Endpoint

7/27/2018
11:30 AM
Robert Block
Robert Block
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
50%
50%

Every Week Is Shark Week in Cyberspace

Your data, identities, and credentials are cyber chum. Here's how to protect yourself from the feeding frenzy.

Your odds of being attacked by a shark are zero if you never venture into the ocean — which is far lower than the odds of being cyber hacked even if you never go online. After all, you could still become a victim of identity theft without ever wading unto Internet waters.

The point is this: Fear the cyber shark far more than the great white, tiger, or bull shark, whose majesty was celebrated this week during the Discovery Channel's Shark Week, as it has every year since 1987.

So, what can Shark Week teach us about cybersecurity? Here are four areas to focus on in honor of Shark Week.

1. Assume the Role of a Lifeguard
An organization's ocean is the Internet. Some if it equates to shallow waters such as internal networks, but much of is deep and uncharted via the cloud. No matter the depth of the water, you still need to assess the risks of venturing into potentially perilous territory. A CISO is a company's lifeguard, which means being aware of, adapting to, taking precautions against, and assuming control of the threats that attackers present. With threats always evolving, it's imperative to keep improving your organizational lifeguarding skills.

2. Guard Against Phishing Attacks and Save the Whales
Phishing attacks — and, specifically, mobile phishing attacks — continue to rise. In fact, the SANS 2017 Threat Landscape Survey reported that phishing remains the most significant threat to organizations, with 74% of cyberattacks beginning when a user clicked on a malicious attachment or link contained in an email.

Spearphishing attacks are also increasing, rising to 50% in the last quarter of 2017. This technique has been used to devastating, well-documented effect over the past few years. Spearphishing takes the form of an email that appears to be from the recipient's friend or colleague. The email encourages the recipient to click on what are in reality malicious links or attachments or persuades that person to reply with sensitive professional or personal information. These attacks are difficult to identify on the surface because they combine the most common attributes of successful social engineering.

Social engineering tactics are also heavily leveraged in an even more insidious method of phishing known as pretexting, business email compromise (BEC), or "whaling" attacks. These attacks create the believable pretext of a fabricated persona in which the victim — most often a C-level executive — develops a false sense of trust in the hacker. Once the relationship has been established, money-transfer fraud and/or outright data theft quickly follows.

Prevention measures for all phishing, spearphishing, and whaling attacks are widely known and essentially the same. Yet despite anti-phishing methods such as reporting suspicious emails and routinely changing passwords, attacks are still increasing. Modern authentication techniques can be great tools for preventing the repercussions of stolen credentials. Performing security audits and providing user education and training are also solid prevention methods.

2. Safeguard Your Waters with Modern Authentication Methods
Many threats are false positives; the dorsal fin of a friendly, curious dolphin can look like the dorsal fin of a shark that's circling the waters. Similarly, an access attempt might not look suspicious until it's too late. With 80% of breaches being caused by valid yet stolen or misused credentials, it is imperative to validate every access attempt — ensuring that the good guys get in (without hindering user experience and productivity) while keeping the bad guys out. Today's available solutions add intelligence and analytics to authentication methods. These risk-based solutions, available from many vendors, focus on the user's profile and tendencies. They can include techniques such as geographic analysis, device recognition, and IP address-based threat services.

3. Continually Assess Your Environments
Threats are everywhere, in the water and online. They're usually hidden. They sometimes don't appear until it's too late. But that shouldn't keep humans from swimming in the ocean or conducting activity online, especially in the age of digital transformation. Safety counts, and precautions matter.

During Shark Week, we witnessed humans taking shelter in shark cages and avoiding seal-populated areas and shark-infested waters. As organizations continue to engage in Internet activities, remember to follow identity and security best practices, keep your senses alert for phishing emails and have a remediation and response plan when an attack does occur.

Related Content:

Learn from the industry's most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Register by July 27 and save $700! Click for more info

As Senior VP of Identity Strategy at SecureAuth and Core Security, Robert Block is responsible for executing strategic vision of preventing the misuse of stolen credentials. Block has over 19 years of IT experience — of which 15 years have been focused on identity and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
seanmajece
50%
50%
seanmajece,
User Rank: Apprentice
8/2/2018 | 5:46:40 AM
Cyberspace
By the way, my father is working with cyberspace. So I know a lot about it
amarre
50%
50%
amarre,
User Rank: Author
7/31/2018 | 1:58:20 PM
The danger is real
Too often, even after a risk is actualized by a real or simulated attack, people continue to ignore the threat and pretend that it is exaggerated.  This comparison to shark infested waters will perhaps make it more real.  People are irrationally afraid of low-likelihood shark attacks; we need them to be rationally afraid of these attacks.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
7/29/2018 | 12:52:37 PM
Threats
Threats are everywhere, in the water and online. They're usually hidden. They are mainly hidden in our logs, we can find them with automation. We mainly miss real threats but deal with false positives or negatives.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
7/29/2018 | 12:50:17 PM
False positive
Many threats are false positives; the dorsal fin of a friendly, curious dolphin can look like the dorsal fin of a shark that's circling the waters. This is where most of our security analyst time is wasted. So we need to change it with automation.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
7/29/2018 | 12:47:15 PM
Human factor
Yet despite anti-phishing methods such as reporting suspicious emails and routinely changing passwords, attacks are still increasing. It is because it exploits human factor, that is what it is effective
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
7/29/2018 | 12:45:34 PM
Phishing
Phishing attacks and, specifically, mobile phishing attacks continue to rise. I agree, Phishing is major and effective way of executing an attack,
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
7/29/2018 | 12:43:19 PM
Nice analogy
An organization's ocean is the Internet. I like the analogy, effective and CISO as lifeguard, all the employees should do their part.
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
8 Security Tips to Gift Your Loved Ones For the Holidays
Steve Zurier, Freelance Writer,  12/18/2018
How to Engage Your Cyber Enemies
Guy Nizan, CEO at Intsights Cyber Intelligence,  12/18/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-16883
PUBLISHED: 2018-12-19
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
CVE-2018-17192
PUBLISHED: 2018-12-19
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on th...
CVE-2018-17193
PUBLISHED: 2018-12-19
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior ...
CVE-2018-17194
PUBLISHED: 2018-12-19
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and even...
CVE-2018-17195
PUBLISHED: 2018-12-19
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, a...