2017网络入侵报告(英文版)_29页_1mb
报告摘要
CrowdStrike Cyber Intrusion Services Casebook 2017 Summary
Core Content
This document is the CrowdStrike Cyber Intrusion Services Casebook 2017, which provides insights into the evolving tactics, techniques, and procedures (TTPs) of cyber attackers. It is based on real-world incident response (IR) cases and highlights the increasing sophistication and persistence of threat actors in breaching organizational security.
Main Points and Trends
- Cyberattacks are a growing reality: Organizations face significant risks from breaches involving stolen data, disrupted operations, and financial loss. Attackers are continuously adapting their methods to exploit vulnerabilities in IT infrastructure.
- Evolving attacker TTPs: Threat actors are using advanced methods such as fileless malware, living off the land (using native OS tools like PowerShell and WMI), and self-propagation techniques to spread ransomware and destructive malware across networks.
- Blurring lines between threat actors: Nation-state-sponsored groups and eCrime actors are adopting similar strategies, making it harder to distinguish between different types of threats.
- Long dwell times: The average time an attacker remains undetected in a network is 86 days, with some cases reaching up to 800–1,000 days, indicating a need for faster detection and response.
- Malware-free attacks are prevalent: 66% of attacks were conducted without writing any files to disk, often through brute-force attacks, stolen credentials, and exploiting system weaknesses.
Key Findings
1. Breach Detection Improvements
- 68% of clients were able to internally detect breaches in 2017, a 11% increase from the previous year.
- This reflects the growing maturity of security postures and the adoption of tools like endpoint detection and response (EDR).
2. Attack Objectives
The most common objectives of cyber intrusions were:
- Intellectual Property (IP) theft
- Monetary loss
- Personally Identifiable Information (PII) theft
- Ransom or extortion
3. Attack Vectors
The most common methods attackers used to gain initial access were:
- Web server/web application exploits: 37%
- Remote access (RDP, VPN): 23%
- Supply chain compromise: 12%
- Social engineering and phishing: 11%
- Cloud-based service or email portal exploits: 11%
- Other: 6%
Case Studies and Recommendations
Case Study 01: SamSam Ransomware via xDedic
- Client: A commercial services organization.
- Attack Method: Ransomware was deployed via compromised RDP servers using brute-force attacks and Sticky Keys for persistence.
- Key Recommendations:
- Enforce Network Level Authentication (NLA) for RDP sessions.
- Implement two-factor authentication (2FA) to prevent unauthorized access.
- Reset passwords for all compromised accounts and apply the least privilege principle.
- Use EDR tools like CrowdStrike Falcon Insight to detect and respond to threats.
Case Study 02: E-commerce Web Server Compromise
- Client: A manufacturer with an e-commerce website.
- Attack Method: Attackers exploited a vulnerability in a web application to upload malicious PHP code and inject web shells into the system.
- Key Recommendations:
- Improve vulnerability patch management.
- Implement File Integrity Monitoring (FIM) to detect file changes.
- Deploy EDR tools for better visibility and threat detection.
- Rebuild compromised systems and reset passwords.
- Enable database logging for transactions and slow queries.
- Conduct regular penetration testing on web applications.
Case Study 03: Fileless POS System Compromise
- Client: A large retailer.
- Attack Method: Attackers used fileless techniques such as RAM-scraping malware and PowerShell implants to exfiltrate credit card data without leaving traces on disk.
- Key Recommendations:
- Implement end-to-end encryption for POS transactions.
- Log full PowerShell commands and enable script block logging.
- Upgrade to PowerShell v5+ for better audit and logging capabilities.
- Train staff to avoid spear phishing and ensure proper log management.
Case Study 04: NotPetya Supply Chain Attack
- Client: A company affected by the NotPetya malware in June 2017.
- Attack Method: NotPetya was delivered via a supply chain attack embedded in a software update from M.E.Doc, an accounting application used in Ukraine.
- Key Recommendations:
- Deploy EDR solutions like CrowdStrike Falcon to monitor and respond to threats.
- Ensure proper system updates and patch management.
- Maintain and review logs to track attacker behavior and improve incident response.
- Use automated tools to detect and respond to threats before they cause significant damage.
Conclusion
The 2017 CrowdStrike Cyber Intrusion Services Casebook highlights the increasing sophistication of cyber threats and the need for proactive and adaptive security strategies. It emphasizes the importance of EDR tools, log management, patch management, and employee training in mitigating risks. The report underscores that traditional security measures are no longer sufficient and that modern, comprehensive security frameworks are essential for resilience in the face of evolving attack methods.
试读结束,高清完整版pdf/doc/ppt,请点下载