the threat landscape jan 2013. 2013 threat report 2

27
The Threat Landscape Jan 2013

Upload: christopher-hadsall

Post on 22-Dec-2015

219 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The Threat Landscape Jan 2013. 2013 Threat Report 2

The Threat LandscapeJan 2013

Page 2: The Threat Landscape Jan 2013. 2013 Threat Report 2

2013 Threat Report

2

Page 3: The Threat Landscape Jan 2013. 2013 Threat Report 2

4

1. Threat VolumeSophosLabs see 250,000 new files each day

250,000previously unseen files

received each day within SophosLabs

Page 4: The Threat Landscape Jan 2013. 2013 Threat Report 2

2. The malicious webWeb servers are under constant attack. A new malicious URL every couple of seconds

20-30kmalicious URLs seen each day. This is almost a new

malicious URL every 2 secs

Page 5: The Threat Landscape Jan 2013. 2013 Threat Report 2

6

3. Professionalism, crimeware‘Monetization’ : the bulk of today’s threats are automated, coordinated & professional

Page 6: The Threat Landscape Jan 2013. 2013 Threat Report 2

Case study 1: Drive-by downloads

7

Page 7: The Threat Landscape Jan 2013. 2013 Threat Report 2

Controlling user traffic

• Inject redirects into legitimate sites

Web threats are all about controlling user web traffic

80%of malicious URLs are actually legitimate sites

that have been compromised

Page 8: The Threat Landscape Jan 2013. 2013 Threat Report 2

It’s all about trafficDistribution of today’s web threats (2012 H1)

Page 9: The Threat Landscape Jan 2013. 2013 Threat Report 2

Drive-by downloadsCompromising legitimate websites to drive user traffic to malware

Page 10: The Threat Landscape Jan 2013. 2013 Threat Report 2

Drive-by downloadsCompromising legitimate websites to drive user traffic to malware

Page 11: The Threat Landscape Jan 2013. 2013 Threat Report 2

Drive-by downloadsCompromising legitimate websites to drive user traffic to malware

“Monetizatio

n”

Page 12: The Threat Landscape Jan 2013. 2013 Threat Report 2

Drive-by downloadsCompromising legitimate websites to drive user traffic to malware

URL filtering

Content detection

Page 13: The Threat Landscape Jan 2013. 2013 Threat Report 2

Case study 2: Ransomware

14

Page 14: The Threat Landscape Jan 2013. 2013 Threat Report 2

RansomwareMulti-lingual!

15

Page 15: The Threat Landscape Jan 2013. 2013 Threat Report 2

Ransomware

• Malware that locks/encrypts user data• Pay ransom to access files

16

Simple• Password

protected archives

Medium• XOR• shift

Complex• RC4• Public key crypto

Recover data?

Page 16: The Threat Landscape Jan 2013. 2013 Threat Report 2

Blackhole payloads

Zbot25%

Ransomware18%PWS

12%Sinowal11%

FakeAV11%

Backdoor6%

ZeroAccess6%

Downloader2%

Other9%

Payload distribution (late 2012)

17

Page 17: The Threat Landscape Jan 2013. 2013 Threat Report 2

Case study 3: Android Threats

18

Page 18: The Threat Landscape Jan 2013. 2013 Threat Report 2

19

Mobile OS market (US)What will mobile malware target?

Page 19: The Threat Landscape Jan 2013. 2013 Threat Report 2

Android ApplicationsSignificant growth

2009 2010 2011 20120

100000

200000

300000

400000

500000

600000

700000

800000

Apps available Customer downloads

Page 20: The Threat Landscape Jan 2013. 2013 Threat Report 2

Android malwareHuge growth in 2012 (x40, just in September!)

21

1000Android samples analyzed

each day within SophosLabs

Page 21: The Threat Landscape Jan 2013. 2013 Threat Report 2

Android vs PC

22

Page 22: The Threat Landscape Jan 2013. 2013 Threat Report 2

SophosLabs

23

Page 23: The Threat Landscape Jan 2013. 2013 Threat Report 2

SophosLabsKey differentiators

24

1. Integrated threat analysis

2. Fast response time

3. Global presence 24/7/365

4. Updates issued from any lab location at any time

5. 100% in-house technology

6. Pre-configured intelligence

Page 24: The Threat Landscape Jan 2013. 2013 Threat Report 2

Top Facts

25

1,000Android samples analysed

each day within SophosLabs

80%of malicious URLs are actually legitimate sites

that have been compromised

250,000previously unseen files

received each day within SophosLabs

20-30kmalicious URLs seen each day. This is almost a new

malicious URL every 2 secs

Page 25: The Threat Landscape Jan 2013. 2013 Threat Report 2

Top Facts

26

Page 26: The Threat Landscape Jan 2013. 2013 Threat Report 2

Mitigating Risks

27

Complete Security Solutions designed to mitigate risks

Page 27: The Threat Landscape Jan 2013. 2013 Threat Report 2

Questions?

28