Free Newsletter
Register for our Free Newsletters
Access Control
Deutsche Zone (German Zone)
Education, Training and Professional Services
Government Programmes
Guarding, Equipment and Enforcement
Industrial Computing Security
IT Security
Physical Security
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec

Signature based protection not enough for new wave of malware

Tier-3 : 14 May, 2008  (Technical Article)
Malicious code that changes signature frequently requires behavioural analysis to prevent it spreading according to Tier-3
Geoff Sweeney, CTO of Tier-3, the behavioural analysis IT security specialist, has echoed remarks made by the head of the Swiss cybercrime operation.

In a media interview late last week, Marc Henauer, head of the cybercrime decision with the Swiss Justice and Police Department, said that viruses and other malware now have the capability to change their signature every few hours.

This, he said, means that the attackers are often one step ahead of protection software.

According to Sweeney, Henauer's recommendation that companies must change their approach to data security because of this is something that Tier-3 has been telling its clients for some time.

'Self changing code designed to dynamically evade recognition is a fact of life, it automatically adapts to the anti-spam and anti-malware engines that it encounters. Unfortunately the knowhow and construction kits used to create this shape shifting threat are now readily available and are unleashing a wave of shape shifting malware based on social engineering techniques. Highly targeted emails containing personalised information and shape shifting trojan attachments are the latest development and each positive infection increases the 'hit rate' for the next wave of emails sent out by the self learning automated engines used by sophisticated attackers', continued Sweeney.

'The days when a single IT security application is sufficient to protect an IT system are long gone. To defend against this onslaught a non rules based monitoring process must be set up that covers all ingress and egress points covering SMTP, DNS, HTTP(s), IM, etc. once this is in place defence against shape shifting threats becomes possible as well as the removal of any previously established covert data leakage channels that will be revealed and dealt with', Sweeney said.

Bookmark and Share
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
   © 2012
Netgains Logo