How to Keep Up with the Latest Email-based Threat Response
An increasing amount of companies and organizations are interested in email threat response regardless of their industry and company size. Emails are often neglected because it has been one of the longest existing traditional threat. However, the way emails attack has changed from mass target to specific enterprises and organizations by utilizing spear phishing methods. This is why most emails are considered as a main entry of APTs (Advanced Persistent Threat).
Most email attacks, targeting companies and organizations, use social engineering techniques to lure recipients. They often impersonate as a well-known company or government by sending what seems to be a business email with attachments, such as resume, invoice, patent, and copyright infringement. In addition, the attachments formats used are constantly changing. Recently, business files, such as Word, Excel, or PDF files, are being sent via attachments to avoid suspicion. Similarly, HTML files are also widely used as attachments. Attackers attach a non-executable (non-PE) file in the form of a document to avoid any suspicion and to evade detection by spam filters or behavior-based security solutions.
As a result, traditional security solutions used by many companies have limitations in detecting the latest email attacks. Also, it is unreasonable to expect that employees with lower understanding of IT and security can be aware of the sophisticated emails designed with social engineering techniques
This is why AhnLab focused on improving response capability for email-based attacks in the latest version of AhnLab MDS (Malware Defense System for APTs). The latest version of AhnLab MDS aims to enhance detection capability against vulnerability-based attack and to increase the efficiency of the threat response by sharing analyzed information.

Figure 1. AhnLab MDS
Content filtering: Enhanced to effectively respond to the latest email attacks
AhnLab analyzed the trends of recent email threats and applied them to the threat response features of AhnLab MDS. First of all, AhnLab enhanced its “content filter” to provide scalability for malicious-suspected email detection and blockage depending on the environment of each company. Security administrators can customize the content filter details, including the email headers, subject lines, body contents, and attachments. In addition, YARA rule creation option has been expanded to allow administrators to set detection conditions and measurements for emails depending on the environment of each company.
To respond to the latest email attacks using attachments in various formats, AhnLab expanded the scope of detection and analysis to appropriately deal with countless file extensions, including compressed files. Severity level indication for email files (.eml) containing detected compressed files and attachments have also been improved. Also, AhnLab enhanced its analysis of encrypted keywords in email subject lines in addition to the encrypted phishing text within the email subject lines. This allows files with passwords to be thoroughly scanned. Security administrators can now efficiently and proactively manage and respond to emails more by using features such as expanding exception handling options.

Figure 2. Severity levels and relevant information provided for compressed files
New analysis engine framework: Applied to improve vulnerability-based attack detection
AhnLab MDS, with its exclusive Dynamic Intelligent Content Analysis (DICA) technology, has been providing sandbox-based dynamic analysis for document files in various formats, namely non-PE files. The latest version of MDS is equipped with a new analysis engine framework for non-PE files developed by AhnLab to enhance MDS's detection performance for non-PE files while also improving sandbox efficiency.

Figure 3. Detection and analysis result of malicious files contained in (non-PE files) document files
The newly implemented analysis framework for non-PE files provides advanced static analysis of malicious document files that are difficult to detect with virtual machines (sandboxes). As the detection for malicious files contained within document files has been improved, security administrators are now able to respond more efficiently to elusive email-based attacks that induce user’s interaction, such as clicking the link in the attached file. In addition, static analysis supports more precise responses to non-PE files while also enabling improved efficiency in sandbox-based analysis.

Figure
4. Malicious file inducing user’s interaction
Efficient response based on internal threat intelligence and cloud-based TI
Early this year, AhnLab added a feature to "share behavioral analysis" with the MDS Manager that integrates and manages MDS devices to provide effective threat response. This feature is used to share the results of the behavioral analysis of multiple MDS devices deployed in the network, email zone, and network connection.
The latest version of MDS allows large companies with headquarters and branch offices or public organizations with central administration agency and affiliated agencies to reliably share behavior analysis information. When a new threat is detected by one of the MDS devices deployed within an organization, the behavior analysis results, along with the information about the file, are shared through the MDS Manager, enabling other MDS devices to immediately respond without any further analysis. By providing accurate detection and response without performing a separate behavior analysis, MDS analysis devices can be efficiently utilized.
AhnLab also provides analytical and diagnostic information via MDS cloud. Customers using the latest version of MDS can utilize this information.
Moreover, AhnLab enhanced MDS for better integration with other devices to enable better threat response. Owing to this, MDS can be used as a dedicated sandbox analysis suited for individual environment of each company.