Skip to content

PCI-DSS: What is this and why should I be compliant

But along with the efficiency ofIn a completely digital world, it is normal for all sensitive data of a person or company to circulate and be stored on computers or mobile devices. Whether through websites, folders or applications.

 control and information disclosure, risks also came along. In different corners of the Internet, there are hidden threats that can steal personal data and cause a tremendous headache to any user.

Among these most common threats in everyday virtual life, we can highlight malware, short for malicious software.

What is Malware?

Malware is a type of computer program designed to infect a person’s device and harm them in many ways. It has various means of infecting computers and mobile devices, and it can also take many forms.

Spyware, viruses, worms, and Trojans are among these threats. Viruses are perhaps the most well-known type of malware and so are called because they are able to replicate various forms of themselves and spread across the network.

Each of them has a different “function”. Spyware, for example, copy and transmit personal information such as credit card numbers. Therefore, being well disguised in any corner of the Internet, the user must know how to identify them to protect themselves in every way.

Looking for more protection for your network? Then visit our website

and request a demo of our services!

How to Identify Malware

Malware can manifest itself in many different ways on devices. Paying attention to these signs is important to be able to neutralize any threat right away.

  • Reduced operating system speed, when browsing the internet or using local applications;
  • System shutdown, crash, or Blue Screen;
  • System and antivirus update failures;
  • Sudden appearance of new toolbars, extensions, or plugins;
  • Mysterious loss of disk space;
  • Change of browser homepage without permission or links that lead to unwanted destinations on the Internet;
  • Excessive ads in pop-up windows on the screen of devices;
  • The high usage of system resources and the computer’s fan working at a fast pace.

Nevertheless, even if everything is working normally on the devices, it does not mean everything is fine. A more powerful malware can hide on the computer and perform illegal activities without awakening any system alerts, managing to steal passwords or sensitive files.

How is The User Infected with Malware?

There are many ways in which a user can be tricked, infected by malware, and put their system and data at risk. The two most common ways it can access your system are on the Internet and through email.

Anything downloaded from the Internet to a device that does not have a quality anti-malware security application can pose risks to the user. The most common ways by which this can happen are:

  • Browsing on compromised websites;
  • Downloading infected music files;
  • Installing new toolbars from an unknown provider;
  • Clicking on game demos;
  • Configuring software from a risky source;
  • Opening suspicious email attachments.

But some can also hide in legitimate apps, especially when downloaded from websites or via messages, rather than through an app store.

Therefore, it is recommended to always use reliable sources of mobile apps or install apps from reputable providers, always downloading directly from the provider and never from other websites.

Even if a user installs something from a reputable source, failing to pay attention to requests for permission to install other program packages at the same time could end up installing unwanted software.

But there are much simpler ways to come across malware. Just visiting a malicious website, for example, or viewing a page and/or an infected ad, a malware download can take place.

How to Protect Yourself from Malware?

In order to protect your computer or network from malware, two things are necessary: always being vigilant to everything that appears on the Internet and using protection tools. It is always good to be on the lookout for any messages or suspicious activity on the system.

Sending emails is one of the main paths where malware is found. Seemingly harmless and unsuspecting messages can be the perfect trick to deceive the

user. It can be disguised as a message from a well-known company, banks, or even people you know in your family and friendship circles.

Emails that ask for passwords (mainly their confirmation) through links are quite common and dangerous. Thus, it is always good to be aware of everything you receive and analyze the situation carefully to find out if it is in fact true.

But personal surveillance alone is not enough. As already mentioned, malware can hide very well over the network and deceive any type of person, whether they are experienced in the matter or not.

When it comes to data security, especially for companies, it is essential to have reinforced security so that there is no risk of data leaks that could compromise an entire work.

An antivirus software package that is very efficient is what guarantees a technological defense capable of protecting computers and other electronic devices. It does a general system check to ensure it is malware-free.

It has a regular update that allows it to recognize the latest threats. It is also possible to warn of previously unknown malware threats based on their own technical resources.

With this anti-virus protection, it is also possible to detect suspicious websites, especially those that might trick the user into revealing passwords or account numbers. Effective protection also helps finances. They protect account information and provide password management.

However, this protection should be easy to use, simple to download and install. No protection is completely absolute, but using the right protection tools and having an awareness of what’s happening on the network ensures your data can be as protected as possible.

Do you want to learn more about how to protect your data from malicious attacks? Then visit our blog for more information and stay on top of everything you need to know!

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

CyberLink Announces the Release of FaceMe® Platform, a Complete API Solution for Facial Recognition

As a member of the FIDO Alliance, CyberLink commits to developing and supporting new biometrics-based authentication standards through FaceMe®, its facial recognition technology

TAIPEI, TAIWAN — April 21, 2022 — CyberLink Corp. (5203.TW), a pioneer of AI and facial recognition technologies, announces it became an Associate Member of the FIDO Alliance, an open industry association focused on authentication standards and device attestation. CyberLink joins hundreds of industry players in developing and implementing new authentication specifications and standards, including facial recognition, that will better protect user privacy.

The FIDO Alliance is an industry association centered on advancing authentication standards to decrease dependence on passwords, which can be easily stolen or hacked. These new standards make authentication simpler for consumers to use and easier for service providers to manage. The Alliance’s rich membership comprises stakeholders that include government agencies, service providers, technology players and financial services industry leaders.

Technology industry member CyberLink is dedicated to providing encrypted biometric authentication through its FaceMe AI facial recognition solutions. With its facial recognition expertise, CyberLink is well-positioned to help the Alliance promote the adoption of biometric technologies that will deliver to our society more secure and convenient authentication alternatives to those with inherent flaws that are generally used today.

“We are excited to welcome our newest Associate Member CyberLink,” said Andrew Shikiar, Executive Director and CMO of the FIDO Alliance. “The FIDO vision of universal strong authentication promises better security, enhanced privacy, more commerce and expansion of services throughout digital industries. CyberLink’s addition to our Alliance supports our industry goal to make user authentication easier and safer for all parties.”

“As privacy and protection are increasingly critical imperatives of our society’s reliance on technology in every facet of life, users deserve stronger yet more intuitive authentication methods,” said Dr. Jau Huang, CEO of CyberLink. “I have no doubt that CyberLink’s biometrics authentication expertise, cemented through FaceMe, our facial recognition technology, will benefit the FIDO Alliance in establishing and providing safer authentication methods for end-users.”

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About CyberLink
Founded in 1996, CyberLink Corp. (5203.TW) is the world leader in multimedia software and AI facial recognition technology. CyberLink addresses the demands of consumer, commercial and education markets through a wide range of solutions, covering digital content creation, multimedia playback, video conferencing, live casting, mobile applications and AI facial recognition.  CyberLink has shipped several hundred million copies of its multimedia software and apps, including the award-winning PowerDirector, PhotoDirector, and PowerDVD.  With years of research in the fields of artificial intelligence and facial recognition, CyberLink has developed the FaceMe® Facial Recognition Engine. Powered by deep learning algorithms, FaceMe® delivers the reliable, high-precision, and real-time facial recognition that is critical to AIoT applications such as smart retail, smart security, and surveillance, smart city and smart home. For more information about CyberLink, please visit the official website at www.cyberlink.com

Malware: Learn How to Identify the Threat Quickly

But along with the efficiency ofIn a completely digital world, it is normal for all sensitive data of a person or company to circulate and be stored on computers or mobile devices. Whether through websites, folders or applications.

 control and information disclosure, risks also came along. In different corners of the Internet, there are hidden threats that can steal personal data and cause a tremendous headache to any user.

Among these most common threats in everyday virtual life, we can highlight malware, short for malicious software.

What is Malware?

Malware is a type of computer program designed to infect a person’s device and harm them in many ways. It has various means of infecting computers and mobile devices, and it can also take many forms.

Spyware, viruses, worms, and Trojans are among these threats. Viruses are perhaps the most well-known type of malware and so are called because they are able to replicate various forms of themselves and spread across the network.

Each of them has a different “function”. Spyware, for example, copy and transmit personal information such as credit card numbers. Therefore, being well disguised in any corner of the Internet, the user must know how to identify them to protect themselves in every way.

Looking for more protection for your network? Then visit our website

and request a demo of our services!

How to Identify Malware

Malware can manifest itself in many different ways on devices. Paying attention to these signs is important to be able to neutralize any threat right away.

  • Reduced operating system speed, when browsing the internet or using local applications;
  • System shutdown, crash, or Blue Screen;
  • System and antivirus update failures;
  • Sudden appearance of new toolbars, extensions, or plugins;
  • Mysterious loss of disk space;
  • Change of browser homepage without permission or links that lead to unwanted destinations on the Internet;
  • Excessive ads in pop-up windows on the screen of devices;
  • The high usage of system resources and the computer’s fan working at a fast pace.

Nevertheless, even if everything is working normally on the devices, it does not mean everything is fine. A more powerful malware can hide on the computer and perform illegal activities without awakening any system alerts, managing to steal passwords or sensitive files.

How is The User Infected with Malware?

There are many ways in which a user can be tricked, infected by malware, and put their system and data at risk. The two most common ways it can access your system are on the Internet and through email.

Anything downloaded from the Internet to a device that does not have a quality anti-malware security application can pose risks to the user. The most common ways by which this can happen are:

  • Browsing on compromised websites;
  • Downloading infected music files;
  • Installing new toolbars from an unknown provider;
  • Clicking on game demos;
  • Configuring software from a risky source;
  • Opening suspicious email attachments.

But some can also hide in legitimate apps, especially when downloaded from websites or via messages, rather than through an app store.

Therefore, it is recommended to always use reliable sources of mobile apps or install apps from reputable providers, always downloading directly from the provider and never from other websites.

Even if a user installs something from a reputable source, failing to pay attention to requests for permission to install other program packages at the same time could end up installing unwanted software.

But there are much simpler ways to come across malware. Just visiting a malicious website, for example, or viewing a page and/or an infected ad, a malware download can take place.

How to Protect Yourself from Malware?

In order to protect your computer or network from malware, two things are necessary: always being vigilant to everything that appears on the Internet and using protection tools. It is always good to be on the lookout for any messages or suspicious activity on the system.

Sending emails is one of the main paths where malware is found. Seemingly harmless and unsuspecting messages can be the perfect trick to deceive the

user. It can be disguised as a message from a well-known company, banks, or even people you know in your family and friendship circles.

Emails that ask for passwords (mainly their confirmation) through links are quite common and dangerous. Thus, it is always good to be aware of everything you receive and analyze the situation carefully to find out if it is in fact true.

But personal surveillance alone is not enough. As already mentioned, malware can hide very well over the network and deceive any type of person, whether they are experienced in the matter or not.

When it comes to data security, especially for companies, it is essential to have reinforced security so that there is no risk of data leaks that could compromise an entire work.

An antivirus software package that is very efficient is what guarantees a technological defense capable of protecting computers and other electronic devices. It does a general system check to ensure it is malware-free.

It has a regular update that allows it to recognize the latest threats. It is also possible to warn of previously unknown malware threats based on their own technical resources.

With this anti-virus protection, it is also possible to detect suspicious websites, especially those that might trick the user into revealing passwords or account numbers. Effective protection also helps finances. They protect account information and provide password management.

However, this protection should be easy to use, simple to download and install. No protection is completely absolute, but using the right protection tools and having an awareness of what’s happening on the network ensures your data can be as protected as possible.

Do you want to learn more about how to protect your data from malicious attacks? Then visit our blog for more information and stay on top of everything you need to know!

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Configuration Management Database (CMDB): Learn More About It

Making a list of all the configuration items used in your company and keeping this list up to date can be quite challenging, but it is extremely important not only for the IT team but also for the business in general.

The good news is that this process can be streamlined through a configuration management database (CMDB), which allows managing and organizing assets to reduce operational and maintenance costs, reduce the redundancy of digital assets, and perform audits, among other numerous advantages.

However, you may have never heard of this solution or do not know exactly how to implement it. Taking this into account, we prepared an article addressing the subject. To facilitate your reading, we divided our text into the following topics:

  • What is Configuration Management Database (CMDB)?
  • Why Can CMDB Be Important to Your Company’s IT?
  • Benefits that CMDB Can Provide to the IT of Your Business
  • What Are the Challenges to Implementing the Solution?
  • How to Implement CMDB in Your Organization?
  • CMDB and Asset Management
  • Relationship Between CMDB and ITIL 4
  • Learn the Origins of CMDB
  • About senhasegura
  • Conclusion

Check it out now!

  • What is Configuration Management Database (CMDB)?

If you own or manage a company, you need to deal with information regarding the assets required to carry out your operations, which include contracts, computers, vehicles, cell phones, among others. These assets in CMDB are called configuration items (CI).

The configuration management database (CMDB) consists of an IT model focused on the management and organization of these items, as it allows evaluating data such as names, characteristics, and details. In addition, one can store data on the relationship between services and different CIs.

There are four fundamental guidelines among the indications for use of the configuration management database (CMDB). Check it out: 

  • Detect What the Configuration Items Are;
  • Maintain the CIs and Update Them Regularly;
  • Ensure that Only Authorized Users Have Access to the Information;
  • Perform Audits for Data Verification.

In the next topic, we cover the importance of the configuration management database for companies. Keep reading it. 

  • Why Can CMDB Be Important to Your Company’s IT?

The aspects listed below demonstrate why the Configuration Management Database (CMDB) can be important for IT operations:

  • It allows for reducing the redundancy of digital assets and expanding their availability;
  • It enables the reduction of operational and maintenance costs, as it reduces redundancy and increases availability;
  • It allows to quickly detect if there is something inappropriate according to the audit criteria;
  • It allows one to check that all inventory and infrastructure are in agreement, whenever new software or equipment is installed;
  • It is a database that can be accessed by all team members and when a user includes data, the others have access to this update;
  • In organizations that adopt DevOps and Agile, it makes it possible to solve issues related to changes in real-time. 
  • Benefits that CMDB Can Provide to the IT of Your Business

Check out some benefits of the configuration management database (CMDB), which go beyond IT operations and impact the business.

  • More Reliable Systems

With the possibility to identify problems faster and improve all items, the company’s systems will be more reliable. This is because a regular assessment is performed on the incidents and their causes, preventing them from happening again. 

  • Control of IT Configuration Elements

Organizing assets and controlling their use can be exhausting for managers, however, it is often critical to support decision-making. With Configuration Management Database (CMDB), this task can be accomplished more easily, clearly, and effectively. 

  • Possibility of Anticipating Risks

Through the CMDB, one can detect and assess risks before an error becomes irreversible. That is, it allows fault reduction management capable of eliminating or minimizing its impacts.

  • Cost Reduction

The goal of every organization is to profit more, and for that, cost reduction is crucial. A configuration management database (CMDB) allows, for example, to store software licensing data and save unused licenses. It also makes it possible to eliminate investments in equipment that are not useful to the business. 

  • Identifies and Includes Items

This control also allows an organization to detect which assets are outside the IT infrastructure and must be included to achieve better results.

  • Updates and Records Configuration Items

Asset management through CMDB allows one to update and record their current status frequently, ensuring that changes are only carried out when it is actually necessary.

What Are the Challenges to Implementing the Solution?

Deploying a Configuration Management Database (CMDB) in an organization is very important, but it also involves several challenges, such as those listed below:

  • First, it is important to know if the company has any control method with the data of its configuration items. Usually, the sector responsible for accounting has this information;
  • Then, it is necessary to define which assets should be controlled and which characteristics of these items are relevant for registration in this control;
  • The next step is to define which resource will be used in the development of the CMDB, evaluating, among several options, which is the most appropriate;
  • Before using the chosen solution, it is necessary to define how this will be done.

Throughout implementation, other tasks will emerge, but these are the initial challenges. 

  • How to Implement CMDB in Your Organization?

To implement the Configuration Management Database (CMDB), one must go through seven steps. Before that, though, let’s recap what a CMDB is.

In practice, this database allows you to manage service assets, such as SLA contracts, hardware, and software, but is not limited to a type of environment where each data is inserted. A CMDB should enable them to relate in a broader context.

Now, let’s go to the steps that must be covered to implement this solution in your company:

  1. First, it is necessary to develop a logical model of the Service Asset and Configuration Management (SACM) process in order to define its scope of activities. This model should explain the level of the SACM relationship. 

In the case of a basic level, for example, you can create relationships between hardware, software, interfaces, and servers.

However, with SACM, it is possible to track relationships to the level of the workstation.

  1. The next step is to define the configuration items, categorizing what you want to manage based on this logical model. Care must be taken not to make mistakes when trying to execute everything at once. Gradual notes should be taken of everything that needs to be followed up.
  2. Choose a person responsible for each CI and its steps. This person should define what information to gather about these assets and how this should be done.
  3. Then, the CI owners must establish the attributes necessary for their categorization. This information may include name, cost, version number, and location.
  4. The next necessary measure is to understand where to find important information about CIs. For this, it is possible to make use of an automatic discovery tool and visually verify hardware data, such as purchase, invoice, warranty, and serial number documentation.
  5. Map the relationships between the CIs by comparing the actual assets with the model created in the first step. This can also be done manually or through an automatic discovery tool
  6. Finally, implement one asset at a time. When creating or uploading a CI to the CMDB, compare it with your mapping and make sure it is correct before moving on to the next one. 

Creating a CMDB takes time and it depends on your dedication and the number of resources available in your company. However, you may already have a place to start. In this sense, keep in mind that having an active administration is essential to achieving this goal.

  • CMDB and Asset Management

A CMDB brings together IT asset management (ITAM) and configuration management characteristics, but its goal is not the same as that of an ITAM record. The latter focuses on the lifecycle of individual assets, to whom they belong, and where they are located.

The CMDB, on the other hand, goes beyond this concept and allows managing how CIs relate to each other in an IT infrastructure. 

However, these two processes can be integrated and a CMDB can assist ITAM in collecting data on CIs, managing incidents related to them, and reducing risks.

  • Relationship Between CMDB and ITIL 4

Launched in 2019, ITIL 4 contains the best practices for information technology, which prioritize the increase of productivity in the IT sector of a company, to optimize the use of its technological infrastructure.

According to this library, the CMDB has the role of storing configuration records within items such as systems, installations, software, and hardware, and it is up to IT professionals to determine what should be tracked and how this should be done.

Stored data may include classifications such as change history, type, owner, and importance of items, as well as interactions between them.

Items tracked in a configuration management database are known as configuration items and defined by ITIL 4 as “any component that needs to be managed to deliver an IT service”.

In practice, the CMDB must enable effective ITSM processes and the best business decisions, as it allows centralizing data and identifying critical configuration items.

CMDBs allow:

  • Analyzing impacts;
  • Analyzing the root cause;
  • Managing incidents;
  • Managing changes; and
  • Verifying legal compliance.
  • Learn the Origins of CMDB

With the original function of helping to develop controls for IT service management, ITIL was created in the 1980s by the UK government and today has five volumes published. These are:

  • Service Strategy;
  • Service Design;
  • Service Transition;
  • Service Operation; and
  • Continual Service Improvement.

This library allows you to align IT services with the objectives of a business and its standards are updated regularly in order to support procedures and processes in an increasingly efficient way. 

Thus, its latest version was released in 2011, but since the 1980s, its purpose was to create and maintain a database that would allow tracking of IT services.

This means the CMDB concept emerged during this period, becoming necessary for the management of IT services. Despite this, configuration management would only become a process in ITIL in 2000.

In 2007, this process was renamed Service Asset and Configuration Management by ITIL 3. 

Currently, the challenge is to reduce the failure rates in the implementation of a CMDB, which would be 80% according to Gartner Research.

  • About senhasegura

We at senhasegura are committed to digital sovereignty, which we believe is a right of citizens, institutions, and society as a whole. Therefore, our focus is to avoid data theft and allow traceability of administrator actions on networks, servers, databases, and a multitude of devices.

We also help our customers achieve compliance with audit requirements and the most demanding standards, such as Sarbanes-Oxley, ISO 27001, HIPAA, and PCI DSS. Click here and check out the mentions and awards we have received throughout our history.

  • Conclusion

By reading this article, you learned that:

  • The configuration management database (CMDB) consists of an IT model focused on asset management and organization;
  • It also makes it possible to store data on the relationship between services and different CIs;
  • Ii impacts not only the IT teams but the business as a whole;
  • It is important for the reduction of operational and maintenance costs;
  • It allows the company to follow audit parameters;
  • It can be accessed by all members of a work team;
  • It enables to anticipate risks and minimize threats, in addition to identifying missing items;
  • Its implementation involves a series of challenges, such as those listed in topic 4, which include defining how assets will be controlled;
  • We also demonstrated step by step how to implement this solution in your company and differentiate CMDB from an ITAM record;
  • We showed that the CMDB concept emerged at about the same time as the ITIL standards;
  • We revealed that the failure rates in the implementation of the CMDB currently are 80%;
  • Finally, we addressed senhasegura‘s area of expertise.

 

Was our Configuration Management Database (CMDB) article helpful to you? So, share it with someone.

 

ALSO READ IN SENHASEGURA’S BLOG

High Availability: Technology that Guarantees Productivity and Credibility

Invest in Disaster Recovery Strategies and Avoid Damages to Your Company

Why Identity and Access Management is Important for LGPD Compliance

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

You want to know whether a dangerous stranger has your passwords?

We already live in a post-apocalyptic future that has nothing to envy to great franchises like Mad Max or Blade Runner.

Proof of this are pollution, pandemics and the fact that your most intimate secrets can be violated because your most impenetrable slogans are in a database of leaked passwords.

Do you feel that pinch? It’s fear and cruel reality knocking at your door at the same time.

But, well, let’s stand by. Just as Mel Gibson or Harrison Ford would do in their sci-fi plots. Let a hard guy grimace get drawn on your face, adjust your pistol grip and put on comfortable shoes. Help us and help yourself answer this question:

Are you in a database of leaked passwords?

You already know that periodically, the security of large companies that store hundreds of data, including your passwords, is violated with total impunity.

We have repeated it countless times: No one is free from evil because, friends, evil never rests. And on top of that, there are no superheroes for these things.

That is why we will try to guide you to check, in a simple way, whether you and your passwords are in a database of leaked passwords.

That way you will find out whether you are safe or you already have to start thinking about coming up with new and original passwords.

*Remember

No matter how far-fetched and armored it may seem, from time to time you will have to check if it has been leaked. We do not want anyone with bad intentions to use them and take advantage of some of the services you have hired or, directly, steal your information. 

To guide you in this search what we will do is start by checking your emails. We will check whether they are included in some of these databases of leaked passwords. That way we will not only reveal if these have been filtered, but also the rest of the accounts in which you repeat the same username and password over and over again.

Is all this necessary?

Between you and me, it’s easier to memorize a password than to try it with hundreds. That’s why you repeat the same one since your teenage days! Damn it… maybe even since you met messenger and Terra chat. 

But this is a very dangerous thing! If someone has already obtained your old hotmail email and the password you used in it, and that you may continue to use, what they will do is, apart from appropriating your email, is to use that information to enter other platforms or services where you continue to use the same username and password as in that hotmail. 

Once you know whether any of the credentials that you usually repeat have been leaked, you will have in your hand the option to change them both on the site that has been violated and in the rest of the places where you use them. 

How do we do it?

To find out whether the passwords of any of the websites in which you have registered have been violated and filtered, you just have to go to:

haveibeenpwned.com

A portal that is responsible for collecting information from password databases filtered throughout the Internet.

*The page is quite intuitive. It works as a search engine. As the main Google page. So calm down.

Let’s go with a small list of steps to follow:

  1. Enter haveibeenpwned.com.
  2. Go to the main text box. In there type the email account you want to verify. You will be immediately shown the accounts or platforms, linked to it, that have been breached.
  3. If after typing your email and pressing enter, the screen turns green, you are in luck, your email has not been involved in any massive leak.
  4. However, if the screen turns to a maroon shade… Shit! The password linked to that email has been leaked! What’s more, the very attentive page will tell you where. Below you will see a list of websites where you used to enter with that email and where the passwords have been stolen.
  5. Go change passwords! Both from your email and from all the pages that appeared to you. Well, and the rest where you may be using the same username and password that you used with the compromised accounts.

Conclusions

We know it’s a hassle to change passwords every once in a while, but so is it to have your account stolen and impersonate you by putting a horrible profile picture. This among many other unmentionable bad deeds that can be done. Now that you can check whether you’re in one of those leaked password databases, we leave it to you.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

ESET Research reveals the workings of three teams behind TA410 and a new version of FlowCloud, their complex espionage tool

  • TA410 is an umbrella group comprised of three teams ESET researchers named FlowingFrog, LookingFrog and JollyFrog, each with its own toolset and targets.
  • ESET telemetry shows victims all around the world, mainly in the governmental and education sectors.
  • TA410 had access to the most recent known Microsoft Exchange remote code execution vulnerabilities, (e.g., ProxyLogon in March 2021 and ProxyShell in August 2021).
  • ESET researchers found a new version of FlowCloud, a complex and modular C++ RAT used by FlowingFrog with several interesting capabilities, including:
  1. Controlling connected microphones and triggering recording when sound levels above a specified threshold volume are detected.
  2. Monitoring clipboard events to steal clipboard content.
  3. Monitoring file system events to collect new and modified files.
  4. Controlling attached camera devices to take pictures of the compromised computer’s surroundings.

BRATISLAVA, MONTREAL — APRIL 27, 2022 — ESET Research reveals a detailed profile of TA410, a cyberespionage umbrella group loosely linked to APT10, known mostly for targeting US-based organizations in the utilities sector, and diplomatic organizations in the Middle East and Africa. ESET researchers believe this group consists of three different teams using different toolsets, including a new version of FlowCloud discovered by ESET. It is a very complex backdoor with interesting espionage capabilities. ESET will present its latest findings about TA410, including results from ongoing research, during Botconf 2022.

These teams, referred to as FlowingFrog, LookingFrog, and JollyFrog, have overlaps in TTPs, victimology and network infrastructure. ESET researchers also assume that these subgroups operate somewhat independently, but that they may share intelligence requirements, an access team that runs their spearphishing campaigns, and also the team that deploys network infrastructure.

Most TA410 targets are high-profile organizations in the diplomacy and education sectors, but ESET has also identified victims in the military sector, a manufacturing company in Japan, a mining company in India, and a charity in Israel. An element worth mentioning is that TA410 targets foreign individuals in China. According to ESET telemetry, this happened at least twice; for instance, one victim is a French academic, and another is a member of a diplomatic mission of a South Asian country in China.

Since 2018, ESET has seen various targets of TA410, as depicted on the map.

Map of countries and verticals targeted by TA410

Initial access to targets is obtained by exploiting vulnerable internet-facing applications such as Microsoft Exchange, or by sending spearphishing emails with malicious documents. “This indicates to us that their victims are targeted specifically, with the attackers choosing which entry method has the best chance of infiltrating the target,” explains ESET malware researcher Alexandre Côté Cyr. Even though ESET researchers believe that this version of FlowCloud, used by the FlowingFrog team, is still undergoing development and testing, the cyberespionage capabilities of this version include the ability to collect mouse movements, keyboard activity, and clipboard content, along with information about the current foreground window. This information can help attackers understand stolen data by contextualizing it.

FlowCloud can also gather information about things happening around the victim’s computer by taking pictures using connected camera peripherals and recording audio using a computer’s microphone. “This latter function is triggered automatically by any sound over a threshold of 65 decibels, which is in the upper range of normal conversation volume. Typical sound recording functions in cyberespionage malware are triggered either when an action on the affected machine is performed – for instance, when a videoconference app is run – or when a specific command is sent to the malware by its operators,” clarifies Côté Cyr.

TA410 has been active since at least 2018, and was first publicly revealed in August 2019 by Proofpoint in its LookBack blogpost. A year later, the then-new and very complex malware family called FlowCloud was also attributed to TA410.

For detailed technical analysis, read the blogpost “A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity” on WeLiveSecurity, and follow ESET Research on Twitter for the latest news from ESET Research. For YARA and Snort rules, consult ESET’s GitHub account.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

How Does Active Directory Help with Access Management?

Active Directory started with Windows Server due to the convenience of using the same password to perform several activities in a company, such as authenticating on a computer, accessing a system, and opening an email.

In its database, one can store information about domains, organizational units, trust relationships, computer accounts, users, groups, group members, and passwords, among other objects.

This solution brings several other benefits, such as the centralization of security features, the use of a single management point for resources, and the simplification of the search for the desired resource.

In this article, we explain the concept of Active Directory and unravel its advantages, among other countless information. To facilitate your reading, we divided our text into topics:

  • What is Active Directory?
  • What Is the Importance of Active Directory?
  • Benefits of Active Directory
  • Active Directory in Practice
  • How Active Directory Is Structured
  • Functioning of AD in Two Perspectives
  • About senhasegura
  • Conclusion

Follow our text to the end!

  • What is Active Directory?

It is a database and set of services performed on Microsoft Windows Server, whose main purpose is to enable the management of permissions and the control of access to network resources. 

Through this solution, one can store data as objects, including users, groups, applications, and devices, categorizing them according to their names and characteristics.

  • What Is the Importance of Active Directory?

Active Directory is important in many ways. It consists of a directory service that makes it possible to store data about networked objects, making this information available to administrators and users. Also, it is a Microsoft software used in Windows.

It was developed to organize the search for required information in daily activities and centralize this data, and its advantages are availability, security, and performance. In addition, an Active Directory can have multiple domains with different administrators and security policies. That is, administrators do not need to have access to all domains.

In Active Directory:

  • Each user can have only one name to access network resources. Their accounts are stored in the AD database;
  • Users need to log on once to access any network environment;
  • Domains can grow unlimitedly without changing the form of administration;
  • Active Directory-based domains enable centralized management. Data related to accounts, groups, and network resources can be managed in a single environment. 
  • If a company needs to have a single location, Active Directory allows users to have access to all network resources with a single password. 
  • Benefits of Active Directory

Active Directory provides several benefits for users, and we can highlight some of them:

  • Centralization of Security Features

In a single location, one can manage and protect network resources and related security objects. A company can manage AD based on a business model, organizational model, or the types of roles it manages.

This is the case for organizations that manage Active Directory by dividing their users according to the departments in which they work, the physical place where they work, or a combination of both.

Active Directory allows one to manage the security of all network resources and extend interoperability with multiple applications and devices. When this feature is implemented and protected in the right way, it makes it possible to implement a company’s policy and procedures involving cybersecurity, resources, and network services in a detailed manner.

  • Single Management Point for Resources

In AD, network resources are accessed from a single management point. This is because a single logon is used to gain access to network resources located on all servers within the domain.

In practice, the user is identified only once. After that, they connect to access network resources, depending on their roles and permissions. 

  • It Simplifies the Task of Finding the Desired Resource

Active Directory simplifies the task of finding the desired resource as it allows publishing files and print resources to the network. Publishing an object enables network resources to be securely accessed for search in the AC database.

To do this search, the name, location, or description of the object can be used. If you want to search for a shared folder, for example, just use the network in Windows 10 or Microsoft Windows Server 2012 and click the search button.

You can configure the search scope without using the shared folder name and keyword as requirements. 

For more specific results, just provide more information. For example, if you set up the same keyword in multiple folders, a search for the keyword will return many results, which will make it more difficult to find the folder you are looking for.

Suppose you have access to a network with dozens of servers, in which each one has several resources required to perform your activities. In this case, it would be difficult to identify which server provides each resource.

This task can become even more difficult when you have mobile users, who need to locate devices from somewhere else.

  • Trust Relationships Between Various Domains

AD makes it possible to establish efficient management of trust relationships between several domains. That is, a trust relationship can be established between two websites. In this way, one can use the features on both websites with a single username and password.

  • Improved Scalability

Through the concept of organizational units (OUs), Active Directory makes it possible to improve scalability in large companies. An OU consists of a collection of users and computers. 

An organization with large domains can organize them into OUs. For example, a company has a large department that has an administrator managing the domain. In this case, one can create an OU to which all user accounts and computers related to that department can be moved.

  • Multi-Master Replication

This concept is another advantage of an Active Directory environment. In an AD multi-master replication environment, each domain controller contains a copy of the directory. 

When a change is made to AD, the nearest controller will be updated. Other domain controllers in the environment will also update. 

That goes for websites, too. Each website has its domain controller, that is, when a user of a website updates Active Directory, the changes are reflected in it. 

  • Active Directory in Practice

Active Directory consists of an administrator network of the logins responsible for releasing access to resources. Through it, users can access one or several rooms, depending on their needs, with a single login and password, eliminating the need to create numerous accesses. 

It works as a free protocol used to manage information from distributed directories over an IP network, which enables users to access network resources by performing a single logon.

It is organized with the use of domains through a hierarchy, with an administration that is based on the tree and forest concepts, which supports the organization of the domain structure and eliminates the need for individual visits to desktops.

In this context, each domain is equivalent to a maximum administrative unit within the network. The forest would be the “set of trees”, which we cover in more detail in the next topic.

  • How Active Directory Is Structured

Active Directory has the function of storing data about network users and resources in a structure formed by domains, trees, and forests.

When we talk about a domain, we refer to a collection of objects, such as users and devices, that share the AD database. 

A tree, on the other hand, is a collection of domains with a contiguous namespace, which have a common DNS root name.

A forest, in turn, refers to a collection of trees that share the same scheme, global catalog, and directory configuration, without being part of a contiguous namespace. It works as a security limit on a corporate network.

Within a domain, objects can be grouped into organizational units (OUs), which enables administrators to create organizational units that allow them to mirror business, functional, or geographic structures and apply group policies that simplify management. 

  • Functioning of AD in Two Perspectives

The AD operation can be understood through two perspectives: the technical and the user one. Here’s how they differ:

  • Technical Perspective

Generally, data stored in Active Directory encompasses user contact, printer queue, and desktop or network configuration information.

The Active Directory Data Store contains directory data, such as information about users, groups, computers, objects that these users can access, other objects, and network components, allowing full access administration.

Directories are still used to manage software packages, files, and user accounts. The administrator uses the AD tree and forest concepts, which do not require individual visits to desktops.

  • User Perspective

With AD, users can access available resources on the network by logging on once to the local network environment.

When the user enters their login and password, Active Directory confirms the validity of the information to grant authentication. As already mentioned, AD is organized hierarchically through the use of domains. 

  • About senhasegura

Present in 54 countries, we are one of the units of MT4 Tecnologia, a group of companies focused on information security founded in 2001.

Our purpose is to guarantee cybersecurity to the organizations we provide services to, acting on the control of privileged actions and information. In this sense, we avoid problems such as: data leaks and thefts in virtual environments and their consequences for our customers.

We understand digital sovereignty is a right of citizens, organizations, and society, so we work around this goal, believing that applied technology is essential for the promotion of prosperity.

Our job is to address the lifecycle of privileged access management, be it before, during, and after access, considering that machine automation is a current need, as manually managing digital privileges has become an insufficient task. Therefore, we seek to:

  • Avoid interruptions due to expirations and increase the efficiency of organizations;
  • Automatically audit the use of privileges;
  • Automatically audit privileged changes to anticipate detection of privilege abuses;
  • Ensure successful deployments and satisfied customers;
  • Provide advanced PAM capabilities;
  • Provide resources that reduce risks in a fast and advanced way;
  • We also bring companies into compliance with audit criteria and standards such as PCI DSS, Sarbanes-Oxley, ISO 27001, and HIPAA.
  • Conclusion

By reading this article, you saw that:

  • Active Directory came up with Windows Server due to the need to use the same password to perform multiple tasks;
  • AD is a database and set of services that have the main function of enabling the management of permissions and the control of access to network resources;
  • It was created to organize the search for necessary information at work and centralize this data;
  • Through it, users log on once to access any network environment;
  • Active Directory-based domains enable centralized administration;
  • An organization can manage AD based on a business model, organizational model, or the types of roles it manages;
  • Active Directory allows one to find a resource more easily, making it possible to publish files and print resources on the network;
  • Through AD, one can establish trust relationships between several areas;
  • Through the concept of organizational units (OUs), AD allows for improving scalability in large organizations;
  • Active Directory has the function of storing data about network users and resources in a structure formed by domains, trees, and forests;
  • The AD operation can be understood through two perspectives: the technical and the user one;
  • The directories are used to administer software packages, files, and user accounts, among other functions;
  • After a user enters their login and password, Active Directory confirms the information is valid and authenticates.

Did you like our article on Active Directory? Share it with someone else who might be interested in this topic.

ALSO READ IN SENHASEGURA’S BLOG

Common Questions about Privileged Access Management (PAM) Solutions

Multifactor Authentication: How to Benefit from This Security Strategy

My Company Suffered a Ransomware Attack: Should I Pay the Ransom or Not?

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Every Moment Secured on Your Android

Our mobile phones are an undeniable part of our lives in the 21st century. We use them to contact our nearest and dearest, check the news, access the internet, make online purchases and even log into accounts, ideally via multi-factor authentication (MFA). Using MFA can block up to 99% of automated attacks. Undeniably, MFA is important for safe mobile use; however, have you ever thought about which types of MFA are riskiest and why?

Many individuals as well as companies are using call- and SMS-based MFA. It may seem like a great way to authenticate the user. Everyone has a mobile phone they can use to take a secure phone call or receive an SMS. Well, it may not be as straightforward as it seems at first glance.

There are many reasons why you should consider replacing SMS-based MFA:

  • SMS and voice calls are not encrypted. Unfortunately, these are transmitted in cleartext, which makes them more vulnerable to attackers.
  • They are vulnerable to phishing attacks via open source and readily available phishing tools, such as Modlishka.
  • Employees of phone network companies may fall prey to a SIM-swapping attack. They can be tricked into transferring phone numbers to a threat actor’s SIM, allowing attackers to receive MFA codes instead of the victim.
  • Phone service failure. As authentication apps and security keys work offline, SMS needs the phone service to be available. Phone network companies are also exposed to changing regulations, which may also impact the availability of MFA.
  • It is likely that SMS and voice calls are not getting more secure any time soon.

It is not a surprise, then, that in 2020 Microsoft advised its users to stop using SMS- and voice call-based MFA and instead use an authentication app or a hardware key. This by no means suggests that you should completely abandon SMS MFA; it is still better than no MFA. Microsoft itself has kept the option for its users to continue to use SMS-based MFA, proving that it is more secure than not using any form of multifactor authentication.

Keeping Your Mobile Device Secure
If you choose to keep your SMS-based MFA, make sure your mobile device is as secure as it can be. A great way to start is with ESET Mobile Security on your Android mobile devices. It is a solution that ensures security against a multitude of mobile threats while securing users’ data.

ESET Mobile Security aims to provide a safe environment by leveraging its Anti-Phishing feature. It also aims to protect and secure your device from criminal activity using manipulation of users, known as social engineering, into gaining access to sensitive data such as bank account credentials, card numbers, PIN numbers, usernames and passwords.

The feature allows the products to scan its malware and phishing database and determine a website’s security—or not—thus making sure you do not fall prey to a phishing attack. The product’s Anti-Phishing feature integrates with the most common web browsers (Chrome and many others) available on Android devices to provide protection to any and all online activities you desire to carry out.

We recommend you keep Anti-Phishing enabled at all times. All malicious websites, listed in the ESET malware and phishing database, will be blocked and a warning notification will be displayed informing you of the attempted attack.

Other features of ESET Mobile Security include:

  • Antivirus – protection against malware: intercepts threats and cleans them from your device
  • Payment protection – lets you shop and bank safely online
  • App lock – requires extra authentication to access sensitive apps; protects content when you’re sharing a device
  • Anti-Theft – a powerful feature to help protect your phone and find it if it goes missing
  • Network inspector – scans your network and all connected devices to identify security gaps
  • Call filter – blocks calls from specified numbers, contacts and unknown numbers
  • Adware detector – identifies and removes apps that display ads unexpectedly
  • Real-time scanning – scans all files and apps for malware
  • Scheduled scans – checks your device every time you charge it, or whenever you want
  • Security audit – checks an app’s permissions
  • Security report – provides an overview of how secure your device is
  • USB on-the-go scanner – checks any connected USB device for threats
    Up to 5 devices – pay once, protect 5 devices associated with the same Google account

ESET Mobile Security makes your Android phones and devices easy to find and harder to steal, and it helps to protect your valuable data. ESET helps protect the Google Play store and is trusted by millions of users like you around the world, and is dedicated to the online safety and education of children and their parents. Click here to find out more.

If you want to protect your phone with ESET Mobile Security, you’re in luck! From April 25 to May 1, the premium version of ESET Mobile Security will be 50% off. No need for a promotional code; the discount will automatically be added to your checkout! It couldn’t be easier.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

SNMP monitoring: Tips to use the Simple Network Management Protocol

SNMP protocol, whose first version was officially released on 1990 and means Simple Network Management Protocol, is the easiest and simplest way a sysadmin has in order to manage and diagnose problems inside his network devices.

Let’s see what is, how snmp works and why this simple protocol is the essential key for a smooth network environment.

What is SNMP?

In the most general terms, network monitoring means the use of available communication protocols to collect information on the status of communication systems, whether they be routers, land line communications or cell phones. Among them, SNMP raises as the most used monitoring tool.


Do you want to know more about network monitoring?

Remote networks, unified monitoring, intelligent thresholds… discover network monitoring in Pandora FMS Enterprise version.


As we previously said, SNMP works as a mechanism of communication between network devices and a network administrator. Routers, switches, servers, printers…, most of every and each network device supports SNMP protocol. Not only with informative purposes, but also to perform different actions inside those devices (such as remote configuration).

How does SNMP work?

Belonging to the application layer (7th layer of the OSI model), allows communication between network devices. Those known as SNMP agents (request receivers) work in a set of predefined UDP ports, known as SNMP port or SNMP ports. Request receiving port (sent by any available port) is UDP 161 and UDP 162 is used to receive notifications (also known as SNMP trap port).

SNMP protocol works in two different ways: SNMP polls and traps. Polling consists of launching remote queries, either actively or on demand, carrying out operation queries synchronously. Traps, meanwhile, are messages sent by SNMP devices asynchronously, according to changes or events, to configured addresses.

To get the most out of SNMP monitoring, it’s best to use both modes when setting up a monitoring system.

SNMP versions

SNMP currently has three different protocol versions, gathered in different RFCs over time (since first ones on 1988, until today).

Those versions are:

  1. SNMPv1 – defined in RFC 1155, 1156 and 1157, defines the way SNMP works.
  2. SNMPv2 – communication and security improvements of first version. It has two subversions, one on which security is community based (version SNMP2c, RFCs 1901 and 1908), and one on which security is user based (version SNMPv2u, RFCs 1909 and 1910).
  3. SNMPv3 – this third version, which includes and improves security and encryption, has struggled to find a market. The SNMP v3 is defined in RFC 3411 and 3418 and, since 2004, SNMPv3 is known as the actual standard protocol version.

SNMP alerts

Therefore, after knowing how SNMP protocol works, it is clear that one of its main uses are the alerts generated by all devices. Two types can be found in a SNMP monitoring network: synchronous alerts, those requested by an agent SNMP request (known as SNMP polling alerts), and asynchronous alerts, without agent request (known as SNMP traps or snmtraps).

This alert and notification system is the true key of SNMP protocol used in network monitoring tools base their operation of custom alerts. For example, in Pandora FMS we handle a wide range of custom alerts that can be triggered based on these SNMP alerts.

Now lets discuss in more detail what are and how monitoring works based on SNMP polling and SNMP traps.

SNMP trap monitoring

First configure your devices to send traps when specific circumstances are met, and secondly set up a tool that can collect the SNMP traps it receives, whether it be a machine with the necessary services, or a piece of monitoring software. How you configure the SNMP devices will depend on the manufacturer’s model and the device itself, and is carried out from a management interface accesible via a browser and its IP address.

Traps can be received in Linux by using the demon snmptrapd, installed as follows, e.g. on CentOS systems:

# yum install net-snmp-utils net-snmp-libs net-snmp

In our example we’re going to use Pandora FMS to receive and process the SNMP traps. If you already have a Pandora FMS server installed you won’t need any new dependencies, but you’ll have to enable it to receive the traps. Search for snmpconsole in the pandora_server.conf file and enable it as follows:

snmpconsole 1

Once the SNMP traps console is enabled Pandora FMS will be able to receive and process them and display them in the corresponding section:

snmp monitoring

To ensure the incoming traps are arriving correctly, you can consult the corresponding log file, usually at: /var/log/snmptrapd.log.

SNMP trap alerts

Alerts can also be configured via SNMP monitoring for the traps we prepared. In this case they won’t function in the same way as any other module, unlike with SNMP polling, but instead are based on filtering rules. Using these rules we can identify traps belonging to other devices, filter the contents of said trap, OID, etc..

In the next screenshot you can see various alerts created with different filtering options, and actions checking that everything is working fine:

snmp monitoring

SNMP polling monitoring

The protocol works by launching a query against an IP address and requires a specific parameter: the SNMP community string, an alphanumeric chain used to authorize the operation, and which adds an extra layer of security. When an SNMP check is launched against a compatible device, you get a list containing a lot of data that can be difficult to interpret at first:

# snmpwalk –v 1 –c public 192.168.50.14

snmp monitoring

monitorizacion snmp

Each line returned by snmpwalk has an OID (object identifier) and corresponds to a piece of data determined by the device. To better understand what the values returned by the SNMP check are, you can install the system manufacturer’s MIBs (management information base). MIBs are libraries that translate these numeric chains into a legible format allowing us to interpret the data.

Let’s look at some data we’ve got back after executing an SNMP check with the MIBs installed:

snmp monitoring

There are also web sites where you can consult any of these OIDs in case of doubt. If you know the OIDs you want to monitor, you can carry out the query like this by indicating the alphanumeric code that appears after the IP address in question:

monitorizacion snmp

# snmpwalk –v 1 –c public 192.168.1.50 IF-MIB::ifPhysAddress.2

snmp monitoring

Done like this, only the values of the SNMP object queried will be shown, so if you have a monitoring tool the data will be included in the different checks. In this case, we created a basic SNMP monitoring for a few devices using Pandora FMS, and the result is as follows:

snmp monitoring

snmp monitoring

SNMP polling alerts

Once data collection on modules via SNMP polling is being carried out, we can create alerts on Pandora FMS for those modules, executing actions proactively in function of the thresholds we’ve configured, and they work in the same way as any other alerts for any modules on Pandora FMS.

SNMP modules in Pandora FMS

We built Pandora FMS as a flexible monitoring software, capable of monitoring devices, infrastructures, applications, services and business processes. Among them, we have a complete SNMP module.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Protecting small businesses with multiple layers of defense

Post Russia unleashing its attack on Ukraine, there’s a high chance that if you’re working in the cybersecurity sector like me, you’re being asked a series of questions like: Do you think Russia will launch a cyberattack? Should I be worried? What can I do to protect my devices?

These questions are justified as the conflict prompted a series of alerts from government agencies and cybersecurity organizations, setting an expectation of a potentially devastating cyberattack on Ukraine and possibly on those supporting Ukraine. The messages keep coming. More recently on March 21, 2022, the White House issued a Statement by President Biden on our Nation’s Cybersecurity, warning that there is the potential of malicious cyberactivity by Russia against the United States in response to the economic sanctions imposed by western governments.

These messages continue to be broadcast and to encourage maintaining vigilance and ensuring that there are no weaknesses in existing cybersecurity operations and practices. Although the advice is especially targeted at organizations and businesses that fall into the critical infrastructure category, where a disruption can potentially cause chaos as witnessed in the case of Colonial Pipeline, all businesses should take heed and prepare accordingly. Malicious attacks can spread well beyond their intended targets, as has been seen with attacks utilizing the EternalBlue exploit, one of the tools chosen to deliver malicious payloads such as WannaCryptor and NotPetya, which caused unprecedented damage, disruption, and financial loss to victims.

The potential of a zero-day vulnerability being exploited as a cyberweapon is, unfortunately, a real risk. A book authored by Nicole Perlroth, This Is How They Tell Me the World Ends: The Cyberweapons Arms Race, published in February 2021, documents the thriving underground marketplace where governments are often the main customers of zero-day vulnerabilities and exploits.

Having set the scene with the need for preparedness, what technologies and actions should cybersecurity admins at small businesses consider? First, I refer you to an article I published on WeLiveSecurity regarding cyber-resilience and the US’s Cybersecurity and Infrastructure Security Agency (CISA) Shields Up campaign. The advice mentions ESET Dynamic Threat Defense, now known as ESET LiveGuard Advanced, a technology designed to detect zero-day exploits, which should be a priority given that the conflict in Ukraine is ongoing.

ESET LiveGuard Advanced can detect new and previously unknown threats by running them in a cloud sandbox. Detecting threats the first time they are encountered can sometimes demand more processing power and memory than is readily available on employees’ machines. ESET LiveGuard offloads the task of detecting such threats to more powerful machines in the cloud. Once these samples are in the cloud sandbox, they can be subjected to multiple machine learning models and robust detection techniques to classify them as clean, suspicious, or malicious. It’s a zero-day game changer.

Another area of focus should be the reduction of the attack surface to minimize the risk of a bad actor gaining access to your network and identifying a zero-day vulnerability to be exploited either now or in the future. Employee devices typically account for a significant portion of the attack surface, and with hybrid workforces being the new norm, revisiting the policies and technology used to protect endpoint devices will assist with reducing risk. To address the heightened need to protect corporate endpoints with multiple layers of defense, a combined package of protection, such as ESET PROTECT Complete or ESET PROTECT Advanced, is recommended.

If you’re a small business and believe you’re not in danger because you’re not as interesting to bad actors as large enterprises, consider the following statistics. According to ITRC’s 2021 Business Aftermath Report, 58% of small businesses suffered at least one security or data breach, and 44% paid between $250,000 and $500,000 to cover their breach costs.

Just like large enterprises, small businesses handle sensitive data and can become collateral damage from attacks aimed at other targets. Small businesses can also be seen as stepping-stones to attack large enterprises or critical infrastructure business partners. Indeed, no company is too small to be noticed by criminals and, therefore, no company should feel exempt from basic cybersecurity practices.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.