Emerging Attack Vector: Cloud Database Services as New Malware Platform

REDWOOD SHORES, Calif., December 11, 2013 - Imperva, Inc. (NYSE: IMPV), pioneering the third pillar of enterprise security with a new layer of protection designed specifically for physical and virtual data centers, today released its latest Hacker Intelligence Initiative report, "Assessing the Threat Landscape of DBaaS." Through an in-depth analysis of malware that used a shared hosting database for its Command and Control and drop server, Imperva discovered a new malware platform for cybercriminals: Database as a Service (DBaaS). The report concludes that by bringing data one step closer to hackers, DBaaS makes it possible for hackers to compromise an organization's database without accessing its network - ultimately increasing the risk of a data breach.

"Our research suggests that we will soon see autonomous malware targeting internal databases within organizations - which we believe would lead to a greater risk of infection and compromise within a network," said Amichai Shulman, chief technology officer at Imperva. "Organizations need to take the risks posed by cloud services into consideration as they decide which data they want to store externally, and adopt a mitigation strategy accordingly."

While the perceived risk of cloud services is already high, the report identifies two factors in particular that increase risk to corporate data: the relative ease of accessing cloud databases, as well as the ease of quickly turning a legitimate foothold on these servers into a privilege escalation attack. Key findings also include:

  • Malware is now capable of connecting to both local and remote databases to retrieve, manipulate and exfiltrate information.

  • Malware can leverage DBaaS for botnet management (e.g., Command & Control as well as Dropper functionality).

  • Cloud databases are prone to attacks via both privilege escalation and exposed vulnerabilities, as opposed to on-premise databases, which are mostly compromised via privilege escalation.

To download the full Imperva report, please visit http://www.imperva.com/download.asp?id=436.

Featured Posts
Recent Posts
Search By Tags
Follow Us
  • Facebook Classic
  • Twitter Classic
  • Google Classic
ISSA
IDAgentPartner-Logo-black
download
LA Sports Color
17_nextLA_AQUA
SCLN Logo
SilverMidmarketSolutionProvider
sophos reflexion
58316-trend-micro-box
Microsoft-Partner-Silver-Small-and-Midmarket-Cloud
mspp_trustmark150
polycom-logo-h-cmyk_highres.jpeg
silver-partner.jpg
samsung-silver.jpg
oracle.jpg
Kaspersky_Lab_logo.jpg
Dlink.jpg
AVG-Reseller-Logo-Lockup_Authorized-Reseller_Authorized-Reseller.png
Los Angeles Area Chamber of Commerce
EZworknet Logo Bold.png
Irvine Chamber of Commerce
HUBLA2.jpg
Intronis
Proud Microsoft Partner
Hewlett pACKARD.gif
Datto_Authorized_Partner_Badge.jpg
Axcient1.jpg
Hewlett pACKARD.gif
APC
Ingram Micro Distribution
Proud IBM Partners
Proud Cisco Meraki Partners
Sonicwall
Dell Sonic Wall
Protect yourself with McAfee
Microsoft Certified Professional
Samsung
Cisco Meraki
Dell Partner Direct.
Proud Lenovo Partner
AdobeRegistered

Managed Technology Support Services  | Managed Security Service Provider

Irvine | Los Angeles | Santa Monica | Palm Springs | San Diego | Santa Barbara | Inland Valleys | Temecula

Toll Free:   1-800-884-1103      |       Email:  Info@ezworknet.com

  • Facebook App Icon
  • Twitter App Icon
  • Google+ Classic
  • LinkedIn App Icon
  • Pinterest App Icon
  • YouTube Classic

© 2019 EZworknet llc

EZworknet Logo Bold.png