Running Head: IT 549 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
IT-549 6-2: Scenario Assignment
SNHU
IT 549 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Quantitative Data
In the organizational context, spoofing could act as a major security concern that
could increase the vulnerability of the IT ecosystem. It is not easy to quantify the exact
extent of the security issue as it could depend on a wide range of factors like the
number of networks that are unable to filter the ingress traffic securely. According to
the network infrastructure security practices figure, 57 of the respondents have anti-
spoofing elements at their network edges (Benno Overeinder: Measuring Spoofed Traffic
| Internet Society, 2019).
Similarly, the average Denial of service attack such as DDOS has trebled in the
last year. The average attack volume has expanded by 194 percent and the hyper-scale
volume has also grown by 150 percent year-on-year (GmbH, 2019). This quantitative
data shows that there is a possibility for DOS to act as a probable threat or vulnerability
for the organization.
The advanced persistent threats (APT) are a parasitical form of cyber-attack that
can infiltrate the computer systems of organizations. According to a report by Cloud
Security Alliance (CSA), the Chinese Cyber-Espionage used its APT model for the
purpose of stealing hundreds of terabyte of data and information from almost 141
organizations from a diverse industrial setting (The Treacherous 12, 2019, p 24).
According to ENISA Threat Landscape Report 2018, the most common form of
threat was the Structured Query Language (SQL) injection in the year 2018. This is
because it dominated the cyber-attack scene by 51 percent (Tounsi & Rais, 2018).
Insight
In the 21st century, the technology setting is highly dynamic and unpredictable in
nature. It can, in fact, give rise to a number of vulnerabilities and threats that can
IT 549 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
adversely influence the IT infrastructure of a business organization. The information
technology landscape is growing and changing like never before. The dynamic nature of
the cyber setting is intensifying the types of threats and vulnerabilities that arise and
impact business organizations (Internet Security Threat Report, 2019). A wide range of
online threats and vulnerabilities have come into the cyber scene such as spoofing,
tampering, repudiation, information disclosure, denial of service (DOS) and elevation of
privilege. The threats that exist in the cyber environment are constantly evolving due to
the evolving nature of the IT setting.
According to the Internet Security Threat Report, data breaches and privacy
issues are becoming quite common with the passage of time. The insider threat is a
common form of threat that business undertakings have to closely monitor to minimize
the level of cyber vulnerability. In the year 2015, the insider threat accounted for 10
percent of data breaches and security issues, but according to the NetDiligence Cyber
Claims study, the incident involvement was much higher and it constituted to 32 percent
of the claims that had been submitted in 2015 (Internet Security Threat Report, 2019, p
53).
Trend in Resources
The cyber-attacks arise from various angles and adversely impact a wide range of
industries and sectors. The industries that are highly vulnerable in the current times due
to the risks in the instances of cyber threats include the healthcare industry, businesses,
banking or finance industry, government or military, and the education industry. The
cyber-attacks work individually or in groups to exploit business organizations that work
in different industries in the dynamic market setting (Manship, 2019).
As per the existing trend in resources, there are a number of advanced persistent
threat (APT) groups that are particularly involved in the gathering of this kind of data.
IT 549 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
Just like other individual cyber attackers, APT groups intend to steal confidential and
sensitive data. Their fundamental intention is to disrupt the operations that are carried
out in the Information Technology infrastructure of a business concern (Platform, 2019).
The cyber attackers work for weeks and months together so that they can infiltrate
various security layers of business organizations and break the defense model.
References
Benno Overeinder: Measuring Spoofed Traffic | Internet Society. (2019). Retrieved from
https://www.internetsociety.org/resources/deploy360/2013/benno-overeinder-
measuring-spoofed-traffic/
GmbH, L. (2019). Average DDoS Attack Volumes Have Trebled in Past Year - Link11.
Retrieved from https://www.link11.com/en/blog/average-ddos-attack-volumes-have-
trebled-in-past-year/
Internet Security Threat Report. (2019). Retrieved from
https://www.symantec.com/content/dam/symantec/docs/reports/istr-21-2016-en.pdf
Manship, R. (2019). The Top 6 Industries At Risk For Cyber Attacks. Retrieved from
https://www.redteamsecure.com/the-top-6-industries-at-risk-for-cyber-attacks/
Platform, H. (2019). Advanced Persistent Threat Groups | FireEye. Retrieved from
https://www.fireeye.com/current-threats/apt-groups.html
The Treacherous 12. (2019). Retrieved from
https://downloads.cloudsecurityalliance.org/assets/research/top-threats/Treacherous-
12_Cloud-Computing_Top-Threats.pdf
Tounsi, W., & Rais, H. (2018). A survey on technical threat intelligence in the age of
sophisticated cyber attacks. Computers & security, 72, 212-233.