2024資訊安全趨勢

科技的快速進步和演化為社會帶來了許多好處,但同時也帶來了更複雜的網路威脅。除了2023年人工智慧(AI)技術的迅速崛起及其帶來的風險外,許多權威組織、專家和學者也對2024年的資安趨勢進行了其他預測。

首先,生成式AI仍然會因駭客的惡意使用而帶來更多的資安風險。隨著生成式AI的應用擴大,駭客可能通過讓機器學習錯誤的資料,入侵模型的資料儲存或流程架構,從而導致自然語言模型洩漏機密資料或使系統受到汙染而無法正常運作。這種情況被稱為「資料下毒」。此外,生成式AI還提高了詐騙能力,例如變種詐騙和網絡釣魚。未來,駭客有可能結合不同的AI工具,以更逼真的方式進行勒索活動。

其次,預計供應鏈攻擊也會增加,其中一種名為供應鏈連鎖攻擊的攻擊方式成為駭客的主要手段之一。該攻擊方式是駭客首先獲取其中一個系統的存取權,然後利用該權限侵入與之相連接的其他系統。這種攻擊方式可以有效地避開堅固的防禦,利用互相連接、受信任但相對脆弱的目標中的漏洞,從而滲透到安全性更高的系統中。

此外,生成式AI的普及還將導致雲端網路成為新的攻擊目標。由於運行這些模型的成本急劇上升,甚至達到數千萬美元。因此,駭客開始將目標轉向雲端,他們在雲端建立算力農場,以籌集資金來支持他們的行動。與數年前以加密挖礦為主要目標不同,未來雲端算力農場可能成為攻擊的焦點。此外,根據預測,雲端原生蠕蟲攻擊也可能大規模出現,駭客可以通過感染的雲端技術作為跳板,將感染擴散到其他地方。蠕蟲可以一次感染多個容器並進行大規模攻擊漏洞,實現偵查、攻擊和常駐等全部自動化。

最後,私有區塊鏈也將成為駭客的攻擊目標。與公有區塊鏈不同,私有區塊鏈採用集中化的設計,並且不會經常在攻擊中不斷強化。未來,駭客可能針對這類區塊鏈開發基於勒索的全新商業模式。在這些勒索行動中,駭客可能使用竊取的金鑰故意在區塊鏈上插入惡意資料或篡改現有的交易記錄,然後向受害者勒索贖金作為封口費用。

總結來說,2024年的資訊安全環境持續面臨著各種威脅與挑戰。我們需要關注人工智慧技術的應用與相應的風險,加強對雲端環境的保護並普及多重驗證機制。教育用戶建立防範意識以應對釣魚和勒索軟體攻擊。同時,區塊鏈技術的應用可以提供更安全的驗證方式。企業需要投資人才培訓並建立良好的資訊安全文化。我們也應該提高資訊安全意識,持續關注技術發展與相應風險,以確保我們的數字生活安全。

 

尹展軒

Senior IT Consultant

More Updates

Further reading

𝗦𝘂𝗺𝗺𝗲𝗿 𝗵𝗼𝗹𝗶𝗱𝗮𝘆𝘀 𝗮𝗿𝗲 𝗵𝗲𝗿𝗲! 𝗛𝗮𝘃𝗲 𝘆𝗼𝘂 𝗽𝗹𝗮𝗻𝗻𝗲𝗱 𝘆𝗼𝘂𝗿 𝗻𝗲𝘅𝘁 𝘁𝗿𝗶𝗽 𝘆𝗲𝘁?

Whether you are travelling overseas, staying at a hotel, or working remotely while enjoying your vacation, there is one thing many of us rely on every day — 𝗵𝗼𝘁𝗲𝗹 𝗪𝗶-𝗙𝗶.After checking in, it is common to connect your laptop or phone to the hotel network without thinking twice. But have you ever wondered:“𝗖𝗮𝗻 𝗜 𝗿𝗲𝗮𝗹𝗹𝘆 𝘁𝗿𝘂𝘀𝘁 𝘁𝗵𝗶𝘀 𝗪𝗶-𝗙𝗶 𝗻𝗲𝘁𝘄𝗼𝗿𝗸?”Public Wi-Fi networks are convenient, but they can also become a target for attackers. A compromised hotel Wi-Fi gateway could potentially allow attackers to manipulate network traffic, redirect users to fake login pages, and steal sensitive information such as Microsoft 365 credentials.Some common risks include:🔹 Fake Wi-Fi login portals🔹 DNS redirection to malicious websites🔹 Credential harvesting through fake Microsoft 365 login pages🔹 Session hijacking attemptsA few simple steps can greatly reduce the risk:✅ Avoid accessing sensitive accounts on unknown networks✅ Use a trusted VPN when connecting through public Wi-Fi✅ Enable Multi-Factor Authentication (MFA)✅ Verify the website address before entering credentials✅ Avoid installing unexpected certificates or applications requested by public networks

𝗘𝗻𝘁𝗲𝗿𝗽𝗿𝗶𝘀𝗲 𝗔𝗜 𝗗𝗼𝗲𝘀𝗻'𝘁 𝗦𝘁𝗮𝗿𝘁 𝘄𝗶𝘁𝗵 𝗔𝗜. 𝗜𝘁 𝗦𝘁𝗮𝗿𝘁𝘀 𝘄𝗶𝘁𝗵 𝗔𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲.

Every organisation is asking the same question today:"𝘏𝘰𝘸 𝘤𝘢𝘯 𝘸𝘦 𝘪𝘯𝘵𝘳𝘰𝘥𝘶𝘤𝘦 𝘈𝘐 𝘪𝘯𝘵𝘰 𝘰𝘶𝘳 𝘣𝘶𝘴𝘪𝘯𝘦𝘴𝘴?"But experienced solution architects often start somewhere else.They ask:"𝘐𝘴 𝘵𝘩𝘦 𝘣𝘶𝘴𝘪𝘯𝘦𝘴𝘴 𝘴𝘺𝘴𝘵𝘦𝘮 𝘥𝘦𝘴𝘪𝘨𝘯𝘦𝘥 𝘵𝘰 𝘴𝘶𝘱𝘱𝘰𝘳𝘵 𝘈𝘐 𝘧𝘳𝘰𝘮 𝘵𝘩𝘦 𝘣𝘦𝘨𝘪𝘯𝘯𝘪𝘯𝘨?"That's an important distinction.Modern enterprise platforms such as 𝗢𝘂𝘁𝗦𝘆𝘀𝘁𝗲𝗺𝘀 now make it possible to build applications, workflows, integrations and AI capabilities within a single development ecosystem.Adding AI is becoming easier than ever.Designing an application that allows AI to deliver reliable business value is the real challenge.Because AI does not work in isolation.It relies on the business systems behind it.Before AI can analyse information, automate decisions or assist users, it depends on a strong enterprise foundation:🔸 𝗖𝗹𝗲𝗮𝗿𝗹𝘆 𝗱𝗲𝗳𝗶𝗻𝗲𝗱 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗽𝗿𝗼𝗰𝗲𝘀𝘀𝗲𝘀🔸 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗴𝗼𝘃𝗲𝗿𝗻𝗲𝗱 𝗱𝗮𝘁𝗮🔸 𝗪𝗲𝗹𝗹-𝗱𝗲𝘀𝗶𝗴𝗻𝗲𝗱 𝘀𝘆𝘀𝘁𝗲𝗺 𝗶𝗻𝘁𝗲𝗴𝗿𝗮𝘁𝗶𝗼𝗻𝘀🔸 𝗖𝗼𝗻𝘀𝗶𝘀𝘁𝗲𝗻𝘁 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗿𝘂𝗹𝗲𝘀🔸 𝗔𝗽𝗽𝗿𝗼𝗽𝗿𝗶𝗮𝘁𝗲 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝗻𝗱 𝗮𝗰𝗰𝗲𝘀𝘀 𝗰𝗼𝗻𝘁𝗿𝗼𝗹𝘀These are not "AI features."They are architectural decisions.When these foundations are built into the application from Day One, AI becomes a natural extension of the business rather than an isolated feature.This is why successful enterprise AI projects don't begin with selecting an AI model.They begin with designing an application architecture that allows AI, data, workflows and enterprise systems to work together seamlessly.That's where enterprise low-code platforms like 𝗢𝘂𝘁𝗦𝘆𝘀𝘁𝗲𝗺𝘀 create long-term value.Not by simply making development faster.But by providing a platform where business applications can continuously evolve as new technologies—including AI—become part of the organisation's digital journey.Before asking:"𝘏𝘰𝘸 𝘥𝘰 𝘸𝘦 𝘢𝘥𝘥 𝘈𝘐 𝘵𝘰 𝘵𝘩𝘪𝘴 𝘢𝘱𝘱𝘭𝘪𝘤𝘢𝘵𝘪𝘰𝘯?"Perhaps the better question is:"𝘈𝘳𝘦 𝘸𝘦 𝘥𝘦𝘴𝘪𝘨𝘯𝘪𝘯𝘨 𝘢𝘯 𝘢𝘱𝘱𝘭𝘪𝘤𝘢𝘵𝘪𝘰𝘯 𝘵𝘩𝘢𝘵 𝘪𝘴 𝘳𝘦𝘢𝘥𝘺 𝘵𝘰 𝘦𝘷𝘰𝘭𝘷𝘦 𝘸𝘪𝘵𝘩 𝘈𝘐 𝘧𝘳𝘰𝘮 𝘋𝘢𝘺 𝘖𝘯𝘦?"Because successful enterprise AI isn't defined by the intelligence of the model.𝗜𝘁'𝘀 𝗲𝗻𝗮𝗯𝗹𝗲𝗱 𝗯𝘆 𝘁𝗵𝗲 𝗶𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗼𝗳 𝘁𝗵𝗲 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 𝗯𝗲𝗵𝗶𝗻𝗱 𝗶𝘁.

𝗦𝗲𝗰𝘂𝗿𝗶𝗻𝗴 𝘁𝗵𝗲 𝗖𝗹𝗼𝘂𝗱 𝘄𝗶𝘁𝗵 𝗜𝗦𝗢/𝗜𝗘𝗖 𝟮𝟳𝟬𝟬𝟭:𝟮𝟬𝟮𝟮

Cloud services have become the backbone of modern business, enabling organisations to operate with greater speed, flexibility, and scalability. However, moving to the cloud does 𝗻𝗼𝘁 transfer all security responsibilities to the cloud provider.Many cloud platforms operate under a 𝘀𝗵𝗮𝗿𝗲𝗱 𝗿𝗲𝘀𝗽𝗼𝗻𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆 𝗺𝗼𝗱𝗲𝗹, where organisations remain accountable for protecting their data, identities, and cloud configurations. That's why effective cloud security requires more than selecting a trusted provider—it demands clear governance, ongoing monitoring, and practical security controls.Here are three key areas organisations should focus on when securing their cloud environments:☁️ 𝟭. 𝗨𝗻𝗱𝗲𝗿𝘀𝘁𝗮𝗻𝗱 𝗬𝗼𝘂𝗿 𝗦𝗵𝗮𝗿𝗲𝗱 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆A strong cloud security strategy begins with clearly defining responsibilities between your organisation and the cloud service provider.・Clearly define security roles and responsibilities between both parties.・Review the provider's security certifications, whitepapers, and control documentation.・Establish Service Level Agreements (SLAs) covering availability, incident response, and security expectations.・Regularly evaluate the provider's security performance—not just during onboarding.🔐 𝟮. 𝗣𝗿𝗼𝘁𝗲𝗰𝘁 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝗶𝗲𝘀 𝗮𝗻𝗱 𝗗𝗮𝘁𝗮Protecting access and sensitive information remains one of the most critical aspects of cloud security.・Enforce strong authentication, including Multi-Factor Authentication (MFA).・Review user access regularly and remove unnecessary permissions.・Classify sensitive data before migrating it to cloud environments.・Encrypt data both in transit and at rest wherever possible.📊 𝟯. 𝗠𝗼𝗻𝗶𝘁𝗼𝗿 𝗮𝗻𝗱 𝗕𝘂𝗶𝗹𝗱 𝗥𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲Cloud security is an ongoing process that requires continuous visibility and preparedness.・Monitor cloud environments for unusual activities and configuration issues.・Ensure cloud-specific incident response procedures are clearly defined and tested.・Verify that backup processes are functioning correctly and can support recovery.・ Regularly test whether critical services can be restored within acceptable recovery timeframes.Cloud security is not a one-time project—it's an ongoing discipline built on 𝗰𝗹𝗲𝗮𝗿 𝗼𝘄𝗻𝗲𝗿𝘀𝗵𝗶𝗽, 𝗿𝗲𝗴𝘂𝗹𝗮𝗿 𝗿𝗲𝘃𝗶𝗲𝘄, 𝗮𝗻𝗱 𝗰𝗼𝗻𝘁𝗶𝗻𝘂𝗼𝘂𝘀 𝗶𝗺𝗽𝗿𝗼𝘃𝗲𝗺𝗲𝗻𝘁.𝗥𝗲𝗺𝗲𝗺𝗯𝗲𝗿: Moving to the cloud doesn't transfer your security responsibilities—it changes how they should be managed.ISO/IEC 27001:2022 provides organisations with a structured framework to manage cloud-related risks while supporting business growth and digital transformation.