joel windels - vp of marketing @ wandera - machine learning: the new frontier for zero-day security...

31

Click here to load reader

Upload: inspired-business-media

Post on 22-Jan-2018

132 views

Category:

Software


0 download

TRANSCRIPT

Page 1: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Joel Windels, VP MarketingMehul vora, head of pre-sales

MACHINE LEARNING: THE NEW FRONTIER FOR

ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Page 2: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Machine learning hype

Page 3: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

“Machine learning

is the science of getting

computers to act without being

explicitly

programmed”

Page 4: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Machine Learning

Traditional Machine Learning

Software

Input

Output

Software

Input

Output

Page 5: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Machine Learning Algorithms

Supervised Unsupervised

Hidden Markov model

Logistic regression

Linear regression

Anomaly detection

Clustering

Principal Component Analysis

Page 6: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Machine Learning Problems

classification regression

Champions

Hazard

Chelsea

Goals scored

Miles run per game

Number of fans

Page 7: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Google Translate

Page 8: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Uber

Page 9: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Netflix

Page 10: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

AirBnb

Page 11: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

For mobile security

Tireless Looks everywhere

ETERNAL IMPROVEMENT

Always online

Breakneck speed

Page 12: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

2010 2011 2012 2013 2014 2015 20160.2

0.3

0.4

0.5

0.6

0.7

0.8

0.9

1.0

20000

40000

60000

80000

Accuracy of results Quantity of training data

Size of d

ata

Page 13: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Mobile data boom

Page 14: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Mobile data boom

Page 15: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Why machine learning?

new malware variants in 2016

357 million

mobile malware: only 59 variants per family, though increasing

Symantec Internet Security Threat Report 2017https://www.symantec.com/content/dam/symantec/docs/reports/istr-22-2017-en.pdf

Page 16: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

The Wandera challengeEvery month we see

2,168,777

Unique Domains Visited

890,448

Unique Apps Processed

1.175Billion

Requests Handled

58,226GB

Data Seen

481,386

High + Medium Severity Threats

Detected

Page 17: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Signatures are not enough

SusceptibleDevices

IdentifyVulnerabilities

App StoreDownload

IdentifyRisky Downloads

Malicious App

IdentifyOn-device Threat

Commandand Control

IdentifyLeaks & Exfiltration

Page 18: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Number of apps running

Page 19: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

xkwtoznzvkpvgdedefeztwdmd.biz

yxofkncueqcnyyplqowlz.com

rwqojpuwdauooblrqgwcfypztcnznb.org

pndlihylmrxukcmnxduae.info

lnnaqlzeahvgtvwmbxqksczlewg.biz

tzdptukaezhpdmamtwwkjbvcdmca.biz

lrpkjvxeipgeiganbmjibrgfqq.biz

hmypqclzinrhapyllvxdegen.com

icmvscrzpghihetpnfikn.biz

cukzylcucqnzguwcvwemdqnfozts.net

gmtotggbudcuwgmhugymjtsd.info

yhtkbxnffmxcypgyeiovaqytxrgby.ru

eaaeyugabuhmhapnhwgozprq.org

lhakrtxcrwlfemgupirtqceu.net

Photo: Wendy Piersall / wendypiersall on Flickr - https://www.flickr.com/photos/wendypiersall/4406503559/ https://creativecommons.org/licenses/by/2.0/

Page 20: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

The false alarm problem

Looking for rare events

1 bad event per million0.1% false alarm rate

Nearly 1000 false alarms per true alarm

Turn it off

Page 21: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

The true alarm problem

Looking at big data

18 Bn DNS events per day1 bad event per million (say)

12.5 true alarms per minute

Turn it off

Page 22: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Rare doesn’t imply bad

Photo: Dennis Jarvis / archer10 on Flickr - https://www.flickr.com/photos/archer10/4062595504/ https://creativecommons.org/licenses/by-sa/2.0/

Page 23: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Spam email Phishing website Malware app Malware in PDF Worm propagation Malware control

Is it bad?

Image: JDHancock on Flickr, jdhancock.com - https://www.flickr.com/photos/jdhancock/6151250051https://creativecommons.org/licenses/by/2.0/

Page 24: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Mobile risk is broad

Vulnerabilities Data Leaks ThreatsRisky content

… and comes in varying degrees

Page 25: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

State of the nation

RISKY CONTENT VULNERABILITIES DATA LEAKS THREATS

27%of corporate devices

run an out-of-date O/S with a

high severity rating

11%of corporate devices

attempt to access risky content every

day

50%of corporations operate devices with data loss

events involving password leaks

< 10%

of security incidents in 2016 involved mobile

malware

Page 26: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Looks can be deceiving

XCODEGHOST

Thousands of bad apps made with compromised compiler

FREE CALCULATOR

Basic app was fine Made more malicious with

additional download

FREE MUSIC PLAYER

Requested permissions to microphone and camera

Uploaded sensitive data to C&C service

Device that was jailbroken in real-time

Didn’t even have WebMD installed

Masqueraded as trusted medical app to avoid investigations

Page 27: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

How we approach machine learning

Page 28: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

SLocker

Page 29: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

SLocker

Page 30: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Anomalous events

Page 31: Joel Windels - VP of Marketing @ Wandera - MACHINE LEARNING: THE NEW FRONTIER FOR ZERO-DAY SECURITY AND MOBILE DATA ANALYTICS

Future: The Internet of Toasters

Intel home energy sensor on toaster. Free Press / IntelFreePress on Flickrhttp://www.flickr.com/photos/54450095@N05/8634158491https://creativecommons.org/licenses/by-sa/2.0/