Netflix Is Dumping Anti-Virus, Presages Death of an Industry
forbes.com
forbes.com
They recently hired a new PR company (http://www.mgpr.info/) who's been spamming articles to Reuters on SentinelOne's behalf (https://www.google.com/?gws_rd=ssl#q=site:reuters.com+sentin...), and then reaching out to hacks to write submarine articles (http://paulgraham.com/submarine.html) about the death of anti-virus -- which just happens to be the marketing lede of SentinelOne's endpoint protection product.
Then they landed a big contract with Netflix and got a sucker at Forbes to write some PR like it was news, and now it's been picked up by HN and being discussed as though it had some substance.
In 2014, Lastline Labs discovered only 51 per cent of AV scanners were able to detect new malware samples.
Let's unpack this statement.First, consider that for some definition of "new" you can get that number up to 100% or down to 0 (stuxnet). Second, the fact that over half of a crowded, very uneven field accomplish something really difficult is remarkable, and yet you use the word "only" as if all antivirus should detect modern threats. Third, you somehow manage to imply that it's rational to dump any AV because 51% of your options fail at doing something hard.
Perhaps I'm old-fashioned but I think reporters should work hard to avoid spin. In this case, removing the "only" and fully explaining what the take-away is (and isn't) would help a lot.
And what does "post-AV anti-malware" mean?
A love letter? You send love letters like this to people? Are you like a post-modern Keats?
Clearly you have technical chops. But the most technical part of your article, concerning whatever technology somehow separates this product from the rest of the industry (let alone makes it "not anti-virus"), is this single line:
"Its end-point security doesn’t rely on signatures, it monitors every process on a device to check for irregularities and does not perform on-system scans or require massive updates like anti-virus..."
If SentinelOne is doing something truly new, something that merits coverage from tech journalists, it would be nice to read about it.
And btw, you said earlier, "When I contacted SentinelOne after the interview they said they couldn't even go on the record about the Netflix contract", which is an odd thing for them to have told you, since they have a Netflix logo and an official statement from them under the testimonials section of http://www.sentinelone.com/?show_epp=true -- wait a minute, in fact the quote from your article is a word-for-word match for the testimonial on SentinelOne's site: "The direction we decided to go was with a company called SentinelOne, who we’ve been working with for year and a half. They were a true replacement for end-point protection".
Your contact at Netflix must've been reading from Rob Fry's script...
Another timeline: Reporter writes story, company sees story, takes it and uses it for marketing. This is a common occurrence across teh interwebz.
We could get into the nitty-gritty of what anti-virus is and isn't, but frankly I don't think we'll agree. Because what else is HN for other than to argue points ad infinitum until we all realize we've wasted a significant portion of our lives that should have been spent to more altruistic, worthwhile ends?
It comes across as a wannabe-buzzword, and something of a contradiction. Further, I can't find any reference elsewhere.
Calling it post-AV just doesn't seem to offer anything. That's what's making this sound like PR for SentinelOne - maybe they do have a better offering than anybody else, but drawing an arbitrary line (the 'post-AV' line, where everyone else is 'left behind in AV-land') doesn't lend any credibility.
In other words, it was self-pwnage. He did the PR firm's work for them, and nobody at that firm even owes him one.
Also, whatever I might speculate, I do know this for a fact: a screenshot of that article is going on a PowerPoint slide and will be victoriously displayed in a meeting at some point soon.
Edit: Also, I wanted to stab myself in the eye when I read this howler:
"Because Netflix, a well-known innovator in the tech sphere, is the first major web firm to openly dump its anti-virus, FORBES has learned. And where Netflix goes, others often follow; just look at the massive uptick of public cloud usage in recent years, following the company’s major investment in Amazon Web Services."
So everyone uses "the cloud" (whatever that is) because Netflix uses AWS. I don't remember the last time I saw a reach like that on a site like Forbes.
You have to admit though, this certainly reads like a native content article. In the current business climate, you can't fault people for assuming this was paid for.
0-days aren't a problem for sentinelone EPP.
Netflix and whoever they hire (e.g. SentinelOne) is still fighting viruses. They're just doing it using more sophisticated algorithms instead of fingerprints. Traditional anti-virus software trying to match file signatures is not effective against 0-day attacks.
What's newsworthy is that a vendor was able to convince important people (e.g. AV-TEST Institute) that algorithms scanning for anomalies is equivalent to, or stronger than, traditional disk-scanning. However, it doesn't look like they've convinced the credit-card industry yet. They're the ones who determine PCI DSS compliance. However, PCI DSS may not apply to Netflix.
Interpreting the story as an ongoing progression of anti-virus technology, it means the industry won't "die" at all. They're just retooling themselves with more algorithmic approaches. Maybe Symantec will add algorithms and also be included in the changing industry of fighting viruses.
Also the PCI council doesn't define which AV is compliant or not, only states that you need anti-virus protection on all systems commonly affected by malicious software.
It's up to the QSA and acquirer(if that one gets really bored) to accept the solution, neither of which care really. You can use Windows Defender, Clam or the most super duper expensive AV out there it's all the same for them.
The requirement is also worded very carefully "on all systems commonly affected by malicious software" so people could make a case against installing AV on things that AV solutions are not common for, such as Mac's, Linux box's, and even Mainframes (yes there are mainframes in certain PCI-DSS scope's because the QSA wasn't smart enough to find a loop hole to keep it out of scope or the costumer is dumb enough to actually process or store credit cards on it).
Ever since I learned about memory analysis, I have considered almost every antivirus useless. I do have the Windows Defender antivirus active, but if I have a real doubt, I turn to memory analysis just to be sure (still clean luckily!).
It seems like the popular thing lately is to bitch and moan and question the morality of using ad-blockers, but using an ad-blocker is the single most important thing you can do to improve security on your machine for the average user. Blocking Flash, or, should you happen to still encounter it, Java, from autoplaying comes in second. Blacklisting SourceForge in your hosts file might be up there, if they are still bundling crapware with the few legitimate downloads that haven't moved elsewhere.
ublock origin has a "Badware risks" filter list with sourceforge in it.
Wat?!!
But in any case the content of the article is rather less sensational that the headline. It seems like Netflix is 'dumping' anti-virus for... well, another anti-virus tool! It's just that SentinelOne is not signature based, and relies on dynamically detecting dubious activities by processes (which some existing anti-virus tools already do, if to a lesser degree).
1) It might have a "baseline" time during which it allows and records everything, and then locks down anything outside of that (like the old ZoneAlarm did for firewalls).
2) Or it might only lock down certain APIs? File and registry and network access? Not sure where you'd stop with that. What about when it emails everyone in Outlook?
Unless I'm completely off base.
Isn't that the main thesis of the attack-driven defense?
They are dropping the wrong name if they actually want to promote the product.
Wat?
I didn't agree at first, but this smells more and more like PR - there seems to be very little understanding of the news in the article.
What is "the post-AV anti-malware game", and why on Earth would Netflix's end-users benefit from the company's staff computers entering said game?!
Probably cost them no more than a decent lunch while they dictated it to the hack who's name is in the byline.
The real concern are advanced worms. Most of these would likely infect a machine regardless of the presence of an AV, either because they are zero-day or because a machine does not have security patches installed. AVs, typically, would struggle to catch an e.g. malicious BIOS flash resulting from an escalation vulnerability.
In the face of security patching, AVs are largely obsolete, irrespective of their detection rates: not 'completely' because human error does exist (which is why I still run one).
I uploaded 30 to virustotal to see what would happen, and I can't recall exact numbers, but I believe we'd be looking at about 25 that has detection rates of 0/51.
Since then, I'd been a staunch advocate of the argument AV just wasn't worth the effort.
Meanwhile, I walk into organisations and every single person has 15 different toolbars clouding up half there screen real estate, and popups hitting them constantly. And you scan with an antivirus and the majority of players end up claiming this sort of thing is legitimate software.
My main point was: a virus that uses a 0-day (or unpatched/unfixed 0-day) is likely going to cause problems for an AV:
> AVs, typically, would struggle to catch an e.g. malicious BIOS flash resulting from an escalation vulnerability.
Over-exaggerating to clarify: AVs are like bringing a knife to a gunfight. You might just be actually able to eliminate the weaker opponents (who also brought knives), but you're going nowhere against the veterans.
I've recompiled Netcat probably 200 times by now, small refactoring playing with compiler flags (compile with x64 profile, debug on, add some symbols etc..) and every time it avoids every AV out there.
I usually use Virustotal which means that it will be short lived but i can do it over and over and over again ;)
(Japanese for "it can't be helped")
The might work on some binaries in some cases but if you want to avoid evasion refactor the malware yourself.
Encoders and compactors are intended to modify existing binaries only :)
Seems like it's pretty effective for bypassing AV according to how everyone is using it.
1st result 2012: "If you want to avoid detection, a 60% success rate is not good enough. Remember, our implant was caught by 40% of the products, not 40% of the targets. Assuming the better anti-virus products have a larger market share, our 40% product failure rate could look more like an 80 or 90% detection rate on target machines. - See more at: http://www.digitalthreat.net/2012/02/anti-virus-evasion-choo...
4th result 2014: "There are a couple of built in encoders in Metasploit (shikata ga nai is the most popular one), but these signatures have been updated in many Antivirus solutions, resulting in detection."
Every decent AV out there today has signatures of packers and encoders they are very easy to find since the artifacts of things like PE headers and binary cave of the encoded binaries will be identical every time you use them.
Most people who claim it works are simply rehashing the same old metasploit guides that are not really relevant in the real world anything that is wide used will be singnatured in a second by every AV company.
Yes if you encode it and upload it to VirusTotal even today you might get 50% or more evasion but those 50% of products will have maybe 5% of the market, and pretty much zero enterprise users.
In general heuristics work very poorly for binary detection some of them might look for various patterns e.g. block the creation of registry entries from non-installer based malware (which is a large amount of false positives) or look for various interactions like hooking into certain applications or functions but in general I haven't seen a good heuristics engine as of yet.
There are some very interesting machine learning tools but they detect large scale anomalies that could indicate a breach, there are also some machine learning binary analysis tools but they work on a different level and they perform something more akin to reverse engineering.
Signature based detection has it's uses and that's to detect common crap that is here to say. If you look at current trends then 70-90* of malware is unique for each organization (the large gap is due to different verticals) most of that malware when detected won't receive a public signature their AV vendor will release it for that organization only and maybe distribute it among that vertical or to similar organizations. And while you might think well that's bull you don't really want all those signatures anyhow for the AV DB to be effective it needs to be fast so vendors have to limit the amount of signatures they carry, to do that they also tend to remove malware which all of it's exploit have been patched or outdated malware which is no longer relevant (e.g. very small amount of infections). The signatures vary from time to time and if there will be an outbreak of old malware that has been removed the vendors will introduce those signatures again into the DB and they became quite good at predicting outbreaks of common malware.
Now if AV's only detect 10-30% of stuff what detects the rest? Sandboxing doesn't really work, Windows isn't really built for that and to implement a security solution that actually provides true sandboxing for all applications is a nightmare, so you are left pretty much with detecting anomalies across the network. The malware it self is usually then discovered once a breach or an incident has been detected, the most common point of detection is when a breach is ongoing and you discover the egress, sometimes if you have really good monitoring across the board than your FIM(file integrity monitoring) or your user activity monitoring will start yelling very quickly.
Now AV's still have their role they are quick and dirty an they usually work for most (home) users for stuff like thumb drives and simple mail attachment crap, and they are still one of the only tools that can provide real time on-excute/write binary detection most of the new heavy weights are based on detecting the malware post exploit.
Some security solutions now claim to be "anti-exploit" the claim part is because their success rate varies they usually are much more focused for example will only protect browsers, office suits, and common PDF reader and what they do is a couple of things: 1 they know how an existing known exploit will look like when it's being triggered in the application and they will terminate it before the payload is executed (hopefully ;)), 2 they have the ability to detect various exploit oriented artifacts like ROP detection, 3 they do some behavior analysts as they usually only protect 10 or less applications they can application specific heuristics rather than attempt at creating general ones.
Like AV's they usually excel at 1, 2 is tricky especially on 64bit applications because the virtual memory now is so large that it's hard (well impossible blindly) to look through it so ironically enough some "anti-exploits" apps actually require you to disable ASLR (a security feature randomized the memory address of an application across the entire/most of 64bit virtual address space to make it harder to exploit B/O's), and some of them are becoming quite good at 3.
If you are an individual keeping basic opsec, using free AV for generic malware, and not running plugins like Java/Flash automatically should be good enough. If you are an organization then you need to have solutions in place across all tiers to actually detect malware, or at least it's activity since if you are infected you are most likely have been targeted so even if it's not a zero day it will be something unique for you.
How is that "ditching anti-virus", then? Wouldn't a better title be "Netflix is switching anti-virus providers"?
And things like Reason Core are brilliant for nuking any rootkits that somehow get on to a system https://www.reasoncoresecurity.com/
Malware has grown up and is now residing in hardware and can survive entire OS re-installs. I feel sorry for Windows users these days because malware has grown up and it is not as obvious you have malware. In the past there were obvious signs you were infected and the malware made itself known (sort of stupid when you're an attacker really).
Also some of the 'second opinion' tools are interesting too:
The dumbest part is that the title isn't even right, Netflix still absolutely do anti-virus/anti-malware, they've just given up on ineffective signature scanning, and are moving to a dynamic scanning engine.
I actually think signature based AV sucks and would be happy to see the industry move away from it, but cannot condone such dumb submarine articles as this.
Precluding cautious web users from reading is somewhat ironic given that this article is about web security, if indeed that is what this is about. It's probably not intentional, just oversight on Forbes' part.
> Use and regularly update anti-virus software on all systems commonly affected by malware