Intro to HDF

How HDF Works »
Neil Hare-Brown

Don't worry about the "Hard Shell (Perimeter) Soft Insides" problem any more. 
Make each and every host invulnerable.
Scan for known patterns of virus code
Previously the most reliable
New virus generators mutate malware to avoid detection
Most serious malware is not detected by this method
A growing amount of non-serious malware is not detected either
H
F
D
How ALL Malware Works
For Malware to be effective it must;
Malware must get on to and run from the hard disk
Yes there may be loads of other files that can contain malicious code but if they cannot execute they can cause no harm.
Yes it is possible for some malware to run from live memory but this malware cannot persist and terminates when the system re-initialises.
Execute
Persist
HDF: Both Simple AND Hard
How All Most AV Works
Virus Signature Scanners
Heuristic AV Scanners
Attempt to guess based on knowledge of patterns
Notoriously unreliable with many false positives and negatives
The Second Biggest Prob for Organisations?
Spend on Traditional AV Tech Goes Up
Technology itself
Admin Burden
Second Biggest Prob for Home Users
Technically invasive
Signficantly degrades performance
Needs Updates - Costs Money - Let's not bother
THE NEXT LARGE-SCALE
MALWARE ATTACK!
Massive Outage
Tsunami-Scale Information Leaks
National Security Level Issues
The First Biggest Prob (for all)
Just not kicking it!
That's where we STOP it!
How HDF Works
1. Known clean system at install
2. Learn mode-HDF Gate Open: all executables on the disk are learned
3. HDF Enabled-HDF Gate Closed: NO other (unauthorised) executables can get to the disk to run
3-steps
Q & A
Install New Software?
Put HDF in learn mode
(Gate Open) - Admin can be separate or same as OS/Domain/AD
Need signatures or any updates?
Simply....... No.
Deployment?
Works with all software distribution tools
Monitoring?
Local and Centrally Managed Logs
Works with QCC's Blackthorn for Alert and Incident Management
Not that there will ever be an actual compromise
Performance?
26k footprint: Client
56k footprint: Server
Operates in Kernel
Seriously negligible performance hit: Simply...no scanning needed!
Significant (noticeable) performance improvements over AV
"Prepare to be amazed!"
Other Functions?
File integrity monitoring
File access monitoring
Read-Copy-Write-Delete
UI: Loads of In-your-face pop-ups?
Simply: No
Activity monitoring written to a secure log
Remember: System never compromised so the only interest will be in monitoring an attempted attack
Security?
Absolute when enabled
Vanilla clients & servers running HDF connected directly (no firewalls) to the Internet since 2008.
Feel free to test
Result: Zero Compromises
Why you need HDF
Significant reduction in AV expenditure
Secure your Internet-facing systems completely
Don't worry about getting signature 
updates to mobile or remote workforce.
Simplify AND Harden your Protection
Be in full control of your patching process:
Hell! Even if your not you won't be insecure.
Not what an attacker wants.
Not now
Management?
Central console management
Simple to see and open/close HDF gate as and when needed
Give us your details and we will give you the address
Ringfence your 
legacy servers

Loading comments...

Please log in to add your comment.

Report abuse

More presentations by Neil Hare-Brown