http://m.sharifulalam.com 2018-01-08 17:31 《中華工控網》翻譯
Kaspersky Report: Targeted attacks against ICS sector on the rise
卡巴斯基報告:針對工業控制系統的目標攻擊上升
January 5, 2018 – According to the Kaspersky Lab, IT Security Risks Survey, every fourth industrial company of over 900 surveyed faced a variety of cyberattacks in 2017. Of the evolving types of threats used by cybercriminals, one of the fastest growing types aimed at industrial organizations is targeted attacks, with 28 percent of those surveyed admitting they faced an attack in 2017, compared to 20 percent in 2016.
2018年1月5日——根據卡巴斯基實驗室的《信息安全風險調查》,在2017年,900余家被調查的工業公司面臨著各種各樣的網絡攻擊。網絡罪犯所使用的威脅不斷演變,其中一個針對工業組織的增長最快類型是有針對性的攻擊,28%的被調查者承認他們在2017年遭遇襲擊,而2016年這一比例只有20%。
The survey also revealed that 48 percent of industrial businesses have insufficient insight into the threats specifically faced by their business. With a lack of network visibility, 87 percent of industrial companies responded affirmatively when asked if any of the informational technology/operational technology (IT/OT) security events they experienced over the previous year were complex. Given there is an unclear understanding of the threats they are facing, it’s no surprise that industrial organizations spend on average of several days (34%) to several weeks (20%) detecting a cyberattack.
該調查還顯示,48%的工業企業對其業務所面臨的威脅沒有足夠的洞察力。由于缺乏網絡可視性,當被問及他們在過去一年所經歷的信息技術/運營技術(IT/OT)安全事件是否復雜時,87%的工業企業做了肯定回答。鑒于人們對他們所面臨的威脅了解不多,工業組織平均花費數天(34%)到數周(20%)來檢測網絡攻擊就不足為奇了。
Although industrial organizations lack insight and have difficultly identifying cyberattacks in their networks, they are fully aware of the need for high-quality protection against cyberthreats. In fact, 62 percent of employees at industrial companies firmly believe it’s necessary to use more sophisticated IT security software. However, software alone is not enough: almost half (49%) of industrial company respondents blame staff for not properly following IT security policies, which is 6 percent more than respondents surveyed that belong to other sectors.
盡管工業組織缺乏洞察力,在他們的網絡中難以識別網絡攻擊,但他們充分意識到需要高質量的保護來抵御網絡威脅。事實上,工業企業62%的員工堅信有必要使用更復雜的IT安全軟件。不過,僅靠軟件是不夠的:近一半(49%)的受訪工業企業指責員工沒有正確遵守IT安全政策,這一比例比其他行業的受訪者高出6%。
“Cyberattacks on industrial control systems have become the indisputable number-one concern,” said Andrey Suvorov, head of critical infrastructure protection business development at Kaspersky Lab. “The good news is that the majority of industrial market players know which threats are coming to the forefront today and will be relevant in the near future. With this knowledge in mind, it’s critically important to implement a flexible, complex security solution that is designed to protect automated industrial environments and is configured in accordance with the technological processes of each organization.”
“網絡攻擊在工業控制系統已成為無可爭議的頭號問題,”卡巴斯基實驗室關鍵基礎設施保護業務發展主管Andrey Suvorov,“好消息是,絕大多數的工業市場參與者知道哪些威脅今天備受關注,并在不久的將來牽涉其身。考慮到這些認知,實現一個靈活的、復雜的安全解決方案至關重要,該解決方案旨在保護自動化的工業環境,并按照每個組織的技術流程進行配置。”
Due to the steady increase in complexity and number of attacks on the industrial market, the consequences of industrial organizations ignoring cybersecurity threats in 2018 could be disastrous. Cybersecurity awareness training is a must when it comes to cybersecurity in industrial organizations, given that all employees – from the administration side to the factory floor – play a key role in the safety of an enterprise and maintaining operational continuity.
由于工業市場的復雜性和攻擊次數不斷增加,工業組織在2018年忽視網絡安全威脅的后果可能是災難性的。在工業組織中,網絡安全意識培訓是必須的,因為所有的員工——從行政部門到工廠——都在企業的安全和保持運營的連續性中扮演著關鍵的角色。
The Kaspersky Lab survey findings further confirm the predictions of Kaspersky ICS CERT experts about the emergence of specific malware that will target vulnerabilities in industrial automation components this year.
卡巴斯基實驗室的調查結果進一步證實了卡巴斯基工控系統網絡應急響應小組專家的預測,今年將出現針對工業自動化組件漏洞的特定惡意軟件。