martin_roesch
VP and chief architect, Cisco's Security Business Group

An Overview of Malware Protection Techniques

Opinion
Jan 15, 20141 min

How systems typically protect endpoints from malware

It should come as no surprise that nowadays malware has become big business. Bad actors are increasingly better funded and improving their approaches for attacking us. We have reached the point where hacking has become industrialized. As vendors develop solutions, attackers continue to innovate. If you think about it, just 10 years ago, we were focused on less sophisticated attacks like Blaster and Slammer. Over time, we have moved from stopping simple viruses and macroviruses of the ‘90s to worms to later the spyware and rootkits of the mid-2000s to today’s APTs and crimeware. Experts estimate that more than 280 million different viruses were released last year alone. The challenge of defending our organizations is a daunting one, requiring a number of technologies working together before, during, and after an attack. In this chalk talk we provide a high-level overview of the techniques that are typically used to protect endpoints from malware.

In Part 2 of this topic, Sourcefire shows a more detailed look at the signatures technique:

martin_roesch
VP and chief architect, Cisco's Security Business Group

Martin Roesch founded Sourcefire in 2001 where he was Chief Technology Officer (CTO) and a member of its Board of Directors. He is now vice president and chief architect for Cisco's Security Business Group. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. A respected authority on intrusion prevention and detection technology and forensics, he is the author and lead developer of the Snort Intrusion Prevention and Detection System (www.snort.org) that forms the foundation for the Sourcefire Next-Generation IPS. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. Roesch holds a B.S. in Electrical and Computer Engineering from Clarkson University.

More from this author