Vulnerabilities / Threats

6/13/2018
02:00 PM
Donald Meyer
Donald Meyer
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

LeBron vs. Steph: The NBA Version of Cyber Defense vs. Cyberattacks

It takes an aggressive, swarming approach to overcome the most dangerous threats today.

If LeBron James didn't play basketball, he'd be just as menacing as a hacker.

And if Stephen Curry hadn't been shooting 3-pointers before he turned 3 years old, he'd be just as effective at cybersecurity as he is a point guard.

For the fourth consecutive year, the Golden State Warriors played LeBron James' Cleveland Cavaliers for the NBA championship, with the Warriors dominating the series in a four-game sweep. If you've tuned in, you've seen an athletic blueprint for the new generation of cyberattacks.

In 2018, championship basketball has distinct parallels with "championship" cybersecurity. They're both about drawing from threat intelligence, deploying unified threat prevention, and securing the perimeter and infrastructure.

NBA teams that are still running isolated, disparate schemes are much like the 97% of organizations that haven't adapted to modern cyberattacks: They're wannabes and also-rans, all but begging to be defeated.

Nowadays, malware is bigger, faster, and smarter than before. Cybercriminals are attacking organizations' systems every day, yet only 3% of companies are actually defeating these threats. Taking on a singular force like fifth-generation malware requires nothing short of the most cohesive, innovative, and intelligent team to ever play the game.

LeBron James: As Tenacious as Fifth-Gen Malware 
Scientists in a lab wouldn't have the budget to engineer a better basketball player than the 6-foot-8, 270-pound LeBron James. At age 33, at the end of his 15th season, he's a singular force who has brought his teams to the NBA Finals for eight straight years, leading all players in every statistical category. 

Versatile, powerful, and prolific, James stands as the athletic equivalent of today's fifth-gen cyberattackers. Like King James, hackers attack multiple vectors. He takes his game inside, outside — all over the court. They'll infect your cloud, and if that doesn't work, they'll switch to relentlessly attacking your mobile, your endpoint, and your network until the malware breaks through.

By using hacking tools stolen from government agencies, fifth-generation attacks bring LeBron-like firepower. The WannaCry and NotPetya attacks, for example, were powered by exploits stolen from the NSA in the infamous Vault 7 hacking leak. Cybercriminals nowadays have access to the same tools that the CIA uses for its digital espionage, and their resulting malware is overwhelmingly powerful.

Cyberattacks have also taken center stage in warfare and crime, shutting down entire countries and spreading through continents at once, causing billions of dollars in damage. With more power and more avenues than ever before, cybercriminals continue to adjust their sights upward.

In that respect, they're no different than LeBron James and Steph Curry — with Curry the unstoppable force to James' immovable object.

Steph Curry's Warriors: A Team Approach That Secures Wins
Curry is the undisputed leader of this Golden State Warriors dynasty. Although the team is loaded with other superstars —including Kevin Durant, Klay Thompson, and Draymond Green — most of the time, all eyes are on Curry. That's because he's good enough at dribbling and shooting that he can take an outside shot from anywhere on the court.

But pay close attention to what the other four Warriors are doing.

On offense, they're providing the chaos needed by screening out defenders and through rapid-fire passing to open-enough space for any of them to cleanly shoot the ball. James may be able to shut down any individual player on defense, but he can't be in two or three places at once. It becomes nearly impossible for the Cavs to keep up with everybody.

On defense, all five Warriors are constantly switching and rotating. On practically every Cleveland possession, whoever has the ball is seeing multiple Warriors defenders. When the defenders step out, they're closing any gaps on the sides for the offensive players to pass through.

At their best, they are unified and cohesive, constantly communicating with each other in order to be aware of each other's movements. 

A Unified Approach to Defense
What can cyber professionals learn from Curry's approach? Cyber defense requires that unified, cohesive system, too.

Fifth-gen malware is able to infiltrate a system by moving laterally, but when an organization has connected, integrated solutions in place for its cloud and mobile networks, it can maintain consistent defense by switching up against the malware. If the malware tries to enter in the cloud, a unified, comprehensive approach will alert and defend the rest of the system about this particular threat.

Instead of having five separate defenders for your organizations all operating independently, you need one defensive system where different products are working together, closing any gaps before they emerge.

Much like the Warriors, the right cyber defense will constantly switch, screen, and communicate in a cohesive fashion. That will enable them to rain devastating 3-pointers, Steph Curry-like, against the LeBron James-esque fifth-gen malware of the world.

Related Content:

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information.

Donald Meyer is the head of product cloud and data center at Check Point. He has more than 17 years of networking and security industry experience. In his current role, he is responsible for Check Point data center and cloud security. View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3937
PUBLISHED: 2018-08-14
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability...
CVE-2018-3938
PUBLISHED: 2018-08-14
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST r...
CVE-2018-12537
PUBLISHED: 2018-08-14
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
CVE-2018-12539
PUBLISHED: 2018-08-14
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows,...
CVE-2018-3615
PUBLISHED: 2018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.