{"id":3300,"date":"2013-12-11T11:30:54","date_gmt":"2013-12-11T03:30:54","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=3300"},"modified":"2013-12-11T11:31:23","modified_gmt":"2013-12-11T03:31:23","slug":"10-security-predictions-2014","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2013\/12\/11\/10-security-predictions-2014\/","title":{"rendered":"10 security predictions for 2014"},"content":{"rendered":"<p>CyberArk has outlined its security predictions for 2014. 2013 has seen many high-profile security breaches, including the NSA-Edward Snowden case, involving the exploitation of privileged or administrator accounts. The theft, misuse and exploitation of privileged accounts has become an increasingly key tactic in each phase of an advance persistent threat (APT) attack cycle, and this will largely continue into 2014.<\/p>\n<p><strong>1. State-Sponsored Attacks Will Become Splintered and More Common<\/strong><br \/>\nThe revelations of the spying programmes by the NSA, GCHQ, and other intelligence agencies have established a precedent how governments use the Internet and technology for national defence. More and more countries are expected to embrace and go beyond this approach \u2013 both in terms of passive surveillance and in aggressive cyber-attacks.\u00a0 The major geopolitical players (the West, Iran, China, and Russia) will continue to refine their cyber efforts, which will have a major impact on the powers of rogue nations and state-sponsored terrorist groups.\u00a0 As with Stuxnet, these attacks are dismantled and re-purposed \u2013 the attacks become commoditised and trickle down to the rogue elements.\u00a0 There will be more attacks of this nature occurring, for a wider array of reasons \u2013 economics, politics, and terrorism.<\/p>\n<p><strong>2. Encrypt Everything<\/strong><br \/>\nThe fallout of the Edward Snowden breach will continue to have a major impact on everything we do. As companies like Google continue the call to now \u201cencrypt everything,\u201d new encryption standards will emerge. As encryption methods develop, frontiers will be reached in encryption and hash cracking, whether by novel mathematical methods or by dedicated hardware, such as this 25 GPU-based platform.<\/p>\n<p><strong>3. Malware Prevention Hits the Rocks<\/strong><br \/>\nThe death of the perimeter has been predicted to some degree for the past 10 years. While there will also be a market for perimeter oriented technologies, there will be wide scale disillusionment with technology like next-generation firewalls and sandboxing, primarily driven by the fact that more and more companies will experience targeted breaches, despite having installed these solutions.<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_791\" style=\"width: 490px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/security_.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-791\" class=\"size-full wp-image-791\" alt=\"Artwork by Janis Dei Abad\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/security_.jpg\" width=\"480\" height=\"280\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/security_.jpg 480w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/security_-300x175.jpg 300w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/a><p id=\"caption-attachment-791\" class=\"wp-caption-text\"><strong><em>Artwork by Janis Dei Abad<\/em><\/strong><\/p><\/div>\n<p><strong>4. Increased Spending on Insider Threat Prevention<\/strong><br \/>\nThe insider threat is ever present and hangs over every company. The Edward Snowden incident continues to reverberate across industries.\u00a0 Hence there will be a much greater emphasis on the person aspect of insider threat prevention in 2014.\u00a0 Companies will spend more money and time on employee screening and monitoring, with a stronger focus on outsourced and contracted positions. A much greater emphasis on monitoring and controlling privileged users is also expected.<\/p>\n<p><strong>5. Social Engineering on Steroids<\/strong><br \/>\nSocial engineering has always been one of the best assets cyber-attackers have at their disposal to breach perimeter security. From spoof emails to fake websites, attackers use the human condition to bypass perimeter security and deliver their malware payload directly into a network. There will be more attacks like the \u2018damsel in distress,\u2019 a targeted attack aimed at male IT workers that used fake social profiles of attractive females who were posing as new hires and requesting \u2018help,\u2019 or fake job proposals and phone calls from \u2018head hunters\u2019 to solicit information \u2013 all to get one employee to unknowingly open the doors for an attack.\u00a0 As online identity increasingly becomes tied to social networking sites, the sophistication of social engineering attacks will grow.<\/p>\n<p><strong>6. Hacking the Supply Chain<\/strong><br \/>\nCyber attackers revealed a similar strategy in 2012 and 2013 by targeting technology vendors (especially security vendors) in an effort to build backdoors or bypass security at corporate clients. This attack vector will worsen in 2014, as more cyber attackers infiltrate companies well down the supply chain to implant malicious code into software products that eventually get installed at a later date in the real target company\u2019s network.<\/p>\n<p><strong>7. Controlling a Connected House<\/strong><br \/>\nResearchers have shown how to use hardcoded and default passwords as backdoors to many enterprise and consumer products.\u00a0 This year, researchers (or attackers) will demonstrate how easy it is to hack smart meters through default passwords.\u00a0 Through this access, hackers will be able to commandeer the environmental controls of a house.<\/p>\n<p><strong>8. Organising Crime<\/strong><br \/>\n2014 will show just how far organised crime can reach into the cyber world as more and more groups target law enforcement networks in order to steal information on current investigations in an effort to stay ahead of the long arm of the law.<\/p>\n<p><strong>9. Black Fridays<\/strong><br \/>\nYes, there is a black market for cyber criminals, where malware, hacking tools and assorted other cyber-attack related items are sold.\u00a0 In 2014, administrative passwords and privileged credentials will become the number 1 hot item on the cyber black markets.\u00a0 The world has witnessed a glimpse of this already in 2013 in the indictment for hacker and black market entrepreneur Andrew James Miller.<\/p>\n<p><strong>10. Cloudy Days Ahead<\/strong><br \/>\nIt is simply a matter of time when one of the main cloud providers is breached \u2013 causing wide spread disruption and downtime.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The theft, misuse and exploitation of privileged accounts has become an increasingly key tactic in each phase of an advance persistent threat (APT) attack cycle, and this will largely continue into 2014.<\/p>\n","protected":false},"author":6,"featured_media":791,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,25],"tags":[286,1071],"class_list":["post-3300","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-software","tag-it-security","tag-predictions"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/3300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=3300"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/3300\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/791"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=3300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=3300"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=3300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}