Feeds

Are you serious about security?

Consider anti-reconnaissance tools

Choosing a cloud hosting partner with confidence

Hurwitz & Associates has been running an IT security campaign: "AVID: Anti-Virus Is Dead" for some time. The argument is based on the principle that blacklists of signatures—small files that contain a unique string of bits, or the binary pattern, that identifies all or part of a virus—do not, and cannot, provide adequate protection against viruses. This is because the signature files can only be written once a virus or other form of malicious software program has been identified. When a new malware program is discovered, the race is on to write a signature file for protecting against that virus. It's like putting a plaster on an open wound, rather than taking care not to get cut in the first place.

Signatures provide ineffective defence against malware such as viruses, unless the exact variant of that malware has been seen before and a specific signature has been made available. Nevertheless, signatures are widely used in security applications. They are used extensively by technology vendors offering intrusion detection and prevention systems (IDSs and IPSs). And they don't work there, either.

Many also employ heuristics—the application of experience-derived knowledge based on the way that particular software applications behave. This type of capability is useful since most malicious software applications adhere to some fairly common characteristics. Because of this, they do a better job at catching unknown threats than signatures, but they have the drawback that they can throw up a large proportion of false positives—that is, where a benign application is flagged as malignant.

When hackers try to attack or intrude on a target, they first try to find out as much as they can about that target. They "case the network", looking to gain as much information about their intended victim as possible: the operating system and applications being used, which versions of software are running, what patches have been applied and so on. Armed with this sort of information, a hacker can plan a more effective attack.

Anti-reconnaissance technology

With this in mind, an improved approach is to deploy a perimeter defense system that intercepts penetration testing attacks as they occur, concealing network resources from the hacker and sending back false information. This defense is known as anti-reconnaissance technology.

To quote Sun Tzu, "All warfare is based on deception. Hence, when able to attack, we must seem unable; when using our forces, we must seem inactive; when we are near, we must make the enemy believe we are far away; when far away, we must make him believe we are near."

Anti-reconnaissance technology takes this principle and applies it to protection of the network. There are only so many reconnaissance tools that can be used to scan a network, such as port scans or BIOS probes, so such probes are relatively easy to identify. Anti-reconnaissance technology works by placing a virtual server in front of the network, intercepting all reconnaissance traffic and responding to attacks on behalf of the network. In this way, the hacker is fed seemingly real data, so they are fooled into believing that the real network is responding, rather than a virtual server that is shielding the network.

Arxceo

Technology vendor Arxceo Corporation, a pioneer in this space, provides anti-reconnaissance appliances that sit in front of network devices, obfuscating the real network and sending responses back to an attacker so that they think they have managed to hit a real network, or dropping attacks into "black holes". For example, a common exploit used by a hacker is a SYN (synchronization) scan, which is used to determine which ports are open on a network. A hacker does this by sending a SYN packet to every port on the server. If the server sends back a SYN/ACK (synchronization acknowledgment) packet from a particular port, the hacker will believe that the port in question is open and can therefore be attacked. By sending multiple SYN packets to the server, a server can quickly become overwhelmed and a denial of service attack can be achieved.

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.