Attacks/Breaches
2/29/2012
09:53 AM
50%
50%

Outsider Hacks Dominated 2011 Security Breaches

Insider attacks comprised only 5% of breaches; most outsiders exploited weak passwords to enter networks, reported Verizon.

RSA CONFERENCE 2012 -- San Francisco -- More than 85% of the data breach incident response cases investigated by Verizon Business last year originated from a hack, and more than 90% of them came from the outside rather than via a malicious insider or business partner.

Tuesday, Verizon published a snapshot of data from its upcoming 2012 Data Breach Investigations Report, using data from its own caseload of some 90 of its 855 breach cases for last year.

"This is the first year that we worked more cases outside the U.S. than inside. That ratio has been building and it makes the case that this is not a U.S.-specific problem. All regions are having data breaches," said Wade Baker, director of research and intelligence at Verizon Enterprise Solutions.

At the top of the list of compromised industries again were retail, financial services, and hospitality. And a big factor in this year's cases was the rise in hacktivist-based attacks, according to Baker.

[ See our complete RSA 2012 Security Conference coverage, live from San Francisco. ]

Outside or external attackers jumped from 88% in 2010 to 92% in 2011, and breaches due to internal threats continued to decline, from just more than 10% in 2010 to less than 5% in 2011, according to Verizon's data. "We can expect this trend to continue. Every single caseload we ever looked at shows the external [threat agent] as the majority except for one," Baker says.

As for breach methods, hacking (86%) and malware (57%) were on the rise, while social engineering, misuse, physical threats, errors, and environmental factors all dropped.

The most commonly used venue for breaches was exploiting default or easily guessed passwords, with 29% of the cases last year, followed by backdoor malware (26%), use of stolen credentials (24%), exploiting backdoor or command and control channels (23%), and keyloggers and spyware (18%). SQL injection attacks accounted for 13% of the breaches.

Read the rest of this article on Dark Reading.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sabrina
50%
50%
Sabrina,
User Rank: Apprentice
3/1/2012 | 6:57:50 AM
re: Outsider Hacks Dominated 2011 Security Breaches
These are the reasons why we have to choose a good internet security which protects from attacks
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: " I think Google Doodle is getting a little out of control"
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.