68
© 2015 Imperva, Inc. All rights reserved. The State of Application Security: Hackers On Steroids Itsik Mantin, Director of Security Research, Imperva

The State of Application Security: Hackers On Steroids

  • Upload
    imperva

  • View
    21.670

  • Download
    2

Embed Size (px)

Citation preview

Page 1: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

The State of Application Security: Hackers On SteroidsItsik Mantin, Director of Security Research, Imperva

Page 2: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

“Study the past if you would define the future” (Confucius)

Page 3: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Speaker

• Director of Security Research at Imperva

• 15 years experience in the security industry

• An inventor of 15 patents in these fields

• Holds an M.Sc. in Applied Math and Computer Science

• Presenter in Blackhat Asia, OWASP IL, EuroCrypt and other conferences

Itsik Mantin

3

Page 4: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Making the Report

4

Page 5: The State of Application Security: Hackers On Steroids

Attack Detection Mechanisms

Application Profiling

5

Page 6: The State of Application Security: Hackers On Steroids

Attack Types

6

Page 7: The State of Application Security: Hackers On Steroids

Attack Incidents

Attack Type Min Ratio #Alert/5min

SQLi 20

HTTP 10

XSS 5

DT 5

Spam 1

RCE 1

FU 1

IncidentCollection of alertsSame attack typeSame targetEssentially same timeNot necessarily same IP

Incident Alert RatioIncident Alert Ratio

7

Page 8: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Attack Trends

1

8

Page 9: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Chance of Getting Attacked

9

Page 10: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Chance of Getting Attacked

Everyone’s at risk3/4 apps attacked for every attack type

10

Page 11: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Chance of Getting Attacked “Perfect” RCE CoverageAll applications were attacked

11

Page 12: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

12

Page 13: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

75th Percentile

Median25th percentile

13

Page 14: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

RCE and Spam are the most popularRCE: Median of 273

14

Page 15: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

Inequality MeasureRatio between 3rd and 2nd quartiles

15

Page 16: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

Inequality MeasureRatio between 3rd and 2nd quartiles

RCE Blind ScansAll applications suffer equally

16

Page 17: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Number of Attack Incidents

Spam is discriminatorySpoiler – some industries suffer more

17

Page 18: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

SQL Injection and Cross-Site Scripting

18

Page 19: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

SQL Injection and Cross-Site Scripting

Most Applications see SQLi and XSS every other week

Median of 12-13 for 6-month period3-5 days for topQ applications

19

Page 20: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Up-Trends

# In

cide

nts

20

Page 21: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Up-Trends

SQLi Persistent Growth 100% increase in 2014200% increase in 2015

# In

cide

nts

XSS Persistent Growth 100% increase in 2014150% increase in 2015

21

Page 22: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Up-Trends

# In

cide

nts

22

Page 23: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Up-Trends

23

Page 24: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Up-Trends

24

Page 25: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Down-Trends

# In

cide

nts

25

Page 26: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Down-Trends

# In

cide

nts

RFI was on fire in 2014Super-popular attack vector in 2014Back to “normal” in 2015

26

Page 27: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Year-over-Year Down-Trends

# In

cide

nts

DT Decrease2014 trend changedSpoiler – in one industry DT is still the attack of choice

27

Page 28: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Magnitude of Attacks

28

Page 29: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Magnitude of Attacks

SQLi Attacks are most Intensive72-204 alerts for quartile 3 (of the incidents)300K alerts in most intensive attack

29

Page 30: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Reputation

2

30

Page 31: The State of Application Security: Hackers On Steroids

Reputation

31

Page 32: The State of Application Security: Hackers On Steroids

Reputation

32

Page 33: The State of Application Security: Hackers On Steroids

Reputation

Serial Attackers – 70%Anonymous Browsing – 8%

33

Page 34: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Serial Attackers Vs. Anonymous Browsing

34

Page 35: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Serial Attackers Vs. Anonymous Browsing

35

Page 36: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Serial Attackers Vs. Anonymous Browsing140,000 anonymous browsing1,800,000 detect-by-content12,500,000 serial attackers

1,700,000 anonymous browsing280,000 detect-by-content28,000 serial attackers

36

Page 37: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Industry Trends

3

37

Page 38: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Per-Industry Trends

Health

Food

Travel

Leisure

Shopping

Business

Financial

Computer

DT FU HTTP RFI SQLi XSSSpamRCE

38

Page 39: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Per-Industry Trends

Health

Food

Travel

Leisure

Shopping

Business

Financial

Computer

DT FU HTTP RFI SQLi XSSSpamRCE

Massive Spam/RCE Campaigns

39

Page 40: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Per-Industry Trends

Health

Food

Travel

Leisure

Shopping

Business

Financial

Computer

DT FU HTTP RFI SQLi XSSSpamRCE

RCE blind scans

Massive Spam/RCE Campaigns

40

Page 41: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Per-Industry Trends

Health

Food

Travel

Leisure

Shopping

Business

Financial

Computer

DT FU HTTP RFI SQLi XSSSpamRCE

RCE blind scans

Spam focused on travel applications

Massive Spam/RCE Campaigns

41

Page 42: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Attack Types

42

Page 43: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Attack Types

43

Page 44: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Attack Types

57% XSS incidents on Health

44

Page 45: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Attack Types

37% DT incidents on Food

45

Page 46: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Web Framework Trends

4

46

Page 47: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Content Management Systems

47

Page 48: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

CMS Trends

All CMS

Non CMS Applications

48

Page 49: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

CMS Trends

All CMS

Non CMS Applications

CMS At RiskCMS applications are attacked 3 Times more oftenTrend consistent for all attack types

49

Page 50: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

WordPress Trends

Other CMS

Non CMS

WordPress

50

Page 51: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

WordPress Trends

Other CMS

Non CMS

WordPress

WordPress at More Risk3.5 times more attacks than non-CMS Applications7 times more RFI and Spam Attacks

51

Page 52: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

WordPress Trends

Other CMS

Non CMS

WordPress

WordPress at More Risk3.5 times more attacks than non-CMS Applications7 times more RFI and Spam Attacks

WordPress at More Risk3.5 times more attacks than non-CMS Applications7 times more RFI and Spam Attacks

52

Page 53: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Geographic Trends

53

Page 54: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Geographic Attack Trends

Country Absolute #Requests

Internet Users

US 17,671,816 278,553,524

China 8,227,498 672,585,110

UK 2,224,749 59,097,955

54

Page 55: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Geographic Attack – Year-over-Year

55

Page 56: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Case Studies

6

56

Page 57: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Shellshock Mega-Trend

57

Page 58: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Shellshock Mega-Trend 75,000 incidents189 applications

26,000 incidents137 applications

23,000 incidents174 applications

57,500 incidents193 applications

58

Page 59: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

SQLi Cases Study

59

Page 60: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

SQLi Cases Study 6,800 alerts per hour

60

Page 61: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Scraping Case Study

• TOR Massive Scraping attack

• 2 million requests

• 777 TOR Ips

• User-Agent faking

61

Page 62: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Scraping Case Study

62

Page 63: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Scraping Case Study

63

Page 64: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Conclusions

64

Page 65: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Recommendations

65

Page 66: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Q&A

7

66

Page 67: The State of Application Security: Hackers On Steroids

© 2015 Imperva, Inc. All rights reserved.

Download 2015 Web Application Attack Report

67

http://www.imperva.com/DefenseCenter/WAAR

Page 68: The State of Application Security: Hackers On Steroids