THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, April 05, 2022
Endpoint security risks are higher due to the current coronavirus epidemic, a changing workplace environment, and evolving data security threats.
FREMONT, CA: As businesses decentralize their operations in response to the coronavirus pandemic, the risks of network intrusion and data breaches increase. Endpoint security risks have become a significant component of corporate security.
Any device that is connected to a computer network is considered an endpoint. However, identifying endpoints is one thing; preventing attacks that may originate from these endpoints is another. Several of the most prevalent endpoint security risks include the following:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Phishing
Phishing is the most common and least sophisticated type of attack. It involves the use of bogus messages to gain access. The message appears to originate from a reputable entity and is intended to dupe users into providing personal information or downloading malware. The data is then used to access the user's system and the larger network.
Apart from the Marriott data breach, phishing was also responsible for the JPMorgan Chase breach, which compromised 76 million households and 7 million businesses, and the Sony Pictures hack in 2014, which resulted in the leak of private emails, the release of upcoming films to torrent sites, and a loss of over $100 million for the company.
Outdated Patches
Constant patches are one of the annoyances of modern life, but they are a necessary evil if entrepreneurs want to stay ahead of evolving online threats. And yet, many businesses continue to ignore the update button.
The most well-known example is the 2017 Equifax data breach. The credit reporting agency ignored a critical vulnerability in one of its servers, allowing hackers to steal the personal information of 148 million US consumers. The ensuing debacle resulted in a $650 million Federal Trade Commission fine and a $77.5 million class-action settlement.
Drive-by Download
As with phishing, this technique employs deception to convince users to click a link or download malware. For instance, all examples are fake system alerts, anti-virus notifications, or deceptive installation agreements unrelated to the program the user intended to download.
Drive-by payloads can include Trojan backdoors such as the RAT, keyloggers that record keystrokes, and ransomware attacks such as the 2016 Locky ransomware attack that exploited an Adobe Flash auto-run vulnerability.
DDoS
Distributed Denial of Service attack (DDoS) attacks overload a website, server, or network by flooding it with incoming traffic. It repeatedly attempts to access the target site and disrupts its bandwidth, resulting in a denial of service attack. According to one study, DDoS attacks increased by 87 percent year over year, with 16 attempts per minute. Two-thirds of all attacks targeted customer-facing enterprise systems.
More in News