GODMODE DDOS ATTACKS INCREASING

Indian network security researchers have noticed an increase in DDoS attacks from a Windows OS and Windows Explorer vulnerability. The attack allows hackers to deliver a malware payload which spreads across the network to infect other machines, and can be controlled by a Command and Control (CnC) server.

In this case, the malware installs via user access to a malicious website. After checking for compatibility, the malware, as part of its penetration into the system, disables restricted VBScript functionality within the browser. This process; which involves changing the safemode flag within the browser, is also known as the “GodMode” exploit. Once “GodMode” is exploited, the virus is downloaded, then the virus payload connects to a remote CnC server, downloads  additional malware executable files, copies itself into C:WINDOWS, and deletes itself to avoid detection. Once installed, the malware spreads throughout the network, and executes DDoS attacks specified by the CnC server. To avoid this infection, researchers suggest immediately installing the latest system and browser updates.

Would you be able to tell if your network was infected with this attack? Updating your browser and operating system might stop future infection, but what about if the infection has already happened, and the malware is lying in wait? GREYCORTEX MENDEL identifies threats like the one described here because its advanced artificial intelligence and machine learning identify communication between the malware and its CnC server. MENDEL is unique in the industry because it can distinguish malware communication with a CnC server from human communication. MENDEL can also identify the threat through flow analysis. Because it analyzes all network flow data (rather than just a specific profiled flow – like Netflow or IPFIX), its IDS engine can identify the malware’s signature, even though it is encrypted.

To learn more about how GREYCORTEX can help you identify attacks of this nature, contact your IT Security professional, or GREYCORTEX directly. The original research on the attack can be found here: http://blogs.quickheal.com/ddos-attacks-spreading-godmode-exploit-cve-2014-6332/

GREYCORTEX IS A STARTUP TO LOOK FOR IN 2017

Leading European start-up blog “EU-Startups.com” has identified GREYCORTEX as one of “7 Czech Startup to Look For in 2017.” The website, an authority on the European startup ecosystem, has published a list of its selections for leading Czech startups since 2015, and has included well-known companies like Kiwi.com (formerly “Skypicker”) in previous editions. Article author Pavel Curda notes the advanced artificial intelligence, machine learning, and big data analysis components of GREYCORTEX MENDEL which set us apart from other network security products.

Developed after several years of academic and market research, and based on technology which won four US-based NIST Challenges in a row, MENDEL uses artificial intelligence and machine learning tools to identify advanced persistent threats which commonly deployed network security solutions often miss. While several other solutions in the market which claim to focus on meeting advanced threats, MENDEL is unique in that it provides exceptionally deep network visibility, combined with the ability to differentiate between human and machine behavior. This allows IT security teams to spot more threats as they emerge, and take action.

You can read the full article here: http://www.eu-startups.com/2017/02/7-czech-startups-to-look-out-for-in-2017/

NEW VERSION 2.4.1 RELEASED

GREYCORTEX has launched version 2.4.1 of its MENDEL solution. This release adds a couple of new features and several bug fixes to help you better and more efficiently identify threats within your network.
The full list of additional features, improvements, and repairs is provided here:
Features

  • New background report generation with historical download capability
  • Extended IDS signature information with integrated description

Bugs Fixed

  • Fixed DNS cache parameters to improve hostname record display in network flows
  • Fixed system timeout issue during transmission of large reports via email
  • Fixed data update when downloading via proxy server
  • Fixed false positive detection for specific time periods
  • Fixed boundary display in network model
  • Fixed invalid time window in incident management link
  • Fixed data traffic display for selected hosts in graphs displayed on the Peers tab
  • Reduced system load following upgrade, including service restart
  • Fixed issue with IDS service restart after system reboot
  • Fixed database upgrade

GREYCORTEX IS THE NATIONAL WINNER IN THE CESAWARDS 2016

GREYCORTEX won the national round in the Central European Startup Awards (CESAwards) 2016. Subsequently, GREYCORTEX is going to compete with other national winners from CEE that have also shown a promising growth, in the Grand Finale held on the 1st of December, 2016 in Ljubljana, Slovenia.


The Central European Startup Awards is a competition of startup enthusiasts, serial entrepreneurs, investors and ecosystem in ten Central and Eastern European countries.
National Winners 2016: http://centraleuropeanstartupawards.com/national-winners-2016

GREYCORTEX WINS AT CESA 2016

GREYCORTEX took home the top prize in its category at the 2016 Central European Startup Awards (CESA) Grand Finale. The Grand Finale, held on December 1st in in Ljubljana, Slovenia, recognized GREYCORTEX as having the most promising growth ahead of startups from nine other Central European countries including Austria, Poland, and Slovakia.
The Central European Startup Awards is a series of national events in the CEE countries, recognizing and celebrating the entrepreneurial spirit and startup ecosystems of the region. CESA regional winners must first win their category in their home country to be eligible for the regional title. Regional winners, like GREYCORTEX, are automatically shortlisted for the World Startup Awards, held this year in Kuala Lumpur, Malaysia.
A list of CESA Grand Finale Winners in 2016 may be found at: http://centraleuropeanstartupawards.com/cesa-2016-winners

NEW VERSION 2.4 RELEASED

GREYCORTEX has launched version 2.4 of its MENDEL solution. This release features several changes to help you better and more efficiently identify threats within your network. We have added a new incident management feature, as well as new MS-SQL and SIP parsers, multiple false positive elimination in IDS/NBA categories, and support for connecting multiple sensors to one collector. We have enhanced the detection and performance capabilities of our Network Behavior Analysis and Intrusion Detection System engines.
The full list of additional features, improvements, and repairs is below.
Additional Features

  • Added a brand new incident management feature
  • Added MS-SQL and SIP parsers
  • Added multiple false positive elimination in IDS/NBA categories
  • Added support for connecting multiple sensors to one collector
  • Added support for separate modification of IDS signatures per sensor
  • Added dynamic dashboard responsiveness
  • Added support for fail-safe connection and data recovery for remote sensors
  • Added support for deployment in Hyper-V virtualization environment
  • Added license change and renew capabilities
  • Added support for HTTP fields in IPFIX format
  • Added an automatic validity check for ISO installation files

Improvements

  • Highlighted parsed L7 data in flows
  • Improved detection and performance of NBA methods
  • Improved the IDS core engine
  • Optimized Netflow processing up to 100,000 flows per second
  • Improved support for Netflow processing for most Cisco, Mikrotik, HP, and other network devices
  • Improved logging capabilities using syslog-ng
  • Improved the flow searching algorithm for the event detail field
  • Added a cookies field in HTTP parsers
  • Improved time synchronization using ntpd
  • Added a sensor column in network services
  • Tuned NBA method settings for DNS services
  • Improved dashboard descriptions

Bugs Fixed

  • Fixed update planning to avoid updating too frequently
  • Fixed an error in saving flows caused by data truncation
  • Fixed an export issue in CEF format
  • Fixed the filter for ipv6, ipv4 protocols, and tunneled traffic
  • Fixed network model visualization for the selected subnet/host
  • Fixed bigger packet processing
  • Fixed the displaying filter in dashboard component settings
  • Fixed severity for IP addresses in top lists by traffic
  • Fixed searching in false positive management
  • Fixed report generation
  • Fixed event calculation in dashboards
  • Fixed network configuration for setting IP address, network mode, and dns servers
  • Fixed editing network metric limits for hosts
  • Fixed user data export/import
  • Fixed typos in the event status monitor
  • Fixed the license information display
  • Fixed firewall editing rules

Parents Can Help Their Children Explore Online Safely

ESET

Brand new, child-friendly ESET Parental Control for Android app is now available worldwide.

ESET®, a global pioneer in IT security for more than two decades, today announces the global availability of its ESET Parental Control for Android app, which helps parents to protect their children when exploring the online world.

Having a tool to manage what their children do with their tablets and smartphones is important for parents. A survey commissioned by ESET showed that 88% of parents are worried about what their children can access online. In that survey, 81% of parents said that they were troubled by the idea of their child visiting inappropriate web pages; 71% mentioned their children forwarding personal details to strangers; while 61% highlighted excessive amounts of time spent on devices. 

Despite parents’ fears, only few of them have installed a parental control app to help manage their children’s online experiences, the survey revealed.  

Children are increasingly moving from PCs to mobile devices in order to access the internet. Statistics show that Facebook alone has 1 billion active users a month connecting via mobile devices.  And with children, the dominant mobile platform is Android. Gartner forecasts that there will be 1.6 billion Android devices worldwide in 2017 and they are attractive for children due to their lower cost in comparison with other products.

ESET Parental Control for Android app is the answer to parents’ worries. It enables them to be sure that children of all ages can enjoy the wealth of information and entertainment available online without the fear of online threats.  

“ESET Parental Control app for Android safeguards children on smart devices by giving them protection and user experience, without limiting performance,” says Branislav Orlik, Product Manager at ESET.

ESET Parental Control for Android is a child-friendly family protection system which helps parents to build a respectful relationship with their children who use their own smartphones or tablets. Designed to help parents protect their children against internet threats and inappropriate web pages, the app boasts a wealth of child protection features and a friendly user interface.
 

Features include: 

Application Guard: blocks inappropriate content based on the child’s age by default.

Time Management: allows parents to limit the time their child spends playing games and using other apps, even when the child is away from home. 

Web Guard: the app automatically blocks predefined website categories, such as adult or offensive content, based on the child’s age. Additional categories or specific websites can be added too.

Child Locator: allows parents to request the current location of child device at any time.

Parental message: SMS sent from predefined parent numbers will lock the screen of the child’s phone until a read-confirmation button is pressed by the child.

Reports for Parents: detailed reports on app and web page usage. Reports are available to view at any time using parent mode in app; or via my.eset.com or can be sent regularly to parents’ email addresses.

The app contains an added option for children to ask their parents for special permission to access certain apps or web content, or ask for extra gaming or browsing time.

 
“These features make ESET Parental Control a unique application for the Android platform,” concludes Orlik.

ESET Parental Control for Android is available from the Google Play Store, at the my.eset.com portal or via ESET’s partners.  

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Version 2 Limited has partnered with Pulseway to provide solutions for remote monitoring and management

Version 2 Limited has partnered with Pulseway to provide solutions for remote monitoring and management 

Hong Kong, China – Version 2 Limited today announced that it has built up a distribution partnership with Pulseway, the specialist provider of remote monitoring and management solutions founded in Ireland. With Pulseway, enterprises, especially in small and medium-sized business, can remotely monitor and control IT systems from any smartphone or tablet in a secure and convenient way. 

Version 2 Limited offers Pulseway’s products to Hong Kong and Singapore market respectively. Customers will be able to completely control their entire IT infrastructure from mobile platforms in their hands at anytime from anywhere.

For additional information about the Version 2 Limited and Pulseway, visit: https://www.version-2.com/products/pulseway/.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About Pulseway
MMSOFT Design was founded in Dublin, Ireland in 2011 and is a specialist provider of remote monitoring and management solutions. 
Pulseway was launched in 2011 and it has almost 300,000 IT users around the world.
Pulseway Enterprise Server is used by large enterprises including DELL, Louis Vuitton, Northwestern University, Conde Nast and British Columbia Institute of Technology.