ENTERPRISE INFORMATION PROTECTION

 
Customer Support

Advanced Persistent Threat (APT) Detection, Mitigation, and Prevention

The rate and sophistication of malicious software ("malware") attacks continues to outpace the capacity for large institutions to defend themselves.  According to the latest figures from leading anti-virus (AV) software vendors, well over 30 MILLION individual pieces of malicious code were analyzed in 2010.

Today's most dangerous online threats to businesses are designed to steal their sensitive data.  They are most often purpose-built, network-specific malware that combine stealth, precision, and social engineering to both penetrate a company's perimeter and compromise systems without detection.
 
These so-called Advanced Persistent Threats (APT) describe a new class of custom malware designed to carry out stealth missions on specific corporate and classified networks.  APT are highly-sophisticated attacks which exploit user trust or system vulnerabilities to penetrate IT defenses and complete a mission undetected from inside the network, ranging from data theft to outright system destruction (e.g. Stuxnet).  Confirmed APT breaches have run the gambit of organizations with highly competitive and proprietary information:  manufacturing; high tech; oil & gas; financial; pharmaceutical; critical infrastructure and public utilities; and, of course, military & government networks.
 
What are Advanced Persistent Threats?
 
APT attacks are designed to complete a specific mission
  • Use custom-made malware ("zero day") which exploits technical vulnerabilities and/or user deception (social engineering) to compromise a machine and penetrate a specific network
  • APT code is not prevalent enough for AV and IPS vendors to deploy a signature
  • APT can be used to steal information or as a weapon

APT can compromise machines via different vectors

  • Infected website; O/S or application vulnerability, infected USB, targeted social engineering (i.e. "spear phishing"), DNS poisoning, etc.

APT are designed to gain privileged administrator credentials

  • Allows an "outsider" to become a privileged insider
  • This creates a stealth "WikiLeaks"-type risk, but with the ability to evolve, obfuscate, and communicate securely with an external "master"

A single APT attack can include multiple payloads, each with their own "objective", to complete a mission:

  • Launch a coordinated stealth operation from inside the network until the mission is accomplished
  • A mission may last a day...or a year
  • APT code is often designed to erase itself and/or only exist in memory to hamper post-incident investigations
 
APT Requires Defense-in-Depth
The most effective defense against APT attacks requires a unified and layered security approach that creates "air gaps" at different stages of an attack which challenge the malware's adaptability and stealth in ways it was not designed to circumvent.  Digital Guardian is a data-centric technology platform for Enterprise Information Protection (EIP) that integrates endpoint and network agents into a coordinated and multi-layered sentry to detect and stop one-off malware designed to steal a particular company's sensitive data.
 
Digital Guardian uses several policy-based technologies to detect and stop a potential attack, even if the code or methodology has not been previously seen "in the wild".  As workstations are often the most vulnerable entry points for APT, Digital Guardian endpoint agents use a powerful combination of technologies which provide early warning and data-level access controls to thwart APT at first contact.  These capabilities include advanced memory scanning and forensics to detect and alert users and security managers to suspicious obfuscated activities at the system memory and kernel levels; identity-based file encryption to prevent unauthorized users from accessing sensitive files; and application monitoring, alerting and blocking to identify and block the launch of dangerous executables.
 
Digital Guardian network agents also provide session-level analysis of incoming and outgoing traffic to detect suspicious activities.  As APT attacks often use obfuscation, encrypted messaging, and vulnerabilities to pass by perimeter defenses, Digital Guardian network agents provide deep session inspection at line speed across all ports and protocols that can detect and block events like connections from suspicious IP addresses, encrypted traffic, application port-hopping, and can deconstruct payloads to see embedded content (e.g. JavaScript within a PDF file) which could be used as an attack vector.
 
Digital Guardian provides a comprehensive and integrated defense-in-depth security model for APT that uses network and endpoint agents that can detect abnormal events by correlating endpoint and network policy alerts and other suspicious activities to provide an enterprise-wide overview of threatening activity that can be monitored and mitigated by a common management interface.  When an APT event is confirmed, Digital Guardian agents can then enforce data-level policy autonomously at different stages of an attack inside or outside the network.

How Digital Guardian Protects Sensitive Data from APT Attacks

APT attacks often have multiple stages; each with its own tactical mission.  Many APT are designed to compromise a system through an application or O/S vulnerability and launch in memory as a “rootkit” with the ability to obfuscate itself, beyond detection by normal IT security solutions like AV or intrusion detection.  With only a single infected machine APT can spread themselves quickly across the network unnoticed, quietly infecting other systems until it gains the intelligence (e.g. credentials to servers with sensitive information) to complete its mission. 

However, in order for APT to steal data undetected it must take several predictable steps on which Digital Guardian agents and policies can be focused:

Stage 1: Initial breach
Custom malware uses deceptive email, vulnerability, or infected media to gain administrative control of a machine and launch its mission to steal a specific company’s sensitive data (e.g. intellectual property).

How Digital Guardian helps:

  • Digital Guardian endpoint agents forensically scan memory to detects suspicious code; triggers a prompt and/or alert
  • Digital Guardian endpoint agents apply application controls to prevent APT code launch
  • Digital Guardian network agent flags suspicious inbound/outbound network traffic
 
Stage 2: Establish external command & control
Once a breach occurs, an APT attack is typically designed to spread to other endpoints:
  • Infects other machines to find credentials to penetrate more secure systems
  • Establishes a secure command/control infrastructure
  • Receives new code or instructions from APT source

How Digital Guardian helps:

  • Digital Guardian endpoint or network agents detect suspicious or unauthorized connections to other machines or external addresses
  • Digital Guardian endpoint agents detect suspicious code execution in memory
  • Digital Guardian can take preventive actions such as block suspicious application launches or quarantine a machine with an elevated risk profile based on system, memory, or network activity

Stage 3: Secondary infections - Identify target machines & compromise
Once the target servers are identified the malware uses acquired credentials to breach the server(s) storing sensitive data.

How Digital Guardian helps:

  • Digital Guardian network agent can alert or block suspicious or unauthorized traffic to a secure data center
  • Digital Guardian server agents can block access to sensitive data by user or machine identity
  • Digital Guardian servers can apply application whitelists to block unknown code, OR prevent a privileged admin from accessing files (i.e. identity-based file encryption)

Stage 4: Exfiltration of data to external site
Once breached, APT code attempts to transmit stolen data outside the network via secure connection.
How Digital Guardian helps:

  • Digital Guardian network agents can detect and block unauthorized encrypted traffic
  • Digital Guardian can apply identity-based file encryption accessible only by authorized internal users
  • Digital Guardian network agents use continuously updated intelligence feeds to detect and automatically block connections to/from known malicious web addresses
Contact Verdasys
P.(781) 788-8180
F.(781) 788-8188
Info@Verdasys.com

SOLUTIONS | PRODUCTS | SERVICES | ALLIANCES | NEWS & EVENTS | ABOUT US | RESOURCES | CONTACT US | CUSTOMER SUPPORT |
© 2012 VERDASYS. ALL RIGHTS RESERVED. TERMS OF USE AND PRIVACY POLICY