Micro Segmentation vs Endpoint Protection: What You Need to Know

Endpoint protection has to stop malware before it spreads across your network. Organizations use many approaches to guard their machines. These include on-site binary isolation, server-based micro-virtualization, real-time system isolation, and over-the-wire binary static analysis.

Why signature-based endpoint protection falls short

Most detection software checks the binary while it moves across the network, not on each machine. True static or dynamic analysis through sandboxing needs a lot of CPU and memory. Sending files off-site for analysis is slower still, so malware often infects the machine before anyone flags the binary as malicious.

Today, most endpoint solutions look for signatures in binaries. They check the entropy of the binary, search for SHASums, and scan strings for known command and control centers. They also look for known IP addresses that talk to those centers. These checks are simple, so attackers have learned to evade them. Malware developers use multiple packers when they compile the malware and build anti-debugging functions into their code. As a result, the endpoint stays infected or open to attack.

Evading signature-based protection is easy because attackers can change a binary after they compile it. That makes it simple to alter trusted system binaries so they bypass security measures. Binary masking and anti-debugging often work together, so a trusted executable looks completely safe and benign to detection tools.

Proper endpoint protection has to account for all of this, or an organization risks widespread infection.

How malware evades sandboxes

Endpoint-based sandboxes, also called micro-segmentation, emulate the execution of each binary inside a virtual residence. They spin up micro virtual machines that work out what the binary intends to do. Malware knows this, so it checks its environment before it delivers its payload.

The malware may check the uptime of the machine, the network around it, and the hard drive space in the virtual environment. If the drive is too small, the malware assumes a sandbox and does not execute. It may also count the installed programs and read the date and time of the server that hosts the staging environment.

Network-appliance sandboxing services have historically helped identify new dynamic threats. However, that approach does not work against intelligent malware that detects its environment and acts accordingly. Malware developers know these detection techniques well, so they use recursive packing to bypass the sandbox once they detect active analysis.

Modern malware families are smarter than the protection software that monitors them. They simply watch for real user interaction, machine uptime, hard drive space, and the programs installed.

Once the malware sees that it sits in a false environment, it performs polymorphism to avoid sandbox based detection engines. The sandbox then treats it as benign. The malware deletes itself from the system, and nobody analyzes it again because the system now trusts its SHASum.

The proper way to protect an endpoint from infection is to avoid network or off-site intermediate sandboxing. It also means avoiding any off-site detection engine or cloud-based “next-gen” binary static analysis altogether.

How Volico’s Endpoint Protection actively works to prevent malware from infecting your business network, servers, and endpoints?

Volico endpoint protection uses endpoint macro-virtualization on the endpoint itself to perform sandboxing. It treats the actual endpoint as the execution environment and wraps each binary in a predictive jail. The malware runs without knowing it sits in a jail, while the system reports its true nature and intent back to the security team.

Threat landscapes change, so security teams constantly need new detection techniques. Positive endpoint protection uses endpoint-based micro-virtualization to attach to the binary and learn its true intent. It informs a dashboard about the life cycle of the malicious code and almost befriends the malware, all to notify the security analyst about its intent.

This gives the analyst a bird’s-eye-view dashboard. The analyst can determine the true nature of a binary, benign or malicious, through static and dynamic real-time monitoring and analysis. Because the technique uses no signature-based algorithms or predefined attributes, the level of false positives stays manageable.

What micro-virtualization means for your security team

Metamorphic, polymorphic, and semi-self-aware malware becomes more relevant every day. Current statistics show that over 2 million new malware variants appear every month. A single variant can cause tremendous financial loss and destroy trust in the infected organization, enterprise, or brand.

Endpoint-based micro-virtualization also removes staff overhead. Security teams no longer need to train or write YARA detection signatures to separate safe binaries from malicious ones. YARA is a tool that helps malware researchers identify and classify malware samples. This is the proper approach to endpoint protection because the product uses no definition files or signatures at all.

Running each binary in a separate space makes it easy to identify memory-based malware and malware that uses birthday attack techniques. The environment fast-forwards time, so time-based tricks fail.

Why detection belongs on the endpoint

Detection has to happen on the intended endpoint itself, in a macro-jailed environment, to catch new emerging threats. This approach assumes that all malware will eventually reach its endpoint.

Once malware reaches the endpoint, a sandbox-by-end detection approach can determine whether the infected binary, or its variant, will cause harm. Signature-based and static analysis systems cannot do this. The sandbox analyzes the entire lifecycle and malicious behavior of the malware and identifies suspicious activity during execution. The binary never knows, because it has passed all evasion checks and believes it runs in a true working environment.

This technique is one of the only ways to detect and prevent unseen malware, including on-the-fly morphic malware that shows no static signatures or known indicators of compromise. Standard behavior analysis, real-time integrity monitoring, and behavior-based detection also work well, because the sandbox wraps the executing binary at the machine level.

This work lets the malware execute its intended malicious activities inside the jail. The system then reports on every disk, memory, network, and registry change the malware intended. It reports home and never runs outside its micro-virtualization environment.

Do you plan on implementing endpoint protection software in the near future?

Volico’s Endpoint Protection solutions provide excellent defense against unwanted intruders from both the internet and the office. Delivered with maximum flexibility for your environment. Our endpoint security is a cost-effective, scalable solution that helps your business guard against intrusion.

Get in touch with us today for a FREE consultation!

•  Call: (305) 735-8098
•  Chat with a member of our team to discuss which solution best fits your needs.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more