Endpoint

5/19/2017
11:30 AM
50%
50%

Ransomware Rocks Endpoint Security Concerns

Meanwhile, threat detection technologies are evolving that can help security teams spot incidents more efficiently.

INTEROP ITX - Las Vegas - The WannaCry attack campaign was top of mind here this week as industry experts and enterprises say that was only the beginning of ransomware threats yet to come.

"Ransomware is one of my biggest concerns and my users' knowledge about opening bad attachments," says Dan Tarnowski, IT manager at CCMA LLC. 

Tarnowski noted that while ransomware is one of his biggest concerns, his organization has been fortunate to have avoided this threat so far.

The high-profile WannaCry ransomware attack was the largest such attack to date, infecting hundreds of thousands of machines in some 150 countries. 

Last year, ransomware was a major driver of endpoint sales for the $9.5 billion market that includes several hundred endpoint security vendors from startups to major players like Symantec, McAfee, and Trend Micro, says Rob Westervelt, a security research manager at IDC.

"CIOs would say, 'why were we hit with ransomware and it wasn't detected,'" says Westervelt.

Westervelt and other security experts expect ransomware will continue to loom large as a threat to endpoint machines. Indeed, the FBI is forecasting ransomware could cost victims $1 billion a year, according to a CNN report.

Other major threats landing on the endpoint that will loom large in the future include more advanced persistent threat (APT) attacks, where an attacker gains access to the network and lays low and undetected for a long stretch of time to pilfer data. APTs are typically associated with nation-state threat groups.

APT attacks tend to target large organizations and often use social engineering in emails to lure the user to provide access via clicking on a link or downloading an attachment, says Michael Canavan, senior vice president of Kaspersky Lab North America.

"They may spoof an email that looks like a LinkedIn connection request, and the user will download malicious code onto their system and the user will not even know an APT is now on their system," Canavan says.

Not only are ransomware and other advanced threats a growing issue for the endpoint, but the rate of new iterations of these attacks and others hitting the endpoint has vastly accelerated, says Michael Spanbauer, vice president of security test and advisory for NSS Labs.

"Over the last ten years, the pace has accelerated immensely. It's like going from a Model T to driving a McLaren at 200 mph," Spanbauer says. "But the good news is innovation and security people have gotten better, too."

Threat Detection Evolution

Most ransomware attacks could be avoided with proper patching, backups, and other basic security hygeine. Meanwhile, emerging technologies for endpoint security such as machine learning could help security teams better and more quickly react to incidents and breaches, say security experts.

"We're now hearing a lot about machine learning," says IDC's Westervelt. "We're hearing about stronger threat detection engines that can improve over time with machine learning looking at files."

Machine learning is rapidly being adopted or in testing phases at organizations, with over 50% of companies big and small likely to fall into either camp in the next year, predicts Stuart McClure, CEO of Cylance, an endpoint security vendor.

Machine learning takes data sets, learns from them, and gets the visibility to detect where the threat came in from, where it is moving to, correlate with other past attacks and conduct similar action as a security analyst, for example - but much faster than a human.

Some experts consider machine learning a narrow form of artificial intelligence (AI). AI proper can determine and consider various actions it can take with the information it has gleaned, similar to the way humans think.

McClure says that roughly 80% of the companies he runs into around the world want to leverage AI in some form around the endpoint. And of this group, half of the companies want to replace traditional signature-based anti-virus technologies right away and the other half want to do it over time.

"The larger companies are strapped with so many layers of protection that it will take more time to figure out where AI fits in the stack, but mid-market to smaller enterprises with 150,000 to 200,000 nodes and below can adopt cutting-edge technology more quickly," McClure says.

IDC's Westervelt notes that although many endpoint startups have launched out of the gate with signature-free detection technology that was based more on users' behavior, many are now adding signature-based detection engines to their products.

"The vast majority of threats are known threats, so why put extra pressure on your sandbox" to test potentially malicious software based on its behavior, Westervelt says.

And in the meantime, traditional signature-based anti-virus vendors have added signature-free security software to their offerings. As a result, Westervelt says, there is less and less differentiation between new and shiny startups and the old guard.

A recent US survey of 253 small-to-mid-size IT managers and directors found that 53% noted price was the top factor in endpoint security purchase decisions, and just 21% cited ransomware in playing a role in their decision to acquire endpoint security technology, according to a survey conducted for VIPRE.

"There are a lot of good products on the street, but my issue is finding the appropriate product," says Stefan Rettig, an end-user platform consultant and attendee of Interop ITX.

"My priorities in the end-user space is threat mitigation," he says.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Now about that mortgage refinance offer from Wells Fargo .....
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3937
PUBLISHED: 2018-08-14
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability...
CVE-2018-3938
PUBLISHED: 2018-08-14
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST r...
CVE-2018-12537
PUBLISHED: 2018-08-14
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
CVE-2018-12539
PUBLISHED: 2018-08-14
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows,...
CVE-2018-3615
PUBLISHED: 2018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.