US GAO Report Highlights Incident Response Shortcomings

On May 30th, 2014, the US Government Accountability Office (GAO) released a report titled “Information Security: Agencies Need to Improve Cyber Incident Response Practices.” GAO conducted its research by randomly selecting six government agencies, then selecting a statistically significant number of incident reports (40 from each organization), documented during 2012. GAO then evaluated how the agencies performed, based on the reports. GAO compared the documented incident response actions to requirements set by the Federal Information Security Management Act of 2002 (FISMA) and National Institute of Standards and Technology (NIST) Special Publication 800-61, Computer Security Incident Handling Guide. The results were surprising and I will explain the significance of several excerpts in this post.

First, “agencies had recorded actions to halt the spread of, or otherwise limit, the damage caused by an incident in about 75 percent of incidents government-wide. However, agencies did not demonstrate such actions for about 25 percent of incidents government-wide.”

This comment references the need to contain an intrusion. If a government agency fails to completely contain an intrusion, any gaps leave the adversary freedom of maneuver. He can exploit the containment failure to proliferate to other systems and remain in control of an organization’s systems. Anything less than 100% containment is essentially 0% containment.

Second, “for about 77 percent of incidents government-wide, the agencies had identified and eliminated the remaining elements of the incident. However, agencies did not demonstrate that they had effectively eradicated incidents in about 23 percent of incidents.”

This comment references the need to remove an intruder from a compromised organization. Similar to the need for 100% containment, one must also achieve 100% removal in order to completely frustrate the adversary. If an adversary retains access to even one system, he can rebuild his position and retake control of the victim.

Third, “agencies returned their systems to an operationally ready state for about 81 percent of incidents government-wide. However, they had not consistently documented remedial actions on whether they had taken steps to prevent an incident from reoccurring. Specifically, agencies did not demonstrate that they had acted to prevent an incident from reoccurring in about 49 percent of incidents government-wide.”

This comment describes the need to learn from intrusions and implement remediation. If a victim fails to make the environment tougher for the adversary, the intruder will likely return using the same techniques that he utilized to first gain access.

Finally, a search of the entire GAO report for the word “strategy” produced zero hits. Beyond being disappointed by the three excerpts I highlighted above, I am dismayed to not hear GAO discuss the need for a security strategy for organizations. Incident response is not a technical action. IR should be part of a business process, done as part of an operation that implements a strategy understood and approved by the highest levels of management. Furthermore, the GAO report did not really evaluate the consequences of the three documented failures and the lack of concrete security strategies. Had GAO taken that step, they might have concluded that the agencies continue to face severe security challenges.

BrutPOS From a Security Practioner’s Perspective

Today, FireEye Labs posted a technical blog on the malware for a botnet that we call BrutPOS. With a lot of attention focused on data breaches in retail, BrutPOS gives us a chance to look retrospectively on the state of retail security.

The popular phrase “a chain is only as strong as its weakest link” has great relevance in the information security world. There are a large number of ways to compromise a business network, yet attackers are quite successful in this endeavor using fairly pedestrian methods of attack. This raises the important question: Why is this the case? Part of the answer lies in the fact that attackers don’t feel a great need to use particularly sophisticated attack methods. In other words, if attackers can succeed using fairly elementary attack methods, why should they work any harder? Let’s examine this principle through the example of the BrutPOS malware.

Most businesses use Microsoft’s Remote Desktop Protocol (RDP) as an integral part of their day-to-day business operations. RDP allows for remote login to Windows systems. This has many legitimate uses, such as an administrator logging on to a system remotely to update a software package. Like any legitimate service, attackers are also quite happy to leverage RDP for their own nefarious purposes. An example of this is the BrutPOS malware, the analysis of which was detailed in a FireEye blog post today. At a high level, the purpose of the BrutPOS malware is to compromise Point of Sale (POS) terminals through the use of the remote desktop protocol (RDP). The malware aims to steal payment card information from those compromised POS terminals. There is no need for the attackers to write a sophisticated protocol for their malware to log on to systems remotely – the RDP works quite nicely.

There are many approaches an organization can take to better manage the risk presented in the BrutPOS malware. One of those approaches is to go back to basics and remember some important foundational tenets of information security. This approach involves ensuring that authentication and authorization policies are sensible and enforced across the organization. For example, some simple steps an organization can take to improve its defenses against threats such as BrutPOS include (but are not limited to):

  • Not allowing administrative access to systems, with the exception of special administrative accounts for administrators
  • Locking out accounts after N number of incorrect login attempts
  • Not allowing RDP login by default on systems, but rather, granting it on an as needed basis
  • Limiting or eliminating the use of shared or group accounts
  • Monitoring authentication logs for repetitive failed login attempts to one system or multiple systems

As organizations look to continually improve their information security postures, it’s important to remember that foundational tenets are as valid as ever. We do need to ensure that we have a variety of defensive measures in our arsenal, but it’s important to remember that not all of them need be cutting edge. Sometimes, foundational best practices can provide us with straightforward approaches to mitigating risk posed by modern threats.

Economics of Security Part II: Qualifying the Economic Return From Cybersecurity Solutions

In part one of this series, my colleague, Bryce Boland, CTO, APAC touched on aligning a security program with the value-areas of a business. To be successful in this endeavor, you must calculate the return on investment (ROI) that a robust security program will offer. In part two, I will offer recommendations to achieving this.

The economics of security is an interesting challenge. I polled some contacts and discovered that, as much as we focus on reducing the capex on software and hardware, the majority of costs are actually opex. Therefore if we want to drive efficiencies in security, we should look at the usability (i.e. the time and costs required to achieve the desired outcome) of the tools as much as what they actually do.

Cybersecurity is a multi-dimensional problem, so whilst we consider efficiencies we must look at them in the context of outcomes and value. Our value question in cybersecurity has two factors: (1) are we able to leverage the most efficient path to obtain the solution and (2) being able prioritize on events/incidents that have the greatest business impact.

Simple event/incident response process

The rudimentary processes behind cyber have been around for years and are well documented in various standards. There’s a catalyst event that drives us to understand the problem, so we can qualify and prioritize if and when we need to respond – i.e. solve the problem.

Screen Shot 2014-07-02 at 10.41.08 PM

Are we increasing or decreasing efficiencies?

In recent years many have suggested the logic that “big data” can help us make smart decisions. Yet there is danger that this can create a spiral effect that has the potential to cripple us. By adding more content, we increase the cycles required to understand, qualify and respond. There is also a key question around the quality of that data. Take for example all the events we aggregate into a SIEM tool today, how many of those are truly worth taking action on?

How do we measure success and value?

If we are to evaluate the economic value cyber security solutions bring we need to look less at what they do and instead more how they do it. We need to understand the quality of the information they provide, both in terms of business impact and conversion to action, as well as the operational cycles required to achieve this; which are the cost & time multipliers.

As our technology world complexity continues, the operational aspect as a multiplier can only increase. Today I hear more companies asking for partnerships to solve problems rather than products; they see the time and skills challenge in solving the problem as prohibitive. If we are to succeed today, we need outcome focused solutions; that is they are efficient in providing actionable responses that are business oriented in their focus and/or services that reduce the operation costs associated with time to action. So how do we evaluate this in our buying criteria?

There have been many ROI tools that try to qualify the potential value that come from security investments. However if we are to align to business goals, we must drill into the process behind event correlation/validation – the heart of security – for business impact assessment and response actions.

Qualifying economic value from event/incident management

The framework below aims to give you a reference point to start to map out the economics of your security program.

Given solving this problem is entirely dependent on each individual organization; we must be able to qualify what makes our businesses profitable and how technology enables this. The model does not include metrics in each part of the incident lifecycle but does highlight some of the common key success metrics.

To make economic judgments, you need to assess the following:

  1. What is the ratio between events received and action taken?
  2. What is the efficacy level in the events & incidents you identify (i.e. the real cyber attack event to false positive ratio)?
  3. How many cycles do you iterate through to get from an event(s) to an action; is it timely and cost efficient? (Can you rank the processes/tools you leverage today in terms of man-hours and skills required to get to to action?)
  4. Do you align, prioritize and qualify events against against business goals and impact (How many cycles does this take)?
  5. Make the assessment using the framework & success criteria below to evaluate the key time and cost multipliers in your event/incident security process, so you can validate the economic value that comes from the processes and tools you leverage today, to see which are effective and which are not?
Measures of effectiveness of event/incident management

Measures of effectiveness of event/incident management

In conducting the evaluation process above (and visually outlined above), there is a defined process for tying operational expenditures with investments for securing the processes that generate business value. By analyzing the actions taken to conduct security operations and the, ideally, efficiencies in doing so, security leaders will be able to provide a full picture of their impact on the business. Ultimately, this changes the security conversations from just security to business practices overall.

Economics of Security Part I: Translating Information Security Risks to Business Risk

In this two-part series, my colleague, Greg Day, VP & CTO EMEA and I will focus on making the business case for security solutions that will protect your organization.

One of the many challenges IT Security professionals face is translating the security risks of technologies into the business risks they pose to the company. This translation is critical to building buy-in from your business to fund security initiatives and ensure your projects are funded properly relative to the myriad other things your business is pursuing with its money.

But where should you start? I’ve found that the best place to start is by looking at the processes in the business that generates value. These are the parts of the business that a results-oriented manager will want to protect from threat. By describing security risks in terms of how critical business processes – and their subsequent value generation – could be disrupted, your concern will resonate better with management. Consider the total business value that process generates today – is it 15 percent of the business or 85 percent? Give it a dollar figure. Given your assessment of the likely threat actors and security risks, how much of that value could be destroyed? This is a simple measure of the possible direct or immediate loss that could be experienced – something management are often measured and rewarded on.

Next you can look at knock-on impacts – this too helps speak to the management incentives. If the security risk manifests and creates a specific and significant business impact, would the market, regulators or customers notice? Would the stock price of the company drop as a result? Most business leaders will have a significant and direct interest in market valuation as their remuneration is often closely linked to the company’s stock market performance. Similarly, ask what is the business impact if a security failure leads to a loss of customers, of transaction volume, or increased regulatory scrutiny? Could you face a class action suit?

Sometimes the link between the business value generated and the technology underpinning it is a little hazy, but any modern business process that creates value will leverage and create data. It might be your customer data, the “secret sauce” of your products, a manufacturing capability that ensures your product has the best quality, the output from your R&D team, or perhaps it’s the plans for your next new business. Whatever this data is, and how you depend on it in your business, ensuring it is protected from threats is the difference between success and failure for many companies. Often this data is what the attacker is after. From a business perspective, the reliance on this data to operate the business effectively is how you connect the security risk to the business risk.

What are the most important assets and data in your business that create real value? This is very specific to every business. Think like an attacker: if you were to attack your business, what information would you steal, and why? What could you monetize, use to gain economic advantage, or gain market share? You can assess the value of that asset to your company in terms of potential losses from the dependent business processes, and the value of that asset to an attacker. Then determine how much you should invest to protect against the risks from cybersecurity threats. By going through the process of understanding how data and IT assets are part of the value creation in your business, you actually create the story to help understand the business risk, because you construct the discussion starting from the business process first.

Sometimes the most valuable thing you have is access to your customers. If your customers are large companies, this might make you a springboard to attack a smaller company – and likewise for a larger company your greatest security risks could be exposure to the less security aware vendors in your operations and supply chain. Make sure to consider these scenarios when talking to your business. As larger organizations consider the risks in their supply chain, they will increasingly consider security requirements in MSAs and demand not just compliance but demonstrable security capabilities in their business partners. It is a logical extension of risk management thinking to consider the broader supply chain risks as part of overall business risk management, and this will drive many smaller businesses to invest in improved security capabilities.

More than half the organizations we surveyed do not regularly assess their information security investments in terms of their value relative to the business process they protect. My recommendation is to re-evaluate your investment plan annually, and ensure that your continued security investments are relevant to the threats your business faces. You might also consider using a risk framework like ISO27005 as a tool to help you manage this in a consistent way, to prioritize risks and corresponding investments.

To summarize: understand how and where your business makes its money, illustrate the dependency on technology and data, then explain security risks in terms of the business impact.

In the second part of this series, Greg will discuss how to measure the economic value of your cybersecurity solutions.

Key Themes From the 2014 Gartner Security Summit

Last week, Gartner held its security summit in Washington, DC. A few key themes bubbled to the top during the course of the conference.

Theme #1: Security needs a new architecture
Security architecture requirements will change radically in the coming years. Basically, security will move to a “detect and respond” approach. This was best summarized by one article that covered the conference explaining how vendors are evolving:

[Gartner analyst Neil] MacDonald noted that the need for adaptive security architectures has triggered a land-grab among vendors, large and small, trying to expand their reach, with many rapidly transforming as investors pour money into startups and acquisitions.

FireEye Inc. is at the top of the list, MacDonald said, not only with its January acquisition of Mandiant, but also recently by adding integrated, low-cost IPS capabilities to its threat prevention platform.

Theme #2: Mobile security
Many CISOs expressed mobile security and BYOD as a key area of concern. In one session, mobile application security was mentioned as a key approach to leverage. To succeed, enterprises should evaluate applications by:

  • Testing application source code
  • Testing application behavior
  • Testing communications between the app and web services
  • Automatically submitting apps for testing.
  • Knowing app risk/reputation—using scores
  • Combining and correlating detection with protection.

Theme #3: Incident Response is a core discipline
Under a security paradigm of detect and respond—the importance of incident response has become critical. In one session, analyst Anton Chuvakin laid out a step-by-step approach for incident response. In addition, other sessions frequently alluded to the growing importance of IR.

Theme #4: Dealing with advanced attacks
Dealing with advanced attackers was a high profile topic—with many sessions focusing on the “how-to’s” of blocking an advanced attacker. Most notably, Lawrence Orans gave a talk on the “Five Styles of Stopping Advanced Attacks.” He started the talk stating that “Traditional defense-in-depth components are still necessary, but no longer sufficient.” His framework recommends five styles of advanced threat defense that include:

  • Network traffic analysis
  • Payload Analysis
  • Endpoint behavior analysis
  • Network forensics
  • Endpoint forensics

The conference highlighted a security industry experience in a great deal of flux with the onset of advanced attacks, mobility and more. At the same time, customers want things delivered via the cloud—all the while hoping for a centralized view and management capability. As always, security is changing and evolving—but this year was a little different. General consensus was that few knew where threats were going—but customers want a security architecture that can deal with today’s threats while adapting to ones we haven’t seen yet.

 

Introduction to Strategic Thought

I plan to address strategic thought as applied to digital security in a series of posts. Here I would like to briefly introduce the concept and offer a simple example.

Joint Publication 1 (JP-1), Doctrine for the Armed Forces of the United States, helps illuminate the strategic approach to digital security. JP-1 defines three levels of warfare: strategic, operational and tactical. Above the strategic level one can place the overall goal of the digital security program, as one might place the overall goal of a military or political endeavor. Below the tactical level one can similarly place tools or technology – the weapons one might employ when conducting tactical maneuvers. Taken as a whole, the five levels appear as shown in Figure 1.

Figure 1. Five Levels of Strategic Security

Figure 1. Five Levels of Strategic Security

Using a strategic security framework enables a digital defender to build a more effective and durable program. A strategic security system doesn’t start with tools and tactics; instead, it begins by setting one or more overall mission goals. The strategy-minded chief information security officer (CISO) obtains executive buy-in to those goals, which works at a level understood by technicians and non-technicians alike. Next the CISO develops strategies to implement those goals, organizes and runs campaigns and operations to support the strategies, helps his or her team use tactics to realize the campaigns and operations, and procures tools and technology to equip the team.

Figure 2 shows an example of one strategic security approach to minimize loss due to intrusions, using a strategy of rapid detection, response, and containment, along with network security monitoring-inspired operations/campaigns, tactics and tools.

Figure 2. Five Levels of Strategic Security Example

Figure 2. Five Levels of Strategic Security Example

Most security professionals – and by association policymakers and leaders taking advice from those practitioners and engineers – fixate on the tools, and to a lesser degree, the tactics of the digital security problem. Goals, strategies and campaigns aren’t usually a consideration because technicians, administrators, programmers and the like spend their time working with tools. The extent of their tactical involvement is thinking about creative ways to use their tools. The communities that tend to think in terms of goals, strategies and campaigns – think tanks, policy analysts and so on – have traditionally not engaged with the technicians to bring the entire strategic security approach to bear on modern challenges.

As shown in Figure 2, “detecting intruders” is actually shorthand for a rich strategic security program – one whose goal is minimizing loss through a strategy of rapid incident detection, response and containment. Security teams run operations to match threat intelligence against security event data and hunt for novel intruders as needed. They tactically collect, analyze, escalate and resolve incidents and the related data using tools suited for those functions.

It is crucial, however, that the ultimate goals and strategy remained linked with the tools at the bottom of the process. If that chain decouples, the outcome could be disastrous, where technical reality makes strategic theory obsolete. For example, a program built on monitoring the network will fail if all network traffic is encrypted. The tools at the bottom of the process will not be able to “see” the contents of network traffic and will be less effective when trying to identify suspicious and malicious activity. In this dysfunctional case, the tools’ inability to deliver required data to the personnel conducting tactical endeavors and operational campaigns will prevent the program goal from being achieved.

In future posts, I will elaborate on these concepts to demonstrate how they improve enterprise security.

Note: This post is adapted from a research paper by the author, published through The Brookings Institution as Strategy, Not Speed: What Today’s Digital Defenders Must Learn From Cybersecurity’s Early Thinkers.

Introducing the Digital Security Strategy Series

This is the first in a monthly series of blog posts I will write on strategic digital security. My goal is to introduce, or reinforce, concepts that are not often emphasized in the field of computer network defense. Our community is dominated by discussions of tools and tactics – such as software and how to use it to counter our adversaries. These are important elements of digital defense, but they should not constitute one’s entire security program.

I studied history and political science at the United States Air Force Academy (USAFA). At USAFA, the instructors were mostly officers; some of whom had fought in the first Gulf War. As a freshman cadet, I learned that prior to the Gulf War, Air Force planners concentrated on quickly deploying assets to conflict zones and fighting tactical engagements (often close air support or combat air patrols) once directed to do so. They seldom adopted a more strategic view of their contribution to national goals because they focused on one-on-one tactical engagements, relying on their individual skills and technical superiority to prevail.

Several officers contributed substantially to a change in the Air Force’s approach to warfighting just in time to prevail during the first Gulf War. These officers included John Boyd, John Warden, David Deptula, and others who sought to employ airpower as a strategic asset. They didn’t think solely in terms of tactics and tools; they planned for airpower to conduct campaigns and operations in support of strategy that ultimately realized national goals. By linking national policy and goals with strategy, operations, tactics and tools, they created a much more effective Air Force and changed the way the service postured itself in future conflicts.

I share this story because I see the same need for change in the digital security community. Yes, we need to have the best tactics and tools, but we must employ them to conduct campaigns and operations that embody strategy and contribute to organizational goals. In the coming months, I will write more about this topic, and I look forward to your questions.

Please leave a comment below on topics you would like me to discuss.

Live from Infosecurity Europe 2014: Cybersecurity Experts Come Together

Infosecurity Europe 2014 was the place to be for any major player in the world of cybersecurity, and live from the show floor; the FireEye Blog team had a front seat to some exciting conversations. Paul Dwyer, director at FireEye, had the opportunity to sit down with a number of influencers and ask questions that were on all of our minds.

In this first podcast in the series, Amar Singh, senior analyst at KuppingerCole, and founder of ARK Advisors discusses the threat of malware, and also touches on the subject of industrial espionage. Click here to listen to the full podcast. Bruce Hallas, founder and curator of The Analogies Project, a not-for-profit venture designed to help the information security community communicate and engage more effectively with stakeholders, joined Paul in our next podcast. Hallas discussed the significance of generational cybersecurity, and outlined the key behaviors and security working practices of generations Y and Z. Click here to listen to the full discussion.

First Base Technologies CEO Pete Wood also sat down with us for a chat, and shared his thoughts on how an information security function evolves to become business-led. Mr. Wood was also asked about the current business security model, and whether cybersecurity should be considered a Board Level issue. Click here to listen.

Finally, FireEye Director of Technology Strategy EMEA, Jason Steer had the chance to speak with Brian Honan from BH Consulting about the recent Internet Explorer (IE) browser vulnerability, as well as the importance of separating networks into different segments. Listen to the full podcast here.

Did you attend Infosecurity Europe 2014? Chime in and let us know what you thought of the event and the topics discussed. Leave us a comment below.

FireEye Enters Agreement to Acquire nPulse Technologies

Today, I’m excited to announce that we’ve entered an agreement to acquire nPulse Technologies, the performance leader in network forensics. The acquisition is expected to close during the second quarter of 2014, subject to standard closing conditions. nPulse has the fastest solution available for high-speed full packet capture and indexing. By combining the nPulse products with the FireEye platform, we’re building enterprise forensics capabilities that will enable incident investigation and remediation that no other security vendor can match. When combined with Mandiant services and the services capabilities of our partners, we’ll be able to provide customers complete visibility into the network with quality analytics that accelerate the path from detection to resolution. This acquisition is a vital part of our long-term strategy to build a single security platform that protects against the most advanced threats and offers customers one solution to detect, contain, resolve and prevent threats.

With the acquisition, FireEye will further expand its security platform with the following:

  • FireEye will offer the industry’s first Enterprise Forensics solution with a unified view of network to endpoint forensics, enabling enterprises to minimize risk and drive down mean time to resolution.
  • The Enterprise Forensics solution, coupled with the FireEye threat analytics solution, will form a comprehensive intelligence platform.
  • The FireEye Network Threat Prevention Platform combined with newly introduced IPS capabilities and the addition of nPulse’s forensics will offer a comprehensive threat management platform.
  • The Enterprise Forensics solution together with FireEye Managed Defense™ will enable the industry’s most advanced managed service capabilities, bringing together deep visibility and rich context from Enterprise Forensics with active defense capabilities of the Managed Defense portfolio.

The New Reality of IT Security
Our Mandiant services team has investigated thousands of breaches and from this experience we know that no matter how good your defenses, with users in the system, every organization has some malicious code within their network. In fact, we know the median number of days attackers were present on a victim’s network before being discovered was 229 days in 2013. But today, when a data breach can result in being called to testify in front of Congress, every organization should be prepared to answer questions about how an attacker got into their network and what data was impacted. Preventing malicious code from entering the network is always key, but now we need to know more - when the malicious code appeared, how the network was compromised and if any data was removed. This is the new reality of enterprise security.

Enterprise Forensics - A Black Box For Your Network

Previously adding enterprise forensics involved building a customized solution that correlated data from multiple point products monitoring different parts of the network and across endpoints. Overwhelmed by cost and complexity, many organizations simply put this off, leaving a wide hole in their IT security and response capabilities. After entering into a technology partnership with nPulse Technologies earlier this year, we saw how our joint customers benefited from bringing together nPulse network information with FireEye threat intelligence and endpoint data.

With this acquisition, FireEye will combine nPulse network forensics with the endpoint products acquired from Mandiant to incorporate attack information from the host, endpoint, network and cloud. We like to think of enterprise forensics as adding a flight data recorder – or a black box – to the network. With complete visibility into the network, the FireEye platform will be able to produce higher quality alerts to help protect against threats as well as quickly quantify the impact of a breach following the discovery of malware on a network. With big-data analytics and real-time capabilities, FireEye will offer enterprise forensics that help answer the most important questions an organization has after a breach.

nPulse extends our reach into an organization’s history because it can log all network activity for as long as they choose to retain that data. With the industry’s fastest lossless, intelligent capture and retrieval, nPulse gives us the ability to “go back in time” to see the full extent of how malicious code behaved on the network. By being the first to deliver end-to-end (network and endpoint) detection and forensics at scale, FireEye enables enterprises to minimize risk by quantifying the impact of a breach while accelerating detection and resolution from days to a matter of minutes. For our Mandiant team and partners, this means we can deliver better service and more comprehensive incident response capabilities.

And most importantly, by reducing incident investigation time, providing validated breach information and improving the quality of alerts, our customers and clients can reduce their exposure to attacks while substantially reducing operational expenses.

At FireEye we’re building the most comprehensive security platform and I look forward to welcoming the nPulse Technologies team to the FireEye family. In the short term after the acquisition, nPulse will continue to operate normally and current customers should expect no disruption in current capabilities and service. Over the coming months after the acquisition, we’ll work to combine the nPulse products with the FireEye platform and bring enterprise forensics to all our customers and partners. Once again, FireEye is leading the way to solve the most complex and time-consuming security challenges.

 

Forward-Looking Statements
This blog post contains forward-looking statements about the expectations, beliefs, plans, intentions and strategies of FireEye relating to its pending acquisition of nPulse. Such forward-looking statements include statements regarding the impact of the pending acquisition of nPulse on FireEye’s competitive position, future product offerings and potential benefits of current and future product offerings. These statements reflect the current beliefs of FireEye and are based on current information available to us as of the date hereof, and FireEye does not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made. The ability of FireEye to achieve these business objectives involves many risks and uncertainties that could cause actual outcomes and results to differ materially and adversely from those expressed in any forward-looking statements. These risks and uncertainties include market adoption of FireEye’s virtual machine-based security platform; the termination of FireEye’s pending acquisition of nPulse if FireEye and nPulse fail to satisfy the conditions for closing in the definitive agreement; the failure to achieve expected synergies and efficiencies of operations between FireEye and nPulse; the ability of FireEye and nPulse to successfully integrate their respective technologies, products, personnel and operations; FireEye’s ability to attract and retain new customers and expand and train its sales force; the failure to timely develop and achieve market acceptance of combined products and services; the potential impact on the business of nPulse as a result of the pending acquisition; the loss of any nPulse customers; the ability to coordinate strategy and resources between FireEye and nPulse; the ability of FireEye and nPulse to retain and motivate key employees of nPulse; general economic conditions; as well as those risks and uncertainties included under the captions “Risk Factors” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” in FireEye’s Form S-1 filed with the Securities and Exchange Commission on April 22, 2014, which is available on the Investor Relations section of FireEye’s website at investors.fireeye.com and on the SEC website at www.sec.gov. Any future product, feature, or related specification that may be referenced in this blog post are for information purposes only and are not commitments to deliver any technology or enhancement. FireEye reserves the right to modify future product or service plans at any time.

 

Ghost-Hunting With Anti-Virus

In October 2012, data security firm Imperva released a controversial report on the efficacy of anti-virus (AV), which concluded that AV solutions only stopped 5 percent of all malware identified. Few reports in the security industry had been as polarizing as this one—many reacting with white-knuckle rage. It was a classic case of Chris Christensen’s “Innovator’s Dilemma,” where old school technologies cling to life, in the face of a new paradigm. Just yesterday, one of the original anti-virus vendors joined the fray in “declaring anti-virus dead” in the Wall Street Journal.

At FireEye, we look at hundreds of malware samples daily, and, in a recent talk at RSA Conference, Zheng Bu, vice president of research at FireEye presented some interesting data that security teams should consider as they think about their AV initiatives. Looking at nearly half a million malware samples over two years, our researchers discovered that the average lifespan of a piece of malware is very short. The chart below compares how many hours (X axis) malware lives against the total pool of malware samples (Y axis) to show just how quickly they disappear:

av1

Our data shows an interesting picture: most malware remains active for no more than two hours when FireEye is detecting it. To be precise, our analysis showed that in 2013:

  • 82 percent of malware disappears after one hour
  • 70 percent of malware only exists once

With the half-life of malware being so short, we can draw the conclusion that the function signature-based AV serves has become more akin to ghost hunting than threat detection and prevention. In spite of this, IDC found the market for endpoint security products like anti-virus to generate $11 billion in revenues in its “Worldwide IT Security Products 2013 – 2017 Forecast” despite APT activities creating nearly fifty unique malware infections everyday.

In AV Land, Everyone Is a Sacrificial Lamb

Today’s AV model makes everyone a sacrificial lamb. In the past, malware writers would write their attack code once with little need to iterate. Today, as our numbers show, rapidly developing iterations of malware is becoming the de facto way of hacking.

A simple comparison of the malware writing process versus anti-virus signature development shows a stark contrast.

First, let’s look at the malware development process:

figure1_v2

Malware is developed, QA’d against the latest AV signatures, released, and once it is picked up by AV sensors and shared among vendors—the malware dies. The process takes a few days at most.

By contrast, anti-virus vendors work in a process that takes a few days to a few weeks.

av2

Examining the two “supply chains,” you quickly see why anti-virus is inherently behind the curve – doomed to chasing ghosts. By the time malware signatures are updated from collection and have gone through QA, the samples are more-or-less defunct unless it is a rare instance where the core code of the malware could not be modified. Over the years AV vendors have increased the frequency of signature updates to convey the benefits of eventual detection. However, it is already an increasing challenge to apply frequent security updates to thousands of business-critical computer assets in medium to large size organizations – especially where many assets such as laptops are also mobile. Ultimately this does not close the days to weeks collecting new malware samples can take, which is why security solutions – like FireEye – that do not rely on such a reactive model detect malware faster.

To be clear, single-iteration malware will continue to persist, and a minor need for AV will remain to provide a layer of reactive protection against these unsophisticated, benign threats. But with high-profile breaches occurring frequently, being driven by fast-moving, advanced threats, it is clear that next generation technologies and approaches are needed. Even Gartner has noted the senescence of anti-virus in two very recent reports. Notably, in the Magic Quadrant for Endpoint Protection Platforms (i.e., anti-virus), where its opening sentences of the “Market Overview” state:

The rise of the targeted attack is shredding what is left of the [endpoint] anti-malware market’s stubborn commitment to reactive protection techniques. Improving the malware signature distribution system, or adapting behavior detection [in endpoint solutions] to account for the latest attack styles, will not improve the effectiveness rates against targeted attacks. (From 8 January 2014).

So, what should we do as an industry knowing that the AV is ineffective today based on these findings? We recommend:

  • Accepting that the signature-based AV model cannot play a key part of enterprises’ threat-prevention models. Start shifting security strategies to modern methods that identify malware at the time of attack rather than after it has died.
  • Reconfigure compliance mandates to place much less emphasis on AV and other reactive, signature-based approaches. Once regulators and compliance mandates make it easier to adopt innovation, we’ll finally make life a little harder for the attackers.

In doing this, we will be able to protect ourselves not from the ghosts that we imagine are haunting our homes, but from the burglars and malware that truly steal our possessions and erode our foundations.