Top five strategies for combating modern computer security threats

Top five strategies for combating modern threats:organizations can enable safe access to the network,
Is anti-virus dead?rather than simply blocking guests or maintain hugely
Changing environment and threatinefficient pools of computers for contractors and
The corporate IT environment has changedpartners to use.
irrevocably over the last few years.Safe, effective web browsing
Threats are no longer high-profile viruses that spreadThe need to control unauthorized endpoint access to
themselves obviously to millions of internet users forthe network is matched by the need to enable safe
maximum publicity. Now they are highly targeted,web browsing while preventing access to infected or
silently infecting computers to steal data and makeinappropriate sites. Although the web has now
money for criminals. They are increasingly surreptitiousbecome the key vector for online hacking attacks, as
and low profile, mutating in hours or even minutes towell as representing a drain on productivity for many
evade detection.businesses, the vast majority of businesses are
At the same time, today’s working environment isunprotected against today’s modern web-based
rapidly changing. The network perimeter has dissolvedmalware.
to such an extent that it is virtually unidentifiable.Solutions that offer reputation filtering, that is, that block
Yesterday’s “castle and moat” architecturewebsites known to be “bad”, provide some
– with its office-based desktops and serversprotection, but this is inadequate against “good”
protected by a gateway firewall – has crumbled.sites that have been hacked. Today’s threats
Remote working, the use of endpoint devices such asrequire that the content itself is also checked – and
USB sticks, constant internet access and the rapidall this without adversely impacting speed and
emergence of Web 2.0 technologies have redefinedefficiency.
how employees interact with an organization’sSTRATEGY 4
systems. In addition, increasingly complex networksControl legitimate applications and behavior
must accommodate not just employees, but alsoApplication control
outside contractors, vendors and customers.Employees installing and using legitimate but
The need for all points protectionunauthorized applications – such as Instant
Cybercriminals exploit any vulnerability they can find toMessaging, VoIP, games, peer-to-peer file-sharing
infect corporate networks. Their latest tricks usesoftware, virtualization software, and unapproved
countless loopholes in web security to get malwarebrowsers – are a real and growing threat. Not only
onto a user’s computer in seconds. One newcan they introduce malware to the corporate network
infected webpage is discovered every five seconds,but they also seriously impact network and employee
and over 90 percent of these pages are on legitimateproductivity and cause unnecessary support issues,
websites that have been compromised.and further security (and legal) risk if sensitive
Users are duped into visiting these compromisedcompany or personal data is sent outside the
websites, typically via links in spammed emails. Therecompany.
can be layers of complexity with the original websiteRestricting the use of these non-business-critical
going to another site and that in turn going to a third,software applications narrows the threat vectors and
and so on, ending with a Trojan being downloadedis an increasingly important facet of an overall security
onto the user’s computer – all of this happeningpolicy. For maximum efficiency and return on
in a matter of seconds.investment it needs to be incorporated into the
The task of securing the network against this andmanagement and control features of an
other exploits – at the web, email and endpoint –organization’s anti-malware solution.
is a daunting challenge for today’s IT departmentsApplication whitelisting
who are being asked to do more and more with theirApplication whitelisting has been suggested as the
constrained budgets.modern solution to the challenge of protecting
Reducing the attack surfacecomputers from unauthorized and malicious software.
Within this new threat environment, and as attitudes toIn this approach, known “good” applications form
work and information continue to evolve away froma whitelist and only this authorized software is allowed
those of the past, organizations have become moreto run, in contrast to the traditional approach where
aware of the acute need to control all points on the“bad” applications (malware) are prevented
network to protect its data and systems fromfrom running.
criminals. However, the speed with which new threatsThe theory is that with application whitelisting,
emerge and infect means that defenses are oftenorganizations do not need to rely on anti-virus
inadequate and usually out of date.companies to keep up with all the new malware
Protection versus detectionreleased every day. While the approach has some
While much can be achieved by user education andmerit, in reality it is just one of many technologies –
enforcement of acceptable use policies – forsuch as anti-virus, HIPS and application control that
example, banning unencrypted laptops and USBs fromneed to be used to ensure comprehensive endpoint
being taken out of the office, or stipulating what cansecurity.
and cannot be sent by email1 – there is need toSTRATEGY 5
take a different approach to technology in order toControl and encrypt devices and data
reduce the attack surface and protect the network,The protection of sensitive corporate data, especially in
systems and data from malware.mobile computing, is more important than ever. The
In addition to the ability to detect, there are severalnews is filled seemingly daily with reports of company
criteria that need to be taken into account to ensurelaptops, CDs and USB keys packed with confidential
ongoing manageable protection. The key strategiesinformation falling into the wrong hands. By using
are highlighted below.device control you can prevent data being copied and
STRATEGY 1stored on devices like these. However, the problem is
Maintain traditional anti-virus protectionthat modern business practice often requires the use
Totally reliable malware detection remains at the coreof such devices. An effective solution to this obvious
of any security solution, and updates created bysecurity weak spot is encryption to ensure that, though
security vendors from samples of particular viruses stillthe medium might be lost, the data itself is protected
form the basis of efficient detection.and that no unauthorized person can access it or the
Issues of manageability and automation are importantrest of their IT infrastructure.
– anti-virus will only protect the network if it isBy encrypting the entire contents of a hard drive,
correctly configured, deployed and updated across theorganizations can complement the operating
whole network, and new computers logging on to thesystem’s own mechanisms and safeguard the
network need to have anti-virus software installedcomputer’s operating system along with its data,
immediately and automatically.ensuring that no changes or unauthorized access can
So while organizations need to take other approachesbe made.
into account too and use other technologies, powerfulIs application whitelisting the magic bullet?
traditional anti-virus protection remains crucial. It isApplication whitelisting – allowing only known
relying solely on the traditional reactive approach that is“good” applications to run has both strengths
no longer adequate.and weaknesses as a solution to the problem of
STRATEGY 2today’s threats.
Proactively protect the networkEncryption software can also help avoid statutory
Traditionally, protection against malware and spampublic disclosure requirements and limit the liability
was created by security vendors collecting samples ofassociated with a data leakage incident as many data
particular viruses and spam, and then developingprotection laws have been updated to accept
specific protection. Today this method is simply tooappropriate encryption as an acceptable safeguard.
slow and inadequate – there are too many targetedStrengths
threats and they mutate too rapidly. For example,A strategy which allows only good code to run is a
SophosLabs sees over 20,000 new malicious samplesvery appealing concept.
every day. Such large volumes of rapidly mutatingWhitelisting is a valuable approach for locked-down
malware require proactive, zero-day protection, toparts of organizations, where there are already strong
protect against threats that the vendor has not yetrestrictions on what applications can be used and
seen or analyzed.where those applications rarely change, for example
Anatomy of a threatPoint of Sale (POS) terminals in retail outlets, or
Here is how a significant number of infections areservers performing a limited, core set of functions.
achieved:Weaknesses
- As part of a highly targeted spam campaign, a userApplication whitelisting does not deal with types of
gets an email from a hijacked computer.malware protection needs that depend on subverting
- The spammed email includes nothing more than aknown good applications, including script malware
subject line and a link to an infected website.running in browsers, macro viruses in Office, buffer
- This is a legitimate site so the user is not suspiciousoverflows.
and clicks on the link.If malware evades detection by a whitelisting solution,
- Using a vulnerability to install, a Trojan is immediatelycleaning up the infection is a major task.
downloaded onto their computer.The whitelisting vendor has to keep up with every
- Their computer sends confidential data to the hacker.release of a good application, as well as custom
- The hacker also uses the newly hijacked computerapplications.
to send out more spam campaigns.Administrators need to know exactly what they want
This proactive protection can be achieved throughto allow in order to define policy and have to maintain
behavioral analysis, a HIPS-like* technology that aimsat least some of the whitelist themselves.
to stop malware before a specific detection update isWhen the policy is defined, there is still a major
released, by monitoring the behavior of code – notchallenge in identifying and maintaining the list of
just when code is run, but also beforehand:authorized applications, without impacting user or IT
Pre-execution analysis – examines the behavior andstaff productivity.
characteristics of files before the file is run to find traitsStrategy support through vendor expertise
commonly found in malware.Underpinning the technology of any security software
Runtime protection – analyzes the behavior of filessolution is the vendor’s expertise, experience and
and processes as they are running, checking forunderstanding of the threat environment. The beginning
suspicious activity.of this paper demonstrated the complexity and
An added advantage of strong proactive protection isblended nature of today’s threats. A vendor with
that the number of individual threats that a researchtruly integrated visibility of spam, virus and web-based
lab needs to analyze is reduced, enabling the rapidthreats will be able to ensure the rapid response
creation of new updates and protection whereneeded to combat new threats. In addition, just as
necessary.analysis needs to reach across all threat types and
STRATEGY 3technologies, so does the support offered by help
Use preventive protectionteams.
Network access controlConclusion
A key weapon in exercising control to ensure securityAlthough traditional antivirus protection remains the
and productivity, is the assessment and managementcornerstone of reliable security, modern threats require
of network access. Finely controlled network accesssolutions that go beyond this, providing proactive
reduces the risk of infection by ensuring security policyprotection against fast-moving, zero-day malware. The
is being complied with by all computers – not justwider issues of controlling network access, web
those owned and managed routinely by the companybrowsing and applications need to be addressed by
but also those unmanaged guest computersorganizations as a matter of urgency, and the
connecting to the network.importance of encryption in securing corporate data
By assessing and certifying systems before and afterneeds to be understood and acted upon. Finally,
they connect to the network, network access controlorganizations need to ensure that their vendor has the
software can ensure compliance with policies, such ascross-threat expertise both in its labs and in its support
requiring all computers to have security software inteams, to make the solution cost-effective and
place and properly configured, and operating systemsuccessful.
and application patches up to date. In this way