2018年-普华永道全球_A_Practical_Method_of_Identifying_Cyberattacks_17页_876kb
报告摘要
Summary of "A Practical Method of Identifying Cyberattacks"
Core Content
This document provides an in-depth analysis of the growing threat of cyberattacks and outlines a framework for identifying their sources, motives, and methods. It emphasizes the challenges of attribution and the increasing complexity of cyber threats due to the involvement of various actors, including governments, criminals, and hacktivists.
Main Types of Cyber Threats
Cyberattacks are categorized into three main types based on the intent and nature of the perpetrators:
-
Crime: These attacks are primarily motivated by financial gain. Attackers steal payment information, hijack computational resources, or execute ransomware attacks to extort money. Examples include the 2017 Equifax data breach and the 2016 Bangladesh Bank SWIFT attack.
-
Warfare: Cyberwarfare involves attacks aimed at destabilizing a nation state or its institutions. These can be direct acts of war or indirect efforts to spread alarm or discontent. Examples include the 2013 attacks on South Korean television stations and a bank, and the 2016 BlackEnergy attack on Ukraine’s power grid.
-
Activism: Hacktivist attacks are designed to protest against real or perceived actions by governments, corporations, or other entities. These often involve DDoS attacks, website defacement, or leaking private information. Examples include attacks on Spanish government websites by Catalan independence supporters and DDoS attacks on Thai government sites by hacktivists.
Key Challenges in Cyberattack Attribution
- Difficulty in Identification: Attackers often use techniques to obscure their identity, making it hard to trace the source of an attack or the motives behind it.
- Political and Legal Implications: Misattribution can lead to inappropriate retaliation or public misunderstanding. In democratic societies, transparency and proof are crucial for public acceptance of attributions.
- Complex Supply Chains: Cyberattacks can involve multiple actors, and the information found in attack files may point to different parts of the supply chain, leading to potential misattribution.
Key Statistics
- Cybercrime is predicted to cost the world $6 trillion annually by 2021.
- The average cost of a data breach is $3.6 million.
- Ransomware is the fastest-growing malware threat, with over 4,000 daily attacks in 2016.
- Cybercrime is now the second most reported economic crime, affecting over 32% of organizations.
- 61% of CEOs are concerned about cybersecurity, while less than half of board members request information on cyber-readiness.
- Global cybersecurity spending is expected to exceed $1 trillion by 2021.
Technical and Analytical Framework for Attribution
The document outlines a framework for identifying the origin of cyberattacks, which includes:
- Motivation: Assessing whether the attacker has a rational incentive for the attack.
- Technical Origin: Tracing the location of devices, command-and-control IP addresses, and communication channels.
- Malware Analysis: Examining the binary code, scripts, and file names to identify technical signatures or clues about the attacker’s background.
- Modus Operandi: Analyzing the timing of attacks, script comments, and malware tactics to match known patterns of behavior.
Conclusion
Understanding the source and nature of cyberattacks is crucial for effective risk management and response. While attribution remains a complex and challenging task, the development of analytical frameworks and the growing awareness of cyber threats are essential steps toward improving cybersecurity preparedness. The document underscores the need for clarity in defining cyber threats and the importance of distinguishing between different types of attacks to respond appropriately.
Appendix: Timeline of Major Cybersecurity Incidents
| Year | Name | Description |
|---|---|---|
| 2017 | Spanish government sites | Hackers, allegedly supporting the Catalan independence movement, launched DDoS attacks and defaced websites run by Spain’s Ministry of Public Works and Transport. |
| 2017 | Neo-Nazi and KKK websites | DDoS campaign targeting alt-right and Neo-Nazi groups following the Charlottesville rally. |
| 2016 | Operation Darknet Relaunch | Hacktivists linked to Anonymous claimed over 50% of the data on Freedom Hosting II servers contained explicit content, with 75 GB of files and 2.6 GB of databases stolen. |
| 2016 | OpOlympicHacking | DDoS attacks targeting various government organizations as a form of protest against Brazil hosting the Olympic Games. |
The document highlights the evolving nature of cyber threats and the urgent need for improved methods of identification and response.
试读结束,高清完整版pdf/doc/ppt,请点下载