{"id":9,"date":"2013-06-17T09:43:19","date_gmt":"2013-06-17T09:43:19","guid":{"rendered":"http:\/\/www.3lectrik.com\/normanshark\/?page_id=9"},"modified":"2013-06-18T05:40:18","modified_gmt":"2013-06-18T05:40:18","slug":"advanced-targeted-attacks","status":"publish","type":"page","link":"https:\/\/www.3lectrik.com\/normanshark\/threat-protection\/advanced-targeted-attacks\/","title":{"rendered":"Advanced Targeted Attacks"},"content":{"rendered":"<h3>Advanced Targeted Attacks: the increasing threat landscape<\/h3>\n<h3>The problem multiplies rapidly<\/h3>\n<p>More and more computers are being connected to each other, and to networks and the Internet, in increasing ways. With servers increasingly virtualized, and more software functions being consolidated onto fewer physical machines, exploitable software layers may increase in number while organizations shrink their data centers.\u00a0 With the proliferation of netbooks, mobile devices, and tablets in the enterprise, group-forming networks increase exponentially the number of avenues for potential attack.\u00a0 Workers are also connecting more from their home or other networks, endpoints which enterprise IT organizations can\u2019t hope to secure, creating additional attack vectors.<\/p>\n<p>The problem of malware itself is not just limited to the threat landscape: the number of malware samples that are found continues to rank in the tens of thousands per day.\u00a0 While many of these are variants of previously known malware, a significant number of these samples are still previously unknown, typically referred to as \u201czero day\u201d attacks.\u00a0 Aside from toolkits that exist to make the creation of malware easier, there is now a burgeoning market in which previously unpublished attacks are sold to the highest bidder, increasing the likelihood that these will grow in number.\u00a0\u00a0 Enterprises face the increasing risk of being overwhelmed by the amount of samples, and additionally face the difficult task of properly prioritizing those samples for analysis.\u00a0 Assuming a qualified malware analyst can reasonably handle one sample per half hour, in an eight-hour workday that analyst can only analyze 16 samples per day.\u00a0 With 250 workdays per year, a perfectly efficient human analyst can analyze 4,000 samples a year.\u00a0 The scalability to handle more than that is linear &#8211; you get only 4,000 samples per year times the number of perfectly efficient human analysts that you can employ.\u00a0 This is not a sustainable model over time, because of the first two risks outlined above, a risk in itself.<\/p>\n<h3>Malware authorship is more mature<\/h3>\n<p>While &#8216;script kiddies&#8217; still exist, malware authors today are typically much more mature and organized than they were just a few years ago.\u00a0 With criminal enterprises and nation states comprising a larger percentage of malware authorship, attacks are less about defacing websites and more about stealing money and\/or intellectual property.<\/p>\n<p>Malware authors no longer need to find vulnerabilities the way they used to. Often they can simply wait for published reports from software vendors as they patch their software.\u00a0 Once a patch is released for a vulnerability, a malware author can identify how the patch fixes the problem, and write malware to take advantage of that flaw.\u00a0 That author will still have time for his exploit to be useful since many organizations will delay patching while they test the patches in their environment.<\/p>\n<p>As nation states get further into the realm they call \u201ccyber warfare\u201d, malware authorship will continue to mature and take advantage of the software development life cycle, to include things like testing, versioning, and even software-as-a-service development methods.<\/p>\n<p>Malware authors are aware that organizations will attempt to constantly thwart their attacks, either directly or through the analysis of the mechanism of attack, or both.\u00a0 Malware authors make every effort to delay this process for as long as possible, and often use a number of anti-forensic techniques to increase the time in which their attacks are effective.\u00a0 This can be done in a variety of ways and leads to an \u2018arms war\u2019 in which the attacking side and the defense side are each trying to outdo the other in their attempts to be successful.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Advanced Targeted Attacks: the increasing threat landscape The problem multiplies rapidly More and more computers are being connected to each other, and to networks and the Internet, in increasing ways. With servers increasingly virtualized, and more software functions being consolidated onto fewer physical machines, exploitable software layers may increase in number while organizations shrink their [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":5,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-9","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/P5TlPb-9","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/9","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/comments?post=9"}],"version-history":[{"count":3,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/9\/revisions"}],"predecessor-version":[{"id":114,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/9\/revisions\/114"}],"up":[{"embeddable":true,"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/pages\/5"}],"wp:attachment":[{"href":"https:\/\/www.3lectrik.com\/normanshark\/wp-json\/wp\/v2\/media?parent=9"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}