Categories: SecurityWorkspace

Advanced Attacks On The Rise For Larger Companies

Malware is increasingly being used as advanced persistent threat attacks against enterprises, according to the latest quarterly report from Cisco.

There were 287,298 “unique malware encounters” in June 2011, double what was found in March, according to a Global Threat Report from Cisco Security Intelligence Operations released on 1 August. Since the beginning of 2011, unique malware encounters have nearly quadrupled, Cisco said.

Malware evolution

In the report, Cisco researchers did not restrict a malware encounter to just malware infecting a single system. It can also include incidents when a system was initially infected by a basic downloader, which analysed the system and downloaded even more sophisticated data collecting malware.

“Malware has evolved along with the Internet and is now the tool of choice for would-be attackers,” wrote Gavin Reid, manager of the computer Security Incident Response Team at Cisco.

Cyber-attackers rely on malware to “remain surreptitious” so that they can continue to remotely manipulate a system while remaining virtually invisible, Reid said. Detecting APTs like unique malware is not an easy task because there is no “silver bullet” such as a software signature that would identify them on a network, he said.

“If anyone attempts to sell your organisation a hardware or software solution for APTs, they either don’t understand APTs, don’t really understand how computers work, or are lying, or possibly all three,” Reid said.

On average, enterprises had 335 malware encounters per month, Cisco researchers found. March had the highest malware activity during the second quarter, with enterprises seeing an average 455 pieces of malware, followed by an average 453 encounters in April.

The majority of the “malware encounters” occured over the web, the report said, as employees surf the web and land on malicious sites. Despite the increase in encounters, the number of unique malware hosts and unique IP addresses remained relatively consistent between March 2011 and June 2011, according to the report.

Larger companies targeted

Companies with between 5,000 and 10,000 employees and more than 25,000 employees “experienced significantly higher malware encounters” compared to other smaller companies. Companies in the pharmaceutical, chemical, energy and oil sectors continued to be at highest risk of web malware, according to Cisco, although transportation, agriculture, mining and education were also at high risk.

Organisations can improve their abilities to detect and respond to APTs if they have some form of deep packet inspection technology that cover all the important points in the network where traffic is entering or leaving the enterprise. The ability to quickly query network connections or flows through NetFlow or a similar service will also help security managers detect malicious activity.

The organisation should also be able to produce, collect and query logs such as host logs, proxies and authentication and attribution logs. “The more the better,” Reid wrote.

Organisations that have not seen any APT attacks should be concerned, according to Reid, as it doesn’t mean that attackers haven’t targeted it or that the security defenses are working. What’s more likely is that the defenses aren’t picking up on the attack itself. “If you have something of interest and you’re not seeing APT attacks in your organisation, you may need to rethink your detection capabilities,” Reid said.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Google Ordered To Pay $43m By Australian Court

Search engine Google fined $43 million by Australian court for tracking Android users location data…

2 days ago

Hacker Touts Data Sale Of 48.5m Users Of Covid App – Report

Personal data of 48.5 million Chinese citizens who used Shanghai's Covid App, is being offered…

2 days ago

Facebook Tests Default End-to-End Encryption For Messenger

Privacy move. Platform tests secure storage of people's chats on Messenger, in a move sure…

3 days ago

UK’s CMA Begins Probe Of Viasat Acquisition Of Inmarsat

British competition regulator the CMA, begins phase one investigation of $7.3 billion merger between Inmarsat…

3 days ago

Cisco Admits ‘Security Incident’ After Breach Of Corporate Network

Yanluowang ransomware hackers claim credit for compromise of Cisco's corporate network in May, while Cisco…

3 days ago

Google Seeks To Shame Apple Over RCS Refusal

Good luck convincing Tim. Google begins publicity campaign to pressure Aple into adopting the cross…

3 days ago