Organisations will have to face the Industrialisation of Hacking Organisations will have to face the Industrialisation of Hacking - RSS feed from Security Park
(08/12/2009)

Imperva has predicted five key security trends to watch for over the next ten years:

1. The Industrialisation of Hacking

There is a clear definition of roles within the hacking community developing, forming a supply chain that starkly resembles that of drug cartels:
­ Botnet growers / cultivators whose sole concern is maintaining and increasing botnet communities
­ Attackers who purchase botnets for attacks aimed at extracting sensitive information (or other more specialized tasks)
­ Cyber criminals who acquire sensitive information for the sole purpose of committing fraudulent transactions

As with any industrialisation process, automation is the key factor for success. Indeed we see more and more automated tools being used at all stages of the hacking process. Proactive search for potential victims relies today on search engine bots rather than random scanning of the network. Massive attack campaigns rely on zombies sending a predefined set of attack vectors to a list of designated victims. Attack coordination is done through servers that host a list of commands and targets. SQL Injection attacks, “Remote File Include” and other application level attacks, once considered the cutting edge techniques manually applied by savvy hackers are now bundled into software tools available for download and use by the new breed of industrial hackers. Search engines (like Google) are becoming an increasingly vital piece in every attack campaign starting from the search for potential victims, the promotion of infected pages and even as a vehicle for launching the attack vectors themselves.

Attack campaigns are constantly launched not only against high profile applications but rather against any available target. An application may be attacked for the value of the information it stores or for the purpose of turning it into yet another attack platform. Protecting web applications using application level security solutions will become a must for larger and smaller organisations alike. End users who want to protect their own personal data and avoid becoming part of a botnet must learn to rely on automatic OS updates and anti-malware software.

2: A Move from Application to Data Security

The effectiveness of network layer attacks has decreased dramatically in this past decade largely due better network layer defences. This gave raise to application level attacks such as SQL Injection, Cross Site Scripting and Cross Site Request Forgery. As these are being gradually addressed by the use of web application firewalls, attackers will turn their attention to more sophisticated attacks either from the outside (business logic attacks) or from the inside (direct attacks against the database). Together with the fast growth in the number of applications that access enterprise data pools these will drive the evolution of data-centric security.

While organisations invest in protecting their major applications using application level tools, many of the smaller applications are still unprotected. Additionally, we see no apparent decrease on the part of internal threats. Disgruntled employees, dubious individuals with internal network access and attackers who control (through Trojans) internal workstations all present a direct threat on enterprise data pools.

It becomes apparent to organisations that controls must be put not only around applications accessing the data but also around the data itself. This holds true to data in its structured format within relational databases as well as unstructured data stored in files on organisational file servers.

To protect these vital assets, Organisations must have a complete change of mindset focusing on protecting data at its source, regardless of the application accessing it, if necessary utilising a combination of technologies such as a data based firewall, data and file activity monitoring and the next generation of DLP products.

3: Mainstream Social Networks and Associated Applications

Previously attracting student communities, the growing popularity of social networking sites, such as Facebook, Twitter and LinkedIn is fast infiltrating mainstream populations with practically every man, and his dog, now ‘on Facebook’. As a consequence, large populations not previously exposed to online attackers can now be targeted by massive campaigns. Elderly people as well as younger children, people who did not grow up with an inherent distrust in web content may find it very difficult to distinguish between messages of true social nature and widespread attack campaigns. Attackers will also take advantage of the social networking information made accessible by social platforms to create more credible campaigns (e.g. make sure you get your Phishing email from your grandchildren). The capabilities offered by the social platform and their growing outreach into other applications (webmail, online games) allow attacker to launch huge campaigns with a viral nature and at the same time pinpoint specific individuals.

Imperva’s team was able to demonstrate that specific ads carrying attack vectors could be presented to named individuals at an attacker’s will. This in turn allows attackers to easily get their foothold inside specific organisations by targeting individuals within those organisations. Much like searching through the Google search engine for potentials target applications, attackers will scan social networks (using automated tools) for susceptible individuals, further increasing the effectiveness of their attack campaigns.

4. Password grabbing/password stealing attacks

Recent statistics show a surge in personal information leakage incidents as well as the compromise of huge amounts of credit card numbers. Leakage incidents were attributed to either media loss (or theft) or deliberate attacks such as SQL injection or sniffing on internal transaction processing networks.

As stolen personal information is increasingly available, the price it commands on the black market is falling, thereby forcing attackers to seek more profitable data. To this extent, the last few months has seen hackers target application credentials. Application credentials hold more value for certain types of attackers as they can be further used in automated schemes. While fraud schemes involving stolen personally identifiable information (PII) usually require manual procedures, an attack that makes use of valid credentials for an online banking system can be fully automated.

Attackers use many different techniques for obtaining application credentials these include Phishing campaigns, Trojans and KeyLoggers on the consumer side and SQL injection, directory traversal and sniffers on the application end.

5: Transition from Reactive To Proactive Security

To date the security concept has been largely reactive - waiting for a vulnerability to be disclosed; creating a signature (or some other security rule) then cross referencing requests against these attack methods, regardless of their context in time or source. As a consequence a lot of resources are invested in distinguishing “bad” requests from “good” requests based on request content alone – a chore that is becoming more and more difficult due to advanced evasion techniques and sophisticated attack schemes. This in turn yields solutions that are forced to make difficult trade-offs between the rates of false detection and no detection.

Rather than waiting to be attacked, security teams must start to proactively look for attacker activity as it is being initialised over the network, identifying dangerous sources or malicious activity before it gets to attack a protected server.

Related topics:  Application and software security   Authentication and identity management   Computer and PC Security   Data management and data security   Hacking and intrusion prevention   Knowledgebase   Security management and policies   Security threats and vulnerabilities   Virus, Worm, Email security, spyware and malware 


print versionPrint version | email this to a friendEmail to a friend | related articlesRelated articles


Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.


Other Security news and resources


Security News Suppliers Directory Jobs forum Classifieds Knowledge base White papers Research library Security books Special reports Security interviews Security companies Security events Security links Security market

Product channels

Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products

IT Security white papers and research library

Access Control  Authentication  Data Management  Data Security  Digital Signatures  Email Security  Identity Management  Internet Security  Intrusion Prevention  Network Security  Remote access security  Security Management  Security Policies  Security Software  Security Threats  Virus Detection Software  Virus Protection  VPN  Vulnerability Assessment  Wireless Security 

Security books, guides, standards and toolkits

RFID and Smart Cards books, guides and reference documents  Biometric books, guides and reference documents  CCTV books, guides and reference documents  Intruder alarms and intrusion detection systems books, guides and reference documents  Monitoring and surveillance books, guides and reference documents  IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits  Fire, Health & Safety books, guides and reference documents





Ensure that you conduct an effective information security risk assessment that is in line with ISO 27001 by purchasing vsRisk™ Risk Assessment Tool

Need a
Security reference book?
Find it on Amazon
Security books

Article search

Directory search


add your company
Google

ISO 18028 (Network Security Management)
Home | About | Contact | Submit article | Advertise | Newsletter | RSS | Search