2021上半年物联网安全报告(英)-39页_5mb
报告摘要
OT/IoT Security Report Summary
Core Content
This report provides insights into the growing threat of ransomware and IoT vulnerabilities in operational technology (OT) and industrial control systems (ICS) environments. It emphasizes the need for proactive security measures and outlines actionable recommendations to mitigate these risks.
Main Points
Ransomware Insights
- Ransomware Trends: Ransomware attacks have significantly increased in frequency and impact over the past few years. Between 2018 and 2020, attacks on industrial organizations rose by 500%, and in 2021, there was an 116% increase in attacks just between January and May.
- Colonial Pipeline Attack: A notable ransomware attack on Colonial Pipeline, attributed to the DarkSide group, led to a 6-day gas shortage on the U.S. East Coast. Although the OT network was not directly breached, the attack disrupted operations.
- REvil Ransomware: REvil, also known as Sodinokibi, is a RaaS operator that has been particularly active. It has executed high-profile attacks on JBS Foods, Acer, and Quanta, with ransom demands reaching $50 million or more.
- RaaS Ecosystem: Ransomware as a Service (RaaS) operates like a cartel, with various players collaborating to execute attacks. This model allows for the distribution of roles and responsibilities among different actors, increasing the efficiency and impact of ransomware attacks.
- Ryuk Ransomware: Ryuk is known for its fast attack execution, sometimes within hours of infection. It has targeted healthcare facilities, which are under pressure due to the pandemic, and has collected over $150 million in ransoms.
- Paying Ransoms: 80% of organizations who pay ransoms experience another attack, and only 8% fully recover their data. On average, those who pay recover 65% of encrypted files, with 29% recovering less than half.
Vulnerability Analysis
- ICS-CERT Vulnerabilities: The number of vulnerabilities published by ICS-CERT increased by 44% in the first half of 2021 compared to the second half of 2020. The number of products affected rose by 19%.
- Critical Manufacturing: Vulnerabilities solely affecting the Critical Manufacturing sector increased by 148%, indicating a growing risk for this industry.
- Vulnerability Trends: The top three industries affected by ICS-CERT vulnerabilities are Critical Manufacturing, Energy, and Multiple Industries.
IoT Security Camera Vulnerabilities
- IoT Growth: The global video surveillance market is expected to grow from $45.5 billion in 2020 to $74.6 billion by 2025, with the infrastructure sector growing the fastest.
- P2P Vulnerabilities: Nozomi Networks Labs discovered and disclosed three vulnerabilities in IoT security cameras that use Peer-to-Peer (P2P) functionality, allowing attackers to access cleartext A/V streams and local user lists.
- Verkada Cyberattack: In March 2021, a public cyberattack on Verkada exposed the live video feeds of 150,000 security cameras. The attack used an internet-exposed support server to gain access to privileged credentials and A/V streams.
- IoT Risks: IoT devices are often insecure-by-design, and organizations must carefully evaluate vendors and technology when selecting such devices. The report highlights the importance of due diligence and security measures for IoT devices.
Key Recommendations
- Malware Infection Prevention: Implement spear-phishing protection, security awareness training, and multi-factor authentication to reduce the likelihood of initial access.
- OT Network Monitoring: Continuously monitor networks for intrusions and ensure rapid mitigation of vulnerabilities. Early detection allows for quick containment and response.
- Network Segmentation: Segment IT and OT networks using firewall rules that align with the IEC 62443 standard to prevent lateral movement of ransomware.
- Threat Intelligence: Use up-to-date threat intelligence with Indicators of Compromise (IoCs) to detect and respond to ransomware and other threats.
- Secure Remote Access: Ensure secure remote access protocols are in place to prevent unauthorized access to critical systems.
- Post-Breach Mindset: Develop detailed failure plans for IT disruptions that could impact OT, including operational continuity and disaster recovery components.
- Disaster Recovery Planning: Create and maintain robust disaster recovery plans to ensure quick recovery and minimal downtime in the event of an attack.
- Attack Surface Reduction: Minimize the attack surface by eliminating unnecessary services and devices.
- IoT Vendor and Device Selection: Choose secure IoT devices and vendors, ensuring they adhere to cybersecurity standards and data privacy.
- IoT Network Monitoring: Monitor IoT networks to detect and respond to threats in a timely manner.
Conclusions
- Ransomware and IoT vulnerabilities are severe threats to operational systems and critical infrastructure.
- The RaaS model has proven to be highly effective and profitable, allowing groups to operate with divided responsibilities.
- Organizations must adopt a proactive and reactive approach to cybersecurity, including monitoring, segmentation, and disaster recovery planning.
- The security of IoT devices is a critical concern, and due diligence must be performed when selecting such devices.
- The report encourages continuous improvement of IT/OT security posture to ensure availability, safety, and confidentiality of operational systems.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载