Endpoint attacks can come from any direction and many sources. Just consider the reported vulnerabilities found in Apache Struts and the damage caused by WannaCry and Petya. Companies need to stay one step ahead of endpoint attacks, but they struggle due to a lack of visibility of endpoint status, the complexity of investigations and ineffective remediation.

Let’s consider the Apache Struts vulnerability in more detail. Some versions of the Apache Struts web application development framework allow attackers to execute arbitrary code in the context of the affected application. See the related S2-052 Apache Security Bulletin and the IBM X-Force Exchange security alerts page for more technical details on how the vulnerability can be exploited, what version of Apache Struts is affected and the best-recommended remediation actions to take.

Register for the Sept. 27 webinar: 3 Tips for Effective Endpoint Security

How Do You Know If Your Endpoints Are Susceptible?

What if you’re vulnerable and you don’t even know it? Security and IT organizations must be able to see, understand and act on endpoint threats fast. In the case of Apache Struts, you must be able to quickly identify every computer where there could be applications exploiting Apache Struts and determine which versions of the framework are installed on which servers or computer endpoint devices. But how do you know if you’ve already been impacted by a security vulnerability? Where do you begin?

Because the Apache Struts runtime library is not deployed in a dedicated directory or file system path, the malicious, arbitrary code may be located anywhere within the file system. As a result, you must first scan the entire file system on every endpoint, including Apache development environments, to determine whether the rogue executable file exists.

Mitigating Endpoint Attacks

Once you know which servers are affected, you need to take the actions suggested by the security bulletins to remediate the vulnerability, such as but not limited to updating software on all the affected endpoints. This includes updating Apache and other applications that leverage the Apache Struts runtime library. These applications must then be recompiled and redeployed. You may not be able to shut down or quarantine the entire server if it is running other critical applications that are not affected by this vulnerability. The IT security and operations teams need to decide how to best remediate based on which servers are affected within their environments.

According to Forrester Research, “Endpoint security represents the front line in your fight against cyberattackers. Breaches have become commonplace among enterprises, and your employee endpoints and servers are targeted more than any other type of asset.” Solutions such as IBM BigFix can help IT security and operations teams put in place the required remediation actions based on the organization’s environment and risk mitigation assessments.

With the ability to clearly see the status of all endpoints across the enterprise and use guided investigations to understand both the scope of an attack and the specific remediation steps needed to contain the threat, security teams can act quickly and decisively to protect valuable assets and reduce the organization’s attack surface.

Read the white paper: Transforming endpoint security — Going far beyond attack detection

more from Endpoint

IOCs vs. IOAs — How to Effectively Leverage Indicators

Cybersecurity teams are consistently tasked to identify cybersecurity attacks, adversarial behavior, advanced persistent threats and the dreaded zero-day vulnerability. Through this endeavor, there is a common struggle for cybersecurity practitioners and operational teams to appropriately leverage indicators of compromise (IOCs) and indicators of attack (IOAs) for an effective monitoring, detection and response strategy. Inexperienced security […]

TrickBot Gang Uses Template-Based Metaprogramming in Bazar Malware

Malware authors use various techniques to obfuscate their code and protect against reverse engineering. Techniques such as control flow obfuscation using Obfuscator-LLVM and encryption are often observed in malware samples. This post describes a specific technique that involves what is known as metaprogramming, or more specifically template-based metaprogramming, with a particular focus on its implementation […]