spiceworld 2011 - appriver breakout session
DESCRIPTION
The rise of malware on the web is threatening businesses around the world. This presentation looks at the trends in malware on the web, and how AppRiver is providing protection against this threat.TRANSCRIPT
Security Crosses the Chasm:
Surfing in Peace
Shane RiceServices Evangelist
Easy. Effective. Affordable.Easy. Effective. Affordable.
Why Web Protection?
“The Web has become the new threat vector of choice by hackers and cyber criminals to distribute
malware and perpetrate identity theft, financial fraud and corporate espionage.” -- IDC
Easy. Effective. Affordable.Easy. Effective. Affordable.
Why Web Protection?
• "Malware” - short for malicious software– Refers to any software designed to cause damage to a
single computer, server, or computer network, whether it's a virus, spyware, et al.
• Malicious Web content can expose your company to higher costs, lower productivity and legal issues
Effective Web security can safeguard employees against online threats and protect network
infrastructure
Easy. Effective. Affordable.Easy. Effective. Affordable.
Avenues of Attack
Source: Blue Coat Security Labs
Top Five Categories for Entering Malware Networks by Percentage of Requests
Easy. Effective. Affordable.Easy. Effective. Affordable.
Malware Threat is Growing…
Malware Delivered by Websites is on the Rise
• Cumulative Malware * – 2007: 5.8 million– 2011: 65 million (as of June)
1120% Increase
• Malicious URLs* – 7,300 new malicious URLs per day
• Legitimate Websites being Compromised
80% of Websites with Malicious Code
*Source: McAfee Labs
Easy. Effective. Affordable.Easy. Effective. Affordable.
Malicious Code Threats in 12 months
133%
Increase in Phishing Sites!500%
More Malware Variations
Attack TargetUsers vs Machines
Of Vulnerable Websites get fixed!4%
Increasing Attack Success!
Of Malware infections are Web application exploits
80%Web 2.0
is the Catalyst!
Of top Malware infections exposed
confidential data
68%
…And Growing More Effective
Easy. Effective. Affordable.Easy. Effective. Affordable.
Alarming 2011 Trend
Source: Cisco ScanSafe
Unique Web Malware Encounters
297% Increase
Easy. Effective. Affordable.Easy. Effective. Affordable.Source: AppRiver
A Clear and Present Danger
Easy. Effective. Affordable.Source: AppRiver
A Clear and Present Danger
Easy. Effective. Affordable.Easy. Effective. Affordable.
A Clear and Present Danger
Source: AppRiver
Easy. Effective. Affordable.Easy. Effective. Affordable.
It’s The Economy Stupid
Source: http://s0.geograph.org.uk/photos/87/30/873046_db56f88b.jpg
Easy. Effective. Affordable.Easy. Effective. Affordable.
It’s The Economy Stupid
Source: flickr.com User: r-z
Easy. Effective. Affordable.Easy. Effective. Affordable.
It’s The Economy Stupid
Source: flickr.com User: AMagill
Easy. Effective. Affordable.Easy. Effective. Affordable.
It’s The Economy Stupid
Easy. Effective. Affordable.Easy. Effective. Affordable.
Categorization: First Line of Defense
• Secures The Network Environment• Enforces Business-focused Internet Access• Reduces Liability• Manages Bandwidth
Shopping
Gambling
Business
IM
Security
Business
Web Filter
FilteringDatabase
SecurityPornography
Hate SitesGamblingShoppingBusiness
IM
Porn
Easy. Effective. Affordable.
Layered Security – Stronger Protection
Anti-Virus
• Anti-Virus
• However it is only a single aspect of the complete solution
• Signature based detection is not enough to cover today’s targeted Web 2.0 Malware attacks
Intent Analysis
• Authenticode – Checks for Digital Signature on active code
• Media Type Filter -verification via “magic byte” analysis not MIME
• Behavioral Malware detector - scans for malicious script intent and removes offending function calls
• Behavioral exploit detector – inspects code for hostile behavior like buffer overflows, etc.
Anti-Malware
• Prevents OS, browser and application exploits as a result of:•Protects from known
malicious code•Protects from
unknown malicious mobile code for which no signature exists
Signature based detection is not enough to cover today’s targeted Malware attacks
+ =
Easy. Effective. Affordable.Easy. Effective. Affordable.
Why Web Protection as a Service?
• Diminishing IT Dollars and Resources for a Growing Problem– IT is constantly asked to do more with a flat budget– Many smaller organizations do not have adequate IT
resources to buy and manage appliances or complex deployments
• Web Protection as a Service Offers– Lower upfront costs – Ease and Speed of Deployment
• No on-site hardware or software to maintain, upgrade, or support
• Simply redirect Web traffic– Fixed operational expense instead of a
capital expense
Easy. Effective. Affordable.18
SecureSurf Case Study
Blocking a Keylogger Attack
• Title company in South Florida• Setup SecureSurf week before Labor Day• Keylogger attempted to upload keystrokes
Friday night• SecureSurf blocked traffic to suspicious IP• AppRiver analysis determined nature of
attack and notified customer
Easy. Effective. Affordable.Easy. Effective. Affordable.
SecureSurf Web & Malware Protection
Easy. Effective. Affordable.
Features & Benefits• Shields networks from malware, adware
and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup
level• Enforces safe search on major search
engines • Easy set up and deployment• Intuitive browser-based Web Portal Access
for Administrators• Anti-Malware/Spyware Protection –
proactive intent-based protection that scans the active code on a Web site before it enters your network
Cloud-based Web Protection & Endpoint Security
SecureSurf Web & Malware Protection
More details at http://www.appriver.com/services/web-protection/
Easy. Effective. Affordable.
Features & Benefits• Shields networks from malware, adware
and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup
level• Enforces safe search on major search
engines • Easy set up and deployment
AppRiver SecureSurf Agent®
• User/device-level protection• Mobile workforce & off-network security• Compliance & enforcement at user level
Cloud-based Web Protection & Endpoint Security
SecureSurf Web & Malware Protection
Easy. Effective. Affordable.
Company
Customers
Market Leadership
AppRiver at a Glance
Company
• 45,000 Customers• 6,000,000 Mailboxes Managed• 93% Customer Retention Rate• Channel-centric (70% Customer base)• Focus on the SMB
• Established: 2002• Headquarters: Gulf Breeze, FL• Employees: 150+• Privately Held, Debt-free, Self-funded• Focus on Email & Web Security with Phenomenal CareTM
• Cloud-based Since Inception
• Leading Worldwide Messaging Security SaaS Provider• Named Best SMB Solution for Hosted Message Security Services• Recognized as a Microsoft Top 5 Hosted Exchange Provider• Tremendous Customer ROI of AppRiver’s Security Solutions• Identified as Shaping the Future of Technology
Easy. Effective. Affordable.
24/7 Phenomenal
CareTM
24/7 Spam & Virus
Operations Center
24/7 Malware
Protection Operation
Center
24/7 – The Next Level
Company
• Continuous Threat Protection for SecureSurf Customers• Threat Data Gleaned from/shared with Spam & Virus Operations• >5 Billion Malicious Websites . . . and Counting
•US-Based, Fully Trained AppRiver Employees•Available 24 Hours a Day, Every Day•By Phone, Live Chat and Email•Easy-to-use Web-based Guides & Tools
• Worldwide Threat Detection System• Sophisticated, Proprietary Software• Real-time Threat Prevention & Instant System-wide Updates
Easy. Effective. Affordable.
AppRiver Timeline
Company
Founded AppRiver
2002 2004 2006 2008 2010 2012
Introduced SecureTideTM
Launched HostedExchange Service
Integrated First Optimized Network for Hosted Exchange(Akamai)
Implemented RackSpaceInfrastructure
Daily Quarantine Reports
40,000 HostedExchange Seats
20,000 HostedExchange Seats
50,000 HostedExchange Seats
ARBO Launched
Hired 100th Employee
100,000 HostedExchange Seats
150,000 HostedExchange Seats
Launched Email Encryption Service
Launched Web & Malware Protection Service
Hired 150th Employee
Easy. Effective. Affordable.Easy. Effective. Affordable.
Proven Track Record
• 2011, 2010, 2009, 2008, 2007 Inc. 5000 Fastest Growing Private Companies
• 2011, 2010, 2009 Florida Trend Best Companies to Work For in Florida
• 2011 CRN Top 20 Cloud Security Vendor
• 2011, 2009, 2006 Network World Fave Raves
• 2010, 2009 MSExchange.org Readers' Choice Award Winner
• 2010, 2009 CRN Five-Star Partner Program
• 2010 CRN Coolest Cloud Security Vendor
• 2009 CSIA International Service Excellence Award
• 2009 Deloitte Technology Fast 500™ Winner
• 2009 Business Solutions Best Channel Product – Email Security
• 2009 Ernst & Young Florida Entrepreneur of the Year - Michael Murdoch, CEO
• 2009 Business Solutions Best Channel Vendor – Security
Easy. Effective. Affordable.Easy. Effective. Affordable.
AppRiver Application Mall
SecureTideTM Spam & Virus Protection
Exchange HostingSecure Hosted Exchange
CipherPostTM Email Encryption
SecureSurfTM Web & Malware Protection
Office 365Microsoft Cloud-based Service
ECSTM Email Continuity Service
Learn more at http://www.appriver.com/services/
Easy. Effective. Affordable.
Questions?
Find SpiceWorld related links from AppRiver @ http://bit.ly/arsw2011