Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    April 2014
    S M T W T F S
    « Mar    
     12345
    6789101112
    13141516171819
    20212223242526
    27282930  
  • About Us
    TrendLabs Security Intelligence Blog(breadcrumbs are unavailable)

    Author Archive - Martin Roesler (Director for Threat Research)




    Last December, I spoke at a cybersecurity summit sponsored by the International Telecommunications Union (ITU) in Baku, Azerbaijan. I was there to discuss one thing that Trend Micro will focus on in 2014 and beyond: how we can we work together with law enforcement to stop cybercrime.

    One may ask, why does law enforcement and the security community need to work together to stop cybercrime? It’s because neither group, working alone, can protect users and stop cybercrime.

    For various reasons, police agencies don’t always deal well with cybercrime. For one, the scale of cybercrime is larger than physical crime. A gang of pickpockets stealing wallets can only target so many people in a day; a cybercriminal can victimize thousands of users in a matter of seconds.

    In addition, many police agencies don’t have the skills to effectively track down and investigate cybercrime. Tracking down cybercriminals requires a very different skill set from traditional policing, which limits the abilities of law enforcement to go after cybercriminals. It also takes resources and trained personnel, which are, in many cases, in very short supply.

    Trend Micro has spent considerable energy in building excellent working ties with law enforcement agencies such as Interpol. This allows us to work in direct partnership with these agencies and become a key part of investigations. Our role in these investigations is beyond just passively handing over information to police; instead we work actively with investigators to figure out what information they need as part of their investigation.

    In some ways, it’s as if our researchers have been deputized to work side by side with police. The investigations are no longer the responsibility of police themselves; to combat cybercrime effectively requires the private industry and police to work side by side. For that to happen, there has to be large amount of trust between us and agencies, and I am proud to say that in many cases we have built up that trust and effectively conduct investigations together.

    Both our researchers and police have to be on the same page when it comes to the objective. Our goal is the same: to put cybercriminals behind bars. We do not focus on “technical” solutions such as shutting down servers, or taking down botnets, or seizing domains. One might even argue this is counterproductive in the long term, as it means that cybercriminals will be pushed to use more sophisticated tactics and more concealed infrastructure, making investigations more difficult. This is something we noted in our 2014 predictions.

    We believe that in order to fully protect our customers, efforts have to be focused on arresting cybercriminals. Taking down their infrastructure is, at best, a short-term solution: cybercriminals can easily rebuild their infrastructure and recover from any “takedown” relatively easily. To really stop cybercrime, the “threat actors” – cybercriminals – have to be the ultimate target.

    This is not always an activity which makes the headlines or spawns press releases. However, we do believe that moving forward, this is the best way to protect our customers and the Internet as a whole.

     
    Posted in Malware | Comments Off



    Recently, Trend Micro and INTERPOL announced that Trend Micro will help train law enforcement personnel from participating countries all over the world to help them cope with today’s cybercrime threats. We are honored to help INTERPOL in its fight against cybercrime; this is completely in line with our vision of creating “A World Safe for Exchanging Digital Information.”

    The details of our collaboration are in our press releases, but I want to use this topic to discuss, more broadly, how and why Trend Micro works with law enforcement agencies around the world to stop cybercrime.

    Why is it so important that law enforcement and security companies like Trend Micro work closely together to deal with today’s threats? The answer is: each group brings very different skillsets – and mindsets – to the table. By working together, they are able to work best to become effective against cybercrime.

    Security researchers have a wide variety of information at their disposal. They have threat information from their company’s operations, as well as underground information – frequently from the “social networks” they form while visiting underground forums undercover.

    In addition, researchers typically work as teams which are multinational, have a wide reach of knowledge and specialties available to them, and used to making decisions quickly. All these traits are quite helpful in keeping up with cybercriminals.

    However, security researchers can only go so far. Law enforcement has access to powers that are needed to truly identify those responsible for attacks. Servers can be seized, communications (electronic or otherwise) can be monitored, as provided for by courts. This in-depth information allows for the identification of the actual persons behind online crimes, who can then be arrested and brought to trial.

    In the absence of cooperation, a wide variety of problems can occur. Researchers may release information into the public, which may interfere with in-progress investigations by police. The released information may not even result in anything of significance, as the researchers cannot enforce laws. Meanwhile, law enforcement can’t deal with cybercrime: it moves fast, it’s not clear “where” it actually takes place, and depending on local laws it may not be “crime” in the first place.

    While it is essential for law enforcement to partner with security companies to catch cybercriminals, they also need to be careful in choosing their partners. Some companies are perceived (rightly or wrongly) to be close to certain governments. The partners also need to be discreet in releasing information to the public; prematurely released information can seriously damage long-running investigations and cause promising leads to go cold. Picking the wrong partner can also hurt, not help, the fight against cybercrime.

    As a company, we work very hard to ensure that we have good relationships with law enforcement agencies from all over the world. We meet at conferences, internal meetings, and other events on a regular basis that serve as a way for us to exchange information. An example of the fruits of our cooperation was the recent arrest of a key figure in ransomware gangs. By working closely with Spanish law enforcement, Trend Micro was able to gather actionable information that led to arrests in this case.

    We strongly believe that by working with law enforcement, we are able to go after cybercriminals directly. Instead of targeting their hosting infrastructure – both infected machines and malicious servers can be replaced easily enough – we go after the true suspects, the persons responsible for various attacks. Going after these perpetrators, we believe, is the best way to ensure a safer Internet for everyone.

     
    Posted in Data, Malware | Comments Off



    What is the difference between cybercrime and a “cyber war”?

    There are different elements of an attack that help us understand this: the targets, the threat actors behind it, as well as the tools used. But I think one of the most important aspects, something that drives all the other aspects, is also the answer to the question I posed earlier: intent.

    I believe this difference in intent matters because it defines the threat itself. There are a lot of reports on different kinds of organizations being successfully victimized by targeted attacks, and it has become so overwhelming to the point that it has obscured our view of what kind of threats we’re dealing with. And though knowing the intent might not be able to help us stop an attack, it can enable us assess if we are a potential target.

    Cyber war or Cybercrime?

    For example, when a threat actor from country A conducts a targeted attack against several companies in country B, does it count as cyber war, or cybercrime? The answer, again, depends on the intent.

    Cyber war, as Raimund Genes also said in his 2013 predictions, refer to politically motivated attacks that may destroy data or even cause physical damage to infrastructure of a specific country. So in my example above, if the goal of the attack is to destroy the companies’ data or their infrastructure with a political intent, it may be considered an act of cyber war.

    However, if the attack is conducted in order to steal information from the companies with a pure financial intent, then it should be considered a form of cybercrime. Most of the cybercrime schemes we’ve seen in the past aimed to affect as many individual users as possible, but the cybercriminals have found a bigger and better target in companies.

    Read the rest of this entry »

     



    Last time, I talked about how attackers are at an advantage when it comes to targeted attacks, and how it is important that we accept that fact in order to deal with attacks properly. Here comes the hard part: knowing that attackers have a great level of control, what do we do now?

    Remember that even though we’ve come to accept that attackers have greater control, does not mean that we don’t have any of it. We do, and it is important to take note of that because using that control is highly critical in dealing with targeted attacks.

    Control the Perimeter

    Of course, any form of control can only be truly successful if founded on an awareness of what we truly own. Acquiring a firm grasp of what and who gets access to the network and the level of access that is provided may come at the expense of what most employees see as convenient, but considering the dangers of targeted attacks, it is important to put security first.

    Part of identifying the network is also having a deep understanding of it, specifically the operations, processes, events, and behavior we consider normal. Knowledge of what is truly normal and what is not will help identify anomalies better and faster.

    Once the network is defined, it is critical to have a means to monitor the network, which means having visibility and control of everything that goes in and out of it. A good example of a technology that can help network administrators do this is DNS Response Policy Zone. DNS RPZ provides a scalable means to manage connections to and from the network. If complemented with a domain name blacklist, it would create a network environment that is significantly safer.

    Deploy Inside-Out Protection

    Traditional defenses focus on hardening firewalls and keeping bad components out through blacklisting. Now, while this “outside-in” strategy would be effective for dealing with fairly straightforward attacks, it would be utterly unreliable against targeted attacks. Traditional defenses are made for attacks where the form and source are easily recognizable, which is not the case for targeted attacks.

    Figure 1. Traditional defense

    Read the rest of this entry »

     
    Posted in Targeted Attacks | Comments Off



    Most of the things our industry has learned about targeted attacks were realized the hard way: through analysis of successful attacks. Our realizations have so far revealed just how unfamiliar we are with the “battle ground” we are currently in, and how that unfamiliarity has caused the industry to be unable to understand what is needed to deal with such attacks. But why is this so? Do the attackers really have the upper hand? The answer, unfortunately, is yes.

    Unfair Advantage

    To put it simply, attackers have a greater level of control and a wider range of resources. They get to decide on the very nature of the threat — how and when the attack will play out. They can employ the use of the numerous tools available on the Internet, including legitimate services. More importantly, they can get intelligence on what they are up against – they can do research on the target and find information that can make infiltration easy and almost undetectable.

    And while attackers are able to utilize such flexibility, targets, on the other hand, are faced with multiple limitations that even by themselves are already difficult to manage. With the dawn of consumerization and rise of mobile computing, it is already a big struggle for companies to identify their own network, even more so to protect it. They can only do so within the limitations of available strategies, whatever control they have over the network, and the awareness of their people.

    Read the rest of this entry »

     
    Posted in Targeted Attacks | Comments Off


     

    © Copyright 2013 Trend Micro Inc. All rights reserved. Legal Notice