Skip to content

網絡安全意識是什麼?為什麼重要?

網絡安全課題中有一句古老格言:「人類是安全鏈中最薄弱的環節!」今天,這個情況變得越來越真實。我們可以把這個薄弱環節,扭轉成一道堅實的防線嗎?關鍵就是網絡安全意識。

研究分析了 2021 年的數據洩露事件,82% 涉及人為因素。員工成為黑客的首要目標,是現代網絡威脅中不可避免的事實。因此為員工提供所需的安全知識和工具,並讓他們了解為何自己會身處於風險之中,是網絡安全意識的基本原則。

嚴重的網絡安全漏洞,無論是第三方攻擊,抑或是意外的數據洩露,都可能導致重大的財務和聲譽損失。最近一項研究顯示,遭受此類情況的企業,有 20% 幾乎因此破產;另一項研究亦指出,全球數據洩露的平均成本比以往任何時候都高,超過 420 萬美元。

幾個趨勢都凸顯了網絡安全意識的迫切需求:

1)密碼:原因很簡單,我們本能地知道如何使用,因此也成為黑客的首要目標。黑客會設法誘騙員工交出密碼,甚至猜測密碼。根據一項估計,超過一半的美國員工仍然會用紙筆來記錄密碼。

2)社會工程學:黑客會使用說服性技術(例如時間壓力和假冒)來誘騙受害者執行他們的命令。最好的例子是網絡釣魚電子郵件、文本(又名 smishing)或電話(又名 vishing)。

3)網絡犯罪經濟:黑客擁有一個複雜的地下暗網,通過這些暗網買賣數據和服務,從防彈託管(bulletproof hosting)到勒索軟件即服務,應有盡有。

4)混合工作模式:一般情況下,家庭網絡和電腦等裝置的保護級別都不如公司企業。新時代工作模式,例如在家工作,或將工作設備用於個人用途,都為黑客攻擊打開了大門。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

The Good News and Bad News About 0-Day Attacks

The team at Google Project Zero deserves a lot more recognition than they receive. Since 2014, they have been systematically studying 0-days (e.g. previously unknown vulnerabilities) to understand this unique cyber threat in depth. They research where 0-days are being found, how hackers are exploiting them, and what trends are developing. And, on an annual basis, they compile their findings into a comprehensive and prescriptive report. The latest report is out, covering attacks throughout 2021, and it has information everyone should be aware of – both good news and bad news.

Bad News – Attacks Have Increased Significantly

There were 58 0-days detected and disclosed in the wild in 2021, the most the Google team has ever recorded. This number is more than double the previous high of 28. Even more alarming, it’s a substantial increase over the 2020 total of 25 0-days. These numbers leave little doubt that 0-days remain a serious threat that could be getting (much) worse than ever before. The 2022 totals seem certain to set new records.

Good News – Detection and Disclosure are Getting Better

The alarming uptick in 0-days could actually be a positive sign according to the Google researchers. They attribute the 2021 totals to improvements in detection – we are catching more 0-days than we could before. They also credit a culture shift around disclosing 0-days. Instead of hiding these flaws away, as was often the case in the past, companies are being upfront about them, pushing the overall total upwards. This would suggest the 0-day problem is not necessarily getting worse but rather we are starting to see its true scope and scale. That’s progress.

Good News – 0-Days are in a Rut

Last year’s 0-days all share a notable feature: they leverage the same attack surfaces, bug patterns, and exploit techniques that we have seen in the past. Given the large annual total, we would expect to see a number of innovative, unique, and unknown tactics in play. That wasn’t the case – only two 0-days in 2021 were considered novel by the Google team. By and large, recent 0-days look a lot like the ones that came before them, which could suggest that hackers lack either the means or skills to push them in new directions.

Bad News – Old Exploits Remain Potent

Another, arguably more valid way to interpret the lack of innovation in 0-days is that it’s unnecessary. Existing methods still work, so hackers have little incentive to devise new ones. It has been the goal of developers and cyber defenders to “make 0-days harder” for years now, but that effort seems to have accomplished relatively little, allowing hackers to return to the same well instead of making them return to the drawing board. The huge number of familiar 0-days in 2021 suggests that while detection and disclosure are improving, actual defenses are not, which raises troubling (but important) questions about how we approach this issue.

Preparing for the Future of 0-Days

The Google report makes clear that we have made some progress on 0-days but still have much left to do. The question is how we get from record high 0-days to record lows?

Above all, it will take cooperation, communication, and collaboration among stakeholders inside and outside cybersecurity. 0-days are a complicated beast, both to prevent and remediate, that exceeds what any team, department, or company can address on its own. A culture of mutual defense and shared responsibility has an obvious advantage: it gives the defenders vastly more resources than the attackers could ever muster.

But it all depends on bringing together different ideas, experiences, and perspectives, which is where the vsociety comes in. This social community provides a space for voices from across cybersecurity and the larger tech landscape to unite around issues like 0-days and so much more. The conversation starts here.

Photo by Adi Goldstein

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About VRX
VRX is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×