Feeds

Sly new tactic sneaks hackers past security dogs

Advanced evasion techniques can bypass network security, warn experts

Choosing a cloud hosting partner with confidence

Updated A new hacking technique creates a mechanism for hackers to smuggle attacks past security defences, such as firewalls and intrusion prevention systems.

So-called advanced evasion techniques (AET) are capable of bypassing network security defences, according to net appliance security firm Stonesoft, which was the first to document the approach. Researchers at the Finnish firm came across the attack while testing its security appliance against the latest hacker exploits.

Various evasion techniques including splicing and fragmentation have existed for years. Security devices have to normalise traffic using these approaches before they can inspect payloads and block attacks.

AET take this basic approach to the next level. Traffic is disguised and modified using a variety of evasion techniques in several protocol layers. By bundling IP fragmentation and SMB session mixing together at the same time it's more likely that security defences will correctly handle garbled traffic. And if devices don't recognise combined attacks then it more likely that these assault will make their way past security defences.

AETs are already in circulation on the net as part of targeted attacks and offer a mechanism to bypass network security systems before attacking exposed enterprise servers, according to Stonesoft.

Stonesoft reported its find and sent samples of AETs to Finland's national computer security incident response team (CERT-FI) earlier this month. It also sent samples to ICSA Labs, an independent third-party testing and security product certification division of Verizon Business.

CERT-FI plans to issue an updated advisory on the attack technique later on Monday (18 October). Stonesoft reckons that AETs are a particular problem for firms that still rely on hardware-coded inspection engines, which may be difficult if not impossible to upgrade.

Amichai Shulman, CTO of database security firm Imperva, described the evasion technique as the latest round in the constant cat and mouse game between malicious crackers and security defenders.

"A lot of what attackers are doing today is about evasion at various levels, there is substantial vigilance out there," Shulman commented. ®

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.