会员中心     
首页 > 资料专栏 > IT > 互联网 > 互联网 > 2022年互联网现状报告PDF

2022年互联网现状报告PDF

陪你一生
V 实名认证
内容提供者
热门搜索
互联网 互联网报告
资料大小:10740KB(压缩后)
文档格式:PDF
资料语言:中文版/英文版/日文版
解压密码:m448
更新时间:2023/6/20(发布于山东)

类型:金牌资料
积分:--
推荐:免费申请

   点此下载 ==>> 点击下载文档


“2022年互联网现状报告PDF”第1页图片 “2022年互联网现状报告PDF”第2页图片 图片预览结束,如需查阅完整内容,请下载文档!
文本描述
Volume8,Issue3
[StateoftheInternet]
Enemyat
theGates
AnalyzingAttacksonFinancialServicesTableofcontents
2Introduction
4Thethreatlandscape
6Growingsecurityrisk
14Dangersposedbynewlydisclosedvulnerabilities
18DDoSattacks
22Financialservicescustomersinthecrosshairs
26Phishingtrends
30Theroadtomalware
32Summary
33Credits
EnemyattheGates:Volume8,Issue3SOTI1Introduction
Financialservicesisamongtheindustriesthathavebeentheheaviesthitby
cybercrime—fromtheheydayoftheZeusandotherbankingtrojanstoDistributed
Denial-of-Service(DDoS)attacks,modernphishingattacks,andransomware.FinServ
isavitalsectorthatplaysamajorrolenotonlyinthelivesofpeople,butalsointhe
globaleconomy.Anydisruptionordowntimeoffinancialservicescarriesserious
implications,andthesensitivedatatheseorganizationsholdcanbeturnedintoa
valuablecommodity.Attackers,therefore,seeFinServasalucrativetargetandlevya
widerangeofattacksagainstthem,fromnewlydiscoveredzero-dayvulnerabilitiesto
tried-and-truephishingattacks.
It’snosecret,then,thatattackersarehighlyfocusedandmotivatedtoattackthe
FinServindustry.Traditionally,theFinancialServicesStateoftheInternet(SOTI)report
haspickedatopiclikephishingorfraud,butthistimewehavetakenamuchbroader
approachandcoveranumberofissuesaffectingthisoftenattackedindustry.
Thisbroaderlenshasallowedustoseetheimmensesurgeinthenumberofattackson
thefinancialservicesindustry,andthealarmingspeedatwhichattackersareleveraging
newlydiscoveredzero-dayvulnerabilities.CustomersofFinServaren’tsparedeither,with
alargeportionofattackerschoosingtoforgoattacksononeofthemostsecure
industriesintheworld,andinsteadattacktheirconsumersenmasse.Withthisenemy
standingatthegate,itisimportantforFinServsecurityprofessionalstounderstandhow
thethreatlandscapeisshifting.Ourreportincludesthesekeypoints:
EnemyattheGates:Volume8,Issue3SOTI2TL;DR
ThefinancialservicesindustryAsignificantincreaseinLocalFile
consistentlyranksinthetopthreeInclusion(LFI)andCross-SiteScripting
targetedverticalsforwebapplication(XSS)attacksdemonstrateshow
andAPI,zero-day,andDDoSattacks.attackersareshiftingtowardremote
codeexecution(RCE)attemptsthat
FinServshoweda3.5xsurgeinwebpresentalargerstrainontheinternal
applicationandAPIattacksyearoveryear,securitynetwork.
thehighestgrowthofanymajorindustry.
AbuseofFinServcustomersisrampant,
Within24hours,theexploitationofwithmorethan80%ofFinServattackers
newlydiscoveredzero-dayvulnerabilitiesfocusingoncustomeraccountsrather
againstFinServcanreachmultiplethantheorganizationsthemselves,either
thousandsofattacksperhouranddirectlyorviaphishing-relatedactivities.
peakquickly,affordinglittletimeto
patchandreact.Phishingcampaigns(likeKr3pto)are
introducingtechniquesthatbypass
two-factorauthentication(2FA)
solutionsusingone-timepassword
tokensorpushnotifications.
EnemyattheGates:Volume8,Issue3SOTI3Thethreatlandscape:
attacksonfinancialservicesgrow
Thefinancialservicesverticalcontinuestobeoneofthemostwidelyattackedindustries
intheworld,andthenumberofattacksshowssignsofgrowing.WebapplicationandAPI
attacks,inparticular,areincreasingatanalarmingratewhilealsogrowingincomplexity.
Attackersareseekingtogainafootholdtointernalnetworksandcausedisruptionasa
meansofpressuringorganizationstopaymoneytopreventfurtherdamages.Asavital
sector,financialservicesneedtobeupandrunning.Attackerscouldalsomonetizestolen
sensitiveinformationorgainaccesstocustomer’saccountsandstealtheirmoney.
Cybercriminalshavesettheirsightsonfinancialservicesanditscustomers,andassuch,
we’veseenthisverticalheightenitscybersecurityawarenessandincreaseitsITbudget
forcybersecurity.Failuretosafeguardtheirperimeteranddatacouldresultinbreaches
byransomwareandotherthreats,andconsequently,significantcriticaldataandfinancial
losses.AccordingtoIBM’sCostofaDataBreach2022report,databreachesagainst
financialservices,whichisconsidered“criticalinfrastructure,”hasanaveragecostof
US$5.97million.
EnemyattheGates:Volume8,Issue3SOTI4