Popular Posts
-
Los Angeles, CA -- (SBWIRE) -- 03/14/2017 -- WebHostingCat.com has announced its annual list of Best Web Hosting Award Winners for 2017. T...
-
June 28, 2016 -- Chicago, IL (PRWEB) June 28, 2016 WiredTree, a provider of fully managed server hosting, will celebrate i...
-
December 21, 2016 -- Everyone interested in effective digital marketing and use of PBNs now has access to a reliable hosting ...
-
This week, Flickr announced that they are taking away one of the key "free" functions: the ability to auto upload photos from your...
-
from what I have understood the new .blog domain to be is that, since it is a new type of domain, you will have the chance to get one ahea...
-
Dark Web is right now going through a very rough time. Just two days ago, a hacker group affiliated with Anonymous broke into the server...
-
I would like to bring another one of my skills to the table, WordPress baby! Starting with this post I will be covering the basics, doma...
-
November 23, 2016: Hosting Manual has announced that it will be publishing the biggest Black Friday web hosting and domain deals ever fr...
-
The free website hosting company Wix is the latest online service to be exploited by cyber criminals. Researchers from security company Cy...
-
The chances are you run into what's called committed host hosting if you began looking at different internet hosting providers, whether ...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Whatâs that worth? Find out on the Dark Web
It's no secret the dark web is where bad guys go to conduct business.
But beyond being the place where cybercriminals share information and buy/sell illicit goods (stolen information, counterfeits, drugs, weapons, etc.), the dark web can also serve as a key resource for the above ground business to understand what is of value to others – and how to quantify the value an organisation places on its data.
When people discuss dark web markets, they tend to focus on payment cards; however, criminals are able to monetise a variety of different types of personal information, account credentials, and other stolen data.
Over just the past week SurfWatch Labs has observed the following items for sale on the dark web:
Stolen payment card data is also readily available on the dark web. This seller is selling compromised card information for $11.95, although buyers can get a better deal if they buy the cards in bulk.
Other cybercrime-related items for sale include pirated media, hacking services and software exploits. For example, our threat intelligence analysts recently came across a seller offering what he claimed was a new Microsoft Office zero day exploit for 40 bitcoins – or around $23,000.
Internal vs. External Threat IntelligenceAwareness of what is being sold on the dark web provides crucial insight into what cybercriminals are currently targeting – and what they're likely to target in the future. Understanding the types of information for sale on the dark web related to your customers, your infrastructure, your supply chain and your competitors can help cut through the overwhelming amount of cybersecurity noise in order to focus resources on the threats that really matter – to see the forest from the trees, as the saying goes.
This is the crucial difference between external and internal threat intelligence. Internal threat intelligence is necessary for tactical defense. It's necessary for detecting and preventing threats, for responding to incidents, and for understanding what is happening inside your own network.
External threat intelligence looks outside the organisation's walls for relevant cyber activity trends facing similar types of organisations to better plan and prepare for impending threats to the business. This intelligence can provide the strategic insight necessary to direct resources and help guide internal tools and processes towards reducing an organisation's cyber risk. For example, if dark web intelligence reveals that gift card fraud is heavily impacting your organisation or others in your sector, resources can be directed towards discovering the cause of that fraud and implementing tactics to plug those weaknesses. Is the fraud due to skimmers making counterfeit cards, an insider stealing and selling cards, a third-party data leak, or something else?
Relevant, timely and accurate external threat intelligence can help to provide the context necessary to better act on your organisation's internal data. It can help to answer questions such as:
In essence, this external intelligence can provide the high-level strategic insight necessary to better direct limited cyber resources and more effectively reduce the cyber risk facing your organisation.
Taking Action on Threat IntelligenceAs a real-world example of this threat intelligence process in action, SurfWatch Labs recently observed an actor going by the name of AlphaLeon discussing his cybercrime operations on a dark web forum. Additional research helped to confirm that web hosting provider Invision Power Services was compromised by AlphaLeon, and that once AlphaLeon executed his code, web forum users on some professional sports leagues as well as major media and entertainment companies would be breached. In summary, the intelligence led to the threat being eradicated before it could be executed.
This is an example of external threat intelligence being used to directly drive changes to an organisation's internal security and infrastructure by identifying a cyber threat before it spreads either further into the organisation or on to others in the supply chain. Identifying active threats such as compromised employee email accounts, stolen payment cards tied to a particular organisation and other indicators can help to limit the potential damage of a cyber incident.
As many studies have noted, a significant percentage of breaches go undetected by the affected organisation and are instead discovered by various third parties. Threat intelligence can help to identify a threat before a breach occurs or shorten the window between breach and discovery.
Adam Meyer, chief security strategist, SurfWatch Labs
Image source: Shutterstock/BeeBright
Leave a comment on this articleSource: What's that worth? Find out on the Dark Web
0 comments:
Post a Comment