Security Firms Using New Strategy: Offense, Not Just Defense
From: Midsize InsiderĀ
by Richard Janezic
The task of protecting midsize business from hackers, virus infections, and advanced persistent threats (APT) to date has been primarily focused on “defensive” measures. But some organizations use a different strategy, combining both offense and defense in their quests to protect clients and organizations.
A story by security industry analyst Richard Stiennon for National Public Radio (NPR) discusses threats, analysis, and actions used by cybersecurity firms like Virginia-based Mandiant Corporation, which is led by Kevin Mandia, a former Special Agent for the U.S. Air Force with training in computer science and forensics. Mandia and his team use intelligence-gathering techniques to find and stop attackers. They specialize in understanding the “playbook” (the methods and tactics used by attackers) to detect, contain, and respond to intrusions.
The Mandiant website provides chilling facts and statistics of attacks, such as the fact that 100% of victims had up-to-date antivirus software and that the median time to detect attackers on a networks is over 400 days. It describes the anatomy of an attack and illustrates the speed with which attackers can penetrate conventional defensive measures. The site also offers tools to help organizations to determine if there may be evidence of a compromise.
Offense as a Strategy Against Advanced Persistent Threats (APT)
A virus infection that requires removal of malicious software can be a costly and time consuming event for your security and technology teams. Generally, conventional defensive measures do an adequate job in preventing such problems, and tools and documentation to help fix such problems are available. But resolving a known problem like that can be a minor inconvenience when compared to the damage which can result from a sophisticated APT.
The term “Advanced Persistent Threat” is intentionally descriptive. “Advanced” means complex, evasive, difficult to detect and sophisticated in operation. “Persistent” means difficult to completely eradicate. APTs require a different and more expensive level of expertise to combat.
APTs are a growing concern, as the damage value from economic espionage can be significant. Consider the research and development (R&D) time and expense of a creating a new product innovation, or instead, the executive and legal time and expense of identifying and due diligence activities for a possible acquisition, or defending against a lawsuit or intellectual property (IP) infringement. Companies can invest millions of dollars in such activities. APTs that perform industrial spying or economic espionage can tell a competitor or a competitive agent what you are doing or steal what you have worked on for years. And it can be stolen in hours, all without anyone knowing.
Using offensive techniques may not be a measure that every mid-market company or organization can use. But for those who have much to protect or who have very competitively sensitive information, it may be a strategy very well worth considering.
| Print article |