Issue link: https://insights.oneneck.com/i/1458399
26 Data Center & Hybrid Cloud Security For Dummies, Palo Alto Networks Special Edition These materials are © 2020 John Wiley & Sons, Inc. Any dissemination, distribution, or unauthorized use is strictly prohibited. compromised credentials. Credential theft has become so prev- alent in the attackers' playbook that it's often said that attackers no longer hack into a target network — they simply log in. The primary techniques that attackers use to steal credentials include: » Social engineering » Phishing and malware » Brute force » Security question reuse » Reusing stolen passwords or shared credentials sold on the dark web Attackers use these credentials to gain access to a network, move laterally, and escalate their privileges for unauthorized access to applications and data (see the "Credential theft: Shamoon 2" sidebar in this chapter). With stolen credentials as part of their toolset, attackers' chances of successfully breaching go up, and their risk of getting caught goes down. To prevent credential theft, most organizations rely on employee education, which is prone to human error by nature. Technology products commonly rely on identifying known phish- ing sites and filtering email. However, these methods can some- times be bypassed — checking for known bad sites misses newly created ones, and attackers can evade mail filtering technology by sending links through social media. Organizations should look for a firewall with machine learning- based analysis to identify websites that steal credentials. If the analysis identifies a site as malicious, the firewall should be automatically updated in real time and block it. Still, there will always be new, never-before-seen phishing sites that are treated as "unknown." Your firewall must allow you to block submission of user credentials to unknown sites. The firewall must also allow you to protect sensitive data and applications by enforcing multi- factor authentication (MFA) to prevent attackers from abusing stolen credentials. By integrating with common MFA vendors, your firewall can protect your applications containing sensitive data, including legacy applications.