A Virtual Tour of SophosLabs Building next-generation protection Fraser Howard Principal Researcher September 2016
Current Threat landscape SophosLabs Systems Layered Protection Demo Agenda Current Threat landscape SophosLabs Systems Layered Protection Demo
Current Threat Landscape
Snapshot of 2016 Threat Landscape 150,000 Suspicious URLs seen & analysed daily 30,000 Malicious URLs daily, over 80% of which are from legitimate web sites 5 million Spam messages daily across 20 countries Malware samples added to Live Protection cloud daily 400,000 Previously unseen files received daily 2,000 Previously unseen Android apps daily 600 million Live Protection lookup events added to Hadoop cluster 50% Of detections based on small number of samples
Impact on security Automation Visibility Layered protection Automated dynamic analysis Cloud response Visibility Track active campaigns Monitor protection levels Layered protection Protection technologies Application control
Roles & Responsibilities SophosLabs Roles & Responsibilities Global Team Real-time response to incidents 24/7/365 operation Threat Response Deep expertise into threats & attacks Create powerful protection solutions Threat Research Build bespoke systems to automate threat analysis & response Enable SophosLabs to scale Automation development Ensure effectiveness & quality of releases Own risk management Quality Assurance Abingdon Vancouver Budapest Ahmedabad Sydney
SophosLabs Team Structure Heuristic rules Advanced detection Customer escalations Anti-spam Android OSX Unix/Linux Android, Linux & Mac Files, URLs, IPs, certs Whitelisting Classifiers Automation Reputation Services Windows malware, PUAs, AppC TFT Unpacking Frameworks Generic Detection Runtime detections (CX, HIPs, mem) Web (CXweb) Email (CXmail) Dynamic Detection APTs Exploits New, niche threats Knowledge gain Emerging Threats Snort IPS data IPS automation C2 signatures Network Security
SophosLabs Systems (live!)
Web distributed threats Visibility Email campaigns Web distributed threats Global spam traps Real-time picture of spam Phish Scams Meds Malware distribution Social engineering Education? The Web – all about content delivery, good or evil. Millions of pages scanned each day Telemetry provides visibility into malicious activity Track attacks Monitor Exploit Kits
Attack Demo: Spam campaign delivering Locky ransomware