post-message checks to identify and respond to fraud.
- Incident Response:
- Develop and test incident response plans.
- Ensure that cancellation messages are flagged and prioritized for quick processing.
Conclusion
The evolving cyber threat landscape demands a continuous, proactive, and collaborative approach to security. While no system is completely secure, implementing comprehensive security measures, maintaining vigilance, and participating in shared intelligence initiatives can significantly reduce the risk of successful attacks. The SWIFT Customer Security Programme is a critical component of this effort, providing guidance, tools, and support to enhance the security of the global financial community.
试读结束,高清完整版pdf/doc/ppt,请点下载