Transcript
Page 1: Technologies of Tomorrow, Today

Technologies of Tomorrow, Today

John Viega

[email protected]

Twitter: viega

Page 2: Technologies of Tomorrow, Today

Why HIPS Sucks

xxx.exexxx.exe

yyy.exeyyy.exe UnpacksUnpacks

Page 3: Technologies of Tomorrow, Today

Web Reputation

Browser exploits

Adware/ Spyware/ Trojan /Virus High Volume Commercial Email

Affiliations with other risky sites Aggressive Pop-up Marketing

Community reviews/ comments

Page 4: Technologies of Tomorrow, Today

Real Time / Cloud analysis

omgwtfetc.exe

omgwtfetc.exe

Possible analysis, or random guessing

Possible analysis, or random guessing

OMG, WTF?

ETC…AV Vendor

Page 5: Technologies of Tomorrow, Today

AV is dead, whitelisting is killing it!

AV is dead, whitelisting is killing it!

Page 6: Technologies of Tomorrow, Today

Problems Still Remain

• Seeing enough samples• Operational scale• The testing problem• Disabling the product

Page 7: Technologies of Tomorrow, Today

Herd Technology

xxx.exe

xxx.exe

YYY.exe

YYY.exe UnpacksUnpacks

xxx.exe

xxx.exe

ZZZ.exe

ZZZ.exe UnpacksUnpacks

xxx.exe

xxx.exe

StonewallStonewall

Please Monitor!

xxx.exe is bad!

kthx!

xxx.exe is bad!

Page 8: Technologies of Tomorrow, Today

Virtualization

Security SWSecurity SW


Top Related