How to Conquer Advanced Persistent Threats: Cybercriminals Never Sleep, Nor Should Your Advanced Threat Defense

First, let’s go over the three main targets of advanced threats: email, network, and endpoint.
Main Target #1: Email
Email is where information breaches most frequently occur because anyone who knows the target email address can easily attack. Many assume that company email is the major target, but attacks exploiting external elements, such as employees opening emails via the web or outlook, have also been prevalent. Since email attacks are highly successful compared to the input effort, it is one of the most widely used techniques to this day.
The majority of email attacks come with attachments, such as executable files, document files, and archive files. Particularly, the use of document files such as Hangul Word Processor (HWP), Microsoft Office, and PDF are predominant. When a recipient executes a malicious document file attached to the email, the threat actor might gain access to perform malicious activities or to download its malware.
Recently, threat actors started including links within emails as more organizations have now deployed security solutions that restrict the delivery of email attachments from external sources. Instead of directly attaching a file, threat actors decided to add a large-sized external download link or an address of a phishing website, prompting the user to open the malicious website to steal sensitive information, such as account information. Sometimes, they use a website link with hidden security vulnerabilities to steal information.
Other attacks are carried out via a text-only email, which does not include an attachment file or link. Their major objective is to make financial profits in a short period of time. For instance, threat actors could ask for ransom by threatening the victim to distribute personal information, such as the web history and video playlist, to all email accounts within the victim’s contact list if the demanded payment is not made. They sometimes trick the victim by pretending to recruit members for financial investments.
There are cases where the threat actor impersonates an organization and notifies the client with a forged bank account in order to snatch the payment. A surprisingly large amount of organizations have reportedly experienced major or minor financial losses from these types of attacks. As threat actors perform their attacks after a thorough investigation of their targets, their success rate is high.
Main Target #2: Network
Cyberattacks targeting networks require more advanced techniques than email attacks. This is because the attacker must prompt the target user to open the malicious website in their own will.
A network attack fundamentally utilizes the file type of malware. It exploits web browser vulnerabilities, blog, or SNS to distribute malicious executable file disguising as a normal program. Macro or document files, images, and video files with vulnerabilities are occasionally exploited as well. Most of these attacks leverage the web as a route while some use FTP. Techniques exploiting IoT vulnerabilities are also increasing as it has become a rising trend.
Network attacks are occasionally attempted without malware, which means that the threat actor exploits the vulnerabilities within the internal server, IP/Port, Scan, and WebShell. Malicious outbound traffic is also considered as a risk factor. For instance, personal or confidential information can be leaked from a pre-infected PC or malicious website that the user carelessly accessed.
An air-gapped network, which is commonly perceived as a robust security method, can also be a target of network attacks. When the user opens a malicious email or file disguised as work-related material while being connected to the business network, there is a risk of malware infection. Also, threat actors can directly execute malicious behavior against endpoints by evading the network. As such, there are various occasions in which air-gapped networks are not so safe after all.
Main Target #3: Endpoint
The endpoint is the ultimate target of many advanced threat actors because this is where most sensitive business data resides.
Current endpoint attacks mostly target internal business PCs, mobile devices, servers, production facilities, or laptops available from outside of the workspace. Threat actors tend to leverage the method that amplifies the impact by spreading from one endpoint to other devices. The commonly used technique in spreading malware across the endpoint is by using a malicious USB and connecting it to a PC, laptop, and even manufacturing systems. Threat actors sometimes exploit OS vulnerabilities in the PC to distribute the malware to other devices connected to the same network. Also, there are fileless attacks that exploit legitimate programs to conduct malicious activities.
Cybercrime is projected to become more advanced, and it will require a more sophisticated defense system. According to the report ‘5G and its Cybersecurity Implications for Enterprises’ by Frost & Sullivan from last July, one of the major security challenges that organizations will encounter in the 5G era is a wider range of attacks. Companies adopting a 5G network will have to use devices and applications in new verticals, such as the OT environments, which are beyond the realm of the traditional endpoint. This will inevitably expand the range of cyberattacks.
Requirements for Security Solutions
Now, let’s explore the requirements for security solutions to effectively cope with advanced threats.
In case of an email attack, solutions should be able to quickly analyze document files to minimize email latency. It needs to dissect the file from the link included in the email and promptly filter the malicious file by utilizing the reputation information. Even without reputation information, security products must be capable of analyzing the link and detect scam email by examining the keywords.
In addition, they must support the response measure for the files circulating locally: archive file with ALZ extension and the one encrypted. All the above must be reflected on both internal and external email.
Network security solutions should secure visibility on every file uploaded or downloaded by user via network. The analysis engine is required to analyze new malware variants not detected by anti-malware. Also, it must be equipped with optimized logic for each file extension to conduct comprehensive analysis. They should detect every inbound and outbound malicious packet by thoroughly monitoring all traffic.
Lastly, endpoint security solutions must conduct real-time monitoring for each device. External PC should maintain an equally high level of security as it can be connected to the internal system with being infected. Solutions need to examine USB and provide features such as vulnerability prevention and real-time detection of fileless attack.
Considering all of these will spawn one complicated question. ‘Is it even realistic to satisfy all these requirements?’. As a side note, adopting multiple security solutions per security vector will possibly undermine visibility and efficiency.
AhnLab MDS — A Systematic Security Solution Against Advanced Threats
The presence of holistic security solutions linking different security features will shine as we should cope with more advanced and intelligent threats. As a single product cannot cover all range of attacks, it is integral to establish a ‘cyber kill-chain’ by combining multiple features in existing solutions followed by considering characteristics of various attack methods.
AhnLab MDS is the ultimate security solution against APT (Advanced Persistent Threats), providing intuitive yet comprehensive threat visibility. Also, the product firmly establishes the following security process: collection analysis & detection monitoring response. This allows the AhnLab MDS to provide a systematic response capability for both network and endpoint and blocks advanced threats that infiltrate via various routes. The key features of AhnLab MDS are as below:
1. Multi-engine analysis
2. Sandbox-based dynamic analysis
3. Network traffic analysis
4. Email analysis
5. PC attack response
6. AhnLab V3 + AhnLab MDS integrated agent

Figure 1. How AhnLab MDS Works
1. Multi-engine analysis:
AhnLab MDS effectively detects and analyzes both existing and new threats by leveraging its multi-engine. For known threats that take up 90% of the total threats, AhnLab MDS mainly employs a signature engine that detects malicious websites and C&C (Command and Control) traffic. Plus, the reputation engine quickly filters malware based on real-time cloud connection and rules such as YARA, Hash, and IP/Domain defined by the administrator. These contribute to the fast completion of analysis.
Then, AhnLab MDS scrutinizes the remaining 10% of unknown threats by utilizing machine learning and sandbox engine (non-signature). The machine learning engine determines whether the file is malicious by examining the data from the document type of file. Sandbox engine implements a specialized analysis engine per file type on the virtual machine.
2. Sandbox-based dynamic analysis:
The sandbox-based dynamic analysis feature of AhnLab MDS consists of behavior and content analysis.
The dynamic behavior analysis engine examines executable files on the virtual machine. It monitors any alteration of files, processes, registries, and networks in real-time. Then, it determines whether the executable file is malicious by recording and analyzing the behavior, reputation, and other relevant information. Consequently, the engine can minimize the false positive rate as it not only analyzes the target preceding and the following behavior but also detects the validity of IP, URL, process, and file by employing in-cloud reputation information.
Dynamic content analysis engine analyzes non-PE files (non-executable files), such as document and script files (JS, VBS, and WSF). It detects the malicious behavior of the file quicker than the behavior detection by separating the code from Macro, inserted object, and vulnerability included in the document before conducting an analysis. It is especially useful in environments where a large amount of email attachments or file transfer is needed via the network connection.

Figure 2. Dynamic Analysis Process of AhnLab MDS
3. Network traffic analysis:
AhnLab MDS blocks malicious traffic from abnormal sources, such as the C&C server and malicious website on the network level. AhnLab MDS enables this by censoring all packets and analyzing network traffic. Then, it transmits traffic information, such as source, destination, IP, and URL to the cloud and filters them based on reputation information.
AhnLab MDS also distinguishes the attack executed by external threat actors and detects malicious outbound packet from internally infected PC. AhnLab MDS immediately blocks any malicious traffic to prevent further damage.
4. Email analysis:
For incoming emails, AhnLab MDS performs dynamic analysis on the attachment and multidimensional analysis of malicious URL/ script within the email based on the allow/block list and reputation information.
As previously mentioned, AhnLab MDS employs a multi-engine to quickly and precisely analyze file attachments. It can analyze a lot of document files using a sandbox-based dynamic content analysis engine.
Links provided in the email are also analyzed from various angles. AhnLab MDS downloads a file from the link to identify its maliciousness and simultaneously analyzes the phishing website as well as the one exploiting vulnerabilities by prompting users to access suspicious URLs.
Any email identified as malicious after a series of analyses by multiple engines is quarantined by AhnLab MDS.
5. PC attack response:
AhnLab MDS provides following PC attack response features via its specialized agent: ▲execution holding ▲vulnerability detection & block.
First, execution holding (EH) prevents a run of unauthorized file and protects the system from initial infiltration. AhnLab MDS detects whether the file is malicious when the file brought from USB or unidentified source is executed. As such, users can preemptively respond to the malware before infection as the solution only allows execution after the file is identified as valid.
In addition, AhnLab MDS can detect and respond to various attacks exploiting vulnerabilities. The solution fundamentally performs a real-time monitoring against the operation and prevents initial malicious behavior, letting users benefitted from a similar feature of EH. The agent’s segmented exclusion feature minimizes false positives as well as other potential user inconveniences.
6. AhnLab V3 + AhnLab MDS integrated agent:
Optimized to each business environment, AhnLab MDS agent acts as a single agent by interoperating with AhnLab’s anti-malware solution, V3. AhnLab V3 detects and responds to known malware and malicious behaviors while MDS deals with unknown threats and variants. AhnLab MDS is compatible with other anti-malware solutions by providing the single deployment of AhnLab MDS agent.
AhnLab MDS Reduces Burden for Security Administrators with 99.1% Threat Detection Rate
MDS solution’s competitiveness lies in its capacity to detect new threats and variants. Modern security solutions must harbor a variety of features to effectively respond to existing attacks, but its value inevitably fades over-time if it is unable to properly detect unknown and advanced attacks.
AhnLab MDS was acknowledged by ICSA Labs in the Q3 2019 Advanced Threat Defense (ATD) evaluation for scoring 99.1% in unknown threat detection and ‘0%’ in false positives. AhnLab passed all evaluation categories with outstanding scores.

Figure 3. AhnLab MDS is certified by ICSA Lab for Advanced Threat Defense
Other notable strengths of AhnLab MDS are as below:
●Management resource optimization: AhnLab MDS provides an automatic response feature against all detected threats in each vector. Thereby, security administrators only need to check the result of the response and restore false positive events.
●Cost-efficiency: AhnLab MDS supports monitoring, analysis, and response for multiple vectors ‘all-in-one’ format. Administrators can utilize a pinpoint scan feature, which enables the analysis of suspicious files or malicious IP/URLs. Also, MDS supports a standardized API compatible with other security products.
●User-defined policy setting: AhnLab MDS allows a user-defined policy setting for each organization. Considering the circumstances of each business environment, MDS can adjust the policy level as well as the size of files for the analysis by meeting the bandwidth of each region.
●Professional service: AhnLab MDS also provides over 25 years of security expertise via its in-house security experts and professional services.
Integration is Essential in Building a Secure Environment
Advanced business environment and newly emerging threats keep putting pressure on security managers. As mentioned above, operating multiple security solutions could degrade visibility and management efficiency. This is the challenge that should be addressed promptly to protect business value.
To some extent, the ability to integrate and connect security capabilities will decide success in security. Now, it is almost impossible to perfectly defend the network, endpoint, email, and other vectors with each different product. This leads to the conclusion that organizations should establish a holistic and agile security process powered by a single integrated solution. But before that, it is essential for entities to clearly understand their security needs and select proper products and policies.
Once the above conditions are adequately met, organizations will be able to take a step towards building a safe business environment.