Cybercrime has emerged as a big business worldwide, says Shantanu Ghosh, vice-president & managing director, India product operations, Symantec. An increasing number of sophisticated cyberattacks have been discovered in recent months. Security threats continue to evolve, sometimes faster than the tools designed to protect against them, he tells Sudhir Chowdhary in a recent conversation. Excerpts:
Why should consumers use caution when accessing the internet?
The past few years have witnessed a dramatic shift in the threat landscape. The motivation of cyber attackers has moved from fame to financial gain and malware has become a successful criminal business model with billions of dollars in play.
We have now entered a third shift in the threat landscape?one of cyber-espionage and cyber-sabotage. Cyber-espionage did not begin with Stuxnet, and crimeware does not end with it. But, Stuxnet was a marker. It is a clear indication that the world is changing and the threat landscape will be different than the previous years. Stuxnet affected industrial control systems used in critical infrastructure in over 155 countries, and India was the third most infected country. Targeted attacks are growing, with the number of daily targeted attacks increasing from 77 per day to 82 per day by 2011-end. Targeted attacks use social engineering and customised malware to gain unauthorised access to sensitive information.
Cyber attacks are growing in sophistication too. What is Symantec?s view on this?
An increasing number of sophisticated cyber attacks have been discovered over the past couple of years. From Stuxnet to the Flamer to Shamoon, each of these attacks had a specific goal and target and are very different from the mass cyber threats of the past. These attacks indicate the dawn of the era of cyber-sabotage and cyber-espionage, and while many may believe that such sophisticated threats will not affect anyone apart from the intended target, the truth is each of them had collateral damage.
According to the Symantec Internet Security Threat Report, targeted attacks and APTs (advanced persistent threats) will continue to be a serious issue and the frequency and sophistication of these attacks would increase. Also techniques and exploits developed for targeted attacks would trickle down to the broader underground economy and be used to make regular malware more dangerous. The objective of an APT may include military, political or economic intelligence gathering, confidential or trade secret threat, disruption of operations, or even the destruction of equipment.
Does the deployment of advanced security solutions helps to substantially reduce the cost and impact of these attacks?
The threat landscape is evolving as cybercriminals become more sophisticated, stealthy and insidious with their attacks. IT departments are dealing with a change in the number of endpoints as employees are bringing an increasing number of devices into the workplace. Once restricted to PCs on the desk and servers in the datacentre, the term now covers laptops, smartphones, tablets, virtual servers and virtual desktops.
There is no silver bullet or single solution that will prevent all attacks. To reduce the risk of a successful cyber attack, there are some steps any organisation can take. First, assess the risk. It?s vital that organisations identify and classify confidential information. Organisations must know where sensitive information resides, who has access to it, and how it is entering or leaving your organisation.
Second, minimise the risk.
Organisations must implement a multi-layer protection strategy to minimise the risk of exploited endpoints. In addition to traditional antivirus, firewall, and host intrusion protection technology, organisations should deploy the latest innovations in endpoint security, such as reputation based security and real-time behavioural monitoring. These newer technologies provide additional efficacy in the battle to thwart many of new cyber-attacks. Finally, organisations must patch applications and systems regularly.
More cyber attacks are hitting social networks too…
Exploiting the popularity of social networks for the purposes of distributing spam, malware, and phishing attacks is quite common these days. The large user base and growing popularity social networks is the main reasons that spammers are continually lured into this lucrative business.
A social medium is perfect for social engineering: it?s easier to fool someone when they think they are surrounded by friends. A recent Symantec report said that more than half of all attacks identified on social networking websites were related to malware hosted on compromised blogs and Web communications websites. It?s becoming important for users to be cautious and mindful of their online behaviour. Because chances are, the passwords that many people use to log in to their social networking accounts are the same ones they use to access other online accounts, which is a big motivation for cyber criminals to target social media.
A recent Symantec report revealed that 82% of Indian enterprises allow employees to use social networking at work. This is a threat not only to individuals but also businesses, since compromising one user can compromise confidential data on the network.