Intel and security software vendor Cybereason will provide ransomware protection at the CPU level in a joint product that combines Intel’s new Hardware Shield technology, built into its upcoming vPro processors, with Cybereason’s anti-ransomware capabilities.
While the ransomware protection isn’t yet available — Intel just launched its 11th Core vPro mobile processors this week at CES — it represents the first instance where PC hardware plays a direct role in protecting enterprise endpoints against ransomware, the companies say.
The new vPro processors come with Intel Hardware Shield built into them. This is essentially a bundle of security capabilities including Intel Threat Detection Technology (Intel TDT), which enables security ISVs to offload memory scanning, artificial intelligence (AI)-based malware detection, and other performance-intensive security workloads. Other Hardware Shield features include hardware-accelerated virtualization and encryption to protect applications, data, and operating systems without hurting user productivity.
Cybereason is the first software vendor to integrate the new technology into its security platform. The endpoint security vendor has been investing heavily in anti-ransomware capabilities since 2016, CTO Yonatan Striem-Amit said.
“As part of that, we started engaging with Intel,” he said. “Intel did two things that, for us, were very interesting in these 11th generation CPUs.”
Cybereason Platform With Intel Hardware ShieldThe first is the embedded GPU, which allows the platform to offload machine learning models and other more advanced, performance-intensive anti-ransomware technologies onto the GPU when it’s idle. “If you try to run those on a regular CPU without acceleration, it may cause some performance impact for the user,” Striem-Amit said. “By leveraging the GPU capabilities, we should be able to run these more complex, advanced models without any risk to the overall user experience.”
The second thing involves using the CPU performance monitoring unit (PMU) to detect ransomware. The Intel PMU sits beneath applications, the OS, and virtualization layers, and it generates signals that report on CPU activity. But it can also detect threats in real time. “What Intel and us have discovered, is that using these signals we’re able to tell if there is a massive amount of encryption happening,” Striem-Amit said.
As it detects threats, Intel TDT sends a signal that can then trigger remediation. Integrating Intel TDT into the Cybereason Defence Platform provides another source of ransomware threat detection, Striem-Amit said.
“Using that (TDT) signal, along with the rest of our behavioral analysis components, we are able to say with greater confidence that right now there is ransomware potentially happening in the customer’s environment,” Striem-Amit said.
Cybereason Says Double-Extortion Ransomware on the RiseRansomware protection takes on a whole new level of urgency in 2021 following the huge spike in attacks and skyrocketing, multi-million-dollar ransom demands we saw last year and the first ransomware-related death at a German hospital.
“We’re seeing the ransomware authors continually evolve their code to become better at extracting money,” Striem-Amit said. “Over the last year we’ve seen many more cases of double extortion, which is particularly nefarious because the criminals are causing even more damage to the enterprise victims.”
Double-extortion ransomware attacks weren’t widely used until 2020, according to Check Point’s 2020 mid-year report. In these attacks, hackers first extract large amounts of sensitive data prior to encrypting a victim’s databases. They then threaten to publish that data unless the victim pays ransom demands, thus putting extra pressure on organizations to pay up. A Q3 Check Point report saw another sharp rise in double-extortion ransomware attacks with the security vendor’s threat researchers reporting a 50% increase in the daily average of ransomware attacks, compared to the first half of the year. The vendor expects to see another ransomware uptick in 2021.
And while $10-billion ransoms and double-extortion ransomware didn’t really take off until 2020, the threat has been around for a while now, and Cybereason has focused on developing anti-ransomware technology for the last five years, Striem-Amit said.
Ransomware ‘Hurts Everyone’“Since 2016, Cybereason observed the threat of ransomware becoming critical, and we, in a sense, took personal offense because it’s hurting everyone, from consumers to our enterprise customers in ways that were debilitating. And it’s heartbreaking to talk to a grandmother who lost pictures of her grandkids. This is as dramatic, if not more, than talking to a business who might go down because they have lost all their data and now required to pay this exuberant amount of money. So we made a commitment to go all in on protection against ransomware.”
This started with a free product for consumers, called RansomFree, and over the years Cybereason has built out its ransomware prevention technology. The vendor’s approach combines intelligence-based, deception, behavioral analytics, and machine-learning algorithms to block ransomware before any data can be encrypted or compromised. This includes protection from attacks leveraging previously unknown, fileless, and master boot record-based ransomware.
“We’ve developed a lot of technology that not only finds known ransomware but really focuses on unknown ransomware by looking at behavior of a system,” Striem-Amit said. “If any program in the operating system is starting to exhibit ransomware-like behavior, we will block it and prevent any damage from being done to your endpoints.”
The new anti-ransomware product in development with Intel also follows Cybereason’s recent push into extended detection and response (XDR) and a new Breach Protection Warranty that provides up to $1 million in coverage to customers in the event of a breach.
Comments