What Do You Mean by Cybersecurity Threats?
Cybersecurity threats are any actions taken by malicious actors with the intention to steal data, damage or disrupt computing systems. Cyber threats fall generally into one of the following categories: Malware, Social engineering, Man in the middle (MitM) Attack, Denial of service (DoS) Attack, Injection Attack; these categories are described in detail below.
Cyber threats can come from many sources ranging from hostile nation-states and terrorist groups, to individual hackers, to insider threats by trusted individuals, such as employees or contractors, who misuse their access to commit harmful activities.
Common Sources of Cyber Threats
The following are some of the most frequent sources of cybersecurity threats to businesses:
Nation-states – Countries hostile to the local companies or institutions can be the target of a cyber attack with intent to cause disorder, damage and interfere with communication.
Terrorist organizations—Terrorists conduct cyber attacks aimed at destroying or abusing critical infrastructure, threaten national security, disrupt economies, and cause bodily harm to citizens.
Criminal groups: These are organized groups of hackers who are trying to crack computing systems in order to gain an economic advantage. These groups employ phishing, spam, spyware and malware to defraud and steal private information and conduct online scams.
Hackers – A single hacker attacks the organizations through various attack methods. They are typically driven by self-interest, vendetta, monetary or political interests. A hacker is always looking for new attacks to develop, to enhance his or her criminal skills and personal reputation.
Malicious insiders—An employee who has legitimate access to company assets, and abuses their privileges to steal information or damage computing systems for economic or personal gain. Insiders can be workers, contractors, vendors or associates of the target company. They also can be outsiders with a privileged account that they’ve compromised and are using to pretend to be the owner.
There are Several Types of Cyber Threats
Malware Attacks
Malware is short for “malicious software” – which is the most common type of cyberattack – and it encompasses viruses, worms, trojans, spyware and ransomware. Malware infiltrates a system, usually via a link on an untrusted website or email or an unwanted software download. Installs on the target system, gathers sensitive data, alters and denies access to network elements, and can corrupt and/or stop network operations completely.
The following are the primary types of malware attacks:
A piece of code is inserted into an application (viruses). The malicious code is run when the application is executed.
Worms: Malware that uses software vulnerabilities and/or backdoors to access an operating system. After being deployed in the network, the worm can mount attacks like distributed denial of service (DDoS).
Trojans – Malicious code or software that looks like a harmless program but is concealed in the App, games or in an email attachment. Once downloaded by the unsuspecting user, the trojan takes control of them.
Ransomware: The user or organization is blocked from using their own systems or data because they are encrypted. The attacker usually asks for a ransom to be paid in order to get a decryption key that will let you regain access or functionality, but there’s no assurance that paying the ransom will allow you to return to full access or functionality.
Cryptojacking—attackers deploy software on a victim’s device, and begin using their computing resources to generate cryptocurrency, without their knowledge. Both affected systems can be slow and cryptojacking kits can impact system stability.
Spyware is a type of malware that is installed by an attacker who successfully infiltrates the data of an unsuspecting user, such as that of a customer, including their payment data and/or passwords. Spyware can impact on the desktop browser, mobile telephones and desktop applications.
Adware: User’s browsing information is gathered to profile the user’s habits and interests so that advertisements can be targeted to the user. Adware is similar to spyware but does not involve installing software on the user’s computer and is not always malicious, but can be used without the user’s consent and can invade the user’s privacy.
Fileless malware – there isn’t any software installed in the operating system. Malicious functions are added to native files, such as WMI and PowerShell. It is a sneaky attack and is hard to detect (antivirus cannot detect it) as the attacked files are recognized as legitimate files.
Rootkits, programs that are embedded into software, firmware, hypervisors or operating system kernels that allow remote administration of a computer. The attacker can initiate the operating system in a compromised environment, completely control the computer and spread more malware.
Social Engineering Attacks
Social engineering is the process of luring the user into giving the attacker access to the system. The victim gives personal information or unknowingly loads malware onto a device as the attacker appears to be a legitimate entity.
Here are some of the main types of social engineering attacks:
Baiting – The attacker sets a trap for a user by offering them something desirable such as a free gift card or some other enticement. The victim gives out sensitive data, like passwords, to the attacker.
Pretexting: Like baiting, except that the attacker is trying to coax the target to reveal information using deception. This usually means pretending to be someone of authority such as an IRS officer or a police officer that will force the victim to do what they want.
Phishing – The attacker emails as if they were from a trusted source. Phishing typically includes sending phishing email messages to as many people as possible, or it can be more targeted. For instance, “spear phishing” is targeting an individual and “whaling” is targeting a high-value individual like a CEO.
Vishing (voice phishing): The imposter uses the telephone to convince the target to disclose sensitive information or give access to the target system. Vishing is usually used against the elderly, but can be used against anybody.
Smishing (SMS phishing)—The attacker uses text messages as the means of deceiving the victim.
Piggybacking- an authorized user allows another individual to “piggyback” off their authorization. Access to a user who has lost their credential card can be given to an employee by an employee, for instance.
Tailgating – an unauthorized person enters an authorized area after the authorized person has opened the door, such as someone walking in after the door has been opened. Tailgating, as described above, is a similar technique but the individual being “tailgated” does not know that he/she is being tailgated.
Supply Chain Attacks
Supply chain attacks are a new type of cybersecurity threat to software developers and vendors. To infect regular applications and spread malware through source code, build processes or software update systems.
Attackers search for unsecured network protocols, server infrastructure, and coding techniques, and are able to exploit these to compromise build and update process, modify source code, and conceal malicious code.
The danger of supply chain attacks is particularly strong because attackers are compromising trusted applications, which have been signed and certified by their vendors. In a software supply chain attack, the software supplier does not know that the program or update is tainted with a malware. Malicious code operates under the same trust and privileges of the compromised app.
There are several types of supply chain attacks, such as:
- Breach of build tools or development pipelines
- Breach of code signing processes or developer accounts
- Virus or worm that is delivered as automatic software updates to hardware or firmware components.
- Malicious code, pre-installed on physical devices.
Man-in-the-Middle Attack
A Man-in-the-Middle (MitM) attack is a method in which an attacker is able to intercept the communication between two endpoints, e.g., user and application. The attacker can listen to the communication, steal sensitive information and pretend to be either of the parties taking part in the communication.
Some examples of MitM attacks are:
Wifi eavesdropping – When an attacker establishes a Wi-Fi network pretending to be a legitimate entity (e.g. a business) to which users can join. It is used to spy on the traffic of the connected users, and steal information like payment card information and login credentials.
Email spoofing: The attacker sends an email as if it had come from a place like a bank, and convinces people to provide sensitive information or wire money to the attacker. The instructions the user receives are apparently from the bank, but are actually from the attacker.
DNS spoofing: DNS (Domain name server) is spoofed, and a user is redirected to a malicious website that pretends to be a legitimate one. The attacker can either divert traffic from the legitimate site, or gain access to the user’s credentials.
An internet protocol (IP): Address links users to a certain website is known as IP spoofing. An attacker can make the website appear to be something else by trickery, using another IP address to make it look that way.
HTTPS spoofing—HTTPS is generally considered the more secure version of HTTP, but can also be used to trick the browser into thinking that a malicious website is safe. The attacker uses “HTTPS” in the URL to conceal the malicious nature of the website.
Denial-of-Service Attack
A Denial-of-Service (DoS) attack is a type of attack that sends a lot of traffic to the targeted system, making it unable to perform its intended actions. Multiple device attacks are called distributed denial-of-service (DDoS) attacks.
There are several techniques used in a DoS attack:
HTTP Flood DDoS: The attacker floods the application or web server with HTTP requests that are valid to the application or web server. This technique does not need a high bandwidth nor malformed packets, and usually it attempts to use as many resources as possible in the target system for each request.
SYN flood DDoS—Initiating a Transmission Control Protocol (TCP) connection sequence involves sending a SYN request that the host must respond to with a SYN-ACK that acknowledges the request, and then the requester must respond with an ACK. A possible attack on this sequence is to use SYN packets but fail to return SYN-ACKs from the host to tie up the servers resources.
UDP Flood DDoS (User Datagram Protocol Flood Distributed Denial of Service): A remote host is sending User Datagram Protocol (UDP) packets to random ports. This technique is such that it consumes the host resources by making the host search for the applications on the affected ports and respond with “Destination Unreachable” packets.
ICMP flood—The target is overloaded with many ICMP Echo Requests using both incoming and outgoing bandwidth. The server(s) may attempt to send an ICMP Echo Reply packet in response to each request, but it is unable to handle the rate of requests, causing the system to slow down.
Network Time Protocol (NTP) amplification is when NTP servers are available for anyone to access and may be used by an attacker in sending a massive amount of UDP packets to a victim server. The ratio of queries to responses is 1:20 to 1:200, making it an amplification attack as it is possible for an attacker to use open NTP servers to launch high volume or high bandwidth DDoS attacks.
Injection Attacks
Injection attacks take advantage of multiple vulnerabilities to directly inject malicious input into the code of a web application. Successful attacks may expose sensitive information, execute a DoS attack or compromise the entire system.
Some of the key vectors for injections attacks are:
SQL injection: An attacker submits an SQL query in an end user input point (eg, a web form or comment field). A vulnerable application will return the attacker’s data to the database, and run any SQL statements the attacker has inserted into the query. Most of the web applications are based on Structured Query Language (SQL) databases and thus are susceptible to SQL injection. A new variant on this attack is NoSQL attacks, targeted against databases that do not use a relational data structure.
Code injection – If vulnerable, attacker can inject code into the app. The web server runs the malicious code as though it’s a part of the app.
OS command Injection – Attacker can use command injection vulnerability to send commands to the operating system. This enables the attack to steal OS data or gain control over the system.
LDAP injection: The attacker passes in characters to manipulate Lightweight Directory Access Protocol (LDAP) queries. A system is vulnerable if it uses unsanitized LDAP queries. Such attacks can be quite serious because LDAP servers can contain user accounts and credentials for an entire organization.
XML eXternal Entities (XXE) Injection—An attack is carried out using specially-constructed XML documents. It’s different from other attack strategies, because it takes advantage of the fact that he has a vulnerable legacy XML parser, not unvalidated user input. XML documents can be used to traverse paths, execute code remotely and execute server-side request forgery (SSRF).
Cross-Site Scripting (XSS)—An attacker’s text string includes malicious JavaScript. The code is loaded into the target’s browser so that the attacker can direct the user to a malicious site or steal the session cookies and hijack the user’s session. Any application that fails to sanitize user input, stripping away any JavaScript code, is susceptible to XSS attacks.
Cybersecurity Solutions
Cybersecurity solutions are the tools that organizations employ to help protect them from cybersecurity threats, accidental damage, physical disaster and other threats. The main security solutions are:
Application security—Used to test software application vulnerabilities during development and testing, and protect applications running in production, from threats like network attacks, exploits of software vulnerabilities, and web application attacks.
Network Security – Monitors the flow of traffic on a network; detects potentially malicious traffic; and helps organizations to block, filter or mitigate threats.
Cloud Security—Applies security controls across public, private and hybrid cloud, identifies and remediates misconfigured security and vulnerabilities.
Endpoint security: Is implemented on the endpoint devices, like servers and employees computers that can block attacks, including malware, unauthorised access and vulnerabilities in operating systems and browsers.
Internet of Things (IoT) security—Connected devices typically do not have built-in security, and are often used to store sensitive information. IoT security solutions help gain visibility and improve security for IoT devices.
Threat intelligence: This is a combination of threat actor and attack signature data from various sources that add context to security events. Cybersecurity Threat intelligence data can also be used to identify attacks, comprehend them, and formulate the most effective response.
Imperva Application Security
Imperva offers a complete application protection solution for applications, APIs, and microservices:
Web Application Firewall – World-class web traffic analysis of your Web Applications to prevent attacks.
Runtime Application Self-Protection (RASP) – Real-time detection and prevention of attacks from your application’s runtime environment that follows your applications. Prevent external attacks and injections and minimize vulnerability stack.
API Security – Automated API security provides protection of your API endpoints as they are published, protecting your applications from exploitation.
Advanced Bot Protection – Deter business logic attacks via all access points – websites, mobile apps and APIs. Be able to see and manage bot traffic to prevent online fraud with account takeover or price scraping by competitors.
DDoS Protection – Defend against attack traffic at the edge – maximize uptime and performance without compromising business continuity. Secure your on premises or cloud-based assets – hosted in AWS, Microsoft Azure, or Google Public Cloud.
Attack Analytics – Ensures complete visibility with machine learning and domain expertise across the application security stack to reveal patterns in the noise and detect application attacks, enabling you to isolate and prevent attack campaigns.
Client-Side Protection – See and control third party JavaScript code to limit supply chain fraud, data breach and client-side attacks.
Imperva Application Security
At the data level, Imperva safeguards all cloud data stores to ensure compliance, and maintains the agility and cost benefits you achieve through your cloud investments:
Cloud Data Security – Make it simple to secure your cloud databases to catch up and keep up with DevOps. Imperva’s solution allows cloud-managed services users to quickly achieve visibility and control of their cloud data.
Database Security – Imperva provides you with data analytics, security and response across your data assets – on-premise and in the cloud – for the risk visibility you need to prevent data breaches and avoid compliance incidents. Connect with any database and get immediate visibility, universal policies and time to value.
Data Risk Analysis – Automate the detection of non-compliant, risky or malicious data access behavior across all of your databases enterprise-wide to speed remediation.