HPE SimpliVity tolerates simultaneous drive failures without data loss, and built-
in data protection and disaster recovery features help keep data safe.
Réplicas de usuarios finales
Takedown Service es el nuevo servicio de Kaspersky. Un servicio
que gestiona de manera integral la eliminación de dominios maliciosos y
de phishing. Esta nueva solución, unida a la herramienta Kaspersky Digital
Footprint, que ofrece la visión que tiene el atacante de los recursos de la
empresa, permite garantizar la protección eficaz de los servicios online de las
empresas y su reputación.
Kaspersky Takedown Service permite eliminar con rapidez cualquier dominio
de phishing malicioso sin importar su ubicación. Para ello, el servicio prepara
todas las pruebas necesarias, incluida una copia del sitio web, capturas de
pantalla y volcado de tráfico. Tras esto, envía la solicitud de eliminación a la
autoridad local o regional pertinente que tiene los derechos legales para cerrar
el recurso. El cliente es informado, mediante notificaciones, de cada paso del
proceso hasta que el dominio quede eliminado con éxito.
Este nuevo servicio puede adquirirse de manera independiente o como parte
de la suscripción de Digital Footprint Intelligence (DFI). En el primer caso, los
clientes pueden enviar solicitudes para eliminar ciertos dominios no deseados
que descubrieron a través de la cuenta de empresa de Kaspersky, y en el
segundo, el servicio DFI se encargará de identificar los recursos maliciosos o
de phishing que atacan al cliente. El paquete estándar incluye diez
eliminaciones al mes y puede personalizarse según las necesidades de cada
cliente.
“Kaspersky Digital Footprint Intelligence, reforzado con Takedown Service, es
un complemento importante de nuestra cartera de soluciones de inteligencia de
amenazas (TI)
La huella digital es el rastro que dejas al navegar en internet. Cada vez que haces un
“clic” o das un “me gusta” en las redes sociales, o cuando usás una aplicación desde
tu celular o tu computadora, dejás información personal. Los datos que genera tu
actividad en la internet crean lo que se llama “huella digital”.
Los dominios maliciosos son aquellos utilizados por los cibercriminales con el fin de
realizar conexiones con servidores command and control, robar credenciales a través
de campañas de phishing o distribuir malware.
En muchas ocasiones, estos dominios comparten entre sí ciertas características
léxicas que a simple vista pueden llamar la atención. Por ejemplo, en campañas de
phishing son relativamente comunes los dominios con TLD xyz, top, space, info, email,
entre otros. De igual manera, los atacantes utilizan técnicas DGA (Domain Generation
Algorithm) para crear dominios aleatorios con los que exfiltrar información como, por
ejemplo, istgmxdejdnxuyla[.]ru. Otras propiedades llamativas pueden ser un exceso de
guiones, dominios de varios niveles o dominios que intentan suplantar organizaciones
legítimas como sería el caso de [Link][.]com y [Link][.]xyz.
Con la digitalización en auge, las organizaciones navegan a miles de dominios
diferentes, lo cual dificulta la detección de dominios maliciosos entre tanto tráfico
legítimo. En una organización de tamaño medio, se registra a diario tráfico de entre
3000 y 5000 dominios. Este volumen hace inviable llevar a cabo su análisis de manera
manual. Tradicionalmente, parte de este proceso de detección se automatiza mediante
reglas de búsqueda de patrones, por ejemplo, reglas para hallar dominios con TLD
(Top Level Domain) utilizados en campañas de phishing, que contengan el nombre de
grandes empresas y no sean los legítimos o que tengan más de X caracteres.
En los últimos años se ha popularizado el empleo de diversas técnicas y algoritmos de
Inteligencia Artificial, especialmente aquellos relacionados con Machine Learning, para
llevar a cabo algunas de las tareas del ámbito de la Ciberseguridad, como la detección
de dominios maliciosos. A lo largo de tres artículos se verá un ejemplo de cómo se
puede emplear este tipo de técnicas y algoritmos para reducir drásticamente la
cantidad de información que los analistas de Seguridad han de procesar de manera
manual, y automatizar en la medida de lo posible la labor de detección.
Antes de pasar al siguiente artículo, conviene recordar la diferencia entre algoritmos
de aprendizaje supervisado y no supervisado. A grandes rasgos, esta diferencia
consiste en que los algoritmos supervisados requieren de un conjunto de datos
previamente etiquetados con los que ser entrenados para resolver el problema,
mientras que los no supervisados no precisan de dicho etiquetado previo, puesto que
basan su funcionamiento en la búsqueda de patrones ya existentes en los datos.
En el caso de este post, la detección de dominios se va a llevar a cabo empleando
algoritmos no supervisados, de modo que no se necesita un conjunto de datos de
entrenamiento en el que se haya llevado a cabo un etiquetado identificando qué
dominios son maliciosos y cuáles no.
Para poder aplicar los algoritmos de clasificación no supervisada, es imprescindible
construir una base de datos robusta, con una cantidad suficientemente grande y
variada de dominios, junto con una serie de características o variables que los definan.
Para la caracterización de dominios se van a calcular una serie de métricas que
definen las características léxicas, tanto de cada dominio completo, como de su
dominio de nivel secundario (Second Level Domain – SLD) y su dominio de nivel
superior (Top Level Domain – TLD). Dichas características léxicas se pueden agrupar
en las siguientes categorías:
Número o recuento de tipos de caracteres que aparecen en el dominio
completo, SLD y TLD. Por ejemplo: número de letras, de dígitos, de caracteres
especiales, de puntos, de guiones, de caracteres en mayúscula y minúscula,
etc.
Longitud del dominio completo, del SLD y del TLD.
Ratios entre distintas características ya calculadas, que permiten relacionar
entre sí dichas características. Por ejemplo: el ratio entre el número de dígitos y
letras de un determinado dominio.
Entropía de Shannon. Esta métrica mide el grado de desorden de una palabra,
en este caso del nombre de un dominio. Los dominios maliciosos generados
por ordenadores suelen ser muy aleatorios, por lo que pueden ser detectados
al tener un valor alto de entropía de Shannon en comparación con los valores
bajos que obtendrían los dominios legítimos.
Presencia de determinadas palabras en el nombre del dominio. Por ejemplo, la
palabra “login” suele ser introducida por los atacantes para obtener la
información del usuario, por lo que es importante identificar cuando aparezca.
Presencia del TLD en listas con los TLD más comunes y sospechosos.
Una vez caracterizado el conjunto de dominios de la base de datos con sus
respectivas variables léxicas, en el siguiente artículo se expondrán con detalle los
diferentes algoritmos de clasificación no supervisada que se utilizarán para detectar
qué dominios tienen unas características léxicas significativamente diferentes del resto
y, por tanto, pueden ser etiquetados como anómalos.
Cloud Computing
Mitigación DNSSEC
The five main ransomware attack vectors are:
1. Exploitable vulnerabilities
2. Brute-force credential attacks
3. Social engineering
4. Previously compromised credentials
5. Abuse of trust
The term “phishing” can be traced back as far as 1996. Since then, the risk of falling victim to a
phishing attack has increased incrementally due to the high usage of the web and mass
adoption of hybrid work, making it the most common cause of a security breach. And the most
alarming fact about a phishing attack is it only takes one click to become a victim.
Related Video
The Evolution of Modern Phishing Attacks
What Is Phishing?
Phishing is a form of social engineering where a threat actor sends one or more fraudulent
communications to a user in an attempt to trick them into downloading malware onto a device or
forfeit sensitive information such as login credentials, personal identifiable information (PII) or
financial data. In most cases, phishing usually occurs through communication channels such as
email, SMS messages, social media or phone calls.
How Does Phishing Work?
In the event of a phishing attack, threat actors will send fraudulent communications made to
look like they are coming from a reputable source. Appealing to emotions such as fear, curiosity,
urgency and greed, threat actors will attempt to get users to ignore basic cybersecurity hygiene
and click a link or download an attachment, which could be a malicious webpage, shell script, or
even a Microsoft Office document containing a malicious macro. If the user is fooled, they risk
leaking sensitive information and may also experience identity theft, data loss or infection of
their device or network with malware, including ransomware.
Phishing attacks have become one of the most prevalent methods of cybercrime because they
are effective due to their ability to avoid detection methods. Most phishing is sent via email as it
is simple to deploy and easy to send large quantities of messages in a single attempt. Adding to
the ease of deployment is the availability of low-cost phishing kits. These phishing kits are
collections of tools, such as website development software, coding, spamming software and
content, which can be utilized to collect data and create convincing websites and emails. The
addition of more sophisticated and evasive phishing techniques has also enabled even novice
threat actors to bypass traditional security defenses.
The Objective of Phishing Attacks
Motivated by financial or informational gain, a hacker typically deploys a phishing attack to steal
data, money or, in some cases, both.
Once a malicious link is clicked, the cybercriminal may download malware onto the device. This
allows them to gain access to the user’s sensitive information or possibly move laterally within
the network to infect other devices. The threat actor may opt to sell the data to third parties for
profit, hold it for ransom, or destroy the victim’s or company’s data if demands aren’t met.
Attackers may also collect contacts from the original victim that can be used in future phishing
attacks.
Most Common Types of Phishing
Depending on the objective and intended target, threat actors will use different types of phishing
techniques to trick the user into falling victim. Each of the following forms of attacks may be
used to achieve different objectives.
Spear Phishing
Spear phishing is the most common form of phishing. An attacker uses gathered intel on an
individual to create a personalized email message that often includes a malicious link or
attachment. When the user opens the attachment, malware is executed on the target’s device,
which gives the attacker access to their private information.
Whaling
Whaling is a form of phishing that is targeted at high-profile executives of a company. The
objective of whaling is to gain access to extremely confidential information through email
communication. Many times, the message appears urgent to convince the receiver to act
quickly. In this case, the victim may click a malicious link without thinking beforehand, enabling
the attacker to steal login credentials and sensitive data or download malware.
Smishing
Smishing acts in the same way as other phishing attacks, but it comes in the form of an SMS
message. Oftentimes, the message will contain a fraudulent attachment or link, prompting the
user to click from their mobile device.
Vishing
Vishing, also called ‘voice phishing’, is when an attacker targets victims over the phone to gain
access to data. To appear legitimate, the attacker may pretend that they are calling from the
victim’s bank or a government agency.
Angler Phishing
Attackers who use angler phishing attacks utilize a social media platform to create a fraudulent
profile posing as a customer service agent. They reach out to users who have expressed
frustration with a specific company to help “solve” their issues. In this communication, the victim
may then send their personal information to the fake account, which allows the hacker to access
their account.
Dangers of Phishing
As one of the main tactics used in successful data breaches today, there are many risks that
come with falling victim to a phishing attack. Many users and organizations have had personally
identifiable information (PII), credentials and sensitive data stolen, resulting in identity theft,
money and reputation loss, as well as disruption of daily operations and productivity. With
phishing attacks continuing to increase in sophistication and volume, it is critical for
organizations and individuals to take extra steps to prevent these attacks from taking place.
How to Prevent Phishing Attacks
As with any organization, a comprehensive security platform that addresses people, technology
and processes minimizes the likelihood of a successful phishing attack. In the case of people,
security awareness training will educate the recipients on what to look for in a phishing attempt
and report it to their security teams. While phishing attack methods may change, many of them
share common warning signs, so continually practicing good cybersecurity hygiene will help
avoid potential attacks.
When it comes to technology, organizations should look to deploy a malware analysis solution
which will analyze the unknown link or file and implement policies to prevent access if it is
determined to be malicious. Deploying a web security solution is also strongly recommended as
it can block modern-day web-based threats like phishing and prevent an organization from
becoming patient-zero.
To learn how you can protect yourself from modern day threats like phishing, check out Palo
Alto Networks Advanced URL Filtering solution.
DMCA Takedown – A takedown request, also called a DMCA
takedown or a notice and take down request, is a procedure for
asking an internet service provider (ISP) or search engine to
remove or disable access to illegal, irrelevant or outdated
information. Takedown requests are often issued for website
content that has been plagiarized.
What is DMCA protection? DMCA protection means that digital
works are protected by the Digital Millennium Copyright Act
(DMCA). The DMCA is a US federal law designed to protect
copyright holders from the unlawful reproduction or distribution
of their works -i.e. prevent digital piracy.
[Link]