How Does the Dark Web Threaten Your Industry?

191 views
•
April 25, 2018
by
RSAC Cybersecurity
YouTube video player
How Does the Dark Web Threaten Your Industry?

TL;DR

Dark web risk must be evaluated against an organization’s unique priorities, assets, and exposure, then combined with intelligence from social media, security researchers, government partners, and open sources. Illicit marketplaces make malware, stolen data, counterfeit goods, hacked accounts, and attack services easier to obtain, creating both routine operational threats and strategic risks that can endanger long-term business viability.

Transcript

Hello, everyone. My name is Jason Rivera. I'm a manager with Deloitte, where I specialize in cyber threat intelligence and SOC operations. And today, I will be talking about the dark web and how it affects just the different industries that you may or may not be in your current career or in your past career, or you may have buddies in different ind... Read More

Key Insights

  • The dark web is only one part of the broader threat environment, not a single destination where analysts can identify every risk facing an organization. Useful intelligence must also be collected from social media, technical security research, government partnerships, and other open sources.
  • Effective dark web analysis starts with understanding the organization itself, including its priorities, purpose, products, and most important assets. Since every company operates differently, leaders must determine how their particular organization could be placed at risk before deciding what marketplace activity matters.
  • Illicit marketplaces make cyberattacks more accessible by selling malware and hacking services to buyers who lack specialized expertise. Available capabilities can include remote-access Trojans, distributed denial-of-service attacks, and phishing kits designed for use against an organization’s employees, customers, or network.
  • Tactical threats are routine, day-to-day problems that security teams commonly defend against, including commodity malware, random distributed denial-of-service attacks, and attempts to locate firewall weaknesses. Strategic threats are broader, longer-term dangers that can seriously damage an organization or threaten its viability.
  • Consumer and industrial businesses face tactical threats from counterfeit product sales and increasing commodity-style malware attacks. Their strategic exposure includes large-scale theft and monetization of member rewards programs, which can reduce consumer confidence and create direct business losses through improperly redeemed benefits.
  • Industrial components can become strategic threats when insiders steal and sell them through dark web or other black-market channels. The transcript uses dimethylmercury as an example of a manufacturing material that may serve benign purposes but can be deadly when obtained and misused.
  • Energy and resource companies face uneven cyber risk because they may operate across many countries with different cybersecurity standards. Commodity attacks that fail against stronger defenses in the United States, Europe, or more advanced East Asian countries may succeed against less-protected operations elsewhere.
  • Industrial control system disruption is a strategic concern because these systems keep machinery, automated processes, conveyor belts, and operational controls functioning. Compromising a regulator or another critical machine on an oil platform could interrupt operations and potentially cause severe physical destruction.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should organizations assess dark web risk?

Organizations should begin by identifying their own priorities, products, purpose, critical operations, and most valuable assets. They should then consider how those specific elements could be placed at risk through illicit marketplaces. Dark web findings become useful only when interpreted within this strategic context and combined with intelligence from social media, technical research teams, government partnerships, and open sources.

Q: Why is dark web monitoring not enough for threat intelligence?

Dark web monitoring is insufficient because illicit marketplaces represent only one location within a much larger threat environment. Relevant warnings and technical information also circulate through social media, security research publications, government partners, and open sources. Concentrating all collection resources on dark web activity can therefore leave analysts without the broader context needed to understand threats and inform organizational stakeholders.

Q: What products and services are sold on dark web marketplaces?

Dark web marketplaces can offer personally identifiable information, credit card data, malware, hacking services, weapons, counterfeit goods, hacked accounts, and pirated electronic products. The range is broad enough that many conceivable illicit items may appear in some form. These marketplaces also allow buyers to acquire attack capabilities without first becoming experts in hacking or other malicious technical activities.

Q: What are commodity-style malware attacks?

Commodity-style malware attacks use capabilities that can be purchased easily through dark web marketplaces and directed against a chosen organization. Examples in the transcript include remote-access Trojans for entering networks, distributed denial-of-service attacks for disrupting services, and phishing kits for composing deceptive messages aimed at employees or customers. Their availability lowers the expertise required to conduct malicious activity.

Q: What is the difference between tactical and strategic cyber threats?

Tactical threats are day-to-day problems that organizations regularly defend against, such as commodity malware, random distributed denial-of-service attacks, and attempts to identify firewall weaknesses. Strategic threats are broader and longer-lasting. They can undermine essential business activities, cause grave harm if they grow uncontrolled, or potentially threaten whether an organization remains viable as a business.

Q: How does the dark web affect consumer and industrial companies?

Consumer and industrial companies face tactical risks from counterfeit product sales and commodity-style malware attacks. Their strategic risks include large-scale compromise and monetization of customer rewards programs, along with black-market trading and weaponization of industrial components. These incidents can harm customer confidence, create financial consequences through improperly used rewards, and place dangerous materials into malicious hands.

Q: Why are rewards programs a strategic dark web risk?

Rewards programs become a strategic risk when criminals compromise many member accounts and monetize the accumulated points. For airlines, hotels, and similar businesses, this can release large amounts of benefits without corresponding revenue. A widespread compromise can also damage consumer confidence, turning account theft from a routine security incident into a broader problem affecting the business and its customer relationships.

Q: Why are industrial control systems vulnerable to strategic disruption?

Industrial control systems operate machinery and automated processes, including conveyor belts, regulators, and equipment that keeps industrial activity functioning correctly. If attackers compromise or break these controls, the consequences can extend beyond data loss. The transcript illustrates the risk with an offshore oil platform, where failure of a machine regulating operations could produce major disruption and potentially severe destruction.

Summary & Key Takeaways

  • Dark web marketplaces sell personally identifiable information, credit card data, malware, hacked accounts, counterfeit goods, pirated electronic products, weapons, and hacking services. Because attackers can purchase ready-made capabilities, they no longer need deep technical expertise to launch phishing, remote-access, or distributed denial-of-service attacks against organizations, employees, or customers.

  • Organizations should not treat dark web monitoring as a complete threat intelligence program. Relevant threat information also appears on social media, in research published by technical security teams, through government partnerships, and across open sources. Effective analysis begins with the organization’s priorities, distinctive operations, valuable assets, and likely methods of exposure or harm.

  • Industry exposure varies considerably. Consumer and industrial businesses face counterfeit sales, commodity malware, rewards-program theft, and trafficking in dangerous industrial components. Energy and resource companies face globally uneven cybersecurity standards, attacks against less-protected operations, possible disruption of industrial control systems, and insiders using anonymous marketplaces to monetize valuable organizational knowledge.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚