The Threat Landscape Jan 2013
2013 Threat Report 2
What you can do with the Threat Report 3 Educate buyers how threats lead to both paths of Complete Security Create opportunities vs. Find opportunities Help your partners become security experts Learn 2-3 case studies and facts/stats from Threat Report
1. Threat Volume SophosLabs see 250,000 new files each day 4 250,000 previously unseen files received each day within SophosLabs
2. The malicious web Web servers are under constant attack. A new malicious URL every couple of seconds 20-30k malicious URLs seen each day. This is almost a new malicious URL every 2 secs
3. Professionalism, crimeware ‘Monetization’ : the bulk of today’s threats are automated, coordinated & professional 6
Case study 1: Drive-by downloads 7
Controlling user traffic Inject redirects into legitimate sites Web threats are all about controlling user web traffic 80% of malicious URLs are actually legitimate sites that have been compromised
It’s all about traffic Distribution of today’s web threats (2012 H1)
Drive-by downloads Compromising legitimate websites to drive user traffic to malware
Drive-by downloads Compromising legitimate websites to drive user traffic to malware
Drive-by downloads Compromising legitimate websites to drive user traffic to malware
Drive-by downloads Compromising legitimate websites to drive user traffic to malware URL filtering Content detection
Case study 2: Ransomware 14
Ransomware Multi-lingual! 15
Ransomware Malware that locks/encrypts user data Pay ransom to access files 16 Simple Password protected archives Medium XOR shift Complex RC4 Public key crypto Recover data?
Blackhole payloads Payload distribution (late 2012) 17
Case study 3: Android Threats 18
Mobile OS market (US) What will mobile malware target? 19
Android Applications Significant growth Apps available Customer downloads
Android malware Huge growth in 2012 (x40, just in September!) Android samples analyzed each day within SophosLabs
Android vs PC 22
SophosLabs 23
SophosLabs Key differentiators 24 1.Integrated threat analysis 2.Fast response time 3.Global presence 24/7/365 4.Updates issued from any lab location at any time 5.100% in-house technology 6.Pre-configured intelligence
Top Facts 25 1,000 Android samples analysed each day within SophosLabs 80% of malicious URLs are actually legitimate sites that have been compromised 250,000 previously unseen files received each day within SophosLabs 20-30k malicious URLs seen each day. This is almost a new malicious URL every 2 secs
Top Facts 26
Mitigating Risks 27 Complete Security Solutions designed to mitigate risks
Questions? 28