Feeds

Are you serious about security?

Consider anti-reconnaissance tools

SANS - Survey on application security programs

Hurwitz & Associates has been running an IT security campaign: "AVID: Anti-Virus Is Dead" for some time. The argument is based on the principle that blacklists of signatures—small files that contain a unique string of bits, or the binary pattern, that identifies all or part of a virus—do not, and cannot, provide adequate protection against viruses. This is because the signature files can only be written once a virus or other form of malicious software program has been identified. When a new malware program is discovered, the race is on to write a signature file for protecting against that virus. It's like putting a plaster on an open wound, rather than taking care not to get cut in the first place.

Signatures provide ineffective defence against malware such as viruses, unless the exact variant of that malware has been seen before and a specific signature has been made available. Nevertheless, signatures are widely used in security applications. They are used extensively by technology vendors offering intrusion detection and prevention systems (IDSs and IPSs). And they don't work there, either.

Many also employ heuristics—the application of experience-derived knowledge based on the way that particular software applications behave. This type of capability is useful since most malicious software applications adhere to some fairly common characteristics. Because of this, they do a better job at catching unknown threats than signatures, but they have the drawback that they can throw up a large proportion of false positives—that is, where a benign application is flagged as malignant.

When hackers try to attack or intrude on a target, they first try to find out as much as they can about that target. They "case the network", looking to gain as much information about their intended victim as possible: the operating system and applications being used, which versions of software are running, what patches have been applied and so on. Armed with this sort of information, a hacker can plan a more effective attack.

Anti-reconnaissance technology

With this in mind, an improved approach is to deploy a perimeter defense system that intercepts penetration testing attacks as they occur, concealing network resources from the hacker and sending back false information. This defense is known as anti-reconnaissance technology.

To quote Sun Tzu, "All warfare is based on deception. Hence, when able to attack, we must seem unable; when using our forces, we must seem inactive; when we are near, we must make the enemy believe we are far away; when far away, we must make him believe we are near."

Anti-reconnaissance technology takes this principle and applies it to protection of the network. There are only so many reconnaissance tools that can be used to scan a network, such as port scans or BIOS probes, so such probes are relatively easy to identify. Anti-reconnaissance technology works by placing a virtual server in front of the network, intercepting all reconnaissance traffic and responding to attacks on behalf of the network. In this way, the hacker is fed seemingly real data, so they are fooled into believing that the real network is responding, rather than a virtual server that is shielding the network.

Arxceo

Technology vendor Arxceo Corporation, a pioneer in this space, provides anti-reconnaissance appliances that sit in front of network devices, obfuscating the real network and sending responses back to an attacker so that they think they have managed to hit a real network, or dropping attacks into "black holes". For example, a common exploit used by a hacker is a SYN (synchronization) scan, which is used to determine which ports are open on a network. A hacker does this by sending a SYN packet to every port on the server. If the server sends back a SYN/ACK (synchronization acknowledgment) packet from a particular port, the hacker will believe that the port in question is open and can therefore be attacked. By sending multiple SYN packets to the server, a server can quickly become overwhelmed and a denial of service attack can be achieved.

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.