Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
ZURICH, SWITZERLAND -- (Marketwired) -- 06/23/15 -- Vectra Networks, the leader in real-time detection of cyber attacks in-progress, today announced the results of the second edition of its Post-Intrusion Report, a real-world study about threats that evade perimeter defenses and what attackers do once they get inside your network.
Report data was collected over six-months from 42 customer and prospect networks with more than 250,000 hosts, and is compared to results in last year's report. The new report includes detections of all phases of a cyber attack and exposes trends in malware behavior, attacker communication techniques, internal reconnaissance, lateral movement, and data exfiltration.
According to the report, there was non-linear growth in lateral movement (580 percent) and reconnaissance (270 percent) detections that outpaced the 97 percent increase in overall detections compared to last year. These behaviors are significant as they show signs of targeted attacks that have penetrated the security perimeter.
While command-and-control communication showed the least amount of growth (6 percent), high-risk Tor and external remote access detections grew significantly. In the new report, Tor detections jumped by more than 1000 percent compared to last year and accounted for 14 percent of all command-and-control traffic, while external remote access shot up by 183 percent over last year.
The report is the first to study hidden tunnels without decrypting SSL traffic by applying data science to network traffic. A comparison of hidden tunnels in encrypted traffic vs. clear traffic shows that HTTPS is favored over HTTP for hidden tunnels, indicating an attacker's preference for encryption to hide their communications.
"The increase in lateral movement and reconnaissance detections shows that attempts at pulling off targeted attacks continue to be on the rise," said Oliver Tavakoli, Vectra Networks CTO. "The attackers' batting average hasn't changed much, but more at-bats invariably has translated into more hits."
A copy of the Post-Intrusion Report is available for download at http://info.vectranetworks.com/post-intrusion-report-2015.
Other key findings of the study include:
The data in the Post-Intrusion Report is based on metadata from Vectra customers and prospects who opted to share detection metrics from their production networks. Vectra identifies active threats by monitoring network traffic on the wire in these environments. Internal host-to-host traffic and traffic to and from the Internet are monitored to ensure visibility and context of all phases of an attack.
The latest report offers a first-hand analysis of active "in situ" network threats that bypass next-generation firewalls, intrusion prevention systems, malware sandboxes, host-based security solutions, and other enterprise defenses. The study includes data from 42 organizations in education, energy, engineering, financial services, government, healthcare, legal, media, retail, services, and technology.
"The Vectra Post-Intrusion Report is especially relevant today in light of the recent cyber-attack on the German Bundestag," said Gerard Bauer, EMEA vice president for Vectra, which recently established its European headquarters in Switzerland. "Network perimeter defenses were penetrated and malware spread undetected for 70 days, giving the attackers plenty of time to steal data."
"Vectra Networks' automated threat-management solution pinpoints cyber-attacks in real time -- as they're happening -- and prioritizes the threats that pose the biggest risk," Bauer added. "This enables security professionals to move swiftly to prevent or mitigate loss."
About Vectra Networks
Vectra Networks is the leader in real-time detection of in-progress cyber attacks. The company's automated threat-management solution continuously monitors internal network traffic to pinpoint cyber attacks as they happen. It then automatically correlates threats against hosts that are under attack and provides unique context about what attackers are doing so organizations can quickly prevent or mitigate loss. Vectra prioritizes attacks that pose the greatest business risk, enabling organizations to make rapid decisions on where to focus time and resources. In 2015, Gartner named Vectra a Cool Vendor in Security Intelligence for addressing the challenges of post-breach threat detection. Vectra's investors include Khosla Ventures, Accel Partners, IA Ventures and AME Cloud Ventures. The company's headquarters are in San Jose, Calif., and it has European operations in Zurich. More information can be found at www.vectranetworks.com.
Vectra Networks and Threat Certainty Index are registered trademarks of Vectra Networks in the United States and other countries. All other brands, products, or service names are or may be trademarks or service marks of their respective owners.
Contact:
Dan Spalding
Email Contact
(408) 960-9297
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs