Showing posts with label protection. Show all posts
Showing posts with label protection. Show all posts

Tuesday, December 31, 2019

Kaspersky Web Traffic Security now available in two deployment options to meet customer demands

Kaspersky released next version of Kaspersky Web Traffic Security, which now offers enhanced protection capabilities though integration with Kaspersky Anti Targeted Attack to improve early detection of sophisticated web threats. The product is now available in two deployment options, as a standalone application and a software appliance, to meet broader customer needs.


According to Kaspersky researchers, 717 million web attacks were revealed in the second quarter of this year. The attacks contain various kinds of malware including generic adware to ransomware and advanced threats that reach corporate networks through phishing, social engineering or unreliable web resource surfing.

Web gateway protection allows companies to block massive amounts of web threats before they reach endpoints. This decreases the number of alerts on endpoints that interrupt users and administrators, as well as ensures protection of devices which don’t have endpoint security product installed or updated.


To make the deployment and use of the product effective for companies with different needs, Kaspersky now offers two options: as a software appliance or a standalone application.

The software appliance is a ready-to-use solution for companies that need to quickly deploy and start using secure web gateway with a proxy server pre-configured. The appliance interface allows users to manage the incorporated proxy server, avoiding configuration hassle.

The Kaspersky Web Traffic Security standalone application allows resource economy and a more agile configuration for companies that need a more customized solution and careful integration of different cybersecurity products. The application does not necessarily demand a separate server, as the system requirements necessary to protect a particular bandwidth are met. It can be installed alongside other applications but configured separately from other gateway components.


The protection capabilities of Kaspersky Web Traffic Security are now empowered by two-way API-based integration with Kaspersky Anti Targeted Attack, which allows customers of both solutions to achieve earlier attack detection and automated responses to advanced web threats. 

Suspicious files are automatically sent to Kaspersky Anti Targeted Attack for analysis. The system reveals the nature and malicious activity that the advanced threat generates, including files, transmission of commands, payloads and stolen data, and blocks them at the early attack stage.


“Different deployment scenarios allow companies to choose the best way to secure corporate web traffic, depending on available resources or IT network architecture,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “It also brings new usage scenarios to our partners. For example, the new format of the all-in-one appliance can be used by managed service providers to add web traffic security to their portfolio. Thanks to the application’s ease of deployment, scalability and multi-tenancy, they can provide web traffic security as a service for additional protection to ever growing number of customers, without the hassle.”

Kaspersky Web Traffic Security is available in both deployment options as part of Kaspersky Security for Internet Gateway and Kaspersky Total Security for Business.

Tuesday, December 24, 2019

Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

Tuesday, December 17, 2019

Infortrend incorporates DaVinci Resolve project server into its scale-out shared storage offering

Infortrend Technology releases on Tuesday its highly scalable shared storage EonStor CS that supports NLE software, such as DaVinci Resolve, Adobe Premiere Pro, and Final Cut Pro to facilitate collaborative editing of 4K and above ultra-high resolution videos. EonStor CS supports over 100 GB/s performance and 100 PB capacity, making it an ideal storage solution for large-scale post-production studios with more than ten workstations. 

In a traditional architecture, the database project server, which contains reels, edited files and timeline, is deployed on a dedicated workstation and connects to other workstations in a peer-to-peer network for editors, colorists, and animators to work together on the same project. Any single point of failure, however, will pose a threat to the project. 

In light of this issue, Infortrend integrates DaVinci Resolve Project Server into the shared media storage and provides RAID protection to guarantee high data availability. The simplified network architecture also makes deployment and management easier for video professionals to focus more on content production.


EonStor CS is a scale-out shared storage solution that allows enterprises to address the sheer volume of data via its scalable capacity and linear-increasing performance. The scalability through a scale-out expansion offers an easier and more cost-effective way of managing growing data in the agile enterprises while reducing consequent performance bottlenecks. 

EonStor CS also improves data utilization and simplifies data management by integrating data from all nodes into one cluster system. The superior performance and scalability make CS suitable for a wide range of data-intensive industries and applications such as media and entertainment (M&E), high-performance computing (HPC), video surveillance, file sharing and backup. 

With EonStor CS, enterprises gain speedy process for storage expansion and data migration. EonStor CS can keep up as the business grows, making it the optimized data storage and management solution.

Moreover, the shared media storage comes with user-friendly management software that is also designed to simplify the deployment. The EonOne software offers two accounts to separate different management roles. One account is for M&E User Administrator, who uses EonOne to set up user accounts and storage quota. The other account is for System Administrator, who is in charge of advanced configurations and maintenance.

In addition, Infortrend develops a client-based utility EonView, which is installed on Windows and macOS workstations to automatically detect the connected storage system and mount the assigned file folder according to the user credentials. This smart utility simplifies the complexities of storage system deployment and network setup, especially for video professionals who are not familiar with IT setting.  

“Infortrend offers comprehensive storage solutions for today’s M&E, no matter the business scale,” said Thomas Kao, senior director of Product Planning. “Besides its highly scalable performance and capacity for large workgroups to fulfill simultaneous workflows, CS supports high density 4U 60-bay form factor to deliver optimized size for massive data storage requirements. With the launch of CS, we aim to serve M&E customers with smarter, easier, and more flexible solutions,” 

Sunday, December 8, 2019

Amazon VPC Ingress Routing and Trend Micro help simplify network security

Amazon Web Services (AWS) announced availability of Amazon Virtual Private Cloud (Amazon VPC) Ingress Routing service. As a Launch Partner for Amazon VPC Ingress Routing, Trend Micro continues to innovate alongside AWS to provide solutions to customers—enabling new approaches to network security. 

Trend Micro TippingPoint and Trend Micro Cloud One integrate with Amazon VPC Ingress Routing deliver network security that allows customers to obtain compliance by inspecting both ingress and egress traffic, thereby providing user with a deployment experience designed to eliminate any disruption in the business.


Amazon VPC Ingress Routing is a service that helps customers simplify the integration of network and security appliances within their network topology. With Amazon VPC Ingress Routing, customers can define routing rules at the Internet Gateway (IGW) and Virtual Private Gateway (VGW) to redirect ingress traffic to third-party appliances, before it reaches the final destination. This makes it easier for customers to deploy production-grade applications with the networking and security services they require within their Amazon VPC.

By enabling customers to redirect their north-south traffic flowing in and out of a VPC through internet gateway and virtual private gateway to the Trend Micro cloud network security solution. Not only does this enable customers to screen all external traffic before it reaches the subnet, but it also allows for the interception of traffic flowing into different subnets, using different instances of the Trend Micro solution.


Trend Micro customers now have the ability to have cloud network layer security in AWS leveraging Amazon VPC Ingress Routing. With this enhancement, customers can deploy in any VPC, without any disruptive re-architecture and without introducing any additional routing or proxies. Deploying directly inline is the ideal solution and enables simplified network security without disruption in the cloud.

A defense-in-depth or layered security approach is important to organizations, especially at the cloud network layer. That being said, customers need to be able to deploy a solution without re-architecting or slowing down their business, the problem is, previous solutions in the marketplace couldn’t meet both requirements.

So, when customers wanted TippingPoint intrusion prevention system (IPS) capabilities to be brought to the cloud, Trend Micro responded with a solution. Backed by research from Trend Micro Research, including the Zero Day Initiative, Trend Micro created a solution that includes cloud network IPS capabilities, incorporating detection, protection and threat disruption—without any disruption to the network.


At AWS re:Invent 2018, AWS announced the launch of Amazon Transit Gateway. This architecture enables customers to route traffic through a hub and spoke topology, and leverage this as a primary deployment model in the Cloud Network Protection, powered by TippingPoint, cloud IPS solution, announced in July this year. This enabled customers to gain broad security and compliance, without re-architecting, and the company will soon add a flexible deployment model.

Friday, November 29, 2019

U.S. Department of Justice takes evolution of unmanned aircraft systems in account; updates its policy documentation

The Justice Department announced publication of its updated policy on the Use of Unmanned Aircraft Systems. In light of advancements in unmanned aircraft system (UAS) technology, and lessons learned from the Federal Bureau of Investigation’s limited use of UAS, the policy enables the Department of Justice’s law enforcement components to safely and responsibly employ UAS technology within a framework designed to provide accountability and protect privacy and civil liberties.



The Policy permits the use of UAS only in connection with properly authorized investigations and activities.  It also requires compliance with the Constitution and all applicable laws and regulations, including regulations issued by the Federal Aviation Administration.  


Department of Justice components anticipate using UAS to support crime scene response and investigation, search and rescue, and site security, among other authorized uses. 



In order to ensure accountability and airspace safety, the Department requires UAS operations to be approved at an appropriate level and conducted by personnel who meet Department-wide training standards. Importantly, the new policy also requires components to evaluate UAS acquisitions for cybersecurity risks, guarding against potential threats to the supply chain and DOJ’s networks.  


“UAS technology assists the Department in protecting public safety and, most importantly, reduces risks to officers and the public,” said Beth A. Williams, Assistant Attorney General for the Office of Legal Policy.  “Our new policy promotes the responsible, appropriate, and effective use of UAS by the Department and can serve as a model for our state, local, tribal, and territorial public safety partners as they develop their own UAS programs and best practices.” 


The policy reflects the department’s commitment to the protection of privacy and civil liberties, mandating annual privacy reviews of UAS programs and assessments of new UAS technology from a privacy perspective.  It also places limits on data retention, generally requiring privacy sensitive data to be deleted within 180 days, unless certain exceptions are met. 


In addition to utilizing UAS as a law enforcement tool, the Department takes seriously the threat posed by unlawful and unsafe uses of UAS.  The Department has trained federal prosecutors and agents across the country on the criminal and civil enforcement tools available to counter the misuse of UAS, such as the use of drones to smuggle contraband into prisons or violate restricted airspace.  



Department of Justice personnel have also trained and collaborated with senior state, local, tribal, and territorial law enforcement officials who face this new threat on a daily basis. 


The department welcomes lawful and beneficial uses of UAS, which promise to enhance the economy and transform the delivery of goods and the provision of critical services ranging from search-and-rescue to industrial inspections. At the same time, the department will not hesitate to take action against those who threaten the safety of skies and the public. 


The updated policy announced draws on the department’s long history of leveraging technology to protect the public, while promoting values and the rule of law.  

Friday, November 22, 2019

Kaspersky uncovers 37 vulnerabilities in open-source VNC systems; exploitation could lead to remote code execution

Kaspersky presented on Friday an analysis of open source Virtual Network Computing (VNC) which uncovered memory corruption vulnerabilities that existed in a substantial number of projects for a significant period of time. 

According to shodan.io, the exploitation of some detected vulnerabilities could lead to remote code execution affecting the users of VNC systems, which amounts to over 600,000 servers accessible from the global network. 


VNC systems provide remote access to one device from another through the use of remote frame buffer (RFB) protocol. Due to its availability on multiple platforms and presence of multiple open sources, VNC systems have become some of the more popular desktop sharing tools to date. 

They are actively used in automated industrial facilities enabling remote control of systems, and approximately 32% of industrial network computers having some form of remote administration tools, including VNC.


The prevalence of such systems in general, and particularly ones that are vulnerable, is a significant issue for the industrial sector as potential damages can bring significant losses through disruption of complex production processes. 

As such, Kaspersky researchers studied some VNC systems including LibVNC, UltraVNC, TightVNC1.X and TurboVNC.

Although these VNC projects were previously analyzed by other researchers, not all vulnerabilities were uncovered and patched. As a result of Kaspersky’s analysis, 37 CVE records marking various vulnerabilities were created. 


Vulnerabilities were found not only on the client, but also on the server-side of the system. Some allowed remote code execution, which can then permit a malicious actor to make arbitrary changes on the attacked systems. Alternatively, many server-side vulnerabilities could only be exploited after password authentication, and some servers do not allow password-free access.

Wednesday, November 20, 2019

Rise in stalkerware programs leads to formation of global initiative called the Coalition Against Stalkerware

Stalkerware programs carry the possibility for intrusion into a person’s private life and are being used as a tool for abuse in cases of domestic violence and stalking. By installing these apps, abusers can get access to their victim’s messages, photos, social media, geolocation, audio or camera recordings (in some cases, this can be done in real-time). Such programs run hidden in the background, without a victim’s knowledge or consent.


Ten organizations – Avira, Electronic Frontier Foundation, European Network for the Work with Perpetrators of Domestic Violence, G DATA Cyber Defense, Kaspersky, Malwarebytes, National Network to End Domestic Violence, NortonLifeLock, Operation Safe Escape and WEISSER RING – have launched a global initiative called the Coalition Against Stalkerware.

For some years, the problem of stalkerware has been on the rise. Non-profit organizations are experiencing a growing number of victims seeking help with the problem. 


According to Kaspersky, the number of users facing stalkerware rose by 35 percent, from 27,798 in 2018 to 37,532 in 2019. The threat landscape for stalkerware has also widened, as Kaspersky has detected 380 variants of stalkerware in the wild in 2019 – 31 percent more than a year ago.


A key objective of the website will be to provide a helpful online resource for victims of stalkerware. Users will find information on what stalkerware is, what it can do, and, most importantly, how to protect themselves. The website will list common indicators to check if a user thinks they may have become a victim of stalkerware, and what steps they should and should not take. 

For example, it is important to consider whether removing stalkerware could potentially cause more harm, as the abuser will be informed immediately by the app, or it could erase evidence critical to a law enforcement investigation.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...