Top countries where cyber attacks originate

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Top countries where cyber attacks originate

L3 Networker

Good day everyone, 

I am looking for some help information with finding "Top 15 countries where cyber attacks originate"

I know there are alot of blocklist out there, those have IP addresses. That is not what I am needing. 

 

If anyone can recommend websites or which countries they have blocked with the reason as well. 

 

I am looking to but together a report showing which countries would be best in blocking that active.

Thank you for any help you can provide.

 

 

1 accepted solution

Accepted Solutions

@AdamCoombs,

The entire concept is what many coin 'Zero Trust Architecture'. Palo themselves has a lot of good information on it HERE and HERE and why 'Zero Trust' is the better way to do things. 

It's not necessary that blocking source countries that are known bad actors is a bad thing, it will certaintly help cut down on the number of logs and such being detected; it's that this is the lowest hanging fruit, it may have already even fallen off the tree. In my mind it's better to get into their mind of only handling legitimate traffic.

View solution in original post

6 REPLIES 6

Cyber Elite
Cyber Elite

hi @AdamCoombs

 

You may want to look into our Autofocus subscription

 

If you reach out to a sales team near you they can probably set you up with a trial (check out this link for a quick overview: Our Most Intelligent Service Yet)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

@AdamCoombs,

I have to say that in general I really hate the idea of blocking countries simply because they are the source of a lot of attacks, that way of thinking is kind of outdated. You should only be allowing traffic that would actually be seen as legitimate. For example if I was a US based grocery store of some type I could setup my security policies to only allow traffic from certain countries without risk of blocking legitmate traffic. I might expect traffic from the US, Mexico, and Canada and block everything else because I don't have a need to allow the traffic anyways. 

Saying that you're going to block traffic from 'RU' or 'CN' is really simple because they do generate a lot of scanning, spam, and stuff like that. But why only block those two countries if you don't have a valid reason of allowing traffic from 'VN' or 'GB'? Geographically limiting access to your network is really easy with PAN; but the bigger question would be "What countries even have a valid reason to accesss my network" in the first place. If you can get away with limiting the source to just the US, or just the US, Mexico, and Canada why wouldn't you? 

Hey BPry, I understand what you are saying really I do. 

This is task, I have been asked to do .   

Lot of people can bypass this really easy, by using a proxy or vpn connection etc..... 

 

Is there a good article or articles you can share show this idea is not a good one. 

 

Anything you can provide would be great. As you have help me in the past.

@AdamCoombs,

The entire concept is what many coin 'Zero Trust Architecture'. Palo themselves has a lot of good information on it HERE and HERE and why 'Zero Trust' is the better way to do things. 

It's not necessary that blocking source countries that are known bad actors is a bad thing, it will certaintly help cut down on the number of logs and such being detected; it's that this is the lowest hanging fruit, it may have already even fallen off the tree. In my mind it's better to get into their mind of only handling legitimate traffic.

L3 Networker

Hi Mate, 

 

Would aggree with all of the above. Can differ from network to network, what locations to block.Running a custom report off a deny rule, currently blocking threats or inbound traffic could help you make your mind up in respect of the risk of traffic to or from certain countries aswell.

 

report1.GIFreport.GIF

 

Best regards,

 

Rob

L1 Bithead

Hello,

There are multitude of articles and what not out there. You might wanna turn on Google Alerts for something like that. I dont know if I am allowed to give links but you can type top 10 countries, or most hacked countries.

  • 1 accepted solution
  • 17751 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!