Mobile Android Is an Even Bigger Opportunity for Attackers Than Windows PCs

Mobile Android is now a bigger threat opportunity than Windows PCs – in terms of shipments, usage, installed base and the number of vulnerable targets.

According to Statcounter, at the end of 2017, the leading mobile operating system, Android OS, was the most used global operating system, surpassing usage of 17 other operating systems, including Windows. Android had surpassed Windows shipments a few years ago, reaching 1.9 billion by the end of 2017 – nine times the shipments of traditional PCs according to Gartner. There are now 2.7 billion Android-based smart devices in use, compared to an estimated 1.5 billion Windows devices.

Historically, cybercriminals simply did not have enough vulnerable mobile devices out there to make significant attacks worthwhile. That’s changed. Cybercriminals are in it for the money; and they look for the most vulnerable targets, in the greatest quantity, that will take the least amount of effort to breach and have the highest potential for monetary gain.

This building of mobile threat has been foreseen for some time. In 2006, roughly six months before the release of the first iPhone, Scientific American warned about the perils of mobile malware and noted mobile malware growth at that time roughly paralleled that of computer viruses in the first two years after the first PC virus, “Brain,” was released in 1986.

In 1988, computer experts dismissed viruses as inconsequential, vastly underestimating how quickly malware could grow in prevalence, diversity and sophistication. In their 2006 article, Scientific American also warned about making the same mistakes with mobile, pointing out that the bigger the target, the greater the attraction for malicious programmers and that smartphones would soon make up most of the world’s computers (now true).

Outdated Windows devices have proven to be a significant security risk. About 140 million active Windows PCs are still running Windows XP, a 14-year-old operating system that Microsoft stopped updating in 2014. The massive WannaCry cyberattack last year exploited a security hole in the Windows XP operating system.

But in comparison, Android has about one billion of the 2.7 billion active devices running outdated operating systems. That’s about seven times the amount of vulnerable XP devices.

Mobile devices do have had some advantages over Windows security-wise, so maybe that will help stall the pace of infection and attack going forward. Applications are more tightly controlled by OS leaders, like Apple and Google, and users must provide permission to allow access to core phone functions. There are fewer malicious actors adept in mobile software. But counter to that is the more casual attitude of subscribers towards security of their mobile devices and the fact that mobile devices have billing mechanisms built in, leading to SMS fraud.

Most mobile subscribers don’t apply even the basic security passwords, and even fewer install device protection. Permissions in new apps are requested and granted broadly by impatient subscribers. The monetary incentives are also getting sweeter for cybercrime. Use of mobile for financial transactions is growing. The GSMA estimated that the industry processed 22 billion financial transactions in 2016 and identifies mobile technology as key to transforming access to financial services in emerging markets for hundreds of millions of people.

Our Unit 42 threat intelligence team has been analyzing threat trends and reporting on the last four years of new Android malware evolution. Check out their latest research on Android threats.

Will the threat landscape for mobile networks and devices reach the attack volume witnessed with Windows devices and enterprise networks? We believe the answer is “yes,” and we think the trend is well underway.

For mobile network operators, the growing number of attacks threatens their own infrastructure as well as their subscribers. Malware-infected devices can be recruited into botnets and turn against mobile infrastructure to degrade network availability. The full visibility provided by Palo Alto Networks Next-Generation Security Platform is essential as it allows mobile network operators to monitor building threats, identify already infected devices and determine appropriate action.

 

Connect with us at Mobile World Congress in Barcelona

Want to learn what we’re doing to help secure the new hyper-connected world that we live in? Connect with our mobile network specialists or reserve your seat at one of our speaking sessions at Mobile World Congress in Barcelona.

[Palo Alto Networks Research Center]

Unveiling Magnifier Behavioral Analytics: Rapidly Hunt Down and Stop the Stealthiest Network Threats

At Palo Alto Networks, we constantly seek out new ways to achieve our mission to protect our way of life in the digital age by preventing successful cyberattacks. We analyze all the steps threat actors take to carry out their attacks and systematically add new protections to disrupt each step. By blocking threat actors’ every move, we limit the opportunity for any attack to succeed.

To bolster organizations’ ability to stop threats across the attack lifecycle, including hard-to-detect attacks inside the network, we’re pleased to introduce Magnifier behavioral analytics. Magnifier is a cloud-based application that analyzes data collected from the Next-Generation Security Platform, profiles the behavior of users and devices in the network, and detects behavioral anomalies that suggest an attack is underway.

But Magnifier doesn’t stop there. It also gathers high-value information from suspicious endpoints and delivers this information, along with user and device context, in actionable alerts. Based on the investigative detail in alerts, security analysts can quickly block attacks.

Magnifier offers several key features to help security teams find the attacks that matter, respond to threats quickly and overcome the challenges associated with logging enormous amounts of data. These key features include:

  • Automated Detection: Magnifier uses machine learning to analyze rich network, endpoint and cloud data from the Next-Generation Security Platform and profile behavior. Based on this information, Magnifier detects behavioral anomalies that indicate command and control, lateral movement and data exfiltration. Magnifier produces a small number of accurate alerts that reveal targeted attacks, insider abuse and malware running on endpoints.
  • Accelerated Response: Magnifier speeds up investigations by dynamically scanning attack sources to find running processes. Then, Magnifier examines suspicious processes with WildFire cloud-based threat analysis to uncover malware. Security analysts receive detailed user, device and endpoint process information in alerts, providing them the information they need to rapidly block threats with Palo Alto Networks Next-Generation Firewall.
  • Cloud Scale and Agility: As a cloud-based application, Magnifier overcomes the scaling challenges of on-premise analytics and allows Palo Alto Networks researchers to roll out security innovations faster. Magnifier analyzes data stored in our Logging Service, which provides an intelligent, operationally efficient and cost-effective way to store the large volumes of data needed for behavioral analytics. Magnifier also increases the speed of innovation by allowing researchers to rapidly roll out new detection algorithms to all customers at once without lengthy software update cycles causing delays.

Magnifier’s detection algorithms are not new; they are based on award-winning technology from LightCyber, a company Palo Alto Networks acquired in February 2017.

Now that LightCyber’s behavioral analytics technology is a part of the Next-Generation Security Platform, we can deliver even better security outcomes. By leveraging the power of the platform, we gain more data sources for attack detection – including unique User-ID, App-ID and Content-ID information – as well as industry-leading threat analysis from WildFire. Our customers can quickly shut down attacks with the next-generation firewall.

Magnifier analyzes metadata from next-generation firewalls and Magnifier Pathfinder endpoint analysis service to uncover active attacks.

Join us on our journey to transform how organizations combat post-intrusion attacks. Subscribe to the first application available on Palo Alto Networks Application Framework.

Availability
Magnifier is expected to become available in February 2018. Contact your Palo Alto Networks account team to find out if you qualify for a free trial of Magnifier, and gain unprecedented visibility into threats inside your network.

Learn more about Magnifier:

[Palo Alto Networks Research Center]

A More Effective Cloud Security Approach: NGFW for Inline CASB

Cloud applications have changed the way organizations do business, introducing new security risks in the process. These applications are easy to set up and use for collaboration, and as a result, the volume and sensitivity of data being transferred, stored and shared in these cloud environments continues to increase. Simultaneously, users are constantly moving to different physical locations and using multiple devices, operating systems, and application versions to access the data they need.

These are significant shifts in work habits and technology, and traditional security tools have not been able to keep pace. The push to address these security gaps has led to new technologies and ways to describe them, including the cloud access security broker (CASB) category.

According to Gartner, “CASBs are on-premises, or cloud-based security policy enforcement points, placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed. CASBs consolidate multiple types of security policy enforcement.”

CASBs provide organizations with three key SaaS security functions and have seen rapid evolution and adoption as a result: (1) visibility into SaaS usage; (2) granular control over SaaS access, and (3) compliance and security for your cloud-based data. There are different deployment modes by which a CASB can deliver its functions, including inline and API mode. We’ll explore these in a bit more detail below, as well as highlight a simpler, more effective approach: NGFW for inline CASB.

Addressing the CASB Need

The definition of CASB at the time of its inception with the use of the term “broker” implied that CASBs were in the path of your cloud traffic. Since then, CASB technology has evolved and now includes two key components: inline and API mode. Let us look at these two modes briefly.


Inline CASB

Inline CASB can be further broken down into two modes: forward proxy and reverse proxy. With forward proxy, CASB vendors need to forward cloud traffic over to an appliance or service that can provide app visibility and control capabilities. It is also important to note that forward proxy capabilities are not limited to proxies alone. Powerful next-gen app control capabilities can be enforced using NGFW appliance or services as well. This is ideal for multiple reasons as many customers already have NGFW deployed as an internet gateway for on-premises or remote users. If customers prefer to use a true proxy (offered by most CASB vendors), it often introduces additional management overhead and complexity. It is important for customers to consider if their existing NGFW already solves their inline CASB needs without additional cost. In the case of a reverse proxy, CASB vendors use SSO (or sometimes DNS) to re-route users to an inline CASB service to ensure that policies are enforced.


API-Based CASB

The API-based approach allows CASB vendors to access the customer’s data within the cloud application without being “in between” the cloud traffic. It is an out-of-band approach to perform several functions, including granular data security inspection on all data at rest in the cloud application or service, as well as ongoing monitoring of user activity and administrative configurations. The cloud application user experience is preserved as the API is non-intrusive and does not interfere with the data path to the cloud application. In addition to applying policies for any future violations, an API-based CASB is the only way to crawl through existing data stored in the cloud, and remediate any DLP violations and threats. This is particularly important as enterprises end up “sanctioning” an app before they have figured out how to secure it, and there is almost always existing content that needs to be investigated. We will cover API-based CASB in much more detail in an upcoming blog post.

We Have a Simpler Approach: NGFW for Inline CASB

next-generation firewall combines user, content and application inspection features within firewalls to enable CASB functions. The inspection technology is then capable of mapping users to applications to deliver granular control over cloud application usage – regardless of location or device. Relevant features to CASB within NGFW include granular app control (including SaaS and on-premise apps), app-specific function control, URL and content filtering, policies based on application risk, DLP, user-based policies, and preventing known and unknown malware.

Customers who choose an NGFW-based approach should have deployment flexibility, using one or a combination of the following scenarios:

  • NGFW as an appliance: Beyond physical appliances that may already be in place, virtual firewalls can act as gateways in the cloud to ensure maximum global coverage for remote users, eliminating the overhead of deploying additional hardware. Most customers already have this component deployed for on-premise users.
  • NGFW as a cloud service: In this scenario, the multi-tenant, cloud-based security infrastructure should be managed and maintained by the security vendor. For example, the Palo Alto Networks GlobalProtect cloud service enables customers to utilize the preventive capabilities of the Palo Alto Networks Next-Generation Security Platform to secure remote networks and mobile users. The service can be a simple extension to their existing NGFW deployment to prevent the exfiltration of sensitive data across all apps, SaaS-based or not. Customers can reduce the complexity and cost of managing global deployments, and gain consistent protection across cloud environments.

What’s more, when an inline NGFW approach is used as part of an integrated, prevention-first, next-generation security platform – including an NGFW, threat intelligence cloud, API-based SaaS security service and advanced endpoint protection – customers can stop data leaks from their cloud apps; reduce threat exposure by controlling sanctioned and unsanctioned application usage; prevent known and unknown threats within allowed traffic and ensure that their cloud application adoption remains compliant.

A next-generation security platform, in fact, provides complete cloud protection at a lower total cost of ownership than typical CASBs.

To learn more, check out the following resources:

 and 

[Palo Alto Networks Research Center] 

Cybersecurity and Human Factors: Why Cybersecurity Is a Human Issue Rather Than a Technical Problem

I recently had a discussion with Japanese business executives on cybersecurity challenges during which one of them asked me about the biggest difference between Japan and other countries regarding their approach to cybersecurity. I answered, “Each country and sector are different; but if I compare Japan and the United States, the Japanese tend to think cybersecurity is a technical problem, whereas the Americans tend to believe cybersecurity is a human issue, based on previous interactions and feedback from my peers and industry experts in the United States.”

This answer surprised him and brought home the point that cybersecurity touches upon various aspects of human nature and activities, rather than just technical problems. Only humans can do the cybersecurity risk assessment and management because this requires decision-making and resource allocation. People are essential for solving challenges around cybersecurity.

The IBM Security Services 2014 – Cyber Security Intelligence Index shows that more than 95 percent of the cyber incidents that IBM investigated occurred due to human errors, such as system misconfiguration and poor patch management. People are the weakest link in cybersecurity because every single person makes mistakes. That is why social engineering works to trick people into doing something they are not supposed to do, and employers encourage their employees not to open suspicious attachments or click URLs from unsolicited senders.

Of course, cybersecurity includes technical elements. Technology is crucial to address cybersecurity challenges because offerings like firewalls and endpoint protection are needed to prevent malicious actors from achieving their goals by cyber means. Technical knowledge is required to innovate, choose and use those products, as well as to analyze malware.

However, it is equally important to analyze and understand human factors behind cyberattacks and risks because these are the biggest trigger of cybersecurity incidents. Since today’s business environment cannot survive without IT, both IT and cybersecurity should be regarded as business enablers rather than cost centers. That is why the Japanese Ministry of Economy, Trade and Industry (METI) and Information-Technology Promotion Agency (IPA) pointed out in their Cybersecurity Guidelines for Business Leadership Ver 1.1 in December 2016, cyberattacks are an unavoidable business risk in today’s business environment, where IT is part of the infrastructure.

To manage risks, acceptance, avoidance, mitigation, or transfer is needed. If a cybersecurity risk is low or moderate, an organization can decide to accept and not take any cybersecurity action to mitigate it. If a potential cybersecurity risk seems to be unacceptable, the organization may decide to take an action to eliminate the basis of the risk, such as a specific activity or technology. If the organization has resources to shift risk liabilities and responsibilities to the others, who have better expertise, the organization can transfer the risk, such as cyber insurance. If the risk is not acceptable, avoidable, or transferrable, the organization should take cybersecurity approaches to reduce the risk, such as authentication, encryption, or firewall installation.

Investment in risk management is also needed. Yet, information technology (IT) was introduced to business operations mainly to cut costs. Because cybersecurity has traditionally been considered part of IT, it is challenging for companies to realize that it is an area to invest in as a business enabler.

In fact, IPA’s Survey of cyber risk management in companies in 2015 in June 2015 showed that less than 50 percent of even major Japanese companies assess their business risks. Only 49.2 percent of the business leadership of even major companies (their annual sales being over 1 billion yen) answered that they do business risk assessment. The ratio is 28.2 percent at medium-sized companies (their annual sales being between 100 million and 1 billion yen) and 14.9 percent at small companies (their annual sales being under 100 million yen).

Japanese companies are behind American and European companies in this regard. According to IPA’s survey about Chief Information Officers (CIO) and Chief Information Security Officers (CISO) in companies in 2017, 34.6 percent of Japanese companies said that risk visualization is challenging or insufficient. The ratio is higher in Japanese companies than in American (32.4%) or European companies (27.9%). Unless business risks are assessed or visualized, it is impossible for business leadership to determine how much in the way of resources to invest in to accept, avoid, mitigate, or transfer each of their business risks. Resources that are limited in quantity will be wasted.

An Indian folk tale about six blind men and an elephant is applicable to cybersecurity and business risk management. The six men touched different parts of an elephant and pictured the elephant is like a wall, snake, spear, huge fan, cow, or rope. None of them obtained a whole picture of the huge animal because they did not have complete information about it. Luckily, the animal they were touching was a gentle elephant. Were it a lion, touching would not have been a good idea.

What actions, then, should business executives, especially in Japan, take now?

  • Review your business risks and understand what kinds of risks your organization currently faces.
  • Talk to your CISO and his or her team to share cyber risk findings and decide on which actions to take, whether from the stance of acceptance, avoidance, mitigation, or transfer.
  • Prioritize business risks that require immediate action to avoid, transfer, or mitigate them and decide on how much in the way of resources should be spent on each risk.
  • Since C-suites need to balance between usability, security, and budgets, consider applying automation, such as defense and the integration of cyberthreat intelligence, to maximize efficiency and effectiveness.
  • Review your business strategy and revise it to reflect the cyber risk findings to maximize business value for your organization, customers, and partners.

It is indispensable to have a whole picture of business risks to optimize the use of limited resources to manage them. Every organization needs to have good decision-making on business risk management, and only people can do it. This step is a great opportunity to increase your business value.

[Palo Alto Networks Research Center]

New PCNSE Exam Now Available

Our Palo Alto Networks Education and Certification team is pleased to announce the availability of the new Palo Alto Networks Certified Security Engineer (PCNSE) exam. This new role-based certification replaces the previous technology versioned certifications to better prepare you for your career leveraging Palo Alto Networks Next Generation Security platform.

The exam covers topics related to PAN-OS 8.0 software, Panorama, GlobalProtect, and other aspects of the Palo Alto Networks network security platform that a firewall administrator needs to know to design, install, configure, maintain and troubleshoot the vast majority of Palo Alto Networks implementations. (Note: This exam does not cover Aperture, Traps or AutoFocus.)

The PCNSE Study Guide and Blueprint supplies an overview of the exam and explains its scope as well as how a candidate can register and prepare for it. The study guide also shows the objectives covered by the exam, and provides sample questions and resources for candidate preparation.

Why Certification From Palo Alto Networks Matters

A gap in cybersecurity skills and the needs of the industry rank among the top issues facing organizations today. As the fastest-growing security vendor, we realize that training and certifying skilled resources helps our customers tackle their cybersecurity goals confidently.

The majority of Palo Alto Networks customers are moving from legacy technologies to our Next-Generation Security Platform to consume the most advanced features and ensure maximum protection against digital attacks. This transformation to network, endpoint and cloud protection is best achieved with properly skilled resources. The certification program from Palo Alto Networks validates that credentialed individuals possess the Next-Generation Security Platform knowledge necessary to prevent successful cyberattacks and safely enable applications.

There are several other notable benefits of certification from Palo Alto Networks, including having:

  • Projects done right the first time
  • Consistency of implementation
  • Improved team performance and productivity
  • Faster identification, investigation and remediation of issues

Palo Alto Networks certification benefits not only organizations but also the individuals by showcasing their knowledge of the Next-Generation Security Platform. It provides an immediate improvement to their professional profile and, for those with their sights on the future, aligns them with the fastest-growing security company.

For more information, visit the PCNSE Certification page or join us for CERT FEST, our upcoming PCNSE exam preparation workshop.

[Palo Alto Networks Research Center]

English
Exit mobile version