Web-threat protection and targeted attacks
#1
Bug 
Quote:
[Image: kwts-enterprise-6.1-featured.jpg]

Web threats are actively used in targeted attacks, so their neutralization should be an integral part of APT defense strategy.

How do cybercriminals get inside corporate infrastructure? Movie plot devices where an infected flash drive is left lying around do occur in real life, but not all that often. Over the past ten years, by and large, the main threat delivery channels have been e-mail and malicious Web pages. With e-mail, everything is fairly clear: a security solution with a decent antiphishing and antivirus engine on the mail server will eliminate most threats. By comparison, Web threats usually get much less attention.

Cybercriminals have long been using the Web for all kinds of attacks — and we don’t just mean phishing pages that steal users’ credentials for online services, or malicious sites that exploit browser vulnerabilities. Advanced attacks aimed at specific targets also use Web threats.

Web threats in targeted attacks

In Securelist’s 2019 APT review, our experts give an example of an APT attack that uses the watering-hole method. In the attack, cybercriminals compromised the website of India’s Centre for Land Warfare Studies (CLAWS), and used it to host a malicious document that distributed a Trojan to gain remote access to the system.

A couple of years ago, another group launched a supply-chain attack, compromising the compilation environment of the developer of a popular application and embedding a malicious module into the product. The infected application, with its bona fide digital signature, was distributed on the developer’s official website for a month.

The above are not isolated cases of Web-threat mechanisms deployed in APT attacks. Cybercriminals are known to study the interests of employees and send them malicious links in messengers or social networks that look like websites likely to appeal to their tastes. Social engineering works wonders on trusting individuals.

Integrated protection

It became obvious to us that to improve protection against targeted attacks, we needed to consider Web threats in the context of other events on the corporate network. Therefore, Kaspersky Web Traffic Security 6.1, released in the run-up to the new year, is integrable with the Kaspersky Anti-Targeted Attack platform. Operating in tandem, they complement each other, beefing up the network’s overall defenses.

It is now possible to set up bidirectional communication between the solution protecting the Web gateway and the solution guarding against targeted threats. First, that lets the gateway-based application send suspicious content for in-depth dynamic analysis. Second, Kaspersky Anti-Targeted Attack also now has an additional source of information from the gateway, enabling the earlier detection of the file components of a complex attack and blocking of malware’s communication with C&C servers, thereby disrupting the targeted attack scenario.

Ideally, integrated protection can be implemented at all levels. This involves setting up a targeted threat defense platform to receive and analyze data from workstations and physical or virtual servers, as well as the mail server. If a threat is detected, the results of its analysis can be forwarded to Kaspersky Web Traffic Security and used to automatically block similar objects (and attempts by them to communicate with the C&C servers) at the gateway level.

See the Kaspersky Web Traffic Security page for more information about our gateway protection application.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] Revo Registry Cleaner P...
OPTION 2 Share feed...zevish — 06:51
NVIDIA’s new DLSS Transformer model requ...
NVIDIA DLSS 310.3....harlan4096 — 10:09
INTEL Arc Graphics 32.0.101.6913 driver
Highlights  Int...harlan4096 — 10:07
AppCheck Anti-Ransomware 3.1.42.3
Version 3.1.42.3 (...harlan4096 — 10:06
AdGuard Browser Extension 5.1.113 (MV3 s...
AdGuard Browser Ex...harlan4096 — 10:03

[-]
Birthdays
Today's Birthdays
avatar (42)uapedDow
avatar (46)suiscced
avatar (47)Angarpaf
avatar (40)clarissalo60
Upcoming Birthdays
avatar (46)dapedDow
avatar (48)TromPerl
avatar (45)RidgeDimb
avatar (36)ipumaqar
avatar (50)tanliorsPeri
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (47)ConradRoand
avatar (38)boineDon
avatar (50)spoofTum
avatar (49)WillieVot
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (40)optsaZes
avatar (39)RaymondViata
avatar (39)ywixazok
avatar (37)ixoqe
avatar (55)Step 1
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>