![]() |
Data security and privacy: A holistic approach Download here |
Zeus isn't the first crimeware kit, but it's the reigning champ thanks to its popularity among criminal groups for being incredibly powerful yet easy to use. A recent entry at the McAfee Labs Blog highlights some of the advanced features in one particular version of Zeus, including screenshots of the ZeuS Builder applications criminals can use to craft their custom Zeus bot.
While it is easy for criminal groups to create new Zeus variants to evade antivirus detection, there are some common defenses enterprises can deploy to help defend their networks and sensitive data. Likewise, there are several freely available resources that should be leveraged to help combat this advanced malware threat since relying on commodity security products for protection isn't enough.
It's impossible to ignore the fact that defense in-depth works and is a good foundation for effectively combating Zeus and similar malware. Some of the highlights defense in-depth include are a comprehensive anti-malware solution installed on all workstations, a Web and e-mail proxy providing content filtering and anti-malware detection, least privilege access for all users (i.e., no casual Web surfing or computer use as an administrator), intrusion detection or prevention systems (IDS/IPS), and firewalls where appropriate within the network and at the Internet gateway.
The problem with relying simply on commodity security solutions is that malware is changing so rapidly that security companies cannot keep their products up-to-date. There are some exceptions, such as offerings from Damballa and FireEye, but they are cutting-edge solutions breaking the commodity mold and not usually found in SMB environments.
IT needs to adapt to meet the current threat head-on and become more involved in actively combating the threat instead of relying on their antivirus solutions or firewalls to do it for them. Prevention is certainly preferred over the reactionary approach that follows detection. But both are incredibly important to be successful in combating Zeus and similar modern malware.
Because so many organizations, both large and small, rely on the false sense of security provided by antivirus on their desktops and e-mail gateways, they discount the need to stay abreast of the threats, thinking their current solutions will protect them. Instead, they would do well to leverage several free resources and inexpensive resources available to supplement their existing solutions.
Not every organization can afford to deploy a Web and e-mail filtering appliance and might be reluctant to outsource security functions to the cloud. One approach that works well is to restrict DNS lookups from internal clients only to company-managed DNS servers and implement DNS blacklists.
The first part of this approach prevents malware from changing infected clients' DNS settings to that of a malicious DNS server that the attackers control. The second part can use well-managed blacklists that track malicious domains and are updated regularly to address current threats. Two lists I've seen work well is the ZeuS Tracker and DNS-BH Malware Domain Blocklist.
Similar to DNS blacklisting, blocking IPs of known bad actors can also assist in a layered defense approach to protecting against IP addresses that have been verified to be hosting Zeus malware and exploits, involved in botnets, or are actively attacking. In addition to DNS for known Zeus domains, the ZeuS Tracker also provides lists of IPs that can be blocked using your firewall, a Squid proxy, iptables under Linux, and the Windows hosts file.
The Emerging Threats project also hosts several lists that can be used for blocking IPs based on the Shadowserver Foundation's Command and Control Server list, DShield Top Attackers, Spamhaus.org, and known Russian Business Network hosts.
It's important to note that blacklists are not foolproof and false positives do occur, but the value in adding them as an additional layer is much greater than the potential to block a nonmalicious site.
Organizations currently using a Snort-based IDS or IPS, or Suricata, should also consider using the bleeding edge rules from the Emerging Threats project. They are updated regularly, often multiple times daily, and focus on malware unlike most commercial rulesets due to the dynamic nature of malware.
And as of this week, Emerging Threats is now offering a professional subscription, including the current malware-focused IDS rules in addition to rules based on the top-notch research they receive from Telus Security Labs.
At the end of the day, it's important to realize that no one security solution is going to fix all security problems. It takes a layered, defense in-depth approach and an active role by IT to leverage the free and inexpensive options available to them that provide bleeding edge information about malware threats.
There is no set-it-and-forget-it option for tools to combat Zeus and modern malware -- companies are learning the hard way by losing money and suffering data breaches that they have to actively fight the current threats.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>