Famous hacker Albert Gonzalez mocked antiviruses. He and his teams wrote malware specifically designed to avoid detection.
Hackers like him load malicious software directly into the server's memory, and gain access to the data exchanged across a bank's corporate networks.
Gonzalez was perhaps the most wanted hacker in internet history. He was eventually jailed for hacking into more than 250 businesses, including retailers like TJX and Hannaford Bros. to payment processor Heartland.
The data that was compromised was worth hundreds of millions of dollars. Even though many of these businesses had antivirus software installed, they were never able to detect what the hacker was doing. Why?
Beware of gaps
Make no mistake: antivirus is an important part of the security arsenal, and every day malware scanners detect and stop millions of malware. It's now a must-have piece of software.
Antivirus tools work by scanning both static files and programs running in memory. They use various techniques to detect malicious activity.
Signature scanning, for example, looks for known patterns in files, and is an established method for finding malware, as is scanning the code running in memory, and looks for potentially malicious activities as they occur.
These are all solid, reliable tools, but when attackers are determined enough, antivirus alone can't stop them and secure your data.
The malware industry focuses on zero-day attacks, exploiting obscure or completely unknown vulnerabilities. A hacker clever enough can devise, or discover, one – and there are many – to bypass detection software.
The smart IT administrator uses complementary technologies to reduce the risk of an attack, and one is to examine all possible distribution channels for malware.
Dangerous Websites
One way attacks are carried out is through drive-by downloads. Employees visiting legitimate websites are relatively safe, but when they visit less trusted sites they run the risk of being infected by rogue JavaScript running in their browser.
Web protection software can reduce the risk by blacklisting certain websites or groups of websites. Filtering internet access is a great way to reduce the risk of infection by simply blocking access to websites that are not essential to your work environment.
It's a worthy complement to an antivirus that will attempt to detect anything installed through the browser. This multi-faceted protection is a core tenet of modern cybersecurity.
All it takes to say goodbye to the integrity of your network is for someone to open a file or click on a link.
Another important vector of infection is email. Attackers use it for phishing, and in some cases for spear phishing targeting specific companies.
Attackers can gather information about a company's organizational structure and employees. The list of sources is endless, and can be found in annual reports or social media.
They use social engineering to extract login credentials from the victim or to very convincingly urge them to open a file containing a zero-day attack.
Employee training is very important for this part, but it should also be supported by a technological solution.
Big phish
The best way to deal with threats delivered via email is to suppress them before they reach employees. Email monitoring and filtering is therefore an important part of any corporate cybersecurity strategy.
Emails can be secured from viruses by having an antivirus scan for known spam signatures. This alone can greatly mitigate malware or hostile emails, ensuring increased employee productivity as well as reducing the risk of a breach.
Using blacklists for known malware vectors and using whitelists for identifiable sources, such as business partners and customers, can be an extremely useful technique for blocking emails.
For added security, companies can keep unscrubbed emails out of their infrastructure. Pre-filtered emails can protect employees not only from infected files, but also from large volumes of spam. Filtering through a third-party service mitigates the problem, ensuring that company servers deliver clean communications.
Updates
Even if all of the above measures have been taken, there is still the possibility that a company's systems are vulnerable.
For hackers like Gonzalez, or the Sony Pictures hackers, a system scan and email filters are not enough.
Make sure the software you are running on your computers is up to date and has no known vulnerabilities.
Patches and updates in general are vital as IT infrastructures become increasingly complex. Understanding the update and installing it on your system can help administrators prevent impending breaches.
All of these above measures, accompanied by a reliable antivirus, can help your cybersecurity.
But don't forget: nothing is 100% secure. The above measures try to make things more difficult for attackers who may decide to move on to easier targets. A hacker with persistence, necessary knowledge and skills is dangerous even if you have followed all of the above to the letter.
