Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

1/29/2011
08:14 AM
50%
50%

The SpiderLabs Report

Four out of five of the victims were so clever that they didn't need a firewall

At the recent Black Hat conference in DC, I sat down with Tom Brennan, the director of Trustwave's SpiderLabs, and Nick Percoco, senior vice president and the force behind the Trustwave SpiderLabs Global Security Report 2011, which was to be released on the following day. In the interim, I've had a chance to read through the report as well.

The report they've produced is a bit sprawling. It's in three sections, the first being what I think of as the actual report, the second a 20-page survey of attack vectors, the third being a set of "11 Strategic Initiatives for 2011." My interest is overwhelmingly in the first section.

The report, like the Verizon report I've written about elsewhere, looks at cases where SpiderLabs has been called in to assist in response to an incident. According to the report, in 85 percent of the "more than 220" investigations SpiderLabs conducted last year, a breach was confirmed. This is considerably more cases than Verizon's team looked at in the same time frame, and it would seem (though the report doesn't supply the underlying demographics to verify this) that the sample spreads across a much broader swath of kinds and sizes of companies.

If we can make one broad generalization about the companies involved in the breaches (or at least in breaches where PCI compliance was an issue), then it's this: They are run by idiots. Complete, flaming idiots:

"Breached organizations did not have a firewall policy that properly protected the payment environment at the network border in 97.5% of our cases. Of those organizations, 84% lacked a firewall completely."

The first part I can see a friendly way to interpret -- getting firewalls to do what you think they are doing can be pretty tricky. But, hey, 84 percent didn't have a firewall?

In a way, this (and some other almost-as-staggering lapses among the afflicted) is good news. These are, after all, the victims of breaches. If you spread the net wider and ask a range of security practitioners who may or may not have suffered a breach, then 98 percent of them have firewalls (and lots of other good measures in place as well). It's certainly not as simple as saying that having a firewall means not having a breach (that's emphatically not true), but at least with the companies that Trustwave deals with, not having a firewall seems to be a pretty fair predictor of soon needing to call in the SpiderLabs folks.

Since you already have a firewall, what may be of more interest to you is the prevalence of problems that involve compromises introduced by third parties:

"88 percent of investigations involved deficiencies such as default vendor-supplied credentials and unsecure remote access applications."

Is this you? Can you prove it's not?

And there are several other good takeaways from the report, which you can find free here. Definitely worth having a look at -- but I must confess that I really don't understand what's going on with that (non)firewall statistic.

Robert Richardson directs content and programs at the Computer Security Institute.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ernie Floyd
50%
50%
Ernie Floyd,
User Rank: Apprentice
3/15/2012 | 6:58:40 PM
re: The SpiderLabs Report
Robert,
After a quick skim of the report, it was not clear what merchant level was most predominant in the investigations.- Prior year reports have noted this.- It's expected that most of these breaches are in Level 4 merchants.- These operators aren't idiots, they simply often know little of IT or PCI in general.-They often only have whatever network equipment that is provided by their ISP.- This would almost never include a firewall and appropriate configuration to meet PCI requirements.-

The report continues to demonstrate there is much work left to do to raise the awareness of cyberrisks in the small business community.- It's ashame as well, because when small businesses are breached, the damages can be so great that they bankrupt the company and cause great personal loss to those owners.
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-25250
PUBLISHED: 2021-04-13
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privil...
CVE-2021-25253
PUBLISHED: 2021-04-13
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to exec...
CVE-2021-28645
PUBLISHED: 2021-04-13
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target ...
CVE-2021-28646
PUBLISHED: 2021-04-13
An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations.
CVE-2021-28647
PUBLISHED: 2021-04-13
Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.