33
SOPHOS - Soluzioni di deep learning ed EDR, utilizzate per creare report in ambito forense Giovanni Giovannelli Senior Sales Engineer Amelia, 18 Ottobre 2019

SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

SOPHOS - Soluzioni di deep learning ed EDR, utilizzate per creare report in ambito forense

Giovanni GiovannelliSenior Sales Engineer

Amelia, 18 Ottobre 2019

Page 2: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Sophos HistoryEvolution to Synchronized Security Evolved

1985

Founded in Abingdon (Oxford), UK

Peter Lammer c1985

Jan Hruskac1985

Divested non-core Cyber business

Acquired DIALOGS

Acquired Astaro

2011 2012 2013

Acquired UtimacoSafeware AG

20081988

First checksum-

based antivirus software

1989

First signature-based antivirus software

1996

US presence established in Boston

Voted best small/medium sized company in UK

Acquired ENDFORCE

2014

Acquired Cyberoam

Acquired Mojave

Networks

AcquiredBarricade

IPO London Stock Exchange

Launched Synchronized Security

2007 2015

Acquired Surfright

20172016

AcquiredPhishThreat

AcquiredReflexion

2019

AcquiredAvid Secure

AcquiredDarkBytes & Rook Security

AcquiredInvincea

Autonomous Systems

Reactive SystemsControl Systems

Machine learning

Public Cloud Secured

EDR / MTR

Page 3: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

3

Page 4: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

DeepLearning

Suspicious!

Synchronized Security

Pre-Execution Post-Execution

AntiVirus

WANTED!

BANK

BehaviorMonitoring

Actions!

$£€

Exploit Prevention

Techniques!

Endpoint Technologies

Page 5: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

04

EXP

LOIT

05

INST

ALL

Anatomy of an Attack – The Cyber Kill Chain

5

01R

ECO

N03

DEL

IVER

02

DEV

ELO

P

06

C&

C

07

AC

TIO

NS

Page 6: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Delivery Exploit Install C&C Actions

Layered DefenseIntercept X Advanced with EDR

CODE MITIGATIONS

LOCAL PRIVILEGE MITIGATION

CREDENTIAL THEFT PROTECTION

MACHINE LEARNING

MEMORY MITIGATIONS

SAFE BROWSING

ANTI-RANSOMWARE

APC MITIGATION

PROCESS PROTECTIONS

APPLICATION LOCKDOWN

INVESTIGATE & REMOVEThreat CasesSophos Clean M with SafeStore

SYNCHRONIZED SECURITYHeartbeat

MALICIOUS TRAFFIC DETECTION

APPLICATION CONTROL

PERIPHERAL CONTROL

DOWNLOAD REPUTATION

DATA LOSS PREVENTIONWEB PROTECTION

WEB CONTROL

ANTI-MALWARE

PRE-EXECUTION BEHAVIOR ANALYSIS

POTENTIALLY UNWANTED APPS

LIVE PROTECTION

RUNTIME BEHAVIOR ANALYSIS

DETECT & RESPONDAI Expert InsightsCross-Estate HuntingSophosLabs Threat Intelligence

Page 7: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Phishing Malicious URL

Credential Theft

RansomwareCommand & Control

Privilege Escalation

Malicious Executable

Data Exfiltration

Server Attack

Power of the Plus

Anti-Exploit

Phishing Training

Web Control

Malicious Traffic

Server

Anti-Ransomware

DLP

1. Delivery andInstruction

Exploit and Execution

BOOM!2. 3. $$$

Code Cave Weaponized Doc

Anti-Exploit

Deep Learning

Hashes

Application Exploit

EDR

Behavior

Page 8: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Sophos Deep Learning Malware Detection Features

• Prevents both known and never-seen-before malware

• Blocks malware before it executes

• Does not rely on signatures

• Classifies files as malicious, potentially unwanted apps (PUA), or benign

• Extremely small footprint (under 20MB) with infrequent updates

• Detects malware in approximately 20 milliseconds

• Protects even when the host is offline

• Works out of the box, no additional training needed

Page 9: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Synchronized Security

BANK$£€

Page 10: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

BANK$£€

Endpoint Detection& Response

SophosLabsThreatIntelligence

Page 11: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Infection chain

.ZIP .JS .PS1

.EXE

.BAT

Page 12: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Intercept X w/ EDR: Detect

Machine learning identifies top suspicious events to investigate

Page 13: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Intercept X w/ EDR: Detect

Easily search by IP address, file name, hash, etc.

Page 14: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Threat Search

Page 15: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Guided Incident Response

15

Page 16: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Security analysis: Cross-estate threat hunting

Page 17: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Threat Analysis Center

17

• EDR Across Endpoint and Server

All threat cases, alerts and searches, across all device types

Page 18: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Hardest part of EDR: Knowing where to start

18

#1Desired EDR feature

Identification of Suspicious Events

Source: Sophos Q1 2019 security survey of 3,100 IT decision makers in 12 countries across five continents

Page 19: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

AI Driven Threat HuntingGroundbreaking machine learning from SophosLabs data science team (coming soon)

Automated Hunting Prioritized Cases

Page 20: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Threat intelligence analysis: Access on-demand threat intelligence curated by SophosLabs

Page 21: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Malware Analysis

Analyze files using deep learning

Page 22: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Understand your security posture with guided investigations

Page 23: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Respond with the click of a button

Page 24: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Day in the Life of an Analyst

*Coming in 2019

Sees Dropper.exe distributed malware (which was blocked)

Remediates threat “Clean and block”

Identifies top incident as Dropper.exe via

Threat Indicators

Determines where else Dropper.exe exists

Requests more details from SophosLabs

Uses Deep Learning to determine file is malicious

Page 25: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Intercept X w/ EDR: Respond

Respond to incidents with a click of a button• Full disclosure of potential threat activity• Isolate machine(s)• Clean file, blacklist or whitelist• Investigate further, create forensic snapshots

Page 26: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

The Forensic Snapshot

26

Page 27: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

The Forensic Snapshot

27

Page 28: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Protect Detect Respond

Prevent attacks and proactively

secure known vulnerabilities

Detect active attacks and identify

potentially malicious behaviors

Rapidly investigate and remediate

incidents to minimize impact

Core Security Capabilities

28

Page 29: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

Core Security Capabilities

29

Protect Detect Respond

EDR

MTR

+EDR

+

+

Page 30: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

We notify you about the detection

and provide detail to help you in

prioritization and response

Notify

We work with your internal team

or external point(s) of contact to

respond to the detection

Collaborate

We handle containment and

neutralization actions and will

inform you of the action(s) taken

Entrust

Response Modes

You choose the best way for our MTR

team to work alongside you

Page 31: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

PARTNER SOPHOS:S.O.S. COMPUTER 2000

www.soscomputer2000.eu/?page_id=155Intercept X + EDR

Page 32: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures

PARTNER SOPHOS:S.O.S. COMPUTER 2000

www.soscomputer2000.eu/?page_id=155Sophos MTR

Page 33: SOPHOS - ONIF · Sophos Deep Learning Malware Detection Features •Prevents both known and never-seen-before malware •Blocks malware before it executes •Does not rely on signatures