computer science

profilesaalecynthia123
Virtualcontainersarereplacingsandboxingasatechnologyoption-InfosecurityMagazine2.pdf

7/29/2017 Virtual containers are replacing sandboxing as a technology option - Infosecurity Magazine

https://www.infosecurity-magazine.com/opinions/security-take-its-head-out-of-the/ 1/3

MAGAZINE EVENTS LEADERS NETWORK INSIGHT

Latest

Verticals Vary Widely When it Comes to Prioritizing Cyber North Korea Turns Cyber-Attention to Hacking for Profit

Israel Levy CEO of BUFFERZONE

29 JAN 2015

Sony Pictures Entertainment: The Fallout from 2014’s Biggest Breach

Why Not Watch?

INFOSECURITY MAGAZINE HOME » OPINIONS » 2016: TIME FOR SECURITY TO TAKE ITS HEAD OUT OF THE “SAND” (BOX)

Log InSign Up

 

News Topics Features Webinars White Papers Events & Conferences Directory

As malware has become increasingly sophisticated, conventional protection solutions have proven insufficient for companies’ IT security needs.

While “sandboxing” is still a popular, and frequently deployed solution, over the last several years new technologies and approaches have been introduced to the market. Let’s take a look at one of those approaches, called “containers”, and see how it measures up vs. the current industry standard set by sandboxes.

Common Problems

Containment is a fairly new concept, deviating from the widely known and popular “sandboxing” method. Sandboxing is a detection method which scans potentially malicious files in a confined area/an isolated environment, otherwise known as the “sandbox”, to determine if it is indeed malware. Sandboxing arose as a response to the realization that signature-based technology had grown increasingly ineffective in protecting endpoints from stealth attacks.

Sandboxing, however, once the “go-to” solution for thwarting unknown threats, is also gradually proving insufficient in today’s increasingly sophisticated malware climate, echoing the challenge IT security execs faced with the inadequacy of signatures.

Enter the next generation, virtual containers. Virtual containers reside on the endpoint and continuously isolate applications like web browsers, email and removable storage that come into contact with untrusted sources. Unlike sandboxes, containers are not a time-limited solution for testing whether code is malicious. Instead, they provide an ongoing buffer between the “insecure” realm of the internet and the “secure” realm of the corporate network.

           

20 OCT 2016

Can Good Security Help Drive Greater Business Agility?

29 APR 2016 OPINION

2016: Time for Security to Take its Head out of the “Sand” (box)

Our website uses cookies

Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing Infosecurity Magazine, you agree to our use of cookies.

Okay, I understand Learn more

7/29/2017 Virtual containers are replacing sandboxing as a technology option - Infosecurity Magazine

https://www.infosecurity-magazine.com/opinions/security-take-its-head-out-of-the/ 2/3

26 MAR 2015

Insights into Incident Response – A View from the Front Lines

Related to This Story

The Security Challenges of Enterprise Container Adoption

A Data-Driven Approach to Security Decision Making

Web Isolation: The Evolution of Enterprise-Ready Isolation

Ten Compelling Reasons to Improve Security when Harnessing the Power of Desktop Virtualization

Attacks on Virtual Infrastructure Cause Double the Pain

The Benefits and Drawbacks of Sandboxes

Several years ago, sandboxing became the popular approach to detecting advanced threats, causing several big-name security companies to advocate this as the preferred method. Sandboxes do not continuously run on endpoints, rather they generally run on a server and are used to detonate a suspicious file. Files are opened there first, and if they don’t trigger any alarms after a short time, they are sent onward.

The sandbox is in action for a short period of time, scanning any unknown content and detecting malware. However, once this process is completed, the approved content is free to transfer over into the trusted network. Malicious content, unfortunately, is “smart” and is known to disguise itself as benign until the testing period is over. Following the testing period, the malware is released and a phenomenon known as “sandbox evasion” occurs.

Evolution of the container

Sandboxing and containers have their similarities - they both use virtualization to create a “safe space” for potentially malicious content. But, as hackers focus on devising attack methods that we haven’t thought of, making them impossible to detect, containers take the approach that everyone is suspect.

The security architecture of containers, as opposed to sandboxes, is designed to outsmart malware evasion. With containers, detection is not essential. Instead, both non-malicious and malicious content remain in the container forever.

Containers have evolved out of the need for a more comprehensive solution, one that will create a sort of perimeter around any application that can be used as an attack vector, constantly running, isolating all unknown content, and maintaining constant segregation from trusted networks. A container runs continuously on the endpoint and rather than isolating a file for a short time, it isolates the risky application, like the web browser or email or Skype continuously. Container technology can be implemented in software, on top of the operating system, or as part of the microprocessor’s firmware.

Containers assume anything unknown is untrusted and, therefore, keeps it in a secure and isolated environment, known as the “container”. Anything unknown is eternally deemed untrusted and can only leave the container through a secure bridge that disarms threats and gives security teams control over what enters the corporate network.

Looking Ahead

With 44% of respondents in a recent SANS endpoint security survey admitting that one or more of their endpoints had been compromised in the past 24 months, 2016 will see more money invested in endpoint security—a market growing at a CAGR of 8.4% from 2015 to 2020.

While server-based file sandboxing has been successful in stopping many threats, today’s sophisticated malware attacks demand a more comprehensive solution. Just as malware has evolved and taken on different forms, sandboxing, as well, is assuming different forms, including virtual containers, and micro-virtualization solutions that provide continuous protection. This more comprehensive approach ensures that any threat that gets in – whether through a web browser, email, document, phone etc. will be locked in a container indefinitely.

If we want to prevent the next data breach from happening, we must offer solutions that provide a solid defense, along with seamless deployment and management. Conventional sandboxing has an important role to play in terms of testing suspicious executables in a safe environment. But it is no longer effective in preventing unknown threats as containers continuously isolate risky applications, do not rely on detection and provide a more effective long-term solution for user endpoints from whatever hackers come up with next.

17 NOV 2016

Network Encryption made EASY: Utilizing Network Virtualization to Simplify Network Encryption & Enhance your Network Security

Read Shared Watched Editor's Choice

What’s Hot on Infosecurity Magazine?

1

2

3

28 JUL 2017 NEWS

German Police to Bypass Encryption by Hacking Devices

25 JUL 2017 NEWS

Widespread, Brute-Force, Cloud-to- Cloud Attacks Hit Office 365 Users

28 JUL 2017 NEWS

Emotet Crimeware Adds Self- Propagation to the Mix

4

27 JUL 2017 NEWS

Our website uses cookies

Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing Infosecurity Magazine, you agree to our use of cookies.

Okay, I understand Learn more

7/29/2017 Virtual containers are replacing sandboxing as a technology option - Infosecurity Magazine

https://www.infosecurity-magazine.com/opinions/security-take-its-head-out-of-the/ 3/3

The Magazine About Infosecurity Subscription Meet the Team Contact Us

Advertisers Media Pack

Contributors Forward Features Op-ed

Report ad

This Game Will Keep You Up All Night Vikings: War of Clans

Learn More

Sponsored by Plarium

0 Comments Infosecurity Magazine Login

Share⤤ Sort by Best

LOG IN WITH

OR SIGN UP WITH DISQUS

Name

Email

Password

By signing up, you agree to the Disqus Basic Rules, Terms of Service, and Privacy Policy.

Start the discussion…

?

Recommend

Report ad

This Game Will Keep You Up All Night Vikings: War of Clans

Learn More

Sponsored by Plarium

5

6

4 #BHUSA: You’re Dealing with SupplyChain Security Whether You Like it or Not 28 JUL 2017 NEWS

North Korea Turns Cyber- Attention to Hacking for Profit

27 JUL 2017 NEWS

Google Uncovers Highly Targeted Spyware "Lipizzan"

Copright © 2017 Reed Exhibitions Ltd. Terms and Conditions Privacy Policy Use of Cookies Sitemap

Our website uses cookies

Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing Infosecurity Magazine, you agree to our use of cookies.

Okay, I understand Learn more

https://bevo-us-east-1.adsnative.com/ck?url=https%3A%2F%2Fclicktabs.net%2Fpath%2Flp.php%3Ftrvid%3D10508%26trvx%3D1587426b%26var1%3D71usauto_7hLICib1_0Spi9xI0h4CaV95KHHEw5NARqgnGrCX%26var2%3D1808428%26var3%3Dwww.infosecurity-magazine.com_https%253A%252F%252Fwww.infosecurity-magazine.com%252Fopinions%252Fsecurity-take-its-head-out-of-the%252F%2523%257B%2522experiment%2522%253A%2522video_lift%2522%252C%2522position%2522%253A%2522top%2522%252C%2522variant%2522%253A%2522fallthrough%2522%257D&data=MzY3OTE4Y2RjODI3MDMxZDI1NzBmZTZmYWQzZWU4OTE1YzA5ZTdhNjQ3M2JiNDM3NWJkYWZiNjE4YTc2YjdlNjk5NjFlYWEyMGEyMzkwMjdhZmFkYzJlNWI0ZDdkODkzNWI3MDc2ZmZhMWU5MTA0Y2QyOWMwYzA0NmE1MmE4MDUyYWU2ZGFhMDM2NDRmZTVmNjQxNmE5MGVmMGExMDE5ZGRmM2U4NjliMDU2NzMxZjc2NzhkOTBjZTVkZGZmZTU3NDIxMTgxMGFjNDk2MjcwN2UxMDI5MTQ5ZmEyMzZhZThlYTJiY2ExNGFmMzJkZGJiMDlhNmZhMDJkMjBkZTk5MTdiZDE5NGMyNDNlYjc5ZDNjODVmM2FiN2Q1MTU3MGY1OGQ0NzlhMWYzZDIxNzI1MWU0ZTM1NGI5Njg0NzlmZmI%3D&sid=9087cd32695940cebd3720b54de33461_f7b0ce8c
https://bevo-us-east-1.adsnative.com/ck?url=https%3A%2F%2Fclicktabs.net%2Fpath%2Flp.php%3Ftrvid%3D10508%26trvx%3D1587426b%26var1%3D71usauto_7hLICib1_0Spi9xI0h4CaV95KHHEw5NARqgnGrCX%26var2%3D1808428%26var3%3Dwww.infosecurity-magazine.com_https%253A%252F%252Fwww.infosecurity-magazine.com%252Fopinions%252Fsecurity-take-its-head-out-of-the%252F%2523%257B%2522experiment%2522%253A%2522video_lift%2522%252C%2522position%2522%253A%2522bottom%2522%252C%2522variant%2522%253A%2522fallthrough%2522%257D&data=NzY3ODNkMDZhNDFhZjI4MWJiNjAyODlmNTYyNDQ2ZTE0NmU1NTEzMGYxY2I5NmQ4OWNmYWYwZmQ5NTgyMDJkZmY2MjBhOTMwMjNhMTdhYjc5ZGMwY2UzMGQ3Y2U0YmRlNDMzYzUyMzE4YzI2ZWY5NjJmNjBlZjUyNzZlZDA0NzE1MjI1OGJmYzljOGI0NzllYWQzNzljZmMxMDgzYzY5ODVlNGY4MDlmNmU2OTFiYTQ5MGE0M2ZhY2EyNjJkZDNlOWY1MTMwMWJkZjJjODg2YmYwNzI2Yjc4MWNmNDgwOWM0YjczZDBiMTdkNTE1ZDg5MmM3MzYwODEyZTA0MTUzZjEyNDcwODMxMDZmYTY0Zjg0Y2IxYzIzYzIyMjNiMmM0NTViYTQ0YzhmMWRiZGY5NzQzY2U5YmU5OWVlYjJlZmI%3D&sid=7b87a10eb29d4a6ba2dbc5dade784ace_2a91b63a