• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Business Issues
  • Channels
  • Enterprise
  • Services
  • SME
  • Technology
FEATURED EVENTS
  • Free Webinar - ISO 22301: The New Standard for Business Continuity Best Practice
    23rd May
    Webinar (online)
  • Telecoms Tech World
    4th June - 5th June
    London, United Kingdom
POPULAR PAPERS
  • FM, IT and Data Centres by Quocirca
  • The next frontier for managed print services by Quocirca
  • Beyond Big Data - The New Information Economy by Quocirca
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "There's a helluva distance between wisecracking and wit. Wit has truth in it; wisecracking is simply callisthenics with words." - Dorothy Parker

PAGE TOOLS
RECENT POSTS
  • CA - Same old same old, or new opportunities?
  • Dreaming of the perfect trip
  • Policing the virtual perimeter
  • Kaspersky Lab - Russia's IT security jewel
  • Is the use of cloud sharing systems worrying you?
  • The age of bring-your-own-identity (BYOID)
ADVERTISEMENT
BLOG ARCHIVE
  • May, 2013
  • April, 2013
  • March, 2013
  • February, 2013
  • January, 2013
  • November, 2012
  • October, 2012
  • September, 2012
  • August, 2012
  • July, 2012
  • June, 2012
  • May, 2012
Blogs > Quocirca

Discovering an old Flame

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 26th June 2012
Copyright Quocirca © 2012
Logo for Quocirca

Computer malware programmes only take on a name and a personality after they have been discovered. These are bestowed by the IT security industry, our would-be defenders. Before this, malware is anonymous and unknown, just the way the perpetrators want it.

Such was the case with Flame, whose discovery was announced a few weeks ago and about which much has been written. Being unnamed, however, does not mean unseen. Bit9, a security vendor, whose protection is based on blocking files with no - or suspect - reputation from running (blacklisting or grey-listing, see previous Quocirca post here), checked its records and found it had been blocking a single instance of what we now call Flame eight months before it was named.

The instance was at a commercial customer in the Middle Eastern country (a “friendly” country; by definition, to be a Bit9 customer, it must be, as it is a US vendor and subject to export restrictions). The attack was persistent, sometimes daily, and targeted at a single end user Windows PC. The malware ran with admin rights, which the PC’s user did not have, probably gaining access via a Windows’ vulnerability. Bit9 says no information was stolen because it stopped it on all occasions. Well done Bit9.

It strikes Quocirca that alongside file reputation there are two other ways the attack could have been thwarted before it was known.

The first focussed on the fact that it needed admin rights to be effective. The granting, management and on-going use of admin rights on Windows devices is usually poorly managed. It need not be; with the right tools in place, admin activity can be limited and audited and Flame may not have been able to run anyway or soon spotted. Such tools are provided by vendors such as BeyondTrust, Avecto and Viewfinity.

Second, some IT security vendors, such as LogRhythm, McAfee and Red Lambda, which have traditionally focussed on audit through security information and event management (SIEM), are now talking about next generation SIEM (NG-SIEM). Here, their tools are used in real time to make advanced correlations and spot strange activity. So, even if the malware had not been blocked based on reputation and admin rights were not controlled, the communication with a suspicious IP address, and regular running of an unusual file at a strange time of day would soon raise the red flag.

File reputation, Windows admin rights, NG-SIEM – these are all advanced security practices that business should be considering as they heed reports such as that issued by the UK’s MI5 recently; “MI5 fighting 'astonishing' level of cyber-attacks”. They are not alternative measures but form part of a multi-layered approach to IT security that is the only way to stand a chance in the increasingly threatening cyber-space.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy
  • | Cookie Policy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761