Protection Against Next-Generation Threats | Antivirus


Protection Against Next-Generation Threats | Antivirus


The wide variety of new cyberattacks, especially those called Zero-day and APT, complicate IT, security administrators. They have the power to overcome traditional defence barriers such as firewalls, IPS systems and antivirus, affecting a very high percentage of networks.

More than ever, secure access to the web, email, and shared resources are at risk. As David DeWalt, member of the Advisory Committee on Telecommunications for National Security of the President of the United States points out; and CEO of FireEye, despite more than $ 20 billion invested in IT security technologies in 2014, cybercriminals and those responsible for Advanced Persistent Threats (APTs) continue to trespass on virtually anywhere. network, stealing data and disrupting business development.

This statement, included in Steve Piper's “Definitive Guide for Next-Generation Threat Protection,” CISSP, published by CyberEdge Group, is the starting point to understand that, today, companies are not facing any type threat or virus isolated. Today, all companies are exposed to persistent, complex and, as this guide says, "stealth" attacks, which are successful when it comes to compromising networks.


The "New" Risks

As in many issues, traditional security paradigms have drastically changed from some years ago until now, and the specialist security channel, in charge of implementing data protection tools in companies, has seen with surprise how threats already they do not come from within companies as before. Today, the picture is different.

Evidence of this new reality is the study carried out three years ago by the Verizon company, which analyzed nearly 900 data security incidents that occurred in 2011, and which determined that 98% of the incidents were originated by external agents.

Another distinctive feature of today's computer attacks is that their perpetrators are no longer just hackers motivated to achieve public notoriety. “The cybercrime industry has been completely transformed from piracy for fun to cyberattacks for profit or, in some cases, for political purposes. Today's cybercriminals are well trained and incorporate sophisticated attack techniques, which cannot be fought with traditional signature-based defences, which are insufficient, "says Steve Piper.

The third element that characterizes today's data security problems is that their nature is as complex as it is diverse. As described in the “Definitive Guide for protection against next-generation threats”, these are multivector and multiphase threats, capable of circumventing traditional security barriers such as firewalls, intrusion prevention systems (IPS, Intrusion Prevention Systems), secure web and email gateways and antivirus platforms

The Damage in Numbers

The statistics on the damage done by next-generation threats to corporate networks are simply staggering. During 2014, cyberattacks against organizations increased by 176%, associated with millionaire losses. Jorge Rojas, NovaRed Services Manager, points out that during the last four years, the number of cyberattacks grew 176%, where the time required to solve them also experienced a considerable increase. Data from an Intel Security survey indicated that 74% of respondents think that targeted intrusions are one of the biggest concerns in their companies and, even more worrying, only 24% trust their ability to detect it in the first few minutes,

NovaRed points out that in some more complex cases, companies take an average of 170 days to detect a malicious attack, which once detected takes around 45 days to be solved, dragging costs close to 1.6 million dollars. Likewise, they indicate that companies that are victims of a computer attack face consequences related to the impact on the business and financial damage. An international study by Kaspersky Labs shows the loss of access to critical information (61%), as the main consequence for a company after a Denial of Service (DDoS) attack, followed by damage to its reputation with 38%. In relation to the expenses that a company victim of this type of attack must incur are the consultations with companies specialized in information technology security (49%); legal advice (46%); payment for improving and securing IT platforms (65%), and final payment for risk managers (41%).

The Danger in the Network

As Piper indicates in his book, cyberattacks are grouped into two broad categories: traditional threats and next-generation threats. The traditional ones are hyper-known, but no less important, because they still cause damage to the systems of companies that are not sufficiently prepared. They include worms, Trojans and viruses, spyware and botnets, social engineering attacks - such as phishing and baiting - and buffer overflows and SQL injections.

When it comes to next-generation threats, the situation is more complex because, as the name implies, they are less known and predictable. Some of the main ones are zero-day threats, advanced persistent threats, polymorphic threats, and blended threats.

Zero-day threats take advantage of an unknown vulnerability in an application or operating system and are named after the attack occurs at the same time the vulnerability is made public, or even earlier. They are highly effective because they can go unnoticed for months or years.

Advanced persistent threats, known as APT or ATA, are sophisticated attacks in which a stranger gains access to a network and remains on it undetected, with the aim of stealing information. The companies most affected by them are those that handle valuable information, such as financial institutions.

Polymorphic threats are cyberattacks that can appear in the form of a virus, worm, spyware or Trojan, and constantly transform - changing the name of the file and its compression level - making it difficult to detect.

Blended threats are a mixture of several types of malware, which attack different areas of systems, to increase the severity of the damage and its speed of spread.


Protection for New Threats

In the face of new and powerful threats, complex, deep and detailed levels of protection are required, in other words, a new category of network security defence, such as Next Generation Threat Protection, known by its acronym NGTP, which in English stands for Next-Generation Threat Protection. According to Steve Piper, "this is a new and innovative network security platform, which has proven to help us win the battle against next-generation threats."

According to the definition of the “Definitive Guide for protection against next-generation threats”, NGTP belongs to a new generation of network security technologies, specifically designed to identify and prevent new modern cyberattacks, which improve security systems. traditional security instead of replacing them. It introduces a new layer of defence-in-depth architecture to create a threat protection fabric that provides protection against cyberattacks, which go unnoticed by typical signature-based defences.

In general, the best-rated NGTP providers offer an integrated platform that examines email message traffic, web traffic, and file-at-rest, and shares threat information between attack vectors. These devices examine traffic and files for suspicious characteristics, including stealth techniques. "Sessions are replayed in a virtual runtime environment made up of virtual machines with a custom virtualization engine specifically designed to analyze security, in order to determine if suspicious traffic contains malware," explains the author.

The feature set of NGTP solutions varies and the channel needs to offer its customers the platform that best meets their needs. However, it is important that this type of advanced solutions benefit from elements such as virtual execution of suspicious objects, fast-path blocking, handling of malicious files in quarantine, centralized administration, ability to share information about malware, custom rules, integration with the antivirus suite, role-based access controls, a dashboard to monitor network security, the ability to generate reports and alerts, and Incident Management and Integration of NGTP into the existing IT infrastructure.

Having a solution that integrates most of these characteristics guarantees to a great extent the protection of a company's systems and networks. It allows you to feel protected against new-generation threats, to face business development with peace of mind.


Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software