As Internet users become more attuned to well-known spamming and phishing attacks, cyber criminals have to invent new ways to lure them into opening a malware-laden email or clicking on a link that goes to a malicious website.
As an avid news reader, I know I’d be much more likely to click on one of the above headlines than on an email of cute kitten pictures.
Unfortunately, the truth remains that individuals are a weak link in the battle against cyber criminals. Many continue to click on links or attachments sent via email without taking any steps to verify the origin of the email or the validity of the link or attachment. It only takes one click to for an attacker to establish a foothold in the target’s systems. The 2013 Verizon Data Breach Investigations Report finds that sending just three emails per phishing campaign gives the attacker a 50 per cent chance of getting one click. With six emails the success rate goes up to 80 per cent and at 10 it is virtually guaranteed. Social media helps spur success, enabling cyber criminals to gather information about us so they know how to more effectively entice targets to click on that malicious email.
We know that security as a people problem is not going away anytime soon, and the advent of the Internet of Everything is going to make this even more of a problem. Not only will users be able to inadvertently expose their systems to malware from their laptops and tablets, they will also be able to click on links from their smartwatches, cars, etc. It won’t take long once that malware is on their device for it to proliferate across the entire network and any connected devices, simply from a seemingly trusted news link sent from a “friend’s” email address.
In order to address this growing concern, we need to move beyond securing devices and data to addressing the people and process aspects of this problem via education. Organisations must recognise this gap in their security and implement internal programs to ensure users know how to recognise and cease to click on potential malware. They must also understand when and how to inform the organisation of any suspicious occurrences so future attempts can be minimised and/or blocked.
Even with the best of education, malware will still make its way onto the network. Organisations need security solutions that couple visibility and control to help protect against these inevitable attacks.
You can’t protect what you can’t see. You need security solutions that have contextual awareness and can see and intelligently correlate extensive amounts of event data related to IT environments – applications, users, devices, operating systems, vulnerabilities, services, processes, network behaviours, files and threats.
Attackers are learning from each attack to increase their chances for success. As defenders, we need to do the same. Education is an essential component of any well-rounded security strategy. When combined with visibility and control, it can help minimise cyber attacks and protect our networks, even from the actions of well-intentioned news junkies.
Sutee Assawasoontarangkoon is country manager of Sourcefire (Thailand) that is now a part of Cisco System.