{"id":30633,"date":"2018-01-09T09:19:44","date_gmt":"2018-01-09T01:19:44","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=30633"},"modified":"2018-01-09T09:24:01","modified_gmt":"2018-01-09T01:24:01","slug":"cybersecurity-past-and-future-whats-come-this-year-and-what-is-coming","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/01\/09\/cybersecurity-past-and-future-whats-come-this-year-and-what-is-coming\/","title":{"rendered":"OPINION | The past and future of cybersecurity"},"content":{"rendered":"<div id=\"attachment_30635\" style=\"width: 250px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/01\/Anthony-Giandomenico-Fortinet.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-30635\" class=\"size-medium wp-image-30635\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/01\/Anthony-Giandomenico-Fortinet-240x300.jpg\" alt=\"\" width=\"240\" height=\"300\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/01\/Anthony-Giandomenico-Fortinet-240x300.jpg 240w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/01\/Anthony-Giandomenico-Fortinet.jpg 400w\" sizes=\"auto, (max-width: 240px) 100vw, 240px\" \/><\/a><p id=\"caption-attachment-30635\" class=\"wp-caption-text\"><strong><em>Anthony Giandomenico, Senior Security Strategist, Fortinet<\/em><\/strong><\/p><\/div>\n<p><strong><em>By Anthony Giandomenico<\/em><\/strong><\/p>\n<p>You know what they say about history: Those who don\u2019t learn from it are doomed to repeat it.\u00a0Another maxim about the future holds true, too: To predict the future, simply look at the\u00a0<a href=\"https:\/\/blog.fortinet.com\/2017\/09\/20\/for-cybercriminals-iot-devices-are-big-business-part-two\">past<\/a>.\u00a0With that in mind, here\u2019s a quick overview of the current state of cybersecurity, along with what lies on the horizon and what organizations can do to secure their networks.<\/p>\n<p><b>Mid-Sized Companies and the Cloud<\/b><\/p>\n<p>Mid-sized companies are facing a Scylla-and-Charybdis moment with respect to the cloud; it offers huge business benefits but huge risks as well.\u00a0Research\u00a0shows that mid-sized firms recently saw higher rates of botnet infections, revealing that these firms deal with more than their fair share of security problems. It is possible that cybercriminals see mid-sized organizations as a \u201chappy medium\u201d because they often do not have the same level of security resources and technologies as large enterprises but still have valuable data assets. At the same time, the attack surface for mid-sized firms is growing at a faster rate than that of larger enterprises due to faster cloud adoption rates.<\/p>\n<p>The cloud continues as a point of vulnerability because its services are centralized and present a huge potential threat landscape. Its complex, hyper-connected networks can produce a single point of failure. Rather than hacking a dozen businesses, criminals can hack a single cloud environment and potentially have access to data from dozens or hundreds of organizations, or wipe out an entire range of services with a single attack. This is the exact scenario by which the Mirai botnet took out a DNS hosting provider.<\/p>\n<p>The success of IoT botnets like Mirai, Hajime and Reaper fuels the\u00a0<a href=\"https:\/\/blog.fortinet.com\/2017\/11\/14\/fortinet-fortiguard-2018-threat-landscape-predictions\">prediction<\/a>\u00a0that criminals will use artificial intelligence (AI) to detect a weakness and then use it to cripple a service that generates millions of dollars a day for the provider while disrupting service for potentially hundreds or thousands of businesses and tens of thousands or millions of their customers.<\/p>\n<p><b>The Trouble with Botnets<\/b><\/p>\n<p>In the\u00a0last quarter, many companies experienced the same botnet infections multiple times. This could be due to one of two reasons. Either the organization did not thoroughly understand the total scope of the breach and the botnet went dormant, only to return again after normal business operations resumed, or they never found the root cause or \u201cpatient zero.\u201d<\/p>\n<p>As unsecured IoT devices become more sophisticated, and attack methodologies become more intelligent, there is the real potential to create swarms of compromised IoT devices that could indiscriminately attack like a hive of angry bees. It is highly probable that cybercriminals will replace botnets with intelligent clusters of compromised devices built around swarm technology to create more effective attack vectors with minimal supervision, or even autonomously.<\/p>\n<p>This would become a hivenet rather than a botnet, and it would be able to use peer-based self-learning to effectively target vulnerable systems at an unprecedented scale. Hivenets will be able to use swarms of compromised devices to identify and tackle different attack vectors all at once. As it identifies and compromises more devices, a hivenet would be able to grow exponentially, widening its ability to simultaneously attack multiple victims.<\/p>\n<p><b>Intelligent Defenses<\/b><\/p>\n<p>Security threats like those discussed above demand the latest in security strategies and technologies, but they also require good, old-fashioned cyber hygiene. After all, the best locks on the planet cannot secure a door that\u2019s been left open. So then, the first order of business is to identify all your authorized and unauthorized assets within your environment. You have to know what you\u2019ve got in order to know what you\u2019re protecting.<\/p>\n<p>It is also important to limit user privileges; not everyone needs administrator credentials. In addition, keep your assets updated and patched, and limit applications to only those with a business need. Using unnecessary applications enlarges the attack surface and increases the complexity of protecting the environment.<\/p>\n<p>As for breaches, have a documented plan for how you will detect, analyze, respond to and recover from a breach. Ensure you focus on properly identifying the full scope of the breach and forensics analysis to determine how the threat got there in the first place.<\/p>\n<p><b>Toward Integrated Security<\/b><\/p>\n<p>Finally, the best defense against today\u2019s intelligent and automated threats is an integrated, collaborative and highly adaptive\u00a0<a href=\"https:\/\/www.fortinet.com\/corporate\/about-us\/security-fabric.html\">security fabric<\/a>. If you can get the fabric-based security system right, using AI applications such as machine learning, you will have the quintessential security defense system, and will be able to survive this year\u2019s threats as well as next year\u2019s.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Anthony Giandomenico You know what they say about history: Those who don\u2019t learn from it are doomed to repeat it.\u00a0Another maxim about the future holds true, too: To predict the future, simply look at the\u00a0past.\u00a0With that in mind, here\u2019s a quick overview of the current state of cybersecurity, along with what lies on the [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":30635,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[5498,495,169,286],"class_list":["post-30633","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-botnets","tag-cybersecurity-and-cybercrime","tag-fortinet","tag-it-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=30633"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30633\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30635"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=30633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=30633"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=30633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}