Feeds

Sly new tactic sneaks hackers past security dogs

Advanced evasion techniques can bypass network security, warn experts

SANS - Survey on application security programs

Updated A new hacking technique creates a mechanism for hackers to smuggle attacks past security defences, such as firewalls and intrusion prevention systems.

So-called advanced evasion techniques (AET) are capable of bypassing network security defences, according to net appliance security firm Stonesoft, which was the first to document the approach. Researchers at the Finnish firm came across the attack while testing its security appliance against the latest hacker exploits.

Various evasion techniques including splicing and fragmentation have existed for years. Security devices have to normalise traffic using these approaches before they can inspect payloads and block attacks.

AET take this basic approach to the next level. Traffic is disguised and modified using a variety of evasion techniques in several protocol layers. By bundling IP fragmentation and SMB session mixing together at the same time it's more likely that security defences will correctly handle garbled traffic. And if devices don't recognise combined attacks then it more likely that these assault will make their way past security defences.

AETs are already in circulation on the net as part of targeted attacks and offer a mechanism to bypass network security systems before attacking exposed enterprise servers, according to Stonesoft.

Stonesoft reported its find and sent samples of AETs to Finland's national computer security incident response team (CERT-FI) earlier this month. It also sent samples to ICSA Labs, an independent third-party testing and security product certification division of Verizon Business.

CERT-FI plans to issue an updated advisory on the attack technique later on Monday (18 October). Stonesoft reckons that AETs are a particular problem for firms that still rely on hardware-coded inspection engines, which may be difficult if not impossible to upgrade.

Amichai Shulman, CTO of database security firm Imperva, described the evasion technique as the latest round in the constant cat and mouse game between malicious crackers and security defenders.

"A lot of what attackers are doing today is about evasion at various levels, there is substantial vigilance out there," Shulman commented. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.