Malware Remodeled

McAfee-Black-Hat-Survey-Images-v3b.png

McAfee Labs detects 387 new samples of malware every minute, according to their Labs Threats Report, 2015.  Malware is getting through enterprise defenses as attackers code new strains and re-clothe old ones in order to thwart information security tools. The malware they aim at mobile devices is maturing, usurping authority over employee hardware and leveraging that control to leap inside the perimeter.
The trend is for malware to leave minimal traces. “Attackers are trying to maintain a low profile to eliminate their chances of detection,” says Paul Morville, Founder and vice president of Products Confer, a start-up that lays claim to end-point detection and response market. 
Meanwhile, the increasing numbers of variants up the odds that one will infiltrate the enterprise network and grow deep into its heart as an APT. “Malware authors keep the target moving by creating large numbers of variants, and this can increase their chances of reaching target victims. Such morphing threats can increase the complexity in isolating the malicious code across all end points,” says Craig Schmager, Security Threat Researcher, McAfee Labs.
Malware also focuses on the employee’s BYOD laptop or smartphone when it connects to unsecured networks outside the enterprise. “These attacks are more sophisticated and attackers are using the employee as the leverage point to gain entry inside the organization,” says Morville.
Attackers infect employee devices to steal usernames and passwords that access financial accounts within the company. They also use employee laptops to get inside the perimeter and drill their way through systems and into servers housing valuable data such as intellectual property.
Even security tools are suffering. Attackers are thwarting signature-based security mechanisms with custom-compiled malware that they repackage from existing malware to create unique drive-by downloads that signature-based tools won’t recognize, according to Rich Tener, director of Security, Evernote. The malware inside is basically the same, but the signature is unique and previously unrecorded.
The cloud has given signature-based tools a boost. By storing the growing numbers of new virus and malware signatures in the cloud, the enterprise can take some of the load off of endpoints and endpoint-based anti-virus and anti-malware tools, enabling these tools and signatures to hold up under the pressure of multiplying malware examples.
With the glut of new malware appearing daily in the wild, enterprises must use behavioral analysis tools. These can include an EDR. EDRs help to mitigate employees as an attack vector when they connect their laptops to networks outside the enterprise. The best EDR tools strive to offer more thorough analysis for threat detection and more thorough response in order to remediate infections and to uncover and address seeds of infections.
Enterprises should continue to protect the network as well as the endpoints. “We use an open-source security monitoring stack that includes Bro, a network analysis framework, Suricata, a network IDS with full packet capture, and Arugs, a NetFlow engine. We also complement that with Palo Alto Wildfire, a commercial, network-based malware detection engine with an on-board anti-virus engine,” says Tener. Similar products come from Cisco and Symantec.
Organizations should also use VPNs, firewalls, and load balancers in concert to protect enterprise infrastructure. “We use these to control what services we expose to the Internet, to segment our production network from the rest of our computing infrastructure,” says Tener. By controlling access to the production environment with strong authentication tools, the enterprise can maintain a healthy separation between prized data and external threats.
Rather than using WAFs and other web application security tools, fix the vulnerabilities in the applications in order to maintain a tight grip on security. “Our experience has been that web application firewalls and runtime analysis tools introduce a lot of operational overhead, both in computing resources and engineering time to constantly tune them,” says Tener.
Enterprises should be able to maintain an acceptable level of mitigation of the multiplying numbers of malware examples after considering these and other security measures and applying the most appropriate combination for their needs.
CSO:  http://bit.ly/1d8X9iM

« Will Open Source Save the Internet of Things?
Obama Authorizes Sanctions Against Hackers »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cato Networks

Cato Networks

Cato connects your branch locations, physical and cloud datacenters, and mobile users into a secure and optimized global network in the cloud.

Cyber Command

Cyber Command

Our Managed IT service allows clients to offload the management of day-to-day computer, server, and networking support to our team of professionals.

Red Canary

Red Canary

Red Canary continuously monitors and analyzes your endpoints, users, and network activity in search of threatening behaviors, patterns, and signatures.

Advanced Systems International SAC

Advanced Systems International SAC

Advanced Systems international is a global company dedicated to data security software design, development, support, and licensing.

HYPR

HYPR

HYPR Decentralized Authentication minimizes the risk of enterprise data breaches while providing an enhanced user experience for your customers and employees.

Mitre ATT&CK

Mitre ATT&CK

MITRE ATT&CK™ is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.

Red Points

Red Points

Red Points protects your brand and content in the digital environment.

Tesserent

Tesserent

Tesserent (formerly Pure Security) is a full-service cybersecurity solutions provider. We partner with clients across Australia and New Zealand in the protection of their digital assets.

CyberEdBoard

CyberEdBoard

CyberEdBoard is a private, peer-to-peer education and networking community focused on cybersecurity, technology, business processes and risk management.

Cyturus Technologies

Cyturus Technologies

Cyturus Technologies delivers cybersecurity business risk quantification services using our proprietary Adaptive Risk Model (ARM).

SightGain

SightGain

SightGain is the only integrated risk management solution focused on cybersecurity readiness using real-world attack simulations in your live environment.

Cyber Defence Solutions (CDS)

Cyber Defence Solutions (CDS)

Cyber Defence Solutions is a cyber and privacy Consultancy with extensive experience in the development and implementation of cyber and data security solutions to your assets.

Firmus

Firmus

As the leading penetration testing services provider in Malaysia, Firmus evaluates the ability of your internal or external information assets to withstand attacks.

Akto

Akto

Akto, the plug & play API security platform. Discover your APIs, run tests and find business logic vulnerabilities at ludicrous speed.

Star Lab

Star Lab

Star Lab specializes in the development and productization of embedded security technologies.