2018数据泄露调查报告(英文版)_68页-1mb
报告摘要
2018 Data Breach Investigations Report Summary
Core Content Overview
The 2018 Data Breach Investigations Report (DBIR), now in its 11th edition, is based on real-world data breaches and security incidents. It provides insights into the nature of cyber threats, their actors, motives, and methods, with a focus on actionable information for security practitioners, executives, and employees. The report highlights trends and patterns in breach data, and offers guidance on how to better defend against cyber threats.
Main Points and Key Information
Incidents vs. Breaches
- Incident: A security event that compromises the integrity, confidentiality, or availability of an information asset.
- Breach: An incident that results in confirmed data disclosure to an unauthorized party.
- The report includes 53,000 incidents and 2,216 confirmed breaches for 2018.
Threat Actors
- External actors are the most common (99% of breaches), with internal actors accounting for 6%.
- Partner actors are rare (<1%).
- Actor motives are primarily financial gain (59%) and espionage (38%).
Threat Actions
- The top threat action categories include:
- Crimeware (most prevalent)
- Everything Else
- Cyber-Espionage
- Phishing remains the most common method of social attacks, with email as the primary vector (96% of social attacks).
Data Compromised
- Personal data (47%) and secrets (26%) are the most commonly compromised data types.
- Credentials (17%) and internal data (22%) are also significant.
Breach Timeline
- The time from the first action in an event chain to initial compromise is often measured in seconds or minutes.
- Discovery time is typically weeks or months.
- Time to exfiltration is not well-documented, but reducing this time can help prevent high-impact breaches.
Social Attacks
- Phishing and pretexting represent 98% of social incidents and 93% of breaches.
- Phishing is the most common method, but pretexting is also on the rise, especially targeting finance and HR departments.
- Business Email Compromise (BEC) is a key form of pretexting, often involving impersonation of executives.
- Only 17% of phishing campaigns are reported, and the average time until the first click is 16 minutes.
Ransomware Insights
- Ransomware has become the most prevalent type of malware in this year’s dataset.
- It is used in both opportunistic attacks and targeted strikes.
- Ransomware is cost-effective for attackers and can affect multiple devices to increase the ransom amount.
- Server and database infections are particularly damaging, and their frequency has increased over time.
Botnets and Malware
- Botnets continue to be a major threat, with over 43,000 breaches involving stolen customer credentials.
- Dridex is no longer a major concern, but other botnets remain active.
- Botnets can affect organizations in two ways:
- Users unknowingly download malware that steals credentials.
- Compromised hosts within the network act as foot soldiers in a botnet.
Industry-Specific Insights
- The report analyzes breach patterns across various industries, including Accommodation and Food Services, Education, Financial and Insurance, Healthcare, Information, Manufacturing, Professional Services, and Retail.
- Each industry has its own common breach vectors, targeted data types, and attack patterns.
Methodology and Biases
- The report uses VERIS (Vocabulary for Event Recording and Incident Sharing) to standardize incident reporting.
- It acknowledges that some bias remains, particularly due to the inclusion of certain data types like botnet-related breaches.
- Appendix E provides a detailed discussion of the methodology used to collect and analyze data.
Key Trends
- Phishing remains the most common method of social attacks.
- Ransomware is the most prevalent type of malware.
- Social engineering is a critical factor in many breaches, especially those involving pretexting.
- Breach detection and response are crucial to minimizing impact.
- Malware installation is more common in phishing incidents (over two-thirds) than in pretexting (under 10%).
Conclusion
The 2018 DBIR serves as a valuable resource for understanding the evolving landscape of cyber threats. It emphasizes the importance of proactive security measures, employee training, and incident response to mitigate risks. The report also highlights the need for real-time detection, strong authentication, and segmentation of networks to prevent the spread of malware and limit the damage of breaches.
Appendix Highlights
- Appendix A: Discusses how to counter cybersecurity threats.
- Appendix B: Provides insights into how users feel about cybersecurity.
- Appendix C: Includes the arc diagram of attack paths.
- Appendix D: Reviews the year in cybersecurity.
- Appendix E: Details the methodology and potential biases.
- Appendix F: Explores data destruction.
- Appendix G: Offers guidance on breach response.
- Appendix H: Focuses on web application security.
- Appendix I: Lists contributing organizations.
试读结束,高清完整版pdf/doc/ppt,请点下载