Light Reading

Verizon Offers Industry-Specific Security Advice

Carol Wilson
4/22/2014
50%
50%

Seven years into publishing its annual analysis of data breach information, Verizon is taking a new approach, combining big data analysis with 10 years of data breach records to produce information specific industries can use to make their networks safer. (See Verizon DBIR Focuses Security by Industry.)

The 2014 Data Breach Investigations Report, known as the DBIR, goes beyond what past reports have delivered, says Verizon Enterprise Solutions 's Marc Spitler, senior analyst and DBIR co-author, to give enterprises more information on which they can act. After analyzing 63,000 incidents and 1,600 confirmed data breaches, Verizon determined that 90% of these fall into one of nine incident patterns. (By the way, you can download a copy of the report here.)

"These incidents patterns are analyzed, and they are mapped to particular industries, because we believe that will make it more actionable to those industries," Spitler says. "We think this is the proper evolution of what we are doing because people want more analysis and more advice on what to do."

By focusing on the type of incidents that most often affect their specific industry segment, enterprises can make more efficient use of the information Verizon is providing. That's particularly important because most industries are hit harder by a limited number of attack types, Spitler says.

What Verizon found is that most industries face the greatest threat from only three of the nine data threat patterns. Those patterns are:

  • Crimeware: malware intended to gain control of systems
  • Insider/privilege misuse
  • Physical theft/loss
  • Cyber-espionage
  • Denial-of-service attacks
  • Web app attacks
  • Point-of-sale intrusions
  • Payment card skimmers
  • Miscellaneous errors such as directing email to the wrong person

That's not to say the 2014 DBIR isn't full of its usual juicy tidbits about trends in cybercrime, because it is. For example, cyber-espionage is up, with the number of incidents reported totaling three times what was reported in 2013, although that is due in part to a greater data set. Many data breaches today happen stealthily and can take a long time to identify, leading to greater damage.

For the first time, the Verizon DBIR chose to address DDOS attacks and found these are getting stronger every year. DDOS attacks compromise network resources and can be either a distraction to the real data breach or an intended disruption of business. Financial services, retail, professional, information, and public sector enterprises all count DDOS attacks among their main threats.

The number one way of getting information remains use of stolen or hacked passwords, and DBIR authors say that makes a strong case for two-factor authentication.

Interestingly, retail point-of-sale attacks, which have been in the news of late, are actually on the wane in terms of volume, the DBIR notes.

Verizon issues its annual DBIR in part to highlight its own Verizon Managed Security Services which delivers, among many other things, two-factor authentication capabilities.

— Carol Wilson, Editor-at-Large, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Carol Wilson
50%
50%
Carol Wilson,
User Rank: Blogger
4/22/2014 | 3:22:35 PM
Re: Social Engineering
One of the DBIR's findings this year is that many data breaches go unnoticed for a substantial period of time. 

Certainly that was the case with many of the retail breaches this year, like the Target and Lord&Taylor incidents. Information gathering can be done over a long period of time, which means the impact of the breach is much greater. 

That puts a premium on not only trying to prevent breaches but on identifying them more quickly, which I think depends more on the ongoing analysis and tracking of LAN and WAN activity. 
danielcawrey
50%
50%
danielcawrey,
User Rank: Light Sabre
4/22/2014 | 3:18:32 PM
Social Engineering
Getting stolen or hacked passwords probably comes from phishing attempts. It would seem, in my estimation, one of the easiest ways to procure authentication information. 

Social engineering is a bit different in that oftentimes a user doesn't realize they have been hacked for a long time. This type of intrusion can go unnoticed for a lengthy amount of time, and can reap a treasure trove of information for malicious actors. 
Educational Resources
sponsor supplied content
Educational Resources Archive
From The Founder
Against the odds, Huawei is growing its telecoms networking equipment business in the US -- that should be ringing some alarm bells for domestic vendors.
Flash Poll
Live Streaming Video
CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
Between the CEOs
Metaswitch's New CEO Martin Lund Discusses His Role

9|2|15   |   11:27   |   (2) comments


Technology industry veteran Martin Lund joins Metaswitch Networks this week as the company's new CEO. In this interview, Lund discusses his new role and the industry's progress with Light Reading CEO Steve Saunders. Lund believes that the industry disruption caused by SDN and NFV is creating opportunities for companies like Metaswitch – network software providers ...
Telecom Innovators Video Showcase
Nominum on Leveraging the Power of DNS to Deliver Superior Subscriber Experiences

9|2|15   |   07:13   |   (0) comments


Nominum CEO Gary Messiana talks about the challenges service providers face in competing for a much more sophisticated customer, a customer that has heightened expectations for more personalized and compelling digital experiences. Providers are focusing their efforts on delivering higher value subscriber services, retaining their existing customers and increasing ...
Between the CEOs
CEO Chat With Jeff Miller, ActiveVideo

8|28|15   |   19:05   |   (0) comments


Jeff Miller, President and CEO of ActiveVideo, talks to Light Reading founder and CEO Steve Saunders about the impact of virtualization on the TV and video distribution market.
LRTV Huawei Video Resource Center
Vodafone: Mobile Money Is About Customer Trust

8|27|15   |   06.36   |   (0) comments


Light Reading spoke with Vodafone's Ian Ravenscroft about the unique responsibilities and opportunities facing operators handling customers' financial transactions over the network.
Telecom Innovators Video Showcase
Palo Alto Networks on Expanding in the Carrier/Service Provider Market

8|26|15   |   07:54   |   (0) comments


Alfred Lee from Palo Alto Networks tells Steve Saunders about their new chassis-based system, the PA-7080, and how it can benefit service providers compared to legacy firewalls.
LRTV Custom TV
Global Services Forum Preview

8|25|15   |   02:36   |   (0) comments


Light Reading's CEO and Founder Steve Saunders talks about Huawei's upcoming Global Services Forum with the help of Heavy Reading's Patrick Donegan and Teresa Mastrangelo.
Telecom Innovators Video Showcase
Infoblox on DNS Threat Index

8|19|15   |   04:39   |   (0) comments


Dilip Pillaipakam from Infoblox talks to Steve Saunders about his company's core network services.
Between the CEOs
CEO Chat With Ihab Tarazi, Equinix

8|14|15   |   20:18   |   (1) comment


Equinix CTO Ihab Tarazi talks to Light Reading founder and CEO Steve Saunders about the dramatic changes in the data center, cloud and interconnect markets and discusses the impact of SDN and NFV in the coming years.
Telecom Innovators Video Showcase
The Netformx Ecosystem

8|14|15   |   09:39   |   (1) comment


Ittai Bareket, CEO of Netformx, talks with Steve Saunders about the Netformx Ecosystem, which employs cutting-edge prescriptive analytics to help solution providers maximize profits.
Telecom Innovators Video Showcase
Versa Networks on Leveraging VNFs

8|12|15   |   07:37   |   (0) comments


Kumar Mehta, founder and CEO of stealth mode startup Versa Networks, talks with Steve Saunders about how providers can best leverage virtualized network functions (VNFs).
LRTV Custom TV
Transforming the Network Through OPNFV

8|5|15   |   7:09   |   (0) comments


Sandra Rivera, VP Data Center Group; GM Network Platforms Group, Intel Corporation, on OPNFV Arno and how the industry is coming together to accelerate the deployment of NFV and transform the network.
LRTV Huawei Video Resource Center
Huawei ONS Product Demo

8|3|15   |   6:01   |   (0) comments


Huawei shows at Open Networking Summit 2015 in Santa Clara how its SDN and NFV solutions embrace openness.
Upcoming Live Events
September 16-17, 2015, The Westin Galleria Dallas, Dallas, TX
September 16, 2015, The Westin Galleria Dallas, Dallas, TX
September 16, 2015, The Westin Galleria Dallas, Dallas, TX
September 29-30, 2015, The Westin Grand Müchen, Munich, Germany
October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
November 5, 2015, Hilton Santa Clara, Santa Clara, CA
November 17, 2015, Santa Clara, California
December 1, 2015, The Westin Times Square, New York City
December 2, 2015, The Westin Times Square, New York City
All Upcoming Live Events
Infographics
Cisco's cloud and virtualization portfolio can increase business agility and innovation by building a more flexible network architecture.
Hot Topics
T-Mobile CEO Plays Data Traffic Cop
Sarah Thomas, Editorial Operations Director, 8/31/2015
CEO Chat With Bill Gates
Steve Saunders, CEO and founder, Light Reading, 8/31/2015
Time to Monetize Cable WiFi
Alan Breznick, Cable/Video Practice Leader, 8/31/2015
Carolina Town Becomes First US 10-Gig City
Mari Silbey, Senior Editor, Cable/Video, 9/3/2015
Eurobites: Anite in OSS Tie-Up With Nokia
Paul Rainford, Assistant Editor, Europe, 9/4/2015
Like Us on Facebook
Twitter Feed
September 22, 2015
Media Begins With “Me”
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
Technology industry veteran Martin Lund joins Metaswitch Networks this week as the company's new CEO. In this interview, Lund discusses his new role and the industry's progress with Light Reading CEO Steve Saunders. Lund believes that the industry disruption caused by SDN and NFV is creating opportunities for companies like Metaswitch – network software providers with the agility to embrace new technologies quickly and the ability to deliver on substantial projects for global network operators.
The scene: Last Saturday, lunchtime, the interior of a shi-shi-foo-foo eatery in Manhattan's SoHo district.
Cats with Phones
It's a New Age... Click Here
When smartphones replace stuffed animals.