{"id":18268,"date":"2022-05-10T12:02:16","date_gmt":"2022-05-10T10:02:16","guid":{"rendered":"https:\/\/www.proactivanet.com\/blog\/sin-categorizar\/consider-you-vulnerable-assets-over-the-long-term\/"},"modified":"2023-02-21T09:57:36","modified_gmt":"2023-02-21T08:57:36","slug":"consider-you-vulnerable-assets-over-the-long-term","status":"publish","type":"post","link":"https:\/\/www.proactivanet.com\/en\/blog\/safety-management\/consider-you-vulnerable-assets-over-the-long-term\/","title":{"rendered":"Consider you vulnerable assets over the long term\u2026"},"content":{"rendered":"<p class=\"p1\"><span class=\"s1\">When we refer to vulnerabilities and cybersecurity, we mean weaknesses in the system that allow attackers to compromise the confidentiality, integrity and availability of these systems and the information and services hosted. In other words, <strong>vulnerable assets<\/strong>.<\/span><\/p>\n<p><!--more--><\/p>\n<p class=\"p1\"><span class=\"s1\">Although it is not always the case, vulnerabilities can be attributed to defects in the design of the system that result in its development not being conducted in accordance with the best security-related practices. In other cases, they are the result of technological limitations, because, as we all know, there is no such thing as a 100% secure system.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">We know that there is a lucrative market for sale of exploits for vulnerabilities to which we do not yet have a solution, but proper management of known vulnerabilities reduces the time of exposure to possible attacks and minimizes the risk of being attacked using known attack vectors.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Many of the best-known cases that have become public lately, and many others that have not, take advantage of these vulnerabilities that already have a solution available but that the organizations have not corrected.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">In almost all situations, cyber attackers carry out their work in different phases:<\/span><\/p>\n<ol class=\"ol1\">\n<li class=\"li1\"><span class=\"s1\"><strong>Reconnaissance<\/strong>: this is a phase in which the attacker seeks information about the target, usually relying on public sources.<span class=\"Apple-converted-space\"> <\/span><\/span><\/li>\n<li class=\"li1\"><span class=\"s1\"><strong>Preparation<\/strong>: in which the attacker prepares the artifact that it intends to distribute by utilizing certain tactics, techniques and procedures.<span class=\"Apple-converted-space\"> <\/span><\/span><\/li>\n<li class=\"li1\"><span class=\"s1\"><strong>Delivery<\/strong>: the attacker locates a vector for the attack, usually based on human error.<\/span><\/li>\n<li class=\"li1\"><span class=\"s1\"><strong>Exploitation<\/strong>: usually based on exploiting a vulnerability or a suboptimal system configuration, which enables escalation of privileges within the compromised system.<\/span><\/li>\n<li class=\"li1\"><span class=\"s1\"><strong>Installation<\/strong>: the main goal is establishing persistence and camouflaging itself to avoid being detected while moving laterally within the organization in order to compromise other systems that are more attractive for the attacker.<\/span><\/li>\n<li class=\"li1\"><span class=\"s1\"><strong>Control<\/strong>: usually for the purpose of exfiltration, hijacking or destruction of information.<\/span><\/li>\n<li class=\"li1\"><span class=\"s1\">Lastly <strong>demanding a ransom<\/strong>.<\/span><\/li>\n<\/ol>\n<p class=\"p1\"><span class=\"s1\">This is the reason that automation and early alert for <strong>vulnerable assets<\/strong> take on an essential role in cybersecurity management. Automation makes it possible to detect and respond to known threats in the most effective manner. It is the most effective way to reduce the total area of exposure.<\/span><\/p>\n<h2 class=\"p2\"><span class=\"s1\">\u2026 because it is perseverance that counts<\/span><\/h2>\n<p class=\"p1\"><span class=\"s1\">Attackers use increasingly sophisticated methods and design new types of attacks that are difficult to detect. Furthermore, security systems process huge amounts of data with origin in numerous sources that human beings are not able to process.<span class=\"Apple-converted-space\"> <\/span><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">The growing number of threats, added to a limited number of human resources dedicated to security, mean that at present it takes more than three months to detect a hidden threat in systems.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">In spite of this, how can a security analyst or administrator make the correct decisions regarding an alert if all the necessary information is not available?<span class=\"Apple-converted-space\"> <\/span><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Analysts must rely on the context surrounding an alert to decide which actions to take, and the manual process of obtaining information on the entire infrastructure of an organization can take days, weeks or even months. Just one piece of information: in 2021, almost 22,000 vulnerabilities were published, more than 60 each day.<\/span><\/p>\n<h2 class=\"p2\"><span class=\"s1\">What if we could detect vulnerable assets and receive an alert in real time?<\/span><\/h2>\n<p class=\"p1\"><span class=\"s1\">If we are able to break down the barrier between the ITAM world and cybersecurity, then we can achieve this.<span class=\"Apple-converted-space\"> <\/span><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Whereas producers of software and operating systems identify and version products without a standard criterion, in the cybersecurity field this has been resolved for several years. Standardization has already been accomplished for some time in the field of vulnerabilities, and MITRE was in charge of carrying out this task.<span class=\"Apple-converted-space\"> <\/span><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Analysis and correlation of all information in real time is the solution, but we know that it is not feasible to have available vulnerability scanners to analyze all our assets on a continuous basis. For technological and financial reasons, it is very complicated for an organization to be willing to deploy and maintain this entire infrastructure. Moreover, from the strategic standpoint and the standpoint of provision of services, it is not feasible to expose our systems to a potential loss of performance 0, or even trigger a shutdown of the business.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">At present, the solution lies in working with information that is continuously compiled and updated without having to interact with systems in operation.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Based on the knowledge that can be provided by discovery and correct management of assets, namely, the entire inventory of devices, operating systems, products, their correspondence with common platform enumeration (CPE) and the broadest possible database of vulnerabilities and products, it is possible to obtain a very advanced vision of the status of security in any organization.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Once we know what vulnerability affects our information systems, we will be in a position to manage them, making decisions in keeping with the level of our appetite for risk that we are willing to assume.<\/span><\/p>\n<h3 class=\"p2\"><em><span class=\"s1\"><b>YES, YES, YES... we are going to Paris. <span class=\"Apple-converted-space\"> <\/span><\/b><\/span><\/em><\/h3>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-7513 size-large\" src=\"https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables-1024x576.jpeg\" alt=\"Consider you vulnerable assets over the long term\u2026\" width=\"1024\" height=\"576\" srcset=\"https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables-1024x576.jpeg 1024w, https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables-300x169.jpeg 300w, https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables-768x432.jpeg 768w, https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables-640x360.jpeg 640w, https:\/\/www.proactivanet.com\/wp-content\/uploads\/2022\/05\/90-minuti-con-activos-vulnerables.jpeg 1440w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>I hope that you enjoy it, and farewell<\/p>\n<p><em>Jes\u00fas Castellanos<\/em><\/p>\n<p><em>Consulting and Compliance Manager in the <a href=\"https:\/\/www.grupoica.com\/\" target=\"_blank\" rel=\"noopener\">ICA Group<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When we refer to vulnerabilities and cybersecurity, we mean weaknesses in...  <\/p>\n<div class=\"read-more mt-4 text-blue text-xs\"><\/div>\n","protected":false},"author":7,"featured_media":16698,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1464],"tags":[1465,1466,1467,1468,1469],"class_list":["post-18268","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-safety-management","tag-security-en","tag-cybersecurity","tag-safety-management","tag-vulnerabilities-en","tag-vulnerable-assets"],"acf":{"is_icon":["no"]},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/18268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/comments?post=18268"}],"version-history":[{"count":0,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/18268\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media\/16698"}],"wp:attachment":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media?parent=18268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/categories?post=18268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/tags?post=18268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}