How to Defend Against Advanced Malware Attacks

788 views
β€’
June 21, 2013
by
RSAC Cybersecurity
YouTube video player
How to Defend Against Advanced Malware Attacks

TL;DR

Advanced malware requires defenses that can detect malicious behavior rather than relying only on known signatures or brief sandbox observations. Attackers evade traditional controls through altered code, coordinated harmless-looking files, human-activity checks, and delayed execution, while spear phishing, compromised websites, and weaponized files provide effective paths into targeted organizations.

Transcript

Good morning. Thank you for attending this session. Um, it's interesting to present at the same time that the Secretary of Defense, Hagel, was visiting Singapore because he talked a lot about cybersecurity issues. He also talked a lot about, uh, issues with, uh, specifically with, with China. Uh, I think that's important, and those issues are certa... Read More

Key Insights

  • Advanced malware is a global security problem rather than an issue confined to China and the United States. Command-and-control infrastructure appears across North America, Europe, Asia, and nearly all connected countries, so organizations must treat the threat landscape as geographically distributed.
  • Intellectual property is a major target because technology, innovation, and intangible assets contribute heavily to economic value. Companies, governments, and defense organizations possessing useful information can attract attackers seeking commercial, political, military, or strategic advantages.
  • Spear phishing is an important infection vector because attackers can direct tailored messages toward selected people or organizations. Its growth contrasts with falling general spam levels, suggesting that focused attempts provide attackers with greater value than broad, indiscriminate distribution.
  • Watering-hole attacks work by compromising websites that attract people sharing a technical, religious, political, or other common interest. Visitors can then become infected, allowing attackers to observe their activity, collect information, or establish access through a site the targets already trust.
  • Weaponized files are a distinct delivery path because malicious content can be placed on file servers or embedded within files that users access. The file itself becomes the attack mechanism, extending the threat beyond suspicious email messages and compromised public websites.
  • Evasion is a central priority for malware authors because traditional antivirus and firewall-based inspection may fail to recognize new or carefully designed attacks. Small code changes can defeat signature matching, while environment-aware behavior can conceal malicious functions during automated analysis.
  • Coordinated malware components can appear harmless when examined separately but become malicious after reaching the same system. This approach weakens defenses that evaluate each file in isolation and demonstrates why complete activity and interactions must be considered when assessing suspicious content.
  • Delayed and human-aware execution can help malware avoid sandbox detection. Some malware activates only when mouse movement indicates human use, while other malware remains silent until a specified time, allowing it to pass through defenses before performing its intended actions.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why are advanced malware attacks considered a global problem?

Advanced malware attacks are considered global because command-and-control servers are distributed across North America, Europe, Asia, and nearly all connected countries. A country may participate knowingly or simply host compromised infrastructure. The presentation therefore rejects the idea that cyberattacks are only a China and United States issue, pointing instead to broad activity connected with commercial interests, governments, defense organizations, and regional conflicts.

Q: Why does intellectual property attract malware attacks?

Intellectual property attracts attackers because technology, innovation, and other intangible assets account for much of an organization's economic value. Rapid growth in patent filings illustrates the increasing importance of ideas and technical knowledge. Any company or country possessing useful intellectual property, sensitive government material, or defense information can interest another party seeking economic, political, military, or strategic advantage.

Q: How does spear phishing deliver advanced malware?

Spear phishing delivers malware through targeted messages aimed at particular people or organizations. Unlike broad spam campaigns, these attempts focus on recipients whose access or information may be valuable. The presentation notes that spear phishing expanded even while overall spam declined sharply, indicating that attackers continued using it because a carefully directed message can provide an effective route into a targeted environment.

Q: What is a watering-hole malware attack?

A watering-hole attack compromises a website that brings together people with a shared interest, such as a technical, religious, or political topic. Attackers place malicious content on that site, and visitors can become infected when they access it. The resulting malware may let the attacker monitor activity, collect valuable information, or communicate with command-and-control infrastructure for further instructions.

Q: How do weaponized files compromise an organization?

Weaponized files compromise an organization by carrying malicious content into systems through documents or files stored on servers and other shared locations. When a person accesses the affected file, the file itself becomes the infection mechanism. This delivery method means defenders must watch more than email links and websites, since ordinary-looking content inside the organization's file environment may also carry an attack.

Q: Why do traditional antivirus defenses miss new malware?

Traditional antivirus defenses can miss new malware because they often depend on recognizing known malicious code, while attackers deliberately modify code to evade detection. The presentation cites a study finding that antivirus stopped only a small share of brand-new malware. Firewall sandboxes can also be bypassed when malicious behavior is concealed, divided among files, triggered by human activity, or delayed.

Q: How can malware evade sandbox analysis?

Malware can evade sandbox analysis by checking whether its environment resembles a real person's computer. One example activates only when it detects mouse movement, treating that activity as evidence of human use. Another divides an attack among several files that appear harmless individually but become malicious together. Delayed execution also lets malware remain inactive throughout a limited observation period.

Q: Why is advanced malware economically difficult to defend against?

Advanced malware is economically difficult to defend against because attackers can obtain exploit tools for far less than defenders may spend investigating a successful breach. The presentation contrasts the comparatively low cost of an exploit kit with the much larger expense of forensic analysis. This imbalance makes offensive activity accessible while forcing affected organizations to devote substantial resources to understanding infections and their consequences.

Summary & Key Takeaways

  • Advanced malware is presented as a global problem driven partly by the growing economic importance of intellectual property and other intangible assets. Organizations possessing valuable research, technology, government information, or defense capabilities can become targets. Regional conflicts further demonstrate that advanced attacks are not limited to a single rivalry or pair of countries.

  • Attackers commonly deliver malware through targeted spear phishing, compromised watering-hole websites, and weaponized files. Traditional defenses often miss these infections because malware developers prioritize evasion. Techniques include changing code to avoid signatures, distributing malicious behavior across individually harmless files, requiring mouse movement before activation, and delaying execution until a predetermined time.

  • The malware economy strongly favors attackers because offensive tools can be far less costly than forensic work following a breach. Command-and-control infrastructure also spans nearly the entire connected world, showing that systems in many countries can participate knowingly or unknowingly. Effective protection therefore requires visibility into infections, callbacks, and evasive behavior across multiple channels.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š