Showing posts with label endpoint protection. Show all posts
Showing posts with label endpoint protection. Show all posts

Thursday, November 28, 2019

Kaspersky data finds suspicious objects are malicious in close to three-quarters of investigated cases

Following Kaspersky’s analysis of anonymized and aggregated statistics of requests to the Kaspersky Threat Intelligence Portal, research showed that when security researchers requested additional details of a suspicious object, 72 percent of cases turned out to be malicious and could put corporate security at risk.

On average, 44 percent of security alerts are not investigated, likely due to the vast volume of incoming warning signals that security teams are challenged with. As a result, analysts must carefully choose which alerts need investigating versus those that do not justify further attention.


Of the 72 percent of cases that are found to be malicious after undergoing additional research, the share of such objects is especially high for web-related items including domains (86 percent), IP addresses (75 percent) and URLs (73 percent). This figure slightly drops for files, as 61 percent of hashes were categorized as dangerous. These statistics imply that it is more difficult for researchers to distinguish legitimate files from malicious ones without consulting with the appropriate threat intelligence.

The Kaspersky Threat Intelligence Portal is a web service which provides customers with knowledge about cyber threats gathered by Kaspersky. The company provides free access to basic information about suspicions files, hashes, IP addresses and others.

Global cybersecurity company Kaspersky offers deep threat intelligence and security expertise is constantly transforming into security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. 

Overall, researchers are most interested to learn about which resources the endpoints in their network are communicating with, as shown by 41 percent of total requests falling under this category. With information on IP address reputation and associated web sites and files, security teams can make a decision if they should deny access to this resource or block any communication with it. 

In addition, a third (31 percent) of requests were about a file hash category, meaning analysts are looking for additional information about the file (i.e. geographical distribution, popularity and connections with other objects) during their investigations.

“As our statistics show, security analysts in organizations rarely make mistakes when they suspect that an alert poses a security risk and might need further investigation,” said Anatoly Simonenko, group manager for technology solutions product management at Kaspersky. “However, it’s not all about checking the hypotheses. To be able to accelerate their incident response and forensic capabilities, analysts need to see the bigger picture on a threat, quickly. Access to threat intelligence provides just that, ultimately saving time and effort for typically understaffed security teams.”

Thursday, November 21, 2019

Kaspersky Sandbox automates protection from advanced threats, combats advanced threats

Kaspersky launched its new Kaspersky Sandbox designed to help organizations combat advanced threats intended to evade detection by endpoint protection platforms (EPP). 

The Kaspersky Sandbox solution is ideal for companies with no dedicated security team, where the IT security role is assigned to the IT department; small businesses that don’t want to incur additional IT security resources; large organizations with a geographically distributed infrastructure and without on-site IT security specialists; and companies who need to ensure that their full-time IT security analysts are fully focused on critical tasks.


The solution automatically analyzes new suspicious files and sends the results to the installed EPP. As a result, organizations are able to strengthen their protection from previously unknown threats, even if they lack teams of experienced threat analysts or have limited resources.


Unlike many threat intelligence services targeted at experienced security analysts, Kaspersky Sandbox does not require manual operations to examine the impact of suspicious files. When endpoint protection solutions detect a suspicious object that cannot be categorized as malicious without deeply analyzing its behavior, they automatically send it to run in Kaspersky Sandbox.

To detect the malicious intent of an object, Kaspersky Sandbox carries out behavioral analysis as well as collects and analyses all artefacts. In addition, if the object performs malicious actions such as encrypting or downloading a malicious payload using a zero-day exploit, the Sandbox recognizes it as malware and reports it to the endpoint protection solution for further actions.


Kaspersky Sandbox also stores the decision on whether or not the object is a threat in the operational cache located on the Kaspersky Sandbox server. With this feature in place, if the analysis of the file that has already been run in the Sandbox is requested by another endpoint within the managed network, the EPP gets the decision from this shared knowledge base without having to re-scan the file, speeding up the response and reducing the workload on servers of virtual machines.


According to a Kaspersky survey of IT decision-makers, 47 percent of SMBs and 51 percent of enterprises say it is becoming more challenging to differentiate between generic and advanced attacks. This means that security analysts have to spend more time evaluating numerous suspicious files instead of focusing on investigating and responding to the most critical threats.  

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...