2018年春季互联网现状-安全_运营商洞察(英文版)-8mb
报告摘要
Spring 2018 State of the Internet / Security: Carrier Insights Report Summary
Core Content
This report is the first State of the Internet / Security: Carrier Insights publication by Akamai, following the acquisition of Nominum in November 2017. It highlights the importance of collaboration and information sharing in the cybersecurity landscape, emphasizing that no single entity can effectively combat the complex and evolving nature of cyber threats. The report also showcases the role of DNS data in identifying and analyzing new threats, as well as the impact of emerging malware on the security ecosystem.
Main Views
Collaboration is the Key to Success
- Importance of Information Sharing: The cybersecurity industry relies heavily on collaboration to detect and respond to threats. Sharing data, insights, and intelligence is crucial for building collective defenses and improving the overall security posture.
- Strategic Collaboration: Companies must move beyond just sharing information and instead engage in strategic collaboration. This helps to increase the cost and complexity for malicious actors, and enables more effective disruption of threats.
- Examples of Collaboration: The report discusses the collaborative efforts that led to the takedown of the Mirai botnet and the ongoing threat of credential abuse. It also highlights the value of platforms like the Cyber Threat Alliance (CTA) in enabling faster and more effective information sharing.
DNS as a Critical Layer
- DNS Data Analysis: The report uses DNS data to identify new threats and understand their behavior. It highlights the use of unsupervised clustering algorithms like Domain2Vec to detect zero-day domains and classify them based on their malicious characteristics.
- Layered Security Model: The report reiterates the importance of a layered security model, where different security layers interact and share insights. This model allows for a more comprehensive and adaptive defense strategy.
Key Information
Threat Trends
- Zero Day Domains: The report notes a 60% increase in zero-day domains during the first peak (October 23 – November 1), with an average of 109,000 unique domains per day.
- WPAD Abuse: The second peak (November 24 – December 14) was caused by Web Proxy Auto-Disclosure (WPAD), which allows attackers to intercept and modify traffic. The number of WPAD-related queries reached 72 million per day, originating from over 1 million unique client IPs.
- Malware Evolution: The report discusses the evolution of malware like Loapi (a mobile trojan) and Terdot (a financial Trojan that now targets social media platforms), highlighting the modular and extensible nature of modern malware.
Emerging Threats
- Terdot: This malware targets social network platforms like Facebook, Twitter, Google Plus, YouTube, and vk.com. It acts as a local proxy server to monitor and manipulate user activity.
- Loapi: This Android malware demonstrates how malicious programmers are learning to write extensible code, expanding its capabilities beyond traditional DDoS attacks.
- JS Miner: This represents a new business model for cryptocurrency mining, leveraging JavaScript to execute mining scripts on infected devices.
Technical Insights
WPAD Vulnerability
- WPAD Functionality: WPAD allows devices to automatically discover proxy servers. Attackers can exploit this to intercept all user traffic, including HTTPS, and redirect it through a rogue proxy.
- Impact of WPAD: The report shows that the WPAD domain is queried 25 million times per day by 240,000 clients. This indicates a widespread vulnerability that malicious actors can exploit.
- Mitigation: By identifying and blocking malicious queries, Akamai's systems can prevent the exploitation of WPAD and protect users from Man-in-the-Middle attacks.
Geolocation and C&C Hosting
- U.S. Leadership: The U.S. remains the leader in C&C server count and malicious queries, accounting for 52.5% of queries and 55.8% of C&C server IPs. This is due to the presence of major hosting companies.
- Rise of China: China is emerging as a significant player, with 2.5% of C&C servers and 12% of malicious queries. This signals a shift in the global threat landscape.
- Preferred Hosting Providers:
- GhostPush (Android malware) uses AWS for most of its C&C servers.
- Dorkbot relies heavily on Rostelecom (Russian telecom).
- Xavier and HummingBad (malicious ad libraries) use Google Cloud.
- Ramnit (banking Trojan) uses Nevacom (Russia) and YHC Corporation (Texas) for C&C.
Conclusion
- Future of Cybersecurity: The report concludes that collaboration and data sharing will become even more essential in the future. As threats grow in scale and complexity, artificial intelligence and machine learning will play a greater role in automating responses and minimizing human intervention.
- Human Element: Despite the rise of AI, human interaction remains a key component in cybersecurity, driving innovation and improving the effectiveness of security systems.
- Call to Action: The report encourages the cybersecurity industry to embrace collaboration, share intelligence, and develop more robust defenses against emerging threats.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载