inconvenient truth of browser security · browser security is in a shaky state browsers and...

41
Session ID: SPO1-204 Session Classification: Intermediate Wolfgang Kandek Qualys, Inc. The Inconvenient Truth About the State of Browser Security

Upload: others

Post on 13-Mar-2020

14 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Session ID: SPO1-204

Session Classification: Intermediate

Wolfgang Kandek

Qualys, Inc.

The Inconvenient Truth About the State of Browser Security

Page 2: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Agenda

Browser Security Project

Browser Plugins

Resulting Threats

Actions

Up and Coming

2

Page 3: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

https://browsercheck.qualys.com

Security check for Browsers and Plug-ins

Page 4: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

Page 5: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

https://browsercheck.qualys.com

Security check for Browsers and Plug-ins

End user focus, free and easy to use

Page 6: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

[email protected]: This is really a wonderful tool for browser check I will recommend this to my friends who would be pleased to try it.

[email protected]: thank guyssssssssssssssss................

[email protected]: Great Tool! It's scarry that I was running my computer in the dark re online securituy for alll of these years. I would like to see feeds added to notify me of changes/upgrades to the programs it is checking.

[email protected]: First, I like that it checks for available updates. Additionally, the links for zero-day issues. Very nice!

[email protected]: This program is the first so far that i have tried that appears to work!!! Thanks

[email protected]: This little tool is great for us non-techy types. I have told my friends about it as well

[email protected]: No Linux support? Pathetic

Page 7: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

Page 8: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project

https://browsercheck.qualys.com

Security check for Browsers and Plug-ins

End user focus, free and easy to use

Windows, Mac OS X and Linux

IE, Firefox, Safari, Chrome, Opera

200,000 visits – Jul 2010 / Jan 2011

Page 9: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

9

Page 10: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: ?

Page 11: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 12: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 13: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 14: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 15: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 16: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: Windows XP – 47 %

Windows 7 – 32 %

Browser: ?

Page 17: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: Windows XP – 47 %

Windows 7 – 32 %

Browser: ?

Plug-in:

Country:

Page 18: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 19: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 20: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 21: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 22: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 23: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: Windows XP – 47 %

Windows 7 – 32 %

Browser: IE 8 – 36 %

Firefox 3.6 – 34 %

Plug-in: ?

Page 24: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: Windows XP – 47 %

Windows 7 – 32 %

Browser: IE 8 – 36 %

Firefox 3.6 – 34 %

Plug-in: ?

Country:

Page 25: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Operating System: Windows XP – 47 %

Windows 7 – 32 %

Browser: IE 8 – 36 %

Firefox 3.6 – 34 %

Plug-in: Adobe Flash – 97 %

Windows Media Player – 95%

Page 26: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 27: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 28: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 29: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 30: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 31: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 32: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 33: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats – MVP – Adobe Reader

Page 34: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Speed of Adoption of new Software versions

Adobe Reader X Introduced in mid November 2010

Improved Usability

Security Enhancements Sandbox (protected mode)

Secure defaults

Page 35: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

BrowserCheck Project Stats

Page 36: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Summary

Browser Security is in a shaky state

Browsers and plug-ins frequently outdated and easily attackable

Malware authors have adapted and most new attacks are against browser plug-ins

36

Page 37: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Consequences

Browsers are in use by your employees

10% of all users come from corporate networks

5-8% of all machines in corporate networks show signs of malware infection

Browsers are in use by your clients

Credentials are in danger

Transaction integrity threatened

37

Page 38: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Actions

Assure Browsers are updated

Aggressive Patch roll-out

Assure Browser Plugins are updated

Enumerate, Evaluate

Plan for Updates

Browser Help (include updates for plugins)

Vendor Help Ask Microsoft to open up and include

Adobe Patches

Sun, Apple Patches

38

Page 39: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Actions

Server: Implement 2-factor authentication

Username/Password are obsolete

2-factor: token, phone

SaaS Services make management easier

Server: Investigate client integrity

VPN plus local checks

Transparent services

39

Page 40: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

Up and Coming

New Platforms

Smartphones, Tablets

Integrated machines

Tight vendor management ++

Loss of Control --

CloudNAC

Client Health Repository

40

Page 41: Inconvenient Truth of Browser Security · Browser Security is in a shaky state Browsers and plug-ins frequently outdated and easily attackable Malware authors have adapted and most

The Inconvenient Truth About the State of Browser Security

[email protected]

http://laws.qualys.com

Twitter: @wkandek

Thank you !