14,698 High & Critical Vulnerabilities since 2005 Source: CVE Details
Testability Gap
Testing “Defense in Depth” Windows Clients Data Center Apps Oracle, EMC, Veritas, HP, Microsoft Microsoft (Windows, IE, Office), Adobe, Mozilla, etc. Firewall & Network IPS Gap Analysis Protected & Exposed Vulnerabilities HIPS, AV, etc. NSS Labs - Live Test™ Framework Attacks
Network Intrusion Prevention (IPS) Varies widely IPS products have significant gaps in coverage Default configs not sufficient Tune Product Block Rate: Default vs. Tuned Policies Source: Q NIPS Test, n=1159
Host Intrusion Prevention (HIPS) varies widely Attackers will try multiple exploits and variants Quality of signatures matters Source: Q EPP HIPS Test, n = 123
Evasion: Every AV product can be circumvented Hundreds of options, thousands of combinations Old attacks can be made new again VendorHTML ObfuscasionPayload EncodingFile CompressionExe Compressors A43%40%80%40% B100%40%80%100% C 40%80% D100%80% E100%60% 80% F43%20%80%40% G43%40%60%40% H57%60%80% I100%40%60% J100% 60%80%
What’s Needed… “Gloves off” Security Testing –If you’re not testing like the bad guys, what’s the point. Real-world malware & phishing tests Vulnerability-focused exploit testing & protection Stopping variants Properly handling evasion techniques Good default, recommended and tuned policies