HomeSecurityExclusive Interview with Alexandru Catalin Cosoi of Bitdefender

Exclusive Interview with Alexandru Catalin Cosoi of Bitdefender

iGuRu.gr had a very interesting conversation with Alexandru Catalin Cosoi, PhD Chief Security Strategist of Bitdefender. We present the interview that was conducted with the help of AlfaVAD, official distributor of Bitdefender. For more information, visit www.bitdefender.gr

catalin cosoi BitdefenderAlexandru Catalin Cosoi, PhD Chief Security Strategist at Bitdefender

iGuRu.gr: What were the new trends in online threats for 2014?

During 2014 we have seen an alarming increase in ransomware attacks (e.g. CryptoLocker, CryptoWall, etc.) along with numerous security vulnerabilities exposed by cybercriminals and security researchers (e.g. Heartbleed, Shellshock, etc.).
Cyberattacks and data breaches at Verizon, JP Morgan, Home Depot, and Sony have made headlines and caused millions, if not billions, of dollars in losses to the aforementioned companies, making 2014 a watershed year for cybercriminals and security firms.

iGuRu.gr: Do you have data on Greece regarding threats or any other special characteristics?

Android threats represent the most notable change in the way malware plagues Greek users. In the first half of 2014, malware of the Android.Trojan.SMSSend family reached 51.94% of the total number of reports, which means that a large portion of users installed (perhaps accidentally) malicious applications that send text messages to premium-rate numbers without the owner's knowledge.

The second half of 2014 seems to have been even more productive for this malware, as the percentage reached 67.90% of the total number of reports from Greece.

It seems that a large portion of users either chose to install (infected) apps from third-party Marketplaces or were victims of drive-by attacks while browsing.
Either way, we recommend that everyone with an Android device download and install a portable security solution that is able to protect them from any online threats (e.g. malicious websites or apps).

iGuRu.gr: Bitdefender has been in the business for many years with many successes, awards and a reliable presence in the field of security and research. Do you remember any difficult incident?

This is the kind of industry where fierce competition is always tough. While direct competition between AV manufacturers is always a factor to be reckoned with, we are also always in competition with cybercriminals, as the ongoing development of new malware tries to bypass security technologies.
Bitdefender is a security company, which means we are constantly researching and developing new security technologies that are designed to proactively detect even new or unknown threats.

We build dynamically scalable infrastructures that can support the full range of threat response technologies to meet the need for top-notch security and performance.
When it comes to difficult incidents, we face a potential challenge every day because malware developers never rest. As threats become more complex, it is always difficult to come up with a timely security solution that can not only repair damage, but also protect against future malware variants.

iGuRu.gr: How do you see security in Greek businesses and public infrastructure?

Infrastructure in Greece is as vulnerable as in any other country. The SCADA systems that monitor, regulate and control everything from street lights to water pumps and electricity grids are vulnerable and cyber threats know no borders

Most of these systems use minimal security mechanisms or no security updates at all, almost inviting attackers to attack them.
The public infrastructure of every country should be protected by more than one layer of security. Imagine what would happen if someone managed to take control of the traffic lights? In a few minutes, hundreds, if not thousands, of traffic accidents would occur, bringing traffic to a standstill. In the worst case, lives could be lost. .
The security of public infrastructure from malicious access should be the highest priority for every country.

iGuRu.gr: What is the future of virus protection?

As long as the Internet works, there will always be a need for security solutions. There will always be someone sitting behind a laptop trying to access your e-banking accounts, your credentials, or use the resources of their victims’ computers to carry out a DDoS attack.
Of course, risk mitigation technologies will have to evolve and, in addition to desktops and laptops, they will also have to address Internet-of-Things devices to benefit from the same top-notch protection. Smart refrigerators, smart toasters, and even smart microwaves will have to rely on threat protection technologies to keep them safe. If your smart washing machine started sending spam, it wouldn’t be much of a joke, would it? (Maybe it was a little funny).

iGuRu.gr: Do you have some basic advice for iGuRu.gr readers? How could an average user protect themselves?

Install an anti-malware and an Anti-spyware. These programs can instantly detect and remove all known threats. Make sure to get them from a reputable vendor with a solid reputation for detecting and repairing a device, as the security of your personal information and files depends on it.

Update all your installed software. Attackers often exploit unpatched software vulnerabilities. It is known that unpatched Java or Adobe applications are often used as a primary point of attack. Of course, you should update Windows regularly, as well as all browsers.

Turn on your Firewall. This protective barrier can effectively 'hide' your computer from prying eyes, as attackers are constantly looking for potential victims.

Scan every removable drive. Most malware resides on infected USB flash drives, opening the way to much more secure networks. Disinfecting all drives before using them is essential.

Strong passwords. A 5-character password might be easier to remember, but it would be weak to a simple brute-force attack. Make sure your passwords are at least 12 characters long and use a mix of uppercase and lowercase letters, along with numbers and special characters.

Avoid emails from strangers. Some attackers might try to trick you into downloading infected files. Try not to click on links or open attachments in emails unless you are absolutely sure that the person sending it to you is trustworthy. An attacker could try to create an email that impersonates either an official government authority or even a long-lost cousin, in order to be believable enough to get you to click on a link or open an attachment.

Beware of Scareware. Sometimes cybercriminals try to scare you into thinking that your computer has already been hacked and the only way to make it safe again is to download some dubious software that will clean everything up. This type of scareware can be very effective if you're not careful. So, don't believe what you read and be careful when browsing.

Avoid free Wi-Fi Hotspots. Public Wi-Fi Hotspots can be a serious security risk, as it is very easy for someone to highjack the entire network to infect all connected devices with malware. If you absolutely must use a public Wi-Fi connection, make sure you have a VPN connection and follow all the security tips mentioned above.

iGuRu.gr: Are there any predictions for 2015?

In 2015, you will probably see more ransomware emerge, as it has been a very lucrative scam technique. Various forms of CriptoWall or CriptoLocker will likely emerge with new features, making security much more difficult for these threats.
In the world of mobile threats, we will probably see the same types of emerging threats, as we know that mobile malware tends to mimic the behavior of PC malware. So, we expect mobile ransomware via drive-by attacks that will exploit OS vulnerabilities. Considering that Google has officially stopped support for Android Jelly Bean and below, almost 1 billion devices are left exposed to vulnerabilities, and this will probably be the starting point for new malware to come in 2015.
The enterprise sector will also have to transform its security approach, as companies look to find cloud-based security solutions. This solution will not only prove to be more cost-effective, but will also allow small and medium-sized businesses to securely protect their operations without being under constant fire from cyber-attacks that endanger their intellectual property.

iGuRu.gr: Are there any plans for a CMS protection software from Bitdefender?

No.

iGuRu.gr: How does BitDefender help the online community, besides software development?

BitDefender always believes and is a fan of raising awareness about the online dangers that plague unsuspecting users. We constantly strive to educate the online community on how to spot potentially unwanted applications or malware and how to stay safe from threats that could compromise their personal information.

*iGuRu.gr thanks Mr. Alexandru Catalin Cosoi, PhD Chief Security Strategist at Bitdefender, for the updated data describing the security landscape in our country, as well as Ms. Maria Tranou for her assistance in this interview.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS