Research Article

Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case

Volume: 14 Number: 2 December 24, 2024
EN

Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case

Abstract

The $5 billion update error in CrowdStrike’s security software led to global disruptions, affecting airports, hospitals, and banking systems. This issue, caused by a faulty software update, resulted in Microsoft Windows computers experiencing "blue screen" failures, impacting approximately 8.5 million devices globally and requiring manual restarts. The malfunction halted aviation, disrupted healthcare services, and disabled some TV channels. Insurance company Parametrix estimated $5.4 billion in losses for 25% of affected Fortune 500 companies in the US and around $15 billion globally. This paper examines the cybersecurity risks associated with vulnerabilities introduced by system updates, with a focus on critical infrastructures. To assess these risks, vulnerability scans were conducted across 12 critical infrastructure organizations, revealing an average 27% vulnerability rate related to updates. Through this study, we identify the evolving threat landscape and propose mitigation strategies to enhance cybersecurity posture, targeting a performance improvement of over 90%.

Keywords

References

  1. [1] J. Franks, U.S. Government Accountability Office Letter, “CrowdStrike Chaos Highlights Key Cyber Vulnerabilities with Software Updates”, 2024.
  2. [2] Premakanthan, Nihila. (2024). Analysis of the CrowdStrike Software Update Failure.
  3. [3] Techfunnel Magazine Online (2023), https://www.techfunnel.com/information-technology/patch-management-challenges/
  4. [4] Tariq, U.; Ahmed, I.; Bashir, A.K.; Shaukat, K. A Critical Cybersecurity Analysis and Future Research Directions for the Internet of Things: A Comprehensive Review. Sensors 2023, 23, 4117. https://doi.org/10.3390/s23084117
  5. [5] Redscan Magazine Online (2020), https://www.redscan.com/news/state-of-cybersecurity-uk-universities-foi-report/
  6. [6] Global Threat Report (2023), https://goo.by/aTlWwA
  7. [7] Cyber Security and Infrastructure Security Agency (CISA) Cyber Security Report (2023), https://goo.by/NdLTyB
  8. [8] TUĞAL, İ., ALMAZ, C., & SEVİ, M. (2021). Üniversitelerdeki Siber Güvenlik Sorunları ve Farkındalık Eğitimleri. Bilişim Teknolojileri Dergisi, 14(3), 229-238. https://doi.org/10.17671/gazibtd.754458

Details

Primary Language

English

Subjects

Software Engineering (Other)

Journal Section

Research Article

Early Pub Date

January 13, 2025

Publication Date

December 24, 2024

Submission Date

October 9, 2024

Acceptance Date

November 13, 2024

Published in Issue

Year 2024 Volume: 14 Number: 2

APA
İş, H. (2024). Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case. European Journal of Technique (EJT), 14(2), 182-188. https://doi.org/10.36222/ejt.1564440
AMA
1.İş H. Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case. EJT. 2024;14(2):182-188. doi:10.36222/ejt.1564440
Chicago
İş, Hafzullah. 2024. “Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case”. European Journal of Technique (EJT) 14 (2): 182-88. https://doi.org/10.36222/ejt.1564440.
EndNote
İş H (December 1, 2024) Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case. European Journal of Technique (EJT) 14 2 182–188.
IEEE
[1]H. İş, “Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case”, EJT, vol. 14, no. 2, pp. 182–188, Dec. 2024, doi: 10.36222/ejt.1564440.
ISNAD
İş, Hafzullah. “Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case”. European Journal of Technique (EJT) 14/2 (December 1, 2024): 182-188. https://doi.org/10.36222/ejt.1564440.
JAMA
1.İş H. Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case. EJT. 2024;14:182–188.
MLA
İş, Hafzullah. “Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case”. European Journal of Technique (EJT), vol. 14, no. 2, Dec. 2024, pp. 182-8, doi:10.36222/ejt.1564440.
Vancouver
1.Hafzullah İş. Evaluating and Mitigating Cybersecurity Threats from System Update Vulnerabilities through the CrowdStrike Case. EJT. 2024 Dec. 1;14(2):182-8. doi:10.36222/ejt.1564440

Cited By

CrowdStrike Causes Global Microsoft Outage

Journal of Information Security and Cybercrimes Research

https://doi.org/10.26735/QHDD4798

All articles published by EJT are licensed under the Creative Commons Attribution 4.0 International License. This permits anyone to copy, redistribute, remix, transmit and adapt the work provided the original work and source is appropriately cited.Creative Commons Lisansı