Finnish CERT flags advanced evasion techniques

Powered by SC Magazine
 

Exploits leave IPS for dead, vendor claims.

A Finnish security vendor has in the last year uncovered 163 so-called advanced evasion techniques (AET) that it says can bypass modern security.

Stonesoft classified the techniques as those that make exploits appear as regular traffic and could bypass modern security like firewalls and intrusion prevention systems.

It said intrusion prevention systems were vulnerable to AETs because they could only detect intrusion attempts that matched a signature base. The technology was less capable than anti-virus to blocking new threats.

The latest AETs consisted of 54 unique evasions and 109 combinations that were found capable of bypassing multiple modern intrusion detection and prevention systems. They work over protocols including IPv4, IPv6, TCP and HTTP.

Stonesoft reported 23 AETs to the Finland Computer Emergency Response Team (CERT-Fi) in October last year.

The CERT then alerted more than 50 vendors, but only a handful had hardened their products to defend against the attacks more than six months after it was reported.

 “Network security vendors have now had more than a year to provide their customers protection against AETs, but unfortunately we still have not seen much success in this area,” Stonesoft chief executive Ilkka Hiidenheimo said.

“Most of the vendors who acknowledge the problem are incapable of building a working solution - instead, they are keeping themselves busy doing temporary and inflexible fixes. The rest just ignore the issue and do nothing.”

Copyright © SC Magazine, Australia


Finnish CERT flags advanced evasion techniques
 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 844

Vote