• No results found

Next-Generation Antivirus: Evolving Your Security to Defend Against Modern Attacks. Bernie Png Senior Regional Security Engineer March 14, 2017

N/A
N/A
Protected

Academic year: 2021

Share "Next-Generation Antivirus: Evolving Your Security to Defend Against Modern Attacks. Bernie Png Senior Regional Security Engineer March 14, 2017"

Copied!
33
0
0

Loading.... (view fulltext now)

Full text

(1)

Next-Generation Antivirus:

Evolving Your Security to Defend

Against Modern Attacks

Bernie Png

Senior Regional Security Engineer

March 14, 2017

(2)

© 2016 Carbon Black. All Rights Reserved.

What We’ll Cover Today

Is traditional antivirus working?

What is Next Generation Antivirus (NGAV)?

(3)

Is Traditional Antivirus

Working?

(4)

Ransomware’s Annual Take

2015:

2016:

$325M

$

1 Billion

(5)

Daily Ransomware Attacks

This is a 300% increase over 2015.

500

per day

5,000

per day

On average, 4,000 attacks

happen each day.

4,000

How many?

(6)

KNOWN

MALWARE

OBFUSCATED

MALWARE

SCRIPTING

ATTACKS

POWERSHELL

RANSOMWARE

MEMORY

ATTACKS

REMOTE

LOGIN

MACROS

UNKNOWN

MALWARE

was used to

launch 38% of

cyber attacks in

2015

POWERSHELL

Guess The Attack

SOURCE: CARBON

BLACK

(7)

Nearly one-half of orgs have

experienced Ransomware

in the last 12 months

(8)

AV-Test.org Results, June 2016

Antivirus

Vendor

May

2016

June

2016

AVG

F-Secure

Kaspersky

Symantec

Bitdefender

G Data

Trend Micro

100%

99.4%

100%

100%

100%

100%

100%

100%

100%

100%

100%

100%

100%

100%

(9)

Cognitive Dissonance

the state of having inconsistent thoughts, beliefs, or

attitudes, especially as relating to behavioral

decisions and attitude change.

(10)

Traditional Antivirus

No Longer Works

(11)

EMAIL SCANNER

TRADITIONAL ANTIVIRUS

Traditional AV takes a

malware-centric view

of endpoint security; identifying

malicious software by matching it to pre-identified signatures and heuristics.

Malware

identification

Signatures &

heuristics

Decide once,

forget forever

PERSONAL FW

URL SCANNER

(12)

Antivirus

Targets

Malware

(13)

1. The Adversary Automates

<attack />

Attacker writes

malicious code

1 million

malware

files

Zero-day

arsenal

100

million

malware

files

Raw malware

repository

Screen out

detected files

Multiple AV

engines @

99%

effectiveness

Anti-signaturing

Anti-reverse eng

Anti-debugging

Anti-sandboxing

Specialized

malware

(14)
(15)

3. The Adversary Adapts

(16)

Next-Gen AV:

A Whole New Approach To

Stopping The Attacker

(17)

EMAIL SCANNER

PERSONAL FW

URL SCANNER

TRADITIONAL ANTIVIRUS

Traditional AV takes a

malware-centric view

of endpoint security; identifying

malicious software by matching it to pre-identified signatures and heuristics.

Malware

identification

Signatures &

heuristics

Decide once,

forget forever

(18)

NEXT-GENERATION ANTIVIRUS

NGAV takes a

system-centric view of endpoint security

, examining every

process on every endpoint to algorithmically detect and block the malicious

tools, tactics, techniques, and procedures

upon which attackers rely.

Long-term analysis to

detect attacker patterns

Data science &

threat intelligence

Deep attack

context & insight

(19)

What Is A TTP?

Tactics, Techniques, and Procedures: specific, identifiable patterns of malicious

activity, discovered through analysis and correlation of files and behavior

RAW DATA

MD5

SHA256

NETWORK

SYSTEM CALLS

FILE ACCESS

CONFIG/REGISTRY

ACTIVE

PROCESSES AND

EXECUTABLES

LOW LEVEL

BACKGROUND

SCAN

TTPs

MOD NET SETTINGS

PERSIST

RUN SYS APPS

LIST PROCESSES

SCRAPE MEMORY

INJECTS CODE

ETC.

READ USER DATA

DROPS CODE

DOWNLOADED FILE

FAKE LOCATION

LISTENS ON SVC PORT

BEACONING

C2 CHANNELS

(20)

Billions of Signatures

!

200 Techniques

FILE SYSTEM

FAKE APPLICATION/ LOCATION

NETWORK

SECURITY

SYSTEM

USER INPUT

FIND A FILE UPLOAD FILE DOWNLOAD FILE FROM

EMAILED URL CODE DROP READ USER DATA,

(CAL, EMAIL, etc.) CREATE/MODIFY EXECUTABLE FILES

ESTABLISH NETWORK CONNECTIONS

LISTENING ON NETWORK SVC PORT COMMUNICATE WITH

LOW REP SITE BEACONING C2 CHANNELS MODIFY NETWORK

SETTINGS

PERSIST / INSTALL CREATE ANOTHER

PROCESS RUN SYSTEM APPS

AND TOOLS LIST PROCESSES MEMORY SCRAPING

CODE INJECTION

PLUGIN INJECTION KILL ANOTHER PROCESS

HIDE PROCESSES REVERSE COMMAND SHELL REVERSE C2 BUFFER OVERFLOW PACKED CODE PRIVILEGE ESCALATION INJECT INPUT MODIFY REGISTRY MODIFY CONFIGURATION HARVEST PASSWORDS DISABLE SECURITY SOFTWARE CAPTURE KEYSTROKES ENABLE MIC/WEBCAM READ FROM CLIPBOARD TAKE SCREENSHOTS

PROCESS

(21)

How TTPs Stop Malware

TIME

Known%malware%variant%

TERMINATE

REPUTATION

BEHAVIOR

ATTACK

VECTOR

NGAV TTP Analysis

(22)

How TTPs Stop Complex Attacks

TIME

Unknown%App%

Read%Security%Data%

Has%Injected%Code%

Run%System%Utility%%

Packed%Call%

TERMINATE

REPUTATION

BEHAVIOR

ATTACK

VECTOR

NGAV TTP Analysis

(23)

NEXT-GEN AV:

System-Centric vs Malware-Centric

File attributes

File contents

File heuristics

Access patterns

Registry

Configuration

Network Activity

System Calls

File attributes

File contents

File heuristics

NEXT-GEN AV

TRADITIONAL AV

Holistic monitoring of every process over

time, whether malicious or not

Point-in-time identification of malware

based on simple rules

(24)

NEXT-GEN AV:

Data Science and

Behavioral Pattern-Matching

Behavioral

Analytics

Machine

Learning

Patterns of

Attack

Reputation

Scoring

Relationship

Tracking

LIGHTWEIGHT

PREVENTION ON THE

ENDPOINT

DEEP DETECTION &

ANALYTICS IN THE CLOUD

ADAPTIVE

LEARNING

EXTENSIBLE

High efficacy

(25)

1.

How did this start?

2.

What happened prior to detection?

3.

Where else does this apply to?

4.

What could the impact have been?

5.

Should I do anything to recover?

6.

Are there holes I should close?

NEXT-GEN AV:

Deep Attack Context & Insight

INTEGRATION

RESPONSE &

REMEDIATION

IMPROVED

SECURITY

POSTURE

PREVENTION

BLOCK

ALERT

(26)

NEXT-GEN AV:

Malware, Malware-less, and

Malicious Use of Good Software

Obfuscated

Malware

Malware is obfuscated or

packed multiple times

Malware unpacks

itself when run

Malicious code is

free to execute

Doesn’t match any

traditional signatures

NGAV spots the

malware and blocks it

(27)

NEXT-GEN AV:

Malware, Malware-less, and

Malicious Use of Good Software

Backdoor

Binary

Attack

Attacker hides shell code

in EXE’s empty space

Program opens secret

back door

EXE

Malicious activity thru

remote access!

Signatures, machine

learning will miss this

NGAV finds these

behaviors and blocks

(28)

User launches

malicious macro

Powershell downloads

Ransomware

Encrypted!

NEXT-GEN AV:

Malware, Malware-less, and

Malicious Use of Good Software

PowerWare

Attack

AV misses – no

malicious software

NGAV blocks before

files are encrypted

(29)

NEXT-GEN AV

TRADITIONAL AV

Ineffective protection that

is

easily bypassed

by the

modern attacker

Targets all the attacker’s

tools, techniques, tactics,

and procedures

(30)

Ready To Jump In?

NGAV EVALUATION CRITERIA

1.

Protection from malware &

malware-less attacks

2.

Extensible cloud analytics

3.

Visibility & context

4.

Integrated response

5.

Lightweight operations

6.

Group-based policies and

security growth path

Seek 3

rd

-party

guidance on

(31)

© 2016 Carbon Black. All Rights Reserved.

ABOUT CARBON BLACK

31

MARKET-LEADING

APPLICATION

CONTROL

MARKET-LEADING

INCIDENT RESPONSE

NEXT-GENERATION

ANTIVIRUS

25

of Fortune 100

2,000

Organizations

7M

+

Licenses

10,000

Practitioners

70

+

IR/MSSPs

#

1

(32)

© 2016 Carbon Black. All Rights Reserved.

Cb ENDPOINT SECURITY PLATFORM

32

IR & THREAT

HUNTING

Cb RESPONSE

NEXT GEN AV

Cb DEFENSE

APPLICATION

CONTROL

Cb PROTECTION

CARBON BLACK

(33)

References

Related documents

Reach for personal use in nana claus is against the item as an active sale at the digital download of art vinyl decal cutting machines such as vinyl decals!. Try and the whole in

Since the time equity markets have been engulfed by volatility, the most frequently heard advice is that best way to invest in equities is “invest via the systematic investment

The DDA makes clear that requests for reasonable adjustments to auxiliary aids and services, and changing terms of leases are not payable by the disabled person or the lessee

The effects of dietary lipid and strain on the PUFA composition and conversion of C18 to ARA, EPA and DHA have been investigated previously (Hoffman et al.. fish in

Kaspersky Security for Virtualization is delivered as a virtual security appliance that integrates with VMware vShield™ Endpoint to provide agentless, anti-malware

Trend Micro Deep Security Antivirus Deep Security for vShield Endpoint integrates with the VMware APIs to provide agentless anti-malware protection for VMware virtual machines with

In March 2012, AV-Test performed a comparative review of 3 home user security products to determine their capabilities to protect against malware that is related to Online

Suzuki Suzuki is is giving giving a a good good service service and and product product that‘s that‘s why why it it has has largest market share and market