Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Saturday, December 21, 2019

Microsoft finds that mobile threat defense and intelligence are now critical part of cyber defense

When handled and analyzed properly, actionable data holds the key to enabling solid, 360-degree cybersecurity strategies and responses. However, many corporations lack effective tools to collect, analyze, and act on the massive volume of security events that arise daily across their mobile fleet. An international bank recently faced this challenge. 

By deploying Pradeo Security alongside Microsoft Endpoint Manager and Microsoft Defender Advanced Threat Protection (ATP), the bank was able to harness its mobile data and better protect the company.


Organizations rely on mobility to increase productivity and improve the customer experience. But the proliferation of smartphones and other mobile devices has also expanded the attack surface of roughly 5 billion mobile devices in the world, many used to handle sensitive corporate data. To safeguard company assets, organizations need to augment their global cyber defense strategy with mobile threat intelligence.

In 2017, the Chief Information Security Office (CISO) of an international bank recognized that the company needed to address the risk of data exposure on mobile. Cybercriminals exploit smart phones at the application, network, and OS levels, and infiltrate them through mobile applications 78 percent of the time. 


The General Data Protection Regulation (GDPR) was also scheduled to go into effect the following year. The company needed to better secure its mobile data to safeguard the company and comply with the new privacy regulations.

The company deployed Microsoft Endpoint Manager to gain visibility into the mobile devices accessing corporate resources. Microsoft Endpoint Manager is the recently announced convergence of Microsoft Intune and Configuration Manager functionality and data, plus new intelligent actions, offering seamless, unified endpoint management. Then, to ensure the protection of these corporate resources, the company deployed Pradeo Security Mobile Threat Defense, which is integrated with Microsoft.

Pradeo Security and Microsoft Endpoint Manager work together to apply conditional access policies to each mobile session. Conditional access policies allow the security team to automate access based on the circumstances. For example, if a user tries to gain access using a device that is not managed by Microsoft Endpoint Manager, the user may be forced to enroll the device. 

Pradeo Security enhances Microsoft Endpoint Manager’s capabilities by providing a clear security status of any mobile devices accessing corporate data, which Microsoft can evaluate for risk. If a smartphone is identified as non-compliant based on the data that Pradeo provides, conditional access policies can be applied.


For example, if the risk is high, the bank could set policies that block access. The highly granular and customizable security policies offered by Pradeo Security gave the CISO more confidence that the mobile fleet was better protected against threats specifically targeting his industry.

The bank also connected Pradeo Security to Microsoft Defender ATP in order to automatically feed it with always current mobile security inputs. Microsoft Defender ATP helps enterprises prevent, detect, investigate, and respond to advanced cyberthreats. Pradeo Security enriches Microsoft Defender ATP with mobile security intelligence. 

Immediately, the bank was able to see information on the latest threats targeting their mobile fleet. Only a few weeks later, there was enough data in the Microsoft platform to draw trends and get a clear understanding of the company’s mobile threat environment.

Pradeo relies on a network of millions of devices (iOS and Android) across the globe to collect security events related to the most current mobile threats. Pradeo leverages machine learning mechanisms to distill and classify billions of raw and anonymous security facts into actionable mobile threat intelligence.

The bank’s mobile ecosystem entirely relies on Pradeo and Microsoft, as its security team finds it to be the most cost-effective combination when it comes to mobile device management, protection and intelligence.

Friday, December 20, 2019

Baidu and Samsung release AI chip, designed based on Samsung’s 14nm process and I-Cube package technology

Chinese-language Internet search provider Baidu and Samsung Electronics announced that Baidu’s first cloud-to-edge AI accelerator, Baidu KUNLUN, has completed its development and will be mass-produced early next year.

Baidu KUNLUN chip is built on the company’s advanced XPU, a home-grown neural processor architecture for cloud, edge, and AI, as well as Samsung’s 14-nanometer (nm) process technology with its I-Cube (Interposer-Cube) package solution.


The chip offers 512 gigabytes per second (GBps) memory bandwidth and supplies up to 260 Tera operations per second (TOPS) at 150 watts. In addition, the new chip allows Ernie, a pre-training model for natural language processing, to infer three times faster than the conventional GPU/FPGA-accelerating model.

Leveraging the chip’s limit-pushing computing power and power efficiency, Baidu can support a variety of functions including large-scale AI workloads, such as search ranking, speech recognition, image processing, natural language processing, autonomous driving, and deep learning platforms like PaddlePaddle.


Through the first foundry cooperation between the two companies, Baidu will provide advanced AI platforms for maximizing AI performance, and Samsung will expand its foundry business into high performance computing (HPC) chips that are designed for cloud and edge computing.

As higher performance is required in diverse applications such as AI and HPC, chip integration technology is becoming more and more important. Samsung’s I-Cube technology, which connects a logic chip and high bandwidth memory (HBM) 2 with an interposer, provides higher density/ bandwidth on minimum size by utilizing Samsung’s differentiated solutions.

Compared to previous technology, these solutions maximize product performance with more than 50 percent improved power/signal integrity. It is anticipated that I-Cube technology will mark a new epoch in the heterogeneous computing market. Samsung is also developing more advanced packaging technologies, such as redistribution layers (RDL) interposer and 4x, 8x HBM integrated package.


“We are excited to lead the HPC industry together with Samsung Foundry,” said OuYang Jian, distinguished architect of Baidu. “Baidu KUNLUN is a very challenging project since it requires not only a high level of reliability and performance at the same time, but is also a compilation of the most advanced technologies in the semiconductor industry. Thanks to Samsung’s state of the art process technologies and competent foundry services, we were able to meet and surpass our goal to offer superior AI user experience. ”

“We are excited to start a new foundry service for Baidu using our 14nm process technology,” said Ryan Lee, vice president of Foundry Marketing at Samsung Electronics. “Baidu KUNLUN is an important milestone for Samsung Foundry as we’re expanding our business area beyond mobile to datacenter applications by developing and mass-producing AI chips. Samsung will provide comprehensive foundry solutions from design support to cutting-edge manufacturing technologies, such as 5LPE, 4LPE, as well as 2.5D packaging.”

Microsoft and Oracle expand interoperability partnership to Canada to help joint customers run their mission-critical workloads

Oracle announced this week continued expansion of its cloud interoperability partnership with Microsoft to help joint customers worldwide run their mission-critical workloads across Oracle Cloud and Microsoft Azure. Its new interconnect location means enterprises can now build workloads that seamlessly interoperate between Microsoft and Oracle cloud regions in Canada. This interconnect builds on an existing partnership announced in June of 2019.

The partnership has received a huge amount of interest, as 80 percent of enterprises use a combination of Microsoft and Oracle software to run their businesses. 


As cloud computing becomes ubiquitous, and businesses rely on multiple cloud providers, the partnership makes managing companies’ most important cloud workloads significantly easier. These workloads include financial planning, inventory, sales applications – and their underlying databases.

The expansion will give more customers direct, fast and highly reliable network connectivity between Microsoft Azure and Oracle Cloud, while providing first-class customer service and support that enterprises have come to expect from the two companies. This multi-cloud solution delivers the performance, easy integration, rigorous service level agreements, and collaborative enterprise support that they need to simplify their operations. 


Simply put, the Oracle-Microsoft partnership means cloud services run by the two providers will interoperate as if they were part of a single cloud, making it easier for customers to run their mission-critical workloads across the two clouds.

“The global demand for running applications and databases in multi-cloud environments continues to accelerate,” said Clay Magouyrk, senior vice president of engineering, Oracle Cloud Infrastructure.  “With the new interconnect, our Canadian customers can now take advantage of a nearly seamless cloud integration between the world's largest enterprise cloud providers, Microsoft and Oracle.”


The two companies are putting customers first by enabling them to run full-stack applications side-by-side across clouds, or one part of a workload within Azure and another part of the same workload within Oracle Cloud. 

For example, using the interconnect makes it possible to connect Azure services like analytics and AI to Oracle Cloud services like Autonomous Database. Together, Azure and Oracle Cloud offer customers a one-stop shop for all the cloud services and applications they need to run their entire business.

From a technical perspective, the interconnect means less latency or delay, which enables better data transfer and application interaction between clouds. It also supports a broader spectrum of workloads, using resources available on both sides. Accenture recently performed testing on the performance of the interconnect and confirmed that the solution offers customers low latency and high ease of use.

Microsoft and Oracle plan to make the direct interconnect available in additional regions, including on the US West Coast, in a US Government specific region, in Asia, and in the European Union. Earlier this year, Oracle and Microsoft created an interconnect in Ashburn (North America), Azure US East, and in London (United Kingdom).

Tuesday, December 10, 2019

NTT forms alliance with Microsoft to enable new digital solutions that help enterprise customers accelerate their digital transformations

NTT and Microsoft announced on Tuesday a multi-year strategic alliance aimed at delivering secure and reliable solutions that help enterprise customers accelerate their digital transformations. The alliance will bring together NTT’s ICT infrastructure, managed services and cybersecurity expertise, with Microsoft’s trusted cloud platform and AI technologies. 


Key initiatives of the alliance include the creation of a Global Digital Fabric, development of digital enterprise solutions built on Microsoft Azure, and co-innovation of next-generation technologies in the area of all-photonics network and digital twin computing.



As one of the world’s largest global technology and business solution organizations, NTT provides integrated services that include digital business consulting and managed services for cybersecurity, applications, cloud, data centers and global networks in over 190 countries and regions. 


As part of the alliance, NTT has chosen Microsoft Azure as its preferred cloud platform for modernizing its global IT infrastructure and customer solutions in the areas of advanced analytics for cybersecurity threat intelligence and the hybrid-IT management platform.



The alliance has announced formation of a Global Digital Fabric that weaves Microsoft Cloud and NTT’s globally connected ICT infrastructure, by combining the strengths of the two companies in the areas of productivity solutions, public cloud, global datacenter and network infrastructure. The Global Digital Fabric aims to create a highly sustainable, secure and robust environment for enterprises to accelerate their digital ambitions around the world.


The alliance also covers the development of digital solutions built on Microsoft Azure to empower enterprises to accelerate their digital transformation and to operate more securely from the enterprise to the edge to the cloud. Key initiatives include advanced analytics for cybersecurity threat intelligence, social robotics with relational AI for digital companions, digital workplace solutions, as well as knowledge discovery and management.


The alliance will also explore research and development of all-photonics network and digital twin computing as part of NTT’s Innovative Optical and Wireless Network (IOWN) concept. The goal is to provide a more natural interaction between people, nature and technology, and to support sustainable growth with an optical-based networking and information processing platform of the future.




Furthermore, NTT and Microsoft are committed to harnessing the power of technology for a more sustainable future. The companies intend to work together to invest in innovative projects that leverage technology to build on NTT’s sustainability initiatives and Microsoft’s AI for Earth grants.


“NTT is committed to helping enterprises realize their digital transformation initiatives to help create a smarter world. We believe that the combination of the Microsoft Azure platform along with NTT’s connected infrastructure and service delivery capabilities will accelerate these efforts,” said Jun Sawada, president and CEO of NTT. “Additionally, the companies will collaborate on IOWN, including areas such as all-photonics network and digital twin computing.”


“Our strategic alliance combines NTT’s global infrastructure and services expertise with the power of Azure,” said Satya Nadella, CEO, Microsoft. “Together, we will build new solutions spanning AI, cybersecurity and hybrid cloud, as we work to help enterprise customers everywhere accelerate their digital transformation.”

Sunday, December 8, 2019

Microsoft validates Lenovo ThinkSystem SE350 edge server for Azure Stack HCI

Microsoft and Lenovo have teamed up to validate the Lenovo ThinkSystem SE350 for Microsoft's Azure Stack HCI program. The ThinkSystem SE350 was designed and built with the unique requirements of edge servers in mind. It is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and can be easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 solution has a focus on smart connectivity, business security, and manageability for the harsh environment.


The ThinkSystem SE350 is the latest workhorse for the edge. Designed and built with the unique requirements for edge servers in mind, it is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and is easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 is a rugged compact-sized edge solution with a focus on smart connectivity, business security, and manageability for the harsh environment.

The ThinkSystem SE350 is an Intel Xeon D processor-based server, with a 1U height, half-width and short depth case that can go anywhere. Mount it on a wall, stack it on a shelf, or install it in a rack. This rugged edge server can handle anything from 0-55°C as well as full performance in high dust and vibration environments.

Information availability is another challenging issue for users at the edge, who require insight into their operations at all times to ensure they are making the right decisions. The ThinkSystem SE350 is designed to provide several connectivity options with wired and secure wireless Wi-Fi and LTE connection ability. This purpose-built compact server is reliable for a wide variety of edge and IoT workloads.

Azure Stack HCI solutions bring together highly virtualized compute, storage, and networking on industry-standard x86 servers and components. Combining resources in the same cluster makes it easier to deploy, manage, and scale, while managing command-line automation or Windows Admin Center.

Consumers can achieve virtual machine (VM) performance for server applications with Hyper-V, the foundational hypervisor technology of the Microsoft cloud, and Storage Spaces Direct technology with built-in support for non-volatile memory express (NVMe), persistent memory, and remote direct memory access (RDMA) networking.

Monday, December 2, 2019

Trend Micro reports on Microsoft discovering polymorphic malware ‘Dexphot’ that affected 80,000 Windows systems

For over a year, Microsoft has been monitoring a malware strain they named “Dexphot” that has been infecting Windows devices since October last year, Trend Micro revealed in a recent post. The malware used computer resources to mine cryptocurrency and profit from the attack. It reached its peak in June 2019, infecting almost 80,000 computers before gradually decreasing over the next months because of Microsoft’s intervention.

Despite the typical malware payload, Microsoft claimed that monitoring the Dexphot gave them insight into not only on how the malware worked but also the techniques that cybercriminals currently use.


This was largely because of the way Dexphot behaved over the course of last year, as noted by Microsoft. The simple payload was delivered through complex techniques that were constantly updated by the malicious actors behind the malware strain.

Microsoft found that the Dexphot malware strain was dropped by another malware known as ICLoader, which is unknowingly installed on a user’s system as part of software bundles. Dexphot was found downloaded and installed in Windows systems that were infected by ICLoader.


While Microsoft Defender Advanced Threat Protection’s pre-execution detection engines blocked Dexphot in most cases, behavior-based machine learning models provided protection for cases where the threat slipped through. Given the threat’s persistence mechanisms, polymorphism, and use of fileless techniques, behavior-based detection was a critical component of the comprehensive protection against this malware and other threats that exhibit similar malicious behaviors.

Microsoft Defender ATP data shows the effectiveness of behavioral blocking and containment capabilities in stopping the Dexphot campaign. Over time, Dexphot-related malicious behavior reports dropped to a low hum, as the threat lost steam.

Dexphot used legitimate system processes for its malicious activities. It used legitimate Windows apps such as msiexec.exe, unzip.exe, rundll32.exe, schtasks.exe, and powershell.exe to decrypt its data files. Using such tools allows Dexphot to evade detection, as the system would consider its activities as normal processes.

In addition, the decrypted files contained three executable files which are never written on filesystem. They remain on memory. This means Dexphot also used fileless techniques.

Dexphot instead laces the first two executable files into other legitimate system processes like svchost.exe or nslookup.exe. These are monitoring services that maintain Dexphot components. Finally, it replaces setup.exe contents with its third executable, a cryptocurrency miner.

Microsoft saw that Dexphot switched miners throughout their monitoring, using both programs like XMRig and JCE.

Microsoft noted that Dexphot was a malware strain that was not likely to garner much attention for its common payload. However, it does paint a good picture of the techniques that had been pervasive throughout this year, namely living off the land and fileless techniques.

Trend Micro’s most recent security roundup reported that threat actors have been increasingly living off the land. In fact, detections for fileless threats was 18 percent higher during the first half of 2019 compared to the total count for 2018.


Remaining vigilant and wary of similar cases as Dexphot can help in defending against fileless threats moving forward. Organizations would need to consider solutions like behavioral indicators and traffic monitoring to defend against the unique challenges that fileless threats present.

Trend Micro's Smart Protection Suites deliver several capabilities like high-fidelity machine learning and web reputation services that minimize the impact of persistent, fileless threats. 

Trend Micro Apex One protection employs a variety of threat detection capabilities, notably behavioral analysis that protects against malicious scripts, injection, ransomware, memory and browser attacks related to fileless threats. Additionally, the Apex One Endpoint Sensor provides context-aware endpoint investigation and response (EDR) that monitors events and quickly examines what processes or events are triggering malicious activity. 

The Trend Micro Deep Discovery solution has a layer for email inspection that can protect enterprises by detecting malicious attachments and URLs. Deep Discovery can detect remote scripts even if it is not being downloaded in the physical endpoint.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...