Since 2010, the UK’s National Security Strategy has rated cyber attacks as a Tier 1 threat to national and economic security.[1] Emergency management agencies in most other industrialized countries have made similar assessments.
Cyber attacks take many forms, from simple denial of service attacks to sophisticated information theft. But one class of attack stands out as the most effective and damaging: advanced persistent threats, or APTs.
As the name implies, APTs are characterized by the following:
- Advanced — able to evade detection
- Persistent — able to move laterally within networks and remain resident to gather information over extended periods of time
While the prevalence and continued success of APTs reflects the increasing sophistication of hackers, they also represent a failure of risk-management calculations.
How APTs Avoid Proper Risk Treatment
I am not arguing that risk management processes are fundamentally broken, or that the professionals implementing them are deficient. After all, these processes usually work well for us in other areas. But three key factors have distorted the inputs to the risk-management calculations. And faulty inputs lead to faulty calculations.
Factor No. 1: Most Malware is not Targeted
Web and email vectors account for almost all malware, and most of it is indiscriminate. A mid-sized organization is exposed to thousands of malware attacks a month. This constant barrage creates a lot of background noise, and true APTs get lost in the clamor.
Factor No.2: The Impact of Most Malware is Trivial
The most visible malware payloads are fake anti-virus (AV) suites, SMTP mass mailers and aggressive adware. Even the ubiquitous Zeus Trojan is often dismissed as having a small business impact when it targets personal bank accounts. When impact calculations aggregate the impact of all malware (or all observed malware, anyway), the average is small, understating the devastation that can result from just one outlier.
Factor No. 3: The Effectiveness of Existing Controls is Overestimated
Some organizations take comfort in having deployed anti-malware technology to treat this risk. They often assume, incorrectly, that a good AV suite will stop most malware. In fact, AV was designed for (and still works best with) threats that change infrequently and have a very wide distribution — the polar opposite of an APT.
Others place faith in desktop controls such as limited account privileges and application whitelisting. But today, even the most basic malware can easily escalate privileges and hijack or masquerade as legitimate system processes.
Conventional methodologies to measure the effectiveness of these controls have not kept pace with the rapid evolution of cyber threats. This widening gap can allow inadequate controls to escape scrutiny.
The Effect on Risk Management Calculations
The highly simplified model of risk assessment below illustrates how these factors conspire to distort our risk-management calculations and leave us vulnerable.
This problem occurs when we conflate all malware as a single threat for risk-assessment purposes. A better approach is to demarcate malware into different classes of risk and assess them separately. When examining APTs in isolation, the calculation is no longer distorted. Suddenly, the elevated risk is clear.
The Search for Better Malware Controls
So we have established that the impact of APTs is much higher than we previously calculated and that our current controls are less effective than we thought. That leads to the question of whether better or additional controls are available to help us.
To fight APTs, defenses must have the following features:
- Signature-less controls
- Exploit detection
- Actionable intelligence without noise
The importance of these features is detailed below.
Signature-less Controls
Reliance on signatures, databases, lists, or any other form of prior knowledge will not counter the APT threat. New controls must be signature-less, able to detect new and evolving malware.
Exploit Detection
Detecting and understanding the exploit is critical. All subsequent phases of an attack can be obfuscated or encrypted, rendering existing controls against executables and callbacks useless. If you miss the exploit, you miss the attack. Controls must detect APT exploits even when they are zero-day or heavily obfuscated. And at a minimum, they must cover the two main exploit vectors: websites and emailed documents.
Actionable Intelligence without Noise
New controls must add actionable intelligence without increasing the overhead on already-overstretched security teams. They must also help analyze the root cause so that the frequency of malware infections can be reduced over time.
Fortunately, the FireEye Threat-Protection Platform, powered by the Multi-Vector Virtual Execution (MVX) engine, offers these very features. To learn more about how FireEye can bolster your risk-management strategy, download our free white paper “Risk Management by Automating the SANS 20 Critical Security Controls.”
[1] The UK Cyber Security Strategy






