2020年数据泄露调查报告(英文版)_119页_6mb
报告摘要
Data Breach Investigations Report (DBIR) 2020 Summary
Core Content
This report, the 13th edition of the Data Breach Investigations Report (DBIR), provides a comprehensive analysis of global data breaches and security incidents, based on a dataset of 157,525 incidents and 3,950 confirmed breaches. The report utilizes the VERIS framework to classify and analyze incidents and breaches, and it aligns with CIS Controls and MITRE ATT&CK to improve data quality and relevance.
Key Findings
Breach Statistics
- Total breaches: 3,950
- Quality breaches: 32,002
- Total incidents: 157,525
- Breach distribution:
- 55% of breaches were attributed to organized criminal groups
- 30% involved internal actors
- 4% had four or more attacker actions
- 1% involved partner actors
- 1% featured multiple parties
- Victim distribution:
- 72% of breaches involved large businesses
- 28% involved small businesses
- 58% of breaches involved personal data being compromised
- Threat action varieties:
- Phishing was involved in 22% of breaches
- Use of stolen credentials occurred in 37% of breaches
- Malware was involved in 27% of Malware incidents, with Ransomware being the third most common breach type
- Web applications were involved in 43% of breaches
- Misconfiguration was a top threat action variety in breaches
Trends and Analysis
- Malware is becoming less prevalent as a standalone threat, with phishing and credential theft increasingly used in combination with other attack types.
- Error is now the most common threat action variety in breaches, surpassing Social and Malware, and is particularly prevalent across all industries.
- Ransomware is rising as an incident type, but it only becomes a breach when paired with credential use.
- Threat actors are primarily organized criminals, followed by state-aligned actors, internal end users, and system administrators.
- Geographic focus has expanded, with the report now analyzing breaches from four global regions: Northern America, Europe, Middle East and Africa (EMEA), Asia-Pacific (APAC), and Latin America and the Caribbean (LAC).
Main Sections
01. DBIR Cheat Sheet
- Provides a quick overview of the report's key data points and findings.
- Introduces the use of dot plots and VERIS terminology for better understanding.
02. Results and Analysis
- Highlights trends in breach actions and actor types over time.
- Discusses survivorship bias in the dataset, emphasizing that the data reflects breaches, not the absence of attacks.
03. Industry Analysis
- Examines the most common attack types, actors, and actions across 16 industries.
- Includes detailed insights for each sector, such as Healthcare, Financial, and Retail.
04. Does Size Matter?
- Analyzes Small and Medium Businesses (SMBs) and their vulnerability to breaches.
- Shows that 28% of breaches involved small businesses, indicating that they are not immune to cyber threats.
05. Regional Analysis
- Breaks down breach statistics by Northern America, EMEA, APAC, and LAC.
- Highlights the global reach of the report and the diversity of threats across regions.
06. Wrap-up
- Offers CIS Control recommendations for improving security.
- Summarizes the year in review, emphasizing the importance of data sharing and collaboration.
- Acknowledges the 81 contributors from 81 countries and encourages more to join.
07. Appendices
- Appendix A: Details the methodology used to collect and analyze data.
- Appendix B: Explains the VERIS Common Attack Framework (VCAF).
- Appendix C: Discusses how to trace cybercriminals using data.
- Appendix D: Features a case study from State of Idaho on incident response.
- Appendix E: Lists the contributing organizations.
Conclusion
The DBIR 2020 emphasizes the importance of data-driven security analysis and the evolving nature of cyber threats. It underscores that organized crime is the most common actor, and that errors and misconfigurations are increasingly significant in breach scenarios. The report also encourages data sharing and collaboration among organizations to improve global cybersecurity resilience.
Key Terms and Definitions
- Incident: A security event that compromises the integrity, confidentiality, or availability of an information asset.
- Breach: An incident that results in the confirmed disclosure of data to an unauthorized party.
- Threat actor: The entity behind a breach (e.g., external attackers, internal employees).
- Threat action: The tactics used to affect an asset (e.g., hacking, phishing, malware).
- Variety: A more specific categorization of threat actions (e.g., SQL injection, brute force).
Recommendations
- Improve data collection and reporting to reduce bias.
- Focus on credential protection and phishing prevention.
- Expand security awareness and training for employees and partners.
- Leverage VERIS and CIS Controls for consistent and actionable data.
- Encourage small and medium businesses to adopt robust security measures.
试读结束,高清完整版pdf/doc/ppt,请点下载