Attacks/Breaches
2/29/2012
09:53 AM
50%
50%

Outsider Hacks Dominated 2011 Security Breaches

Insider attacks comprised only 5% of breaches; most outsiders exploited weak passwords to enter networks, reported Verizon.

RSA CONFERENCE 2012 -- San Francisco -- More than 85% of the data breach incident response cases investigated by Verizon Business last year originated from a hack, and more than 90% of them came from the outside rather than via a malicious insider or business partner.

Tuesday, Verizon published a snapshot of data from its upcoming 2012 Data Breach Investigations Report, using data from its own caseload of some 90 of its 855 breach cases for last year.

"This is the first year that we worked more cases outside the U.S. than inside. That ratio has been building and it makes the case that this is not a U.S.-specific problem. All regions are having data breaches," said Wade Baker, director of research and intelligence at Verizon Enterprise Solutions.

At the top of the list of compromised industries again were retail, financial services, and hospitality. And a big factor in this year's cases was the rise in hacktivist-based attacks, according to Baker.

[ See our complete RSA 2012 Security Conference coverage, live from San Francisco. ]

Outside or external attackers jumped from 88% in 2010 to 92% in 2011, and breaches due to internal threats continued to decline, from just more than 10% in 2010 to less than 5% in 2011, according to Verizon's data. "We can expect this trend to continue. Every single caseload we ever looked at shows the external [threat agent] as the majority except for one," Baker says.

As for breach methods, hacking (86%) and malware (57%) were on the rise, while social engineering, misuse, physical threats, errors, and environmental factors all dropped.

The most commonly used venue for breaches was exploiting default or easily guessed passwords, with 29% of the cases last year, followed by backdoor malware (26%), use of stolen credentials (24%), exploiting backdoor or command and control channels (23%), and keyloggers and spyware (18%). SQL injection attacks accounted for 13% of the breaches.

Read the rest of this article on Dark Reading.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sabrina
50%
50%
Sabrina,
User Rank: Apprentice
3/1/2012 | 6:57:50 AM
re: Outsider Hacks Dominated 2011 Security Breaches
These are the reasons why we have to choose a good internet security which protects from attacks
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0714
Published: 2015-05-02
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCut53595.

CVE-2014-3598
Published: 2015-05-01
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.

CVE-2014-8361
Published: 2015-05-01
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request.

CVE-2015-0237
Published: 2015-05-01
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.

CVE-2015-0257
Published: 2015-05-01
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.