Showing posts with label ML. Show all posts
Showing posts with label ML. Show all posts

Friday, December 20, 2019

Emotet security attack causes shutdown of Frankfurt’s IT network

The city of Frankfurt, Germany, became the latest victim of Emotet after an infection forced it to close its IT network. But the financial center wasn’t the only area that was targeted by Emotet, as there were also incidents that occurred in Gießen and Bad Homburg, a town and a city north of Frankfurt, respectively, as well as in Freiburg, a city in southwest Germany.

The infection started after an employee of the Fechenheim (a district in Frankfurt) civil registry clicked on an Emotet-laden attachment from a malicious spam email, apparently sent by a city authority. Alarms were raised by the security system, prompting officials to restrict city services and take the IT system off the network as a precautionary measure.  


Germany has been a frequent target over the past few weeks by threat actors employing Emotet, and in general has been a target for malicious activity this year, according to data from the Trend Micro Smart Protection Network infrastructure. In fact, the German Federal Office for Information Security (BSI) issued a press release warning the public about malicious spam emails that carry Emotet.

First detected in 2014, Emotet has become one of the most notorious malware families of the past few years. Its original iteration was as an information-stealing banking malware — however, it has since undergone multiple evolutions, including acting as a loader for other malware families. It went into hiatus earlier in the year but came back after a few months with a vengeance. This recent spate of attacks on Germany is likely a continuation of Emotet’s comeback campaigns.

Despite all the changes Emotet has undergone, spam mail remains the malware’s most prominent distribution method. The key strategy organizations can implement is to educate their employees regarding email threats and to encourage them to follow the recommended security best practices when accessing their emails. This includes always double-checking an email for any red flags, as well as refraining from clicking any links or downloading any attachments haphazardly.

Combating threats like Emotet calls for a multilayered and proactive approach to security that involves protecting all fronts — gateway, endpoints, networks, and servers. Trend Micro endpoint solutions such as Trend Micro Smart Protection Suites and Worry-Free Business Security can protect users and businesses from these threats by detecting malicious files and spammed messages, as well as blocking all related malicious URLs.

To bolster their security capabilities and further protect their end users, organizations can consider security products such as the Trend Micro Cloud App Security solution, which uses machine learning (ML) to help detect and block spam and phishing attempts. 

If a malicious email is received by an employee, it will go through sender, content, and URL reputation analysis, which is followed by an inspection of the remaining URLs using computer vision and AI to check if website components are being spoofed. The solution can also detect suspicious content in the message body and attachments and provide sandbox malware analysis and document exploit detection.

Saturday, December 14, 2019

VirtualWisdom 6.3 enhances infrastructure capacity planning to deepen visibility, simplify capacity management, control costs

Virtana introduced latest version of VirtualWisdom, its hybrid IT infrastructure management and AIOps platform for mission-critical workloads. VirtualWisdom 6.3 is the initial product launch since Virtana’s rebrand in October, and continues the company’s push into capacity management with global storage array analytics, an expanded range of integrations, and new portable reports and dashboards.

Mission-critical hybrid applications combine resources in public clouds, with physical or virtual resources residing in private data centers. For these crucially important workloads, operating at web-scale, managing cost, performance, and capacity has never been more complex or important. 


To gain the insights and operational control that deliver efficient, cost-effective operation, organizations need real-time visibility, automated discovery, AI-powered analytics, and immediate access to best-practice solutions that proactively solve infrastructure-related performance and capacity issues for critical applications.

The VirtualWisdom release features the new Capacity Auditor, a global storage array analytic that offers a unique approach to global capacity management designed to provide app-centric insights and intelligence across hybrid infrastructure and multi-vendor data storage environments. With Capacity Auditor, organizations have a broad view of storage usage and trends across all storage arrays, applications, locations, physical storage assets, and effective capacity.

The VirtualWisdom 6.3 release includes support for Oracle’s Solaris, Red Hat KVM, and Pure Storage solutions that provide all the power of the VirtualWisdom platform to applications using infrastructure within these environments, and management of infrastructure elements that live within them. It also enhances VirtualWisdom’s continuous real-time infrastructure discovery with simple, intuitive dashboards and reports for servers, storage, and networks. Enabling immediate insights into critical relationships between infrastructure elements, visibility into vital statistics, and the capability to automatically apply customizable information sets for identification and cost.


The offering empowers users to share collective insights, dashboards and reports across the VirtualWisdom community. Customers and partners can easily exchange best-practice monitoring reports and visualizations unique to specific environments and applications. Its hybrid, real-time application views make it easy to visualize hybrid applications that cross multiple technology boundaries in one view – including applications that span multiple clouds (AWS, Azure), virtual environments (VMware, KVM, HyperV, PowerVM) as well as physical systems.

VirtualWisdom provides real-time, data-driven lifecycle recommendations to assure performance, speed problem resolution, automate workload optimization, free-up capacity, and ensure resource availability. AI-powered capacity forecasting helps organizations avoid capacity-driven problems before they can happen, and AI-powered workload optimization keeps applications operating within SLAs.

“To provide organizations with a competitive advantage, IT needs to use and manage their resources efficiently. IT professionals need tools to enable them to quickly resolve problems, even as the infrastructure becomes increasingly more complex. They also need to automate as many of the mundane IT tasks as possible,” said George Crump, President and Founder of Storage Switzerland. “Powered by AI/ML capabilities, VirtualWisdom offers recommendations and automated problem resolution, providing customers with deep infrastructure visibility.”

“The Virtana VirtualWisdom platform has been a fundamental enabler of our mission-critical manufacturing technology solutions and services for many years now,” said Todd Weeks, Plex Systems Global VP of Cloud Operations. “Our ability to offer our customers nearly 100% business continuity in a highly efficient cloud infrastructure relies on the real-time infrastructure visibility and AI-powered analytics that are unique to the VirtualWisdom platform.”

“Digital transformation is driving exponential data growth as today’s enterprises must have global visibility into all storage resources to continuously meet these ever-growing demands. Point solutions to managing data sets across multiple vendor storage environments result in highly fragmented, manual and wasteful practices and resources – and can put entire applications at risk,” said Tim Van Ash, SVP of Products at Virtana. “With application aware, predictive insight into the underlying digital infrastructure, VirtualWisdom offers the industry’s first and only global infrastructure capacity auditor and forecaster that can providing real-time visibility into mission-critical digital workload infrastructure.”

Friday, December 13, 2019

GigaSpaces Version 15.0 set to operationalize and optimize machine learning; gain actionable insights from data

GigaSpaces announced this week availability of GigaSpaces Version 15.0, including InsightEdge Platform and XAP, to operationalize and optimize machine learning with the required speed, scale, accuracy and management tools. GigaSpaces Version 15.0 powers machine learning operations (MLOps) initiatives, helping enterprises maximize the business value derived from big data. 


Deploying machine learning models in production remains a major challenge for many enterprises. The Gartner Accelerate Your Machine Learning and Artificial Intelligence Journey Using These DevOps Best Practices says that, “according to the 2019 Gartner CIO Survey, AI and ML continue to be viewed as the No. 1 game-changing technology by CIOs. However, most organizations underestimate how long it will take to move AI and ML projects into production.”

GigaSpaces delivers fast in-memory computing platforms for real-time insight to action and extreme transactional processing.  With GigaSpaces, enterprises can operationalize machine learning and transactional processing to gain real-time insights on their data and act upon them in the moment.  


The always-on platforms for mission-critical applications across cloud, on-premise or hybrid, are leveraged by organizations across various verticals, including financial services, retail, transportation, telecom and healthcare. GigaSpaces offices are located in the US, Europe and Asia.

GigaSpaces Version 15.0 simplifies integrating AI workloads with the organization’s core infrastructure, accelerating machine learning deployment and enabling enterprises to more readily experience the business benefits of machine learning models.

GigaSpaces Version 15.0 introduces a new enterprise-grade monitoring and administration tool, Ops Manager, that provides visibility into the components of systems running models including logs, inputs, outputs and exceptions, using different performance visualization techniques. 

The Ops Manager enables continuous monitoring of machine learning pipelines, starting at the cluster level and drilling through to individual services so users can maintain accurate data models and ensure that problems are resolved before they affect overall performance. 

The new AnalyticsXtreme Batch Indexing included in GigaSpaces InsightEdge Version 15.0 optimizes and automates data access and storage with the added ability to move data between the more frequent (cold data) access and infrequent (archive data) access tiers on data lakes and data warehouses.  


The performance of ML models is enhanced since frequently accessed cold data can be retrieved 80 times faster directly from data lakes and processing costs are reduced as data access patterns change. 

GigaSpaces Version 15.0 also provides a native smart space client in Kubernetes that supports remote CRUD operations, task execution, and event-driven analytics providing high throughput and fast serialization, as well as automatic load balancing. Writing and updating of data without a predefined schema allows easy changes to the data model, while ensuring compatibility with JDBC and BI tools so code can be integrated more reliably and faster with lower administrative overhead.

“Machine learning is becoming an essential component of mission critical applications to optimize operations and deliver superior real time customer experiences,” said Yoav Einav, VP product at GigaSpaces. “GigaSpaces Version 15.0 provides enterprises with the machine learning model management capabilities, speed and scale that they need to accelerate their machine learning and artificial intelligence journey.”

Trend Micro warns Android users on malicious Christmas-themed shopping, game and chat apps that lure users with deals

Security researchers from Trend Micro have cautioned Android users when downloading apps for shopping, games, and Santa video chats as they found hundreds of malicious apps likely leveraging the season to defraud unwitting victims. 

A scan of thousands of apps revealed seven with malicious routines such as replacing the legitimate apps with a version downloaded from a command and control (C&C) server. They also found 35 apps containing adware with more invasive behaviors than standard in-app advertisements, and 165 apps enabling “excessive or dangerous combinations of permissions,” such as camera, microphone, contacts and text messages. 


Researchers from Barracuda Networks recommend that users examine the apps they download to their phones, especially as online shopping and banking are expected to reach new heights this year.

Invasive adware were reportedly related to DIY gift projects and used suspicious ad networks by displaying catchy deals and coupons. Cybercriminals can go after banking, email, and access credentials by replacing legitimate website forms, or by using malware or injected skimmers

The researchers noted the excessive permissions that users may grant apps can be used to steal stored information from the devices such as contacts for phishing and spam campaigns, as well as banking authentication tokens via SMS messages when shoppers finalize their purchases online.

When downloading apps and shopping online, users must check app reviews on reputable websites; review access permissions being requested by the app and evaluate if they are necessary for the functions of the app; directly type the retailers’ websites, and avoid clicking on URLs found in emails and text messages, especially from unknown senders; limit the amount of personal information provided to websites and apps; and regularly update devices’ operating systems and apps.


Users and enterprises can take advantage of multilayered mobile security such as the Trend Micro Mobile Security for Android solution. Trend Micro Mobile Security for Enterprise provides device, compliance and application management, data protection, and configuration provisioning, as well as protects devices from attacks that exploit vulnerabilities, prevents malicious and unauthorized access to apps, and detects and blocks malware and fraudulent websites. 

Trend Micro’s Mobile App Reputation Service (MARS) covers Android threats using leading sandbox and machine learning technologies, protecting devices against malware, zero-day and known exploits, malicious apps, privacy leaks, and application vulnerabilities.

A10 Networks Orion 5G security lineup delivers business transformation for service providers

A10 Networks announced its Orion 5G Security Suite that enables mobile carriers and service providers to be ready for the business transformation 5G and NFV brings. The suite allows customers to meet the requirements needed today and helps them future proof their networks for tomorrow by delivering security, scalability, agility and analytics, while integrating with a partner ecosystem. A10 brings unique expertise from working with many of the production 5G networks that are now operational around the world.

A10 Networks has been at the forefront of initial 5G rollouts with tier-one carriers worldwide and is working with many others to plan for their future 5G initiatives. 

With the announcement of the 5G Orion Security Suite, service providers have a proven comprehensive suite of secure applications services that have been engineered for cloud-native architecture to aid in making their 5G and NFV strategies successful. 


The Orion 5G Security Suite enables advanced security and reliability functions as individual services by modularizing and offering them as a service layer with a set of connected technologies that employ automated intelligence, machine learning and centralized visibility and control.

Partnering with tier-one operators, A10 has honed its solutions to meet the critical 5G requirements for improved security, reliability and performance learned from 5G network rollouts over the last year. A10 provides an interconnected suite – virtual or physical – resulting in lower latency, larger scale, higher reliability and lower TCO—all of which have been required for the emerging 5G use cases customers are enabling.


In the last year to 18 months, first movers have deployed the first wave of 5G networks and demonstrated improved customer satisfaction and increased average revenue per user (ARPU), despite an increase in network demands, including higher data usage and download rates.

The Orion 5G Security Suite addresses existing and emerging mobile network architecture requirements for agility, consolidated services, greater scale, and lower latency communications across the Gi-LAN, virtualized evolved packet core (vEPC), and multi-access edge computing (MEC) environments. 

The Orion 5G Security Suite’s disaggregated, cloud-native security services provide agility while maintaining scale and performance by leveraging cutting-edge technologies. It also goes beyond just protecting the data plane through a GiFW by adding protection for the control plane and signaling plane with full visibility.

The Orion 5G Security Suite represents a major evolution of the company’s 5G strategy outlined in late 2018 by providing a comprehensive solution for mobile operators and other service providers to successfully deploy 5G non-standalone (NSA) and standalone (SA) solutions at hyperscale for 5G devices and new NFVi requirements.

A10 supports existing 4G and 3G network architectures and use cases for the Gi-LAN and EPC, while catering to demanding requirements for 5G architectures, including the cloud-native agility needed for MEC. These solutions can be deployed in infrastructure but are future proofed for 5G deployments. This includes functional consolidation for application visibility and control, subscriber-aware intelligent traffic steering, Gi/SGi firewall with carrier-grade NAT (CGNAT), GTP/SCTP firewall, integrated DDoS for frequently attacked services, intelligent traffic steering and more.

5G demands are inherently different than 4G, with smaller packet sizes, more throughput, and higher concurrent session counts. A10 solutions can scale concurrent sessions to multi-billion levels and throughput to multi-terabit levels in a scale-out cluster. 5G deployments can benefit from compact and efficient options, for example, 385 Gbps in compact physical network functions (PNFs), or high-performance 180 Gbps virtual network functions (VNFs) and cloud-native network functions (CNFs). 


Support for Kubernetes and Docker containers are available now. The compact PNF form factors and very high-performance software offerings (including containerized) are especially beneficial in emerging MEC use cases where space and power are at a premium.

With new user-plane and control-plane security requirements coupled with the increased attack surface and scale brought by 5G and IoT device proliferation, more advanced, scalable and automated approaches are needed. To guarantee uptime and ensure control- and user-plane security, components include edge firewall, GTP firewall, Gi/SGi firewall, control- and user-plane policy enforcement, DNS protection, RAN security gateways (SeGW), and more. 

Additionally, A10’s advanced DDoS protection solution includes artificial intelligence (AI) and machine learning (ML) capabilities with its Zero-day Attack Protection (ZAP), continuous base lining, and One-DDoS for distributed intelligence. This provides full visibility into all packets versus traditional sample-based-only solutions. Network-wide ML-powered DDoS detection and mitigation for in-house protection can also be offered as a customer scrubbing service.

A10’s solutions can be delivered in a variety of form factors to meet the demands of the emerging NFVi architecture including, VNFs, CNFs, bare metal and PNFs. These solutions are integrated with leading NFVi architectures and interoperate with multiple MANO environments for faster network roll-out and optimized performance and agility. A10 also provides flexible software licensing and consumption with FlexPool subscription-based capacity pooling licensing.

A10 Harmony Controller provides actionable intelligence to manage subscriber services, meet law enforcement agency mandates and compliance, and deliver per-subscriber analytics. Harmony Controller provides visibility, management, orchestration and automation. Coordination of distributed One-DDoS data from all the Orion 5G Security Suite solutions is seamlessly orchestrated from the integrated aGalaxy TPS system.

A10’s products integrate with multiple third-party solutions and vendors, ranging from DevOps tools, such as Ansible, to providers of 5G solutions such as Ericsson, Red Hat, NEC, Tech Mahindra and Lenovo.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...