18 Oct 2010
Security vendor Stonesoft claims to have discovered a dangerous new category of threat which could render network security tools useless.
So-called advanced evasion techniques (AETs) use different methods in virtually limitless combinations to avoid detection by 99 per cent of current products on the market, according to the vendor.
AETs can be coupled to an exploit to effectively make that exploit invisible, allowing hackers as much time as they like to test and refine exploits on a target system until they are successful, according to Stonesoft chief executive Ilkka Hiidenheimo.
The use of AETs at a network level could lead to serious data breaches involving the loss of corporate information from mission-critical applications, Stonesoft warned.
"Even our product doesn't offer full protection because we're finding new holes and combinations of evasions all the time," said Hiidenheimo.
"A very clear rethink is needed in network security. All security functionality must be software-based, automated and updatable, because when something is found in the wild you need to make changes very quickly."
Stonesoft has informed CERT-FI in Finland for vulnerability co-ordination purposes, and has had its research validated by third-party testing organisation ICSA Labs.
The company has shared its intelligence with the industry in an attempt to help in the race to find an effective solution.
"The issues identified by Stonesoft affect a range of content inspection technologies," said Jussi Eronen, head of vulnerability co-ordination at CERT-FI.
"Continuous co-operation among CERT-FI, Stonesoft and other network security vendors is essential for remediating the identified vulnerabilities."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
About Us WorldPay provides a globally connected, locally...
About Us WorldPay provides a globally connected, locally...
SQL Server Developer - Our client, an international...
IT Technical Service Delivery Manager / ITIL / Reigate...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?