Watch: The Palo Alto Networks-VMware NSX Integration Explained

In this latest of our lightboard sessions, Warby Warburton shows how the seamless integration between VMware NSX and our VM-Series virtualized Next-Generation Firewalls allows you to automate security provisioning, inclusive of firewall services and associated security policies, as a means of segmenting your virtual machines using Zero Trust principles.

Watch below to better understand next-generation security that will keep pace with your virtualized data center:

For more on Palo Alto Networks integration with VMware

For more Palo Alto Networks lightboard videos

[Palo Alto Networks Blog]

Tracking the WireLurker Arrests

Well that was fast.

Not quite ten days after we released our white paper on WireLurker, arrests have already been made in China.  WireLurker is a new family of malware specifically targeting iOS devices via USB.  There is WireLurker malware for both Mac OS X and Microsoft Windows operating systems.

WireLurker works by looking for any iOS devices connected via USB with an infected OS X or Windows computer. When it detects one, it installs downloaded third-party applications or automatically generated malicious applications onto the device, regardless of whether it is jail broken. This is the reason we call it “wire lurker”.

On November 14, the Beijing Municipal Public Security Bureau announced it had arrested three people in connection with the WireLurker malware.  The police received a tip from the Chinese technology company Qihoo 360 and subsequently arrested three individuals, respectively surnamed Chen, Li, and Wang. The third-party app store that had been serving WireLurker, Maiyadi, was also shut down.

The police have not released the suspects’ full names, but several Chinese sources are reporting two of them may be the founders of Maiyadi, Chen Peng and Wang Jian.  The third is likely the “Li Fei” whose name appears in the Windows WireLurker code, and had a certificate from Apple used in the iOS version.  As noted in an earlier WireLurker blog, these details support the technical analysis that indicated a likely tie between Maiyadi and the malware.

It is not known if the developer previously tracked down and accused of being tied to WireLurker is among those arrested, or whether his claim of innocence is founded. Of note, the Chinese-language forum that originally publicized that developer’s information was served with legal paperwork and deleted the respective content.  Interestingly, the lawyer CC’d a Maiyadi email account for Chen Peng when sending the paperwork, one of the individuals who may been arrested. A screenshot of the removal request from the lawyer is below.  The two highlighted characters in the CC’d line are Chen Peng.

Figure 1. Removal letter from a lawyer sent to the Chinese-language forum that initially published a possible WireLurker-related developer’s personal information. The characters highlighted in blue on the CC’d line are Chen Peng, a Maiyadi founder possibly among those arrested last week for WireLurker.

We will continue to monitor for WireLurker-related activities and make updates here as appropriate.

[Palo Alto Networks Blog]

The Grey Area in App Behaviors: It’s Not Malware, But It’s Still a Concern

Beyond the glitzy hardware and the mind-blowing specs of your smartphone and tablet, the real factor for determining functionality comes from the apps. Most apps are not out do harmful things, but some are.

Malware, by definition, are apps that are out to do subversive and often harmful things. They are operating on a hidden agenda of the attacker’s design. There’s no question that malware is something that must be prevented as part of an enterprise mobile security strategy.

One challenge here is that some app behaviors are not so easily defined. There’s a range of behaviors that fall into a grey zone, because they make use of personal data in unexpected ways. Many apps access information about the mobile device, the user, app data, location, and contacts, sometimes for purposes unknown because the app doesn’t even need the information. With all the network services available via a mobile device, that also means this data can be sent to third parties as well.

In many cases, there are a few reasons for these activities, including ambivalence about the permissions granted to an app and the growing use of third party mobile ad network libraries. In the former, the permissions granted come as a result of the click-through presented to users when they install an app. Most users do not pay close attention to what these permissions do or why they’re necessary, they just want to use the app.

Many app developers use mobile ad networks to create a source of income for apps that are otherwise very cheap or free. These ad networks sometimes take very aggressive measures to collect user information. We have seen these ad networks used for the delivery of malicious code as well.

Thus, we have a growing grey area of apps that may not be malicious in the same vein as malware, but could aggressively collect end user information often without the user’s knowledge. This presents a set of dangerous conditions because the user isn’t fully aware of what’s happening, the data is being shared outside of the context of the device, and there’s no transparency on what’s happening with the data once it leaves the device.

These conditions create a large, undefined problem space: what are apps trying to do with your data and do you know about it? Researchers from Carnegie Mellon University have sought to address this issue by grading apps based on metrics for privacy concerns. The results are interesting, because they do shine light on just how many issues exist, and how even very popular apps are not as straightforward as they might appear to be.

The article does call attention to the prevalence of issues in apps targeted at children. I suspect this is largely to do with the economics of children’s apps, as the casual games market typically relies on free-to-play models subsidized by advertising or in-app purchases, thus introducing the third party library that performs additional data gathering.

Today, people expect to use both personal and business apps on the same device. Whether it’s a personally owned device or a corporate device, there are going to be mix of non-business apps installed on it as well. As a result, the concern over how to protect data on mobile devices becomes far more complex, as bad actors cover a gamut of privacy and security behaviors.

As your mobile security strategy evolves, consider how you will plan to address apps and threats. From one standpoint, your organization must clearly take a proactive stand to stop malware and spyware. But you should also consider protecting data from the apps that fall in this grey area: not exactly malware, but definitely a concern. This requires protecting business data and keeping it away from the other apps installed on the device. All of these efforts should be applied and tied together with network security to enforce policy.

These are all principles that underline the philosophy behind GlobalProtect, the mobile security solution from Palo Alto Networks. To learn more about GlobalProtect, visit our resources page here.

[Palo Alto Networks Blog]

Palo Alto Networks Named to Deloitte’s 2014 Technology Fast 500

Palo Alto Networks was again named to Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media communications, life sciences and clean technology companies in North America. We’re proud to be one of a few enterprise security companies to make the Top 50 rank, which we attribute to rapid adoption this past year of our Enterprise Security Platform. (See the full 2014 Deloitte Technology Fast 500 list here.)

 

By focusing on prevention of both known and unknown threats, versus detection and remediation, we can offer network security, cloud-based threat intelligence and Advanced Endpoint Protection in one integrated, automated platform. See how our platform protects every corner of your organization, from your mobile workers to the core of your virtualized data centerhere.

[Palo Alto Networks Blog]

Moving Cybersecurity Discussions Beyond the IT Department and Into the Board Room

Earlier this week more than 100 participants gathered at the Copenhagen Marriott in Denmark for an emergency meeting on Cyber Crime, coordinated through AmCham Denmark in cooperation with the Overseas Security Advisory Council and partners Deloitte, Palo Alto Networks and Symantec.

We’re pleased to have been part of this important event, titled “Align Business and Security Now” and focused on how to move discussions of security beyond the IT department and into the board room. Along with presentations from the Danish Center for Cyber Security, the U.S. Federal Bureau of Investigation, Deloitte and Symantec, our own Stijn Rommens, systems engineering manager for Northern Europe, discussed why aligning all processes, technology and people — not just perimeter protection — is crucial to an effective security posture.

From left to right: Lars Bennetzen (moderator), Stijn Rommens (Palo Alto Networks), Janus Friis Bindslev (Deloitte), James Hanlon (Symantec), Sigurd Hellums (Palo Alto Networks) and Morten Efferbach (Symantec). 

Click here to see more details and a full photo gallery from the event.

[Palo Alto Networks Blog]

English
Exit mobile version