paloalto-2020年物联网威胁报告(英文)-2020.3-22页_2mb
报告摘要
2020 Unit 42 IoT Threat Report Summary
Core Content
This report provides an in-depth analysis of the IoT threat landscape as of late 2019, focusing on the growing risks and vulnerabilities associated with IoT devices in enterprise and healthcare environments. It highlights the challenges organizations face in securing these devices and offers actionable recommendations to mitigate threats.
Main Points
IoT Security Landscape
- Rapid Growth: By the end of 2019, an estimated 4.8 billion IoT endpoints were in use, representing a 21.5% increase from 2018.
- Security Challenges: IoT devices are increasingly becoming targets for cyberattacks due to poor security practices, outdated software, and lack of visibility.
- Unencrypted Traffic: 98% of IoT device traffic is unencrypted, exposing sensitive data to attackers who can intercept and exploit it.
- Outdated Software: 83% of medical imaging devices run on unsupported operating systems, a 56% increase from 2018 due to Windows 7 end of life.
- Network Segmentation Gaps: Only 3% of healthcare VLANs strictly contain medical IoT devices, while 72% mix IoT and IT assets, allowing malware to spread across the network.
- Legacy Protocols at Risk: Decades-old OT protocols, such as DICOM, are being exploited to disrupt critical operations and spread malware.
Top IoT Threats
- Exploits and Password Attacks: 57% of IoT devices are vulnerable to medium- or high-severity attacks, and default passwords remain a common vector for attacks.
- IoT Worms: There is a growing trend of IoT worms over botnets, with malware spreading via self-propagation features.
- Cryptojacking: This threat has increased from 0% in 2017 to 5% in 2019, using IoT devices to mine cryptocurrency without user knowledge.
- Lateral Movement: Attackers exploit vulnerabilities to move laterally across networks, often starting with phishing attacks.
- Unpatched Devices: The lack of patches and updates on IoT devices, especially those running legacy OS, continues to be a major security risk.
Case Studies
- Conficker in Healthcare: A hospital's network was infected with Conficker, which exploited outdated Windows systems. Despite re-imaging, the lack of updated security patches left devices vulnerable again.
- Cryptojacking in the Wild: A healthcare organization experienced cryptomining code transfers between IT and OT devices. The attack was subtle and hard to detect, highlighting the need for continuous monitoring.
Key Information
- IoT Vulnerability: IoT devices are a prime target for attackers due to their weak security posture, lack of encryption, and outdated software.
- Healthcare Risks: Healthcare organizations are particularly vulnerable, with 51% of threats involving imaging devices. The use of legacy systems and poor network segmentation exacerbates these risks.
- Security Gaps: Organizations often lack the tools to discover and secure IoT devices, and IT and OT teams operate independently with different security practices.
- Threat Evolution: Cyberattacks are becoming more sophisticated, using peer-to-peer communication and exploiting legacy protocols to spread malware and disrupt operations.
Recommendations
Immediate Steps to Reduce Risk
- Discover IoT Devices: Use IoT security solutions to identify all network-connected devices, including those with unknown types or behaviors.
- Patch Vulnerable Devices: Focus on patching printers and other easily patchable devices to reduce the attack surface.
- Segment IoT Devices: Implement network segmentation using VLANs to isolate IoT devices from IT systems and reduce lateral movement risks.
- Enable Active Monitoring: Continuously monitor network traffic for suspicious behavior and malware activity.
Long-Term Strategy
- Think Holistically: Orchestrate the entire IoT lifecycle, from deployment to decommissioning, to ensure consistent security practices.
- Integrate Security Across All Devices: Use product integrations to expand security coverage to all IoT devices, ensuring they are treated with the same level of protection as IT systems.
Conclusion
The IoT threat landscape is evolving rapidly, with new attack techniques and an increasing number of devices exposed to cyber risks. Organizations must take proactive steps to discover, secure, and monitor their IoT assets to prevent attacks that can disrupt operations, compromise data, and even endanger lives. Implementing a holistic IoT security strategy is essential for long-term protection and resilience.
试读结束,高清完整版pdf/doc/ppt,请点下载