ANSecurity, a specialist in advanced network and data security, has successfully deployed the Palo Alto Networks TRAPS advanced endpoint solution to help a major financial services organisation strengthen its security controls.

The financial organisation regularly processes a lot of active content from third-party organisations and its workforce had struggled to differentiate between legitimate or malicious attachments within emails.  The organisations had previously used a “traditional” Anti Malware product, in conjunction with Anti-Virus software but found that attacks were still breaching this line of defence.

Proven technology

TRAPS is a technology from Palo Alto that focuses on intercepting the 30 or so underlying techniques that are commonly used across millions of malware examples instead of trying to detect malware signatures that can only be created after an incident. The technology has proven itself as a way of stopping new threats based on understanding these common steps that malware must perform to achieve a successful attack, and Palo Alto claims that these core techniques grow by only a few each year. As a result, Traps offers a way of blocking both common and previously unseen attacks.

“The initial deployment was very fast and we set up TRAPS in its learning mode allowing it identify a number of false positives,” explains Laurence Wright, Network Security Specialist for ANSecurity, “In this mode it starts to identify third party and bespoke in-house developed apps and the regular update processes. Once these were ‘dialled out’ of the detection process, the solution went into production and regular updates from PAN to the client and server software have added features and functionality to ease management, speed up debug and forensic examination of potentially malicious samples and events.”

More visibility over activity

ANSecurity then deployed malware behaviour controls using execution restrictions on unknown software and child process restrictions to allow more visibility over activity at the endpoint. “Some user re-education was required, especially for power-user and developer machines,” explains Wright, “For example, allowing for the delay in execution of newly downloaded EXE files whilst Wildfire analysis takes place and not running them from folders that could be identified as malicious activity.”

TRAPS has proven itself as a way of stopping new threats based on understanding common steps that malware must perform to achieve a successful attack

As a result, the likelihood of a successful core attack technique at the endpoint during the exploitation phase is reduced, even before the malware has a chance to run. As a result of TRAPS, malware related security incidents have reduced to almost zero as well as minimising the time consuming process of dealing with false positives.

“There is no magic bullet that will fix everything but as attacks become more sophisticated, TRAPS is a useful and pretty unique security approach that is able to detect the most dangerous type threats” says Wright, “Although it could be considered as a next generation concept, we have also seen particular interest and success helping customers to protect legacy systems running XP and Windows server 2003 that cannot be patched but are considered critical in areas like SCADA and ICS. We continually recommend migration but this is not always possible straight away and TRAPS has also proven very effective in this role.”

ANSecurity seminar

ANSecurity is running a seminar and hands-on demonstration in collaboration with Palo Alto Networks in London on the 20th October. The session allows participants to take on the role of an attacker and use evasive malware and exploits in an attempt to compromise an endpoint protected by TRAPS.

Save

Save

Save

Download PDF version Download PDF version

In case you missed it

What is the expanding role of audio in today's physical security systems?
What is the expanding role of audio in today's physical security systems?

Audio might detect sounds like breaking glass or footsteps before a person even enters the field-of-view of a video camera. Audio also helps to provide context: Someone running in...

Marin Hospital enhances security with eCLIQ access control
Marin Hospital enhances security with eCLIQ access control

The Marin Hospital of Hendaye in the French Basque Country faced common challenges posed by mechanical access control. Challenges faced Relying on mechanical lock-and-key technol...

Climax releases an advanced smart telecare solution with voice control
Climax releases an advanced smart telecare solution with voice control

GX-MAX-DT35B Smart Care Medical Alarm comes with a brand-new case design. The battery level and the cellular signal strength will be indicated through the white bar on the top cove...

Quick poll
Which feature is most important in a video surveillance system?