Showing posts with label software. Show all posts
Showing posts with label software. Show all posts

Tuesday, December 31, 2019

Kaspersky Web Traffic Security now available in two deployment options to meet customer demands

Kaspersky released next version of Kaspersky Web Traffic Security, which now offers enhanced protection capabilities though integration with Kaspersky Anti Targeted Attack to improve early detection of sophisticated web threats. The product is now available in two deployment options, as a standalone application and a software appliance, to meet broader customer needs.


According to Kaspersky researchers, 717 million web attacks were revealed in the second quarter of this year. The attacks contain various kinds of malware including generic adware to ransomware and advanced threats that reach corporate networks through phishing, social engineering or unreliable web resource surfing.

Web gateway protection allows companies to block massive amounts of web threats before they reach endpoints. This decreases the number of alerts on endpoints that interrupt users and administrators, as well as ensures protection of devices which don’t have endpoint security product installed or updated.


To make the deployment and use of the product effective for companies with different needs, Kaspersky now offers two options: as a software appliance or a standalone application.

The software appliance is a ready-to-use solution for companies that need to quickly deploy and start using secure web gateway with a proxy server pre-configured. The appliance interface allows users to manage the incorporated proxy server, avoiding configuration hassle.

The Kaspersky Web Traffic Security standalone application allows resource economy and a more agile configuration for companies that need a more customized solution and careful integration of different cybersecurity products. The application does not necessarily demand a separate server, as the system requirements necessary to protect a particular bandwidth are met. It can be installed alongside other applications but configured separately from other gateway components.


The protection capabilities of Kaspersky Web Traffic Security are now empowered by two-way API-based integration with Kaspersky Anti Targeted Attack, which allows customers of both solutions to achieve earlier attack detection and automated responses to advanced web threats. 

Suspicious files are automatically sent to Kaspersky Anti Targeted Attack for analysis. The system reveals the nature and malicious activity that the advanced threat generates, including files, transmission of commands, payloads and stolen data, and blocks them at the early attack stage.


“Different deployment scenarios allow companies to choose the best way to secure corporate web traffic, depending on available resources or IT network architecture,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “It also brings new usage scenarios to our partners. For example, the new format of the all-in-one appliance can be used by managed service providers to add web traffic security to their portfolio. Thanks to the application’s ease of deployment, scalability and multi-tenancy, they can provide web traffic security as a service for additional protection to ever growing number of customers, without the hassle.”

Kaspersky Web Traffic Security is available in both deployment options as part of Kaspersky Security for Internet Gateway and Kaspersky Total Security for Business.

NetApp predicts data management and IT trends will lead in the New Year

2019 was a year of rapid innovation—and disruption—for both the IT industry and the broader business community. With the widespread adoption of hybrid multicloud as the de facto architecture for enterprise customers, organizations everywhere are under tremendous pressure to modernize their infrastructure and to deliver tangible business value around data-intensive applications and workloads.

As a result, organizations are shifting from on-premises environments to using public cloud services, building private clouds, and moving from disk to flash in data centers—sometimes concurrently. These transformations open the door to enormous potential, but they also introduce the unintended consequence of increased IT complexity.


NetApp predicts that a demand for simplicity and customizability will be the number one factor that drives IT purchasing decisions in 2020. Vendors will need to offer modern, flexible technologies with the choice of how to use and to consume those technologies so that customers can keep pace with their evolving business models. As IT departments strive to deemphasize maintenance and hardware, to reduce overhead, and to adopt pay-as-you-go models, simplicity and choice will be crucial.

Achieving this simplicity will serve as the foundation for companies as they navigate the exciting technological trends that we identify in the following sections.

1. As the advent of 5G makes AI-driven Internet of Things (IoT) a reality, edge computing environments are primed to become even more disruptive than cloud was.


In preparation for the widespread emergence of 5G, lower-cost sensors and maturing AI applications will be used to build compute-intensive edge environments. This effort will lay the groundwork for high-bandwidth, low-latency AI-driven IoT environments with the potential for huge innovation—and disruption.

The advent of 5G is what AI-driven IoT has been waiting for. It will take a few more years for 5G data technology to spread across the entire United States. However, 2020 will see many players in the technology industry and business community invest in building edge computing environments to support the reality of AI-driven IoT. These environments will make possible new use cases that rely on intelligent, instantaneous, and autonomous decision-making, with low-latency, high-bandwidth capabilities. This evolution will bring us to a world where the internet will work on our behalf—without even having to ask.


This AI-driven IoT innovation, however, will depend on a massive prioritization of edge computing, further disrupting IT infrastructures and data management priorities. As edge devices move beyond home devices (such as connected thermostats and speakers) and become more far-reaching (such as connected solar farms), more data centers will be placed at the edge. Also, platforms such as artificial intelligence for IT operations (AIOps) will be necessary to help monitor complex environments across the edge, the core, and the cloud.

2. The impact of blockchain will be undeniable as indelible ledgers rapidly enable game-changing use cases outside of cryptocurrency.


The world is quickly moving beyond Bitcoin to adopt enterprise-distributed indelible ledgers, setting the stage for a transformation that’s exponentially bigger than the impact that cryptocurrency has had on blockchain in finance. 

While the crypto frenzy continues to steal the limelight when it comes to blockchain, most players in the industry understand the bigger picture of the technology and its potential. Going into 2020, we will see a tipping point for larger implementations as enterprises go a step further to adopt indelible ledgers based on Hyperledger, which represents the maturation of blockchain for wider use cases. Indeed, we will start to see blockchain go “mainstream” as it enables industries such as healthcare to create universal patient records, to improve chain-of-custody pharmaceutical processes, and more.

With such use cases validating blockchain and indelible ledgers, additional widespread adoption of the technology will drive transformation across society on a larger scale. This widespread adoption will build on the disruption that cryptocurrency has brought to finance to touch nearly every industry. As a result, new data management and compute capabilities will encourage companies to invest in indelible ledgers to build differentiated applications and to collaborate on critical, sensitive datasets.

3. Hardware-based composable architecture will have less short-term potential against commodity hardware and software-based infrastructure virtualization.


Continued improvements in commodity hardware performance, software-based virtualization, and microservice software architectures will eliminate much of the performance advantage of proprietary hardware-based composable architectures, relegating them to niche data center roles soon. 

Hardware-based composable architecture is being hyped as the next evolution of hyperconverged infrastructure (HCI). This architecture enables CPUs, networking cards, workload accelerators, and storage resources to be distributed across a rack-scale architecture and to be connected with low-latency PCIe-based switching. 

Although composable architecture does have potential, standardization has been slow, and adoption has been even slower. Meanwhile, software-based virtualization of storage, combined with software-based (but hardware-accelerated) compute and networking virtualization solutions, offers much of the flexibility of hardware-based composable architectures today with lower cost and consistently increasing performance.

Next year, attempts to build a true hardware-based rack-scale computing model will no doubt continue, and the space will continue to evolve quickly. However, most organizations that must transform within 2020 will be best served by a combination of modern HCI architectures (including disaggregated HCI) and software-based virtualization and containerization.

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

SolarWinds Backup for Office 365 delivers cloud-first data protection for Office 365 Exchange, OneDrive, SharePoint

SolarWinds, provider of IT management software, launches SolarWinds Backup for Office 365, designed to extend data protection services by helping ensure the retention and recoverability of Office 365 data.

Backup for Office 365 backs up and helps restore Exchange, OneDrive and SharePoint data, managed from the same web-based dashboard used to protect servers, workstations, and critical business documents. The need for effective and affordable tools to help MSPs reduce the potential impact of malicious external attacks or internal user error is growing. 


Related data retention, recoverability, and the ability to demonstrate regulatory compliance is becoming even more critical, as more businesses continue to adopt SaaS applications and shift resources to the cloud.

With Backup for Office 365, users are able to save administrative time by managing Office 365 backups alongside server and workstation backups, keep recoverable copies of Exchange data for seven years, and archive OneDrive and SharePoint data for one year. Backup storage in SolarWinds’ private cloud is included, with more than 30 data centers worldwide to help meet data locality requirements.


Users can often unwittingly (or purposely) delete important emails, or OneDrive or SharePoint files. If this happens, SolarWinds Backup offers the ability to search for, and recover what is needed. If employees leave and the company does not want to continue paying a subscription fee to store their email and shared documents, then the SolarWinds Backup for Office 365 offers an additional way to retain and access this data. If the enterprise must comply under regulations with data-retention requirements, SolarWinds Backup is designed to help retain and archive critical data.

With SolarWinds Backup for Office 365, users can manage Office 365 Exchange, OneDrive, and SharePoint backups from a single web-based dashboard. They can also view and manage backup status across customers, and several devices and data types. SolarWinds Backup also helps strike the right balance between automation and control. Users can manually select which accounts and mailboxes they want to protect, or automatically add newly created Office 365 accounts to the backup schedule.


“Backup for Office 365 has assisted us in making our clients feel more secure and comfortable with cloud solutions because they’ve regained control over their data backups,” said Kelvin Tegelaar​, CTO, Lime Networks. “This solution is easy to manage, is super-efficient, and gives our customers an extra layer of protection and continuity.”

“If you’re relying on storage to do the job of backup, you’re putting your data at risk. Anything from an overzealous email cleanup to a deliberate ransomware attack can leave you scrambling if your data isn’t safely backed up. Microsoft is focused on the availability of active email and data, but potential gaps exist around the recoverability of accidentally deleted or overwritten data that are only solved by an effective backup product,” said Mav Turner, group vice president of products, SolarWinds MSP. “Backup for Office 365 is designed for peace of mind; you retain control over the retention and recoverability of your customers’ data in Office 365 and can be ready to help them in their time of need. Your backups will run seamlessly in the background, and the only difference you’ll notice will be increased trust that your data is safe, no matter what.”

Friday, December 20, 2019

Commvault data protection software now fully tested and validated to support AWS Outposts

Commvault announced on Thursday that Commvault software has been tested and validated to support AWS Outposts, which is a new, fully-managed service that extends Amazon Web Services (AWS) infrastructure, services, APIs and tools to virtually any data center, co-location space, or on-premises facility for a truly consistent hybrid cloud experience.

Many customers need to keep certain workloads on-premises while managing other workloads in the cloud. Commvault has robust and expansive support for the ever-growing number of diverse workloads rapidly migrating to AWS from other platforms and delivers the same look, feel and performance for data protection and management on-premises as it does in the cloud. 


As a complement to AWS Outposts, Commvault’s software provides a true single solution, not just a single interface, which creates cost efficiencies, provides simplicity and reduces risk.

Commvault is an Advanced Technology Partner in the AWS Partner Network (APN) and holds AWS Storage Competency status. Working with the AWS engineering team allows Commvault to offer integrated cloud storage solutions and support, giving customers the ability to migrate, backup and store data in the cloud. The depth and breadth of Commvault’s software with the wide array of storage services available from AWS allows customers to rest assured that their data is secure and available in the cloud. 


“Our tested and validated support for AWS Outposts allows our customers to leverage Commvault’s powerful cloud data protection and management capabilities on AWS,” said Karen Falcone, Vice President of Worldwide Cloud GTM, Commvault. “With the growth of cloud services and so many Commvault customers moving into AWS, we are helping organizations achieve the same level of data protection in the cloud as they did on-premises without the complexity and costs of installing and managing infrastructure.”


In October, Commvault announced product and experience enhancements to Commvault Activate, its data insights and governance solution that gives users greater visibility into their data, identifies opportunities for storage efficiencies and manages risk. Enhancements include the addition of file access controls for file storage optimization and new redaction functions with sensitive data governance. 

Sunday, December 15, 2019

Wind River announces RISC-V support for VxWorks RTOS

Wind River announced this week RISC-V open architecture support for its VxWorks real-time operating system (RTOS), which is a widely deployed commercial RTOS to have support for the RISC-V open hardware instruction set architecture (ISA). 


The company has also joined the RISC-V Foundation, a non-profit consortium chartered to standardize, protect, and promote RISC-V ISA together with its hardware and software ecosystem for use in all computing devices.



VxWorks is a deterministic, high-performance RTOS that sets the standard for a scalable, future-proof, secure, safe, and reliable operating environment for mission-critical devices and systems that must meet the highest standards.


VxWorks is ideal for hard real-time embedded applications because it is a deterministic, priority-based, preemptive RTOS with low latency and minimal jitter. In addition to standard preemption, VxWorks can ensure that safety- and time-critical applications get a predetermined number of CPU cycles through various forms of scheduling as well as time and space partitioning. It also provides flexible features needed for various industries. 



As new features and functionality are added to VxWorks, compatibility is always top of mind because Wind River strives to protect and future proof its customers’ software and tool investments. Compatibility allows developers to take advantage of the latest VxWorks innovation, enabling them to add new features and upgrades with minimal retesting of the entire system, thereby saving both project time and expense.


VxWorks has IPv4 and IPv6 stacks that are also time-sensitive networking (TSN) capable, guaranteeing real-time communications and packet delivery within a bounded time or latency on a switched Ethernet network. VxWorks supports industrial applications, including but not limited to OPC Unified Architecture (OPC UA); SocketCAN used in automotive applications; and host, target, and on-the-go (OTG) USB.


VxWorks supports 32- and 64-bit, as well as multi-core processors including Intel, Arm and Power Architecture. Its comprehensive multi-core processor support allows OS configurations for asymmetric multiprocessing (AMP) and for symmetric multiprocessing (SMP) with CPU affinity for bound multiprocessing (BMP). 


Adding RISC-V support for VxWorks comes on the heels of the recent wave of innovations made to the RTOS, making it the first to include support for C++17, Boost, Python, and the Rust collection of technologies.


“We are pleased to welcome Wind River into the RISC-V Foundation and our global ecosystem," said Calista Redmond, CEO of the RISC-V Foundation. “VxWorks significantly extends the reach of RISC-V in the embedded developer space. We look forward to continued software developments by Wind River and the RISC-V community.”



“It’s exciting to see RISC-V gain significant industry traction as it brings the dynamism of open architecture development to hardware,” said Michel Genard, vice president of product at Wind River. “Wind River is very pleased to continue innovating VxWorks while contributing to the success of RISC-V with collaborations like the ones we have with SiFive and MicroChip providing support for their Unleashed and PolarFire SoC FPGA boards.”


“Having VxWorks support for our RISC-V-based PolarFire SoC FPGA family brings an extremely compelling offering to embedded systems designers who increasingly need real-time, and Linux capable solutions that are low power, thermally efficient, and secure,” said Shakeel Peera, associate vice president, marketing, FPGA business unit at Microchip. “Our partnership with Wind River is an important one as we work together to advance the collaborative RISC-V ecosystem and community.”


“The adoption of RISC-V by Wind River in VxWorks is a great step in the ongoing enablement of the RISC-V ecosystem,” said Dr. Naveed Sherwani, president and CEO of SiFive. “The ability to run VxWorks on SiFive Core IP and devices will enable new application markets across the world.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...