The technology and techniques used by those producing malware is improving at a frightening pace according to experts in the field. As businesses begin to accept the reality that targeted attacks could become the norm, security experts are emphasising that it’s become harder to protect businesses against the tide of increased threats.
"Human error is a factor," said David Keating, security sales manager with DataSolutions, "but companies are being targeted directly with attacks that are aimed at tricking them, so it’s becoming easier for that human error to occur."
Giving an example, Keating said, "If you’re in a HR department and someone sends you in a CV, well really you have to open it. That’s what some hackers will do. They find out who works in HR, they see a job that’s being offered with the company and send in a CV that’s actually a file full of harmful software. That’s just one method from plenty they have."
Dermot Williams, managing director with Threatscape told ComputerScope that the volume of malware floating around the world at the minute is phenomenal – citing Symantec’s analysis of 286 million discreet malware samples in 2010. He agreed that the major danger for companies at present is that "everything is far more targeted now", with hackers sitting down and planning who they’ll try to disrupt.
Integrity Solutions’ Paul Ryan, principle security consultant, noted that the targeted malware is using root-kits to install itself deep within machines "ensuring it loads before the underlying OS starts, making it very hard to detect with traditional desktop anti-virus applications".
Ryan continued, "Examples of this are Stuxnet or TDSS botnet. Malware evasion techniques such as code metamorphism and noise insertion are common tactics that attempt to bypass pattern recognition systems employed by such anti-virus, intrusion prevention system (IPS) technologies."
UPPER HAND
Ryan also makes the point that malware is also using "adopted serial variant construction" as a means of evading detection. In short, as long as those at the root of the problem can release newer versions of malware faster than companies can release detection updates, they’ll continue to have the upper hand. "In my opinion, any detection technology that requires samples before signatures can be applied will always be behind."
Ryan commented that in response to all these new threats security vendors have enhanced their capabilities to obtain new malware examples by using "honeypots or spam traps" as well as other tactics of this ilk. Such methods will, he said, enhance the pace at which they develop new signatures or algorithms to conquer the "zero-day gap" of being able to combat vulnerabilities. Traditional vendors, Ryan claimed, are also moving towards cloud-based systems to minimise content distribution delays making it easier to collect malware samples. He stated that some vendors are now, "employing appliances out of band at the network layer on the core where it can monitor stealth techniques being used by modern malware in advanced persistent threats or data exfiltration attempts".
"These technologies are capable of analysing traffic at the application layer over a multitude of protocols in not only detecting malware but also the mechanisms used by malware to propagate-watch this space," he added.
USING ‘JUDO’
Threatscape’s Williams used the analogy that the latest forms of anti-malware technology have taken a lesson from judo; as they use the strength of the malware creators against them. "As in judo, their strength becomes your strength, so leverage that against them" he said, "in the case of the people writing malware, well previously it’s been in their favour that there is an enormous amount of potential victims out there, so they can choose who to go after from so many different targets. That fact can be turned to the advantage of the people trying to catch them out though."
Talking about Symantec’s latest version of Endpoint Protection he notes that with the software working on potentially 175 million machines worldwide, "we can, along with the users, turn this into an intelligence-gathering network against those producing malware." An "enormous cloud-based solution" is essentially what is being described, as huge numbers of executable files are analysed – with information found on how old they are, where they’re coming from how widespread they are in use, as well as whether they’re doing anything malicious.
"All this information is feeding back into this enormous database, and when a particular executable files turns up on your computer they’re able to tell immediately something about that file-its age, its intelligence, its maliciousness. If we’ve never seen something before, that’s actually the first thing we do know about it. That it’s a new type of file out of 175 million computers and that’s a powerful piece of knowledge."
CLOUD INFLUENCE
The growing influence of the cloud in this sector was also confirmed by Keating, who said, "With spam and the web-filtering, a lot of that seems to be moving towards the cloud. There’s a good argument for e-mail, that if you scan it and take all of the spam out of it before it comes down to your network you’re saving a lot of bandwidth traffic. Essentially you can root out all your spam up in the cloud.
For some people, he commented, spam could be "80 or 90%" of e-mail traffic. "The traditional method was to bring it down on a gateway box on your network and then to discard 90% of what you bring down. It’s an inefficient way of doing it, and particularly in a big organisation a lot of money can be burned doing that. Why continue to do that?"
Asked about the year just gone for the AV/malware/spam-fighting industry Commtech’s managing director Justin Owens would say that over the course of the last year there’s been some major progress in security of virtual servers. "VMware in particular," he commented, "have launched a lot of extensions to their VMsafe product. One major advantage is that it can be rolled out quickly and in the past it was quite a large, time-consuming process."
CHIP LEVEL
When drawn on the future of this particular corner of IT, Owens was quick to point out that Intel’s acquisition of McAfee is beginning to beginning to bear fruit. "Having paid $8 billion for the company, the first products are coming out of that now where the security is being linked more at the chip level rather than at the pure software level." He’s referencing McAfee DeepSAFE designed under the new Intel ownership to mitigate risks at the sub-operating system level.
The point of the product is to use hardware features already in the Intel processors to provide security beyond the operating system. This vantage point can help it to apply new techniques to deliver what its makers believe is a "new generation of protection in real time to prevent malicious activity and not just detect infections".
For several of the experts questioned by ComputerScope, DeepSAFE and how effective it actually is will have a lot of bearing on where the anti-virus, anti-spam and anti-malware industry moves to over the coming year. Indeed, Intel/McAfee look set to continue launching similar products over that time period. Seen generally as a positive move, Owens among others was quick to point out that it should be interesting to see if the main players in the industry will follow suit or adopt a "wait and see" attitude before making their next move.
REAL TIME ANALYSIS
Integrity’s Ryan commented meanwhile that already the technology to combat advanced malware and dangerous bots has developed rapidly over the past year. "Vendors are offering appliances that detect advanced malware and command-and-control infrastructure used by criminals to extract data from infected assets. Technologies such as Damballa have the ability to correlate suspicious activity and events seen at listening points across the network and have the ability to run malware analysis in real-time across the network to block potential threats," he added.
In Ryan’s opinion vendors that have the ability to detect and block malware pattern activity "such as command and control infrastructure" in real-time and vendors who can "provide malware analysis in real time and block suspicious activity" will offer better capability over the next year for potential customers.
He continued, "The fastest growing malware categories are fake anti-virus programs, downloader Trojans and information stealing executables. Defending against malware up until now has been reactive, however smart defence strategies still apply by making sure networks are less vulnerable to attack, by eliminating underlying vulnerabilities."
AVAILABLE TECHNOLOGIES
DataSolution’s Keating weighed in on the subject of the industry’s future by saying the technology available at present "is actually an awful lot better than a lot of companies out there think it is". The security sales manager added to his argument by saying that, "I think over the next 18 months if a lot of companies out there utilised the technology that’s available now, they’d be okay. Now obviously there are probably some areas around the command and control of viruses that will come on stream in that time, but what’s out there is impressive."
Keating noted that companies must also take note of the fact that no matter how much they’re spending on a solution, or how complex it is, it won’t be effective in protecting the companies interested unless the people within the organisation have an "awareness of the risks they face". An appropriate, and regularly audited, policy on all matters malware is recommended.
BEHAVIOUR BLOCKING
For Williams, one interesting area to watch out for is behaviour blocking. The Threatscape man explained that this technology, which allows companies to monitor file activities, preventing certain modifications to files or even the operating system, will become increasingly important.
"This," he said, "is because if you get to the point within a protection product of saying ‘y’know what, we’re reasonably sure this file is good and we’ll allow it to run,’ and these decisions are taken within milliseconds by a computer, it’s possible to then watch its behaviour and have a closer look into what it’s doing.
"I mean if a program is suddenly making registry changes for example, we’d ask why that’s happening, or why is it spawning new processes or even spontaneously connecting to a remote server. By watching, monitoring, managing and even locking it down we can say we’re not happy about that programme, we’re going to block it and report it back to a cloud server. So, if anyone runs it in the future it’ll be stopped before it starts."
MOBILE ISSUE
While for Owens, another major area of interest over the next year will be how those fighting spam, malware and viruses deal with the recent explosion of smartphones as well as tablet products. These devices, the Commtech-man commented, are posing a threat to the traditional network that need to be addressed in a uniform way. He said that he’s seeing significant interest in managing the increasing variety of end point devices out there.
"Everyone knows all the negative publicity surrounding lost laptops and confidential information, but there’s so much more information in the palm of you hand now than there was even two ago. It’s so much more crucial for companies to put in policies and systems to actively deal with this. That’s going to be huge in the next few years.
He continues, "It’s concerning a lot of businesses, the bigger they are the more concerned they are too," he said. "What you need to do is keep things on a simple platform. You need to be able to manage all those devices as simply as possible. The only way to do that is using a product that allows you to generate a policy and apply that to multiple devices."







Subscribers 0
Fans 0
Followers 0
Followers