Connect with us

E-Business

Gartner Reveals Five Styles of Advanced Threat Defense

Published

on

gartner.jpg
Kindly share this post

The threat of advanced targeted attacks, also known as advanced persistent threats, or APTs, has spawned a wave of innovation in the security market.

According to a document share by Lawrence Orans, Jeremy D’Hoinne, analysts at Gartner, a company that provides security managers with a framework to select and deploy the most-effective threat defense technologies, part of the key findings show that traditional defense-in-depth components are still necessary, but are no longer sufficient in protecting against advanced targeted attacks and advanced malware.

According to Lawrence Orans, Jeremy D’Hoinne, “Today’s threats require an updated layered defense model that utilizes “lean forward” technologies at three levels: network, payload (executables, files and Web objects) and endpoint; combining two or all three layers offers highly effective protection against today’s threat environment and many vendors fit squarely in one style, but also have some characteristics of adjacent styles. The trend will be for vendors to “bleed through” multiple styles as solutions mature”.

Analysis of the Key Findings

Traditional defense tools are failing to protect enterprises from advanced targeted attacks and the broader problem of advanced malware.

Advertisement

In 2013, enterprises will spend more than $13 billion on firewalls, intrusion prevention systems (IPSs), endpoint protection platforms and secure Web gateways (see Note 1).

Yet, advanced targeted attacks (ATAs) and advanced malware continue to plague enterprises. ATAs are considered advanced because of their ability to bypass traditional security mechanisms.

Five Styles of Advanced Threat Defense: Strengths & Weaknesses

Style 1 — Network Traffic Analysis

This style includes a broad range of techniques for Network Traffic Analysis. For example, anomalous DNS traffic patterns are a strong indication of botnet activity.

Advertisement

NetFlow records (and other flow record types) provide the ability to establish baselines of normal traffic patterns and to highlight anomalous patterns that represent a compromised environment.

Some tools combine protocol analysis and content analysis. The sample vendors we list all use internally developed signatureless techniques that have been effective in detecting advanced threats.

The strengths include, real-time detection; includes signatureless and signature-based techniques and endpoint agents are not required.

But the challenges include, it requires careful tuning and knowledgeable staff to avoid false positives; limited ability to block attacks (applies to out-of-band tools) and does not monitor traffic from off-network mobile endpoints.

Style 2 — Network Forensics

Advertisement

Network Forensics tools provide full-packet capture and storage of network traffic, and provide analytics and reporting tools for supporting incident response, investigative and advanced threat analysis need

The ability of these tools to extract and retain metadata differentiates these security-focused solutions from the packet capture tools aimed at the network operations buyer.

The strengths: Can deliver a high ROI (due to reducing incident response time and personnel); can reconstruct and replay flows and events over days or weeks, due to high-capacity storage options (for example, 200TB) and detailed reports can be used to help meet regulatory requirements, such as e-discovery or Payment Card Industry, for in-depth analysis and continuous monitoring of network traffic.

However, the challenges are the tools are complex, and skilled personnel are required to operate them; costs rise with the amount of data and the retention time; reports that analyze large amounts of data are time-intensive and may need to be run off-hours and does not capture traffic from off-network mobile endpoints.

Style 3 — Payload Analysis

Advertisement

Using a sandbox environment, the Payload Analysis technique is used to detect malware and targeted attacks on a near-real-time basis.

Payload Analysis solutions provide detailed reports about malware behavior, but they do not enable a postcompromise ability to track endpoint behavior over a period of days, weeks or months. Enterprises that seek that capability will need to use the incident response features of the solutions in Style 5 (Endpoint Forensics). The sandbox environment can reside on-premises or in the cloud.

Cloud-based Payload Analysis is a valid approach, but it is also a low barrier to entry for vendors.

Off-the-shelf hypervisors and virtualization technology, vendors can easily create sandbox environments and label them as Payload Analysis solutions.

Feedback from Gartner clients indicates that there is a wide range in the ability of these cloud-based Payload Analysis solutions to accurately detect malware.

Advertisement

As per the strengths, it is very effective in detecting malware that successfully bypasses signature-based solution; detailed reports highlight registry changes, API calls, process behavior and other information about the behavior of the malware (these reports are helpful for postcompromise analysis, but are not a substitute for the in-depth tools outlined in Style 2 and Style 5).

Also, there is an optional blocking capability for outbound callback to command and control centers for those on-premises-based (noncloud) solutions that can be placed in the line of traffic.

The challenges abound because behavioral analysis can take several seconds or minutes to complete, previously undetected malware is allowed to pass through, potentially compromising one or more endpoints; some evasion techniques can defeat the behavioral analysis technique.

For example, sleep timers, in which the malware code executes on a delayed basis (hours or days), may result in the malware going undetected during the time it is resident in the sandbox. Some vendors have techniques for detecting and thwarting sleep timer evasions.

It does not provide validation that the malware executed on endpoints. Just because the malware behaved a certain way in a simulated environment does not guarantee that it will behave that way on real endpoints.

Advertisement

Some malware does not install and execute as expected on every endpoint.

Many solutions only support a limited range of payloads. Some support executables (.exe files) only.

Most solutions only support Microsoft Windows, although some cloud-based approaches support Android. At the time of this writing, none support Apple Mac OS X.

Privacy and data protection concerns may prevent some enterprises from implementing cloud-based sandboxes.

Style 4 — Endpoint Behavior Analysis

Advertisement

There is more than one approach to Endpoint Behavior Analysis to defend against targeted attacks.

Several vendors focus on the concept of application containment to protect endpoints by isolating applications and files in virtual containers.

Other innovations in this style include system configuration, memory and process monitoring to block attacks, and techniques to assist with real-time incident response.

An entirely different strategy for ATA defense is to restrict application execution to only known good applications, also known as “whitelisting” (see “How to Successfully Deploy Application Control”).

The application containment approach allows malware to execute, but it does so in a contained environment where it cannot access content and information outside of its container. For example, the containers intercept kernel system calls and block malicious activity such as thread injection attacks.

Advertisement

By isolating Web browsing sessions, this approach protects users from malicious websites, including drive-by download sites and “watering holes.”

These solutions require an agent on every endpoint. (For more information, see “Technology Overview for Virtualization and Containment Solutions for Advanced Targeted Attacks.”).

The strengths are: blocks zero-day attacks and previously unseen malware (applies to application containment solutions); protects systems whether they are on or off the corporate network; provides basic forensic capabilities through analysis of blocked malware.

While the challenges are: deploying and managing endpoint agents can be operationally intensive and creates challenges in bring your own device (BYOD) environments; endpoint agents have varying restrictions for supporting operating systems, file types, applications and browsers and containment solutions utilize additional CPU and memory resources.

The more containers in use, the greater the impact, according to Gartner.

Advertisement

Style 5 — Endpoint Forensics

Endpoint Forensics serves as a tool for incident response teams. Endpoint agents collect data from the hosts they monitor.

These solutions are helpful for pinpointing which computers have been compromised by malware, and highlighting specific behavior of the malware.

Some solutions use various indicators of compromise (IOCs) to detect malicious behavior on the endpoint.

Examples of IOCs include suspicious Microsoft Windows registry key creation, DNS requests or installed binaries.

Advertisement

The strengths are, it helps automate the time-consuming task of incident response; monitors activity on hosts when they are on or off corporate networks; some agents provide limited containment features (for example, preventing previously detected malware from running again or on other endpoints in the company) and limited remediation capabilities.

The challenges include, a lack of ability to block zero-day attacks in real time; deploying and managing endpoint agents can be operationally intensive; at the time of this writing, support for non-Windows endpoints is limited and events are not always prioritized and typically require knowledgeable staff to investigate.

 

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Kaspersky Uncovers New Mirage Kitten Malware Used in Cyber-espionage Campaign Across Africa, Others

Published

on

Kindly share this post

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META).

The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.

It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network.

Advertisement

This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods.

The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa.

“Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts.

Advertisement

“Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.

 

Kindly share this post
Continue Reading

E-Business

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.

DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).

In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC,  described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.

The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.

Advertisement

According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.

Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”

It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”

The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”

According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”

Advertisement

Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.

“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.

Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.

The commission warned that entities failing to comply with the registration requirement could face legal consequences.

“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.

Advertisement

 

Kindly share this post
Continue Reading

E-Business

UNN to Partner Firm on AI, Smart Mobility Innovation Centre

Published

on

Kindly share this post

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.

The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.

Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.

He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.

Advertisement

According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.

He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.

“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.

Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.

He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.

Advertisement

Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.

“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.

He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.

The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.

Advertisement

Kindly share this post
Continue Reading

Trending