The Coronavirus gives hackers more freedom to infiltrate your network
In recent weeks, the coronavirus has become the main topic for the global population, health authorities, politicians and organisations. For hackers,...
3 min read
DriveLock May 26, 2020 2:00:00 AM
Again and again, we read about hacking incidents where attackers can spy on a company, an authority or a ministry and remain unnoticed for months without affecting the systems. In this blog post we are explaining what a silent hacker attack is and how you can prevent it!
TABLE OF CONTENT |
Imagine the following scenario: A company has been infiltrated but knows nothing about it. Sensitive data flows into the hands of cybercriminals; either intellectual property (industrial espionage) or personal data used for criminal activities such as credit card fraud through identity theft. If the infiltration is noticed and becomes public, it is already too late for the company concerned. the costs of rescuing the systems and eliminating the defects are performed by data protection law penalties and the reputation damage of the company's image toward their customers, suppliers and other business partners.
So we are not dealing with quick and obvious blackmail by data encryption or a compromise of the systems, which means an immediate loss of work and data. At least not yet.
Let's take a step back. Did the controls fail before?
Experts largely agree that despite protective measures such as firewalls, anti-virus protection, application or interface controls, 100% protection is not possible against silent hacker attack. Malware and attack methods are simply evolving rapidly and people are falling into (increasingly sophisticated) traps.
Furthermore, not all silent hacker attacks are carried out by explicit malware. So-called Living-off-the-Land (LotL) methods largely make use of what is already present in the environment. There is no need to develop malicious files from scratch. Rather, they exploit entry points that already exist in IT systems.
This tactic can achieve several things: First, they often bypass traditional protection systems - virus scanners do not raise an alarm when software appears to be secure. In this way, they allow cybercriminals to infiltrate IT systems unobtrusively and thus often unnoticed. Even if an infiltration case is detected, under these circumstances it is much more difficult to identify where the attack comes from. Many traditional cyber security solutions are not able to detect dangerous behaviour when performed with tools that are considered legitimate.
The analysis of behaviour and the search for abnormalities are particularly relevant in this context. Endpoints (end devices such as PCs, laptops, mobile devices) must be continuously monitored.
Events on the end devices and in the system should be analysed to identify traces of hackers, determine employee misconduct and detect security gaps.
With the help of definable rules, security managers should be able to set up which events can be reacted to with which behaviour, e.g. by defensive behaviour such as shutting down processes. This relieves the burden on IT departments, which are often deployed on many fronts.
Find out more on EDR Security Platform in our blog post!
In recent weeks, the coronavirus has become the main topic for the global population, health authorities, politicians and organisations. For hackers,...
In our last blog post " Silent hacker attacks and the need for detection mechanisms" we talked about covert cyber attacks and the need for...
In this relentless digital battlefield, businesses and organizations are pitted against a multitude of adversaries ranging from individual hackers...