Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Stolen Passwords Used In Most Data Breaches
Threaded  |  Newest First  |  Oldest First
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
4/22/2014 | 2:54:13 AM
Phish vs. Use of Credentials
I find it interesting that even though the use stolen credentials is the number one threat action reported by verizon the vast majority of the other threats focus on stealing credentials atleast in part. 

Moral of the story, we need to quickly move toward multi-factor authentication and adaptive authentication.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/22/2014 | 10:00:13 AM
Re: Phish vs. Use of Credentials
@Robert. I agree with your multifactor authentication. Also, now that biometrics is increasing in popularity, what are the breach trends in accordance with this type multi-factor setup. (Biometrics & Hardcode passwords) My organization doesn't use biometrics and I am unsure how many organizations do but I am curious to see what difficulties they are facing in this space.
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
4/22/2014 | 8:10:41 AM
The Verizon Data Breach Investigations Report bears a close look
Great story from Kelly Jackson Higgins, but if you can make the time, it's worth reading the entire Verizon DBIR from beginning to end. The DBIR is one of the most interesting security studies released each year because it is not a survey -- it's data collected from actual breaches that Verizon and partners have investigated in the past year.

Surveys are great, but in security sometimes respondents don't give all the details of their posture, or simply don't know what they don't know. The DBIR shows the actual reasons behind major security breaches, how they occurred, and what their impact was. It's a great benchmark for the industry, and sometimes brings our flaws or faulty practices that enterprises have overlooked.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
4/22/2014 | 8:22:24 AM
Re: The Verizon Data Breach Investigations Report bears a close look
Absolutely, Tim. There is a lot to the report, as always. Even more so this year with the broader and more global input. This year's report is a truly global and comprehensive look at what's really happening in data breaches as well as other security incidents. As always, we'll be drawing from its findings all year long. 

 
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
4/22/2014 | 10:27:37 AM
Let's Talk About Response In Addition To Defense
Attackers have the advantage: they only need to find one flaw to get a beachhead, while the defenders have to be perfect all the time. It seems like the security industry is starting to put more emphasis on how organizations respond to an incident, instead of going for the impossible standard of perfect security. It's important to have a robust defense, but just like companies have DR/BC plans, they also need to have breach response plans in place.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
4/22/2014 | 10:31:04 AM
Re: Let's Talk About Response In Addition To Defense
Totally agree, @Drew Conry-Murray. I've been writing a series on IR's role in security (was on hold for  Heartbleed but another installment coming on Thursday :-) ), and the bottom line is that by necessity, IR is gradually becoming part and parcel of a good security strategy.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/22/2014 | 11:51:48 AM
Re: The Verizon Data Breach Investigations Report bears a close look
In case you missed the link to the full report in Kelly's news story, you can get all the details here
Markus5
50%
50%
Markus5,
User Rank: Strategist
4/23/2014 | 6:09:44 AM
Re: The Verizon Data Breach Investigations Report bears a close look
Isn't it time for everyone to start using a password management system? I use Sticky Password, but there are many others out there.
douglasmow
50%
50%
douglasmow,
User Rank: Apprentice
4/23/2014 | 4:51:46 PM
Supplement Security With Access Analytics
@Kelly, Your story covering the 2014 Verizon DBIR highlights something we work to continuously convey to customers... what may look like a customer or partner or staff member, may not in fact be so. With the report citing 2 out of 3 data breaches are from stolen credentials, organizations with insight into who is accessing what information for what purpose will be able to better detect, deter and possibly even prevent a breach. The only way to gain this insight is by applying analytics to the big data of identity and access. By analyzing user access rights and the associated risk on a continuous basis, organizations can identify suspicious behavior patterns to expose external, as well as internal, threats of inappropriate access.

 

@Robert, agree fortifying perimeter defense is critical but security can be enhanced by knowing who should be accessing what once a user, legitimate or not, is inside.

 
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
4/23/2014 | 6:00:25 PM
Re: Supplement Security With Access Analytics
Thanks so much for sharing your insight and experience with this @douglasmow. What seems to be such a basic thing to secure and track, a logon & password, always seems to rear its ugly head. The Verizon DBIR put an exclamation point on it, that's for sure. 
ChrisB093
50%
50%
ChrisB093,
User Rank: Strategist
4/24/2014 | 9:47:52 AM
Solutions to stop credentials-based-attack
Despite the widespread occurance and high profile too many corporations are not doing enough to mitigate the risk of security breaches from password based attacks.

Such an attacker is likely to log in with stolen credentials from an abnormal location at an unusual time. Restricting user's individual access to the network by physical location (workstation or device, IP range, department, floor, building...) and setting usage/connection time limits helps organizations avoid these credentials-based attacks.

In addition by preventing concurrent logins network vulnerability is significantly reduced. This limits users to only one possible connection at any one instant making it impossible for any rogue user to use valid credentials at the same time as their legitimate owner, wherever they are based.

Our solution UserLock ensures unauthorized access is no longer possible for Windows based infrastructures - even when credentials are compromised. It stops malicious users seamlessly using valid credentials. 

We blog further about internal security breaches from password based attacks here: http://www.isdecisions.com/blog/it-security/internal-security-breaches-from-password-based-attacks/


Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-0828
PUBLISHED: 2020-02-21
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BM...
CVE-2012-0844
PUBLISHED: 2020-02-21
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
CVE-2013-3587
PUBLISHED: 2020-02-21
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses...
CVE-2012-6277
PUBLISHED: 2020-02-21
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8....
CVE-2012-0063
PUBLISHED: 2020-02-21
Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.