Leading by Innovation McAfee Endpoint Security The Future of Malware-Detection: Activate protection on all Layers outside the Operating System Dipl.-Inform. Rolf Haas Principal Security Engineer, S+,CISSP
Intel and McAfee Joined Security Vision BETTER SECURITY SOLUTIONS & PRODUCTS POWER EFFICIENT PERFORMANCE INTERNET SECURITY CONNECTIVITY SECURITY
Stealth Techniques New Industry Problem Rootkits are designed to hide themself below the OS (just lately a new type in BIOS) Target only very special IP which makes them difficult to detect Use weakest link to get into the organization Social Engineering Embedded Devices Current Solutions only provide protection within the OS
The Motivation has changed... Targeted Attacks, Stealth techniques, Rootkits, etc SLAMMER Virus ZEUS Trojan STUXNET Targeted Attack Cyber Crime AURORA/ Shady Rat Advanced Persitent Threat Hacking for Fun Organized Crime Physical Harm State-Sponsored Cyber Espionage
DEVICES CONNECTED DEVICES
AEROSPACE DIGITAL SIGNAGE INDUSTRIAL ENTERPRISE RESIDENTIAL TEST & PC SECURITY GATEWAY IP SERVICES MEASUREMENT TRANSPORTATION ATM POINT OF SALE MOBILE KIOSK MANUFACTURING MEDICAL DEVICE PRINTER USB MILITARY MEDICAL IMAGING NETWORK APPLIANCES WIRELESS INFRASTRUCTURE IP CAMERAS IN-VEHICLE INFOTAINMENT ROBOTICS GAMING ROUTING & SWITCHING ENTERPRISE VOIP ENERGY & UTILITIES CONTROL HOME AUTOMATION
OF MODERN AUTOMOBILES
lines of code in an average automobile
MEDICAL DEVICES
Malware Tsunami 60.000 Threats plus 50 Billion Devices =??? 2000 2001 2002 2003 2004 2005 2006 2007
McAfee and Intel The Strategic Initiatives Next Generation Endpoint Security Secure Embedded Devices Secure Mobile Devices Cloud Security Platform Activate Silicon Features Security Platform Beyond the OS Expanding Global Threat Intelligence (GTI) Application Whitelisting Integrity Monitor Change Control Device Management Expanding GTI Hardware Root of Trust OS Security App Sandboxing App Validation Management Expanding GTI Identity and Trust Management Application to Application Security Expanding GTI Power Management Embedded Encryption Out of Band Management Out of Band Recovery Anti-Theft Deep Defender using Intel VT-x Application Whitelisting Support for Windriver OS epo Deep Command using Intel AMT Intel AES-NI Intel Anti-Theft SaaS with Ultrabooks
Intel vpro Technology: More than just Manageability Intel vpro Technology Intel Active Management Technology Intel Anti-Theft Technology Intel Trusted Execution Technology Intel Virtualization Technology Intel vpro Technology Support Intel s latest hardware based management, security, and virtualization Ideal for customers who have defined a long-term cross client strategy Available on both Desktop and Notebook PCs
McAfee DEEP DEFENDER NEXT GENERATION ENDPOINT SECURITY USING INTEL VT-X Announced at Intel Developer Forum (IDF) September, 13th 2011
Introducing McAfee Deep Defender Endpoint Security Beyond the Operating System Industry s first hardware-assisted security technology Text Uses McAfee DeepSAFE technology Applications AV DLP Deep Command Deep Defender Real-time kernel memory protection Operating System Virtual Machine Protection from previously hidden threats beyond the OS for enhanced security McAfee DeepSAFE CPU Intel Core VT-x Security Engine Managed by epo + GTI integrated I/O Memory Disk Network Display
McAfee Deep Defender Stopping Stealthy Rootkits beyond the OS DeepSAFE Technology by McAfee & Intel A new vantage point on security Operates beyond the OS Threats cannot hide DeepSAFE Intel i3/i5/i7 CPU (BIOS VT-x Enabled) OS Loader DeepSAFE Loader/Agent Boot Driver Rootkit Boot Driver Driver AV Driver Rootkit Driver Driver Deep Defender Agent Application Application Malware Application Malware DeepSAFE Loaded Here Beyond the OS Boot Drivers Other Drivers Services and Applications
McAfee epo DEEP COMMAND ENHANCED SECURITY MANAGEMENT USING INTEL AMT Announced at Intel Developer Forum (IDF) September, 13th 2011
McAfee epo Deep Command Requirements epo Deep Command utilizes Active Management Technology built into the following Intel platforms: Intel Core i5 vpro Intel Core i7 vpro McAfee Agent 4.5 or higher Supports Intel vpro AMT versions 4.2, 5.2, 6.1.2,7.0, and 7.1.4 No language localization needed Tested to operate on English, Korean, Traditional Chinese, Japanese German and Spanish operating systems
McAfee epo Deep Command Next Generation Security Management Deep Command utilizes Intel vpro Technology for local and remote management beyond the operating system AMT-enabled Desktop running McAfee Agent and Security Software Apps McAfee Security McAfee Agent OS Preboot Intel AMT
Identifying vpro AMT-Enabled Endpoints Deep Command Discovery & Reporting (FREE)
McAfee epo Deep Command Security Use Cases Deploy updated security ahead of an attack if endpoints are powered off (DAT files or ODS) Remote remediate Compromised systems or system failures force physical access to the endpoint, e.g. Endpoint Encryption for PC Disaster Recovery Repair Policy or system misconfigurations that cause connectivity issues Green IT by maintaining security & compliance regulations (Average Cost Per Kilowatt $0.097 25k nodes annual cost savings $400,000)
Endpoint Encryption Traditional Wake On LAN Approach Computer is powered up and waiting in the PreBoot Login disconnected McAfee Agent Endpoint Encryption Network Card Management console sends Wake Up impulse to the machine
Secure Wake & Patch Reset User Passwords Remote Remediation Location aware Preboot Endpoint Encryption epo Deep Command Management Computer epo Deep is Command powered up has and unlocked Endpoint Encryption PreBoot securely will ask and epo the Deep Computer Command can boot for up unlock Windows key McAfee Agent Endpoint Encryption Intel Network vpro Card AMT epo Deep Command sends Wake Up Request to the Computer