How Can Ideal Victim Analysis Stop Cyberattacks?

71 views
•
May 16, 2019
by
RSAC Cybersecurity
YouTube video player
How Can Ideal Victim Analysis Stop Cyberattacks?

TL;DR

Studying the victims adversaries prefer can reveal their objectives and help defenders interfere with attack returns. Organizations should combine victimology, deception, honeypots, threat intelligence, and automation to identify adversary interest, compensate for human limits, and build defenses around the missions attackers are actually trying to accomplish.

Transcript

Welcome here today. Thank you for joining us. Uh, we're trying out some new human stuff. Um, for those who don't know me real well yet, um, I struggle with humans. I'm more on the robot side, so I'm kind of navigating through the waters. Um, this is my first time at the human, um, track, and this is Naoki Spencer. She works with me at Intuit. We're... Read More

Key Insights

  • Ideal victims are targets whose characteristics help adversaries increase the return on their attacks. Studying those characteristics shifts attention from trying to know every possible attack toward understanding what attackers value, what missions they pursue, and why particular people or systems attract their interest.
  • Identity theft is presented as a large and growing trust problem, with 60 million cases cited through the previous year and almost 17 million in that year alone. The talk connects repeated data theft with increasing public reluctance to trust internet services and adopt applications.
  • Modern adversaries are using many of the same capabilities as legitimate organizations, including cloud services, automation, collaboration, open source resources, information sharing, and pattern analysis. These shared capabilities can help attackers scale their operations, coordinate their work, and extract more useful information about human behavior.
  • Successful attacks require intent, opportunity, means, and methods. A person may be encouraged to think like a thief yet remain ineffective without the necessary skill or circumstances. Security analysis should therefore examine both adversary motivation and the practical conditions that make a specific attack possible.
  • Branded vulnerabilities are easier for people to remember than numerical identifiers. Names such as Heartbleed, Dirty Cow, and Shellshock gained recognition because branding made technical problems memorable, but that memorability also highlights how difficult it is for humans to retain the broader vulnerability landscape.
  • Vulnerability volume exceeds realistic human memory, with about 20,000 vulnerabilities per year and roughly 55 per day cited in the talk. The speakers also state that some vulnerabilities never reach common disclosure lists, even though a portion is exploitable and some receive proofs of concept from malicious actors.
  • Automation is necessary because security professionals cannot keep every vulnerability and attack pattern in their heads. It can process technical volume and support detection, but it does not eliminate human error because people still create, configure, and rely upon the automated systems used for defense.
  • Deception and honeypots are tools for interfering with an adversary's mission. When defenders understand the attacker’s preferred victim, they can shape a security program around actual adversary interest, draw attention toward controlled targets, and make it harder for attackers to achieve the outcome they seek.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is an ideal victim in cybersecurity?

An ideal victim is a target whose characteristics help an adversary increase the return on an attack. Rather than treating every person, application, or system as equally attractive, victimology examines which targets support the attacker’s mission most effectively. Understanding that preference can help defenders identify adversary interest quickly and tailor security controls, deception, and honeypots around the targets attackers are most likely to pursue.

Q: How can ideal victim analysis help stop cyberattacks?

Ideal victim analysis helps by revealing what adversaries value and what outcome they are trying to achieve. Defenders can use that understanding to focus a security program on the people, data, and systems that attract the greatest interest. They can then deploy deception and honeypots to misdirect attackers, obstruct their progress, and prevent them from completing their intended mission.

Q: Why is automation necessary in vulnerability management?

Automation is necessary because the volume of vulnerabilities exceeds what people can reliably remember or process manually. The talk cites about 20,000 vulnerabilities per year, which is approximately 55 each day. It also notes that some exploitable vulnerabilities never appear on common disclosure lists. Automated processes can help teams scan, track, and respond at this scale, although human mistakes can still affect those processes.

Q: Why are branded vulnerabilities easier to remember?

Branded vulnerabilities attach distinctive names and imagery to technical issues that would otherwise be represented by difficult numerical identifiers. The talk uses Heartbleed, Dirty Cow, and Shellshock as examples that became recognizable across the industry. Their memorability helped people discuss and respond to them, but it also exposed a larger problem: security professionals cannot retain the details of every vulnerability through memory alone.

Q: What capabilities are cyber adversaries using to improve attacks?

Cyber adversaries are using cloud services, automation, collaboration, open source resources, information sharing, and technologies that identify patterns in human behavior. These are many of the same tools and platforms used by legitimate organizations. According to the talk, their adoption contributes to attackers becoming more effective, finding more victims, and improving how they coordinate and execute malicious activity.

Q: What conditions are required for an adversary to conduct an attack?

An adversary requires more than a desire to cause harm. The talk says the person must also have an opportunity to act and the means and methods needed to carry out the attack. Someone can be encouraged to think like a thief without becoming an effective attacker. Defenders should therefore evaluate motivation together with capability, access, circumstances, and the practical route to the target.

Q: How do deception and honeypots disrupt adversaries?

Deception and honeypots can present controlled targets that appear valuable to an adversary. When they are designed around the attacker’s preferred victim and likely mission, they can attract attention away from real assets, expose adversary behavior, and consume attacker effort. The central objective is not merely to observe attacks, but to stop adversaries from obtaining the outcome that makes their operation worthwhile.

Q: Why should security programs focus on adversary missions?

Security programs should focus on adversary missions because knowing every attack vector and maintaining perfect defenses is not realistic. Attackers choose actions that advance particular objectives, and their preferred victims provide clues about those objectives. By studying adversary interest, defenders can prioritize the assets most likely to be targeted and design controls that directly interfere with the attacker’s path to success.

Summary & Key Takeaways

  • Cybercrime and identity theft are weakening public trust in internet services and applications. Adversaries are also adopting cloud platforms, automation, collaboration, open source resources, and pattern-finding technologies. These trends make attacks more scalable while giving defenders a reason to study attackers as people with recognizable objectives, preferences, capabilities, and constraints.

  • Security teams cannot reasonably memorize every vulnerability or anticipate every attack. The presentation cites about 20,000 vulnerabilities per year, or 55 each day, while noting that some exploitable weaknesses never reach common disclosure lists. Automation is therefore necessary for handling technical volume, although humans still design, operate, and sometimes misconfigure automated defenses.

  • An adversary needs more than malicious intent. The person must also possess the opportunity, means, and methods required to conduct an attack. Defenders can use this constraint by identifying the victims attackers value most, studying their likely missions, and deploying deception or honeypots that obstruct those missions and reduce the expected return from attacks.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚