2017安全威胁报告(英文版)_49页-4mb
报告摘要
McAfee Labs Threats Report Summary - April 2017
Core Content
This report from McAfee Labs provides an in-depth analysis of two key topics in the cybersecurity landscape: threat intelligence sharing and the Mirai IoT botnet. It also includes updated quarterly threat statistics and highlights the company's recent developments and strategic changes.
Main Topics
1. Threat Intelligence Sharing
- Importance: Threat intelligence sharing is crucial for reducing attackers' advantages and shortening the lifecycle of cyber campaigns.
- Drivers: The increasing complexity of the technology environment, the need to understand attacker-target relationships, and the emergence of more sophisticated threats are key drivers for intelligence sharing.
- Models: Several models exist for threat intelligence sharing, including:
- ISACs (Information Sharing and Analysis Centers): Nonprofit organizations that share intelligence between governments and industry sectors.
- ISAOs (Information Sharing and Analysis Organizations): Broader in scope, can be private or nonprofit, and are encouraged by legal frameworks.
- CERTs and IRTs: Government-funded or company-specific teams that focus on threat and vulnerability research and incident response.
- Threat Exchanges: For-profit or crowdsourced platforms that facilitate intelligence sharing, often with a focus on quality and trust.
- Challenges:
- Volume: High data influx from sensors and defenses makes it difficult to filter and prioritize.
- Validation: Ensuring the authenticity and relevance of intelligence is essential to avoid false positives.
- Quality: Intelligence can be duplicated or low-quality, reducing its value.
- Speed: Timely intelligence is critical for effective response, especially in the context of fast-moving threats.
- Correlation: The ability to connect disparate data points into meaningful insights is vital for identifying and mitigating threats.
- Improvement Areas:
- Simplify event triage for security practitioners.
- Improve relationships between indicators of compromise.
- Enhance sharing mechanisms between internal products and external vendors.
2. Mirai, the IoT Botnet
- Overview: Mirai is a notable IoT botnet responsible for the massive DDoS attack on Dyn in October 2016, which peaked at 1.2 Tbps.
- Functionality: Mirai exploits weakly secured IoT devices, turning them into bots to launch attacks. It uses a variety of attack vectors, including default credentials and known vulnerabilities.
- Impact: The attack caused widespread disruption, affecting major websites and services. The release of Mirai's source code led to the creation of derivative bots and the emergence of "DDoS-as-a-service" platforms.
- Evolution: Mirai has evolved with the release of its source code, leading to new variants and increased accessibility for less-skilled attackers.
Key Information
- McAfee Labs is a leading authority in threat research and intelligence, now part of Intel Security.
- New Protection Technologies:
- Real Protect: Detects zero-day malware using cloud-based machine learning.
- McAfee Cloud Threat Detection: Identifies unknown malware using machine learning and group classification methods.
- Threat Landscape Dashboard: Launched as part of the Intel Security Threat Center, it lists top threats and provides mitigation guidance.
- McAfee GTI Statistics (Q4 2016):
- 49.6 billion queries per day.
- 66 million protections against malicious URLs.
- 71 million protections against malicious files (down from 150 million in Q3).
- 37 million protections against potentially unwanted programs.
- 35 million protections against risky IP addresses.
Strategic Changes
- McAfee's Independence: Intel Security is set to become an independent entity again, known as McAfee, with Chris Young as CEO.
- Cyber Threat Alliance (CTA): A consortium of security vendors, including Intel Security, Symantec, Palo Alto Networks, Fortinet, Cisco, and Check Point, that aims to improve threat intelligence sharing through automated platforms and scoring systems.
Conclusion
The report emphasizes the need for improved threat intelligence sharing mechanisms, the growing threat posed by IoT botnets like Mirai, and the importance of leveraging advanced technologies to detect and respond to cyber threats more effectively. It also highlights the role of collaboration and the establishment of shared platforms in enhancing cybersecurity defenses across industries.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载