TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Interviews

View of the online attack surface

by Mark Rowe

When it comes to company security and the online attack surface, an outward and inward view is essential says Fabian Libeau, EMEA VP at RiskIQ, a security intelligence platform.

It is no understatement that the 2020s have so far been a formidable experience for cybersecurity experts. First, the global pandemic heralded an unprecedented cyber-crimewave, as criminals sought to exploit rapidly deployed distributed work conditions, as well as a demand for information from the general public. Across the globe, company attack surfaces were weakened, and sophisticated phishing campaigns became constant.

Worldwide businesses were then hit by the first ever large-scale supply chain attack in the form of SolarWinds breach affecting more than 18,000 organisations worldwide. Following this, a Russian-backed attack, targeting a Microsoft Exchange Server remote code execution vulnerability, dwarfed the massive SolarWinds breach and compromised hundreds of thousands of organisations across the planet. Indeed, 2021 has already seen well over a dozen โ€œzero-daysโ€ uncovered โ€“ computer-software vulnerabilities unknown to the software authors โ€“ impacting countless organisations. For todayโ€™s cybersecurity professionals, threats seem to be coming from every angle.

Challenging adversaries

Security teams protecting the attack surfaces of enterprises are now tasked with countering powerful opponents. These teams find themselves on the frontlines of cyber conflicts that mirror geopolitical showdowns. Indeed, Chinese, Russian and North Korean-backed hackers looked to steal from or compromise information of US-aligned companies. These state-backed APTs are, by their very nature, well-funded and sophisticated.

Matching the sophistication of state backed APTs are the online criminal syndicates that are constantly trying to steal data or spread crippling ransomware to strong arm a massive pay-out from a targeted company. One such example is Magecart, which inserts credit card skimmers into company websites to steal customer payment information on a vast scale. For companies to remain safe in the face of such adversaries, situational awareness is vital. However, while companies may have vision into their own networks, often the most successful attacks arise from the vast, hidden expanse of the wider internet. Therefore, true security lies in sweeping threat intelligence across every vector through which a company exists in the digital realm โ€“ this is known as the โ€œonline attack surface.โ€

Security relies upon a holistic view

A holistic view of a companyโ€™s online attack surface relies on two equally important areas of insight โ€“ knowing itself and knowing the enemy. For a company to โ€œknow itself,โ€ IT security teams must have a concrete understanding of every vector through which the company may be exposed on the internet. This is not as simple as just knowing the whereabouts of company assets, such as websites, but having insight into the multiple components that make up these assets. This includes the underlying operating system, frameworks, third-party applications, plugins, trackers, and so on.

These components represent layers of infrastructure that deliver the modern customer experience users now expect of a website. However, it is within these layers that vulnerabilities are exploited beyond the purview of security teams. A worrying dynamic is that many of these components are used as part of the website infrastructure of thousands of companies, meaning that once an exploit is found, cybercriminals are able to attack a vast number of organisations. Security teams must know immediately of flaws found within different website infrastructures, or else their companies will be at risk of a breach.

Unfortunately, an inward view is only half the battle for security teams, and they must also have a clear picture of their enemies to secure their companies from attack. To this end, it is imperative to rely upon in-depth internet reconnaissance to understand threat actors. Specific threat actors will exhibit different tactics, techniques, and procedures โ€“ they will also possess different assets and exploit unique vectors.

Intelligence gathering on the deep and dark webs โ€“ the traditional hiding place of threat actors โ€“ will provide additional context of an adversary. For example, where have they attacked before and where might they attack again or what sort of information they are stealing. These investigations take time as they deal with a huge number of events occurring every day. This being the case, automation is required to integrate internet visibility into core security applications used within security operations. This can take the form of techniques such as reputation scoring and event enrichment to efficiently automate responses.

If security teams are able to maintain both an outward and inward view of their companyโ€™s online attack surface, then they are well positioned to guard against new threats as they arise. This situational awareness is vital, as while modern companies cannot exist without a presence on the internet, the online world is becoming increasingly dangerous.

Related News