The first step of any information-based attack--"legitimate" hacking, phishing, social engineering, and so on--is information gathering. This can be done online, in a dumpster, over the phone, through wireless sniffing, or through "chance" meetings. All these actions can reveal information about the target, and any one piece of information can lead to the toehold of the next successful breach.
This makes sense: a well-informed attacker is much more formidable than an uninformed one. "Plans are established by counsel; by wise counsel wage war" (Proverbs 20:18) is a principle that applies to hackers and InfoSec professionals alike, and the ability of a single attacker (or defendant) to successfully carry out their agenda is largely dependent on their ability to utilize good counsel/information/data.
The Internet of Things is a double-edged sword in this topic; a hacker can clandestinely find a lot of information from an improperly configured webcam (think Shodan), and the huge amount of traffic so many Internet-connected devices will produce can be used for evil quite easily. However, this large amount of data can also be used by the InfoSec professional to predict, prevent, and detect attacks. For example, we can "fight fire with fire"--perform Internet reconnaissance on our own organizations, identify information that could be used by an attacker, and remove it from the Internet and/or adjust our defenses to address these revealed attack vectors. Also, using data from current attacks (such as IoT-based botnets that can perform 400Gbps DDoS attacks) can help us identify and remediate current vulnerabilities and potential threats. This data is on the Internet--perhaps not directly on Google itself, but on the networks that comprise the Internet. Thus, Internet recon isn't all bad; it just depends on how it is used.
This makes sense: a well-informed attacker is much more formidable than an uninformed one. "Plans are established by counsel; by wise counsel wage war" (Proverbs 20:18) is a principle that applies to hackers and InfoSec professionals alike, and the ability of a single attacker (or defendant) to successfully carry out their agenda is largely dependent on their ability to utilize good counsel/information/data.
The Internet of Things is a double-edged sword in this topic; a hacker can clandestinely find a lot of information from an improperly configured webcam (think Shodan), and the huge amount of traffic so many Internet-connected devices will produce can be used for evil quite easily. However, this large amount of data can also be used by the InfoSec professional to predict, prevent, and detect attacks. For example, we can "fight fire with fire"--perform Internet reconnaissance on our own organizations, identify information that could be used by an attacker, and remove it from the Internet and/or adjust our defenses to address these revealed attack vectors. Also, using data from current attacks (such as IoT-based botnets that can perform 400Gbps DDoS attacks) can help us identify and remediate current vulnerabilities and potential threats. This data is on the Internet--perhaps not directly on Google itself, but on the networks that comprise the Internet. Thus, Internet recon isn't all bad; it just depends on how it is used.
No comments:
Post a Comment