The Address Resolution Protocol (ARP) is a core communication protocol used for LANs. RFC 826 defined it in 19821 but paid little attention to security. Although we've been aware of potential attacks against ARP for more than 10 years, we've only recently started observing them in the real world, especially from various Chinese hacking groups. Here, I explain ARP attack fundamentals and analyze recent attacks that used ARP poisoning against Web hosting companies to let attackers insert malicious code into virtually thousands of Web sites.
We collected DNS responses at the University of Auckland Internet gateway in an SQL database, and analyzed them to detect unusual behaviour. Our DNS response data have included typo squatter domains, fast flux domains and domains being (ab)used by spammers. We observe that current attempts to reduce spam have greatly increased the number of A records being resolved. We also observe that the data locality of DNS requests diminishes because of domains advertised in spam.
We collected DNS responses at the University of Auckland Internet gateway in an SQL database, and analyzed them to detect unusual behaviour. Our DNS response data have included typo squatter domains, fast flux domains and domains being (ab)used by spammers. We observe that current attempts to reduce spam have greatly increased the number of A records being resolved. We also observe that the data locality of DNS requests diminishes because of domains advertised in spam.
This chapter covers Defense in Depth (DiD). It deals with Paul Schmehl’s work, in which he takes a broad look at DiD in the enterprise. Following this, it discusses Ken Bechtel’s work, which covers many of the implementation angles. It also considers David Harley’s research, which looks at some specific tools and technologies. Mitigating the impact of malicious code upon the enterprise requires more than just anti-virus (AV) software. It requires a well-thought-out plan of action that addresses various contingencies. This chapter is designed to facilitate that thought process and to outline procedures and issues that can help ensure a reasonable level of protection in a generic corporate environment. Many security practitioners prefer a centrally managed infrastructure with a dedicated AV console. Such a system not only provides positive control of the AV software but also provides critical reports and statistics, resulting in meaningful metrics. These can be used to further enhance the defensive architecture. Current AV products work best against known viruses. Vendors are improving their technology to detect new, unknown viruses using advanced heuristics, but these systems are still evolving, as are the technologies against which they are designed to provide protection.
Members of (the Anti-Virus Information Exchange Network) have been setting agendas in malware management for several years: they led the way on generic filtering at the gateway, and in the sharing of information about new threats at a speed that even anti-virus companies were hard-pressed to match. members represent the best-protected large organizations in the world, and millions of users. When they talk, security vendors listen: so should you. AVIEN's sister organization AVIEWS is an invaluable meeting ground between the security vendors and researchers who know most about malicious code and anti-malware technology, and the top security administrators of who use those technologies in real life. This new book uniquely combines the knowledge of these two groups of experts. Anyone who is responsible for the security of business information systems should be aware of this major addition to security literature. * Customer Power takes up the theme of the sometimes stormy relationship between the antivirus industry and its customers, and tries to dispel some common myths. It then considers the roles of the independent researcher, the vendor-employed specialist, and the corporate security specialist. * Stalkers on Your Desktop considers the thorny issue of malware nomenclature and then takes a brief historical look at how we got here, before expanding on some of the malware-related problems we face today. * A Tangled Web discusses threats and countermeasures in the context of the World Wide Web. * Big Bad Bots tackles bots and botnets, arguably Public Cyber-Enemy Number One. * Creme de la CyberCrime takes readers into the underworld of old-school virus writing, criminal business models, and predicting future malware hotspots. * Defense in Depth takes a broad look at DiD in the enterprise, and looks at some specific tools and technologies. * Perilous Outsorcery offers sound advice on how to avoid the perils and pitfalls of outsourcing, incorporating a few horrible examples of how not to do it. * in Education offers some insights into user education from an educationalist's perspective, and looks at various aspects of security in schools and other educational establishments. * DIY Malware Analysis is a hands-on, hands-dirty approach to security management, considering malware analysis and forensics techniques and tools. * Antivirus Evaluation & Testing continues the D-I-Y theme, discussing at length some of the thorny issues around the evaluation and testing of antimalware software. * AVIEN & AVIEWS: the Future looks at future developments in and AVIEWS. .
This chapter reviews the work of David Harley and Andrew Lee who emphasize the do-it-yourself (D-I-Y) theme, discussing at length some of the thorny issues around the evaluation and testing of antimalware software. Testing is a particularly hot topic among antivirus (AV) professionals. Evaluation in the real world is about painstaking research to find the imperfect solution that best matches one’s particular environment and a future involving lots of monitoring, reviewing, tweaking, filling gaps and cracks, and being prepared to re-evaluate one’s present approach. This chapter explores the question of which antimalware packages should be used and how they should be configured and used to the best advantage. There are a number of other very capable packages, and while some of the core technology is very similar between products, the interfaces can be very different even between individual products in a single vendor’s range, reflecting the very different functionalities between them. There’s a great deal of difference between a no-cost evaluation product (or a free-for-home-use version), and a full-blown multi-platform enterprise edition with central console management and cascading staging servers. In any case, security products (especially AV) change frequently, and sometimes very dramatically.