How To Detect And Root Out Sophisticated Malware
New report offers insights on excising that hard-to-detect malware
Malware 'Licensing' Could Stymie Automated Analysis
The use of encryption and digital-rights management techniques by the authors of malicious code could make automated analysis of malware take longer and require human intervention more often
SCADA/Smart-Grid Vendor Adopts Microsoft's Secure Software Development Program
Meanwhile, utilities lag when it comes to cyberattack preparedness and risk management at the executive and board level
Cyberspies Target Victims Via 'Strategic' Drive-by Website Attacks
Cyberespionage attackers more and more are injecting specific, legitimate websites with malware in hopes of snaring victims with common interests -- most recently, human rights organizations
Targeted Attack Infiltrates At Least 20 Companies
Attackers conducted a sustained espionage campaign against a score of private- and public-sector targets with links to policies of interest to China
IBM Profiles The New CSO, Security Exec
Infosec leaders say their role in the business is maturing, with roughly three-fourths now doing more than just responding to breaches and handling compliance, a new survey reveals
Advanced Attacks Call For New Defenses
With conventional wisdom now that 'advanced attacks happen,' has the time come to create the next-generation sandbox or other containment method?
Iranian Cyberthreat To U.S. A Growing Concern
'Seismic shift' in Iran's cyberstrategy, but the U.S. is lacking an official strategy for response and offense, experts tell Congress
Microsoft: Conficker Worm Remains 'Ongoing' Threat
Three-year-old 'dead' Windows worm infection is still spreading -- mainly via weak or stolen passwords, new Microsoft report says
Security Teams Need Better Intel, More Offense
Adversaries go through five steps to prepare and execute an attack, but defenders only react to the last two steps. It's time for defenders to add intelligence gathering, counter intel, and even offense to the game, security experts say
Iran: Oil Industry Hit By Malware Attack
Deja vu all over again as Iranian government-owned systems reportedly targeted by a 'worm'
Apple Mac Attack Began With Infected WordPress Sites
Meanwhile, researchers await a possible Flashback comeback by the botnet operators
Anonymous Must Evolve Or Break Down, Say Researchers
The movement started as an Internet meme and grew into a complex and chaotic community. Security experts argue that the Anonymous brand is now in danger of imploding
How Did They Get In? A Guide To Tracking Down The Source Of An APT
Advanced persistent threats can be complex and sophisticated. Here are some tips on how to analyze them
DOE Lab Releases Open-Source Attack Intelligence Tool
Pacific Northwest National Laboratory offers up, continues to build out a tool that drills down into the processes and apps employed by the bad guys
Botnet Takedowns Can Incur Collateral Damage
Microsoft Zeus botnet case demonstrates risks, challenges associated with takedowns when multiple groups are tracking the same botnet
Controversy Erupts Over Microsoft's Recent Takedown Of A Zeus Botnet
Dutch researchers accuse Microsoft of mishandling the recent Zeus botnet takedown and hurting other investigations- - but others defend Microsoft's operation as thorough
Malware Encryption Efforts Mixed, But Getting Stronger
Russian botnets mostly use crypto, Chinese attacks mostly don't, but attack analysis finds that the bad guys are increasingly using better encryption
Zeus Trojan Targets Online Payroll Services Providers
New attack could be used for paying money mules from victimized corporate accounts
It's (Already) Baaack: Kelihos Botnet Rebounds With New Variant
Botnet hunters debate whether Kelihos/Hlux operators can reclaim rescued bots
China Hacked RSA, U.S. Official Says
And RSA official responds to Gen. Keith Alexander's telling Congress this week that Chinese attackers were behind the SecurID breach last year
Malware To Increasingly Abuse DNS?
Many companies do not scrutinize their domain-name service traffic, leaving an opening for malware to communicate using the protocol
Microsoft, Financial Partners Seize Servers Used In Zeus Botnets
Most Zeus operations still untouched, but a noticeable dip in Zeus botnet activity spotted by one botnet-monitoring organization
New Botnet Emanates From Republic Of Georgia, Researchers Say
Win32/Georbot steals documents, hides from anti-malware scanners
Duqu Alive And Well: New Variant Found In Iran
Researchers at Symantec dissect part of new, retooled version of the reconnaissance-gathering malware
Rooting Out Sophisticated Malware
As malware gets increasingly sophisticated, so, too, must the technology and strategies we use to detect and eradicate it (or, better yet, stop it before it ever makes it onto network systems). There is no one product or product category that can do the job alone. Instead, security professionals must become familiar with--and adept at using--a combination of technologies. Security pros must also become skilled at connecting the dots among sometimes innocuous-seeming events to root out trouble. In this report, we examine the tools, technologies and strategies that can ease some of the burden.
How Did They Get In? A Guide to Tracking Down The Source of an APT
If you think that your organization hasn't been affected by an advanced persistent threat, you probably haven't looked hard enough. Identifying that your organization is under attack is difficult enough; determining the scope of infiltration and damage presents a whole new level of challenge. To effectively protect against APTs, security pros will need to employ an arsenal of tools in a coordinated fashion, as well as develop new understandings of and approaches to system and data exploits. Here's a short and simple guide to this challenge.
Detecting and Defending Against Advanced Persistent Threats
APTs are a growing problem for enterprises big and small. Protecting your organization from these targeted threats
requires constant vigilance, ongoing employee training and a concerted effort to align security systems to address
every phase of an APT. Companies also need to develop a remediation and response plan if, despite best efforts, defenses are breached.
Other reports from the Advanced Threats Tech Center:
| Sponsored by: |
MOBILE SECURITY - Mapping an Ecosystem of Risk
This white paper highlights the various considerations for defending mobile applications-from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
Software Security Delivered in the Cloud
This Solution Guide details the automated, turnkey service that requires no special security assessment expertise. It details HP's market-leading static and dynamic analysis technologies that help organizations worldwide gain insight into the security state of their essential business applications.
SANS Mobility/BYOD Security Survey
This survey, which includes input from more than 500 IT professionals, explores how organizations are managing risk around their end user mobile devices as well as what level of policies and controls enterprises have around mobile usage.
Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.
A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.
MORE NEWSFEED >>>