BLOG

The end of the cat-and-mouse game in cybersecurity?

Since the invention of the internet, cybercriminals and cyberdefense teams have been locked in a never-ending game of cat and mouse. Sophisticated attacks are on the rise, hacking techniques are constantly evolving, and companies face ever-changing challenges to protect their data and infrastructure. However, there is a glimmer of hope on the horizon. With the emergence of new technologies and new approaches to security, we are moving toward an era where this dangerous game may finally come to an end.

A preventive approach in addition to a curative installation

The traditional reactive approach to cybersecurity is no longer sufficient. Waiting for an attack to identify and block malware and then trying to repair the damage is no longer a sustainable solution. Instead, companies must implement a proactive approach focused on prevention.
For example, more than 13 million malicious domains (containing malware or other harmful content) are created every month. With such a volume of new content, often short-lived or created shortly before attacks, traditional tools that maintain a database of threats are quickly overwhelmed and become outdated.
Dealing with this large amount of malicious content requires investing in new security technologies and solutions that can detect and mitigate threats before they hit your systems.
Web security gateways (SWGs) are on the front line of these attacks and, when configured with a whitelist, are highly effective against this threat. They restrict access to domains whose content and legitimacy have been duly verified beforehand. With this approach, any domain that is not recognized and does not appear on the whitelist is considered risky and is blocked. This is an excellent way to deal with the large number of ephemeral phishing domains.

In addition, it is essential to adopt a multi-layered defense system that combines technology, education, and policy. Relying on a single tool that oversees multiple aspects of defense—for example, a firewall, IPS, and filtering on the same machine—leaves vulnerable gaps that cybercriminals can easily exploit. By separating various specialized elements, such as firewalls, intrusion detection systems, xDRs, encryption, and employee training, companies can create a robust security infrastructure that significantly minimizes the risk of successful cyberattacks.

Harnessing the power of artificial intelligence and machine learning

With the advent of ChatGPT, artificial intelligence (AI) and machine learning (ML) have become more accessible and powerful tools for combating cyber threats. These cutting-edge technologies enable companies to find intelligent solutions that continuously learn and adapt to new attack patterns.
AI and ML can help in a variety of ways, such as detecting anomalies and suspicious behavior to predict and prevent future threats. By analyzing vast amounts of data in real time, these technologies can identify potential risks and take immediate action before any damage occurs. Most modern tools, including EDR/XDR, already leverage AI-based approaches to prevent attacks more effectively.

Cybersecurity is a team sport

Cybersecurity is a team sport, and companies can no longer fight this battle alone. Sharing intelligence, best practices, and knowledge about the latest threats can help all parties stay one step ahead of criminals. Modern CTIs allow CERT information, YARA or SIGMA rules to be pooled to identify traces or behaviors corresponding to known cybercrime activities.
Long confined to isolated pockets where each company operated with closed information, the environment is changing with sharing initiatives such as the ANSSI's OpenCTI project or the MISP Project.

Building a culture of cybersecurity

When it comes to cybersecurity, every employee in your organization plays a crucial role. They are the first line of defense against cyberattacks. Educating and empowering your staff to recognize and report suspicious activity is paramount to maintaining a secure environment.
Ongoing training programs and awareness campaigns are essential elements of building a culture of cybersecurity. By ensuring that all employees understand the risks and know how to respond appropriately, companies can create a united front against cyber threats.
Company employees are often the most vulnerable entry points for cybercriminals. By educating them on best practices for online security, raising their awareness of the risks, and increasing their vigilance, we can significantly reduce the opportunities for successful attacks.
IT hygiene awareness services have become more widespread in recent years. Examples include the ANSSI MOOC and other tools such as Olfeo Awareness.

The cat-and-mouse game between cybercriminals and businesses is far from over. However, with a proactive and holistic approach to cybersecurity, combined with the power of artificial intelligence and strong collaborations, businesses are seeing considerable progress.

For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.

The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.

For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.

The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.

Web filtering remains one of the pillars of a cybersecurity strategy, and UTM cannot do everything (well).

Today, we can no longer be complacent about cybersecurity. Attacks are inevitable, and malware can disrupt business operations, as was the case this year for the Fleury Michon agri-food group, which was hit hard enough to have to disconnect all of its systems to prevent the threat from spreading. Web filtering and SSL-TLS decryption of HTTPS traffic, which help to better detect malicious code, are therefore essential for an effective cybersecurity strategy.

Furthermore, we must not forget the legal and liability issues associated with internet use, which are part of the challenges of web filtering. UTMs based on international categories do not offer the same level of quality as our URL database, which has been built up by a French team over the past 16 years. The result is often that the lack of precision in the categories and URLs leads to certain sites being blocked unfairly because they have been incorrectly classified by robots. With Olfeo, the Pornic town hall website or the Paris-Expo website will not be classified as pornography, and a doctor researching the male reproductive system will not be blocked. On the contrary, there are many different categories in Olfeo, and the granularity of the URLs is highly appreciated by our customers for customizing their user rules.

THE BLOG
Discover our latest articles