Don't worry about the "Hard Shell (Perimeter) Soft Insides" problem any more. Make each and every host invulnerable. Scan for known patterns of virus code Previously the most reliable New virus generators mutate malware to avoid detection Most serious malware is not detected by this method A growing amount of non-serious malware is not detected either H F D How ALL Malware Works For Malware to be effective it must; Malware must get on to and run from the hard disk Yes there may be loads of other files that can contain malicious code but if they cannot execute they can cause no harm. Yes it is possible for some malware to run from live memory but this malware cannot persist and terminates when the system re-initialises. Execute Persist HDF: Both Simple AND Hard How All Most AV Works Virus Signature Scanners Heuristic AV Scanners Attempt to guess based on knowledge of patterns Notoriously unreliable with many false positives and negatives The Second Biggest Prob for Organisations? Spend on Traditional AV Tech Goes Up Technology itself Admin Burden Second Biggest Prob for Home Users Technically invasive Signficantly degrades performance Needs Updates - Costs Money - Let's not bother THE NEXT LARGE-SCALE MALWARE ATTACK! Massive Outage Tsunami-Scale Information Leaks National Security Level Issues The First Biggest Prob (for all) Just not kicking it! That's where we STOP it! How HDF Works 1. Known clean system at install 2. Learn mode-HDF Gate Open: all executables on the disk are learned 3. HDF Enabled-HDF Gate Closed: NO other (unauthorised) executables can get to the disk to run 3-steps Q & A Install New Software? Put HDF in learn mode (Gate Open) - Admin can be separate or same as OS/Domain/AD Need signatures or any updates? Simply....... No. Deployment? Works with all software distribution tools Monitoring? Local and Centrally Managed Logs Works with QCC's Blackthorn for Alert and Incident Management Not that there will ever be an actual compromise Performance? 26k footprint: Client 56k footprint: Server Operates in Kernel Seriously negligible performance hit: Simply...no scanning needed! Significant (noticeable) performance improvements over AV "Prepare to be amazed!" Other Functions? File integrity monitoring File access monitoring Read-Copy-Write-Delete UI: Loads of In-your-face pop-ups? Simply: No Activity monitoring written to a secure log Remember: System never compromised so the only interest will be in monitoring an attempted attack Security? Absolute when enabled Vanilla clients & servers running HDF connected directly (no firewalls) to the Internet since 2008. Feel free to test Result: Zero Compromises Why you need HDF Significant reduction in AV expenditure Secure your Internet-facing systems completely Don't worry about getting signature updates to mobile or remote workforce. Simplify AND Harden your Protection Be in full control of your patching process: Hell! Even if your not you won't be insecure. Not what an attacker wants. Not now Management? Central console management Simple to see and open/close HDF gate as and when needed Give us your details and we will give you the address Ringfence your legacy servers
More presentations by
Risk Modelling Pt 1 : A Tribute to Charles Darwin
Neil Hare-Brown on
The Natural Selection of Good Risk Managers
Popular presentations
Trello Architecture
Brett Kiefer on
This is the visual part of a talk I gave on the trello.com architecture at the MongoDB user group on 18 Jan 2012. Blog post ...
Academy: 10 ways to say it with prezi
Adam Somlai-Fischer on
Prezi is simple: You Write, Zoom, Arrange.Using these simple means, you can express many things - with great impact.Here are some basic examples such as ...
More popular prezis in Explore>