FireEye

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    FireEye - Presentation Transcript

    1. FireEye Network Malware Control System Chad Harrington VP of Marketing
    2. Overview Crimeware’s rise to prominence Traditional security barriers collapsing FireEye Network Malware Control System
    3. Understanding Crimeware
      • Targeted malware for profit
      • Funded by criminal orgs & online markets
      • Allows remote control by external parties
      Cybercrime now ranks among the FBI’s top priorities behind terrorism & espionage. Computer-based crimes caused $14.2 billion in damages to businesses around the globe in 2005
    4. The Crimeware Economy
    5. Impact of Crimeware Attacks
      • Bottom line losses
        • Product/service theft
        • Intellectual property stolen
        • PC & bandwidth exploited
      • Liability & clean-up
        • Customer notifications & lawsuits
        • Data restoration & downtime
      • Brand erosion & loss of customers
        • 20% of notified customers have ended business relationship due to breach
    6. How Does Targeted Malware Infiltrate?
      • Common vectors
      • Mobile laptop
      • Employee home machine
      • 3 rd party, guest PC
      • Enterprise desktop
      1 Customized attack
    7. How Does Targeted Malware Infiltrate? 2 Customized attack Command & control
      • Remote Control Established
      • Begin probing network
      • Identify high-value victims
      • Install additional malware
      • Steal data & information
    8. How Does Targeted Malware Infiltrate? Targeted infiltration 3 Customized attack Command & control
    9. How Does Targeted Malware Infiltrate?
      • Keyloggers
      • Password crackers
      • Trojans
      • Spam/Phishbots
      4 Customized attack Command & control
    10. Traditional Security Barriers Collapsing
      • Crimeware is designed to escape attention
      • Exploits bypass traditional security, such as
        • Firewalls – use open ports
        • Antivirus – be slightly new & different
        • Anomaly detectors – remain calm & look normal
      “ Botnet worm infections can occur even when the impacted organization has the very latest antivirus signatures and is automatically pushing out OS and application patches .” US-CERT whitepaper
    11. Targeted Malware Simply Undetectable by Traditional Security Techniques Targeted malware has 2 to 6 year window Window of Exploitability Signature or Patch Released Vulnerable Software Released Vulnerability Discovered/ Disclosed
    12. Fire FireEye Network Malware Control System
      • Stops botnet & malware infiltration others do not
      • Ensures only compliant PCs gain network access
      • Continuous network traffic analysis
      • Automatic prevention & enforcement
    13. What is Network Malware Control? Ensure Compliance On-connect network access controls ensures only compliant machines gain network access Continuous Analysis Continuous analysis of network activities for botnet transmissions & infection attempts Automatic Enforcement Automatically filter out malicious packets, botnet transmissions, and block infected machines
    14. Ensure Compliant Network Access Remote & Wireless users LAN users WAN/VPN Internet Wireless Network access controls - Limit network access to machines with updated AV signatures & OS patches
    15. Continuous Analysis using the FireEye Attack Confirmation Technology (FACT) An infinite supply of virtual victim machines analyzes network traffic flows for targeted attacks Mirrored network traffic flows
    16. Automated Prevention & Enforcement Switches Close off / restrict network access to infected machines to protect customer data and company resources Mobility controllers MAC exclusion, VLAN re-assignment to block infected machines from network Packet filtering Productive traffic can continue to flow, but malicious traffic is blocked Internet
    17. Typical FireEye Deployments Backbone WAN Internet Data Center Eliminate Network Borne Crimeware from Wireless Users Protect Data Center Windows Servers from Crimeware Eliminate Crimeware From Infiltrating from Internet Eliminate Network Borne Crimeware From Remote Branch Offices and Stores
    18. The FireEye Ecosystem
      • Active collaboration with law enforcement, industry, & security researchers to root out crimeware
        • Law enforcement & Military
        • Research institutions
        • Industry participants
        • Enterprise customers
        • Internet Service Providers
    19. About FireEye, Inc.
      • Dedicated to eradicating malware from the world’s networks
      • Based in Menlo Park, CA
      • Led by an experienced team from Sun, Cisco, Aruba, Symantec, Check Point, & McAfee
      • Online at www.fireeye.com
    20. www.fireeye.com

    + gigamongigamon, 3 years ago

    custom

    878 views, 0 favs, 2 embeds more stats

    FireEye, Inc. is the leader in network malware cont more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 878
      • 866 on SlideShare
      • 12 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 0
    Most viewed embeds
    • 7 views on http://www.lovemytool.com
    • 5 views on http://www.gigamon.com

    more

    All embeds
    • 7 views on http://www.lovemytool.com
    • 5 views on http://www.gigamon.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories