Anti-Malware Defenses
Anti-malware defenses detect and remove malicious software to protect systems and networks from compromise.
7 slides · 4 min read · Domain 7
The threat of malware is pervasive and persistent, and the means of introducing malware into the environment remain as long as the environment has any contact with the outside world. Therefore, a realistic defense-in-depth (DiD) strategy should also involve the use of anti-malware solutions. These can take the form of hardware or software implementations, or combinations of both.
Anti-malware solutions can be installed on network devices and individual systems, as well as mobile endpoints, including user devices, when they are allowed to be connected to the production environment.
Most security frameworks identify endpoint anti-malware applications as a necessary part of DiD. The complexity of managing anti-malware services across a large infrastructure, however, has forced vendors to develop dedicated monitoring platforms for the management of their anti-malware products. These monitoring platforms can be further integrated into the organization's logging practice, Security Operations Center (SOC), and security information and event management (SIEM) environment. Regardless of how your organization chooses to use anti-malware defenses, it is vital that they be tightly integrated into your SIEM or Security Orchestration, Automation, and Response (SOAR) processes.
Because most malware attacks involve social engineering, focused awareness, education, and training for all organizational members are essential first lines of defense.
Email, email attachments, and removable media are prime vectors for introducing malware into the organization's IT systems; thus, policies should establish the proper culture, management processes, and technical controls regarding the right way, and the many wrong ways, to use these capabilities. Possibly the most significant procedural lack in many organizations is having clear, concise instructions for users regarding what to do when they suspect they have encountered malware, a phishing attack, or other suspicious event.
Many security professionals are advocating that organizations move away from annual training, which tends to be delivered in hour-long multimedia click-through activities. These have not made as great a contribution to improving security posture as initially hoped.
Microtraining is a recognized and effective method for delivering short, focused cybersecurity training, including anti-malware strategies, throughout the year to improve staff confidence, knowledge, and awareness.
Microtraining combined with user-focused phishing awareness testing can then provide analytics to measure the effectiveness of the training, as well as identify problem areas that might require different training and other defensive controls to achieve required levels of security. This can help identify categories of users, for example, who seem to routinely have difficulty in doing their parts to protect the organization's systems (and their own jobs in the process.
Many organizations large and small would benefit from some common-sense cyber hygiene measures as critical components of their malware defenses.
Large enterprises and those serving government, military, and financial sector customers are often contractually or legally required to implement policies in compliance with standards such as those published by the National Institute of Standards and Technology (NIST) or the International Organization for Standardization (ISO). Small- and mid-sized organizations, however, may find NIST and
ISO standards intimidatingly complex. In the 2020 CISO Desk Reference Guide, Alan Watkins outlines a pathway that begins with assessing information sensitivity through classification and categorization. From there, organizations set priorities, define policy objectives (clarifying what needs to be achieved and why), and then determine how to manage the activities necessary to implement those policies.
Cyber hygiene measures for malware defense should include:
- Evaluating the security of software systems and products prior to adopting them for use.
- Establishing procedures for handling email and attachments, including instructions on:
- When and how to verify the sender is who they claim to be;
- Clear labeling standards for sending attachments, internally and externally, as to their content, meaning, and purpose; and
- Verification of attachments via voice or face-to-face contact with senders prior to any attempts to open or download them.
- Setting policies and guidelines for use of removable media, USB storage, personal cloud storage, and commingling of personal and business data storage.
- Establishing bring your own device (BYOD), guest device and user access, and external network, cloud, or platform use policies and procedures.
- Establishing common technical settings for anti-malware defense, via:
- Selecting, installing, and maintaining anti-malware software and tools; and
- Establishing and enforcing identity management and access control procedures.
- Establishing policies for ensuring that systems, servers, endpoints, and devices are kept properly updated, and that health checks (verification of update currency status) are enforced when devices attempt to connect to the network.
These steps, including elements of IT acceptable-use policies, are just part of the advice in the Center for Internet Security's Implementation Group 1. This focuses on the small office/home office (SOHO) market segment's need for effective common-sense information security; these types of organizations often lack the in-house technical savvy to implement more rigorous defenses.
