December 7, 2016
-
J. Gomez
,

More On Detection Gaps...

<p>How often have we seen a security news headline detailing a new malware strain or exploit kit campaign? The next question for security teams will usually be, do we detect that? In today’s threat landscape, delivery methods and network traffic patterns that are detected at present will eventually be superseded by new ones that are not. These situations can pose a risk to enterprises as they are windows of opportunity for compromises to occur and cause damage to systems and data without generating alerts.</p><p>In recently published articles for <strong><a href="http://www.itsecurityguru.org/2016/12/02/detection-gaps-inconvenient-truth/">IT Security Guru</a></strong> and <a href="http://www.cyberdefensemagazine.com/newsletters/november-2016/index.html#p=30"><strong>Cyber Defense Magazine</strong></a> we discuss the threat that these kinds of detection gaps can pose to IT environments</p><p>While the obvious culprit would be outdated detection content (i.e, AV/IDS/IPS updates) that would leave solutions blind to the latest threats, other areas where temporary detection gaps can arise include, but are not limited to:</p><ul><li>Zero Day Exploits / Vulnerabilities</li><li>Malicious Redirects and Malvertising campaigns</li><li>Compromised Websites</li><li>Updates to Exploit Kits</li><li>New Malware Callbacks / C2 Communication</li><li>BYOD / Mobile Threats</li></ul><p>Ensuring your security solutions are always up to date is essential in minimizing detection gaps, in those situations where detection gaps are unavoidable, access to up to date threat intelligence with fresh indicators can be helpful in determining if you are at risk and allow you to take a proactive approach to detection.</p>

Get the Latest Anomali Updates and Cybersecurity News – Straight To Your Inbox

Become a subscriber to the Anomali Newsletter
Receive a monthly summary of our latest threat intelligence content, research, news, events, and more.