Malware in Corporate Networks – David Anteliz, Skybox Security
David Anteliz, senior technology director for Skybox Security, explains why there’s a lot more malware lurking on corporate networks than many IT teams fully appreciate.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with David antillese, who is Director of sales engineering for Skybox security and we're talking about dwell times for malware and what's going on and people's networks David. Welcome the show. Thank you, Mike.
Thank you for having me really excited to be here. See you're predicting in the coming year that we're gonna see a major corporation kind of a reveal or announced that they've had some sort of infection on their Network that has been around for months. Maybe even sometimes years.
So what's the thought process behind that and I thought we were getting better at hunting all the stuff down. Well while we are somewhat getting better now get to that in a minute. You think about everything that is transpired and leading up to this year in terms of all of the activity and malware activity ransomware activity that is happening.
Now while the payouts may not have been what the bad guys had had anticipated there has been an uptick in the activity itself. IBM IBM itself has has said that usually it takes about 197 days or someone to recognize that there is a breach and they're in environment and usually that will materially cost them, you know significant amount of money if if left undetected and usually if you detect something within 30 days, it's a much lesser significance, but still It continues to happen. It continues to they continue to dwell.
They continue to find new ways and tactics to evade, you know, the the scanners and and such. It seems like to me that they're also getting better at creating back doors. And then they're using that back door to drop malware into environments that they may not immediately turn on or they're gonna wait for it to be activated and that's part of this whole process.
I guess the bad guys are being more patient than ever. Is that fair assessment? That's exactly right just like, you know owning your own business.
It takes a little bit of time. It takes a little bit of grind to get to where you want to be, you know their secret recipe for any any measure of success anywhere is patience and they've discovered that if they are able to wait someone is going to make a mistake or they're going to uncover a mistake and it may not be a personal mistake and maybe just there's a problem with the software. There's problem with the firmware there.
There may be laps coverage in support and specific products. That's because maybe they've they've been Sunset so they look for different ways. To understand what the environment looks like both from a networking and software operating systems the whole kit and caboodle and at the end of the day all they have to do is wait, it doesn't cost them any money to wait because does cost them money to try to bang against the door and have it shut in their face.
So they're alternative is let's wait a little while. That malware is also starting to show up in software that people are building and deploying we're seeing a lot more efforts by the bad guys to insert malware at the front end of the development process that may not actually be turned on for quite some time. So is that part of their thinking as well these days?
Yeah, they're hoping to catch somebody asleep that they're going to insert something in that in that development cycle. Usually, you know when you're trying to bring product to speed and and I've I've witnessed this myself where you're trying to bring something to bear and you're doing all the things that you think you need to be done correctly. Unfortunately, sometimes the speed of doing business horses you to kind of Overlook things at times and that's what they're looking for those opportunistic moments in that shift left mentality where there might be a gap.
So they are too they too are shifting left and trying to catch, you know, the right opportunity the right packet or code to insert themselves and in the hopes that somebody will put that in their code and deploy it in a container somewhere and unleash their brand of nefarious activities So, how can we find this malware? We kind of have a suspicion that it's out there. But what are the challenges in locating it before it gets activated?
So in cyber security, we've done a magnificent job of making things a little bit complicated, you know kind of layering layering and layering and when there did need to be so much layering. Let's take for example compliance, right? We used that as a mechanism to in order to make sure that we are falling in line with a certain set of statues a certain instead of rules and policies in order to help Safeguard us.
But when we don't ask the question, well, why do we need to deploy or what do we need to deploy in terms of compliance or even products that might meet help us meet that criteria? We we fail to understand the not only the reasoning but the mechanisms that are actually going to secure our environments. We we invest in so many different point products in the hopes that it will help protect our networks.
Our operating systems are assets Etc. But we don't take the time to understand. Where does everything sit.
How is it being protected and do we in fact understand the requirement for it to be protected meaning? Is there a monetary value assigned to that specific asset? Is there a record is this asset going to represent some material cost or loss to the organization and when you don't have that type of introspection in your organization things can kind of get lost because it lets glossed over and basically bundled in with everything else.
Do we also underestimate how quickly that malware may be able to laterally move around our environment. So we tend to think about well this particular asset is in very valuable, but it is as it turns out connected to something that is and we're not really thinking through how that malware can shift in before we know it. Yeah.
Absolutely you hit the nail on the head when it comes to understanding your estate understanding what you have deployed but also understanding how that connectivity or accessibility between devices assets and operating systems and like Can actually happen do we have had do we have enforcement points? Do we have Micro segmentation or something? That's going to help Safeguard the secret sauce or intellectual property or pii?
Sometimes we don't because we put them on combined servers and we put them on, you know, multiple environments that you know, maybe we're thinking we're going to put one here for backup. We really don't have any any idea that the potential for going back and forth and going to and from a network is there maybe we didn't look at the accessibility. Maybe we didn't take out take a look at what our firewalls and how they're set up or you know, whether or not there's a routing or access list that's been defined or that type of that level of accessibility and I bring up one other point and that is our Partnerships.
The Partnerships that we have with our upstream and downstream providers. You know, what kind of access do they have? You know, we need to take a look at those and we should take a look at it at a deeper level and not only do we understand their security criteria, but they understand hours as well.
So by hours, I mean the organizations that are partnering up with other organizations. They should have a mutual understanding of what security looks like and what safeguarding data should be. Is the malware itself getting more sophisticated are the bad guys just saying why bother, you know the stuff we have works just fine and we don't really need to do anything more complicated.
I think what's happening with the malware is that the traditional State or the way they've deployed malware is the same. It's the same. It's the same type of malware.
There's just different variants and different tactics going about deploying that you take you take a look at what happened with the colonial pipeline, right? And you take a look at what the hacker group did in terms of taking out the information and making that information, you know rant, you know ransoming that that information. Well when when everybody came down crashing on on Dark Side, nobody really nobody really know what the next step was going to be well, but in it happening is that now the hackers and the malware providers started changing tactics, they started changing their approach just like a business would you know, we have to reinvent ourselves.
Otherwise, we're gonna go under you know, they start doing things like call centers, you know, you know doing spearfishing and fishing and other ways of trying to manipulate or insert that data getting you to click on a link Because we've sent you an email saying hey your Amazon account has just been you know, been denied your credit card failed or what have you things that somebody unsuspectedly or unwittingly would know, you know, is this valid or is this not valid? So I would say that they're getting craftier. They're changing up the variance to try to fool the scanners.
For all intents and purposes. They're still kind of pretty much doing the same, but I think it's just more at volume. We hear a lot about AI these days for better and worse this some folks say the sky is falling other folks say hey, I will save us from ourselves.
What's your assessment of the current state of AI and cybersecurity? Well, it's certainly introduces another another wrinkle to the fabric right because AI you can modify it. You can you can pretty much teach it a lot of different things a little teach itself take chat GTP and GPT.
For example, I myself have you know, just practice a couple times out there and said, hey write me a python script, you know for XYZ and immediately it pops out code. So using AI for things of that nature I could see will accelerate how much of it you can pump out again. You have to have that ability to push it now.
The rub will be if you're using AI to evade tactics now now that's where you know, the malware or the ransomware is going to start becoming smarter and applying. Some some level of intelligence to evading the tactics that are being utilized, you know in the infrastructure from from a security standpoint. So I say coming down the pipe not immediately.
It's still early days, but I think at some point, you know AI is going to play a part and how they're going to be deploying malware. All right, ultimately, if I have all this malware that's lurking Somewhere Out There is the way I measure people on their ability to find and eliminate that malware. Is it more about how quickly I can respond to it once I know it's been activated.
Well, I think response time is very important identifying it as one thing but being able to respond to it is another usually because it's been sitting out there. I mean the damage is already been done. Now, how do we become transparent as organizations?
And you know, share that information with our you know, constituents or those that are using our services. But secondly, how do we respond in being able to close that door and then assess and do a you know, post-mortem and understand, you know, how do we close that door for good? We shouldn't just be measured on compliance.
You know, we should just be measured on how many devices security appliances or how many malware's we are. We are, you know or variants were capturing on a monthly basis. We need to be tactical.
We need to be strategic in our approach and I think most organizations are doing that these days, you know, as new mandates are coming down and new new guidance is coming down, you know from the various different organizations nist is looking at, you know, restructuring its framework and kind of modernizing itself for the times But at the end of the day, it's up to each individual organization to take it upon themselves to take an assessment of what they have deployed and how they're important how they're applying their security security practice because if you're just if you think you have I have all these pointed products or I have this compliance or this policy governance and you're using that as the impetus or the reason why you feel like you're secure and you're you're going to be kind of fooling yourself at that point. All right, folks, you heard it here. There's malware out there and it's in your systems whether you like it or not.
We suggest that you go look for it as much as you can but if you can't find it and you probably won't find all of it. You need to be prepared for the unexpected. Hey, David.
Thanks for being on the show. I appreciate the time. Thank you.
Have a great day. All right back to you guys in the studio.