什么是下一代病毒(NGAV)?

Next Generation Antivirus 被认为是防病毒(AV)解决方案功能的一个进步, and leverages known, 基于签名的防御技术与 扩展检测和响应(XDR) 结合人工智能(AI)和/或机器学习(ML)的功能. 通过利用高级分析来关联来自多个遥测源的警报, NGAV quickly identifies actionable threat intelligence to anticipate and prevent threats faster. 

NGAV is deployed in the form of cloud-based software that has a lighter impact on systems and endpoints,并且在组织和企业中日益成为更常见的AV类型.

NGAV vs. 端点检测和响应(EDR)

In a sense, when XDR and NGAV work together, they are both protecting the network perimeter and extending threat-detection techniques beyond it. EDR发生在位于安全边界内的端点. 不法分子仍然可以找到方法进入手机或笔记本电脑等终端, 所以一个好的EDR解决方案是最后一道防线.

NGAV vs. Anti-malware

再一次,这是广义和具体的区别. As mentioned above, 现代NGAV解决方案旨在利用先进的分析来确保安全, anticipate, 防御网络内外的威胁. Anti-malware solutions are primarily designed to scan individual systems for malware built to bypass security controls.

How Does NGAV Work? 

NGAV的工作原理是检测和防止恶意软件和无文件攻击. 它利用预执行方法来防止战术, techniques, and procedures (TTPs) and malicious behavior used with purpose by bad actors or unwittingly by someone who is properly credentialed. Let’s take a closer look at how an NGAV solution accomplishes its detection and prevention goals:

  • Memory injection prevention blocks attempts by fileless threats so that it can avoid execution of code from the file system. Memory injection prevention can stop injection of and hide malicious code that may occur during a legitimate process. 
  • Malicious documents prevention 破坏或解除试图滥用功能(如maros)的恶意文档, scripts, and built-in tools. By doing this, it allows users to benefit from the full capabilities of modern applications and worry less about infections. 
  • Living-off-the-land prevention interferes with attempts to misuse system-native tools that would otherwise cause damage without the need to deploy classic forms of malware. 威胁无法从这些本地工具中“蹦蹦跳跳”地感染端点. 
  • 操作系统凭证转储保护块 deception technology like credential-theft attempts. 

Providers of NGAV solutions and services typically design the technology to be rapidly launched and operating in such a way as not to hinder performance of network systems or endpoints. 

NGAV vs. Traditional AV

当我们谈论NGAV时,这最后两个字母在文化中仍然很突出. 几十年来,“反病毒”这个词一直是使用计算机的社会的一部分, so it bears asking the question: What exactly are the differences between modern NGAV and traditional perceptions of AV?

AV primarily focuses on protecting the endpoint and/or quickly removing an affected device that may be part of a larger critical infrastructure, 因此可能会对未受影响的设备造成更大的干扰. 这可能会导致企业遭受重大的财务和声誉损失.

NGAV超越了这些传统的AV流程, blocking diverse attacks – including fileless malware – across the entire endpoint ecosystem. NGAV’s main goal is to detect and prevent attacks from reaching critical endpoints all over the network. 不仅如此,通过机器学习和人工智能学习,它还可以帮助阻止逃避行为. 再多的检测技术也解决不了问题 malware and other threats, rather it’s smarter detection focused on prevention that will put attackers on the defensive.

最后一个关键区别在于之前提到的学习概念. 传统的AV在端点上可能很重, meaning it doesn’t really have the capability to adapt to a system’s unique behaviors – it is what it is, and that’s all it will ever be. NGAV, on the other hand, 能否从端点过去的行为中学习, systems, 以及安装了它的网络. This is why it’s so adept at detecting evasive actions and blocking threats much earlier in the killchain than was heretofore possible.

What are the Benefits of NGAV? 

The benefits of NGAV are numerous compared to traditional AV, and can accelerate an organization's network detection and response (NDR) program.

Prevent Threats Earlier 

为企业和安全组织抵御现代威胁, 他们必须努力超越使用ngav阻挠技术的坏人. 这包括在杀戮链中更快地阻止已知和未知的威胁, 切断终端和深层系统访问, or even preventing network access entirely. Traditional AV typically uses signature-based detection methods whereas NGAV leverages a combination of signature-based detection, AI, 和ML来揭示当今攻击者使用的http.

Gain Endpoint Visibility 

As previously mentioned, ML and AI impart NGAV solutions with the ability to adapt to specific behaviors in systems they’re tasked with protecting. This helps analysts to gain a deeper understanding of their endpoints and network systems so they can defend against threats and design better protections based on telemetry that could indicate impending attacks.

See 十大赌博正规信誉网址 Fast

NGAV解决方案通常被设计为轻量级的, add-on technology that won’t slow down system operations – and therefore security personnel productivity. It typically has a small footprint that can deploy quickly, drive key insights, and enable faster mean-time-to-respond (MTTR) 使用自动化资产和流程控制等操作.

Evolve Traditional AV 

具有更低的运营成本、更高的效率 threat intelligence and detection capabilities, and comprehensive coverage, NGAV solutions are typically ideal for security professionals looking to further consolidate across the tech stack. 作为现有检测和响应(D&R)组织可能已经有的解决方案, NGAV可以加速打破安全实践之间的孤岛. 这可以是生产力、效率和增长的驱动力 security operations centers (SOCs) that may already be stretched thin.

NGAV解决方案:需要考虑的问题

As with any solution – especially shopping for one within a category that has the buzzy phrase “next gen” in its name – there are many options and potential vendors. So, it’s best to know how to find one that can tailor an NGAV solution to your unique environment.

  • 您如何使用当前的AV解决方案?? 这个问题的核心是战略. Is there a system or plan in place for how AV is deployed, and what exactly is it built to protect? If a standard enterprise AV is not properly designed to protect the system on which it's running, 那么你的组织可能需要重新校准. 
  • 每个端点上的AV需要多少维护? As covered extensively on this page, a modern NGAV solution goes beyond the endpoint to get ahead of attacks before they reach individual systems. 维护AV在多个端点(数百个)上运行? thousands?)没有利用人工智能和机器学习支持的NGAV预测效率.
  • 您对当前端点事件的可见性有多大? A competent team is going to have a good amount of visibility into their network and the endpoints on it. The question is, could you benefit from more and leverage the insights that visibility brings to better plan and proactively defend? 
  • 降低运营成本对首席信息安全官来说有多重要? The answer here may seem obvious, but holistic solutions that break down silos and consolidate capabilities are increasingly contributing to an uptick in productivity and lower overall costs versus maintaining multi-provider products. 虽然这些单独的产品可能有效, they can create workforce lag when looked at in tandem with other bespoke solutions under an organization’s umbrella.
  • 你的云操作/安全的当前状态是什么? Keep in mind that the ideal state to deploy an NGAV solution is one where robust cloud-operations are currently in place. This will make it possible to get the solution up and running in near-real time and begin seeing benefits almost immediately.

Read More

Antivirus: Latest Rapid7 Blog Posts

Rapid7 Research: 在Metasploit框架中封装反病毒(AV)规避技术