34
EMERGING THREATS & THREAT LANDSCAPE Fighting Today’s Cybercrime Anthony Arrott, Trend Micro

Arrott Htcia St Johns 101020

Embed Size (px)

Citation preview

Page 1: Arrott Htcia St Johns 101020

EMERGING THREATS & THREAT LANDSCAPE

Fighting Today’s CybercrimeAnthony Arrott,Trend Micro

Page 2: Arrott Htcia St Johns 101020

Triple challenge to IT security

• Changing ITBEFORE:80%+ of daily info available inside the enterpriseNOW:80%+ of daily info comes from outside the enterprise

• Changing cybercrimeBEFORE:vandalism, simple fraud, opportunistic data theftNOW:high tech organized crime for huge profits

• Changing protectionBEFORE:latest threat info deployed to each computerNOW:computers query a cloud database about suspected threats

1

Page 3: Arrott Htcia St Johns 101020

Triple challenge to IT security

• Changing ITBEFORE:80%+ of daily info available inside the enterpriseNOW:80%+ of daily info comes from outside the enterprise

• Changing cybercrimeBEFORE:vandalism, simple fraud, opportunistic data theftNOW:high tech organized crime for huge profits

• Changing protectionBEFORE:latest threat info deployed to each computerNOW:computers query a cloud database about suspected threats

disappearing network boundaries

1

Page 4: Arrott Htcia St Johns 101020

Triple challenge to IT security

• Changing ITBEFORE:80%+ of daily info available inside the enterpriseNOW:80%+ of daily info comes from outside the enterprise

• Changing cybercrimeBEFORE:vandalism, simple fraud, opportunistic data theftNOW:high tech organized crime for huge profits

• Changing protectionBEFORE:latest threat info deployed to each computerNOW:computers query a cloud database about suspected threats

disappearing network boundaries

overwhelming volume of threat

1

Page 5: Arrott Htcia St Johns 101020

Triple challenge to IT security

• Changing ITBEFORE:80%+ of daily info available inside the enterpriseNOW:80%+ of daily info comes from outside the enterprise

• Changing cybercrimeBEFORE:vandalism, simple fraud, opportunistic data theftNOW:high tech organized crime for huge profits

• Changing protectionBEFORE:latest threat info deployed to each computerNOW:computers query a cloud database about suspected threats

disappearing network boundaries

overwhelming volume of threat

cloud-client protection networks

1

Page 6: Arrott Htcia St Johns 101020

Traditional AVoverwhelmed by the volume of new threats

4

AV

> 2000new threats

per hour

> 2000new threats

per hour

Page 7: Arrott Htcia St Johns 101020

Threats now mostly from the Internet

5

How threats arrive on PCs

1. Visits to malicious websites

( 42% )2. Downloaded by other

malware( 34% )

3. E-mail attachments & links

( 9% )4. Transfers from

removable disks( 8% )

5. Other (mostly via Internet)

( 7% )

source: Trend Micro

Page 8: Arrott Htcia St Johns 101020

AV

Use multiple layers of reputation services

4

Exposure Layerinspection based on source (URL, domain)

http://abc.com/xyz.exe

Infection Layerinspection based on file

content (code, hash)

Infection Layerinspection based on file

content (code, hash)

http://abc.com/xyz.exe

Page 9: Arrott Htcia St Johns 101020

9

John Dillinger,Flamboyant Bank Robber

Meyer Lansky,Quiet Mobster

Page 10: Arrott Htcia St Johns 101020

10

John Dillinger,Flamboyant Bank Robber

Meyer Lansky,Quiet Mobster

• 8 years in prison• killed by US

federal agents• died age 31

Page 11: Arrott Htcia St Johns 101020

11

John Dillinger,Flamboyant Bank Robber

Meyer Lansky,Quiet Mobster

• 8 years in prison• killed by US

federal agents• died age 31

• 0 years in prison• listed in Forbes 400

richest Americans• died age 80

Page 12: Arrott Htcia St Johns 101020

12

John Dillinger,Flamboyant Bank Robber

Meyer Lansky,Quiet Mobster

• 8 years in prison• killed by US

federal agents• died age 31

think: VIRUS OUTBREAK

• 0 years in prison• listed in Forbes 400

richest Americans• died age 80

Page 13: Arrott Htcia St Johns 101020

13

John Dillinger,Flamboyant Bank Robber

Meyer Lansky,Quiet Mobster

• 8 years in prison• killed by US

federal agents• died age 31

think: VIRUS OUTBREAK

think: BOTNET SPAM ENGINE

• 0 years in prison• listed in Forbes 400

richest Americans• died age 80

Page 14: Arrott Htcia St Johns 101020

Popular conception of cybercrime

Page 15: Arrott Htcia St Johns 101020

But like Prohibition, we’re not the main victims …

… more likely, we’re unwitting accessories.

Page 16: Arrott Htcia St Johns 101020

Today‘s Infection Chain

Spyware/TrojanDownloader

Web Drive ByDownloader

Email Spam

Port ScanVulnerabilities

Infection Vector

Spam & Phishing

Dedicated Denial of Service

Data Leakage

Adware/Clickware

Recruitment

Activities

MalwareWriter

Wait for Instructions

Get Updates from Command & Control

Fool the AV HostManagement

HostInfection

HTTPIRCDNS

BotHerder

Botnet

Command &Controller

Criminals

Page 17: Arrott Htcia St Johns 101020

Canadian IP addresses generating spam

Page 18: Arrott Htcia St Johns 101020

Worldwide IP addresses generating spam

Q22009

Q32009

Q42009

Q12010

Page 19: Arrott Htcia St Johns 101020

19

Breakdown of compromised IP’s

Business

Consumer

EMAIL REPUTATION

Page 20: Arrott Htcia St Johns 101020

Top 5 spam generators as of April 2009

Page 21: Arrott Htcia St Johns 101020

Top 5 spam generators as of April 2009

Turkey ? #2 ?

Page 22: Arrott Htcia St Johns 101020

Top 5 spam generators as of April 2009

Trend Micro begins working with Turkish ISP

Page 23: Arrott Htcia St Johns 101020

Top 5 spam generators as of April 2009

Start seeing dramatic reductions

Page 24: Arrott Htcia St Johns 101020

Top 5 spam generators as of April 2009

Turkey: from #2 to #21

Page 25: Arrott Htcia St Johns 101020

Popular conception of cybercrime

Page 26: Arrott Htcia St Johns 101020

Not just botnet spam engines

Page 27: Arrott Htcia St Johns 101020

… and no small amount of money

Online ad revenues ofGoogle, Yahoo, Microsoft, & AOLare more than $8b per quarter …

… click fraud is more than $5b per year.

Page 28: Arrott Htcia St Johns 101020

Obscured network boundaries

Where’s my data?

Page 29: Arrott Htcia St Johns 101020

Deceptive information transactions

Who am I sharing information with?

Page 30: Arrott Htcia St Johns 101020

Disguised website identities

Is this the web address I think it is?

Page 31: Arrott Htcia St Johns 101020

and track cyber-criminal operations

Page 32: Arrott Htcia St Johns 101020

… billions of times a day

E-mail reputation queries

6.2 billionE-mail reputation blocks

4.4 billion

Web reputation queries

41 billionWeb reputation blocks

585 million

Trend MicroSmart Protection NetworkTuesday, 14 Sep. 2010

Page 33: Arrott Htcia St Johns 101020

Protection from the Cloud

E-mail (IP) Reputation Load295 GB per day

Web (URL) Reputation Load1305 GB per day

File (MD5) Reputation Load334 GB per day

Page 34: Arrott Htcia St Johns 101020

Trend Micro internal use only34

Thank You