Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Mutating Malware and Data Center Blind Spots in 2016
Articles

Mutating Malware and Data Center Blind Spots in 2016

Brian A. McHenryBy Brian A. McHenryDecember 15, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Data Center Blind Spots in 2016
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Predictions for the coming new year always abound. While no one has a crystal ball, I have the benefit of talking to a lot of security teams. Last year around this time, I held forth that HTTP/2 and TLS 1.3 would be disrupting the Internet in 2015. While HTTP/2 adoption is only now starting to really pick up speed, and we’re still awaiting a new version of TLS, the all-HTTPS Internet is unquestionably on its way. While intelligence agencies speculate upon the impact of criminals and terrorists encrypting their communications, the all-HTTPS Internet is already impacting most of us in much more direct, provable ways.

Inbound attack vectors for malware are well known. Phishing, fraudulent emails, social media links, infected attachments, drive-by infections, and a litany of other techniques exist to infect a desktop, mobile device, or server. However, once a device is infected, the malware designed to steal data must then smuggle that data out without detection. Two methods of data smuggling leap immediately to the forefront: via DNS and via TLS-encrypted connections. These methods are effective because most enterprises are unable to effectively inspect these outbound connections. Let’s break down each data smuggling method, both of which I predict will grow rapidly in 2016.

First, DNS data smuggling—commonly called DNS tunneling—is effective because most enterprises leave DNS wide open outbound from the data center or campus. That’s because almost every system on the network needs to make DNS calls. Even though many anti-malware solutions are able to detect anomalous DNS traffic, these anomalies are often not detected until they reach the outbound DNS caching resolver. The DNS caching resolver forwards requests on behalf of other systems and serves up cached responses to reduce the outbound DNS traffic volume. The problem here is attribution and tracing the indicators of compromise (IOC) back to the source, as most caching resolvers do not log much detail about which source IP requested what name resolution. Bigger than the attribution problem is the fact that those same caching resolvers often lack a DNS firewall, which would enable protocol and payload inspection to verify a legitimate request and/or the presence of data leakage.

While DNS will continue to be a growing attack vector due to the often loose outbound DNS security models of many enterprises, the trend toward an all-HTTPS Internet continues to blind even the most advanced anti-malware and data-loss prevention (DLP) architectures. HTTP/2 RFC prefers TLS encryption by default. In fact, all browsers supporting HTTP/2 require TLS to successfully make an HTTP/2 request. In addition to requiring TLS encryption, the HTTP/2 protocol blacklists ciphers that do not support Perfect Forward Secrecy (PFS), even when the minimum version of the TLS protocol (v1.2) is in use. If a firewall, IPS, or other device happens to be passively decrypting traffic with a copy of the private key, this functionality will also be blinded when HTTP/2 and forward secrecy ciphers are in use.

The second data smuggling method is via TLS-encrypted connections. Following the April 2016 IETF meeting in Buenos Aires, we expect the ratification of TLS 1.3, which supports only perfect forward secrecy ciphers and is the preferred TLS protocol of HTTP/2. Recent changes to the Payment Card Industry (PCI) Digital Security Standard (version 3.1), will soon require all PCI merchants—including e-commerce websites—to support TLS 1.2 or better. Since e-commerce sites depend on fast page-load times and secure credit card transactions to be successful, it’s easy to see why the performance and security benefits of HTTP/2 will encourage rapid adoption of these new protocols that are broadly supported by modern browsers.

Since traffic-heavy websites like Facebook, LinkedIn, Twitter, YouTube, and even Netflix are now TLS-encrypted by default, well over half of all Internet traffic will be encrypted in 2016. Some TLS-encrypted sites such as streaming media can be easily blocked by policy based on category. But for others such as social media, it’s harder to establish a blanket blocking policy as there are legitimate business reasons to allow this traffic out. Effective interception of this TLS-encrypted traffic, even with PFS ciphers in place, is vital to an effective anti-malware strategy. With new malware variants numbering in the hundreds of thousands per day, signature-based protection on endpoints is only partially effective. Inspecting traffic payloads and patterns is absolutely vital to supplement signature-based solutions. Preserving the capabilities of existing anti-malware and data loss prevention solutions, even as encrypted traffic grows, will be the number one priority for security and risk management teams in 2016.

In 2016, as malware increasingly mutates to leverage outbound data paths with blind spots, we’ll need to stay one step ahead of data smugglers and reduce the risk of a breach. Focus on the most common data paths, which are HTTPS and DNS, and arm our incident response teams with the visibility and forensics they require to have a fighting chance.

Brian_McHenry
Brian A. McHenry

As a Senior Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers and F5 product teams, providing a hands-on, real-world perspective. He is a regular contributor on InformationSecurityBuzz.com, a co-founder of BSidesNYC, and a speaker at AppSecUSA, BC Aware Day, GoSec Montreal, and the Central Ohio Infosec Summit, among others. Prior to joining F5 in 2008, McHenry, a self-described IT generalist, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

  • Brian A. McHenry
    The WAF Is Not Enough
  • Brian A. McHenry
    Access Management, With A Side Order Of Identity
  • Brian A. McHenry
    The Internet of Thingbots
  • Brian A. McHenry
    Black Hat USA 2017: Bigger and Better (?)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}