Identity-based attacks have become one of the most rapidly evolving and dangerous threat vectors in recent years. Organisations are struggling to protect against identity-based attacks, which are growing in speed and sophistication. In this blog, Ian Tinney, CEO of 4Data Solutions, looks at why cybercriminals thrive on credentials and identities, explains why existing solutions can miss identity-based attacks and highlights why speed of real-time detection is a critical factor in mitigating the damage of identity-based attacks.

Identity-based threats have emerged as a primary vector for cyberattacks, posing significant risks to modern organisations. By exploiting vulnerabilities in identity and access management systems, threat actors can gain unauthorised access to sensitive data and systems. To mitigate these risks, organisations must implement comprehensive identity security solutions that incorporate strong authentication, authorisation and continuous monitoring.

Let’s look at some of the key factors behind the rise in identity-based attacks.

1. Increased reliance on digital identities
As organisations increasingly adopt cloud-based services and remote work models, the reliance on digital identities has grown significantly. This creates more opportunities for attackers to target and compromise these identities.

2. Increasingly sophisticated attack techniques
Attackers have become more sophisticated in their ability to steal, compromise and exploit identities. Techniques such as phishing, credential stuffing and social engineering are used to trick users into revealing their credentials or bypassing security controls.

3. Rise of remote work and BYOD
The rise of remote work and bring-your-own-device (BYOD) environments has introduced new challenges for identity management. It can be difficult to ensure that all devices and users are adequately protected and compliant with security policies.

4. Humans are easy to trick
As with so many other aspects of adversary tradecraft, phishing and smishing campaigns are growing more subtle and sophisticated, an unsettling trend fuelled by the rise of artificial intelligence (AI). AI has also made it significantly easier and cheaper for adversaries to create technologies such as stealer malware – specialised malware used to steal account passwords, cookies, credit card details, etc – giving criminals yet another method to harvest credentials and either use them against you or sell them on the criminal underground.

5. Identities are easy to monetise
There’s a thriving underground economy for stolen credentials, making them easier for criminals to monetise. Just a decade ago, usernames and passwords were essentially worthless. Today, threat actors can use, trade or sell stolen credentials more easily than ever, giving them more incentive to target this information.

6. Valid credentials are like cheat codes
Valid credentials allow attackers to bypass initial access and quickly move laterally within an environment, significantly reducing the time needed to achieve their objectives. This is partly why the average breakout time – the time it takes for an attacker to move from initial compromise to another host within the victim’s environment – is down to 79 minutes, with the fastest eCrime breakout time at just seven minutes!

7. Identities span the enterprise
Stolen credentials provide attackers with access to various systems and data, including cloud infrastructure and sensitive information. Without strong security controls like MFA, attackers can move quickly and freely within an organisation’s environment, potentially causing significant damage.

Why identity-driven attacks are extremely hard to detect
When a valid user’s credentials have been compromised and an adversary is masquerading as that user, it’s often challenging to differentiate between the user’s typical behaviour and that of an attacker using applications and tools existing in the target environment.

Lack of visibility and protection across attack paths means that it’s difficult to identify and address potential vulnerabilities throughout the complex web of interconnected components in a cloud infrastructure.

Existing solutions can miss identity-based attacks due to several factors:

  • Relying on outdated methods: Traditional security measures often focus on perimeter protection and network-based threats, overlooking the vulnerability of identities themselves. This includes relying on passwords as the primary authentication method, which can be easily compromised through phishing or brute-force attacks.
  • Lack of comprehensive identity visibility: Many organisations have fragmented identity systems, making it difficult to have a complete view of all user identities and their access privileges. This lack of visibility can make it challenging to detect and respond to unauthorised access or identity compromise.
  • Limited analytics and threat detection: Traditional security solutions may not have the advanced analytics capabilities to detect and respond to sophisticated identity-based attacks. This includes the ability to identify unusual patterns of behaviour, such as multiple failed login attempts from different locations, or the use of compromised credentials.
  • Slow response times: In the event of an identity-based attack, traditional security solutions may be slow to detect and respond. This can allow attackers to gain unauthorised access and cause significant damage before the breach is identified and remediated.
  • Inadequate risk assessment: Organisations may not have a comprehensive risk assessment process to identify and prioritise identity-related threats. This can lead to a focus on low-risk threats while neglecting more critical vulnerabilities that could lead to a data breach or other serious consequences.

Why speed is of the essence when detecting identity-based attacks
Speed is absolutely of the essence when detecting identity-based attacks. Modern cyberattacks, especially those targeting identities, are often highly automated and can happen within minutes or even seconds. The sooner an attack is detected, the less time an attacker has to exploit the compromised identity and cause damage. Quick detection can prevent the exposure of sensitive data, mitigate reputational damage, and prevent future breaches.

Breaches with stolen credentials take 292 days to detect. Adversaries move laterally undetected with valid credentials.

Several factors influence the time it takes to detect identity-based attacks:

  • Complexity of the attack: Sophisticated and novel attacks, such as credential stuffing, phishing, and account takeovers, can be difficult to detect in real-time due to their mimicry of legitimate user behaviour and their evolving nature.
  • Security infrastructure: The sophistication of security tools and the quality of data significantly impact the speed of detecting identity-based attacks. Advanced tools like IDS, SIEM, and behavioural analytics platforms, combined with accurate and timely data, are crucial for identifying suspicious activities.
  • Response time: The speed and efficiency of incident response teams and automated response mechanisms can significantly impact the containment of identity-based attacks.
  • Data volume and velocity: Analysing vast amounts of data in real-time, a computationally intensive task, is crucial for detecting and responding to fast-moving attacks. Efficient infrastructure and algorithms, along with real-time data streaming capabilities, are essential for timely detection.
  • Human factors: Skilled security analysts can identify subtle indicators of compromise that automated systems may miss. However, heavy workloads can hinder their ability to respond promptly to alerts and investigate incidents.

Conclusion

In today’s digital age, identity-based attacks pose a significant threat to organisations of all sizes. The rapid evolution of attack techniques, coupled with the increasing reliance on digital identities, has created a complex security landscape. To effectively combat these threats, organisations must prioritise speed and accuracy in detecting and responding to incidents. By implementing robust identity and access management solutions, leveraging advanced security technologies, and fostering a culture of security awareness, organisations can significantly reduce their risk exposure and protect their valuable assets.

You can register here to arrange a FREE Identity Security Risk Review from one of our identity experts. Alternatively, you can find out more about CrowdStrike Falcon® – the industry’s only adversary-focused platform that unifies endpoint and identity telemetry – by phoning us on +44 330 128 9180 or emailing info@4datasolutions.com.

CrowdStrike Falcon® provides real-time correlation of threats along with threat intelligence and adversary tradecraft. This is the only effective method to get full visibility into attack paths covering all aspects of the adversary toolkit – from exploitation and malware delivery to fileless attacks and stolen credentials – to stop the full attack lifecycle.