Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Tuesday, December 31, 2019

Kaspersky Web Traffic Security now available in two deployment options to meet customer demands

Kaspersky released next version of Kaspersky Web Traffic Security, which now offers enhanced protection capabilities though integration with Kaspersky Anti Targeted Attack to improve early detection of sophisticated web threats. The product is now available in two deployment options, as a standalone application and a software appliance, to meet broader customer needs.


According to Kaspersky researchers, 717 million web attacks were revealed in the second quarter of this year. The attacks contain various kinds of malware including generic adware to ransomware and advanced threats that reach corporate networks through phishing, social engineering or unreliable web resource surfing.

Web gateway protection allows companies to block massive amounts of web threats before they reach endpoints. This decreases the number of alerts on endpoints that interrupt users and administrators, as well as ensures protection of devices which don’t have endpoint security product installed or updated.


To make the deployment and use of the product effective for companies with different needs, Kaspersky now offers two options: as a software appliance or a standalone application.

The software appliance is a ready-to-use solution for companies that need to quickly deploy and start using secure web gateway with a proxy server pre-configured. The appliance interface allows users to manage the incorporated proxy server, avoiding configuration hassle.

The Kaspersky Web Traffic Security standalone application allows resource economy and a more agile configuration for companies that need a more customized solution and careful integration of different cybersecurity products. The application does not necessarily demand a separate server, as the system requirements necessary to protect a particular bandwidth are met. It can be installed alongside other applications but configured separately from other gateway components.


The protection capabilities of Kaspersky Web Traffic Security are now empowered by two-way API-based integration with Kaspersky Anti Targeted Attack, which allows customers of both solutions to achieve earlier attack detection and automated responses to advanced web threats. 

Suspicious files are automatically sent to Kaspersky Anti Targeted Attack for analysis. The system reveals the nature and malicious activity that the advanced threat generates, including files, transmission of commands, payloads and stolen data, and blocks them at the early attack stage.


“Different deployment scenarios allow companies to choose the best way to secure corporate web traffic, depending on available resources or IT network architecture,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “It also brings new usage scenarios to our partners. For example, the new format of the all-in-one appliance can be used by managed service providers to add web traffic security to their portfolio. Thanks to the application’s ease of deployment, scalability and multi-tenancy, they can provide web traffic security as a service for additional protection to ever growing number of customers, without the hassle.”

Kaspersky Web Traffic Security is available in both deployment options as part of Kaspersky Security for Internet Gateway and Kaspersky Total Security for Business.

Tuesday, December 24, 2019

Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

Saturday, December 21, 2019

Ericsson strengthens its agreement for 5G research and development with NIB

Ericsson is announcing that it has signed an agreement for credit facility with the Nordic Investment Bank (NIB) for USD 150 million, maturing in 2025. Of these new funds, 98 million will replace credit with NIB that was set to mature in 2021.

In addition to strengthening Ericsson’s balance sheet and financial flexibility, the loan has been granted for the purpose of financing Ericsson to support investments in research and development (R&D) in relation to the development of 5G technology during the years 2020-2022.



Key for success in the telecom industry is the delivery of future-proof, high-quality networks and solutions. To build on its technology leadership, Ericsson invested SEK 38 billion in R&D in 2018. This has enabled the company to be the leading contributor in the development of open telecom standards, with some 49,000 patents.


"Our increased investments to secure technology leadership in 5G, IoT and digital services have enabled us to reach nearly 80 commercial 5G agreements and contracts with unique operators, 24 of which are live networks - more than any other company,” said Erik Ekudden, Ericsson chief technology officer. “In the coming years, we will see 5G networks going live around the world, with major deployments from 2020 and we expect the global number of 5G subscriptions to top 2.6 billion in 2025. The technologies that we are investing in are fundamentally changing the way we innovate, collaborate, live and do business.”

Friday, December 20, 2019

Emotet security attack causes shutdown of Frankfurt’s IT network

The city of Frankfurt, Germany, became the latest victim of Emotet after an infection forced it to close its IT network. But the financial center wasn’t the only area that was targeted by Emotet, as there were also incidents that occurred in Gießen and Bad Homburg, a town and a city north of Frankfurt, respectively, as well as in Freiburg, a city in southwest Germany.

The infection started after an employee of the Fechenheim (a district in Frankfurt) civil registry clicked on an Emotet-laden attachment from a malicious spam email, apparently sent by a city authority. Alarms were raised by the security system, prompting officials to restrict city services and take the IT system off the network as a precautionary measure.  


Germany has been a frequent target over the past few weeks by threat actors employing Emotet, and in general has been a target for malicious activity this year, according to data from the Trend Micro Smart Protection Network infrastructure. In fact, the German Federal Office for Information Security (BSI) issued a press release warning the public about malicious spam emails that carry Emotet.

First detected in 2014, Emotet has become one of the most notorious malware families of the past few years. Its original iteration was as an information-stealing banking malware — however, it has since undergone multiple evolutions, including acting as a loader for other malware families. It went into hiatus earlier in the year but came back after a few months with a vengeance. This recent spate of attacks on Germany is likely a continuation of Emotet’s comeback campaigns.

Despite all the changes Emotet has undergone, spam mail remains the malware’s most prominent distribution method. The key strategy organizations can implement is to educate their employees regarding email threats and to encourage them to follow the recommended security best practices when accessing their emails. This includes always double-checking an email for any red flags, as well as refraining from clicking any links or downloading any attachments haphazardly.

Combating threats like Emotet calls for a multilayered and proactive approach to security that involves protecting all fronts — gateway, endpoints, networks, and servers. Trend Micro endpoint solutions such as Trend Micro Smart Protection Suites and Worry-Free Business Security can protect users and businesses from these threats by detecting malicious files and spammed messages, as well as blocking all related malicious URLs.

To bolster their security capabilities and further protect their end users, organizations can consider security products such as the Trend Micro Cloud App Security solution, which uses machine learning (ML) to help detect and block spam and phishing attempts. 

If a malicious email is received by an employee, it will go through sender, content, and URL reputation analysis, which is followed by an inspection of the remaining URLs using computer vision and AI to check if website components are being spoofed. The solution can also detect suspicious content in the message body and attachments and provide sandbox malware analysis and document exploit detection.

Thursday, December 19, 2019

Ericsson and Telstra achieve container-based commercial Evolved Packet Core milestone

Ericsson and Australian communications service provider Telstra have deployed the industry’s first live cloud-native container-based Evolved Packet Core for 4G and 5G services. The achievement is a significant milestone in network orchestration and automation.
The cloud-native container-based Evolved Packet Core has been deployed in Telstra’s production Network Functions Virtualization Infrastructure (NFVi), provided by Ericsson. It is fully integrated into Telstra’s mobile core network and is carrying live 4G and 5G Non-Standalone (NSA) traffic.

Telstra’s cloud-native Evolved Packet Core includes Ericsson Packet Core Controller and Ericsson Packet Core Gateway products. They support 4G and 5G Non-standalone (NSA) control and user plane functions in both a centralized configuration and edge-breakout configurations.
As part of this deployment, Ericsson’s Packet Core Controller is deployed as a cloud-native container-based Mobility Management Entity (MME) in an existing MME pool.
Both the Ericsson Packet Core Controller and Packet Core gateway are designed from the ground up to be fully cloud-native container-based solutions. They run on Ericsson’s Cloud Container Distribution (CCD) that is part of Ericsson’s NFVI solution or on other Cloud Native Computing Foundation (CNCF) aligned distributions.
Ericsson CCD provides container management and orchestration for the latest Ericsson cloud native applications. CCD can be run on bare metal or within a Virtual Machine in an OpenStack deployment.
Ericsson and Telstra have a long history of partnering in industry innovation. In May 2019 Telstra launched 5G commercial services using Ericsson solutions.  
This achievement is a key step in Telstra’s goal to build a web-scale core network and deliver the full power of 5G to consumers and enterprise customers. The containerization of core network functions will move communication service providers such as Telstra towards greater orchestration and automation of their networks. This in turn will help them to create and deliver new services such as enhanced mobile broadband, network slicing, mobile edge computing, mission critical vertical industry support and advanced enterprise services.
Containerized technologies are also designed to improve network resilience and software upgrade techniques to increase overall network availability for Telstra’s customers and services.
“Telstra and Ericsson are leading the mobile industry with this first container-based cloud-native Evolved Packet Core in Telstra’s production environment and carrying live traffic. This is an important step towards fundamentally changing the way both companies deploy and operate mobile core networks,” said Emilio Romeo, head of Ericsson Australia and New Zealand. “Core networks will become much more flexible and agile, allowing operators such as Telstra to quickly create and deploy compelling new services for their customers. This in turn helps operators build new revenues.”
“Through the T22 initiative, Telstra’s business is being transformed to improve service delivery and provide customers with enhanced experiences. To achieve this transformation, Telstra’s network needs to become more flexible and efficient, and cloud-native container-based applications such as Ericsson’s containerized Evolved Packet Core are a key element of this,” said Shailin Sehgal, product enablement technology executive, Telstra. “This is key to cost effectively scaling and automating our network and speeding up the delivery of innovative new services that are essential in a 5G world. We are pleased to be working with Ericsson to deliver innovation into our network that will assist Telstra maintain its industry leadership.”

Agero supports nearly half of passenger vehicles on the road with Oracle SD-WAN


Agero is using Oracle enterprise communications technologies to safeguard drivers in more than 115 million vehicles in the U.S. When a driver is stranded roadside, time is of the essence. With Oracle, the company has achieved continuous contact center uptime, so customers can get the assistance they need and are back on the road as quickly as possible.

For 45 years, Agero has provided smart solutions for its clients and their drivers. Currently, Agero’s  roadside assistance, accident management and consumer affairs services are leveraged in the U.S. by drivers in two-thirds of new passenger vehicles, policyholders from nine of the top 15 auto insurance carriers and customers of a variety of other diversified clients. 


Oracle SD-WAN was created to solve the ongoing IT challenges network managers face every day—from expensive, sluggish, inflexible WANs to difficulties deploying new office WAN links and accessing cloud services. 

With Oracle SD-WAN, enterprises can benefit from internet economics, leverage high-bandwidth and inexpensive Internet connections, and safely migrate applications to the public cloud and SaaS at their own pace – without sacrificing the high availability and predictable application performance they expect from their MPLS-only WANs..

To maximize the quality of its customers’ experiences and to eliminate communication failures or downtime, Agero needed predictable enterprise communications performance and real-time application support. Agero selected Oracle for the failsafe reliability, security and interoperability.

“When drivers are stranded on the road in the winter, creating not only an uncomfortable situation but also a health and safety issue, it is crucial for our customers to get directly in contact with an agent,” said Robert Sullivan, vice president, technology and shared services, Agero. “Oracle has the best of breed technology in the Oracle SD-WAN and Enterprise Session Border Controllers, which have helped us to deliver high availability, reliability and quality of experience for our customers.”

Since working with Oracle and Presidio to implement the Oracle SD-WAN solution, Agero has reduced downtime and created special routing situations for sites without substantial circuit diversity. This advanced, “always-on performance” is invaluable to Agero as the company processes more than 12 million roadside and emergency support requests per year.

“Agero is reinventing how driver assistance is delivered, while elevating the consumer experience in often dire scenarios,” said Andrew Morawski, senior vice president and general manager, Oracle Communications - Networks. “As enterprises demand flexible WAN solutions supporting shifting business requirements, Oracle is increasing and leveraging bandwidth for affordable and trusted WAN connectivity, anywhere and whenever it’s needed.”

In addition to the Oracle SD-WAN, Agero deployed Oracle 1100 Enterprise Session Border Controller (E-SBC) Oracle 3900 E-SBC and the Oracle Communications Converged Application Server (OCCAS) to protect its network and contact center from external threats.

Tuesday, December 17, 2019

Ericsson and MediaTek embark upon 5G voice landmark, using a 3.5 GHz TDD band

Conducted at the Ericsson Lab in Kista in early December, the interoperability test involved the use of an end-to-end solution from Ericsson and Dimensity 1000 commercial chipset from MediaTek deployed on a 3.5GHz TDD band. 


The first commercial 5G smartphones on the market use dual-mode connectivity to make voice calls over 4G but uses 5G for data boost. The next step in the network evolution is to tap 5G to accommodate data traffic while using 4G for voice calls with EPS Fallback. The final step, however, will involve avoiding dependence on 4G altogether, with the exclusive use of 5G (NR standalone) for both voice and data services.



Ericsson enables every step of this network evolution through its 5G portfolio, which includes 5G radio access, IMS, and 5G Core with the dual-mode 5G cloud core capability.


With Standalone New Radio (SA NR), a 5G-enabled device does not need to rely on 4G technology to make 5G voice (VoNR) calls. SA NR networks will enable a range of new services and simplify network architecture.



With the arrival of standalone NR access, voice and other communication services will need to be provided, requiring the 5G network to support native voice calling services for 5G smartphones. Using VoNR on SA architecture, service providers will be able to offer voice services on 5G-voice-capable devices as well as enhanced mobile broadband (eMBB) services to consumers and business users.


Commercial 5G networks are going live around the world - and Ericsson technology is leading the way. First movers can reshape the market and increase market share and revenue streams. Combining improved capacity with increased cost-efficiency 5G represents an opportunity for telecom operators to improve their consumer business. 5G also allows operators to explore new use cases and business models and capture new revenue streams through addressing industry digitalization. 



“Although 5G is closely associated with superior data-transfer capabilities, voice services remain essential for mobile users. So 5G phones are expected to provide all the capabilities of 4G phones in addition to new 5G features and services,” said Hannes Ekström, head of product line 5G RAN, Ericsson. “Ensuring continued voice services on 5G devices must therefore be addressed properly.


“With multivendor interoperability, we can help our customers provide voice support for 5G SA. This shows our readiness with a complete 5G network solution tested with 5G chipsets, paving the way for native voice services on commercial 5G devices.”



Ericsson has collaborated with MediaTek on performing interoperability tests spanning SA NR, 5G Core and IP Multimedia Subsystem (IMS) to ensure that voice support is enabled as service providers evolve their 4G networks to 5G. The two partners have also successfully tested Evolved Packet System (EPS) Fallback for situations where SA is not available.


“As a 5G leader, MediaTek is committed to bringing unrivaled 5G experiences to consumers around the world,” said JS Pan, General Manager of Wireless System Design and Partnership, MediaTek. “This technology milestone will let device makers support native voice calling services on 5G networks, providing users with a seamless connectivity experience as SA 5G networks are rolled out in the coming year.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...