News
3/20/2014
07:45 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Stop Targeted Attackers

All cyber-attackers aren't equal. Focus more attention on exploits made just for you

Not so long ago, the main threats in cyber-security were random: viruses and worms that crawled across the entire Internet, or malware buried in spammy email blasts. Enterprises coped with the problem with protective screens that recognized and blocked these random attacks, as an umbrella keeps off the rain.

Today, the most dangerous attacks are no longer random. They are targeted specifically to steal or damage data from a specific organization, or even from specific systems and people in that organization. The targets aren't always large companies or government agencies; targeted attacks can be launched against government contractors, media firms, or even small businesses. Targeted attacks are the attack vector of choice for sophisticated cyber-criminals, and against certain exploits, existing enterprise defenses are about as effective as an umbrella against a surprise Super Soaker attack.

Targeted attackers sometimes spend months, even years, scouting their targets. They'll probe for weaknesses and pinpoint vulnerabilities that can be used in a tailored attack. That first vulnerability may get them the crown jewels right away, but typically, targeted attacks are a multistep process. Attackers start by gaining a foothold in the target's infrastructure. Once inside, they'll quietly scope out the network, looking for further points of attack and ways to access specific information.

Read the full article here.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.