2017年数据泄露调查报告(英文版)_74页_2mb
报告摘要
2017 Data Breach Investigations Report Summary
Core Content
The 2017 Data Breach Investigations Report (DBIR) is the 10th edition of the annual report that analyzes data breaches and provides insights into the evolving landscape of cybersecurity threats. It emphasizes the importance of understanding the trends, patterns, and industry-specific vulnerabilities that contribute to data breaches.
Main Points
-
Breach Trends:
- The percentage of breaches involving external actors decreased, while internal actors increased slightly.
- Financial and espionage motives remained the top two, accounting for 93% of breaches.
- The report notes that ransomware is not always reflected in breach statistics due to the lack of confirmed data disclosure.
- Breaches involving multiple actors or business partners are less frequent but still exist.
- Breach discovery methods have shifted, with employee notifications being the most common internal method.
-
Breach Timeline:
- Most breaches are discovered within minutes or hours, but some take months to detect.
- The time-to-compromise is typically seconds or minutes, and the time-to-exfiltration is often days.
- The report cautions against using "Detection Deficit" metrics, as they may not be meaningful when comparing time-to-compromise and time-to-discovery.
-
Industry Focus:
- This year's report includes industry-specific sections to better understand how different sectors are targeted and how breaches occur.
- The Information industry has the highest number of breaches, while Education has the lowest.
- The Accommodation and Food Services industry is particularly vulnerable to Point of Sale (POS) intrusions, with 96% of breaches involving external actors, and 96% of the data compromised being payment information.
-
Threat Vectors:
- Phishing remains a significant threat vector, with email being the primary method of delivering malware.
- Malware is prevalent, with RAM scrapers, C2 (Command and Control), and keyloggers being the most common types.
- Physical theft and loss and miscellaneous errors are also common causes of breaches, though they are less frequent compared to other vectors.
-
Patching and Vulnerability Management:
- The report includes patch cycle analysis, highlighting that some industries patch vulnerabilities more quickly than others.
- "Leftover" vulnerabilities are those that remain unaddressed after a patch cycle, and the report provides a breakdown of these across industries.
- The Information industry has the most active patching, while Education has the most "leftovers."
Key Information
- The DBIR has grown to include 65 contributing organizations, providing a broader and more diverse dataset.
- The report introduces nine incident classification patterns to better categorize and understand breach types.
- Ransomware is a growing concern, though it is not always captured in breach statistics due to lack of confirmed data disclosure.
- Data types such as personal information and credentials are frequently compromised, often in large volumes.
- DDoS attacks are more common in industries that rely heavily on internet presence.
- Patching efficiency is a critical factor in reducing vulnerabilities, and the report encourages organizations to evaluate their own patching timelines and address "leftover" vulnerabilities.
Industry-Specific Findings
Accommodation and Food Services
- 96% of breaches are external, with 96% involving payment data.
- Point of Sale Intrusions, Everything Else, and Privilege Misuse are the top patterns.
- Malware is the most common threat action, often involving RAM scrapers, C2, and keyloggers.
- Brute force attacks and desktop sharing are also used in hacking incidents.
Conclusion
The DBIR serves as a valuable tool for information security professionals to understand the current threat landscape and improve their organization's security posture. While the report acknowledges the persistent nature of cyber threats, it also offers hope that with better awareness and proactive measures, the security community can make meaningful progress. The industry-specific analysis and tactics section provide actionable insights to help organizations better prepare for and respond to breaches.
试读结束,高清完整版pdf/doc/ppt,请点下载