Persistent Threats Can Last Inside SMB Networks for Years

  /     /     /  
Publicated : 23/11/2024   Category : security


Persistent Threats Can Last Inside SMB Networks for Years


The average dwell time for riskware can be as much as 869 days.



Dwell time — the amount of time a threat spends inside of a network before an organization discovers and removes it — has become a significant problem for small and midsize businesses (SMBs), according to a report released today by Infocyte.
The report, based on more than 339,000 accounts and behavioral logs for malicious activity, focuses on companies that have between 99 and 5,000 employees and annual revenue of up to $1 billion.
Dwell time for attacks with ransomware averaged 43 days, the report points out. On the other hand, average dwell time for all other persistent threats (non-ransomware) averaged 798 days, while dwell time for riskware – defined as unwanted applications, Web trackers, and adware – averaged a whopping 869 days.
According to Chris Gerritz, co-founder and chief product officer at Infocyte, 72% of SMBs had riskware and unwanted applications in their networks that took longer than 90 days to remove. While they were generally lower risk issues, the bigger takeaway is networks that fail to control riskware typically have a lower readiness to respond to high-priority threats when they are uncovered.
We found that 60% of malware is identified by [antivirus] vendors using a generic signature – it doesnt specify what the issue is – so thats also why SMBs cant always understand the difference between high-priority and low-priority risks, Gerritz says.
The
Infocyte report
also explains why the dwell times of some of the persistent threats and riskware are well more than two years. For example, some of the active infections residing on the inspected systems are configured to sinkholed domains and pose no immediate threat, it says.
That said, one family of infections that researchers found traced back as long as a decade ago. While they didn’t pose a threat after a series of botnet operators were arrested in subsequent years, it’s still surprising to find the malware still active on what appear to be protected endpoints so many years later, Gerritz says.
If continuous monitoring is not an option, Gerritz recommends that SMBs once a year bring in a third party to perform a compromise assessment at the same time they conduct a vulnerability assessment and pen tests.
If companies cant afford threat analysis, they should at least get these tests done once a year, he says, so security pros can check for active malware with long dwell times that may have been sitting active in the network for many years.
Aaron Sherrill, a senior analyst at 451 Research, says Infocytes research brings to light how most small companies lack standard security controls.
They may not have updated technology, the signatures are not updated, the alerts and events are often ignored, or maybe they just dont have the bandwidth to do it all, Sherrill says. If companies can afford them, compromise assessments should be more than once-a-year events.
Too often companies do these assessments as a checkbox item and they forget about it, Sherrill says. Many of these threats are very sophisticated and are engineered not to be detected. Companies are at risk every minute of every day. What they really need is to have their networks continuously monitored.
Related Content:
More Than Half of SMB Devices Run Outdates Operating Systems
ADT Teams up With SonicWall for SMB Security Services
Small Businesses Turn to Managed Security Providers for Security
Cyber Readiness Institute Launches New Program for SMBs
 
Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the 
conference
 and 
to register.

Last News

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Persistent Threats Can Last Inside SMB Networks for Years