Header

Tue, 17 Jun 2008

rethinking ye old truths
@

since forever, i've been told (and told others) that the greatest threat is from the inside. turns out, not so much. verizon business (usa) apparently conducted a four year study on incidents inside their organisation and found that the vast majority, 73%, originated from outside. however, the majority of breaches occurred as a result of errors in internal behaviour such as misconfigs, missing patches etc. (62% of cases).

So attackers are generally outsiders taking advantage of bad internal behaviours, rather than local users finding 0-day. From the exec summary:

In a finding that may be surprising to some, most data breaches investigated were caused by external sources. Breaches attributed to insiders, though fewer in number, were much larger than those caused by outsiders when they did occur. As a reminder of risks inherent to the extended enterprise, business partners were behind well over a third of breaches, a number that rose five-fold over the time period of the study

Other interesting snippets that tie directly back into what we cover when we train, and why we think there is value in not only aiming at sploit-writing and 0-day:

Most breaches resulted from a combination of events rather than a single action.

Intrusion attempts targeted the application layer more than the operating system and less than a quarter of attacks exploited vulnerabilities.

In other words, bite-sized chunks for the win, core/canvas/metasploit are cute but that's not how customers get owned most often in the real world.

Link to the report, link to summary.

Blog
Video
Research
QotW
Categories
README (1)
Uncategorized (3)
about:us (15)
blog (7)
community (1)
conferences (21)
fail (1)
foos (1)
fun (39)
howto (5)
infosec-soapies (13)
infrastructure (1)
mac (9)
materials (1)
mindless-politics (2)
mindmaps (1)
post-it (1)
privacy (5)
programming (3)
public (141)
qo[w|m|?] (4)
real-world (7)
research (19)
reversing (1)
security-fyi (5)
security-news (3)
silly-yammerings (13)
tech-toys (2)
time-waster (4)
tin-foil-hat (6)
tools (25)
training (3)
vendors (5)
videos (1)
web_x.0 (2)
webapps (5)
writing-advice (1)
zen-hacking (6)
Archives
August 2008 (6)
July 2008 (6)
June 2008 (6)
May 2008 (2)
April 2008 (3)
March 2008 (7)
Feburary 2008 (12)
January 2008 (10)
December 2007 (8)
November 2007 (4)
October 2007 (9)
September 2007 (14)
August 2007 (18)
July 2007 (13)
June 2007 (17)
May 2007 (2)
July 2006 (1)
April 2006 (1)
August 2005 (1)
June 2005 (1)
May 2005 (2)
Archives
Conditions of use Privacy statement
Top of Page Legal stuff