Can anti-virus technology morph into breach detection systems?
Such breach detection systems would need a centralized management reporting system and cloud-based analysis of gathered threat data.
Anti-virus software is still often considered a “checkbox” item for enterprise deployments, especially on Microsoft Windows, but over the decades, anti-virus software changed to do far more than just signature-based virus blocking. Today, the question is whether the type of anti-malware product that evolved from virus checking can transform again to be a part of a “breach detection system,” or BDS
“The premise of breach detection is things will get through all your defenses and you need to contain it as soon as possible,” says Randy Abrams, research director at NSS Labs, which has begun testing what it calls BDS products that can identify evidence of stealthy cyberattacks, track down what corporate computers and networks were hit and quickly mitigate against any malware dropped in that attack which would be used to spy and exfiltrate sensitive data. BDS products, however they do it — through sandboxing, an endpoint agent or other approach — should be able to at least catch the breach within 48 hours, he says.
The premise of threat detection is things will get through your defenses and you need to contain it as soon as possible.
— Randy Abrams, research director at NSS Labs
BDS products are largely immature, Abrams acknowledges, but enterprise customers are keenly interested in them and asking to have them independently tested. NSS Labs started doing that last year with products from AhnLab as well as FireEye and Fidelis Security, which was acquired by General Dynamics. These three did fairly well in that first round of basic testing, Abrams says. But the main limitations appeared to be there needs to be more protocol analysis done in to ensure attackers don’t have “a hidden tunnel out of the enterprise,” he adds. The next round of BDS tests anticipated for later this year will be tougher, he says.
+More on Network World: McAfee plans enterprise security package for fast threat detection and response | Is rapid detection the new prevention? | IDC tabs ‘Specialized Threat Analysis & Protection’ as new segment +
The vendors that NSS Labs consider to be part of the emerging BDS market today include Cisco, FireEye, Symantec, McAfee, Palo Alto Networks, Damballa, Fidelis and AhnLab. The security industry itself is abuzz with the utterances of “indicators of compromise,” the “IOC” clues such as anomalous outbound traffic that might indicate an attacker successfully broke in. Abrams thinks any BDS will need a centralized management reporting system and probably a lot of cloud-based analysis of gathered threat data.
Where this will all go is uncertain. The term BDS isn’t universally applied as a description. One research firm, IDC, last year started tracking what it calls “Specialized Threat Analysis and Protection” as a new segment that seems similar to BDS.
The question is whether the established vendors in the traditional antivirus industry, particularly Symantec and McAfee which lead in market share, can transition over to anything close to the NSS Labs’ view of BDS. Abrams notes the problem with any anti-malware product, however good, is that criminals determined to break into corporations are testing the attack and espionage code they’ve developed for that against existing antivirus products to find something that will get through and not be noticed, at least for a while.