Showing posts with label information. Show all posts
Showing posts with label information. Show all posts

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Tuesday, December 10, 2019

McAfee aligns with Amazon Web Services to bring MVISION Cloud support to Amazon Detective

McAfee has announced that McAfee MVISION Cloud for Amazon Web Services (AWS) now includes support for Amazon Detective, providing customers with seamless incident detection and remediation. Through the integration of MVISION Cloud with Amazon Detective, customers have the ability to react to security issues quickly and confidently while leveraging the appropriate tools for incident investigation. 


Amazon Detective is a security service that is designed to easily analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. Amazon Detective automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to help customers visualize and conduct faster and more efficient security investigations. 

With McAfee MVISION Cloud, AWS customers can leverage a trusted cloud platform that has achieved AWS Security Competency status as well as AWS Well-Architected Partner designation for its Cloud Access Security Broker (CASB) technology to help locate issues and threats, and move without friction into the analysis phase to resolve the risk.


The capabilities in McAfee MVISION Cloud for AWS include integration with Amazon Detective to detect configuration issues or other cloud risks using McAfee MVISION Cloud and move seamlessly into the investigation phase with Amazon Detective.


The offering comes with architectural freedom of choice that includes Configuration Audit / Cloud Security Posture Management (CSPM) for diverse cloud workloads. Incidents can be detected for a wide array of virtual machine (Amazon Elastic Compute Cloud (Amazon EC2)) or container-based workloads (Amazon Elastic Container Service (Amazon ECS), and Amazon Elastic Kubernetes Service (Amazon EKS) including storage services needed to support the target applications.

Its rich, multifaceted incident data provides integrated CASB-derived functionality such as DLP / Malware detection and user behavior and threat analytics that go beyond detecting basic configuration issues. Identify threats and prioritize remediation, for a frictionless move into Amazon Detective to resolve risks quickly and efficiently.

“We worked closely with AWS to integrate a solution that our mutual customers can use to get total visibility and control over their applications and workloads on AWS,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Amazon Detective’s capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to seamlessly enforce data loss prevention, avoid unauthorized sharing of data, address threats from insiders and compromised accounts, prevent misconfiguration drift, audit all user activity and secure corporate data as organizations leverage the cloud to accelerate their business.”


“McAfee’s market-leading Cloud Security Platform provides a uniform approach to protecting data and stopping threats in the cloud through comprehensive and consistent policies,” said Nemi George, vice president, information security officer, Pacific Dental Services. “The new Amazon Detective integration will give us the added investigation capabilities to improve our compliance and reduce the risk within our cloud infrastructure.”

“We’re delighted that McAfee MVISON Cloud on AWS now supports Amazon Detective, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Dan Plastina, vice president of ESS Security Services, Amazon Web Services. “Customers using Amazon Detective will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

Wednesday, November 27, 2019

Kaspersky research shockingly reveals that over half of companies share their IT budget

A Kaspersky report found that a vast majority, about 89 percent of Chief Information Security Officers (CISOs) are regularly called upon by their board of directors to provide recommendations for the business. 

The study also revealed that despite regular communication with top decision makers to share important insights, it does not necessarily result in dedicated security investments. In fact, 54 percent of respondents admitted having to share their organization’s IT budget.


In the third quarter of this year, 451 Research conducted an independent study, commissioned by Kaspersky, to explore the various factors shaping information security from the perspectives of enterprise security leaders. The study surveyed 305 respondents that have senior or executive responsibility roles for cybersecurity in enterprises worldwide, with the findings revealing how the nature of cybersecurity and security leadership has evolved.

According to the study, top management seek advice from IT security leaders regardless of the organization’s reporting structure, with only 23 percent reporting to the board. 


Additionally, 60 percent of respondents said business leaders need input from their CISO most often when an internal cybersecurity incident happens. However, it’s not all about breaches. Executives also seem to be proactive and mindful about how to protect the company now and in the future. 

More than half (57 percent) of the surveyed IT security chiefs schedule meetings with the board on a regular basis, and 56 percent are requested to provide their expert opinions on future IT projects.

Despite being visible and valuable to the board, CISOs still face difficulties when it comes to justifying necessary spending on IT security. Having to siphon their expenses from the broader IT budget, 43 percent of those surveyed feel that they are in direct competition with other business and IT initiatives, making it one of the top three challenges they face in order to make the case for essential information security investment.


“As the study shows, boards of directors now understand that cybersecurity is an important part of business success,” said Veniamin Levtsov, vice president of corporate business at Kaspersky. “Nevertheless, there’s still a challenge for CISOs to be able to convert this understanding into actual support. Speaking business language instead of using technical jargon, focusing on how to solve problems and bringing in third-party expertise to justify meaningful measures are all key components to win over directors.”

Saturday, November 23, 2019

Microsoft Research shows that logarithmic mapping allows for low discount factors by creating action gaps similar in size

While reinforcement learning (RL) has seen significant successes over the past few years, modern deep RL methods are often criticized for how sensitive they are with respect to their hyper-parameters. One such hyper-parameter is the discount factor, which controls how future rewards are weighted compared to immediate rewards.

The objective that one wants to optimize in RL is often best described as an undiscounted sum of rewards (for example, maximizing the total score in a game). 



In practice, however, a discount factor is introduced to avoid some of the optimization challenges that can occur when directly optimizing on an undiscounted objective. And while in theory a discount factor can take on any value between 0 and 1, in reality good performance is only obtained for a small subset of values close to 1.



The company will present a novel hypothesis as to why the effective discount-factor range is so small. Also, based on its hypothesis, Microsoft outlined a technique to avoid this discount-factor sensitivity and introduce a method, which is called logarithmic Q-learning, based on this technique. 


Logarithmic Q-learning is the first method able to achieve good performance for low discount factors on sparse-reward tasks with function approximation. In addition, the method not only reduces discount-factor sensitivity, but can also improve performance altogether.

While a logarithmic mapping function makes action gaps more homogenous, there are a number of challenges to overcome to build a robust algorithm, based on this outcome, that can be applied to stochastic domains with both positive and negative rewards. 


Microsoft managed to overcome these challenges and develop an algorithm, logarithmic Q-learning, that can be applied to general tasks and has convergence guarantees under standard conditions. These results do not only show great performance for low discount factors. Early performance of high discount factors is also better than it was without the logarithmic mapping.

Tuesday, November 19, 2019

conova deploys ADVA OLS solution for highly secure DCI connectivity to deliver with ALM monitoring technology, encryption

ADVA announced that conova communications is using its technology for secure, high-capacity transport between data centers. conova has deployed the ADVA FSP 3000 open line system (OLS) with ConnectGuard Optical encryption in response to booming demand from business customers for reliable and protected cloud services. 


The fully redundant infrastructure supports 100Gbit/s Carrier Ethernet as well as 32Gbit/s Gen 6 Fibre Channel, a key requirement for the most advanced enterprise storage services. 




Featuring ADVA ALM fiber assurance technology, the new DCI network also enables rapid repair times and improves performance. The solution was designed and implemented by ADVA’s Elite partner dacoso, a German IT service provider focusing on connectivity, cyber defense and virtual networking.



conova’s new network is built on the ADVA FSP 3000 OLS, a high-performance packet-optical solution with low-power consumption and an extremely compact design. The infrastructure is protected by ConnectGuard Optical for network encryption at the lowest network layer. This is not only the most robust security method available, but it also maximizes throughput and ensures the lowest possible latency. 



The network is assured by the ADVA ALM fiber monitoring solution, which provides real-time information on fiber integrity for fast failure detection and short repair cycles. As the first platform on the market to achieve mainframe qualification for Gen 6 Fibre Channel transport, the ADVA FSP 3000 enables conova to make the leap to 32Gbit/s Fibre Channel and maximize the performance of flash-enhanced data storage in its facilities.

Tuesday, November 12, 2019

Cortical.io releases initial application of real-time semantic supercomputing based on natural language understanding

Cortical.io announced Tuesday debut of a new class of high-performance enterprise applications based on “Semantic Supercomputing,” which combines Cortical.io AI-based NLU software inspired by neuroscience with hardware acceleration to create new solutions to understand and process streams of natural language content at massive scale in real time.

The first application of Semantic Supercomputing, a Messaging Classification Appliance that can filter, classify and route streams of messages in real time by understanding the semantic content – the meaning and intent of the messages – was unveiled Tuesday at Xilinx Developer Forum (XDF) Europe keynote session in The Hague.



The Cortical.io approach to NLU is inspired by the latest findings on the way the brain processes information. This approach provides advantages over traditional machine learning methods and helps businesses solve many open NLU challenges like meaning-based filtering of terabytes of unstructured text data, real-time topic detection in social media, or semantic search over millions of documents across languages.

Building on the alliance announced with Xilinx at last month’s at XDF Americas in San Jose, Cortical.io is developing this first of a series of FPGA-based appliances powered by Xilinx Alveo accelerator cards. Cortical.io also announced it is partnering with Supermicro (SMCI), vendor of enterprise computing, storage, networking solutions and green computing technology, to deliver the email solution on a pre-loaded server. 

The appliance will enable enterprises to filter and route massive volumes of email messages in real time with high precision and recall based on the meaning of the message. The product will be available in the first quarter of next year.


“Ever-increasing unstructured data is overwhelming the world and the available processing power and current statistical approaches to deal with it,” said Francisco Webber, co-founder and CEO of Cortical.io. “We are taking the concept of supercomputing to the next level with the introduction of Semantic Supercomputing and the ability to deliver real-time processing of semantic content.”

“The goal is to reduce the wasted efforts of handling irrelevant or misdirected emails by first line business operations – including support, sales, purchasing,” said Cortical.io CMO Steve Levine. “The appliance will be able to handle a massive volume of messages daily in real time.”

Enterprise system administrators will be able to train the system and customize the filtering and routing based on a small number of sample emails. Once trained, the appliance works across multiple languages (English, Spanish, German, Portuguese, Cantonese, Arabic, French, Italian, Mandarin Chinese, Dutch).


“The demand for real-time AI services has never been greater and, together with Cortical.io and Supermicro, we’re excited to be building a solution for solving the incredible processing challenges of real-time Natural Language Understanding on a massive scale,” said Adam Scraba, director of marketing, Data Center Group, at Xilinx.

“Supermicro’s proven and extensive server portfolio when combined with Xilinx Alveo accelerators and the Cortical.io AI-based NLU software, delivers a sophisticated enterprise platform to address the growing data explosion, especially email,” said Don Clegg, senior vice president, Worldwide Sales, Supermicro.


This is the first instance of using the power of semantic supercomputing. 

“Our goal is to make possible the broad implementation and deployment of AI solutions for automating business processes and solving the most challenging use cases that depend on human understanding, decision making and execution,” added Cortical.io CEO Webber.

Tuesday, October 29, 2019

Motorola strengthens software lineup with Broadband PTT streaming video, community engagement, cloud-based records management

Motorola Solutions announced on Monday an expanded set of cloud-based software and video capabilities for the public safety community. These include WAVE push-to-talk (PTT) streaming video, a new service that allows users to push live video to individuals, groups or dispatchers; CommandCentral Community, a next-generation community engagement solution designed to optimize information sharing between agencies and the public; and CommandCentral Records, a cloud-based records and evidence management solution.


WAVE PTT Streaming Video is a cloud-based, carrier-independent broadband PTT service, now allows users to push live video to individuals, groups or dispatchers. Streaming Video, a new optional feature, makes it possible for WAVE users to continuously stream video and audio from their devices at the push of a button, providing recipients with a real-time view of events and activities as they happen.




CommandCentral Community helps build a relationship with the community to act as a key driver for every public safety agency. Motorola’s next-generation community engagement solution is designed to build and strengthen that relationship through better two-way communication, helping agencies work more efficiently with the public. 


The community-facing portal, CityProtect.com, consolidates crime mapping, tipping, camera registration, agency pages and non-emergency reporting into one, easy-to-find location that empowers communities to connect and help solve crime. Users of CrimeReports.com, our current crime mapping site, will be transitioned to CityProtect.com over time, with no disruption in the public's ability to view crime data.


With public safety agencies struggling to collect, store, manage and share the growing amount of data and media created during an incident, Motorola is developing CommandCentral Records to help meet the challenge. A cloud-based records and evidence management solution, CommandCentral Records breaks down barriers by unifying all agency information - including often-siloed 9-1-1 call audio and body-worn and surveillance video - into a single, searchable management experience to enhance productivity. 




Existing customers of Motorola Solutions’ PremierOne Records and Spillman Flex Records solutions currently benefit from free access to cloud-based CommandCentral features that seamlessly connect to their on-premises solutions in a way that helps extract the most value from previous investments, such as simplified searching, case review and judicial sharing. 


Upon its formal launch in 2020, CommandCentral Records will round out Motorola Solutions’ next-generation records and evidence portfolio, which offers new and existing customers the flexibility to transform information management either through the cloud, or with existing on-premises solutions.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...