The Threat Landscape Has Changed Beyond Anti Spam And Anti Virus

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    To replace the title / subtitle with your own: Click on the title block -> select all the text by pressing Ctrl+A -> press Delete key -> type your own text

    1 Favorite

    The Threat Landscape Has Changed Beyond Anti Spam And Anti Virus - Presentation Transcript

    1. The Threat Landscape Has Changed: Moving Beyond Anti-Spam and Anti-Virus Eric Hanselman, CISSP Network Protection Architect
    2. Email Management: An Ongoing Problem
      • Has always been an issue
      • Too easy an access path
        • Ubiquitous, anonymous access
      • Too critical to block
      • Cycles of control
        • Problem is getting worse…
    3. The Problem is Complex
      • Spam
      • Attacks
      • Content management
        • Intellectual property
        • Legal liabilities
    4. Nefarious Goals are Blending
      • Product sales
      • Stock manipulation
      • Money laundering
      • Bot recruitment
      • Data Theft
        • Phishing
        • Keystroke loggers
    5. The Mule Trade
    6. Registrant: Said Mahmod abdulla@abdulla.cc +96.485743234 Said Mahmod inc. Gavi-ayesh 34 21 Reeayad, Reeayad, PALESTINIAN TERRITORY , OCCUPIED 7849343 Domain Name: elxtrading.com Record last updated at 2007-03-02 10:27:15 Record created on 2007/3/2 Record expired on 2008/3/2 Queried whois.apnic.net with " 58.65.236.129 "... % [whois.apnic.net node-1] % Whois data copyright terms http://www.apnic.net/db/dbcopyright.html inetnum: 58.65.232.0 - 58.65.239.255 netname: HOSTFRESH descr: HostFresh descr: Internet Service Provider country: Hong Kong [email_address] .cc - TLD “.CC” is for the Cocos (Keeling) Islands +96.485743234 International Telephone Country Codes +96x is for the “Middle East” (Iraq, Jordan, Kuwait, Lebanon, Maldeves, Oman, Saudi Arabia, Syria, Yeman) +964 is for IRAQ
    7. Profit Motivates Innovation
      • There is a lot of money to be made!
      • Senders are smart
        • Techniques are evolving
      • Spam and attack traffic are converging!
    8. Two Traditional Paths of Defense
      • Anti-spam
        • Block known bad senders
          • RBL’s
        • Block known bad words
        • Block known bad paths
      • Anti-Virus
        • Block known bad attachments
      • We expect some will get through!
    9. Sender Innovations
      • Spread the senders
        • Botnet spam agents
      • Obscure the words
        • Image spam
      • Multiply the paths
      • Morph the attachments
        • Polymorphic encoding
      • Embed new attacks
    10. Image Spam Gets Smarter
    11. Techniques Get Smarter
    12. Avoiding Detection
      • Senders are stealthy
        • No news is good news!
      • Techniques are quieter
        • Stay under the radar
        • Slip between the cracks
      • Targets are smaller
      • Keeping victims quiet
        • Social engineering
    13. A Tale of Two Bots
      • Similar roots
        • Use self-replicating worm techniques to infect hosts via email
        • Establishes connection to bot network for download of additional components
          • Future activities are limitless
      • Stration
        • Great polymorphic encoder
      • SpamThru
        • Brings its own Anti-Virus
        • GIF tools
    14. Masking By Morphing
      • Polymorphic encoder beats Anti-Virus protections
      • High volumes increase success probabilities
    15. Self-Modifying Malware – Stration
      • Number of Variants Captured
      • 8/16/06 to 11/26/06
    16. Next Generation Payloads
      • Script-based obfuscation
        • Payload is hidden by Java script
        • Can pass built-in encoder
      • Additional hiding capabilities
        • Very hard to see in transit
        • Depends on interpretation on the endpoint
      • We can’t count on clean-up
      • We can’t allow any to succeed
    17. How to Approach Protection
      • Staunch the flow
        • Better mail stream filtering
        • Limit user choices
      • Protect at the end points
        • The only place to catch them
        • Ultimate user protection
    18. Staunching the Flow
      • Traditional techniques need a priori knowledge
        • Elusive at best…
        • Bad Stuff is Hard to Predict
      • Time is required for analysis
        • Delay causes scaling problems
      • Statistical analysis
        • An a posteriori technique
        • Good for large volumes
      • Some still gets through
    19. Better Flow Techniques
      • URL references
        • Analyze web links
      • Structure analysis
        • Better capabilities
      • Image analysis
        • Beyond OCR
      • Sender identity control
        • Still a long way off
    20. Host-Based Detection
      • Best for executable content analysis
        • Highly scalable
      • Behavioral executable analysis
        • Anti-Virus isn’t enough
      • Poor statistical capabilities
      • Traditional security
        • Patching still required, but…
    21. The Risks Have Expanded
      • Our protections need to expand, too!
        • Plan for action today!
        • Review existing protections
        • Coordinate email and host protection planning
        • Keep data security planning on the horizon
      • Risks aren’t standing still!
    22. Threats are everywhere… and always evolving. Will you be protected?
    23. Resources
      • Spam and Phishing
        • http://www.antiphishing.org/
        • http://www.sans.org/
        • http:// www.secureworks.com/research/threats/spamthru /
        • http://www.iss.net/documents/whitepapers/X_Force_Exec_Brief.pdf
      • Security Protections
        • http://xforce.iss.net/
        • http://www.av-test.org /
    24. Thank You! Questions?

    + jpricejprice, 3 years ago

    custom

    1355 views, 1 favs, 1 embeds more stats

    INBOX The Messaging Industry Event


    Track: SEC more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1355
      • 1354 on SlideShare
      • 1 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 88
    Most viewed embeds
    • 1 views on http://www.realgoodmedia.com

    more

    All embeds
    • 1 views on http://www.realgoodmedia.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories