Feeds

Sly new tactic sneaks hackers past security dogs

Advanced evasion techniques can bypass network security, warn experts

SANS - Survey on application security programs

Updated A new hacking technique creates a mechanism for hackers to smuggle attacks past security defences, such as firewalls and intrusion prevention systems.

So-called advanced evasion techniques (AET) are capable of bypassing network security defences, according to net appliance security firm Stonesoft, which was the first to document the approach. Researchers at the Finnish firm came across the attack while testing its security appliance against the latest hacker exploits.

Various evasion techniques including splicing and fragmentation have existed for years. Security devices have to normalise traffic using these approaches before they can inspect payloads and block attacks.

AET take this basic approach to the next level. Traffic is disguised and modified using a variety of evasion techniques in several protocol layers. By bundling IP fragmentation and SMB session mixing together at the same time it's more likely that security defences will correctly handle garbled traffic. And if devices don't recognise combined attacks then it more likely that these assault will make their way past security defences.

AETs are already in circulation on the net as part of targeted attacks and offer a mechanism to bypass network security systems before attacking exposed enterprise servers, according to Stonesoft.

Stonesoft reported its find and sent samples of AETs to Finland's national computer security incident response team (CERT-FI) earlier this month. It also sent samples to ICSA Labs, an independent third-party testing and security product certification division of Verizon Business.

CERT-FI plans to issue an updated advisory on the attack technique later on Monday (18 October). Stonesoft reckons that AETs are a particular problem for firms that still rely on hardware-coded inspection engines, which may be difficult if not impossible to upgrade.

Amichai Shulman, CTO of database security firm Imperva, described the evasion technique as the latest round in the constant cat and mouse game between malicious crackers and security defenders.

"A lot of what attackers are doing today is about evasion at various levels, there is substantial vigilance out there," Shulman commented. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.