Daily Mirror (Sri Lanka)

Sophos research finds nearly a quarter of malware communicat­es using TLS

- „ By Pradeep Piyasena

A sampling of malware analyses made over the last six months by Sophos, a global leader in nextgenera­tion cyber security, finds that nearly one-third of malware and unwanted applicatio­ns enter the enterprise network through TLS (Transport Layer Security)-encrypted flows.

The research also observes that more malicious functions are being orchestrat­ed from the Command and Control (C2) server, rather than implemente­d in the malware binary.

The research, which was released in conjunctio­n with Sophos’ latest release of a new architectu­re for its XG Firewall, explains how 23 percent of malware families use encrypted communicat­ion for C2 or installati­on.

“Out of all the malware that made some kind of network connection during their infection process, about 23 percent communicat­ed over HTTPS (Hypertext Transfer Protocol Secure), either to send or receive data from the C2, or during installati­on when they may use HTTPS to conceal the fact that they are retrieving malicious payloads or components,” Luca Nagy, a researcher at Sophos wrote in a blog article titled ‘Nearly a Quarter of Malware now Communicat­es Using TLS’.

The article details, for example, three common and ever-present Trojans – Trickbot, Icedid and Dridex – that leverage TLS during the course of their attacks. Cybercrimi­nals also use TLS to hide their exploits, payloads and stolen content and to avoid detection. In fact, 44 percent of prevalent informatio­n stealers use encryption to sneak hijacked data, including bank and financial account passwords and other sensitive credential­s, out from under organizati­ons.

Network traffic encryption is more important for Trojans, especially informatio­n stealers, says the research. “An informatio­n stealer’s main goal is to collect as much data about the victim as possible, including sensitive financial informatio­n, and remain undetected while doing so. Among our sample set, informatio­n stealers made up 16 percent of the total number of samples tested during the time period.”

The newly-introduced ‘Xstream’ architectu­re for Sophos XG Firewall with high performanc­e TLS traffic decryption capabiliti­es that eliminate significan­t security risk associated with encrypted network traffic, which is often overlooked by security teams due to performanc­e and complexity concerns. XG Firewall now also features Ai-enhanced threat analysis from Sophos Labs and accelerate­d applicatio­n performanc­e.

 ??  ??
 ??  ??

Newspapers in English

Newspapers from Sri Lanka