HomeCyber SecuritySecurity: Defenders Must Reduce the Time for Attackers to Operate

Security: Defenders Must Reduce the Time for Attackers to Operate

Date:

Today, attackers enjoy unlimited time to operate. Their campaigns, which often exploit known vulnerabilities that organizations and end users may have-and should know about and address-can remain active and unnoticed for days, months or even longer.

Defenders, meanwhile, are striving to gain visibility into activity around threats and to reduce time to detection (TTD) for new and known threats. They are making great and clear progress, but still have a long way to go to truly weaken adversaries’ ability to lay the groundwork for attacks to counter them with high, cost-effective impact.

- Advertisement -

The bi-annual Cybersecurity Report 2022 Cybersecurity Report 2022 which presents research, insights and perspectives from security professionals on the trends covered in our security report while also examining developments that could affect the security landscape later this year. Our observation of recent developments within and from the informal economy confirms that adversaries have only become more focused on revenue generation. Ransomware has become a particularly effective profitable business, and business users appear to be the preferred target for some operators.

Many of the threat and security trends presented in this report relate to ransomware, from techniques used to launch campaigns and hide attacker activity to our expectations for how the next generation of this potent threat will evolve.

In this report, we look at the many ways organizations can and should take steps to begin improving their defenses.

The researchers’ recommendations are as follows:

- Advertisement -

– Institute and test an incident response plan that enables a rapid return to normal business operations following a ransomware attack.
– Not relying blindly on HTTPS connections and SSL certificates
– Move quickly to fix published vulnerabilities in software and systems, including routers and switches that are components of the critical Internet infrastructure
– Educating users about the threat of malicious browser infections
– Understanding what actionable threat intelligence really is

In this report, we cover four main topics:

Ransomware

I. Top Story on Cybercrime Trends: Ransomware

Security researchers have turned their sights on ransomware by examining innovations that may make this specific type of malware attack much more prevalent. We also provide predictions on the evolution of ransomware, based on past trends observed. In addition, we analyze how vulnerabilities in unpatched systems and outdated devices give criminals time to operate. Ransomware operators are now targeting business users. This is why organizations must ensure that they back up critical data to a protected location and establish actionable plans that allow them to resume normal business operations as quickly as possible after an attack.

II. Time to operate

This section examines client-side attack vectors that provide adversaries with time and opportunity to innovate threats and conduct their campaigns. The increase in vulnerabilities related to encryption and authorization indicates that threat actors are now attempting to manipulate secure connections. Trends in attack kits and vectors are discussed, such as the attractiveness of server attacks for online criminals seeking access to larger data sets. The emergence of “malvertising-as-a-service” and the complications it creates for defenders is also discussed, as are the questions that arise about who should protect web users.

III. Time to secure

In this section, security researchers explore the gap between attacker activity and security solutions. For example, while vendors have shortened the time between the announcement of public vulnerabilities and the availability of patches, users have lagged in implementing such patches. This section also includes an update on Cisco’s ongoing efforts to reduce mean time to detection (TTD) and the impact of the ongoing “arms race” between attackers and defenders. Cisco researchers also detail the increasing use of HTTPS in malicious campaigns and the use of the Transport Layer Security (TLS) protocol by criminals to encrypt communications.

IV. Global Perspective and Security Recommendations

This section examines current geopolitical trends related to security, including growing government concerns about the challenges of keeping pace with technological change to understand threats and control or access data. Recommendations are also offered for defenders to reduce the time to operate for adversaries. In addition, the key difference between indicators of compromise (IOCs) and threat intelligence is explained.

Key findings

– Ransomware is dominating the malware market. While not a new threat, it has evolved to become the most profitable type of malware in history, and enterprises are now becoming the target of choice for some ransomware operators. In the first half of 2016, ransomware campaigns targeting individuals and business users became more widespread and effective. On the horizon: faster and more efficient propagation methods that maximize the impact of ransomware campaigns and an increased likelihood of generating significant revenue from adversaries.

– Attack kits, which have helped ransomware become such a notable threat, continue to exploit Adobe Flash vulnerabilities. In Cisco researchers’ recent analysis of the popular Nuclear attack kit, for example, Flash accounted for 80% of successful attack attempts.

– Vulnerabilities in JBoss enterprise application software provide attackers with a new vector they can use to launch campaigns such as ransomware. Cisco research shows that JBoss-related risks made significant inroads inside servers, leaving them vulnerable to attack.

– From September 2021 to March 2022, security researchers observed a five-fold increase in HTTPS traffic related to malicious activity. The increase in this type of web traffic can largely be attributed to malicious ad injectors and adware. Threat actors are increasing their use of encrypted HTTPS traffic to hide their web activity and extend their time to operate.

– While patches are available from major software vendors at about the same time vulnerabilities are announced, many users are still failing to download and install them in a timely manner, according to Cisco research. The gap between the availability and actual deployment of such patches gives attackers ample time to launch attacks.

– To direct attention to the security risks organizations create by failing to properly maintain their aging infrastructure or patch vulnerable operating systems, the researchers analyzed a sample set of devices to determine the age of known vulnerabilities running on critical infrastructure. We found that 23% of those devices had vulnerabilities since 2016and nearly 16% had vulnerabilities that were first published in 2013.

– A small but growing number of malware samples point to criminals using the Transport Layer Security (TLS) protocol, which allows network traffic to be encrypted, to hide their activities. This is a cause for concern among security professionals, as it renders detailed packet inspection ineffective as a security tool. The combination of machine learning methods and new data visualizations provides insights into this higher quality trend.

– For the period December 2020 to April 2021, the average TTD was reduced to about 13 hours, well below the current and unacceptable industry estimate of 100 to 200 days. The increases and decreases in TTD observed during this period highlight an ongoing heated “arms race” between attackers and defenders, with adversaries unleashing a constant barrage of new threats that require security vendors to move quickly to identify them.

- Advertisement -

Related articles:

Boost Your Career: Top 5 Computer Security Courses for Aspiring Cybersecurity Professionals

Discover the top 5 computer security courses to kickstart your cybersecurity career. Learn essential skills and gain certifications to protect digital assets.

Securing the Cloud: Best Practices for Cybersecurity in Cloud Computing Environments

Discover essential cybersecurity practices for cloud computing environments. We explore how to safeguard your data and infrastructure in the ever-evolving digital landscape.

Learning Through Play: 7 Cybersecurity Games That Sharpen Your Hacking Defense Skills

Discover 7 engaging cybersecurity games that make learning fun while boosting your hacking defense skills. We explore how these cyber security games sharpen your expertise.

The Backbone of Cybersecurity: A Deep Dive into Modern Network Security Practices

Discover how network security in cyber security protects organizations from threats. Learn about firewalls, encryption, and best practices for safeguarding digital assets.

5 Critical IT Security Threats You Can’t Afford to Ignore

Discover the top 5 IT security threats that could put your business at risk. Learn how to protect your data and systems from these critical vulnerabilities.

12 COMMENTS

    • I’m glad you found this article eye-opening, but reducing attackers’ operating time is just the tip of the iceberg when it comes to security. There are numerous other factors to consider as well. Keep digging deeper! #SecurityMatters

    • Are you serious? Hot sauce in cybersecurity? That’s one of the most ridiculous things I’ve ever heard. Stick to the facts and stop wasting everyone’s time with these silly ideas.

  1. “Wow, this article really hits home! Time is money, especially when it comes to cyber attacks. Let’s shave off those attacker operating hours!”

    • Are you serious? Shaving off attacker operating hours won’t magically solve cyber attacks. It’s a complex issue that requires a comprehensive approach. Time may be valuable, but it’s not the only factor at play here. Let’s focus on real solutions instead of oversimplifying.

  2. Wow, this article really opened my eyes to the importance of reducing attacker time! #CybersecurityIsSeriousBusiness

    • I couldn’t agree more! Cybersecurity is no joke and we all need to be more vigilant. It’s scary how easily attackers can exploit vulnerabilities. Let’s stay informed and take action to protect ourselves and our data. Thanks for sharing this eye-opening article!

    • Interesting perspective, but reducing attackers’ time is just one piece of the puzzle. We also need to focus on proactive measures like regular security audits and employee training. Let’s aim for a comprehensive approach to keep our data safe. #SecurityMatters

  3. “Hey guys, after reading this article, I can’t help but wonder – is reducing attackers’ time to operate really feasible? 🤔”

    • I understand your skepticism, but reducing attackers’ time to operate is crucial in minimizing the damage they can cause. It may not be easy, but it is definitely feasible with the right strategies and technologies in place. Let’s focus on solutions rather than doubts. 💪🔒

LEAVE A REPLY

Please enter your comment!
Please enter your name here