Welcome!

Wearables Authors: Jnan Dash, Craig Lowell, Elizabeth White, Pat Romanski, Bob Gourley

News Feed Item

NSS Labs Tests Show Enterprise End Point Protection Solutions Improving Ability to Block Exploits, Evasions and Phishing Attacks

AUSTIN, TX -- (Marketwire) -- 02/25/13 -- NSS Labs today released three new 2013 Corporate End Point Protection Comparative Analysis Reports, which evaluated 11 enterprise level end point protection (EPP) products to test their effectiveness in blocking exploits and evasions. While only 3 of the 11 vendors -- McAfee, Kaspersky and Microsoft -- scored 100% across all 6 types of evasion testing, the average score across all vendors increased to an average of 87% in 2013 testing, compared to 27% in NSS' 2010 tests. In exploit testing, the top 3 vendors -- McAfee, Kaspersky and Symantec -- all scored over 90%, with an overall group average of 74.5%, also an improvement over 2010 test results.

Read the Reports:
NSS 2013 Corporate End Point Protection Comparative Analysis Report - Exploits
NSS 2013 Corporate End Point Protection Comparative Analysis Report - Evasions
NSS 2013 Corporate End Point Protection Comparative Analysis Report - Phishing

NSS vulnerability research has shown that the number of vulnerabilities disclosed in 2012 jumped 26% after a 5-year decline. Given the growing availability of exploit toolkits that automate the creation of evasions and exploits targeting newly-discovered and existing vulnerabilities, NSS recommends that enterprises -- especially those that have implemented a bring your own device (BYOD) policy -- fully understand the ability of their EPP solutions to adequately protect against key exploits and types of evasions.

NSS's research yielded several key conclusions:

  • Enterprise EPP products differ up to 53% in effectiveness at blocking exploits: Protection levels in the 2013 tests ranged from 97% (McAfee) to 41% (Panda). The top 3 vendors all scored over 91% with half (4) of the remaining 8 vendors scoring in the 70 - 80% range. In 2010 exploit testing, the overall block rate ranged from 20% to 100% with an overall average of 67%.

  • Default vendor settings may favor performance over security: While all of the vendors tested were able to block exploits once malicious files were decompressed, only 3 of the 11 vendors -- ESET, Kaspersky, and Trend Micro -- blocked all of the compressed threats upon download. NSS believes having a default setting that does not inspect compressed downloads is typically a choice of performance over security and that malicious downloads inside of compressed files should be blocked by default.

  • Vendors' anti-evasion protection against encoded payloads and layered evasions has greatly improved since 2010: In 2010, none of the products scored 100% and most scored below 40% in their ability to handle encoded payloads. In 2013 tests, 8 of the 11 vendors scored 100% in these tests -- followed by one vendor scoring 83% and two that only scored 17%. In 2010, even single layers of evasion caused problems for many vendors, but in 2013, all 11 vendors scored 100% even when attempts to use as many as 4 levels of obfuscation were used.

  • Web browsers rather than EPP should be considered the first line of defense against phishing: Modern Web browsers now offer 90% to 94% protection against phishing according to recent NSS tests. Only one of the vendors tested -- Trend Micro -- scored as well or better than current Web browsers did in these latest tests. Organizations should still take time to educate users about phishing and best practices for avoiding phishers' increasingly deceptive attacks.

  • Detection of exploits delivered via HTTP vs. HTTPS can vary as much as 39% in a single product: Only 3 of the 11 vendors blocked the same percentage of exploits when delivered via HTTP and HTTPS. On average, there was a 7% difference in the ability of products across the board to block HTTPS vs. HTTP exploit attacks. NSS believes security product should ideally protect against all exploits for a given vulnerability, regardless of the transport protocol.

  • Enterprise Using Internet Explorer 6 (IE6) may be less protected against exploits: Because some enterprises are still using IE6, NSS ran tests using exploits requiring IE6 and those that did not. For exploits not requiring IE6, the average block rate across all products was 77% with a range of 44% to 98%. For those requiring IE6, the average block rate dropped to 65% with a range of 20% to 100% effectiveness. Enterprises running IE6 should be aware of this discrepancy and evaluate their EPP defenses carefully, given IE6's impact on their attack surface.

Commentary: NSS Labs Research Director Randy Abrams
"The simple detection of malware is insufficient to cope with the multitude of attacks that companies face today; for example, Facebook and Apple have both recently fallen prey to Java exploits that resulted in breaches," said Randy Abrams, Research Director at NSS Labs. "With phishing and targeted drive-by attacks (ambiguously referred to as watering hole attacks) targeting users who may be outside perimeter defenses, endpoint protection products are often the last line of defense and criminals can -- and do -- use obfuscation techniques to evade malware detection. Most Endpoint protection products are dealing well with evasions for the exploits they detect, however there is still a lot of room for improvement in the detection of known exploit attempts and simply detecting exploits alone falls short of the protection needed by today's enterprises."

To read more NSS Labs research and reports, visit www.nsslabs.com.

About NSS Labs, Inc.
NSS Labs, Inc. is the world's leading information security research and advisory company. We deliver a unique mix of test-based research and expert analysis to provide our clients with the information they need to make good security decisions. CIOs, CISOs, and information security professionals from many of the largest and most demanding enterprises rely on NSS Labs' insight, every day. Founded in 1991, the company is located in Austin, Texas. For more information, visit www.nsslabs.com.

© 2013 NSS Labs, Inc. All rights reserved. All brand, product and service names are the trademarks, registered trademarks, or service marks of their respective owners.

Add to Digg Bookmark with del.icio.us Add to Newsvine

More Stories By Marketwired .

Copyright © 2009 Marketwired. All rights reserved. All the news releases provided by Marketwired are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.

@ThingsExpo Stories
"ReadyTalk is an audio and web video conferencing provider. We've really come to embrace WebRTC as the platform for our future of technology," explained Dan Cunningham, CTO of ReadyTalk, in this SYS-CON.tv interview at WebRTC Summit at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Financial Technology has become a topic of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 20th Cloud Expo at the Javits Center in New York, June 6-8, 2017, will find fresh new content in a new track called FinTech.
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
Successful digital transformation requires new organizational competencies and capabilities. Research tells us that the biggest impediment to successful transformation is human; consequently, the biggest enabler is a properly skilled and empowered workforce. In the digital age, new individual and collective competencies are required. In his session at 19th Cloud Expo, Bob Newhouse, CEO and founder of Agilitiv, drew together recent research and lessons learned from emerging and established compa...
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
Businesses and business units of all sizes can benefit from cloud computing, but many don't want the cost, performance and security concerns of public cloud nor the complexity of building their own private clouds. Today, some cloud vendors are using artificial intelligence (AI) to simplify cloud deployment and management. In his session at 20th Cloud Expo, Ajay Gulati, Co-founder and CEO of ZeroStack, will discuss how AI can simplify cloud operations. He will cover the following topics: why clou...
The Internet of Things (IoT) promises to simplify and streamline our lives by automating routine tasks that distract us from our goals. This promise is based on the ubiquitous deployment of smart, connected devices that link everything from industrial control systems to automobiles to refrigerators. Unfortunately, comparatively few of the devices currently deployed have been developed with an eye toward security, and as the DDoS attacks of late October 2016 have demonstrated, this oversight can ...
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discussed how businesses can gain an edge over competitors by empowering consumers to take control through IoT. He cited examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He also highlighted how IoT can revitalize and restore outdated business models, making them profitable ...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
"Once customers get a year into their IoT deployments, they start to realize that they may have been shortsighted in the ways they built out their deployment and the key thing I see a lot of people looking at is - how can I take equipment data, pull it back in an IoT solution and show it in a dashboard," stated Dave McCarthy, Director of Products at Bsquare Corporation, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.