<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ThreatFire Research Blog &#187; Strategy</title>
	<atom:link href="http://blog.threatfire.com/category/strategy/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Do I need ThreatFire?</title>
		<link>http://blog.threatfire.com/2009/03/do-i-need-threatfire.html</link>
		<comments>http://blog.threatfire.com/2009/03/do-i-need-threatfire.html#comments</comments>
		<pubDate>Tue, 03 Mar 2009 18:41:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Strategy]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/03/do-i-need-threatfire/</guid>
		<description><![CDATA[Do I need ThreatFire? That&#8217;s a fairly common question on security forum boards. Yes, systems need a protective behavioral layer like ThreatFire next to an AV scanner, current built-in OS security functionality, and a firewall.Not only do AV scanners have a difficult time keeping up with malware volume from the underground undetectables marketplace, but client [...]]]></description>
			<content:encoded><![CDATA[<p>Do I need ThreatFire? That&#8217;s a fairly common question on security forum boards. Yes, systems need a protective behavioral layer like ThreatFire next to an AV scanner, current built-in OS security functionality, and a firewall.<br />Not only do AV scanners have a difficult time keeping up with malware volume from the <a href="http://blog.threatfire.com/2009/02/antivirus-scanner-sites-and-quest-for.html" target="_blank">underground undetectables marketplace</a>, but client side exploit activity, especially those attacking the most popular web browsers and third party plugins, is in extremely high volume. The obfuscation and variety in web based exploits often lead to an even lower detection rate here.</p>
<p>One of our first posts titled &#8220;How do Storm, NotFound and other threats infiltrate so many PC&#8217;s?&#8221; from <a href="http://blog.threatfire.com/2007/08/how-do-storm-notfound-and-other-threats.html" target="_blank">August 2007</a> detailed a Windows structured exception handler overwriting technique that has been commonly abused over the past few years. It is something commonly seen in the attacks prevented by ThreatFire.<br />Matt Miller, who used to go by &#8220;skape&#8221; and rode alongside H.D. Moore of Metasploit fame, recently posted on a new functionality designed to combat this sort of reliable attack technique in the future. A new &#8220;Structured Exception Handler Overwrite Protection&#8221;, or SEHOP, will replace previous attempts (SafeSEH) at combating the technique. In other words, SEH continues to be bashed in the wild, even with the availability and efforts behind SafeSEH.<br />Interestingly, data supporting the need for SEHOP was based on the percentage of exploits in the Metasploit project that abuse SEH (that number is approximately 20%) and not on exploits observed in the wild.</p>
<p>So, will SEHOP have an impact on the future of client side exploits? Possibly, and more likely, it will have an impact on exploit and shellcode development. We have seen fantastic security attempts like much needed memory space randomization (ASLR) implemented, but even that effort was quickly smashed by the likes of talented researchers <a href="http://www.phreedom.org/research/bypassing-browser-memory-protections/" target="_blank">Mark Dowd and Alexander Sotirov</a>. Granted, tricks were used to abuse various components released and implemented by default in the browser and OS. But that&#8217;s how the exploit market (black, grey, white hat) works. Underlying complexities in massive software projects facing deadlines to market, competitive pressure, and the need for powerful, flexible computing functionality often push software out the door with uncertain results. Creative new talent will continue to take advantage of the uncertainties inherent in this environment, even with creative talent implementing new protective features.</p>
<p>Yes, you need a behavioral layer like ThreatFire, now and for the foreseeable future.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/03/do-i-need-threatfire.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Scanner Sites and the Quest for &quot;Fully UndetecteD&quot;</title>
		<link>http://blog.threatfire.com/2009/02/antivirus-scanner-sites-and-the-quest-for-fully-undetected.html</link>
		<comments>http://blog.threatfire.com/2009/02/antivirus-scanner-sites-and-the-quest-for-fully-undetected.html#comments</comments>
		<pubDate>Tue, 24 Feb 2009 16:30:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[Evasion technique]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Undetected malware]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/02/antivirus-scanner-sites-and-the-quest-for-fully-undetected/</guid>
		<description><![CDATA[It&#8217;s always disappointing to see traditional antivirus scanners miss malware detections, especially those in the formal WildList (the WildList is not dead! Well, not completely). It does and will happen, even with the best performing scanners. And witnessing the detection rates and delays in AV detection updates for various malware families that are being run [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s always disappointing to see traditional antivirus scanners miss malware detections, especially those in the formal WildList (the WildList is not dead! Well, not completely). It does and will happen, even with the best performing scanners. And witnessing the detection rates and delays in AV detection updates for various malware families that are being run on end user systems but prevented by behavioral protection can be a bit overwhelming. Layered protection is an important part of keeping a system secure.</p>
<p>So when we observe &#8220;underground&#8221; activity, it&#8217;s never a surprise to see ongoing and more sophisticated efforts in developing malware that evades AV detection. Some of the efforts are getting more organized, and we continue to see more professional looking services and amateur looking betas popping up that replace the venerable and legitimate <a href="http://www.virustotal.com/" target="_blank">Virustotal</a> and <a href="http://virusscan.jotti.org/" target="_blank">Jotti</a> virusscan sites. We&#8217;ve presented before on some underground services, where blackhat developers offer to write fully undetected stubs (undetected by all of the major anti-virus products), and once they are detected, the developer sends on a limited number of new undetected stubs to their customers. When that limit is reached, the customer shells out some more cash for their new AV evasion kit.<br />Not only the major media grabbers like Storm, Waledac, and botnets related to McColo, but smaller, under-the-radar efforts like the distributors of rogueware and fakeav benefit financially and further this sort of work.</p>
<p>Below is a snapshot of one fairly recent effort put together with malicious intent, to help provide a confirmation that those stubs remain fully undetected without exposing the upload to distribution to AV companies (Virustotal and Jotti both distribute samples to AV companies). Many of the blackhat forums bring on new, unexperienced members that upload new undetected crypters to the legitimate sites, which sends the samples on to AV vendors and has been a problem for their efforts in the past. The site is in beta and slow as molasses.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_YaXoRZbsXc4/SaQkK4DoXqI/AAAAAAAAAwY/JeO48IGqCSE/s1600-h/fudscanner.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 254px;" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/SaQkK4DoXqI/AAAAAAAAAwY/JeO48IGqCSE/s320/fudscanner.png" alt="" id="BLOGGER_PHOTO_ID_5306406030214192802" border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/02/antivirus-scanner-sites-and-the-quest-for-fully-undetected.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Dave&#8217;s $30 Billion Smashter Prediction</title>
		<link>http://blog.threatfire.com/2008/12/daves-30-billion-smashter-prediction.html</link>
		<comments>http://blog.threatfire.com/2008/12/daves-30-billion-smashter-prediction.html#comments</comments>
		<pubDate>Mon, 08 Dec 2008 18:35:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[AntiMalware Solutions]]></category>
		<category><![CDATA[Security breach]]></category>
		<category><![CDATA[Strategy]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/12/daves-30-billion-smashter-prediction/</guid>
		<description><![CDATA[Sometimes you get a crystal ball prediction and gimmickry. Sometimes you get something with real insight. Dave Aitel&#8217;s real insight on DailyDave this morning focused on a NY Times article about the U.S. federal government&#8217;s  National Security Presidential Directive 54/Homeland Security Presidential Directive 23 that Bush signed in January 2008:&#8220;Faster, smashter. When I see [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes you get a <a href="http://blogs.wsj.com/biztech/2008/10/28/tech-security-companies-turn-to-gimmicks/">crystal ball prediction</a> and gimmickry. Sometimes you get something with real insight. Dave Aitel&#8217;s real insight on DailyDave this morning focused on a <a href="http://www.nytimes.com/2008/12/06/technology/internet/06security.html?_r=1&amp;_r" target="_blank">NY Times article</a> about the U.S. federal government&#8217;s  <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/25/AR2008012503261.html" target="_blank">National Security Presidential Directive 54/Homeland Security Presidential Directive 23</a> that Bush signed in January 2008:<br /><a href="http://lists.immunitysec.com/pipermail/dailydave/2008-December/005445.html" target="_blank">&#8220;Faster, smashter</a>. When I see 30 billion dollars, I can tell you what you&#8217;re going to get, as a taxpayer, for your money: Patch management, IDS, Anti-Virus,  scanners of all shapes and sizes. Audits. Big rooms full of large screens correlating information that has absolutely no relevance to security. You can&#8217;t correlate what you can&#8217;t see. You can&#8217;t patch what you don&#8217;t know about.<br />Mr. Markoff is trying to tell us that the defenders are losing the battle. But if they are, it&#8217;s because they *chose* to.  Hackers use 0day and always have. The defenders are off making millions selling things that don&#8217;t work against 0day.<br />I guess what I&#8217;m trying to say here is that at this point the attackers are just &#8220;reasonably competent&#8221;. When it comes to offensive information security, we ain&#8217;t seen nothing yet.&#8221;</p>
<p>NPR, the Washington Post, and the NYT have all been spending more time reporting on computer security. It was very interesting to hear a guest on Boston NPR&#8217;s hour long <a href="http://www.onpointradio.org/shows/2008/12/cyber-warfare/?autostart=true" target="_blank">&#8220;On Point&#8221; this morning</a> discussing characteristics of Secretary of Defense Robert Gates&#8217; laptop and other PC based resources at the U.S. Department of Defense, as well as the legal arm-twisting used to silence individuals that have participated in security breach investigations. And therein lies the real problem. All the discussion in the world about network security is useless when talk about real issues is silenced, and the individuals that need to protect their organization&#8217;s data do not understand or cannot describe what they need to protect it from.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/12/daves-30-billion-smashter-prediction.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global cyber-intelligence</title>
		<link>http://blog.threatfire.com/2008/06/global-cyber-intelligence.html</link>
		<comments>http://blog.threatfire.com/2008/06/global-cyber-intelligence.html#comments</comments>
		<pubDate>Tue, 03 Jun 2008 14:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security breach]]></category>
		<category><![CDATA[Strategy]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/global-cyber-intelligence/</guid>
		<description><![CDATA[You can check out a somewhat lengthy and fascinating article on recent cyber intelligence, SCADA systems and various actors on the global cyber stage at The National Journal.
&#8216;Asked whether Washington knew of hacker involvement in the two blackouts, Joel Brenner, the government’s senior counterintelligence official, told National Journal, “I can’t comment on that.”&#8217;
]]></description>
			<content:encoded><![CDATA[<p>You can check out a somewhat lengthy and fascinating article on recent cyber intelligence, SCADA systems and various actors on the global cyber stage at <a href="http://www.nationaljournal.com/njmagazine/cs_20080531_6948.php">The National Journal</a>.</p>
<p>&#8216;Asked whether Washington knew of hacker involvement in the two blackouts, Joel Brenner, the government’s senior counterintelligence official, told <em>National Journal</em>, “I can’t comment on that.”&#8217;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/06/global-cyber-intelligence.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Strategy and book review</title>
		<link>http://blog.threatfire.com/2007/12/strategy-and-book-review.html</link>
		<comments>http://blog.threatfire.com/2007/12/strategy-and-book-review.html#comments</comments>
		<pubDate>Mon, 31 Dec 2007 21:58:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Book/Doc review]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Security breach]]></category>
		<category><![CDATA[Strategy]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2007/12/strategy-and-book-review/</guid>
		<description><![CDATA[A &#8220;Strategy&#8221; thread was started on the DailyDave mail list by Dave himself, criticizing information warfare papers:&#8220;If you&#8217;re reading an information warfare book or paper you&#8217;ll invariably see a lot of:1. Inane references to Sun Tzu (or, in some even more horrible cases, any two of Sun Tzu, Clausewitz, and John Boyd)2. Declarations that information [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://lists.immunitysec.com/pipermail/dailydave/2007-November/004774.html" target="_blank">&#8220;Strategy&#8221; thread</a> was started on the DailyDave mail list by Dave himself, criticizing information warfare papers:<br />&#8220;If you&#8217;re reading an information warfare book or paper you&#8217;ll invariably see a lot of:<br />1. Inane references to Sun Tzu (or, in some even more horrible cases, any two of Sun Tzu, Clausewitz, and John Boyd)<br />2. Declarations that information warfare is an &#8220;asymmetric attack&#8221;</p>
<p>Dave goes on to drop a couple product names and then describe the money saving mono-culture Microsoft technology implementations within the US .com and .mil communities, and describes it as poor strategy:<br />&#8220;Bad strategies like this result in flailing and moaning as you get defeated over and over by someone with better strategy, not because the battlefield is inherently asymmetric.&#8221;</p>
<p>Unfortunately, <a href="http://biz.yahoo.com/ap/071231/data_breaches.html" target="_blank">this past year was a record year for data breaches</a>, according to a couple of groups. (Although, I&#8217;m not sure that statement is completely true. It seems more to have been a record year for reporting breaches, due to a number of new factors. Incident reporting has always provided only a cloudy window into actual events.)<br />Any way you slice it, in light of the sheer volume of security breaches, Dave&#8217;s statement about the mono-culture of .com and .mil communities is a troubling one &#8212; in spite of a year of record profits for the .com community and record budgets for the .mil community, it seems that technology implementations still are not getting the budget or focus that they require when it comes to effectively addressing security needs.</p>
<p>Another poster on the list responded to Dave&#8217;s complaints <a href="http://lists.immunitysec.com/pipermail/dailydave/2007-November/004782.html" target="_blank">by posting a book review</a> about &#8220;Spec Ops: Case Studies in Special Operations Warfare: Theory and Practice&#8221; by William McRaven, a U.S. Navy SEAL commanding officer. I got a chance to check it out this past week and the eight case studies McRaven analyzes really are fascinating (if you&#8217;re a bit of a military history buff). The theory and principles at the beginning of the book (summarized on the DailyDave post) can be applied to analysis of the targeted attacks that have become much more commonplace on the net. It&#8217;s a stimulating read for security enthusiasts, and applies well to the ongoing security breaches around the world:<br />&#8220;If you can&#8217;t draw the parallels to general security practices from those principles then the book is not for you, otherwise you might find yourself ripping through the book and thinking in an entirely different light by the final chapter.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2007/12/strategy-and-book-review.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
