Introduction
The retail firm begins getting complaints from customers saying they had been conned through an email that mimicked a confirmation of an order. The link directed the consumer to a website which replicated the company's branding in terms of the logo, colors, and login screen down to the last detail. Upon investigation of the company's internal networks and servers by the security department, no breach was found because none had occurred at all; the attackers just used the company's identity.
This is very common among modern-day attacks on cyberspace. The criminals do not have to gain access to the network in order to cause trouble. This is because they can create a fake domain name, replicate the site design or act in the name of a brand over social media, never coming near any of the company's infrastructures.
This is where Digital Risk Protection Services (DRPS) come into play. DRPS concentrate on detecting such kinds of external threats that happen outside an organization's internal network, but may be used against employees, clients, or other third parties of the organization. The question arises: How can you recognize the attack when it is not required to get inside your system at all?
What is Digital Risk Protection Services (DRPS)?
DRPS represents a type of security service which constantly surveils the Internet through websites, social media platforms, mobile app stores, code storage sites, and parts of the dark web in order to detect threats that directly target the company's reputation or its employees and customers. DRPS, unlike traditional security monitoring, which focuses on events within the company's network, surveils what is going on outside the network in the Internet.
Such an approach is required for the same reason that the digital footprint of any organization goes well beyond its own servers. The identity of an organization, its logo, the domain name, and even the identity of its employees can be stolen and misused without any kind of penetration into the internal network of the company.
Why Traditional Security Misses External Threats
Most of the currently available security systems are designed to secure what the firm owns or controls itself. It is vital, but at the same time it means that these security systems are destined to miss one point.
- Firewalls: Regulates traffic that enters and leaves the corporate network. The attacker has no visibility into the phishing site hosted on another website.
- EDR (Endpoint Detection and Response): Monitors behavior on the devices owned by the company, such as laptops or servers. The solution has no visibility into the phishing app that was uploaded to the app store under the guise of the company.
- SIEM (Security Information and Event Management): Analyzes log files produced internally by systems. A social media profile pretending to be a real one will produce no logs for SIEM to examine.
- Antivirus: Detects any malicious files residing on its device. There is no visibility into the credentials leaked on a dark web forum.
- Identity Protection: Is typically designed to verify the identities of its employees and protect them.
All these technologies are very useful, but all have the common limitation that they track assets owned by the organization. On the other hand, DRPS is designed specifically to track the part of the internet which is not owned by the organization but is used by them to store their identities and data.
| Security Tool | Primary Focus | Sees External Impersonation? |
|---|---|---|
| Firewall | Network traffic control | No |
| EDR | Endpoint activity and behavior | No |
| SIEM | Internal log correlation | Limited, only if external data is fed in |
| Antivirus | Malicious file detection | No |
| DRPS | External brand, domain, and data exposure | Yes |
Common Digital Risks DRPS Detects
DRPS systems tend to examine a range of classes of outside threat. All of them provide a distinct means by which an attacker could abuse an organization's identity and data without even penetrating its network.
Brand Impersonation
The attacker creates phony websites, ads, and profiles using a logo and content similar to the one used by the company. The DRPS looks at all similar content on the web and finds them quickly.
Phishing Websites
These fake log-in pages that attempt to get a user's username, password, or financial information usually look just like the website of a legitimate business. DRPS analyzes the new domains and the page designs for similarities to the actual website of the business.
Typosquatting Domains
These include those domains that use misspelled names of brands by changing just one character, fooling the user while he is typing or clicking on the link. The DRPS monitors domain registration that closely resembles its own domain name.
Credential Leaks
Credentials used in other security breaches unrelated to the company are often re-used by employees, and the credentials may be found on forums and other web pages. DRPS looks up such leaks involving the company's email domain addresses.
Exposed Cloud Storage
If cloud storage buckets have been misconfigured, then it could accidentally result in a exposure of internal files on the internet. DRPS tools search for open storage buckets and services that have been misconfigured that are linked with the infrastructure of the organization.
Fake Mobile Apps
The attackers use the company's name in publishing fake apps on app stores, either official or third party, and these fake applications can infect user devices with malware. The DRPS checks app stores for any apps with brand names or icons without authorization.
Fake Social Media Accounts
Fake account impersonators can conduct fraud, misinformation, and fake customer service. The DRPS monitors the creation of new accounts based on the company name, logo, and executive names through all major networks.
Dark Web Mentions
There are discussions in such forums about the firm or the data even prior to any attack. This is monitored by DRPS in the accessible areas of such forums.
Third-Party Exposure
Partners and vendors having access to information of the company can be seen as weak links if they have insufficient security mechanisms in place. DRPS would monitor any mention of breach or exposure from partners that might affect the organization.
Public GitHub Secrets
Sometimes programmers by mistake commit API keys or passwords to public code repositories. The DRPS tool checks public repositories for any exposed credentials that are related to assets belonging to the organization.
How DRPS Works
Although the specific platform is different, the majority of DRPS platforms use a similar process for converting internet traffic data into usable data for the security teams.
Figure 1. DRPS Workflow — organizations continuously monitor internet-exposed assets, analyze external threat intelligence, prioritize risks, and help security personnel act before an attacker takes advantage of their digital assets.
Asset Discovery
The platform creates an inventory of the organization's digital fingerprint which includes the domains, brand names, executive names, logos, and infrastructure.
Continuous Monitoring
The platform monitors the internet and the dark web for any matches to the above inventory through continuous monitoring of websites, domain registration systems, app stores, social media platforms, code repositories, and even accessible parts of the dark web.
Threat Intelligence Correlation
Findings are then cross-checked against threat intelligence including phishing infrastructure and malicious hosting patterns to determine the probability that the finding is a real threat.
Risk Analysis
Analysts use a scale to determine the severity of the finding by looking at elements such as its similarity to the organization's brand and the malicious activity being shown.
Alert Prioritization
Findings are ranked in order of importance and credibility so that the most pressing ones can be identified quickly.
Security Team Review
Once the alert is validated as a legitimate threat, further action is decided upon.
Response and Takedown
In certain cases, a takedown request is initiated by either the organization itself or the DRPS vendor to the hosting platform, domain registry, or website itself.
Realistic Example
"Company Inc." is a fictional company that works on company.com. However, one week, an attacker acquires the domain company-login-support.com and creates a page that mimics the login page of the original website with the sole purpose of stealing login information.
Here is how a DRPS platform might catch this, step by step:
- New domain detected: DRPS system flags company-login-support.com as a new registration as this looks very much like the organization's own domain name.
- TLS certificate observed: The moment that the cybercriminals set up HTTPS on this phishing page, the certificate gets recorded and becomes publicly available via the certificate transparency logs, and DRPS picks this up.
- Phishing page identified: Automated scanning detects the new domain, discovers a login page, and finds out that its design is identical to the real company's login page.
- Credential collection behavior flagged: The analysis identifies that the page is designed to submit entered credentials to an external server, a strong indicator of a phishing attempt rather than a legitimate site.
- Alert raised and reviewed: The finding is prioritized as high risk and sent to the security team, who confirm it is malicious.
- Takedown initiated: A takedown request is submitted to the hosting provider and domain registrar to get the fraudulent site removed.
In this scenario, the company's own network was never touched. The threat existed entirely outside its infrastructure, which is exactly the kind of risk DRPS is designed to surface early.
Benefits of DRPS
- Early Detection: Detects malicious domains, counterfeit apps, or data leaks well ahead of any use in attacks.
- Brand Protection: Assists in maintaining customer trust through detection of imposters that could harm the reputation of the business.
- Reduced Phishing Risk: Faster detection of phishing infrastructure means less time where employees and customers can fall victim.
- Faster Incident Response: Provides information necessary for quick response to threats from outside.
- Continuous Visibility: Provides continuous visibility into the exposure of the business in the public internet space.
- Executive Awareness: Helps management know what risk trends affect the brand externally.
Limitations
DRPS is a useful addition to a security program, but it is not a complete solution on its own.
- False Positives: Automatic detection may result in false alarms when the material being detected is simply similar to the brand, and this will require human confirmation.
- Cannot Prevent Attacks Alone: DRPS detects and alerts to external threats but does not necessarily prevent the attacker from performing their actions.
- Requires Analyst Validation: Most findings have to be verified by a person, and thus, DRPS still relies on professional staff members.
- Depends on Quality Intelligence Sources: The usefulness of DRPS greatly depends on the extent and timeliness of data sources utilized; lack of comprehensive data results in missing threats.
- Cannot Replace SIEM or EDR: DRPS deals with external risk and not network or endpoint security and therefore complements these solutions and does not replace them.
DRPS vs Other Security Technologies
| Technology | Purpose | Monitors | Examples |
|---|---|---|---|
| Firewall | Controls network traffic | Internal network perimeter | Next-generation firewalls |
| EDR | Detects and responds to endpoint threats | Company-owned devices | Endpoint agents on laptops and servers |
| SIEM | Aggregates and analyzes security logs | Internal systems and applications | Centralized log correlation platforms |
| Threat Intelligence | Provides context on known threats and actors | Broader threat landscape data feeds | Indicator and actor tracking feeds |
| ASM | Identifies exposed internet-facing assets the organization owns | Known and unknown owned infrastructure | Exposed server and service discovery |
| EASM | Focuses specifically on internet-facing attack surface visibility | Externally reachable owned assets | Internet-wide asset scanning |
| DRPS | Detects impersonation and misuse of brand and data outside the network | External web, social media, app stores, dark web | Brand and phishing monitoring platforms |
Future of DRPS
Digital risk protection continues to evolve alongside changing attacker techniques and new technology trends.
- AI-Assisted Monitoring: Machine learning will assist in analyzing the huge amounts of internet data DRPS scans, leading to faster and better accuracy in detecting them.
- Brand Monitoring: With the advancement of impersonation tactics, it is expected that brand monitoring will grow further, spreading to more and different types of platforms.
- Deepfake Detection: As synthetic media improves, it is becoming important for DRPS providers to look at how they can detect fake videos and audio impersonating executives or brands.
- Supply-Chain Risks: It has become imperative to pay more attention to third-party and vendor exposures since most attacks occur through the weakest link in a supply chain.
- LLM-Powered Phishing: With the development of generative language models making it difficult to detect any form of fraud with writing skills alone, it is becoming necessary to focus on technical aspects like domain names and infrastructure when detecting such cases.
- Digital Identity Protection: Protection of executives and employees from identity impersonation is an emerging trend within digital risk programs.