Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - All Seeing All Knowing Border Control
Articles

All Seeing All Knowing Border Control

ISB Editorial StaffBy ISB Editorial StaffMay 30, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

peter-cohenNecessity is the mother of invention, and with new breaches reported on a near-daily basis, the evolutionary arms race between hackers and cyber-defenders has led to the rapid disruption of the traditional managed security service provider (MSSP) market. As vendors scramble to stay relevant, this has led to a sea of sales messages and acronyms – including the advent of ‘EDR and proactive threat hunting’.

Breaking this down, we have EDR (Endpoint Detection and Response), the word proactive (the mainstay of copyright teams globally), and threat hunting (why wouldn’t you want that) … but marketing aside, what does this actually mean?

The easiest way to explain EDR and proactive threat hunting is to use an analogy. Let’s liken the corporate IT network to a country, and use the UK as illustration.

ID Check Point

The UK goes to great lengths to stop known foreign criminals entering the country.

There is the expectation that, individuals who are known to have performed illegal activities in the past, maybe a potential risk to society if allowed into the country. To mitigate this risk, the UK Border Agency check everyone’s passport arriving at international airports, and if there’s a match against the database, entry to the country is denied.

This is much like your traditional MSSP vendor monitoring an organisation’s internet ingress points for known or suspected ‘bad’ IP traffic. The danger is that, if the criminal has a new passport with a new name, they may be able to get through the border in the same way that a moderately capable attacker would spin up a new IP address or flip some bits in their malware to target an organisation.  Indeed, in the 2015 Verizon breach report, over 80% of malware samples associated with breaches were unique to that organisation.

Is that it then? Is any criminal with a new passport guaranteed to get through?

Behaviour Analysed

The answer is no. Thankfully, the UK Border Agency staff receive extensive training to help them spot suspicious behaviour which may indicate that someone is not who they say they are.

In the same way, IT security vendors have evolved to address the problem with the widespread deployment of heuristics and behavioural analytics run against inbound files. For example – ‘This file says it does ‘x’, but actually hidden inside it does ‘y’ so it must be blocked’

The problem with this approach is that each vendor will plug just one or perhaps a handful of attack paths with its specific technology, and even then, being driven by automation, they cannot be accurate 100% of the time.

Breaches occur almost daily, week in week out from relatively unsophisticated attackers, proving this approach fails.

Alternative Entry Point

Going back to the original analogy, and taking the example of an advanced criminal who is well resourced and persistent. The criminal wants to get into the UK, and to guarantee their success at doing so, they plan to land deep inside the country, parachuting in, and thereby bypassing all border controls entirely. If anyone did spot them on landing, they would have a new passport anyway. This is how modern cyber threat actors operate; they go straight for the users’ endpoints with custom malware in phishing campaigns, USB sticks or watering hole attacks, bypassing the security controls to establish a foothold on the network.

Eyes and Ears Everywhere

EDR and proactive threat hunting is different.  It assumes that the above scenarios will play out, that the perimeter will be breached, that compromise is inevitable.

In terms of border control in the UK, an EDR tool is the equivalent to the Border Agency going door-to-door to every single house in the country, every single minute, to check whether there is anyone new or different on the premises (anomaly based analysis).

This intelligence is then utilised by the Serious Organised Crime Agency (SOCA) to guide their agents through counties, into towns, narrowing down to streets, and ending up at the specific house where a new or different person is deemed to be – this is the equivalent to proactive threat hunting.

Once at the house, the SOCA agents need to determine where the person has come from (network traffic analysis) and what they have done since arriving (log analysis and further EDR).

Rather than just relying on a passport check at the airport.

While it unrealistic to implement these draconian controls in countries – after all, the analogy can only go so far, thankfully corporate networks are a different story. Managed EDR threat hunting services are readily deployable, and affordable, so the electronic ‘foreign criminals’ looking to infiltrate the enterprise has nowhere safe to hide.

Countercept is exhibiting at Infosecurity Europe – 7 to 9 June at London Olympia, Stand B260

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}