HomeCyber SecurityDocuments: a Hackers Gateway to your Enterprise

Documents: a Hackers Gateway to your Enterprise

Date:

Your business, just like cybermatters, probably uses documents as a key tool in sharing and disseminating information. As we have known for a very long time now documents can be a source of security infection, but technology does not see to be coping very well in protecting against it – UNTIL NOW.

Attack Scenario

Hopefully, by now, we all know how an attack of this type works, the following description is from Symantec when describing Operation Shady Rat:

Target organizations are selected and then emails are created and sent to individuals within those organizations. The emails follow the typical targeted attack modus operandi—that is they contain some subject or topic that may be of interest to the recipient, such as rosters, contact lists, budgets, and so forth. The attached file contains the details promised in the email text, as part of a social engineering ploy. In our investigations we’ve uncovered many such emails covering a whole gamut of topics. These emails contain various attachments, typically Microsoft Office files such as Word documents, Excel spreadsheets, PowerPoint presentations, and PDF documents. These files are loaded with exploit code, so that when the user opens the file the exploit code is executed, resulting in the computer becoming compromised.

- Advertisement -

Role of Anti-Virus Technology

Surely protecting against this is relatively easy: make sure you have up-to-date Anti-Virus technology installed. Right? Do the following quotes from leading player in the Anti-Virus technology supply base worry you?

  • “Signature AV does not really work except for the obvious stuff”
    James Lyne, Director of Technology, Sophos
  • “It’s no secret that there is a huge industry devoted to bypassing anti-virus.”
    Rob Rachwald, Director of security strategy at Imperva
  • “The truth is, consumer-grade antivirus products can’t protect against targeted malware”
    Mikko Hyyponen, Chief Research Officer of F-Secure
  • “The game has changed from the attacker’s standpoint. The traditional signature-based method of detecting malware is not keeping up.”
    Phil Hochmuth, Industry Analyst, International Data Corporation

They should do! They are essentially saying the traditional approach to Anti-Virus does not work – and the evidence from the increasing rate of security disclosures supports this

What is wrong?

The technical challenge is that viruses / malware technology has evolved to a level such that it is very easy to morph the attack such that it evades the signature based detection mechanisms used by Anti-Virus technology.

The Anti-Virus industry is busy pushing solutions to this based on heuristic techniques. But there is still a fundamental issue here: these approaches are all about trying to detect signatures or behaviour that are known to be bad.

- Advertisement -

Look for Known Good

At Nexor, we have implemented a solution in Nexor Merlin that turns this model in its head. When importing a document into a network (via email, web, or file transfer), rather then examine the file to see if it contains bad stuff, we create a completely new file built from elements that are known to be good. What determines “good”? Well, that depends upon your risk appetite!

More information will follow in the coming weeks about how this approach works. If you can’t wait, please contact us directly or leave a comment below!

To summarise, rather than trying to detect security attack vectors such as used by Operation Shady Rat and Beebus by looking for historically is known to be bad, this patented new approach enables us to protect a business by only allowing the import of data this is known to be good, thus significantly reducing the attack surface of the organization.

- Advertisement -

Related articles:

Boost Your Career: Top 5 Computer Security Courses for Aspiring Cybersecurity Professionals

Discover the top 5 computer security courses to kickstart your cybersecurity career. Learn essential skills and gain certifications to protect digital assets.

Securing the Cloud: Best Practices for Cybersecurity in Cloud Computing Environments

Discover essential cybersecurity practices for cloud computing environments. We explore how to safeguard your data and infrastructure in the ever-evolving digital landscape.

Learning Through Play: 7 Cybersecurity Games That Sharpen Your Hacking Defense Skills

Discover 7 engaging cybersecurity games that make learning fun while boosting your hacking defense skills. We explore how these cyber security games sharpen your expertise.

The Backbone of Cybersecurity: A Deep Dive into Modern Network Security Practices

Discover how network security in cyber security protects organizations from threats. Learn about firewalls, encryption, and best practices for safeguarding digital assets.

5 Critical IT Security Threats You Can’t Afford to Ignore

Discover the top 5 IT security threats that could put your business at risk. Learn how to protect your data and systems from these critical vulnerabilities.

13 COMMENTS

  1. Wow, did you guys read that article on “Documents: a Hackers Gateway to your Enterprise”? Mind-blowing stuff! 🤯 #cybersecurity #mindblown

    • I definitely read it! It’s alarming how easily hackers can exploit documents to infiltrate enterprises. We all need to step up our cybersecurity game. Stay informed, people! 💪🔒 #StaySafe #CyberAware

    • Seriously? Anti-virus software won’t protect you from everything. Stay ignorant and keep updating your software while the real threats evolve. Good luck with that false sense of security.

    • Are you out of your mind? Hacking is illegal and unethical. Don’t glamorize criminal activities just because of a misguided fascination. There are plenty of legitimate career paths to consider. Think before you speak!

LEAVE A REPLY

Please enter your comment!
Please enter your name here