{"id":22748,"date":"2016-05-31T20:09:15","date_gmt":"2016-05-31T12:09:15","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=22748"},"modified":"2016-05-31T20:09:15","modified_gmt":"2016-05-31T12:09:15","slug":"can-ransomware-today-tomorrow","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2016\/05\/31\/can-ransomware-today-tomorrow\/","title":{"rendered":"What we can do about ransomware \u2013 today and tomorrow"},"content":{"rendered":"<p><strong>By Alan Zeichick<br \/>\nPrincipal Analyst, Camden Associates<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/05\/ransomware.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-22749\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/05\/ransomware.jpg\" alt=\"ransomware\" width=\"620\" height=\"445\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/05\/ransomware.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/05\/ransomware-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/a><\/p>\n<p>Ransomware is a huge problem that\u2019s causing real harm to businesses and individuals. Technology service providers are gearing up to fight these cyberattacks \u2013 and that\u2019s coming none too soon.<\/p>\n<p>In March 2016, Methodist Hospital reported that it was operating in an internal state of emergency after a ransomware attack encrypted files on its file servers. The data on those servers was inaccessible to the Kentucky-based hospital\u2019s doctors and administrators unless the hackers received about $1,600 in Bitcoins.<\/p>\n<p>A month earlier, a hospital in Los Angeles paid about $17,000 in ransom money to recover its data after a similar hack attack. <a href=\"http:\/\/hollywoodpresbyterian.com\/default\/assets\/File\/20160217%20Memo%20from%20the%20CEO%20v2.pdf\">According to the CEO of Hollywood Presbyterian Medical Center, Allen Stefanek<\/a>, \u201cThe quickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key.\u201d<\/p>\n<p>As far as we know, no lives have been lost due to ransomware, but the attacks keep coming \u2013 and consumers and businesses are often left with no choice but to pay the ransom, usually in untraceable Bitcoins.<\/p>\n<p>The culprit in many of the attacks \u2014 but not all of them \u2014 is a sophisticated trojan called <a href=\"https:\/\/nakedsecurity.sophos.com\/2016\/02\/17\/locky-ransomware-what-you-need-to-know\/\">Locky<\/a>. First appearing in 2013, <a href=\"https:\/\/blog.avast.com\/a-closer-look-at-the-locky-ransomware\">Locky is described by Avast<\/a> as using top-class features, \u201csuch as a domain generation algorithm, custom encrypted communication, TOR\/BitCoin payment, strong RSA-2048+AES-128 file encryption and can encrypt over 160 different file types, including virtual disks, source codes and databases.\u201d Multiple versions of Locky are on the Internet today, which makes fighting it particularly frustrating. Another virulent ransomware trojan is called <a href=\"http:\/\/www.pandasecurity.com\/mediacenter\/malware\/cryptolocker\/\">CryptoLocker<\/a>, which works in a similar way.<\/p>\n<p>Ransomware is a type of cyberattack where bad actors gain access to a system, such as a consumer\u2019s desktop or a corporate server. The attack vector might be provided by downloading a piece of malware attached to an email, visiting a corrupted website that runs a script that installs the malware or by opening a document that contains a malicious macro that downloads the malware. In most ransomware attacks, the malware encrypts the user\u2019s data and then demands an untraceable ransom in order to either decrypt the data or provide the user with a key to decrypt it. Because the data is encrypted, even removing the malware from the computer will not restore system functionality; typically, the victim has to restore the entire system from a backup or pay the ransom and hope for the best.<\/p>\n<p>As cyberattacks go, ransomware has proven to be extremely effective at both frustrating users and obtaining ransom money for the attackers.<\/p>\n<p>Beyond the ransom demands, of course, there are other concerns. Once the malware has access to the user or server data\u2026 what\u2019s to prevent it from scanning for passwords, bank account information, or other types of sensitive intellectual property? Or deleting files in a way where they can\u2019t be retrieved? Nothing. Nothing at all. And even if you pay the ransom, there\u2019s no guarantee that you\u2019ll get your files back. The only true solution to ransomware is prevention.<\/p>\n<p><strong>RANSOMWARE\u2019S SCOPE AND IMPACT<\/strong><\/p>\n<p>The U.S. Federal Bureau of Investigation received 2,453 complaints about ransomware cyberattacks in 2015, which the FBI says cost the victims more than $24 million dollars in ransom. Who knows how many people quietly paid and didn\u2019t tell anyone, because of shame, perhaps, or lack of knowledge about who to tell?<\/p>\n<p>One top network security vendor, <a href=\"http:\/\/www.wedgenetworks.com\/\">Wedge Networks<\/a>, has seen huge growth on the carrier networks that its service monitors. \u201cOn those networks\u201d, says CEO James Hamilton, \u201cWe saw a 100% increase in the observed number of ransomware attacks detected in 2015 verses 2014, and a 50% increase in mobile ransomware from Q4 2015 to Q1 2016.\u201d<\/p>\n<p>Wedge Networks is an Alberta, Canada-based company with extensive customer deployments across Canada, the United States and Asia Pacific. Mr. Hamilton explains that \u201cLast year, our customers in Canada reported more ransomware attacks (as a percentage) than we observed in the U.S. In APAC, Japan and Taiwan are experiencing a slower increase in ransomware than we\u2019re seeing in Southeast Asia, possibly due to more mature and advanced security practices in those markets.\u201d<\/p>\n<p>Mr. Hamilton continues, \u201cJust last week I was discussing ransomware with a service provider planning to roll out Security-as-a-Service in a major Southeast Asia market and they stated that ransomware has become more widely active in their country over the past 12 months. Previously it was very infrequent, but they are seeing it spread rapidly.\u201d<\/p>\n<p>Jason Steer, EMEA Solutions Architect for <a href=\"https:\/\/www.menlosecurity.com\/\">Menlo Security<\/a>, based in Menlo Park, Calif., explained that while consumers can lose important files, especially irreplaceable financial documents and personal photos, ransomware can be devastating for businesses.<\/p>\n<p>\u201cFor enterprises, ransomware is a major pain and slows them down from getting on with their key IT-related business functions,\u201d Mr. Steer explains, adding that Menlo Security focuses on malware prevention. \u201cWe have met many customers where every local file and central server stored file has been encrypted by ransomware. This impacts every user accessing any central file on the network and for any user impacted it encrypts every local file on their PC as well.\u201d<\/p>\n<p>The impact? \u201cYou are dependent on the age of the most recent backup and may not be able to restore every file. The cost of losing that data may be minimal or large depending on the importance of the file.\u201d<\/p>\n<p><a href=\"https:\/\/www.cylance.com\/\">Cylance<\/a> has seen some pretty devastating ransomware damage recently. A cybersecurity firm based in Irvine, Calif., the company is spending a lot of time helping its customers prevent ransomware attacks, as well as helping new victims recover from trojans. Andy Solterbeck, Regional Director APAC for Cylance, explained about <a href=\"http:\/\/www.cyber.nj.gov\/exploit-kit-angler\/\">Angler<\/a>, a cyberattack exploit toolkit that hackers can use to customize their own attacks \u2013 kind of a do-it-yourself starter kit. The damage from Angler: \u201cIt\u2019s currently causing 90,000 infections per day, and bringing in at least $60 million dollars per year.\u201d<\/p>\n<p>There are so many attack vectors, it\u2019s virtually impossible for a consumer \u2013 or an IT professional \u2013 to keep track of them all. Jayendra Pathak, Chief Architect at <a href=\"https:\/\/www.nsslabs.com\/\">NSS Labs<\/a>, a top tech security analyst firm based in Austin, Tex., says \u201cAdobe Flash is becoming an extremely troublesome vector towards delivering ransomware. Microsoft Word attacks are also on the rise, exploiting human weaknesses in opening email attachments.\u201d<\/p>\n<p>The days of paying a few hundred dollars as ransom may be over, as cyberattackers target businesses, Mr. Pathak adds. \u201cOn top of that, ransomware authors are moving to more targeted campaigns aimed at the enterprise. Asking ransom for hundreds of thousands of dollars is on the near horizon. NSS Labs has tracked thousands of infections primarily coming from drive-by campaigns.\u201d He adds that while ransomware is a problem all over the world, it is more prevalent in areas where online payment systems are extremely common. \u201cThe United States and Europe are primarily targeted. Japan, Korea, China, and Singapore\u2019s ransomware infection rates are relatively less in comparison to Europe and the U.S. However, APAC countries must take note of the prevalence of ransomware attacks in the U.S. and Europe. Now is the time to be embracing preventative cybersecurity measures.\u201d<\/p>\n<p><strong>THE INDUSTRY RESPONDS<\/strong><\/p>\n<p>For consumers, the best way to prevent a ransomware attack is to be proactive. Backup often, and maintain many backups so that recovery can pre-date the infection. Don\u2019t click on email attachments. Use up-to-date anti-virus and anti-malware tools and services. Don\u2019t use old versions of Web browsers that lack current protections. Disable macros in Microsoft Word and Microsoft Excel, and consider uninstalling Adobe Flash. Even then, however, there is no guarantee that systems will be protected against ransomware.<\/p>\n<p>In the enterprise, and on carrier networks, there are larger-scale tools that can be more effective. For example, Menlo Security offers an isolation platform that ensures that malware cannot touch the end user\u2019s laptop, desktop or mobile computer, or infect a corporate server, explains Mr. Steer. It\u2019s ideal for implementation by enterprise IT and security professionals.<\/p>\n<p>\u201cIsolation is a new concept on the block to help organizations become more resilient to attacks. Enabling endpoints to be more secure and robust ensures they get hacked less and the fallout of data and intellectual property loss is reduced,\u201d he says. \u201cGartner considers isolation as key in the malware prevention capability: It\u2019s what administrators can do to prevent their users running into bad things through no fault of their own.\u201d<\/p>\n<p>Mr. Steer continues, \u201cThe Menlo Technology eliminates the possibility of malware reaching user devices via compromised or malicious websites or documents. The user\u2019s web session and all active content (e.g. video, JavaScript or Flash), whether good or bad, is fully executed and contained in the Isolation Platform. Only safe, malware-free rendering information is delivered to the user\u2019s endpoint. No active content &#8211; including any potential malware &#8211; leaves the platform. So malware has no path to reach an endpoint, and legitimate content needn\u2019t be blocked in the interest of security and all done\u00a0without changing the enduser&#8217;s surfing experience.\u201d<\/p>\n<p>Wedge Networks\u2019 customers are carriers and cloud service providers, who want to detect and block malware \u2013 including ransomware \u2013 before it ever gets close to the end-customer\u2019s network or devices. Its technology is based in the cloud, and that\u2019s where Mr. Hamilton says security like this belongs.<\/p>\n<p>\u201cOne of the biggest breakthroughs is the realization that security needs to evolve from an endpoint and perimeter paradigm to a cloud-based connectivity paradigm in order to close gaps with today\u2019s IT model,\u201d he explains. \u201cThe network, the users, and their devices are no longer static. They are dynamic and constantly moving and changing. As a result, the only way to secure the network is to secure the connections for everything connecting to that network. This can only be achieved by moving security to the cloud-layer of the network, which has visibility of everything connecting to the network.\u201d<\/p>\n<p>How does Wedge Networks\u2019 technology protect against ransomware? \u201cOur Wedge Cloud Network Defense was purpose-built to run in the cloud to support virtually unlimited scale, and to support the multi-tenancy operational requirements of service providers that want to offer Security-as-a-Service to their customers,\u201d Mr. Hamilton describes. \u201cCloud Network Defense dynamically scales up or down cloud-compute resources to support the widely varying security workloads of their customers with efficiency and sustained performance.\u201d In other words \u2013 it blocks ransomware trojans and related threats without affecting network performance or application response time.<\/p>\n<p>Cylance\u2019s Mr. Solterbeck explains how his company addresses ransomware: Artificial Intelligence. \u201cWe apply the power of Machine Learning and Artificial Intelligence to the problem of malware detection,\u201d so that even if the attack has never been seen before, Cylance\u2019s technology can successfully block it. \u201cCylancePROTECT predicts cyberattacks and blocks them on the endpoint in real-time before they ever execute \u2013 and that includes malware like ransomware, memory attacks, unauthorized scripts and privilege escalations that can give hackers complete access to your systems.\u201d<\/p>\n<p><strong>THE PROBLEM WILL GET WORSE<\/strong><\/p>\n<p>The bad news is that malware, including ransomware, is on the rise. The good news is that the cybersecurity industry is responding with tools and services that can help protect businesses and consumers. Don\u2019t get complacent, however: There will always be malware, and ransomware isn\u2019t going away. \u201cThere is no magic fairy dust to solve this problem on the near horizon\/in the near future, says NSS Lab\u2019s Mr. Pathak. \u201cThe effective solution to combat this threat is keeping applications up to date, not putting implicit trust on anything that is received via email, disabling macros altogether, and keeping backups regularly.\u201d<\/p>\n<p>Have you done your backups? If not\u2026 now is the time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>APAC countries must take note of the prevalence of ransomware attacks in the U.S. and Europe. The good news is that tools and technologies are emerging to combat these cybercrimes.<\/p>\n","protected":false},"author":7,"featured_media":22749,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[2883,1591,54],"class_list":["post-22748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-cyberattacks","tag-ransomware","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/22748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=22748"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/22748\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/22749"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=22748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=22748"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=22748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}