{"id":13520,"date":"2016-12-05T07:14:02","date_gmt":"2016-12-05T07:14:02","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=13520"},"modified":"2016-12-05T07:14:02","modified_gmt":"2016-12-05T07:14:02","slug":"saudi-hacks-and-the-case-for-endpoint-detection-response","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2016\/12\/05\/saudi-hacks-and-the-case-for-endpoint-detection-response\/","title":{"rendered":"Saudi hacks and the case for endpoint detection &amp; response"},"content":{"rendered":"<p>As reported by <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2016-12-01\/destructive-hacks-strike-saudi-arabia-posing-challenge-to-trump\">Bloomberg<\/a> and <a href=\"\/Users\/alfred.chung\/AppData\/Local\/Microsoft\/Windows\/Temporary%20Internet%20Files\/Content.Outlook\/A1LYJ3ZM\/v\">others<\/a> on Thursday, hackers successfully launched an attack against Saudi Arabian government agencies, including the General Authority of Civil Aviation, the government agency that manages Saudi airports. The attackers, believed to be affiliated with the Iranian government, used the destructive malware Shamoon to wipe data and damage equipment. Shamoon was previously \u00a0used in a 2012 attack that wiped 35,000 computers at Saudi Aramco, the world&#8217;s largest oil company, writes\u00a0<em>Anthony Di Bello, Senior Director and Security Strategist, Guidance Software.<\/em><\/p>\n<p>The Saudi Aramco breach was a watershed moment in the cybersecurity world that generated ripples across the globe. So how, four years later, could a known threat like Shamoon be leveraged again to such an effect?<\/p>\n<p>This attack is the latest to highlight the critical need for Endpoint Detection and Response (EDR) solutions.<\/p>\n<p>Preventing known threats is the bread-and-butter for the myriad of next-gen AV and Endpoint Protection Platform (EPP) tools on the market today. Virtually every organisation has some form of perimeter-based security designed to stop known threats. But as this attack shows us, 100% prevention is not possible, even with well-known malware like Shamoon. However, there are ways to reduce the chance of a successful breach and to prevent malware from quickly spreading across the network should a breach occur. The following diagram illustrates how EPP and EDR work together to create a holistic approach to defence.<\/p>\n<p><em>Figure 1: EPP and EDR work in conjunction to prevent, detect, and respond to threat of all kinds<\/em><\/p>\n<p><img decoding=\"async\" title=\"ER - EPP\" src=\"https:\/\/www.guidancesoftware.com\/images\/default-source\/default-album\/ees-epp2.png?sfvrsn=0\" alt=\"ER - EPP\" \/><\/p>\n<p>On Nov 16, <a href=\"https:\/\/www.gartner.com\/doc\/3512935?ref=AnalystProfile&amp;srcId=1-4554397745\">Gartner<\/a> predicted (or foreshadowed) the new cybersecurity reality, recommending that organisations, \u201ccommunicate the importance of a \u2018continuous response\u2019 security mindset, wherein systems are assumed to be compromised, necessitating monitoring and remediation.<a href=\"\/Users\/austin.dearman\/Desktop\/Blogs\/Security\/Saudi%20Hacks_FInal.docx#_ftn1\" name=\"_ftnref1\">[1]<\/a>\u201d<\/p>\n<p>\u201cContinuous Response\u201d demands an EDR tool like EnCase Endpoint Security. With an EDR solution, Shamoon or other malicious threats can be detected proactively, and if necessary an EDR solution can perform the required triage and remediation, before the malicious binary is executed. EnCase Endpoint security provides a single platform to mitigate exactly this type of threat and completely remove it from the network to possibly prevent, or at least limit, data loss or damage.<\/p>\n<p>This attack also highlights the need for better information sharing in the cybersecurity community to ensure security teams are prepared for similar threats. When information is shared more openly, security teams can use EDR solutions to proactively scan and hunt for similar threats on endpoints. When armed with the right information and a proactive approach, an organisation has a better chance to detect and neutralise a threat before it can cause any real damage.<\/p>\n<p>To learn more about how EnCase Endpoint Security can ensure you are prepared for a breach, please visit: <a href=\"https:\/\/www.guidancesoftware.com\/encase-endpoint-security\">https:\/\/www.guidancesoftware.com\/encase-endpoint-security<\/a> or contact us at <a href=\"mailto:sales@guid.com\">sales@guid.com<\/a>.<\/p>\n<p><em>Anthony Di Bello is a Senior Director and Security Strategist at Guidance Software. Anthony is responsible for the voice of the customer, go-to-market strategy and product roadmaps across Guidance Software forensic security, data risk management and digital investigations products.\u00a0 An 11-year veteran of Guidance, Anthony previously served as director of Strategic partnerships.<\/em><\/p>\n<p>&nbsp;<\/p>\n<div>\n<hr align=\"left\" size=\"1\" width=\"33%\" \/>\n<div id=\"ftn1\">\n<p><a href=\"\/Users\/austin.dearman\/Desktop\/Blogs\/Security\/Saudi%20Hacks_FInal.docx#_ftnref1\" name=\"_ftn1\">[1]<\/a> Gartner, \u201cPredicts 2017: Information Security management\u201d<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>As reported by Bloomberg and others on Thursday, hackers successfully launched an attack against Saudi Arabian government agencies, including the General Authority of Civil Aviation, the government agency that manages Saudi airports. The attackers, believed to be affiliated with the Iranian government, used the destructive malware Shamoon to wipe data and damage equipment. Shamoon was [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":13532,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[829,5,1493,6,16,791],"tags":[101,202,2873,2948,790,277],"class_list":["post-13520","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-choice","category-enterprise-security","category-government","category-insights","category-regional-news","category-ksa","tag-cyber-crime","tag-gartner","tag-guidance-software","tag-hacks","tag-ksa","tag-saudi-arabia"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=13520"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/13520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/13532"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=13520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=13520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=13520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}