Conference Presentation, Lecture
Giovanni Vigna
- Security focus is predicted to shift from attacking computer systems to targeting human users via social engineering and behavioral manipulation.
- The adversarial arms race is expected to be perpetual, with opponents capable of actively countering defensive measures.
- Signature-based antivirus is projected to detect approximately 50% of new samples upon appearance, with significant detection rates increasing after two weeks.
- Traditional sandboxing may fail to identify malware utilizing in-memory or stalling loops that avoid invoking privileged operations.
- Effective countermeasures must impose costs high enough to force attackers to restructure their code or modify monetization infrastructure.
- Future evolution of countermeasures will aim to limit adversary maneuvering space while utilizing evidence of evasion as a primary detection signal.
- Definitive algorithmic determination of program safety is deemed impossible due to the halting problem, necessitating continued reliance on heuristics.
- The company plans to prioritize innovation and automation to match the pace of very fast threat evolution.
- Competitive advantages in hacking challenges, including team resources and funding, are expected to fluctuate rather than remain static.