The State of Application Security: Hackers On Steroids презентация

Содержание

“Study the past if you would define the future” (Confucius)

Слайд 1The State of Application Security: Hackers On Steroids
Itsik Mantin, Director of

Security Research, Imperva

Слайд 2“Study the past if you would define the future” (Confucius)


Слайд 3Speaker
Director of Security Research at Imperva

15 years experience in the security

industry

An inventor of 15 patents in these fields

Holds an M.Sc. in Applied Math and Computer Science

Presenter in Blackhat Asia, OWASP IL, EuroCrypt and other conferences

Itsik Mantin


Слайд 4






198 Applications
WAAR #6 Report
103,455,308 Alerts
6 Months
Making the Report
Cleaning
Classification
Aggregation
Analysis


Слайд 5Attack Detection Mechanisms
Application Profiling


Слайд 6Attack Types


Слайд 7Attack Incidents
Incident
Collection of alerts
Same attack type
Same target
Essentially same time
Not necessarily same

IP

Слайд 8Attack Trends

1


Слайд 9Chance of Getting Attacked


Слайд 10Chance of Getting Attacked
Everyone’s at risk
3/4 apps attacked for every attack

type

Слайд 11Chance of Getting Attacked
“Perfect” RCE Coverage
All applications were attacked


Слайд 12Number of Attack Incidents


Слайд 13Number of Attack Incidents


Слайд 14Number of Attack Incidents

RCE and Spam are the most popular
RCE: Median

of 273

Слайд 15
Number of Attack Incidents
Inequality Measure
Ratio between 3rd and 2nd quartiles


Слайд 16
Number of Attack Incidents
Inequality Measure
Ratio between 3rd and 2nd quartiles
RCE Blind

Scans All applications suffer equally

Слайд 17
Number of Attack Incidents
Spam is discriminatory Spoiler – some industries suffer more


Слайд 18SQL Injection and Cross-Site Scripting


Слайд 19SQL Injection and Cross-Site Scripting
Most Applications see SQLi and XSS every

other week
Median of 12-13 for 6-month period
3-5 days for topQ applications

Слайд 20Year-over-Year Up-Trends
# Incidents


Слайд 21Year-over-Year Up-Trends
SQLi Persistent Growth 100% increase in 2014
200% increase in 2015
#

Incidents

XSS Persistent Growth 100% increase in 2014
150% increase in 2015


Слайд 22Year-over-Year Up-Trends
# Incidents
Exponential Growth


Слайд 23Year-over-Year Up-Trends
Exponential Growth


Слайд 24Year-over-Year Up-Trends



Exponential Growth


Слайд 25Year-over-Year Down-Trends
# Incidents


Слайд 26Year-over-Year Down-Trends
# Incidents
RFI was on fire in 2014 Super-popular attack vector in

2014
Back to “normal” in 2015

Слайд 27Year-over-Year Down-Trends
# Incidents
DT Decrease
2014 trend changed
Spoiler – in one industry DT

is still the attack of choice

Слайд 28Magnitude of Attacks


Слайд 29Magnitude of Attacks
SQLi Attacks are most Intensive
72-204 alerts for quartile 3

(of the incidents) 300K alerts in most intensive attack

Слайд 30Reputation

2


Слайд 31Reputation


Слайд 32Reputation
80,605,285 Alerts
78%
22,850,023 Alerts 22%


Слайд 33Reputation
80,605,285 Alerts
78%
22,850,023 Alerts 22%
Serial Attackers – 70%
Anonymous Browsing – 8%


Слайд 34Serial Attackers Vs. Anonymous Browsing


Слайд 35Serial Attackers Vs. Anonymous Browsing


Слайд 36Serial Attackers Vs. Anonymous Browsing
140,000 anonymous browsing
1,800,000 detect-by-content
12,500,000 serial attackers
1,700,000 anonymous

browsing
280,000 detect-by-content
28,000 serial attackers

Слайд 37Industry Trends

3


Слайд 38Per-Industry Trends



DT
FU
HTTP
RFI
SQLi
XSS
Spam
RCE


Слайд 39Per-Industry Trends



DT
FU
HTTP
RFI
SQLi
XSS
Spam
RCE
Massive Spam/RCE Campaigns


Слайд 40Per-Industry Trends



DT
FU
HTTP
RFI
SQLi
XSS
Spam
RCE
RCE blind scans
Massive Spam/RCE Campaigns


Слайд 41Per-Industry Trends



DT
FU
HTTP
RFI
SQLi
XSS
Spam
RCE
RCE blind scans
Spam focused on travel applications
Massive Spam/RCE Campaigns


Слайд 42Attack Types


Слайд 43Attack Types


Слайд 44Attack Types

57% XSS incidents on Health


Слайд 45Attack Types

37% DT incidents on Food


Слайд 46Web Framework Trends

4


Слайд 47Content Management Systems


CMS Applications (excluding WordPress)
Non-CMS Applications
WordPress Applications


Слайд 48CMS Trends


Слайд 49CMS Trends
CMS At Risk
CMS applications are attacked 3 Times more often
Trend

consistent for all attack types

Слайд 50WordPress Trends
Other CMS
Non CMS

WordPress


Слайд 51WordPress Trends

Other CMS
Non CMS

WordPress
WordPress at More Risk
3.5 times more attacks than

non-CMS Applications
7 times more RFI and Spam Attacks

Слайд 52WordPress Trends
Other CMS
Non CMS

WordPress
WordPress at More Risk
3.5 times more attacks than

non-CMS Applications
7 times more RFI and Spam Attacks



WordPress at More Risk
3.5 times more attacks than non-CMS Applications
7 times more RFI and Spam Attacks


Слайд 53Geographic Trends



Слайд 54Geographic Attack Trends


Слайд 55Geographic Attack – Year-over-Year
2015
2014


Слайд 56Case Studies

6


Слайд 57Shellshock Mega-Trend


Слайд 58Shellshock Mega-Trend
75,000 incidents
189 applications
26,000 incidents
137 applications
23,000 incidents
174 applications
57,500 incidents
193 applications


Слайд 59SQLi Cases Study


Слайд 60SQLi Cases Study
6,800 alerts per hour


Слайд 61Scraping Case Study
TOR Massive Scraping attack

2 million requests

777 TOR Ips

User-Agent faking


Слайд 62Scraping Case Study


Слайд 63Scraping Case Study


Слайд 64Conclusions


Слайд 65Recommendations


Слайд 67Download 2015 Web Application Attack Report
http://www.imperva.com/DefenseCenter/WAAR


Обратная связь

Если не удалось найти и скачать презентацию, Вы можете заказать его на нашем сайте. Мы постараемся найти нужный Вам материал и отправим по электронной почте. Не стесняйтесь обращаться к нам, если у вас возникли вопросы или пожелания:

Email: Нажмите что бы посмотреть 

Что такое ThePresentation.ru?

Это сайт презентаций, докладов, проектов, шаблонов в формате PowerPoint. Мы помогаем школьникам, студентам, учителям, преподавателям хранить и обмениваться учебными материалами с другими пользователями.


Для правообладателей

Яндекс.Метрика