A Security Resolution: Be More Intelligent
On October 15, AhnLab, a global security solution provider, hosted the AhnLab Integrated Security Fair (AhnLab ISF 2014) in Seoul, South Korea. AhnLab ISF is one of the largest information security conferences, offering valuable insights on the latest security threats and providing countermeasures. Approximately 2,000 IT and security managers from various industries attended this event.
This year, under the theme of “RE:SOLUTION,” AhnLab presented ”Intelligence-driven Security” as its response strategy to the latest evolution of sophisticated threats. Through 12 presentations and technical sessions, AhnLab emphasized the importance of finding a “resolution” for threat factors, optimized to the individual company’s needs. AhnLab explained that the resolution of security can be achieved by combining an understanding of industrial characteristics with effective solutions. The conference reflected AhnLab’s goal to build a security ecosystem through collaborating with other security vendors such as Barracuda, EMC Korea, Tenable Network Security, Palo Alto Networks, Akamai Korea and HP Korea.
AhnLab CEO Chijung Kwon stated, “Today we need to set priorities to effectively implement security solutions when security threats are advancing and increasing in number.” He added, “The standard for setting priorities is intelligence—in other words, customer experience and knowing the customer’s needs.” He then continued to define AhnLab’s security intelligence as providing optimized security based on the customer’s particular characteristics and demands combined with AhnLab’s data and information on each customer’s experience of threats and their responses. Kwon emphasized that “AhnLab’s security purpose is to provide customer-driven security based on customer intelligence, not a security provider’s one-sided intelligence for delivering solution and knowhow.”
Is there a PERFECT solution to Advanced Persistent Threats?
The hottest topic at AISF 2014 was advanced persistent threats (APT). Advanced Persistent Threats are hard to detect and prevent as it is a type of targeted attack which makes heavy use of zero-day vulnerabilities or unknown security holes; they are able to remain undetected for a long period of time before the attack is actually carried out. On top of that, the latest intelligent threat response solutions, which are becoming more complicated, make it difficult for security managers to select the proper security solutions.
For such cases, AhnLab has provided information on various APT solutions available in the market today, and presented methods to determine the perfect solution for each business characteristic. An important fact when implementing APT solutions is that an effective response system structure and its operations are possible when one acknowledges that a complete defense against all security threats is impossible. In other words, an expectation of a perfectly complete defense should be lowered, but companies should further develop and plan realistic response mechanisms to strive for the goal of the most complete defense possible. Also, for an APT solution to work properly, information about the malware, such as how the malware was created and where it came from, must be analyzed in real-time, and the intrusion must be responded to at the endpoint level.
Intelligent threat response: From deployment to management
APTs can be thought to be launched by sophisticated technology, but in the end, they are carried out by human. Based on this fact, defenders need to understand APTs in the shoes of their attackers. Attackers investigate the target company’s system and security solution to find a method to infiltrate the computer system and bypass security, but companies are passive in finding countermeasures. On the other hand, many security solutions, including NG firewalls, claim to offer APT protection, but most features have nothing to do with APT response. An effective APT solution must provide features that will analyze all files entering the network, detect the latest attack trends, and be easily manageable and cost-effective.
Exploit-based APT attack: Limitation in behavior-based technology
Although APT attacks do not occur as frequently as other known threats, the problem lies in the fact that its damage is “serious.” At AISF 2014, AhnLab demonstrated a malicious file used in an exploit attack against a South Korean company; a file containing malware executed when the victim performs a certain behavior on file; and a malware executed when a specific application installed to a specific OS meets the version requirements. In reality, it is difficult to detect such threats by only using existing behavior-based technology only. However, Dynamic Intelligent Content Analysis (DICA) provided by AhnLab MDS detects these document-type malware before they start their malicious behavior. The technology conducts assembly code-based analysis in the memory and detects and responds to malware in the application exploitation stage, which bypasses behavior-based analysis technology. It is expected that DICA will advance in technology to detect and respond to malware which exploits zero-day vulnerabilities.
Back to the Basic, Back to the Endpoint
The latest intrusion incidents do not leave any trace of the host file or attack vector in the suspicious file found at the endpoint. This is 1 percent of the unknown threats. The host file and intrusion path information are needed to thoroughly figure out the damages and also respond to additional threats. In other words, visibility, timeliness and accuracy are needed to respond to unknown threats at endpoints. AhnLab MDS provides agents based on AhnLab’s accumulated knowhow on agents. These exclusive agents can be used to automatically or manually remove the host that downloaded the malware. With this agent, even new malware that directly enters the endpoints via encrypted traffic like SSL or USB flash drives or the local network can be analyzed and blocked as execution holding is performed on files that are not diagnosed yet.