Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

04:18 PM

Expert: Attacks, Not Vulnerabilities, Are Keys To IT Defense

Attackers are increasingly cribbing code from existing exploits, rather than creating new ones

In the past year, attackers have shifted from mining software advisories for new vulnerabilities to grabbing code from zero-day disclosures, bugs bounty programs, and targeted attacks, according to a security expert.

Security consultant Daniel Guido said last week in a presentation at the Source Boston conference that although thousands of vulnerability reports are issued every year, only 13 of the vulnerabilities discovered in the past year and 27 of the flaws discovered in the past two years were involved in the most popular exploit kits used to fuel mass attacks.

On the other hand, an increasing number of those kits incorporate exploits copied from advanced targeted attacks aimed at enterprises.

"We can step back and study these things that are coming after us, and we can build more informed defenses that are more effective against those particular threats and that are less costly than not having done this process to begin with," Guido said.

Defenders should pay attention to these emerging exploit kits because systems hardened against those attacks would also be immune to the mass attacks that frequently target specific networks, Guido said.

Rather than focus on the more than 8,000 vulnerabilities found in 2010, according to data from security-services firm Secunia, companies need to focus on the techniques that attackers are using, Guido said.

"The goal is not to create invulnerable software, but to minimize the attack. Somewhere along the line we forgot about that," he said. "You have to realize that these applications have vulnerabilities, no matter how many patches we apply or how many pieces of malware we write signatures for."

Focusing on attacks and not vulnerabilities can help companies prioritize their defensive efforts, says Dino Dai Zovi, a well-known independent security researcher. While 27 vulnerabilities threatened the average company in 2009 and 2010, the other 99.7 percent of vulnerabilities could have been given a lesser priority for patching, he says.

"If you look at it that way, you realize that vulnerabilities just don't matter at all," Dai Zovi says. "There is almost no level of mobilization that we -- vendors, organizations, and everyone involved -- could mount to get all these vulnerabilities off our systems in the span of a few years."

Attackers attempt to economize their efforts by copying successful exploits that can reach many computers, rather than writing such exploits themselves, experts say. For example, Guido found that out of the 15 exploit kits widely used in the underground, 11 crimeware frameworks used Java exploits. Turning off Java in the Internet zone could have prevented any attacks based on those vulnerabilities.

Another key defense mechanism is turning on data-execution protection (DEP), Guido said. The exploit packs Guido studied contain methods of compromising systems using 19 memory-corruption vulnerabilities. By turning on DEP, the exploitation of 14 of those vulnerabilities would have been prevented, he said.

"We now know how effective our particular defenses are," Guido said. "We have hard numbers now about how effective, say, DEP is against attacks."

Defense-in-depth still matters, Guido said, and companies should still have a process to patch their vulnerabilities. But to help prioritize their efforts, companies should first protect against the most likely attacks, he noted.

"How can you protect yourself against [advanced persistent threats], when you can't even protect yourself against being accidentally hacked?" Guido asked.

Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Threaded  |  Newest First  |  Oldest First
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-13
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying th...
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another serv...
PUBLISHED: 2021-05-13
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.