“Be the Change.” Test Methodologies for Advanced Threat Prevention Products

Organizations are under assault by a new generation of cyber attacks that easily evade traditional defenses. These coordinated campaigns are targeted. They are stealthy. And they are persistent. Many exploit zero-day vulnerabilities and orchestrate attacks across multiple vectors (Web, email, file, mobile). The threat actors are dead set on finding an organization’s weaknesses, finding their way into the systems, and stealing intellectual property. Guarding against these advanced threats necessitates, nay demands, a fundamentally different approach to threat defense. Importantly, this is even more true for testing methodologies used to validate the efficacy of these products. This is because legacy test methodologies were developed to test the efficacy of legacy security products that are signature-based and designed to detect known malware and known vulnerabilities – not the advanced threat landscape!

Before we define a good test methodology for advanced security products, it is important to establish what advanced security products must do - for only when we know what the products must accomplish will we know how to test them.

Continue reading »