Skip navigation

Cyber security: the threat on the internet and how you can protect yourself

In the following blog post, you'll get an overview of the field of cyber security. We'll also inform you about various types of threats and show how we can support you.

Marcus AsshauerMarcus AsshauerSenior System Engineer · synaigy

6 min. reading time

Internet-Bedrohungen und wie du dich schützen kannst

The challengers

The current challenges in the field of cyber security can be divided into 4 areas:

Malware

Malware is software that is smuggled into company networks / environments and then causes damage there. In recent years, attacks have increased in which the systems of affected companies are encrypted and can then be released again upon payment of a ransom. This particular type of malware is also known as ransomware. Other malware scenarios include the espionage of data or the crippling of entire environments by exploiting vulnerabilities in software.
Common gateways for malware are usually e-mail attachments or infections via website visits.

Phishing

Phishing attempts to spy out access data for particular systems. The approach is in some ways similar to malware, where a spyware tool is smuggled onto the end systems to record users' input. Another common method is to lure users to fake login pages and intercept passwords there. In most cases, the gateway for phishing is e-mail, but it can also be by telephone.

(D)DoS

(D)DoS attacks are characterised by aiming to flood a particular service, e.g. a website, with requests so that the system can no longer manage to answer them. So what's the difference between DoS and DDoS? In a Denial of Service (DoS) attack, a single source attempts to overload the target system. Due to the constant improvement of resources in current systems, both in terms of bandwidth and better CPU performance, it's becoming difficult to overload a system with just one source. That's why nowadays most attacks of this kind are distributed across many systems — hence Distributed Denial of Service (DDoS). This also makes defending against such attacks harder, since malicious traffic must be filtered very precisely from legitimate traffic. The gateways are the public interfaces of the systems.

Brute force

Brute-force attacks are the classic attacks used to "guess" login data by trying it out. Based on our experience with the environments we manage, we can also classify further "web attacks" under this type of attack, which target vulnerabilities and SQL injections, since certain scenarios are simply run through here as well. Brute-force requests can definitely be traced and detected very well in the log files of the individual services. The gateways are the public interfaces of the systems. Where and how can we help you?

Malware

Here, the end devices and company networks of the customer are affected. We're only able to support here to a limited extent, when there's a VPN connection to a system hosted by us. Here, we can use firewall rules at the VPN gateway to prevent the spread of malware from the VPN and also prevent malware being brought in via the VPN.

Phishing

Here too, the gateway is on the customer's side. What we do, however, is protect the logins of the systems we host. For example, via an integration of two-factor authentication or, in the simplest case, by placing another authentication layer in front. However, these measures only prevent the exploitation of intercepted login data, not the spying itself.

DDoS

All attacks in this area fall, for the systems we look after, within our remit. That's why, when choosing our hosting providers, we already made sure they have DDoS protection. This means the systems are generally protected against these types of attacks. Generally speaking, if a DDoS attack gets through as far as the system itself, there's not much more that can be done. That's why we also recommend using a CDN such as Cloudflare as extra protection for the website, to stop potential DDoS attacks as far upstream as possible. Of course, a CDN has other benefits too, particularly around performance, but those aren't covered further here. So why still have DDoS protection at the host as well? Upstream DDoS protection via a CDN can only help against attacks on the DNS name; it offers no protection against attacks on the IP address.

Brute force

Brute-force attacks happen constantly on many levels and on nearly all systems publicly reachable via the internet. Usually a glance at the ssh/authentication log files is enough to confirm this. What matters with brute-force attacks, whatever the system and whether login or vulnerabilities are affected, is detection. Once such an attack is detected, the attacker can, ideally automatically, be blocked. There are manifold ways to react to such events. One of our recommendations here is again the use of a CDN with appropriate security features such as a web application firewall. Beyond that, a somewhat more generalised approach is also possible and sensible. As described at the outset, these types of attacks aren't tied to one service or protocol — SSH, FTP and web services are all popular targets. Thanks to the good detection options in log files, you can classically use fail2ban here, or better still CrowdSec - The open-source & collaborative security suite. The advantage is that this also blocks IPs that have been flagged by other users. The further benefits of Crowdsec will be covered in more depth in a later blog post. Other ways to defend against brute-force attacks include firewall rules with rate limits, possibly deploying a web application firewall for web services, or other log analysis tools that can generate alerts.

Where can I find out more about these topics?

Good overview and introduction to cyber security offered by course Community Driven Cybersecurity (in English) on new Crowdsec Academy. It offers a much broader view of topics. Based on this overview, we aim here to give overview of which challenges in this area we already address and where we can help.

Conclusion

In conclusion, of the 4 major cyber threats currently affecting our customers in 3 areas, we have either already implemented responses and solutions "by design", or can implement them in a personalised way.

In our Managed Commerce offering (https://www.synaigy.com/details/managed-commerce) and Managed Cloud Hosting (https://www.synaigy.com/details/managed-cloud-hosting), we offer you a setup that lets you sleep more soundly.

We're happy to support and advise you on all topics relating to cyber security, just get in touch.

Subscribe to the blog now and never miss any news again

✔️free ✔️weekly news ✔️expert knowledge

Please accept the corresponding cookies to view this embedded content.