2017网络入侵报告(英文版)_31页-1mb
报告摘要
CrowdStrike Cyber Intrusion Services Casebook 2017 Summary
Core Content
This CrowdStrike® Cyber Intrusion Services Casebook for 2017 provides a comprehensive overview of the evolving tactics, techniques, and procedures (TTPs) used by cyber threat actors. It draws from real-world incident response (IR) engagements and outlines key findings, trends, and recommendations to help organizations improve their security resilience against increasingly sophisticated attacks.
Main Points and Key Findings
- Cyberattacks are inevitable and impactful: Successful intrusions can lead to massive consequences, including the theft, exposure, or destruction of valuable data, and can disrupt business operations significantly.
- Threat actors are evolving rapidly: Attackers are adopting new methods such as fileless malware, "living off the land" techniques, and self-propagation mechanisms, making traditional security measures less effective.
- Organizations are improving breach detection capabilities: 68% of clients detected breaches internally in 2017, a 11% increase from the previous year, indicating a growing maturity in security posture.
- Average attacker dwell time is 86 days: This highlights the critical need for faster detection and response mechanisms to minimize damage.
- Ransomware and destructive attacks are becoming more sophisticated: Self-propagating ransomware variants are now able to spread across networks without user interaction, increasing the risk of large-scale impact.
- Malware-free attacks are prevalent: 66% of attacks did not involve writing files to disk, using techniques like memory-based execution and credential-based access to avoid detection.
- No organization is immune to cyber threats: Across various industries, including retail, healthcare, finance, and IT, all types of organizations are vulnerable and must prepare for potential attacks.
Key Trends
Trend 1: Blurring Lines Between Nation-State and eCrime Actors
- Shared TTPs: eCrime groups are increasingly using the same tactics as nation-state actors, such as fileless malware and "living off the land" methods.
- Anti-forensics tools: Attackers use these to erase traces of their presence and prolong their dwell time in the network.
- Brute-force attacks on RDP servers: These are a common method for attackers to gain initial access, especially in organizations with weak authentication controls.
Trend 2: Rise of Self-Propagating Ransomware and Destructive Malware
- Spread without user intervention: Malware like NotPetya and SamSam can propagate across systems automatically, making it harder to contain.
- Impact of outdated systems: Failing to maintain up-to-date systems and relying on legacy security tools can lead to severe consequences.
- Targeted attacks: Attackers are increasingly focused on specific systems or data, often using RDP credentials or other stolen access points to expand their control.
Case Studies and Recommendations
Case Study 01: SamSam Ransomware via xDedic
- Attack Overview: The SamSam variant was used to encrypt files and demand ransom, with the initial access gained through compromised RDP credentials.
- Tools Used: Brute-force attacks on RDP, Sticky Keys for persistence, and xDedic-related tools.
- Recommendations:
- Enforce Network Level Authentication (NLA) for RDP sessions.
- Implement two-factor authentication (2FA) to prevent unauthorized access.
- Use EDR tools like CrowdStrike Falcon Insight to detect and respond to threats more effectively.
- Rebuild and reset compromised systems to eliminate backdoors and malicious code.
- Apply vulnerability patch management to close known and unknown security gaps.
- Enable File Integrity Monitoring (FIM) to detect file tampering.
- Enable database logging for transactions and slow queries to aid in forensic investigations.
Case Study 02: E-commerce Web Server Compromised via Vulnerability
- Attack Overview: Attackers exploited a vulnerability in a widely used e-commerce application to upload malicious images and inject code, leading to web shells and database compromise.
- Tools Used: PHP code injection, web shells, and malicious JavaScript for credit card data exfiltration.
- Recommendations:
- Conduct regular penetration testing of web applications and systems.
- Implement FIM and EDR for continuous monitoring and detection.
- Rebuild compromised systems to remove any malicious artifacts.
- Reset passwords and apply the least privilege principle to limit access.
- Enable database logging for auditing and incident response.
Case Study 03: Fileless Attack on POS Systems
- Attack Overview: The attacker used fileless techniques, including PowerShell-based implants and RAM-scraping malware, to exfiltrate credit card data without leaving traditional malware traces.
- Tools Used: cgwin.exe for data validation, RemoteExec for remote command execution, and 7-Zip for data archiving.
- Recommendations:
- Implement end-to-end encryption for POS transactions.
- Ensure log archives are maintained and used for forensic analysis.
- Train staff to avoid spear phishing and other social engineering attacks.
- Enable full PowerShell command logging and use PowerShell v5+ for better auditing and tracking.
- Avoid relying solely on traditional antivirus; use EDR solutions for comprehensive visibility.
Case Study 04: NotPetya Supply Chain Attack
- Attack Overview: NotPetya was delivered through a compromised update of the M.E.Doc accounting software, targeting Ukrainian-based organizations.
- Tools Used: Fileless techniques, self-propagating malware, and exploitation of software vulnerabilities.
- Recommendations:
- Use EDR platforms like CrowdStrike Falcon to monitor and respond to threats in real-time.
- Deploy FFC for forensic data collection and historical analysis.
- Maintain up-to-date systems and avoid reliance on outdated software and infrastructure.
- Engage in proactive threat intelligence and incident response planning.
Conclusion
The 2017 CrowdStrike Cyber Intrusion Services Casebook underscores the growing sophistication of cyber threats and the need for organizations to adopt more advanced and proactive security measures. With the increasing use of fileless attacks, self-propagation, and the convergence of eCrime and nation-state actors, traditional security tools are no longer sufficient. Organizations must invest in endpoint detection and response (EDR), file integrity monitoring (FIM), log management, and employee training to improve their resilience and response capabilities. The report emphasizes that preparation and rapid detection are key to mitigating the damage of cyber intrusions and protecting digital assets.
试读结束,高清完整版pdf/doc/ppt,请点下载