ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်
Attacker အများစုရဲ့ motivation က ငွေ (ransomware, fraud, stolen card data ရောင်း), data (personal info ရောင်း၊ industrial espionage), access (botnet အဖြစ်သုံးဖို့ device ခိုးယူ), reputation/politics (website defacement, disinformation) ဆိုတဲ့ လေးမျိုးထဲ ကျရောက်ပါတယ်။ Individual user တစ်ယောက်ကို 'ငါ့မှာ ခိုးစရာမရှိဘူး' လို့ ထင်စရာရှိပေမယ့် password ကို reuse လုပ်ထားရင် တခြား service ကို ဝင်ဖို့ steppingstone အဖြစ် သုံးနိုင်ပါတယ်။
လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်
Small business တစ်ခုက 'ငါတို့က ကြီးကြီးမားမား company မဟုတ်ဘူး, ဘာလို့ attack ခံရမလဲ' လို့ ထင်တတ်ပါတယ်။ တကယ်တော့ small business တွေက security investment နည်းလို့ attacker အတွက် target လွယ်ပါတယ် — Automated scanning tool တွေက target ကို manual ရွေးမနေဘဲ vulnerable server ရှိသလား scan ချည်း လုပ်နေတာပါ။ 'ကျွန်တော်တို့ target မဖြစ်နိုင်ဘူး' ဆိုတဲ့ ယူဆချက်က အန္တရာယ်အကြီးဆုံးပါ။
အတူတူ ကြည့်မယ်
Common attacker motivations
---------------------------
Money → ransomware, fraud, stolen card data
Data → personal info, corporate secrets
Access → botnet, steppingstone to bigger target
Reputation → defacement, disinformation, activismAttack news တစ်ခုကို ဖတ်ရင် motivation ဘယ်ဟာလဲ ခန့်မှန်းနိုင်မည်။၅ မိနစ် စမ်းကြည့်
မကြာသေးမီက ကြားဖူးတဲ့ cyber attack news တစ်ခုရွေးပြီး motivation ၄ မျိုးထဲက ဘယ်ဟာနဲ့ ကိုက်ညီလဲ ရေးကြည့်ပါ။
သတိလေးတစ်ချက်
Password ကို service အားလုံးမှာ ပြန်သုံးရင် (reuse) service တစ်ခု data leak ဖြစ်ရင် ကျန် account တွေပါ အန္တရာယ်ရှိပါတယ်။