CPR-网络安全报告2020(英文)-2020.8-80页_14mb
报告摘要
2020 Cyber Security Annual Report Summary
Executive Summary
This 2020 Cyber Security Annual Report by Check Point Research (CPR) provides an analysis of 2019's major cyber incidents, outlines key predictions for 2020, and offers best practices for preventing future attacks. The report emphasizes the growing sophistication of cyber threats, the need for a proactive and preventive approach, and the importance of adapting to the evolving technological landscape. The global threat environment has become more complex, with cybercriminals exploiting new attack vectors and targeting critical infrastructure, including IoT devices, cloud services, and mobile platforms.
Key 2019 Cyber Events
- January 2019: Over 770 million email addresses and 21 million unique passwords were exposed in a data breach on MEGA, later revealed as part of a larger 1TB data leak.
- January 2019: Airbus faced a data breach exposing employee personal data.
- February 2019: 127 million account details were leaked from 8 additional hacked websites.
- March 2019: 620 million account details were stolen from 16 hacked websites.
- April 2019: Over 106 million credit card applicants' data was exposed in a Capital One breach.
- April 2019: A massive data leak involving over 500 million Facebook user records was discovered.
- April 2019: Over 100 million JustDial users' personal data was exposed.
- May 2019: The FBI acknowledged that businesses may need to evaluate ransom payment options due to the severity of ransomware attacks.
- June 2019: Lake City, Florida, paid $500,000 after a ransomware attack disrupted its systems for two weeks.
- July 2019: Nearly one million New Zealand residents' medical data was exposed.
- August 2019: UniCredit, an Italian bank, suffered a data breach affecting 3 million customers.
- October 2019: New Orleans mayor declared a state of emergency due to a cyber attack disrupting city services.
2020 Vision: Cyber Security Predictions
- Targeted Ransomware: Cybercriminals are increasingly focusing on specific industries and organizations, conducting extensive reconnaissance before launching attacks. This trend is expected to continue and become more damaging.
- Phishing Beyond Email: Phishing attacks are now extending to SMS and social media platforms, making them more sophisticated and effective.
- Mobile Malware Attacks: Mobile banking malware attacks have surged, with new versions being widely distributed for profit. Phishing techniques are becoming more advanced, targeting mobile users.
- More IoT Devices, More Risks: The rise of 5G will accelerate the adoption of IoT devices, increasing the attack surface. These devices are often unsecured and pose significant risks.
- Data Volumes Skyrocket with 5G: The increased connectivity brought by 5G will result in a massive influx of data, requiring stronger security measures to protect against breaches.
- AI Will Accelerate Security Responses: AI is set to play a key role in identifying and responding to new threats faster. However, it also presents new challenges as cybercriminals may exploit AI for their own purposes.
- Security at DevOps Speed: Security solutions must evolve to match the speed and agility of DevOps, with flexible and resilient cloud-based architectures.
- Rethinking Cloud Approaches: Organizations are moving toward hybrid cloud environments due to increased exposure from public cloud outages and security risks. Cloud security controls are often lagging behind development speed.
2019 Cyber Security Trends
- Shifting Attacks to Supply Chain Targets: Threat actors are targeting trusted service providers and business partners as a means to access primary targets. Examples include the ShadowHammer and Operation Sheep attacks.
- Magecart Becomes an Epidemic: Magecart attacks, involving malicious JavaScript code injection, have become widespread, targeting e-commerce platforms and stealing payment information.
- Attacks Against Cloud Environments: Cloud misconfigurations remain the primary cause of cloud-based breaches, but attacks are also increasing against cloud service providers.
- Evolving Mobile Landscape: The mobile threat landscape has matured, with more malware and vulnerabilities being exploited.
- Targeted Ransomware: Ransomware attacks have become more targeted and sophisticated, affecting industries like healthcare and government.
- Reemergence of Exploit Kits: Exploit kits have seen a resurgence, allowing attackers to exploit known vulnerabilities in a more automated and scalable way.
Global Malware Statistics
- Cyberattack Categories by Region: Different regions face unique types of cyber threats based on their infrastructure and digital usage.
- Global Threat Index Map: Highlights areas with the highest cyber threat exposure.
- Top Malicious File Types: Web-based attacks are increasing, with JavaScript skimmers being a major threat to e-commerce.
- Top Malware Families: Includes ransomware, phishing malware, and mobile banking malware.
- Global Analysis of Top Malware: Focuses on the spread and impact of major malware families, including Magecart and Sodinokibi.
High-Profile Global Vulnerabilities
- Microsoft RDP Vulnerabilities: BlueKeep and DejaBlue (CVE-2019-0708, CVE-2019-1182) posed a significant risk to systems running Windows.
- Oracle WebLogic Server Vulnerabilities: Exploitable vulnerabilities (CVE-2017-10271, CVE-2019-2725) allowed attackers to execute remote code.
- Exim Mail Server Remote Code Execution Vulnerability (CVE-2019-10149): Enabled attackers to gain control over mail servers.
Recommendations to Prevent Cyber Attacks
- Choose Prevention Over Detection: Proactive security measures are more effective than reactive ones.
- Leverage a Complete Unified Architecture: A unified security approach can help detect and respond to threats more effectively.
- Keep Threat Intelligence Up to Date: Staying informed about the latest threats is crucial for maintaining a secure environment.
Zero Trust Networks: Best Practices
- Implement Zero Trust Architecture: Assume that all users and devices are untrusted until verified.
- Continuous Monitoring and Verification: Ensure that every access request is authenticated and authorized.
- Micro-segmentation: Limit access to sensitive systems by isolating them within a network.
- Encryption and Secure Communication: Protect data in transit and at rest.
- Regular Audits and Updates: Keep systems and software up to date to reduce vulnerabilities.
Appendix: Malware Family Descriptions
- Ransomware: Encrypts data and demands payment for decryption.
- Phishing Malware: Steals login credentials and sensitive information through deceptive tactics.
- Mobile Banking Malware: Targets mobile devices to steal payment information.
- Magecart: Involves injecting malicious JavaScript code into e-commerce sites to steal payment data.
- Exploit Kits: Automated tools used to exploit known vulnerabilities.
Conclusion
The 2020 Cyber Security Annual Report highlights the increasing complexity and severity of cyber threats. Organizations must adopt a proactive, prevention-focused strategy, utilizing advanced threat intelligence and modern security architectures. With the rise of 5G, IoT, and cloud computing, the need for robust, flexible, and intelligent security solutions has never been greater. By staying informed and implementing best practices, businesses can better protect themselves against the ever-evolving cyber landscape.
试读结束,高清完整版pdf/doc/ppt,请点下载