20160805-2016_Data_Breach_Investigations_Report_85页_3mb
报告摘要
2016 Data Breach Investigations Report Summary
Core Content
The 2016 Data Breach Investigations Report (DBIR) provides an in-depth analysis of information security incidents and data breaches that occurred in 2015. It highlights the persistent nature of cyber threats and the challenges organizations face in mitigating them. The report includes data from over 100,000 incidents, with 3,141 confirmed data breaches, and focuses on the patterns, motives, and methods behind these attacks.
Main Points
Breach Motives
- 89% of breaches were motivated by financial gain or espionage.
- Financial motive remained the dominant driver, with espionage as the second most common.
- Other motives included fun, ideology, grudge, and everything else, but these were less prevalent.
Breach Trends
- External actors were the primary source of breaches, with internal and collusion playing a smaller role.
- Phishing and Point-of-Sale (POS) attacks were the most common threat actions.
- Malware and hacking were frequently used in breaches, with phishing leading to credential theft and other malicious activities.
Breach Discovery
- Detection time for breaches has not improved significantly, with many breaches going undetected for days or longer.
- Law enforcement and fraud detection were the leading methods of breach discovery, with law enforcement dominating in 2015 due to a botnet takedown.
Breach Classification
- Nine incident classification patterns identified in the 2014 report remain prevalent.
- These include Web App Attacks, Point-of-Sale Intrusions, Insider and Privilege Misuse, and Miscellaneous Errors.
Key Information
Victim Demographics
- Breaches affected organizations in 82 countries and across various industries.
- Retail and Accommodation industries were the most affected, with confirmed data breaches.
- Public sector had a significantly higher number of incidents, likely due to reporting requirements.
Incident vs. Breach
- Incidents are security events that compromise the integrity, confidentiality, or availability of an information asset.
- Breach is an incident that results in the confirmed disclosure of data to an unauthorized party.
VERIS Framework
- The report is based on the VERIS framework, which categorizes incidents using the 4As (Threat Actor, Action, Asset, Attribute).
- This framework helps in understanding the timeline, victim demographics, discovery method, and impact data.
Threat Action Categories
- Phishing and POS attacks were the most common threat actions.
- Malware was used in C2, data export, and spyware attacks.
- Hacking included brute force, backdoor, and credit card use.
Time to Compromise and Exfiltration
- The time to compromise was typically days or less, with some breaches happening in minutes.
- Exfiltration often took days to complete, especially in POS attacks where malware is used to capture and export data.
Vulnerability Management
- Older vulnerabilities are still heavily targeted, suggesting that patching is not always effective.
- New vulnerabilities are also exploited, with the top 10 accounting for 85% of successful exploit traffic.
- Remediation efforts are often not fast enough, and mitigation is sometimes the only option.
Recommended Controls
Vulnerability Remediation
- Establish a process for vulnerability remediation that targets vulnerabilities being exploited in the wild.
- Prioritize vulnerabilities with known exploits or proof-of-concept code.
Plan B
- For systems that cannot be patched, identify them and apply configuration changes or isolation.
- Discuss a plan for replacement to avoid severe business disruption.
Vulnerability Scanning
- Use vulnerability scanning to identify new devices and services.
- Review scan-to-scan changes to detect unknown devices and deviations from standard configurations.
Summary of Findings
- Phishing remains a critical vector for attacks, with 13% of users clicking on malicious attachments.
- Credential theft is a common outcome of phishing, often leading to persistent malware installation.
- Public sector continues to be a major target, but not necessarily less secure than other industries.
- No significant real-world data on mobile attacks or IoT as vectors for breaches was available.
- Vulnerability management is a continuous challenge, with old vulnerabilities still being exploited.
- Mitigation is often as effective as remediation and is necessary when patching is not feasible.
Appendices
- Appendix A discusses post-compromise fraud.
- Appendix B lists contributing organizations.
- Appendix C includes the Taupe Book.
- Appendix D provides attack graphs.
- Appendix E details methodology and VERIS resources.
- Appendix F offers a year in review of the data.
This report underscores the need for continuous vigilance and proactive measures in information security, emphasizing the importance of understanding both the patterns and motives behind breaches to better defend against them.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载