Verizon-2020年数据泄露调查报告(英文)-2020.8-119页_6mb
报告摘要
Data Breach Investigations Report Summary (2020)
Core Content
The 2020 Data Breach Investigations Report (DBIR) presents a comprehensive analysis of 157,525 security incidents, with 32,002 meeting quality standards and 3,950 confirmed as data breaches. The report highlights global trends in cyber threats, focusing on the actors, actions, and industries involved in breaches, and provides actionable insights for improving cybersecurity.
Main Findings
Breach Overview
- Total Breaches: 3,950 breaches were identified, with each square in the report representing roughly one breach.
- Data Coverage: The report's data is extensive and includes breaches from 16 industries and four world regions.
- Global Perspective: The report introduces a regional analysis, offering a broader view of global data breach trends.
Threat Actors
- External vs. Internal: External attackers are more common than internal ones, though internal actors are increasing in number.
- Primary Motives: Financially motivated breaches are the most common, followed by Espionage, with Fun, Ideology, and Grudge being less prevalent.
- Organized Crime: Organized criminal groups were responsible for 55% of breaches, making them the most frequent threat actors.
- Internal Actors: 30% of breaches involved internal actors, with 4% having four or more attacker actions.
- Partner and Multiple Parties: 1% of breaches involved Partner actors, and 1% featured multiple parties.
Threat Actions
- Most Common Actions: Phishing, Use of stolen credentials, and Misconfiguration are the top threat actions in breaches.
- Error as a Major Factor: Error actions have become increasingly common, now matching the frequency of Social breaches and surpassing Malware.
- Malware Trends: Malware is still a significant factor, with 27% of Malware incidents being Ransomware. Password dumper is the most common Malware variety in breaches, followed by Email and Direct install.
- Ransomware: Ransomware is the third most common Malware breach variety and the second most common Malware incident variety.
Incident Classification
- Incident vs. Breach: An incident is a security event that compromises an asset, while a breach is a confirmed data disclosure to an unauthorized party.
- Secondary Motives: Secondary motives (e.g., using compromised infrastructure as a stepping stone) are also significant, though not as common as primary motives.
Industry Analysis
The report includes an in-depth analysis of 16 industries:
- Financial and Insurance (NAICS 52): The most affected industry, with 72% of breaches involving large businesses.
- Healthcare (NAICS 62): A significant portion of breaches involve Personal data, with 58% of victims having their Personal data compromised.
- Retail (NAICS 44-45): 28% of breaches involved small businesses, and the report notes a trend in decreasing RAM-scaper malware.
- Other Industries: Includes Construction, Education, Information, Manufacturing, etc., each with their own breach patterns.
Regional Analysis
- Northern America (NA): The most frequently reported region.
- Europe, Middle East, and Africa (EMEA): A growing focus in the report.
- Asia-Pacific (APAC): Increasing in relevance.
- Latin America and the Caribbean (LAC): Also gaining attention in the report.
Key Trends and Insights
- Decreasing Malware Use: Malware is becoming less common in breaches, possibly due to the increased use of credential theft in phishing and social engineering attacks.
- Rise in Error Actions: Error actions, particularly Misconfiguration, are on the rise and are now a major category.
- Geographic Proximity: Most attacks originate from the same country, state, or city as the victim, suggesting local or regional threat actors.
- Surveillance and Reporting: Breach disclosure is becoming more normalized, leading to more reported errors and increasing the visibility of these incidents.
Methodology and Tools
- VERIS Framework: Used to classify and analyze incidents and breaches. It includes categories like Threat Actors, Threat Actions, and Threat Action Varieties.
- Survivorship Bias: The report acknowledges that some data is skewed due to the nature of incident reporting, where only breaches that occurred are recorded, not those that were blocked.
- Data Sources: Data is collected from various sources, including Verizon Threat Research Advisory Center (VTRAC), external collaborators, and public breaches.
Recommendations and Next Steps
- CIS Controls: The report emphasizes the importance of aligning with the Center for Internet Security (CIS) Critical Security Controls.
- Mitigation Strategies: Focus on reducing Error and Misconfiguration vulnerabilities, as well as improving credential protection.
- Contributor Involvement: The report encourages more organizations to become data contributors to enhance the accuracy and comprehensiveness of future reports.
Appendices
- Appendix A: Details the methodology used in the report.
- Appendix B: Explains the VERIS Common Attack Framework (VCAF).
- Appendix C: Discusses the importance of tracking financial flows to identify and apprehend cybercriminals.
- Appendix D: Highlights how the State of Idaho improved its incident response using VERIS.
- Appendix E: Lists contributing organizations from 81 countries.
Conclusion
The 2020 DBIR underscores the evolving nature of cyber threats, emphasizing the need for a data-driven approach to cybersecurity. It highlights the dominance of organized crime, the rise of Error actions, and the shifting focus from Malware to credential-based attacks. The report serves as a critical resource for understanding and mitigating data breaches across industries and regions.
试读结束,高清完整版pdf/doc/ppt,请点下载