20221225-Akamai-2022年互联网现状报告_34页_11mb
报告摘要
Analysis Summary: Enemy at the Gates – Financial Services Cybersecurity Threats
Introduction to the Issue
Financial services is a highly targeted sector by cybercriminals due to the critical nature of its operations, the value of sensitive data, and the potential for significant financial gains. The industry faces a broad range of cyber threats, including web application attacks, malware, and phishing campaigns, which have surged in frequency and sophistication.
Overall Threat Landscape
The threat landscape against financial services shows a dramatic increase in cyberattacks. Web application and API attacks have grown by 3.5 times year-over-year, making them the most targeted area. Financial services consistently ranks high in attacks, alongside high technology and commerce industries. New vulnerabilities, such as zero-day exploits, are rapidly leveraged by attackers, with significant attack waves observed within hours of disclosure.
Growing Security Risks: Web Application and API Attacks
Web applications and APIs are critical for customer experiences and business operations but are also major entry points for attackers. The rise includes attacks like Local File Inclusion (LFI) and Cross-Site Scripting (XSS), enabling remote code execution and data breaches. These attacks are driven by automation and reconnaissance, with attackers exploiting vulnerabilities to gain footholds and move laterally.
Dangers of Newly Disclosed Vulnerabilities
Emerging vulnerabilities, such as Log4Shell and Spring4Shell, pose significant risks due to rapid exploitation. For instance, the Confluence vulnerability CVE-2022-26134 was exploited extensively, with peak attack attempts observed within days. Emerging vulnerabilities are a preferred method for infiltrating networks, and financial services, as a high-revenue target, remains under constant attack.
DDoS Attack Trends
DDoS attacks have shifted regionally, with the US experiencing a decline in target volume while EMEA saw growth. This shift is partly influenced by geopolitical factors, such as the Russia-Ukraine conflict. DDoS attacks aim to disrupt services, extort money, or serve as a smokescreen for other attacks, causing significant financial losses and downtime.
Abuse and Customer Targeting
A concerning trend is that over 80% of attacks focus on financial services customers rather than institutions. This includes account takeover (ATOs), which are often facilitated by botnets and credential stuffing. Customer accounts are targeted due to weaker defenses compared to institutional security, leading to identity theft, financial loss, and reputational damage.
Phishing and Multi-Factor Authentication Bypass
Phishing campaigns, such as those using the Kr3pto toolkit, account for a large portion of attacks. These kits can bypass traditional two-factor authentication (2FA) methods like OTP tokens or push notifications, enabling credential theft. Businesses require stronger alternatives, such as FIDO2 passwordless authentication, which reduces the risk of phishing by not relying on stolen credentials.
Road to Malware and Ransomware
Once attackers breach networks, they deploy malware, including ransomware, to exfiltrate data, disrupt operations, and demand payments. Ransomware TTPs involve phishing for initial entry, lateral movement, and exploitation of tools like Mimikatz for credential harvesting. Mitigation requires proactive measures, including patch management, security controls, and adopting zero-trust architectures.
Summary and Conclusions
The threat surface for financial services continues to expand, driven by technological adoption and evolving cybercrime tactics. Key recommendations include enhancing security controls, prioritizing patching, securing APIs, and implementing stronger multi-factor authentication. Organizations must improve cyber resilience to mitigate risks from emerging threats and protect both institutional and customer assets, potentially affecting trust and finances.
Stay informed with ongoing research to address the growing challenges effectively.
试读结束,高清完整版pdf/doc/ppt,请点下载