{"id":33503,"date":"2019-09-05T14:33:41","date_gmt":"2019-09-05T13:33:41","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/09\/05\/emea-identified-as-global-hotspot-for-brute-force-access-attacks\/"},"modified":"2019-09-17T08:46:28","modified_gmt":"2019-09-17T07:46:28","slug":"emea-identified-as-global-hotspot-for-brute-force-access-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/09\/05\/emea-identified-as-global-hotspot-for-brute-force-access-attacks\/","title":{"rendered":"EMEA identified as global hotspot for brute force access attacks"},"content":{"rendered":"\n<p>EMEA\nis a global hotspot for brute force access attacks, according to research from\nF5 Labs.<\/p>\n\n\n\n<p>The analysis forms part of the <em>Application Protection Report 2019<\/em>, which explores the fact that most applications are attacked at the access tier, circumventing legitimate processes of authentication and authorisation. Brute force attacks are typically defined as either 10 or more successive failed attempts to log in in less than a minute, or 100 or more failed attempts in a 24-hour period. <\/p>\n\n\n\n<p><strong>EMEA\nhit hardest<\/strong><\/p>\n\n\n\n<p>In 2018, the F5 Security Incident Response Team (SIRT) reported that brute force attacks against F5 customers constituted 18% of all attacks and 19% of addressed incidents. <\/p>\n\n\n\n<p>Of all SIRT-logged attacks taking place in EMEA last year, 43.5% were brute force. Canada was a close second (41.7% of recorded attacks), followed by the USA (33.3%) and APAC (9.5%). The public services sector was most affected, with 50% of all incidents taking the form of brute force attacks, followed by financial services (47.8%) and the healthcare industry (41.7%). Education (27.3%) and service providers (25%) were also in the firing line.<\/p>\n\n\n\n<p>\u201cDepending\non how robust your monitoring capabilities are, brute force attacks can appear\ninnocuous, like a legitimate login with correct username and password,\u201d said\nRay Pompon, Principal Threat Research Evangelist, F5 Networks. \u201cAttacks of this\nnature can be hard to spot because, as far as the system is concerned, the\nattacker appears to be the rightful user.\u201d<\/p>\n\n\n\n<p>Any\napplication that requires authentication is a potential venue for a brute force\nattack, but F5 Labs mostly recorded attacks focusing on: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>HTTP form-based\nauthentication brute force (29% of logged attacks globally).<\/strong> Attacks against web authentication forms in the browser.\nMost of the traditional logins on the web take this form. <\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Outlook web access (17.5%), Office 365 (12%) ADFS (17.5%) brute force<\/strong>. Attacks against authentication protocols for Exchange servers, Microsoft Active Directory and federated services. Since these services are not accessed through a browser, users authenticate to them through separate prompts. Due to the single sign-on capabilities of AD and federation, successful access attacks of these protocols encompass mail, as well as entire intranets and significant amounts of sensitive information. <\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>SSH\/SFTP brute force (18%).<\/strong> SSH and SFTP access attacks are among the most prevalent, partly because successful SSH authentication is often a quick path to administrator privileges. Brute forcing SSH is hugely attractive to cybercriminals as many systems still rely on default credentials ease of use.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>S-FTP brute force\n(6%)<\/strong>. S-FTP brute force is dangerous as\nit is a method to drop malware, which presents a wide range of disruptive\noptions, including escalation of privilege, keylogging or other forms of\nsurveillance and network traversal. <\/li><\/ul>\n\n\n\n<p>Overall, email is the most targeted service when it comes to brute force attacks. For organisations that do not rely heavily on e-commerce, the most valuable assets are often stored far from the perimeter, behind multiple layers of controls. In this case, email is often a powerful staging ground to steal data and gain access to the tools needed to wreak widespread havoc. <\/p>\n\n\n\n<p>Breach\ndata also pegged email as a primary target; it was involved in the top two\nsubcategories of access breaches, representing 39% of access breaches and 34.6%\nof all breach causes. Email is directly attributed as a factor in over a third\nof all breach reports.<\/p>\n\n\n\n<p><strong>Staying safe<\/strong><\/p>\n\n\n\n<p>According to the <em>Application Protection Report 2019<\/em>, safeguarding against access tier attacks is still a major challenge for many organisations. Multi-factor authentication can be hard to implement and not always feasible in the required time-frame. Worryingly, while passwords are typically inadequate forms of protection, F5\u2019s <em>Application Protection Report 2018<\/em> found that 75% of organisations still use simple username\/password credentials for critical web applications.<\/p>\n\n\n\n<p>\u201cWhile\naccess attack tactics will certainly change as defensive technologies become\nmore advanced, the core principles to stay safe will remain significant for the\nforeseeable future,\u201d said Pompon.<\/p>\n\n\n\n<p>\u201cTo start, make sure your system can at least detect brute force attacks. One of the main challenges is that confidentiality and integrity can sometimes find themselves at odds with availability. It is important to establish reset mechanisms that work for both the organisation and its users. It is not enough to set up some firewall alarms on brute force attempts and take a nap. You have to test monitoring and response controls, run incident response scenario tests and develop incident response playbooks so that you can react quickly and reliably.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>EMEA is a global hotspot for brute force access attacks, according to research from F5 Labs. The analysis forms part of the Application Protection Report 2019, which explores the fact that most applications are attacked at the access tier, circumventing legitimate processes of authentication and authorisation. Brute force attacks are typically defined as either 10 [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":33791,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[13349,3677,10823,13350,13351,567,13352],"class_list":["post-33503","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-brute-force","tag-f5-networks","tag-http","tag-principal-threat-research-evangelist","tag-ray-pompon","tag-threats","tag-web"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33503","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=33503"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33503\/revisions"}],"predecessor-version":[{"id":33782,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33503\/revisions\/33782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/33791"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=33503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=33503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=33503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}