Identifying Malware and Botnets via Cisco Stealthwatch

How Malware Works

Malware is an umbrella term employed to talk about a diversity of forms of aggressive or invasive software comprising computer viruses, worms, Trojan horses, ransomware, spyware, adware and other such malevolent programs. Malware is intended to be surreptitious in disposition, and is commonly used to steal personal data or spy on computer users for lengthy periods of time without their knowledge. Other uses include incapacitating victim computers/networks, or encrypting files to obtain payments under duress/blackmail.

How Botnets Work

Botnet operators employ networks of command-and-control (C&C) servers situated all over the world to control malevolent software that they have installed on victim’s devices. Hackers have deployed malware onto millions of computers all over the globe so that they possess an army of devices standing by to follow their commands. A single device infested with this kind of payload is known as a “bot.” Together, all devices under the control of their attacker are known as a “botnet” or in some cases a “zombie network.”

The extraordinary surreptitiousness of these attacks and their extensively distributed nature make them exceptionally perilous. Each and every botnet-infested system can leak personal data or attack other companies at any time. Botnets can be employed for an assortment of reasons alternating from forwarding spam to DDoS and network infiltration.

By employing clandestine command-and-control methods, criminals are able to use infested internal systems as a launch pad for performing reconnaissance activities, dispersing malware and stealing information to abuse and compromise complete enterprises. As companies have now started to permit personnel to bring their own personal laptops, tablets and smartphones onto the network (a policy known as “bring-your-own-device” or BYOD), it has supplied a new way for attackers to get bots under their control inside otherwise unapproachable networks.

Cisco’s Stealthwatch Solution

Via cutting edge behavior scrutiny, Lancope’s Stealthwatch System can quickly find and alleviate the spread of malware across inside hosts. Using the Stealthwatch Worm Tracker, Admins can easily see where a worm has been on the network and where it is likely to go next. The Worm Tracker visually graphs the spreading of a worm/virus over the network from node to node, giving immediate visibility into the scope and impact of the outbreak. In this way, malware proliferation can be stopped inside a few hours instead of weeks.

Lancope’s Stealthwatch System can also find the command-and-control communications amongst botnet attackers and affected hosts inside the network. In addition, Lancope’s Stealthwatch Labs Intelligence Center (SLIC) Threat Feed gives cutting edge botnet identification, incessantly screening client networks for millions of known C&C servers and the addition of new botnets to its locating system as they are recognized in the wild. From there, Stealthwatch produces warnings to flag these communications for Admins so they can be quickly alleviated.

Lancope’s Stealthwatch Labs performs continuing, in-depth examination into the newest attack kinds to unceasingly reinforce network security. Via Stealthwatch Labs security updates, Lancope gives behavioral security algorithms for the leading threats prowling online to clients outside of their normal product upgrade cycles. These security updates supply yet another layer of reassurance for protecting networks from the newest malware and threat vectors.

Outside enhancing threat detection in real time, the Stealthwatch System radically hastens incident response times, reducing troubleshooting down from days and months to a few minutes. The capability to save network data for months or even years, with the addition of cutting edge security analytics, also make Stealthwatch the ideal choice for performing more accurate post-incident forensic inquiries to help avert future attacks.

To speak with one of our Licensing Specialists, please click here.