This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Navigating the Cyber Frontier: 2024’s Emerging Internet Threats

Download resources

About this session

Parul Sharma, an enterprise solutions engineer at Cloudflare, presents the vendor's own data on the past year of internet application threats and pairs each with a business recommendation. DDoS keeps growing in scale (a 201 million request-per-second peak) and shifting toward layer three and four traffic that organizations often leave unprotected while focusing on layer seven. CVE exploitation now starts within minutes of disclosure, making signature-based WAFs too slow without a machine-learning layer. Client-side, third-party scripts such as payment widgets or maps create supply-chain risk, illustrated by the polyfill.io incident, and are now a PCI DSS 4.0 requirement. A third of API endpoints remain unknown to the organizations running them, most detected bot traffic is malicious, and phishing keeps succeeding despite training, pushing Sharma to recommend blocking over education. She closes on zero trust replacing VPNs as networks become hybrid, and on the need for AI-specific firewalls as organizations feed sensitive data into internal and public language models. An extended Q&A covers DDoS attacker infrastructure, zero trust versus VPN architecture, and layer three and four protection gaps.

In 2024, cybersecurity trends reflect a rapidly evolving threat landscape driven by technological advancements and new challenges. Artificial Intelligence (AI) is at the forefront, enhancing threat detection and response through sophisticated algorithms that analyze vast amounts of data to identify anomalies and potential breaches in real time. Zero Trust Architecture (ZTA) has become a cornerstone of modern security strategies, enforcing the principle of “never trust, always verify“ to protect against both internal and external threats by continuously validating user and device identities. Phishing remains a prevalent threat, with attackers employing increasingly sophisticated tactics; organizations are countering this with advanced email filtering and employee training programs to recognize and respond to phishing attempts. Meanwhile, as cloud adoption surges, securing cloud environments is critical, with a focus on robust access controls, encryption, and vigilant monitoring to safeguard against vulnerabilities and data breaches. Together, these trends represent a comprehensive approach to addressing the multifaceted nature of contemporary cyber threats.

During this session, you will gain knowledge about-

1. Generative AI's Dual Role: Balancing Risks and Opportunities

2. Zero Trust Implementation: The Timeless Yet Evolving Security Essential

3. Cloud Security: An Essential Defense Layer

4. Cybersecurity Complexity: Advancing Cyber Capability Development

Key takeaways

  • Deploy dedicated layer three and four DDoS protection, not just layer seven; that gap is where recent large-scale attacks concentrated.
  • Add a machine-learning layer to your WAF; signature-based patching alone is too slow against CVEs that get exploited within minutes of disclosure.
  • Inventory and monitor third-party, client-side scripts (payment widgets, maps, ad pixels); they are a growing supply-chain risk and a PCI DSS 4.0 requirement as of March 2025.
  • Discover shadow APIs before trying to protect them; roughly a third of an organization's API endpoints are typically unknown to the team running them.
  • Stop relying on phishing-awareness training alone; block phishing emails before they reach mailboxes, since employees still click malicious links regardless of training.

Speakers

Parul Sharma
Parul Sharma
Enterprise Solutions Engineer · Cloudflare
Parul Sharma is the Enterprise Solutions Engineer at Cloudflare, the Internet security and performance company running one of the world’s largest networks. In this role, she advises key customers on strategies to secure and optimize distributed… Read moreRead less

Parul Sharma is the Enterprise Solutions Engineer at Cloudflare, the Internet security and performance company running one of the world’s largest networks. In this role, she advises key customers on strategies to secure and optimize distributed workforces and computing architectures. Cloudflare’s mission is to help build a better Internet and today its infrastructure spans more than 310 cities in over 120+ countries including locations in Mainland China. Since joining Cloudflare, Parul has been assisting customers in harnessing the power of cutting-edge technologies at Cloudflare to meet their business goals. She is working with businesses around the world to develop robust, agile, and secure computing architectures. Parul has worked with multinationals, national governments, and many enterprises from a range of industries to help them plan, build, and execute strategies to secure their infrastructures, accelerate their digital transformation, and propel their businesses forward.

Resources

Tags

More from GoSec 2024

Also from Parul Sharma

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.