More Than One-Fourth of Malware Files “Shared”

Last week, Netskope released its global Cloud Report as well as its Europe, Middle East and Africa version highlighting cloud activity from January through March of 2016. Each quarter we report on aggregated, anonymized findings such as top used apps, top activities, top policy violations, and other cloud security findings from across our customers using the Netskope Active Platform, including by industry.

This report took up where we last off last quarter on our cloud malware research, in which we found that 4.1 percent of enterprises had at least one sanctioned cloud app laced with malware. This quarter that number has risen to 11.0 percent, or nearly triple since last quarter. This is before counting unsanctioned apps, which we are researching and will incorporate into future reports. When we do, we expect these numbers to increase dramatically. Beyond sharing volume of detections, this quarter’s report breaks down those malware into the following observed categories, several of which are known to be used to distribute or propagate ransomware:

  1. JavaScript exploits and droppers
  2. MS Office macros
  3. Backdoors
  4. Mobile malware
  5. Spy- and Adware
  6. Mac malware

We also rated discovered malware in terms of its severity based on the extent to which it affects user privacy and computer security and causes damage to files, computers, or networks. 73.5 percent of detected malware this quarter ranks “high” in terms of severity, with 8.3 percent “medium,” and 18.2 percent “low.”

Perhaps the most shocking finding is that 26.2 percent of discovered malware files had been shared, either internally (with one or more people inside of the organization), externally (with one or more people outside of the organization), or publicly (with a publicly-accessible link). Sync and share, two important capabilities that characterize the cloud, are liabilities when it comes to malware because malware can use sync and share to propagate rapidly between users and devices, and the reason we dubbed this issue the cloud malware fan-out effect.

What do we recommend to combat the fan-out? Five things:

  1. Back up versions of your critical content in the cloud. Enable your app’s “trash” feature and set the default purge to a week or more. This is one of your best bets for preserving your data should you become infected with data destructing malware such as ransomware.
  2. Use your CASB to scan for and remediate cloud malware in your sanctioned apps. Make sure to check for infected users through sync and share. Integrate your CASB with, and share detections across, your existing security infrastructure such as your sandbox and endpoint detection and response (EDR) so you can stop malware wherever it’s propagating in your environment.
  3. Detect malware incoming via sanctioned and unsanctioned apps.
  4. Detect anomalies in your sanctioned and unsanctioned cloud apps, such as unusual file upload activity or other out-of-the-norm behaviors.
  5. Monitor uploads to sanctioned and unsanctioned cloud apps for sensitive data, which can indicate exfiltration in which malware is communicating with a cloud-based command and control server.

Krishna Narayanaswamy, Chief Scientist, Netskope

[Cloud Security Alliance Blog]

Is That You We Saw at Palo Alto Networks Day Japan?

Thanks to everyone who made our record-breaking Palo Alto Networks Day Japan what it was. Watch below a wrap-up of the event — and see if you can spot yourself!

For more on Palo Alto Networks Day

[Palo Alto Networks Research Center]

Customer Spotlight: Warren Rogers Achieves PCI Compliance in its Cloud-based Data Center

Warren Rogers Associates (Warren Rogers) specializes in statistical analyses and advanced system diagnostics for the retail petroleum industry. As an industry leader in retail fuel monitoring and diagnostics, Warren Rogers manages thousands of data collection devices, installed at service stations across the United States, that gather data and transmit it back to the Warren Rogers data center for analysis and reporting.

Because these data collection devices reside alongside the fuel station business systems that handle credit and debit card data, Warren Rogers must guarantee the protection of cardholder data and ensure PCI DSS compliance by segmenting traffic and preventing malicious network traffic from penetrating the company’s cloud-based corporate data center.

By deploying Palo Alto Networks Next-Generation Security Platform with VM-Series next-generation virtualized firewalls and GlobalProtect gateways in AWS, Warren Rogers created aPCI-compliant network that automatically blocks cardholder data from other network traffic. With the virtualized Palo Alto Networks platform deployed in multiple Amazon Web Services (AWS) regions, Warren Rogers also achieved disaster resilience to ensure continuous availability ofthreat prevention and secure gateway services while simplifying day-to-day administration. As Warren Rogers continues to expand its business, the Palo Alto Networks platform also helps the company onboard new customers.

“Every customer is different in the way they implement our On Site Processors (OSP) at their fueling locations,” Matthew McLimans, Computer Engineer at Warren Rogers, says. “The Palo Alto Networks platform provides a uniform approach for implementing security regardless of where the OSP sits on their local network. Palo Alto Networks is also a brand our customers recognize as a leader in the security market, which makes everyone more comfortable.”

Read the full case study.

[Palo Alto Networks Research Center]

English
Exit mobile version