Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Tuesday, November 19, 2019

Orange uses embedded software to improve end-user experience on its ThousandEyes alliance

Orange partnered with US-based ThousandEyes, an Internet and cloud intelligence company, to deliver real time, end-to-end visibility on both its enterprise networks and the Open Transit Internet (OTI).

The ThousandEyes platform, combined with Orange expertise around data analytics, provides businesses and carriers with improved digital experiences delivered across the Internet to cloud service providers (CSPs), Internet service providers (ISPs) and content providers (CPs). 


Using the ThousandEyes platform, Orange is now able to continuously monitor the performance of certified ISPs and their connection to the Orange Next-Gen Hubs, OTI points-of-presence globally, and all major cloud service providers and content providers. This allows Orange to deliver on the promise of the Internet of Enterprises and OTI by providing performance measurements over Internet in 60 countries, and will continue expanding coverage in the coming months.

Orange Business Services, the global enterprise division of the Orange Group, intends to power this partnership to provide its customers with leading-edge enterprise-grade managed Internet, multi-cloud connectivity and SD-WAN visibility services.

Orange has already deployed the ThousandEyes platform successfully with customers. This includes a German industrial manufacturer, who used it to determine the best cloud connectivity solution in China. 

During a performance assessment of Office 365 and Microsoft Azure connectivity, Orange compared direct connectivity via its Orange Business Services Next-Gen Hub to an alternative solution over Internet. The results were clear: Next-Gen Hub provided up to three times more bandwidth and with more reliability, thereby delivering the best experience for the customer’s users in China.


A key Orange Business Services objective is to accompany its customers around the world in their cloud and SD-WAN transformation journeys, and the ThousandEyes platform is a critical enabler to optimize the migration phases. It allows Orange to monitor quality of experience at both the application and network level, and speed up troubleshooting in case of Internet-related performance issues. 

Customers will be able to gain insight into the internal and external dependencies that impact the end-user experience.

Monday, November 11, 2019

Kaspersky report finds over half of third quarter DDoS attacks occurred in September itself

According to statistics gathered from Kaspersky DDoS Protection, DDoS attacks rose 30 percentage points in the third quarter of this year as compared to the previous quarter, and also rose 32 percentage points when compared to the third quarter of last year.

The rise in DDoS attacks for the third quarter of this year was caused by a large number of rather simple types of attacks. In previous quarters this year, total growth stemmed from a surge in the number of smart attacks focusing on the application layer, usually carried out by skilled cybercriminals. 



In the third quarter this year, the share of ‘smart’ attacks dropped to 28 percent from 50 percent in the second quarter of this year, and grew by only seven percentage points when compared to the third quarter of last year.

Kaspersky surmised that the attackers attempted to use another, rather exotic protocol to amplify DDoS attacks. Experts at Akamai Technologies recently registered an attack on one of their clients that was carried out by spoofing the return IP address through the WS-Discovery multicast protocol. According to other security researchers, cybercriminals started using this method only recently, but have already achieved an attack capacity of up to 350 Gbps.


The WSD protocol has limited scope and is not generally intended for connecting machines to the Internet; rather devices use it to automatically discover each other on LANs. However, it is fairly common for WSD to be used not entirely for its intended purpose in a variety of equipment — from IP cameras to network printers (about 630,000 such devices are currently hooked up to the Internet). 

Given the recent rise in the number of WSD-based attacks, owners of such devices are advised to block on the server UDP port 3702, which is used by this protocol, and to take a number of additional steps to protect their routers.

Another new tool in the hands of DDoSers was detected by Trend Micro in the shape of a new payload distributed through a backdoor in the data search and analytics tool Elasticsearch. The malware is dangerous because it employs a multi-stage approach to infection, successfully avoids detection, and can be used to create botnets for launching large-scale DDoS attacks.


Trend Micro recommends all Elasticsearch users to upgrade to the latest version, since the backdoor has already been patched.

This swing can be attributed to a surge of DDoS activity at the beginning of the academic year. While the early summer months were relatively inactive, the majority of DDoS attacks (53 percent) was detected in September. Kaspersky statistics reveal that 60 percent of the attacks that were prevented during this month were conducted against schools and electronic journal sites. 

With this in mind, Kaspersky experts suggest that these attacks were carried out by school-age cyber attackers who do not have a deep understanding of how to properly organize DDoS campaigns.

Like last year, the arrival of September went hand in hand with a significant rise in the number of DDoS attacks. Moreover, this month accounted for 53 percent of all third quarter attacks, and it was only because of September that any growth in general was observed. 60 percent of DDoS activity in the early fall was directed at education-related resources: electronic grade books, university websites, and the like. Against the backdrop of such attacks, most of which are short and poorly organized, the share of smart attacks in the third quarter sank by 22 percentage points.


Kaspersky observed a similar picture last year, since it is due to students returning to school and university. Most of these attacks are acts of cyber hooliganism carried out by amateurs, most likely with no expectation of financial gain.

The average duration of smart attacks has not changed substantially compared to numbers from the second quarter of last year, but it has almost doubled when compared to the third quarter of last year. Additionally, the average duration of all attacks fell slightly, which is likely due to a large number of shorter attacks in this quarter.

“Despite this spell of seasonal activity from young hooligans who appear to celebrate the beginning of the school year with a spike in DDoS attacks, the more professional market of DDoS attacks is rather stable,” said Alexey Kiselev, business development manager on the Kaspersky DDoS Protection team. “We have not seen an explosive increase in the number of smart attacks compared with the previous quarter and the average length of attack remains the same. However, this still causes serious damage to business. Our survey of IT decision makers revealed that DDoS attacks are the second most expensive type of cyber-incident that led to date breaches for SMBs, with the average cost of a breach estimated at $138,000.”

Wednesday, November 6, 2019

Menlo Security now part of VMware SD-WAN security technology partner program to provide secure cloud transformation

Cloud security company Menlo Security has announced a new integration with VMware SD-WAN by VeloCloud, which offers flexible enterprise SD-WAN architecture. 


The solution delivers Secure Cloud Transformation, which optimizes and secures local Internet breakouts and enables global low latency access to the Internet and business-critical SaaS applications for an enterprise’s entire local and remote workforce. The integration is available immediately to all VMware SD-WAN customers.




VMware SD-WAN customers have simplified their branch office networking and optimized application performance over the Internet. Secure Cloud Transformation, powered by isolation, allows companies to improve security control and visibility across their SD-WAN deployment.


Moving to SD-WAN requires an enterprise to move their security to the cloud since user traffic is not backhauled to a central security stack. Menlo Security Cloud Platform allows users to go directly to the Internet, while ensuring consistent and robust security controls, whether they are connecting from HQ, remote offices, on the road or in a coffee shop.


Menlo Security’s customers include some of the largest enterprises and government agencies. The company’s cloud security platform currently processes more than 500 million web requests per day. Among the company’s customers are seven of the 10 largest banks, four of the five largest credit-card issuers and some of the largest energy and transportation companies in the world.



“Menlo Security helps some of the largest enterprises and government agencies in the world transform their infrastructure and move security to the cloud, while maintaining global visibility and control of their traffic,” said Poornima DeBolle, chief product officer at Menlo Security. “VMware SD-WAN by VeloCloud combined with the Menlo Security Cloud Platform powered by isolation redefines security and provides the industry’s most secure solution for Internet and SaaS applications.”


"VMware SD-WAN provides the optimal combination of intrinsic security in the multi-service Edge for corporate traffic as well as SD-WAN optimized access via our Network of Clouds Service gateways to the innovative Menlo Security Cloud Platform powered by isolation," said Steve Woo, senior director of product management at VMware. "Access to cloud and SaaS applications is automatically provisioned, optimized for performance and secured with VMware SD-WAN and Menlo Security Cloud Platform."

Friday, November 1, 2019

Uplevel delivers SD-WAN to small business; gives high-quality VoIP, reliable Internet and 75 percent savings

Uplevel Systems now offers software-defined Wide Area Network or "SD-WAN" capabilities optimized for small to medium businesses (SMBs). SD-WAN traditionally involves replacing costly telecom services with cost-effective Internet connections between sites. 

Smaller companies find SD-WAN cost-prohibitive because most offerings include advanced features and other "bells and whistles" they must pay for but do not need. In practice, the prospective cost savings also may be compromised by poorly performing Internet connections or call quality between sites.


The Uplevel solution optimizes SD-WAN for small business in four critical ways, including ensuring call quality for voice over Internet Protocol (VoIP). Phone systems are still the lifeblood of many small businesses and voice call quality is highly sensitive to delays of mere tenths of a second. 

Uplevel's integrated managed service platform includes built-in VoIP quality of service (QoS) mechanisms that ensure voice calls always receive priority over data and other "best effort" transactions and also eliminate packet loss that can lead to poor call quality. 

Uplevel delivers a targeted and reliable small business SD-WAN solution that removes both cost and complexity to deliver the features and benefits SMBs need. Uplevel eliminates traditional upfront costs of approximately $1,000 per site and reduces ongoing costs by 75 percent or more versus traditional solutions. 


Along with adding failover and load balancing optimizing quality and reliability, the Uplevel solution reduces upfront equipment costs by up to $3,000 per site. Users can log in safely using secure virtual private network (VPN) services and cloud-based management allows MSPs to manage multiple sites in real time from anywhere on the device of their choice. 

The Uplevel solution enables two SD-WAN mechanisms for improving and maintaining reliability: "Failover" whereby companies purchase a second Internet connection to provide backup, and "load balancing" in which two primary Internet connections remain in use at all times with traffic distributed to achieve the desired bandwidth at the lowest possible cost.

Borusan Holding adopts A10 Networks Thunder SSLi to protect network from hidden threats

A10 Networks announced that Borusan Holding has selected A10 Thunder SSL Insight to help protect its network from hidden threats that may come in with the growing amount of encrypted internet traffic. Thunder SSLi is a comprehensive SSL/TLS decryption solution that enables security devices to analyze enterprise internet traffic against potential threats.


The vast majority of web and application traffic is encrypted using SSL/TLS to ensure data integrity and privacy, not necessarily security. This creates real issues as security tools become blind to any nefarious activity happening in encrypted traffic - before the attack, during the attack, and even after the attack. Criminals take advantage of this and hide attacks in an enterprise’s encrypted traffic.

Guarding against such hidden threats is a top priority for Borusan. Volumes of encrypted web traffic were rising dramatically, driven by the adoption of Microsoft Office 365 and other cloud-based applications. Outbound SSL traffic was a growing blind spot.


Borusan evaluated the SSL inspection products and chose Thunder SSLi because of its interception technology, source-side NAT support, and integrated load balancing, which helps to distribute internet traffic between proxy appliances.


Thunder SSLi decrypts traffic across all ports, enabling third-party security devices to analyze all enterprise traffic without degrading performance. Thunder SSLi decrypts HTTPS traffic and forwards it in clear text to the firewall, proxy, IPS and deep-packet inspection solutions. Thunder SSLi then re-encrypts traffic and sends it off to its final destination.


“Today, encryption has become ubiquitous. And while encryption can ensure the privacy of the data, it can put enterprises at risk,” said Yasir Liaqatullah, vice president of product management at A10 Networks. "Cyber criminals are increasingly taking advantage of encrypted traffic to launch phishing and ransomware attacks, and to spread viruses and Trojans embedded into documents. Thunder SSLi is a high-performance, dedicated SSL inspection solution that allows enterprises to remove the blind spots while maintaining compliance with privacy standards.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...