Crowdstrike-2017网络入侵报告(网络安全)(英文版)-2017-31页
报告摘要
CrowdStrike Cyber Intrusion Services Casebook 2017 Summary
Core Content Overview
This document, CrowdStrike Cyber Intrusion Services Casebook 2017, provides a comprehensive review of cyber intrusion cases handled by CrowdStrike Services in 2017. It highlights evolving attacker tactics, techniques, and procedures (TTPs), along with actionable recommendations for organizations to enhance their security resilience. The casebook is based on real-world engagements and aims to inform both executive stakeholders and security professionals on how to better detect, respond to, and prevent cyberattacks.
Main Points and Key Findings
1. Evolving Threat Landscape
- Cyberattacks are increasingly sophisticated and persistent, with attackers continuously adapting their methods to exploit gaps in IT infrastructure.
- Nation-state actors and eCrime threat actors are blurring in their tactics, with eCrime groups adopting similar techniques as nation-states, such as fileless malware and "living off the land" strategies.
- Self-propagation techniques are now common in ransomware and destructive attacks, allowing malware to spread across networks without user intervention.
2. Detection and Response Improvements
- 68% of clients detected breaches internally in 2017, up from 57% the previous year, indicating a maturing security posture.
- Average attacker dwell time is 86 days, with some cases reaching up to 800–1,000 days, highlighting the need for faster detection and response mechanisms.
3. Common Attack Objectives
- Intellectual Property (IP) theft
- Monetary loss
- Personally Identifiable Information (PII) theft
- Ransom or extortion
4. Attack Vectors
- Web server/web application exploits (37%)
- Remote access (RDP, VPN) (23%)
- Supply chain compromise (12%)
- Social engineering, phishing, and spear phishing (11%)
- Cloud-based service exploits (11%)
5. Malware-Free Attacks
- 66% of attacks were malware-free, meaning they did not involve writing files to disk.
- These attacks often use fileless techniques, such as:
- Executing code from memory
- Exploiting vulnerabilities in IT infrastructure
- Leveraging Sticky Keys (a Windows accessibility feature) for persistence
Key Trends
Trend 1: Blurring Lines Between Nation-State and eCrime Actors
- eCrime groups are increasingly using advanced tactics like fileless malware and "living off the land" techniques, which are traditionally associated with nation-state actors.
- Anti-forensics tools are used to erase digital traces and extend dwell time.
- RDP brute-force attacks are a common method used to gain initial access.
Trend 2: Self-Propagating Ransomware and Destructive Malware
- Ransomware and destructive malware are now capable of self-propagation, spreading across systems without user interaction.
- The NotPetya malware is a prime example, using a supply chain attack to infect systems and propagate itself.
- Legacy security tools (e.g., signature-based antivirus) are often ineffective against these types of attacks.
Case Studies and Recommendations
Case Study 01: SamSam Ransomware via xDedic
- Client: Commercial services organization
- Attack: SamSam ransomware was deployed via compromised RDP credentials, likely obtained through brute-force attacks.
- Findings:
- SamSam is associated with xDedic, a Russian darknet forum.
- Attackers used Sticky Keys for persistence and RDP brute-force to gain access.
- Recommendations:
- Enforce Network Level Authentication (NLA) for RDP sessions.
- Implement two-factor authentication (2FA) to prevent unauthorized access.
- Reset passwords and apply least privilege principles.
- Use EDR tools like CrowdStrike Falcon Insight for real-time monitoring and response.
Case Study 02: E-Commerce Web Server Compromise
- Client: Manufacturer
- Attack: Exploitation of a vulnerable e-commerce application led to arbitrary file uploads and web shells.
- Findings:
- Attackers uploaded six image files, three of which were unique and contained web shells.
- Malicious JavaScript was used to steal credit card data.
- Recommendations:
- Improve vulnerability patch management.
- Implement File Integrity Monitoring (FIM).
- Use EDR tools for real-time visibility.
- Rebuild compromised systems and reset passwords.
- Enable database logging for transactions and slow queries.
- Conduct regular penetration testing of web applications.
Case Study 03: Fileless POS System Compromise
- Client: Large retailer
- Attack: RAM-scraping malware was used to steal payment card data from POS systems.
- Findings:
- Attackers used PowerShell-based implants and spear phishing to maintain access.
- Data was copied and deleted from POS systems, making detection and recovery challenging.
- Recommendations:
- Implement end-to-end encryption for POS transactions.
- Ensure proper log archiving and use it for forensic analysis.
- Train staff to avoid spear phishing.
- Log full PowerShell commands and upgrade to PowerShell v5+ for enhanced auditing.
- Avoid reliance on traditional antivirus; instead, use EDR solutions to detect fileless attacks.
Case Study 04: NotPetya Supply Chain Attack
- Client: Company affected by the NotPetya malware in June 2017.
- Attack: Delivered via a supply chain attack, likely through a compromised software update.
- Findings:
- NotPetya was a Trojan that used self-propagation and network disruption.
- The attack was geopolitically motivated, targeting Ukrainian-based organizations.
- Recommendations:
- Deploy EDR platforms like Falcon Insight for real-time visibility.
- Implement strict network segmentation and containment protocols.
- Monitor for unusual network activity and ensure regular patching of systems.
Conclusion
This casebook underscores the critical need for organizations to move beyond traditional security measures and adopt more advanced, proactive strategies. It emphasizes the importance of endpoint detection and response (EDR), file integrity monitoring (FIM), and network-level authentication in mitigating the risks posed by sophisticated and evolving cyber threats. The recommendations provided are aimed at improving security resilience, attack detection, and response efficiency. By learning from these real-world examples, organizations can better prepare for and defend against future cyber intrusions.
试读结束,高清完整版pdf/doc/ppt,请点下载