不要让你的帮助台成为网络攻击的切入点.pdf

编号:187748 PDF 21页 2.40MB 下载积分:VIP专享
下载报告请您先登录!

不要让你的帮助台成为网络攻击的切入点.pdf

1、12024 RSA Security LLC or its affiliates.All rights reserved.Dont Let Your Help Desk Become an Entry Point for Cyberattacks22024 RSA Security LLC or its affiliates.All rights reserved.Todays SpeakerCISORobert Hughes32024 RSA Security LLC or its affiliates.All rights reserved.Audience Poll Have you e

2、ver worked as part of a Help Desk Team?42024 RSA Security LLC or its affiliates.All rights reserved.Attack vector:Tricking the help desk April 2024 US Health Department warns that hackers are targeting help desks September 2023 MGM SEC 8-K filing-USD$100 million impact Caesars Palace-USD$15 million

3、ransom paid 3 other companies hit with similar attacks March 2022 LAPSUS$DEV-0537-attack against Microsoft to get source codeHelp Desks Targeted52024 RSA Security LLC or its affiliates.All rights reserved.Impersonate an Employee Target the Help DeskAttacker may have credentials or some access alread

4、yMay have intel on the employee they are impersonatingLikely target:Get around MFA Multi-Factor Authentication Talk Help Desk into disabling MFA for admin account Talk Help Desk into changing/allowing a new false authenticatorPlan:Get deeper into the networkHelp Desk Attack VectorsImpersonate the He

5、lp Desk Target an employeePre-MFA-extract credentials Post-MFA trick user to complete MFA response,or share MFA info One Time Passwords62024 RSA Security LLC or its affiliates.All rights reserved.Still on targetFeeling its AgeNew Context Call logging,ticketing/proactively identifying possible red fl

6、ags Escalation to supervisor External authentication/remote user guidance Ensure secure and clear business processes Use of MFA techniques Corporate phone systems Focus on IPSec VPNs Focus on hardware/hard tokens Ubiquitous MFA AI and Deepfakes Prevalence of remote users in the post-COVID era Smartp

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(不要让你的帮助台成为网络攻击的切入点.pdf)为本站 (学无止境) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠