BRKSEC-2139: Advanced Malware Protection
Presenter: Eric Howard, Techincal Marketing Engineer

Why aren’t we stopping all the malware???
The term “APT” has become the boogey man of cyber security. :-)
You don’t need to know squat about writing malware in order to launch malware
- Malware rentals
- Malware as a Service (swipe CC, pay bitcoin)
Why aren’t we stopping all the malware?
- To solve the malware problem is to follow a very involved, multi-step process. Not every step can be automated; humans are needed (analysis, triage, more). This makes the process expensive, too.
- There’s no silver bullet
Product does not solve the issue. Process is required, too. Ideally, good process backed by good product.
If you knew you were going to be compromised, would you do security differently? — Marty Roesch, Cheif Architect, Cisco Security, founder of Sourcefire
Do security different:
- Plan A – Prevention: shore up the environment; dig a bigger moat, build thicker walls
- Plan B – Retrospection: track system behaviors without regard for disposition (ie, do this for everything, not just known malware but also “known good” and “unknown”)
Plan A
- 1-to-1 signatures: like anti-virus; also hashes; AV vendors only enable 8-10% of their rules; AMP cloud runs all sigs all the time; Continue reading

Some programmer treats, new hardware, and a handshake with Microsoft highlight a mass of Cisco ACI enhancements.
Intel Network Builders gets a big-name boost.