Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/11/2019
08:00 AM
Connect Directly
Twitter
RSS
E-Mail
100%
0%

Persistent Threats Can Last Inside SMB Networks for Years

The average dwell time for riskware can be as much as 869 days.

Dwell time — the amount of time a threat spends inside of a network before an organization discovers and removes it — has become a significant problem for small and midsize businesses (SMBs), according to a report released today by Infocyte.

The report, based on more than 339,000 accounts and behavioral logs for malicious activity, focuses on companies that have between 99 and 5,000 employees and annual revenue of up to $1 billion.

Dwell time for attacks with ransomware averaged 43 days, the report points out. On the other hand, average dwell time for all other persistent threats (non-ransomware) averaged 798 days, while dwell time for riskware – defined as unwanted applications, Web trackers, and adware – averaged a whopping 869 days.

According to Chris Gerritz, co-founder and chief product officer at Infocyte, 72% of SMBs had riskware and unwanted applications in their networks that took longer than 90 days to remove. While they were generally lower risk issues, the bigger takeaway is networks that fail to control riskware typically have a lower readiness to respond to high-priority threats when they are uncovered.

"We found that 60% of malware is identified by [antivirus] vendors using a generic signature – it doesn't specify what the issue is – so that's also why SMBs can't always understand the difference between high-priority and low-priority risks," Gerritz says.

The Infocyte report also explains why the dwell times of some of the persistent threats and riskware are well more than two years. For example, some of the active infections residing on the inspected systems are configured to sinkholed domains and pose no immediate threat, it says.

That said, one family of infections that researchers found traced back as long as a decade ago. While they didn’t pose a threat after a series of botnet operators were arrested in subsequent years, "it’s still surprising to find the malware still active on what appear to be protected endpoints so many years later," Gerritz says.

If continuous monitoring is not an option, Gerritz recommends that SMBs once a year bring in a third party to perform a "compromise assessment" at the same time they conduct a vulnerability assessment and pen tests.

"If companies can't afford threat analysis, they should at least get these tests done once a year," he says, so security pros can check for active malware with long dwell times that may have been sitting active in the network for many years.

Aaron Sherrill, a senior analyst at 451 Research, says Infocyte's research brings to light how most small companies lack standard security controls.

"They may not have updated technology, the signatures are not updated, the alerts and events are often ignored, or maybe they just don't have the bandwidth to do it all," Sherrill says. If companies can afford them, compromise assessments should be more than once-a-year events.

"Too often companies do these assessments as a checkbox item and they forget about it," Sherrill says. "Many of these threats are very sophisticated and are engineered not to be detected. Companies are at risk every minute of every day. What they really need is to have their networks continuously monitored."

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...