Advanced Targeted Attacks: the increasing threat landscape
The problem multiplies rapidly
More and more computers are being connected to each other, and to networks and the Internet, in increasing ways. With servers increasingly virtualized, and more software functions being consolidated onto fewer physical machines, exploitable software layers may increase in number while organizations shrink their data centers. With the proliferation of netbooks, mobile devices, and tablets in the enterprise, group-forming networks increase exponentially the number of avenues for potential attack. Workers are also connecting more from their home or other networks, endpoints which enterprise IT organizations can’t hope to secure, creating additional attack vectors.
The problem of malware itself is not just limited to the threat landscape: the number of malware samples that are found continues to rank in the tens of thousands per day. While many of these are variants of previously known malware, a significant number of these samples are still previously unknown, typically referred to as “zero day” attacks. Aside from toolkits that exist to make the creation of malware easier, there is now a burgeoning market in which previously unpublished attacks are sold to the highest bidder, increasing the likelihood that these will grow in number. Enterprises face the increasing risk of being overwhelmed by the amount of samples, and additionally face the difficult task of properly prioritizing those samples for analysis. Assuming a qualified malware analyst can reasonably handle one sample per half hour, in an eight-hour workday that analyst can only analyze 16 samples per day. With 250 workdays per year, a perfectly efficient human analyst can analyze 4,000 samples a year. The scalability to handle more than that is linear – you get only 4,000 samples per year times the number of perfectly efficient human analysts that you can employ. This is not a sustainable model over time, because of the first two risks outlined above, a risk in itself.
Malware authorship is more mature
While ‘script kiddies’ still exist, malware authors today are typically much more mature and organized than they were just a few years ago. With criminal enterprises and nation states comprising a larger percentage of malware authorship, attacks are less about defacing websites and more about stealing money and/or intellectual property.
Malware authors no longer need to find vulnerabilities the way they used to. Often they can simply wait for published reports from software vendors as they patch their software. Once a patch is released for a vulnerability, a malware author can identify how the patch fixes the problem, and write malware to take advantage of that flaw. That author will still have time for his exploit to be useful since many organizations will delay patching while they test the patches in their environment.
As nation states get further into the realm they call “cyber warfare”, malware authorship will continue to mature and take advantage of the software development life cycle, to include things like testing, versioning, and even software-as-a-service development methods.
Malware authors are aware that organizations will attempt to constantly thwart their attacks, either directly or through the analysis of the mechanism of attack, or both. Malware authors make every effort to delay this process for as long as possible, and often use a number of anti-forensic techniques to increase the time in which their attacks are effective. This can be done in a variety of ways and leads to an ‘arms war’ in which the attacking side and the defense side are each trying to outdo the other in their attempts to be successful.

