+ All Categories
Home > Documents > Sushant Rao, Senior Product Manager Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks...

Sushant Rao, Senior Product Manager Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks...

Date post: 26-Dec-2015
Category:
Upload: richard-mcdowell
View: 212 times
Download: 0 times
Share this document with a friend
47
Sushant Rao, Senior Product Manager www.mailfrontier.com Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring
Transcript
Page 1: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

Sushant Rao,Senior Product Manager

www.mailfrontier.com

Emerging Threats:Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring

Page 2: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

2

Threats Are More Complex & Dangerous

Page 3: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

3

Typical Attacks Are Worldwide Events

Page 4: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

4

Attack Lifecycle

Page 5: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

5

Typical Approaches in Email Security

Sender ReputationMessage Content

Attachment

Page 6: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

Real Spam Attack

Page 7: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

7

Messages Scored: What’s the Right Number?

Re: Loan info - 15 years 6.0%

Re: Loan info - 15 years 6.0%

You are pre-approved

You are pre-approvedSpam that hit user’s inbox

Legitimate emailcaught by filter

Page 8: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

8

Reputation Services

Sender ID Framework Validates sender’s claimed identity

Reputation ServiceEvaluates sender’s reputation

Page 9: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

9

Content Evaluation (Bayesian)

Page 10: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

10

Community Response

Page 11: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

11

Content Analysis 80% effectiveness 0.5% false positive rate

There’s No One Way

Sender’s Identification & Reputation

• 70% effectiveness

• 1.0% false positive rate

Community Response

• 75% effectiveness

• 0.25% false positive rate

Page 12: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

12

Chained: High Effectiveness, High False Positive

70% effectiveness

1.0% false positive rate

75% effectiveness

0.25% false positive rate

80% effectiveness0.5% false positive rate

Overall 70% Effectiveness1.0% False Positive Rate

Page 13: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

13

Chained: High Effectiveness, High False Positive

70% effectiveness

1.0% false positive rate

75% effectiveness

0.25% false positive rate

80% effectiveness0.5% false positive rate

Overall 94% Effectiveness1.5% False Positive Rate

Page 14: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

14

Chained: High Effectiveness, High False Positive

70% effectiveness

1.0% false positive rate

75% effectiveness

0.25% false positive rate

80% effectiveness0.5% false positive rate

Overall 98% Effectiveness1.75% False Positive Rate (1 in 50)

Page 15: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

15

Messages Judged: Good, Spam, or Likely Spam

Overall98% Effectiveness0.0% False Positive Rate for Definite

Page 16: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

Real Virus Attack

Page 17: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

17

Page 18: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

18

http://itmanagement.earthweb.com/columns/executive_tech/article.php/3316511

Page 19: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

19

Virus Attack Timeline

Time

Page 20: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

20

Decisive Anti-Virus Technology

Page 21: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

21

Responsive Anti-Virus Technology

Page 22: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

22

Predictive Anti-Virus Technology

Page 23: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

23

Multiple Technologies Detect & Protect

Conventional Signature Protection SimulationBehavior Monitoring & Pattern Heuristics

MailFrontierTime Zero Virus

Technology

Page 24: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

24

Time Zero Virus Technologies

Deceptive File Type Detection

invoice.txt really invoice.exe

Statistical Attachment Analysis

picture.jpg .exe

Page 25: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

25

Time Zero Virus Technologies

Deceptive File Type Detection Statistical Attachment Analysis

MIME Exploit Protection Dangerous Attachment Blocking

.exe

.bat

.pif

picture.jpg .exe

resume.bat

File name is picture.jpg File type is .exe

Page 26: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

26

Statistical Attachment Analysis

069 139 139 012

.TXT.JPG .DOC .EXE

119 111 114 100

Gateway Server

069 139 139 211

invoice.txt invoice.txt

069 139 139 211

? ?

ORIs it invoice.txt? Is it invoice.exe?

Page 27: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

27

Statistical Attachment Analysis

069 139 139 012119 111 114 100

Gateway Server

069 139 139 211

invoice.txt invoice.txt

069 139 139 211

==

invoice.exe

OR

.TXT.JPG .DOC .EXE

Page 28: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

Real Phishing Attack

Page 29: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

29

Consumer Phish

Page 30: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

30

Phishing for Enterprise Information

Page 31: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

31

Phishing is Not Spam

What is the Difference between Spam and Fraud?

Spam But Fraud

How does it arrive? Sneaks in the back door. Walks in the front door.

How does it make its offer?

Looks bad, seems far-fetched.

Looks plausible, seems credible.

What is it trying to do? Tries to sell you something.

Tries to steal something from you.

Page 32: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

32

A Phishing Attack

Sending Machines Phish Web Sites

66.165.106.111

152.146.187.172

161.58.214.148

195.75.241.4

212.250.162.8

Receivers

61.152.175.161

210.114.175.226

211.23.187.151

Mary

Tomas

Andy

Tonia

George

John

Frank

Tim

Herman

Luann

Ramona

Evan

Jan

Scott

Venkat

CharliePhil

Elisa

Dom

Joe

Lana

June

Chao

Vadim

Oliver

Page 33: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

33

Phishing Protection

Page 34: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

Other Enterprise Email Threats

Page 35: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

35

Zombies – Compromised Internal Nodes

Mail Server

Enterprise Network

Internet

XOnly legitimate emails are sent

Emails from Zombiesare identified and quarantined

Page 36: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

36

Directory Harvest Attacks

Enterprise Network

Page 37: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

37

Outbound Compliance – Regulatory & Corporate

CONFIDENTIAL

Mail Server

Enterprise Network

Virus

Policy Violation

CONFIDENTIAL

Disguised Text

C*NFIDENTIAL

C*NFIDENTIALOnly legitimate emails are sent

Page 38: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

MailFrontier Gateway

Page 39: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

39

MailFrontier Cognite: End-To-End Email Attack Monitoring

Page 40: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

40

MailFrontier – Security Against All Threats

Page 41: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

41

MailFrontier – All Threats, 1 Product

Typical Mail Data Center

Mail Data Center Consolidatedwith MailFrontier Gateway

e.g. Microsoft Exchange

e.g. Microsoft Exchange

Page 42: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

42

MailFrontier: Effortless Control

Powerful Reporting Provides Quick

Insight

Page 43: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

43

MailFrontier:High Performance

Page 44: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

44

1400+ Enterprise Customers • 98% Retention

Healthcare Transportation Nonprofit

RetailEducation Real Estate

Hospitality

Financial Services

Software

Media/Publishing

Pharmaceutical

Telecommunications Manufacturing

Technology

Government

Consumer Goods Financial ServicesRetail

Media/Publishing

Consumer Goods

Page 45: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

45

Extraordinary Awards & ReviewsExtraordinary Awards & Reviews

NetworkWorld Top-Rated Enterprise Anti-Spam Software “…MailFrontier’s ASG put up some impressive results in terms of blocking spam and letting legitimate mail pass.” – September 15, 2003

Recommends MailFrontier be included on “Short List” of products evaluated for large-scale, high-performance anti-spam systems – December 20, 2004

Red Herring Top 100 Private Companies/InnovatorsRecognizing the company for its innovation and strategy – May 2004 and December 2004

CRN Recommended“MailFrontier's hands-off approach can help ease the administration burden on IT departments.” – June 7, 2004

InfoWorld Rated Excellent“MailFrontier had the easiest installation…provides lots of control to the admin…[and] provides excellent accuracy.” – September 27, 2004

IT WEEK Editor’s Choice – 5 out of 5 Stars  “MailFrontier Gateway Appliance m500 setup was easy…and took less than an hour..lt really blocks all unwanted email.” – June 6, 2005

Page 46: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

46

MailFrontier - The Leader in Email Security

Best Protection • Effortless Control • High Performance

Appliances • Software

Page 47: Sushant Rao, Senior Product Manager  Emerging Threats: Stop Spam, Virus, and Phishing Outbreaks through End-to-End Attack Monitoring.

47

Powerful Protection without Complexity

“MailFrontier offered me a solution that delivered on every front.”

-- Kristi ReeseExchange Administrator


Recommended