+ All Categories
Home > Documents > Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at...

Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at...

Date post: 02-Aug-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
46
Stopping the Threat at the Door Matt Pannebaker Sales Engineer – Ohio and Kentucky Today
Transcript
Page 1: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Stoppingthe Threatat the Door

Matt PannebakerSales Engineer – Ohio and Kentucky

Today

Page 2: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

2

Page 3: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Top Threats in the US

3

Exploits44%

Ransomware35%

Generic Malware

9%

Malvertising6%

Crpytocoin Generator

6%

Phishingo 93% of phishing emails have a

ransomware payload (CSO Online)

Exploitso Industrialized attacks

o Flash, Downloader, JS redirect, Malvertising

Ransomwareo Dropper, Phish, Shortcut, Doc Macro

o Successful attacker can earn up to $394,000 in a single month

Page 4: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Top Threats

4

Secure StateCleveland, Ohio

Page 5: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

HD Fishing

5

Page 6: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

HD Phishing

6

Page 7: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Specifically & Locally Targeted

7

Page 8: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

8

Tail-tell signs of Phishing…

It just doesn’t look right

Generic salutations

Requests for sensitive data

Specific information on you

Scare tactics

Poor grammar or spelling

Sense of urgency

“You’ve won the grand prize!”

“Verify your account.”

Cybersquatting

Page 9: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

9

Changing our minds about the

how’s and why’s of hackers & malware…

Page 10: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Pavel Vrublevsky

10

Page 11: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Exploits as a Service

Initial Request

Victims

Exploit Kit Customers Redirection

MaliciousPayloads

Stats

Landing Page

Tor

Exploit Kit Admin

Exploits

Payloads

Get Current Domain

Get Stats

Update payloads

Management Panel Malware DistributionServers

Gateway Servers

Page 12: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

THIRD PARTY

Malvertising Threat Chain

AD NETWORK

RTB

Page 13: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

No site is immune…

Page 14: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

14

Who Likes Extortion?

Page 15: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Ransomware Is Hitting the Headlines…

15

Page 16: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

16

Page 17: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Precast Concrete

~12bn

…And Keeps Growing…

17

• Estimated to be a $1 Billion a year industry by the end of 2016 (FBI)

• Criminals are dedicated and professional – even setting up customer care teams to secure payment

Page 18: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Document malware

18

Page 19: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Ransomware Prevalence

CryptoWall AU, GB, US, CA, DE, FR

TorrentLocker AU, GB, IT, ES

CTBLocker EU, NA

TeslaCrypt UK, US, CA, SG, TH

Page 20: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Targeted Ransomware

Page 21: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Malware with fancy names: Fantom, Mamba & Odin

• No ransom & potentially unrecoverable

• DiskCryptor instead of File Encryption

• Permission to make changes to your disk

• Reboots and installs as DefragmentationService

• Dcrypt using password in log_file.txt

• Evolution of Locky, Zepto

• Email with ZIP attachment (2 files)

• JavaScript that poses as a Text file

• Localized “Buy” page

• View File Name Extensions

• Unprofessional but does the job

• Reused a ransomware framework

• Poses as a Windows Critical Updateo Critical Update (32 bit)o Windows Form Application5

• Fake update screen

• Attempt to wipe out backup copies

Page 22: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Evolution of your industry…

24

Page 23: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

MelissaVirus

1999

$1.2B

Love LetterWorm

$15B

1998

$2.3B

2007

$800M

2014

Ransomware

$1.1B

2016+

FinFischerSpyware

2003

$780M

Exploit as aService

$500M

2015

Traditional Malware Advanced Threats

The Evolution of ThreatsFrom Malware to Exploits

Page 24: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Traditional Malware Advanced Threats

The Evolution of SecurityFrom Anti-Malware to Anti-Exploit

Exposure Prevention

URL BlockingWeb/App/Dev Ctrl

Download Rep

Pre-Exec Analytics

Generic MatchingHeuristicsCore Rules

File Scanning

Known MalwareMalware Bits

Run-Time

Behavior AnalyticsRuntime Behavior

Exploit Detection

Technique Identification

Page 25: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Intercepting NeXt Gen Threats…

Page 26: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Introducing…

Page 27: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Intercepting Exploits

Exploit Prevention• Monitors processes for attempted use of

exploit techniques e.g Buffer overflow, code injection, stack pivot and others

• Blocks when technique is attempted

• Malware is prevented from leveraging vulnerabilities

?

Page 28: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

31

Page 29: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Intercepting Ransomware with CryptoGuard

Monitor File Access

• If suspicious file changes are detected, file copies are created

• Cryptography events

Attack Detected

• Malicious process is stopped and we investigate the process history

Rollback Initiated

• Original files restored

• Malicious files removed

Forensic Visibility

• User message

• Admin alert

• Root cause analysis details available

Page 30: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Sophos CleanMalware Removal. Forensic-Level Cleanup. Second Opinion

• 100% Automated with Intercept X• Also available as a standalone Forensic Clean Utility and On-Premise Managed AV

Removes Threats• Deep System Inspection

• Removes Malware Remnants

• Full Quarantine / Removal

• Effective Breach Remediation

On-Demand Assessment

• Identifies Risky Files / Processes

• Constantly Refreshed Database

• Provides Additional Confidence

• Command-Line Capable

Page 31: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Root Cause AnalyticsUnderstanding the Who, What, When, Where, Why and How

34

Page 32: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats
Page 33: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

36

Page 34: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Why Should You Worry About Your Mobile Devices?

37

Users want to access everything, from anywhere, all the time

Not managing mobile devices means flying blind, with zero visibility

Users find a way to access business resources on unsecured devices

Data breaches involving smartphones or tablets

more than doubled in 2015 (1)

2x of large organizations have had a security or

data breach involving smartphones or tablets in 2015 (1)

15%

1) HM Gov’t, Information Security Breaches Survey 2015

More than 200,000phones are left in London Taxis each year!

Page 35: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

38

How Mobile Devices are Lost

Left in Public Space Stolen at resturant Taken from House or Car

Taken at nightclub Pickpocketed Stolen off the street

Page 36: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Containers – Separate Business and Personal Data

39

PERSONALBUSINESS

Page 37: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Should you worry about mobile malware?

40

Page 38: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Potentially Unwanted Apps (PUA) vs Malware

41

Malware

Not entirely honest about its intentions

Often misuses your resources, leaves you with hidden costs

“Gateway drug”

PUA

A weapon, not a fun tool, or a prank

Steals your data for money

Accesses data or resources with the intent to do harm

You pay for what you get…

Page 39: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

42

Page 40: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

43

0

200,000

400,000

600,000

800,000

1,000,000

1,200,000

1,400,000

1,600,000

2012 2013 2014 2015 2016 2017 (est)

Mobile Threats Are Real…

Source: SophosLabs, 2017

Android Malware

0

500,000

1,000,000

1,500,000

2,000,000

2,500,000

3,000,000

3,500,000

2012 2013 2014 2015 2016 2017 (est)

Potentially Unwanted Applications

Page 41: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

44

What about ransomware?

Source: SophosLabs, 2017

0

20,000

40,000

60,000

80,000

100,000

120,000

Android ransomware 2015-2017

“In September 2017 alone, 30.37% of malicious Android malware processed by SophosLabs was ransomware”

Page 42: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Threats on Google Play Doubled

45

Millions of devices infected

Many apps with 100,000-500,000

installations

Page 43: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Sophos Security Best Practices and Recommendations

46

• Run an anti-malware app – Sophos Mobile Security for Android is FREE, or can be managed in Sophos Central

• Stick to the official app stores, not perfect but…

• Avoid low reputation apps – think before installing

• Make sure your device’s OS is up to date (if you can…)

• If in doubt about your network, use VPN or use cellular/mobile data

• Manage your mobile devices with Sophos Mobile

• Configure Mobile Management for Securityo Jailbreak/Rooting detectiono Version check/enforce upgradeso Restrict devices and remove unneeded features if possible

Page 44: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Sophos Homehome.sophos.com

Manage 10 Windows / Mac Computers

Same Great Sophos Engine

Web Content Filtering

Page 45: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

53

Award-winning computer security news

Page 46: Stopping the Threat at the Door - Ohio Precast Concrete Association · 2018-03-26 · the Threat at the Door Matt Pannebaker Sales Engineer –Ohio and Kentucky Today. 2. Top Threats

Thank You


Recommended