230 likes | 368 Views
PandaLabs Evolving Protection. César Saiz Critical Malware department director. Index. Malware trends Real world attacks PandaLabs evolution Current focus Disinfection False positives Behavioral analysis URLs. Malware trends. Malware trends. Malware trends. Malware trends.
E N D
PandaLabsEvolving Protection César Saiz Critical Malware department director
Index • Malware trends • Real world attacks • PandaLabs evolution • Current focus • Disinfection • False positives • Behavioral analysis • URLs
Malware trends Malware goals • Yesterday • Notoriety • Huge spreading • Today • Benefit oriented • Targeted • Tomorrow • More benefit oriented • More targeted
Malware trends Detection challenges • Increasing cost • Polymorphic engines • File-infectors reemerge • Packers and more packers
Malware trends Detection challenges • False positives • Wolf in sheep’s clothing • Generic vs. specific • Long tail malware • Huge variability • Targeted • Short-living ? ?
Real world attack Stuxnet • Exploits 0-day vulnerabilities • Hides using rootkit techniques • Focused on SCADA systems: • Industrial espionage • Hidden industrial processes manipulation • Cyberwar?
! Real world attack !
Real world attack Zeus “mobile edition” • Banker trojan (complete suite) • Supports mobile infection for SMS hidden management Order Security Code SMS forwarding module ZEUS network
Real world attack Transfer order Security Code Security Code Transfer done
PandaLabs evolution • Focus on: • Customers • Comparatives • Critical Malware response team • Automatic Malware processing systems • Deploy Cloud • Plug-ins, backward compatible framework, non PE signatures, new generic signatures, heuristic periodic updates…
Current focus • Disinfection • Automation of malware • Optimized delivery though the cloud • Behavioral analysis • Improved sensors • Improved detection logic
Current focus • False positives: • Increase Goodware knowledge • Enforce quality control • URLs • Increase browsing knowledge • Optimize delivery though the cloud
Current focus Our goal 1 2 3