<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Charles Kolodgy, Author at Security Current</title>
	<atom:link href="/author/charles-kolodgy/feed/" rel="self" type="application/rss+xml" />
	<link>/author/charles-kolodgy/</link>
	<description>Security Current improves the way security, privacy and risk executives around the world collaborate to protect their organizations and their information. Its CISO-driven proprietary content and events provide insight, actionable advice and analysis giving executives the latest information to make knowledgeable decisions.</description>
	<lastBuildDate>Wed, 03 Jan 2018 01:21:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2020/09/cropped-Security-Current-Round-Logo-32x32.png</url>
	<title>Charles Kolodgy, Author at Security Current</title>
	<link>/author/charles-kolodgy/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Security as a Proactive Business Tool</title>
		<link>/security-as-a-proactive-business-tool/</link>
					<comments>/security-as-a-proactive-business-tool/#respond</comments>
		
		<dc:creator><![CDATA[Charles Kolodgy]]></dc:creator>
		<pubDate>Fri, 15 Nov 2013 19:33:59 +0000</pubDate>
				<category><![CDATA[Archived Articles]]></category>
		<guid isPermaLink="false">http://184.154.4.181/?p=17151</guid>

					<description><![CDATA[<p>IT security is a complicated issue.  However, the focus on what security can do, can&#8217;t do, and how it is perceived, ordinarily is narrow.  Generally, managers deal with security in&#8230;</p>
<p>The post <a href="/security-as-a-proactive-business-tool/">Security as a Proactive Business Tool</a> appeared first on <a href="https://securitycurrent.com">Security Current</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecuritycurrent.com%2Fsecurity-as-a-proactive-business-tool%2F&amp;linkname=Security%20as%20a%20Proactive%20Business%20Tool" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecuritycurrent.com%2Fsecurity-as-a-proactive-business-tool%2F&amp;linkname=Security%20as%20a%20Proactive%20Business%20Tool" title="LinkedIn" rel="nofollow noopener" target="_blank"></a></p><p>IT security is a complicated issue.  However, the focus on what security can do, can&#8217;t do, and how it is perceived, ordinarily is narrow.  Generally, managers deal with security in silos.  When a threat exists or appears, the manager’s answer is to use a product as a defensive response, or to add a security policy/procedure to mitigate the threat.  From an IT perspective, this approach works just fine when dealing with a specific threat, but from a business perspective, it may not provide value to the enterprise.</p>
<p>From a business perspective, security is either considered a cost, with the only benefit being that money, or more likely an intangible asset, is saved through prevention of a security breach or by meeting some compliance requirement.  In the case of meeting compliance requirements, security is still considered a cost, and one you just try to minimize, as you do on insurance, electricity or rent. However, security costs should be considered a positive for an enterprise.  Security should enable an enterprise to run a function or service that wouldn&#8217;t be possible otherwise due to security concerns.  Indeed, there is another way to look at IT security that hasn’t been given much thought in the past. IDC, the market intelligence and advisory provider, suggests that security should be approached as a business benefit to the enterprise in competitive environments.</p>
<p>The point is that security can provide a business with competitive advantages. Security allows you to be better than your business competitors.  If you and your competitors must meet certain security standards, such as PCI, and if your business can do it more efficiently than your competition, a business can gain a competitive advantage.</p>
<p>Another competitor that an enterprise might not be aware of is an attacker searching for your data.  Attackers either want to steal your money, proprietary data, or protected information (e.g. credit card numbers).  They are competing for these assets, which you want to protect from disclosure, just as you protect your business specific information. Attackers may want your resources to secretly use your servers, email resources or storage.  The reason attackers have become competitors to businesses is that they are no longer independent hackers working alone. Rather, they are business entities motivated by profit.  An attacker ecosystem has been established that has divisions of labor and many elements that are being run as a business.  This &#8220;hacker economy&#8221; has the same goal as all businesses &#8211; to maximize profits.</p>
<p>IDC believes one reason the attacker ecosystem works is that the security industry perceives hackers by nature as &#8220;bad&#8221; or &#8220;evil.&#8221;  The security industry should move beyond this idea because this concept makes the security challenge much more difficult.  There is no discounting that there are still some people out there who are motivated by malice, but they are becoming rare.  Since many people still think of attackers this way, they are giving them much more power than they deserve.</p>
<p>No matter how many systems you put in place, you are not going to <strong><em>deter</em></strong> evil people.  They are going to continue to assault vulnerable targets and cause havoc.  However, if you think of the attacker as just another businessman (although an immoral one) you can now create a deterrent that is based on risk management, cost-reward and other business concepts.  With an evil hacker, you need to put up as many defenses as possible. In contrast, with a competitive attacker you need to implement best practices with a logical security posture that makes the cost of the attack greater than the value of the results.</p>
<p>When security is considered as a competitive endeavor, it’s possible to make logical proactive decisions, and not just be reactive.  It’s time for enterprises and security professionals to take on this challenge to use security to provide competitive advantages against all types of competitors.  The current economic environment is the perfect opportunity to stop looking for the boogeyman and instead look for a competitor.</p>
<div class="links"></div>
<div id="disqusWrapper">
<div id="disqus_thread"><iframe id="dsq-app322" tabindex="0" title="Disqus" src="https://disqus.com/embed/comments/?base=default&amp;f=securitycurrent&amp;t_u=http%3A%2F%2Fwww.securitycurrent.com%2Fen%2Fanalysis%2Fac_analysis%2Fsecurity-as-a-proactive-business-tool&amp;t_d=Security%20as%20a%20Proactive%20Business%20Tool&amp;t_t=Security%20as%20a%20Proactive%20Business%20Tool&amp;s_o=default#version=0f0a865317e99ed65c3b6704321fb8c2" name="dsq-app322" width="100%" height="150" frameborder="0" scrolling="no" data-mce-fragment="1"></iframe></div>
</div>
<p>The post <a href="/security-as-a-proactive-business-tool/">Security as a Proactive Business Tool</a> appeared first on <a href="https://securitycurrent.com">Security Current</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>/security-as-a-proactive-business-tool/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Defending Against Custom Malware: The Rise of STAP</title>
		<link>/defending-against-custom-malware-the-rise-of-stap/</link>
					<comments>/defending-against-custom-malware-the-rise-of-stap/#respond</comments>
		
		<dc:creator><![CDATA[Charles Kolodgy]]></dc:creator>
		<pubDate>Wed, 23 Oct 2013 19:53:38 +0000</pubDate>
				<category><![CDATA[Archived Articles]]></category>
		<guid isPermaLink="false">http://184.154.4.181/?p=17165</guid>

					<description><![CDATA[<p>How do you defend against something that&#8217;s never been seen before?  That&#8217;s the key question organizations struggle with.  A decade ago, the first victims of any worm or virus outbreak&#8230;</p>
<p>The post <a href="/defending-against-custom-malware-the-rise-of-stap/">Defending Against Custom Malware: The Rise of STAP</a> appeared first on <a href="https://securitycurrent.com">Security Current</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecuritycurrent.com%2Fdefending-against-custom-malware-the-rise-of-stap%2F&amp;linkname=Defending%20Against%20Custom%20Malware%3A%20The%20Rise%20of%20STAP" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecuritycurrent.com%2Fdefending-against-custom-malware-the-rise-of-stap%2F&amp;linkname=Defending%20Against%20Custom%20Malware%3A%20The%20Rise%20of%20STAP" title="LinkedIn" rel="nofollow noopener" target="_blank"></a></p><p>How do you defend against something that&#8217;s never been seen before?  That&#8217;s the key question organizations struggle with.  A decade ago, the first victims of any worm or virus outbreak had difficulty defending against a brand-new threat, leaving resources vulnerable until the attack could be detected and signatures created.  Today the ultimate problem is the same, but the level of difficulty is considerably higher.  Attacks used to be massive and indiscriminate, trying to catch anyone that had the vulnerability exploited by the malware.  Once the new attack was discovered, one set of defenses could be deployed to neutralize the threat.  Organizations that were not exploited would receive updated signatures to allow their perimeter and endpoint defenses to thwart the threat.</p>
<p>The environment has evolved from quick smash-and-grab tactics which exploit targets of opportunity to one that has targets of choice.  Actors such as criminal organizations and nation states are interested in the long haul.  They create specialized malware, intended for a specific target or groups of targets, with the ultimate goal of becoming embedded in the target&#8217;s infrastructure.  These threats are nearly always new and never seen before.  This malware is targeted, polymorphic, and dynamic.  It can be delivered via Web page, spear-phishing email, or any other number of avenues. The ultimate goal is typically data exfiltration, which lends itself to a low and slow approach where attacks can go unnoticed for long periods of time. In the example of the Shady RAT attack, intrusions went unnoticed for years. The desktop is typically not the ultimate target for an attack, but rather an entry point from which to escalate privileges and move laterally throughout the target organization, all without being detected. When coupling zero-day exploits and zero-day malware, attackers have an enormous head start against traditional defenses.</p>
<p>While methods vary, the commonality of these attacks is they are created to avoid detection by mainstream security technologies, such as antivirus, firewalls, and content inspection gateways. Following the emergence of these specialized threats, a new category of security technology aimed at detecting, analyzing, and preventing these threats has emerged.  IDC is defining this market as Specialized Threat Analysis and Protection (STAP).  Products within this market must use a predominantly signature-less technology (i.e., sandboxing, emulation, big data analytics, containerization) to detect malicious activity. These solutions can be based at the network level, on the endpoint, or both, and scan both inbound and outbound traffic for anomalies including botnet and command and control traffic. This market also includes products that allow for the reverse engineering and forensic analysis of discovered malware.</p>
<p>This new category leverages a variety of techniques to collect information around behavior, communication, activity, reputation, and other factors in order to detect the seemingly undetectable.  Many of the products in this category attempt to solve the same problem (or some aspect of the same problem) by leveraging a different core technology.  IDC puts the products into three general categories:</p>
<ul>
<li><strong>Virtual sandboxing/emulation and behavioral analysis</strong> are increasingly being deployed to detect advanced malware. Since the targeted malware is designed to avoid signature based defenses, determining how the file will behave becomes increasingly important. Suspicious files can be sent to a virtual environment (either locally or in the cloud) where activity is analyzed to determine if registry keys are modified, processes are changed, or unexpected outbound communication is attempted.  Finally, network traffic can be monitored for anomalous behavior, such as communications with command and control servers or with other resources on, or segments of the network that are outside the bounds of normal activity.</li>
<li><strong>Virtual containerization/isolation</strong> addresses the threat of advanced attacks from the endpoint. Solutions that follow this framework essentially forgo trying to prevent malware from breaching the organization but work to prevent malicious activity by limiting Internet connectivity or ration system resources.  Applications and tasks are segmented and verified.  When malicious activities occur, the segmentation can be locked down to prevent the malware from spreading or &#8220;phoning home.&#8221;  Eventually the malware can be removed from the environment and evaluated fully.</li>
<li><strong>Advanced system scanning</strong> also focuses on the endpoint, but rather than segmenting resources, lightweight agents examine system behavior for signs of malicious activity. This can be done by watching the operating system for registry modifications, questionable processes, or other signs, or by analyzing the actual physical memory for malicious activity. These solutions are designed to be lightweight so as to not impact performance and retain a stealthy posture on the device to prevent the malware&#8217;s own stealth defense mechanisms from kicking in.</li>
</ul>
<p>When dealing with advanced malware there is no magic bullet.  However solutions must be put into context on what they provide.  They need to be able to identify the malware as quickly as possible in order to limit the damage.  The deployment of the products must center on the discussion of protecting data and critical assets.  The safest course of action is to assume that a breach will occur and determine how best to limit the damage.  As is often the case with security, the best defense is multilayered, and STAP is no different.  The best solution is a combination of technologies that focus on preventing malware from entering the network, monitor internal traffic for lateral movement and egress traffic for command and control communications as well as data exfiltration, and leverage strong forensics capabilities to facilitate quick remediation. However, the deployment of that combination of technologies would be incredibly expensive, so a thorough evaluation of the existing infrastructure is necessary to determine what type of deployment would be most efficient at protecting the largest number of resources and limiting the most exposure.</p>
<p>Enterprises must not consider STAP as an immediate replacement for existing security technologies. Rather, STAP should be viewed as an evolution of the layered security, or &#8220;belt-and-suspenders 2.0.&#8221; When used in concert with the existing security infrastructure — IPS, firewalls, anti-virus, Web/email gateways, and endpoint protection suites — STAP can help decrease infection rates by identifying the unknown before it becomes a problem.</p>
<p>The post <a href="/defending-against-custom-malware-the-rise-of-stap/">Defending Against Custom Malware: The Rise of STAP</a> appeared first on <a href="https://securitycurrent.com">Security Current</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>/defending-against-custom-malware-the-rise-of-stap/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
