The FireEye Advanced Threat Report 2013: European Edition

We recently published the 2013 FireEye Advanced Threat Report during RSA Conference, providing a global overview of the advanced attacks that FireEye discovered last year. We are now drilling that global analysis down into the European threat landscape with our first Regional Advanced Threat Report.

Recent European cyber attacks, like the ones against the European Parliament or LaCie, make it clear that advanced attacks are a becoming a harsh reality in Europe. Motivated by financial and political objectives, threat actors have increased their levels of sophistication to steal personal data and put organizations into non-compliance with user privacy EU directive (2002/58/EC).

The top-line findings from our first Regional Advanced Threat Report are alarming, as we:

  • Recorded over 250 new workstations infected every day
  • Identified more than 90 APT families
  • Observed threats impacting all verticals, particularly the Healthcare, Financial Services and Government verticals

Diving deeper, we saw that the rate of increase in workstation infections skyrocketed in the last four months of 2013. A clear sign of how rapidly threat actors targeting European organizations are evolving, the number of unique infections more than doubled from January to December 2013.

eu1

Figure 1 – Unique Infections Trending over 2013

We also took a look at the distribution of infections amongst European nations and saw a heavily skewed landscape. In particular, Great Britain, Switzerland, Germany and France represented more than 70 percent of infections across 2013, leaving 18 nations to split the remaining 30 percent.

eu2

Figure 2 – Unique Infections by Country

Next, let’s consider which industry verticals in Europe were most targeted by advanced attackers. Threat Actors have been busy targeting high-value organizations that offer rich personal information or intellectual property. The below chart shows the number of infections that occurred in each of the 20 verticals that FireEye tracks around the world. Alarmingly, no industry vertical in Europe was spared and this trend is most likely to continue.

eu3

Figure 3 – Unique Infections by Industry Vertical (Listed from Most-Infected to Least on Right)

Based on the latest Mandiant M-Trends report, the Financial Services vertical accounted for 15 percent of threat actors’ actions on a global basis. In Europe, we saw Financial Services account for 17 percent of attacks, aligning closely to the global statistic. In a stark contrast however, Healthcare/Pharmaceuticals represented 21 percent of infections in Europe compared to the four percent this vertical accounted for globally.

Beyond Infections: Diving Into APT Attacks

When pulling this report together, we saw the notable rise in infection rates and the attacks across verticals, and we also saw strong similarities in how APT attacks targeted European industry verticals. As you can see below, aside from the extraordinary fact that European Federal Governments accounted for a quarter of APT attacks, the Financial Services and Healthcare/Pharmaceutical industries maintained top positions as targets.

eu4

Figure 4 – APT Attacks per Vertical (Listed from Most-Targeted to Least on Right)

This consistency between infections and APT attacks also carried over to the distribution of APT attacks between different countries. As we see below, when it comes to country-by-country analysis, the top-three most impacted in Europe are the UK, Germany and Switzerland – the same top-three infected countries.

eu5

The highest number of APT activity in Europe, by country can be summarized in the following order:

  1. Germany
  2. United Kingdom
  3. Switzerland
  4. Luxembourg
  5. France
  6. Spain
  7. Norway
  8. Belgium
  9. Finland

In addition, we found that when measuring the world’s most-targeted nations by number of unique verticals hit by APT attacks, three European nations made the top-ten: France, the UK, and Germany.

UKI52

With such a strong rise in infections and just a couple of industries and countries accounting for a massive number of the attacks carried-out in Europe, we are certainly seeing a change in the threat landscape with this report. And while the situation would seem bleak already, we predict that there is still more time for the European market to strategically get ahead of these advanced attack before they fully mature into a constant threat.

With that time in mind, we recommend the following for European organizations:

  1. Ensure existing security tools are up to date. Much commodity malware can be easily addressed with legacy, signature-based tools.
  2. Implement Advanced Threat Protection systems to ensure high value data is safeguarded.
  3. Plan and Implement an Incident Response and Management strategy to close existing security gaps.
  4. Share and collaborate with other entities on emerging cyber threats to optimize your security posture.

To find out more about the report or how to address these rising issues, come visit the FireEye team at InfoSec UK at Stand J60.

The FireEye Advanced Threat Report 2013: UK & Ireland Edition

Accompanying our Regional Advanced Threat Report (ATR) for Europe, we are also drilling even deeper with a Regional ATR focused on the United Kingdom and Ireland (UKI). During our assessment of these two countries, we have identified all types of threat actors compromising our customers’ networks: nation state, cyber criminals, activists, and amateurs alike.

This report summarizes 2013 data gleaned from the FireEye Dynamic Threat Intelligence (DTI) cloud of worldwide malware protection platforms. Over the past year, FireEye:

  • Recorded over 70 new workstations infected every day
  • Identified more than 42 APT families
  • Observed threats impacting all verticals, particularly Financial Services, Telecom, and Energy

As we saw with the European report, the rate of increase in workstation infections across Ireland and the UK skyrocketed in the last four months of 2013. This may indicate that threat actors increased the volume of activity against organizations in the United Kingdom and Ireland in the post-vacation lull because they anticipated employees would be less attentive around security matters and thus have a higher rate of success. Alarmingly, the number of unique infections more than tripled from January to December 2013.

UKI1

Figure 1 – Unique Infections Trending over 2013

Next, let’s consider which industry verticals in UKI were most infected by attackers. Unsurprisingly, the Financial Services vertical is far and away the most targeted in UKI as “The City” is the largest financial platform for Europe and the world. Of course, threat actors have also been busy targeting the other high-value industries of UKI, particularly the Telecommunications and Energy/Utilities/Petroleum Refining verticals. As with the rest of Europe though, no industry vertical was spared in the UK or Ireland and this trend will likely continue as new attack vectors enter these industries.

UKI2

Figure 2 – Unique Infections by Industry Vertical (Listed from Most-Infected to Least on Right)

Rising Attack Landscape Means Rising APT Families

The consistency between the UK’s and Ireland’s threat landscapes has also extended into the way the APT attacks are carried out. Most important to highlight is that Federal Government continues to be the number one target in UKI – as with Europe – only with that industry vertical accounting for a startling 49 percent of APT attacks versus 25 percent for all of Europe.

UKI3

Figure 3 – APT Distribution per Vertical (Listed from Most-Targeted to Least on Right)

Financial Services remains a top-three target of APT attacks as well in UKI, but the Energy/Utilities/Petroleum Refining industry climbs from seventh place in Europe to second place in UKI. Given the major corporations in those spaces operating out of UKI, that these organizations are a prime target by APT actors is unsurprising.

How those APT attacks were carried out is shown in the chart below identifying the 21 APT malware families that we identified in attacks throughout 2013.

UKI4

Figure 4 – APT Malware Families for UKI

We previously noted in our European report that, when looking at the sheer number of APT attacks, the United Kingdom received the second most of any European country in 2013. Despite trailing Germany as the most-targeted European nation, the UK was tied for fourth globally with France and Thailand when it came to most verticals targeted by APT attacks. Specifically, all three nations saw 12 distinct verticals hit, with the next closest European nation being Germany with nine verticals.

UKI52

Figure 5 – APT Attacks by Country

While the UK and Ireland face unique challenges based on the maturity of the Financial Services, Telecommunications and Energy-based industries that are based there, we have found that the overall market is very much in-line with the rest of Europe. Thus, as with our outlook for the whole of Europe, we see an opportunity for UKI cyber defenders to get ahead of the rapidly expanding advanced threat actors.

To find out more about the report or how to address these rising issues, come visit the FireEye team at InfoSec UK at Stand J60.

The Road to Resilience: How Cybersecurity is Moving from the Back Office to the Boardroom

For too long, our industry has framed cybersecurity as a technical issue.

We have measured success on the volume of malware we detect and block, not how we respond to the threats that matter. We have taken a one-size-fits-all approach to security incidents, regardless of who’s attacking, how they work, and what they’re after. We have rarely engaged other business units when responding to incidents — and when we do, we fixate on the technical details rather than weighing their business impact.

Yes, cybersecurity has a technical component. But more than anything, it is a business issue.

Fortunately, the old mindset is changing. Under the banner of “cyber resilience,” security leaders are beginning to acknowledge that cybersecurity must evolve. Striving to ward off attacks is no longer enough — organizations must also respond to incidents with a focus on managing their business impact.

To gauge how far along organizations in the Europe, Middle East, and Africa (EMEA) are in this evolution, FireEye recently asked 25 security leaders across the region about their experience and perceptions. Their answers reveal a sizable divide among in both awareness and maturity when it comes to cyber resilience.

Breaches Increasingly Routine
Not surprisingly, EMEA security leaders say that cyber breaches are increasingly routine. In our survey, 44 percent of organizations said they had breached at least once per year. And that total probably understates the problem — a full 28 percent were not sure whether they have been breached.

img1

All threats viewed equally — regardless of risk or impact
A solid majority of respondents (68 percent) said they “always” care about breaches. Only 16 percent said their level of concern depends on the severity of the incident. This lopsided statistic suggests that IT professionals are not yet looking at breaches from the perspective of risk or impact.

img2

Priorities misaligned in incident response
We see the same lack of business alignment in organizations’ responses to breaches. When a breach occurs, 84 percent of those in our EMEA survey notify relevant business leaders, and 76 percent notify company executives. We often hear that companies are looking for security leaders to engage at a business level. But if business leaders and executives are still being notified about most breaches, we’re still treating security as a technical problem.

img3

Our survey found a split in where security teams focus their response. About 60 percent base their response plan around all IT systems, and 40 percent focus on critical systems and resources. This response, too, suggests that organizations see many breaches as a technical problem rather than a business problem.

Along the same lines, communications, public relations, and business teams are typically far less engaged in incident responses than IT security and technical teams, executives, and HR departments. If cyber resilience is about enabling business resilience, then business teams should play an equally critical role in incident response.

When engaging with executives, we in the security community do not seem to be taking a risk-based approach. And clearly, we are not speaking executives’ language: the impact of a breach on the company’s financial results.

Who is included in incident response plans?

img4

Moving toward a risk-based security framework
Most security leaders leverage at least one security framework or standard — and in most cases, they leverage two or more. These frameworks include best practices defining what to protect, how to protect it, and how to monitor deployed controls. These features make the frameworks valuable tools to help define strategies and gauge their effectiveness. But adoption of ISO27005 — which focuses on business-risk assessment — is far behind that of ISO27001.

Adopted security frameworksUntitled

Leveraging automation
Just about every security leader would like more resources. But most of us must make the most of what we have.

What is clear from our survey is that incident response is consuming the biggest share of time and resources.

Security tasks that consume the most time and resources (weighted average)img5

The volume of attacks is rising. And IT systems are playing an increasingly critical role in business. So having well-defined and tested response capabilities that leverage automation would seem a key component to cyber resilience.

Bolstering cyber resilience
Cyber security is, and will remain, an evolution. Everyone is on their own journey along the maturity curve. Security leaders must evaluate their place along that curve based on their perceptions of risks and the controls they need to put in place.

Cyber resilience recognizes that prevention is only part of the solution. Organizations must realize the following:

  • Businesses will increasingly measure security leaders not just on what they stop or let through, but on how they respond to what does get through.
  • A breach can happen in seconds, yet the exfiltration takes hours or days and can last for months.[1]
  • When it comes to measuring business impact, not all breaches are equal.

At the same time, organizations must retool their strategies to better discover and respond to security incidents. This shift requires:

  • Having a documented, regularly reviewed, and well-tested cyber response strategy that includes both the business and technical response plans.
  • Reducing the time and costs involved in response.
  • Being able to qualify the business risk of the incident. By better aligning cyber strategies to business drivers and business risk, security leaders can have a bigger business impact and increase their relevance to executives.

Zero-Day Attacks are not the same as Zero-Day Vulnerabilities

When it comes to “zero-days,” there is much room for confusion in terms of definition and priority. At FireEye, we follow the industry-standard term of “zero-day attacks.” This term is defined as software or hardware vulnerabilities that have been exploited by an attacker where there is no prior knowledge of the flaw in the general information security community, and, therefore, no vendor fix or software patch available for it.

Here is the Wikipedia definition:

“A zero-day (or zero-hour or day zero) attack or threat is an attack that exploits a previously unknown vulnerability in a computer application, one that developers have not had time to address and patch.[1] There are zero days between the time the vulnerability is discovered (and made public), and the first attack.”

Many security researchers identify vulnerabilities – some as a byproduct of attack detection and others as a core focus. With the exception of vulnerabilities identified by black hat hackers for use in attacks, nearly all vulnerabilities are responsibly, and confidentially, sent to the party responsible for the creation of the software so that fixes can be made. These can range from critical holes like those we found exploited in globally popular software like Internet Explorer to the never-exploited ones in rarely used applications.

FireEye has demonstrated unparalleled capabilities finding zero-day exploits that are “in the wild,” meaning the vulnerability is being used by criminals and threat actors for malicious purposes. In 2013, FireEye discovered 11 zero-day exploits that were actively in use by advanced threat actors and has already discovered an additional two in 2014. Zero-day exploits already in use by APT actors represent the most critical cyber threat to the CISOs of organizations. Even if APT actors do not target an organization, other criminal exploit authors will often reverse the zero-day exploit and create their own version before patches can be released.

At FireEye, we examine data from over 2 million virtual machines located in every corner of the globe, resulting in near instantaneous threat intelligence and threat metrics being captured in our Dynamic Threat Intelligence™ (DTI) cloud. This intelligence allows us to evaluate the entire attack life cycle, or “kill chain,” of an attack and view the behaviors of the attacker. FireEye examines all of the tools, tactics and procedures (TTPs) used by attackers to create an initial compromise, establish a foothold, escalate privileges, conduct internal reconnaissance, move laterally, maintain persistence, and finally complete their mission.

Killchain

Figure 1. The attack lifecycle

Our focus is to create a holistic view towards security at every step in the attack lifecycle, of which identification of zero-day exploits in use by malicious actors plays one component. We also contribute back to the security research community by sharing detailed, comprehensive views on attack lifecycles, for example in Operation Ephemeral Hydra. At FireEye, our defense strategy encompasses all malicious activities you may find on your network, or on your endpoints – including those that leverage zero-day vulnerabilities and those that do not.

Dissecting Advanced Attacks: FireEye Labs and the 2014 DBIR

Each year, a number of reports are released on the changing state of the threat landscape and where cyber security is headed. Like our annual Advanced Threat Reports and M-Trends Reports, Verizon has released the “Data Breach Investigations Report” (DBIR), which is considered by many in the security industry as the most comprehensive guide to data breaches. This year, owing to the large number of and deep insights into cyber espionage and advanced persistent threat campaigns that we track, Verizon tapped the FireEye Labs team to contribute to the latest version of the report.

The 2014 DBIR takes a comprehensive look into all forms of attacks from the past year and, as we have always done with our investigations, newly examines the incident patterns of attacks. This type of analysis is what we like to call behavioral or contextual analysis of a breach lifecycle and is invaluable in understanding advanced threats that are not readily apparent in traditional detection methods.

To help with this initiative, FireEye Labs contributed information on several advanced attacks uncovered in 2013 that were likely driven by cyber espionage motives. Information on the individual attacks can be found here:

To view a full version of the Verizon DBIR, you can download a copy here: http://www.verizonenterprise.com/DBIR/. Also, be on the lookout for the release of our European Advanced Threat Report next week.

InfoSecurity Europe 2014: Cybersecurity for the Masses

InfoSecurity Europe is the biggest security event and most important date on the calendar for information security professionals across Europe. The event aims to break through the noise and provide the European audience with all the necessary information to better understand cyber threats to their networks. Join FireEye experts and learn how to prepare for a new frontier of advanced attackers:

  • Visit stand J60 and check out FireEye’s Geek Bar. A certified geek will analyze your portable device to determine if you’ve received any malware. The live demonstration can prove useful to better understand and identify potential threats to your network.
  • Join FireEye Director of Technology Strategy Jason Steer, SI Technical Lead Simon Mullis, and Greg Day, EMEA CTO among others, as they discuss the threat landscape and walk attendees through interactive, educational workshops and presentations. Join us on our stand to understand the threat landscape – presentations every 30 minutes all 3 days.
  • Senior Director of Market Research at FireEye Rob Rachwald will be speaking on Wednesday, April 30, where he’ll cover the nitty gritty of sandbox evasion. Mr. Rachwald’s presentation will help the audience gain an overview of various sandboxing techniques, understand current sandbox bypass methods, as well as identify best practices to optimize malware detection.
  • Mandiant's Director, David Damato and Technical Director, Ryan Kazanciyan will be speaking on Wednesday, April 30. Drawing from the speakers’ first-hand experiences and case-studies, this presentation will highlight lessons learned from many years of responding to targeted attacks by nation state actors and other groups.
  • FireEye SVP and COO Kevin Mandia will make a special appearance on Wednesday, April 30 to discuss FireEye’s recent acquisition of Mandiant, as well as to discuss today’s changing threat landscape.
  • The FireEye team will also release the latest findings from Mandiant’s annual M-Trends report and European ATR research report. The results offer visibility into motives, approaches, and different skill levels of attackers both in Europe and around the globe.
  • Participate in FireEye’s photo contest and have the opportunity to win an Apple® gift card worth £250! Look around London and you will see FireEye branded taxis zipping around the city. Grab your camera or smart phone and take a picture of you and the taxi. Submit your photo to helena.brito@fireeye.com and your photo will be posted to FireEye’s Facebook page. You will also be automatically entered into the contest.

FireEye Taxi

Stop by Stand J60 to learn more about the newly expanded FireEye Security Platform, which integrates expertise from Mandiant and is designed to give customers one solution to go from threat alert to remediation. We’ll have live demonstrations of all the new FireEye products. In the mean time, be sure to follow @FireEye for the latest threat research and updates from the company.

We hope to see you in London the week of April 29 through May 1. If you are unable to attend, check back on the blog for interviews and insights from the conference. You can register for a free entry ticket by clicking HERE – your badge will arrive with “FireEye Guest” printed on the bottom.

The Economics of Security

During many of my customer meetings, I often hear security leaders ask the question: “What technology could I remove to free up budget to enable the implementation of FireEye?”

My natural response is to inquire how and when they assess the real value, not the ROI, they get from their existing solutions. Whilst every security solution provides an “ROI” – often a metric based around industry data on how many security “events” they return – this assessment should not focus on noisy “ROI,” but which solution gives your company the most valuable information. Considering the nature and pace of change when it comes to malware and advanced attacks, this is something to validate regularly and involves looking at more factors than a generic ROI tool can factor in.

In a small survey of about 30 European CxOs we ran in December 2013, I asked the question of how they validated the value of security controls, and, surprisingly, at least 36 percent still didn’t conduct any annual assessment.

doyouvalidate

Having spent quite a bit of time looking at analyst models and what exists publically today, the fact that some still don’t conduct these assessments emphasizes that there still isn’t a well-defined model to correlate business value against investment for security solutions.

Take, for example, the outsourced model where Key Performance Indicators (KPIs) are typically established. Too often I hear anecdotal examples where KPIs were based on incidents found; this simply encourages dialing-up the technologies being monitored so that every incident – malicious or not – is tracked and reported, drowning out the ability to identify real threats.

For example, companies investing in big data solutions that gather and equate the millions to billions of events delivered each week to value. However, because they are too resource-constrained to convert these into actionable data, the true value is not extracted and, because doing so in a resource-constrained environment takes so long, the return here would seem extremely poor to a sheer numbers-based evaluation.

However, if the value of said product is measured by the actions taken to mitigate a major security event, that extra time spent executing on a few major items rather than not executing on a large amount of items becomes invaluable to the business. As such, we must blend together the quantitative metrics such as the costs of a solution (capex & opex), incident levels and overlay those values with qualitative insight. These evaluation criterion would look something like the below:

opexcapex

 

  • Noise to incident ratio - What is an acceptable incident to noise (i.e., false positives or irrelevant alerts) ratio?
  • Volume versus impact - We can alert and respond to a million incidents but it’s the one outage of a critical system or breach of business IP or customer records will have a far more significant impact on the business.
  • How actionable is the solution - Critical to an alert is timeliness, how long does it take to identify an incident and what level of human skills are required to interpret the results. Spotting a breach is hard, doing the forensics is harder, and understanding the motives of the attacker is harder still.
  • Business outcome - Did a technology mitigate, reduce or simply delay the business impact. Did it tick a compliance control to avoid penalty fees or did it protect IP & customer data?

In the coming months we are going to delve into the economics of security in greater detail. Whilst there are many tools out there discussing security process and ROI tools showing generic return, we all have limited budget and resources. With the scale and scope of security tools continues to grow we must innovate our thinking, in how we each quantify the value of our investments.

 

 

Annual M-Trends Report Looks Beyond the Breach

Since 2010, Mandiant’s annual threat report, “M-Trends” has provided the industry with in-depth analysis and insight based on hundreds of advanced threat investigations conducted during the previous calendar year for the U.S. government, the defense industrial base and commercial organizations. As a leader in combating advanced threats, FireEye stresses the continuous education that needs to take place in order to be one step ahead of attackers. That is why it is with great excitement that I present the fifth installment of M-Trends.

2013 was an explosive year for the cybersecurity industry; a result of Mandiant’s APT1 report, The New York Times breach, and other organizations coming to the forefront to openly discuss their own incidents. In addition, President Obama discussed concerns about cyber-attacks in his annual State of the Union address. This was a huge step for the industry in terms of bringing advanced attacks to the forefront of the nation, and the world’s, attention.

This year’s report compiles incident response trends from hundreds of clients in more than 30 industry sectors. Some highlights include:

  • The time it takes to detect a compromise continues to improve
    The median number of days it takes an organization to discover a network breach dropped to 229 days in 2013 from 243 in 2012. This improvement is incremental relative to the drop from 416 days in 2011. However, organizations can unknowingly be breached for years. The longest time an attacker operated undetected in a network before being discovered was six years and three months in 2013.
  • Organizations are yet to improve their ability to detect breaches
    In 2012, 37 percent of organizations detected breaches on their own. This number dropped only minimally, to just 33 percent in 2013.
  • Phishing emails largely look to capitalize on trust in IT departments
    44 percent of the phishing emails observed in attacks investigated by Mandiant sought to impersonate the IT departments of the target’s workplace. The vast majority of these emails were sent on Tuesday, Wednesday and Thursday.
  • Political conflicts increasingly have cyber components that impact private organizations
    In the past year, Mandiant responded to an increased number of incidents where political conflicts between nations spawned cyber-attacks that impacted the private sector. Specifically, Mandiant investigated incidents where the Syrian Electronic Army (SEA) compromised external-facing websites and social media accounts of organizations with the primary motive of raising awareness for their political cause.
  • Suspected Iran-based threat actors conduct reconnaissance on energy sector and state governments
    Multiple investigations of suspected Iran-based network reconnaissance activity indicates that threat actors are actively engaging in surveillance activities at energy sector companies and state government agencies. While these suspected Iran-based actors appear less capable than other nation-state actors, nothing stands in the way of them testing and improving their capabilities.

Click here to request a copy of the report.

Let us know your thoughts by leaving a comment below.

Real World vs Lab Testing: The FireEye Response to NSS Labs Breach Detection Systems Report

Today, NSS Labs released a report detailing the performance of several vendors’ ability to detect advanced attacks. We declined to participate in this test because we believe the NSS methodology is severely flawed. In fact, the FireEye product they used was not even fully functional, leveraged an old version of our software and didn’t have access to our threat intelligence (unlike our customers). We did participate in the BDS test in 2013 and at that time we also commented on the flaws of the testing methodology. In fact, we insisted that the only way to properly test was to run in a REAL environment. NSS declined to change their testing methodology so we declined to participate in the most recent test, results of which have been published today. When NSS tested our product a year ago, they used a sample set that included 348 total samples. FireEye detected 201 of 348 total samples. Of the 147 “missed” samples:

  • 11 were non-malicious.
  • 19 were corrupted (as to why other vendors detected these because some vendors scored higher – close to 100% - means that their detection engines are based on hashes which will match regardless of whether the sample is malicious).
  • 117 were duplicates (as to why FireEye didn’t receive credit for detecting these, we never received a response from NSS).

Clearly, nobody could take this approach seriously—it was a major mismatch versus what we see in the wild.

Understanding advanced threats still represents a black hole for many in today’s security industry. The test unfortunately perpetuates a general failure by many to fully understand and appreciate the inner workings of advanced threats that continue to plague organizations despite millions invested in legacy security technologies. In this case, the test contained a number of flaws that security professionals should thoroughly understand before taking these results at face value.

Issue #1: Poor sample selection. Specifically:

  • NSS mostly relied on VirusTotal to download payloads (clear text executable files). The NSS sample set doesn’t include Unknowns, Complex Malware (Encoded/Encrypted Exploit Code & Payload), and APTs. Almost by definition, APTs use new or updated code to bypass detection, which is standard procedure. However, NSS used a known corpus of malware. Advanced threats are in, out, and cleaned-up in minutes. In the past, the malware samples used in the NSS tests were available on VirusTotal (an aside: the oldest sample on VirusTotal is from 2006 and the median sample age is 17.2 months). By contrast, when tests specifically leverage malware samples that are new and unknown, antivirus detection rates fall dramatically. For example, the Imperva study found that antivirus detected only 5% of malware. The other vendors in the NSS report are built for detecting known malware. By relying on VirusTotal, NSS missed out on AK-47s and spent time analyzing pea shooters.
  • Even for Payloads, NSS doesn’t perform Forensics Analysis to understand if the sample is malicious, goodware or corrupt (can’t execute). NSS gives a positive score as long as a vendor sees the sample on the wire, even if the sample is not actually malicious.

 

Issue #2: Differing definitions of advanced malware: Vendors and test agencies differ in how they define advanced malware. The NSS test confused Adware, Spyware, & APTs and accounted for Adware and Spyware as APTs. For instance, some of the NSS tests expected Adware to be classified as malware. In this series of tests, Adware that changes the home page of the browser, but does not infect the system in any other way, must be flagged as malware by a product in order to receive a positive score. FireEye solutions wait for true malicious behavior to avoid false alerts. In the aforementioned case, the page load of the new home page would be analyzed to identify if the change was truly malicious or not.

Issue #3: Poor test methodology. Specifically, the NSS test:

  • Doesn’t account for the use of zero day exploits. There were no zero day exploits in the test sample. This is difficult to do. Testing for zero days requires having a zero day on hand or developing one yourself, which is expensive. Finding new malware that utilizes zero day exploits is where FireEye thrives. In 2013, we found 11 exploitable zero days as well as countless malware campaigns used in cyber espionage, warfare or crime. This year, we have already uncovered two zero days.
  • Did not have access to our security intelligence in the cloud. Unlike our customers, the FireEye appliances were NOT connected to our Dynamic Threat Intelligence cloud to get latest content updates, virtual machines and detection capabilities.

We respect NSS and the work they do—especially for IPS – and their testing methodology for BDS is also more suited to testing IPS products. However, we believe the issues we identified with their evaluation of advanced threats are indicative of the security industry’s broader lack of knowledge regarding sophisticated attacks. FireEye is designed to supplement legacy signature and reputation based technologies to protect against advanced threats—and the NSS tests didn’t properly gauge our capabilities. Our product’s efficacy is proven by how well we protect customers in real-world deployments. Consider that in 2013, FireEye:

  • Found 11 exploitable zero day vulnerabilities, with two uncovered so far in 2014. (By comparison, among the top 10 cyber security companies ranked by security-related revenue, only 2 other zero-day vulnerability were reported in 2013.)
  • Tracked more than 40 million callbacks.
  • Tracked more than 300 separate APT campaigns.
  • Deployed more than 2 million virtual machines globally.

Any lab test is fundamentally unable to replicate the targeted, advanced attacks launched by sophisticated criminal networks and nation-states. The best way to evaluate FireEye is for organizations to deploy our technology in their own environment and they will understand why we are the market leader in stopping advanced attacks. We believe it is erroneous for NSS to compare security efficacy, performance, and cost in the same graphic, because doing so assumes that all three buying criteria are all equally important. In our experience, security efficacy is much more important than the others. In fact, most users and vendors are moving toward a malware prevention, detection, and response architecture.

In August 2013, IDC issued a report, Worldwide Specialized Threat Analysis and Protection 2013–2017 Forecast and 2012 Vendor Shares. This report identified and ranked vendors claiming to stop advanced malware attacks. FireEye was listed as the top vendor based on market share (38%) compared to the nearest competitor with 14% market share. The market is voting with dollars based on their real-world experience while under real-world attacks from advanced threats.

APT1: The State of the Hack One Year Later

A little over a year ago, Mandiant released a report that brought the term “Advanced Persistent Threat” (APT) into the public conversation and made these types of targeted attacks top of mind for government and commercial organizations around the world. Recently, FireEye COO, Kevin Mandia took the stage at RSA USA 2014 to take a look back and share his perspective on the activities that led to the release of the APT1 report and the aftermath.

While the initial report caused a media frenzy, unquestionably, the most important part of the story is the aftermath. Mandiant released the report to elevate the dialogue and address the frustration of organizations that were throwing money at cybersecurity problems and still facing attacks. Yet, the results were not what we expected.

Watch the video below for Kevin’s full speech and feel free to drop a comment below to continue the discussion.