2017年度企业信息系统安全评估(英文版)-2mb
报告摘要
Security Assessment of Corporate Information Systems in 2017 Summary
Core Content
This document presents a comprehensive security assessment conducted by Kaspersky Lab's Security Services department in 2017, focusing on the vulnerabilities and attack vectors found in corporate information systems. The analysis covers protection against both external and internal intruders, as well as web application security.
Main Findings
Protection Against External Intruders
- Attack Vectors: Most attacks were possible due to inadequate network filtering, weak passwords, and vulnerabilities in web applications.
- Common Vulnerabilities:
- Arbitrary File Upload was the most frequently used vulnerability to gain access to network perimeter hosts.
- SQL Injection, Arbitrary File Reading, and XML External Entity were commonly used to extract sensitive information.
- Default credentials and unrestricted network access to management interfaces were major factors in successful attacks.
- Software Updates: Only 10% of attack vectors exploited the lack of software updates, despite 86% of companies using outdated software.
- Security Levels:
- 86% of companies had extremely low protection.
- 100% of companies had low or below average security.
- 14% had above average security.
Protection Against Internal Intruders
- Privilege Escalation:
- 86% of companies with domain infrastructure had their domain administrator or enterprise administrator privileges compromised.
- On average, 2-3 attack vectors were identified per company, with many more potential vectors found using tools like Bloodhound.
- Common Attack Vectors:
- NBNS/LLMNR Spoofing was used in 67% of companies to intercept NetNTLMv2 hashes.
- NTLM Relay attacks were successfully applied in 42% of companies.
- Kerberoasting attacks were used in 20% of companies against accounts with SPN.
- Vulnerability Exploitation:
- CVE-2017-3881 (Cisco IOS) was exploited in 50% of companies.
- MS17-010 (Eternal Blue) was identified in 60% of all companies, and 75% of those tested after the vulnerability was disclosed.
- CVE-2017-5638 (VMware vCenter) and CVE-2017-7494 (Samba Cry) were also widely exploited.
- Password Attacks:
- 58% of companies were vulnerable to online password guessing attacks.
- 20% of companies had weak passwords for accounts with SPN.
- 13% of companies obtained domain administrator rights through Kerberoasting attacks.
Key Vulnerabilities and Statistics
Most Common Vulnerabilities
| Vulnerability Type | Usage |
|---|---|
| Arbitrary File Upload | 73% of attack vectors |
| SQL Injection | Common for extracting sensitive data |
| XML External Entity | Common for extracting sensitive data |
| Weak Passwords | 20% of companies had vulnerable SPN accounts |
| Default Credentials | Frequently used to access management interfaces |
| Unrestricted Network Access | Used in 50% of attack vectors |
| Exploitation of Obsolete Software | 1/3 of all attack vectors used known vulnerabilities in outdated software |
Vulnerabilities Exploited in 2017
- CVE-2017-3881 (Cisco IOS) – 50% of companies
- MS17-010 (Eternal Blue) – 60% of all companies, 75% after vulnerability disclosure
- CVE-2017-5638 (VMware vCenter) – 75% of companies
- CVE-2017-7494 (Samba Cry) – Widely exploited
Attack Techniques
- NBNS/LLMNR Spoofing – Used to intercept hashes and initiate further attacks
- NTLM Relay – Enabled rapid privilege escalation using intercepted hashes
- Kerberoasting – Used against accounts with SPN to extract TGS tickets
- Deserialization Attacks – Effective against many corporate software products
Security Recommendations
- Web Application Security:
- Regular security assessments for all publicly available web applications.
- Implement a vulnerability management process.
- Update third-party components and libraries regularly.
- Network and System Security:
- Restrict network access to management interfaces.
- Use strong passwords and avoid password reuse.
- Update software to the latest versions.
- Disable the NBNS and LLMNR protocols.
- Enable SMB signing in group policies to prevent NTLM Relay attacks.
- Password Management:
- Implement strict password policies.
- Use complex and unique passwords for different systems and accounts.
- Audit all systems for default credentials.
- Monitoring and Detection:
- Monitor for 4625, 4771, and 4776 events for password guessing attempts.
- Use honeypots to detect NBNS/LLMNR spoofing.
- Collect and analyze process launch events for unusual activity.
- Use EDR solutions or Sysmon to monitor for suspicious process behavior.
- Monitor network logons from non-typical IP addresses.
Conclusion
The 2017 security assessment highlights significant vulnerabilities in corporate information systems, particularly in web applications, outdated software, and misconfigured management interfaces. Kaspersky Lab's findings emphasize the need for stronger password policies, regular updates, and improved network security configurations. The report also provides actionable recommendations for both protection and detection, which are crucial for maintaining a secure corporate environment.
试读结束,高清完整版pdf/doc/ppt,请点下载