Malware and ransomware
Malware – including viruses, ransomware, spyware, worms, and Trojans - is most commonly delivered via malicious payloads – files and URLs. Thousands of new malware variants appear each day. Legacy solutions fall short when dealing with advanced evasion techniques and defending collaboration platforms.
Advanced Email Security helps you stop malware with multi-layered defenses, including:
- Anti-evasion – Detect hidden malicious content
- Threat intelligence – Stay ahead of emerging threats
- Anti-phishing filters – Detect malicious URLs
- Antivirus engines – Stop known malware
- Next-generation dynamic engine – Catch zero-days and APTs that evade conventional defenses
Phishing
Phishing attacks are the root of 91% of all cyberattacks, as reported by CSO Online. They leverage social engineering to deceive their target and gain access to sensitive information by employing files, URLs, and text-based techniques posing as legitimate sources.
Advanced Email Security helps prevent phishing before it reaches end-users with:
- Anti-evasion – Unpack deeply embedded, hidden phishing attempts
- URL reputation – Block known, malicious URLs based on four leading URL reputation engines
- Image recognition engine – Block unknown malicious URLs based on the images and logos used on webpages
- Threat intelligence – Combine six market-leading sources and Perception Point’s unique engine
Business email compromise (BEC)
Impersonation-based attacks trick employees into making innocent mistakes, thinking they’re communicating with a person they know. A significant part of BEC attempts do not have a malicious payload and leverage only text-based techniques, making them especially tricky to detect and prevent.
The Advanced Email Security helps prevent impersonation attempts with:
- Anti-spoofing - Prevent payload-less attacks through machine-learning algorithms with IP reputation, SPF, DKIM, and DMARC record checks
- Anti-evasion – Deep scan to detect malicious hidden content
- Payload-based protection – Reduce “further along the line” BEC attacks with threat intelligence, phishing, and antivirus engines
Zero-days and APTs
Zero-days and APTs are especially hard to catch and prevent. They can lie in wait and strike months before they’re discovered by leveraging unknown software vulnerabilities. Standard APT modules, such as sandboxes or content disarm and reconstruction solutions (CDRs), rely on known data and behaviors that evasion techniques can mask when in a sandbox.
Advanced Email Security's market-leading technology helps you prevent zero-days and APTs:
- Next-generation dynamic scan – Stop zero-days and APTs with a unique CPU-level technology that detects and blocks advanced attacks at the exploit stage, before malware release, based on the assembly code
Evasion techniques
Email-borne attacks are getting trickier to detect. Attackers use evasion techniques such as new file types, link chains, malicious content hidden within clean files, stalling mechanisms that sandboxes can’t observe, ensuring the malicious payload takes action only when facing actual end-users. For conventional defenses, preventing such techniques is almost impossible as it takes too much time, money, and technological resources.
The Advanced Email Security uses unique technology to prevent evasion techniques that conventional defenses miss:
- Anti-evasion - Recursively unpack the content into smaller units which are then dynamically checked by multiple engines in under 30 seconds, compared to 20+ minutes for legacy sandboxing solutions.
Account takeover (ATO)
Account takeover (ATO) has been increasingly commoditized through the cybercriminal ecosystem — whether the target is business email or a company’s bank accounts. Known also as account compromise, ATO occurs when a cyber attacker gains control of a legitimate account. Once they have control of an account, attackers can launch a variety of attacks, such as supply-chain phishing, BEC attacks, data exfiltration, financial fraud, etc. There are no preliminary signs of such an attack; in most cases, once the signs of ATO are obvious, the damage has already been done.
Advanced Email Security helps you to intercept account takeover attempts, at any stage — ready to prevent, detect, and rapidly respond with multiple defense layers:
- Prevent credential theft — block phishing attempts to steal employees’ credentials with multiple engines
- Monitor accounts for signs of compromise — analyzes end user patterns and behaviors and uses machine learning algorithms to detect anomalies that could suggest an account has been compromised
- Instantly detect and remediate compromised accounts — ensure fast remediation and account containment by the incident response team in the event of account takeover