Thursday, September 24, 2015

Blended Threats/Controls

Question - considering the plethora of Blended Threats which leverage both the Email & Web channels to exploit our networks... is it important that our Security Controls have visibility into both mediums?

Case in point - current phishing email traversing the internet which leverages legitimate looking graphics (directly below).  Wouldn't it be nice if your web security solution knew of these spam/phishing URLs?  On the flip side, wouldn't it be nice if your email security solution knew about malicious URLs?



As you'd expect, the link redirects to a malicious site... located in the Netherlands in this instance.  Question - how important is it that your security solutions have a worldwide research team/presence?



Note that the site is attempting to obfuscate the content by leveraging javascript and Base64 encoding:



Final question - wouldn't it be nice if your security solutions not only had a worldwide presence in the Web & Email channels... but could also block active code (javascript, java, active-x) ala the Websense ACE Engine?  :-)

2 comments:

  1. Share great information about your blog , Blog really helpful for us . We read your blog , share most useful information in blog . Thanks for share your blog here . Biometric Security Systems Singapore

    ReplyDelete