Petya最新變種須知

最近發生的全球網路攻擊,ESET將其檢測為Win32/Diskcoder.C,而這再次凸顯出過時的系統和不足的安全解決方案仍然普遍存在。

此次攻擊所造成的損失方面存在著許多疑問,ESET資安專家在這裡為您解答。

該病毒的特點是什麼?

  • 加密:只加密特定副檔名的檔,但也會嘗試加密MBR (Master Boot Record)。
  • 傳播:像蠕蟲一樣,他可以透過網路傳播並感染其他台電腦。
  • 利用漏洞:利用了尚未更新和安裝安全更新的電腦中所存在的漏洞。

是否與WannaCryptor具有同樣強的破壞力?

兩者感染後的後果相同,使用者無法讀取系統中存儲的資料。但Diskcoder.C不僅僅加密漏洞電腦上的檔案,更在系統重啟後,使作業系統無法載入,迫使受害者重新安裝系統。

與WannaCryptor傳播方式相同嗎?

部分相同,但不盡然。雖然兩者都利用了美國國家安全局的漏洞入侵工具-永恆之藍,但Win32/Diskcoder.C還利用了其他傳播技術,通過濫用Microsoft Windows所供Sysinternals工具包中的PsExec等合法工具,以及Windows Management Instrumentation Command-line (WMIC)進行傳播;後者是為運行Windows作業系統的本地或遠端電腦提供的一種資料和功能管理資源。

與Mischa和Petya有何類似之處?

將這三種惡意程式家族歸為一類的主要原因,是因為它們除了加密作業系統之中的檔案資料外,還會通過加密MBR的方式,使作業系統無法運行。除這共通性以外,它們之間再沒多少相同之處,所採用的技術和處理機制各有不同。

該病毒的具體工作原理是什麼?

惡意程式運行後,首先會建立在特定時間之後重啟電腦的排程任務,通常不超過60分鐘。

此外,該病毒還會查看是否存在可以複製自身到共用資料夾或隱藏磁碟區。如果存在,則會利用WMIC在遠端設備上運行惡意程式。

接著,該病毒開始加密含有特定副檔名的檔案。需要強調的是,Win32/Diskcoder.C與多數勒索病毒不同,不會在加密每個檔後修改或添加特定副檔名;後者是攻擊者廣泛運用、區別染毒檔的方式之一。

下圖中,可以看到病毒試圖加密的檔案的副檔名:

此外,該病毒還試圖刪除事件日誌、不留下任何線索,並隱藏其行為。使用上述技巧執行命令列的畫面,如下圖所示:

如何傳播?

如上所述,傳播技術是該病毒的主要特徵。一旦成功感染電腦後,病毒會嘗試提取使用者帳戶和密碼,並配合PsExec和WMIC搜索共用資料夾和隱藏磁碟區,然後在通過電腦網路傳播。借助這種方式,便可感染位於其他國家和海外地區的電腦。

多數情況下,跨國公司團隊在通過同一網路連接位於歐洲或亞洲的其他分公司時,便會受到病毒感染。病毒的傳播機制與蠕蟲相同。

如何防範這一病毒?請參考以下五個建議:

1.使用專業可值得信賴的防毒軟體 (ESET NOD32)

在家用和工作電腦上安裝防毒軟體,確保定期更新系統。需正確配置port,明確開放port及其開放原因 – 尤其是WMI和PsExec所使用的135、139、445和1025-1035 TCP port。

 

2.阻止EXE檔案

在資料夾%AppData%和%Temp%中阻止EXE執行,禁用預設ADMIN$帳戶與Admin$共用資料夾。可以的話禁用SMB v1。

 

3.監測網路狀態

確保網路配置正確、分級管理,時刻檢測網路流量並查找異常行為。

 

4.備份資料

找出電腦上的關鍵資料和資料,做好備份 – 將備份檔案離線儲存。一旦您的電腦不幸感染勒索病毒,可將資料資料回復到近期狀態。

 

5.密碼管理

必須認真管理密碼。如果不同管理中心統一使用同一密碼,一旦其中一台電腦染毒,便可洩露管理員帳戶和密碼,從而可導致整個網路染毒。作為防範措施,最好確保不同團隊和管理中心各自使用不同的密碼。

同時啟用【雙重身份驗證機制】(ESET雙重認證安全)也十分重要,因為它為驗證使用者身份的帳戶密碼提供了一道新增安全屏障。一旦某台設備不幸中毒,便能夠在病毒試圖獲取其他電腦管理許可權之時,阻止病毒在網路內部橫向傳播。

已染毒且無法訪問系統,怎麼辦?

可借助取證技術,嘗試在記憶體中運行另一作業系統,以讀取已加密檔。但除了恢復備份,可以避免重裝作業系統外,再沒有其他更好的解決途徑。

對於此病毒,繳交贖金是沒有任何意義的,ESET近期所作的TeleBots調查結果顯示,攻擊背後的疑似駭客團隊表示,Win32/Diskcoder.C並非常規意義上的勒索病毒。

雖然該病毒加密檔並索要300美元解密贖金,但攻擊者實際想要的效果 – 也正是他們的主要目標 – 就是造成損失。因此,他們竭盡全力,使資料幾乎不可能解密。

此外,該病毒還能夠運用自身惡意程式碼,修改MBR。但這種操作方式本身,使主引導記錄根本無法恢復。攻擊者根本無法提供解密金鑰,同時解密金鑰也無法輸入到勒索介面之中,因為所生成的密碼含有非法字元。

缺乏安全意識、公司教育訓練不足和相關網路安全技能缺乏,是造成檔案被勒索的主要原因之一。不幸的是,許多職員仍未意識到網路攻擊對公司經營帶來的潛在危害,直到淪為受害者、被勒索支付贖金,而此時也為時已晚。由於網路罪犯遇到的防禦水準較低,因此他們更有動力持續利用薄弱環節,開發出新的勒索病毒並成功執行攻擊,造成用戶損失。因此擁有資安危機意識是很重要的,預防措施永遠更勝於後續補救,ESET資安產品及企業解決方案能主動偵測已知(如WannaCryptor、Petya)、未知病毒及勒索軟體,抵禦網路攻擊或資安威脅,協助您打造良好的資安環境。

原文出處: https://www.welivesecurity.com/2017/07/06/everything-need-know-latest-variant-petya/

GREYCORTEX JOINS ESET TECHNOLOGY ALLIANCE

Excellent news from Brno!
GREYCORTEX is proud to announce that we have been named as part of the ESET Technology Alliance. In addition to complimenting ESET’s existing endpoint security solutions – by addressing traffic within the network, this relationship means that GREYCORTEX MENDEL is now available through all ESET partners, worldwide. You can read our full press release below:

GREYCORTEX Joins ESET Technology Alliance

Brno, Czech Republic – GREYCORTEX, advanced network security solutions provider, is happy to announce that it has been named as a part of the ESET Technology Alliance which provides holistic protection against advanced cyber threats. Launched in 2013, the ESET Technology Alliance is an integration partnership that aims to better protect businesses by offering a range of complementary IT security solutions. All members of the ESET Technology Alliance are carefully vetted against a set of established criteria to extend “best-in-class” business protection across IT environments.
Through the ESET Technology Alliance partnership, MENDEL, GREYCORTEX’s network traffic analysis solution, is now available to enterprise customers through all ESET partners. MENDEL uses advanced artificial intelligence, machine learning, and data analysis to detect threats to enterprise, government, and critical infrastructure networks that other network security solutions miss. It is able to offer rapid detection and response to network security teams, but also gives them the security to know that they can efficiently monitor network performance and visualize the entire network up to, and including the application layer.
Providing effective network security is continually evolving. Security analysts need to be able to identify not just threats like viruses, but also advanced persistent threats like malware, RATs, Trojans, and Zero-day attacks. Analysts also need to know that they have full network visibility on every device and application in the network. MENDEL provides complete network visibility and detailed insight into application and network performance, so that security teams can identify threats before they do damage,” said Petr Chaloupka, CEO, GREYCORTEX.
GREYCORTEX compliments ESET’s existing endpoint security solutions, by addressing traffic within the network. “There are never enough layers of security for one’s network infrastructure,” said Jeronimo Varela, Director of Global Sales at ESET. “The GREYCORTEX solution provides an analysis of any behavioral anomalies that may go unnoticed. Moreover, the solution is easily integrated into the infrastructure of businesses of any size and can work not only as a detection or monitoring tool, but also to provide visibility into the  functionality of additional security components.”
For more details about GREYCORTEX’s solution MENDEL, please click here.
More information about the ESET Technology Alliance can be found here.
About GREYCORTEX
Built on a decade of extensive industry and academic experience, GREYCORTEX uses advanced machine learning and data analysis to help protect sensitive data, networks, trade secrets, and reputations. In addition to the ESET Technology Alliance, serves customers in over 14 countries through its own distributor network. In 2016 GREYCORTEX received an investment of 1.3 million USD from Y Soft Ventures, a venture capital arm of leading enterprise office solution provider Y Soft.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security, to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real-time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centers worldwide, ESET becomes the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information visit www.eset.com or follow us on LinkedInFacebook and Twitter.

ESET 企業版防毒軟件獲評滿分 SC Magazine:「我們找不到任何弱點。」

今次的測試從功能、使用說明、性價比、效能、技術支援和易用性共6個方向作出評分,ESET Endpoint Security 獲 SC Magazine 的實驗室研究團隊給予全部滿分。

儘管許多的 I.T. 保安公司聲稱可以應對不斷變化的威脅形勢,但在過去的 25 年裡,很少有廠方一直在開發主動、多層級的安全技術。然而,ESET 結合自動化的機器學習和人類知識,基於超過 25 年的研究經驗,為各種規模的企業和端點平台,提供主動和智能的防護產品。

對於任何業務,特別是中小型企業來說,安全性必須對運營造成最小的干擾,並且必須易於部署和使用。SC Magazine 對 ESET Endpoint Security 給予評語:「管理員選項是我們看過最全面的。它整合了用戶、機器、策略或其他管理層面。您可以從單一控制台中完成所有操作 – 從配置、部署到用戶管理。」

更重要的是,SC Magazine 研究團隊在測試中充份展示了 ESET Endpoint Security 在預防勒索軟件上的能力,例如,測試員嘗試複製感染了 Locky 加密勒索軟件的文件,ESET 在完成粘貼過程前,已成功攔截了惡意軟件。

ESET 商業安全產品經理 Michal Jankech 表示:「ESET Endpoint Security 獲業內專家評為滿分,證明我們為企業提供了優質的產品。企業需要比網絡犯罪分子領先一步。我們為提供整合、完整的解決方案而感到自豪,這些產品能夠提供最全面的預測、預防、檢測和反應功能,從而支援企業現在以及將來必須具備的完整端點安全環境。」

了解 SC Magazine 的完整評論,請點擊 這裡

關於 SC Magazine – 定期透過獨立的產品測試及研究文案,與讀者分享深入、中肯的綜合見解,致力為 I.T. 保安專家能夠為所屬企業作出正確的安全決策。

關於Version 2 Limited
Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。 

MENDEL: SECURITY AND VISIBILITY IN NETWORK MANAGEMENT

Network management is a stressful proposition, comprising not only the administration of the network, but also maintaining its performance, provisioning devices, etc. With the number of devices in a network growing – due in part to IoT within the office and BYOD which come and go frequently, and the risks of advanced persistent malware, the stress is only increasing.

Luckily, GREYCORTEX MENDEL helps reduce the stress of network administration. According to recent studies, 76% of IT Professionals cite lack of visibility as a challenge in addressing issues in their networks. MENDEL offers full network visibility, up to, and including the application layer, without profiling a specific subnet or host. This means that whenever a new device enters the network, or a subnet or host is moved, identifying vulnerabilities or reconnecting appropriate devices is easy to accomplish.
MENDEL also helps network administrators improve their security, especially against advanced threats hiding within a network. It is common to use firewalls, antivirus, but also SIEMs, IPS, sandboxes, etc to protect a network. These various solutions all overlap for layered security, but each can be defeated.
Currently it takes 46 days to detect a network breach. MENDEL steps into these gaps by identifying anomalous network traffic activity, differentiating between human and machine activity, and integrating robust IDS rulesets to identify threats before they can do damage – often within hours. In some cases, like the recent WannaCry ransomware attack, MENDEL was able to identify the attack in a matter of minutes, well before it could start encrypting files.
MENDEL is based on machine learning and big data analysis. It installs in 30 minutes and can be configured in under two hours. It monitors networks using network traffic analysis without slowing traffic. Because deployment is painless, and network speed is preserved, a risk free 30 day trial is truly “risk free.” To find out more about MENDEL, or to see what may be hiding in your network from a 30 day trial, contact your local distributor or GREYCORTEX directly.

WE ARE CESA AWARDS NATIONAL FINALISTS IN 3 CATEGORIES

For the second year in a row, GREYCORTEX has been nominated as a National Finalist at the Central European Startup Awards (CESA) – http://centraleuropeanstartupawards.com. The awards select the best startups from across 10 Central European countries, with the winners qualifying to go forward to the Global Startup Awards.
Last year, GREYCORTEX won Best Early Stage Startup, given in Ljubljana, Slovenia. This year, GREYCORTEX is nominated in three categories:

  • Startup of the Year
  • Best AI Startup
  • Best Newcomer

The Czech winners will be announced at the Czech National Finale on September 25th in Prague. Public voting GREYCORTEX in these three categories is currently open, and may be found here: http://centraleuropeanstartupawards.com/vote

Branded Lifestyle跨國成衣企業擇優部署 ESET NOD32守護資安

時至今日,穿著已是個人風格、品味、審美觀及時尚的表彰,任何人穿上適合自己風格的衣服,都會散發自信光彩及個人獨特魅力,足見服飾其深層價值之意涵。

Branded Lifestyle隸屬香港馮氏集團,是臺灣規模最大的零售服飾品牌集團,目前代理HANG TEN、Arnold Palmer、H:CONNECT、LEO與Roots等五大時尚品牌,擁有超過430家服飾品牌直營門市,藉由跨越不同價格與風格的服飾、配件,為顧客營造愉快購物體驗。例如為熱愛韓流的年輕人,提供H:CONNECT系列產品,針對講求純真簡樸的消費者,則可選擇Roots系列服飾,讓擁有不同喜好的所有顧客,皆能獲得滿足。

最佳防護系統 嚴防客戶資料外洩

Branded Lifestyle為人熟知的競爭優勢,便是擅長嚴選優質服飾品牌,該公司承襲關係企業活用IT的優良基因,懂得善用資訊科技帶動作業效能提升,並抱持精選服飾品牌的同樣精神,所以慎選最佳資訊安全系統,全力守護珍貴的營運數據與龐大客戶個資。

Branded Lifestyle資訊部副總裁趙粵斌指出,早期該公司曾在伺服器或用戶端,部署某知名廠牌端點防毒軟體,以保護大量POS設備;其POS系統架設於Windows伺服器,所有POS設備都與這臺中央伺服器即時連線,進行資料轉換。但這套防毒軟體佔用較大的系統資源,導致POS系統與設備的執行效能,皆受到影響,拖慢日常工作效率;趙副總裁意識到一旦任由此現象持續蔓延,唯恐對公司營運造成衝擊,於是決定壯士斷腕,汰換既有防毒軟體。

「有了先前經驗,我們對於新防毒軟體的首要評選重點,便是不佔用POS系統及設備效能,協助提升整體工作效率」,趙副總裁接著說,該公司據點眾多且分散,所以要求新的防毒軟體須具備中央管理功能,擁有友善的操作介面,提供各種類型資訊報表,方便MIS集中管控,甚至進一步做到跨國管理。再者,新的防毒軟體,必須有能力控管外接式裝置,並廣泛支援Windows(含Server與Client)、MAC OS、Linux與行動作業平臺,藉此交織成為綿密防護網絡,嚴防客戶資料外洩,提高機密資料安全性。在確立篩選標準後,資訊部同仁積極展開評估與測試,發現在多個受測的資安軟體中,唯有ESET NOD32防毒軟體能充分符合所有條件,因而雀屏中選。

選購前,資訊部透過國外第三方防毒測試機構報告已知ESET NOD32防毒軟體表現出色,但還是對多家軟體執行實際測試,結果顯示,ESET NOD32不論在效能或其他方面表現,果然較其他品牌技高一籌,因此最終選定ESET。

輕盈無負擔 跨國好管理

趙副總裁認為ESET 防毒軟體勝出的主因,在於體態輕盈無負擔,幾乎完全不折損系統與設備效能,符合Branded Lifestyle講求提高整體工作效率的初衷,確保即時連線的資料交換作業正常運作,不受任何干擾。產品除擁有輕盈、快速等優勢,還有一個重要特質,便是提供了可涵蓋跨國區域、全臺各縣市的中央管控機制,目前Branded Lifestyle將ESET中央總管理平臺設置在臺灣,監管範圍包括臺灣、香港、韓國與新加坡,藉此保護這個範圍內所有Windows Server/Client、MAC OS、Linux與Android等端點設備。使MIS輕鬆實現集中管理,將公司制定的安全政策,精準迅速地貫注到每個據點,其間完全無需借助任何第三方工具,降低了成本卻能發揮到最高成效。

作業環境好安全 時裝銷售更完美

採用ESET NOD32至今超過兩年光景,已經成為ESET忠實的企業用戶,在這段不算短的時間裡,它始終扮演稱職的守護者,在後臺默默運行,悉心呵護所有Branded Lifestyle員工的作業安全,毫不影響系統及設備效能,讓公司不必經常為了提振效率,斥資升級硬體設備;同時ESET防毒軟體能支援多平台集中控管的特性,同樣有助於公司節省人力管理成本,避免MIS在各據點奔波,此外無需額外增購授權,一體適用於保護多元化平臺系統設備。

隨著多項效益顯現,趙副總裁深覺當初換置防毒軟體的決定,果真恰到好處。依據他個人使用體驗,點出ESET值得推薦的功能:(1) 中央控管系統,可同時控管端點、虛擬系統、郵件伺服器及閘道伺服器等多種設備;(2) 裝置控制功能,能依據廠商、型號、序號及權限,配合中央控管,針對可移除式媒體執行防護,落實統一裝置管理、抵擋USB病毒,及防範未經允許的資料存取;(3) 垃圾郵件過濾及釣魚防護,可協助自動過濾端點垃圾郵件,減少用戶端點擊惡意附檔及釣魚網站,避免威脅入侵。

除了在端點架設防毒軟體及防火牆,Branded Lifestyle尚有多項嚴密措施,包括在郵件伺服器及閘道伺服器建立過濾機制,並與資安廠商保持聯繫,持續討論如何強化威脅預防與處理、及災後修補策略,種種努力,都是為了建構安全無虞的作業環境,選擇並使用專業的資安產品,才能讓同仁無後顧之憂全力打拼,將時裝銷售業務經營得更臻完美。

如何安心上雲,ESET資安專家分享教戰手則

當雲端匯聚越來越多企業應用程式與資訊,駭客對它的關注度也就跟著拉高。根據資安預測報告:前幾大網路安全趨勢中,其中一項就是,針對雲端及虛擬化基礎設施的攻擊將日益增加。

ESET資安專家在Digitimes雲端資安台中研討會的議程裡分析說到,企業上雲面臨的威脅有二,一是內憂,包括員工蓄意取走公司資料、誤傳資料或遺失可攜式裝置,二是外患,包括感染勒索軟體、APT,或雲端系統被入侵;近期引發軒然大波的WannaCry,便算是嚴重的外患之一。

也有不少人詢問,ESET能否防範WannaCry?ESET專家給予肯定答覆,透過ESET網路攻擊防護功能,即使微軟尚未發布更新,亦可主動阻止蠕蟲傳播,另搭配ESET雲端防護系統,毋需更新便能阻止WannaCry。ESET「勒索防護盾」擁有獨特的多重防護核心,搭配LiveGrid雲端技術,可在網際狙殺鏈的各階段主動反擊,阻擋惡軟體攻擊。

企業上雲的威脅,絕對不僅勒索軟體,台灣二版(ESET)亦針對其餘禍患,為企業提供安內攘外方案。譬如藉由ESET進階記憶體防護、LiveGrid及漏洞防護等技術,防禦APT攻擊;利用ESET Secure Authentication雙重認證安全,防止雲端系統被入侵;透過DESlock+資料加密方案,執行完整硬碟加密、檔案或資料夾加密、隨身碟加密、電子郵件加密,縱使員工不慎丟失裝置或外洩郵件帳密、仍可保障資料安全;另提供Safetica DLP方案,降低人為因素(員工有意或無意外傳資料)造成的傷害。

【活動照片】

我要下載議程資料

ESET亞太區總代理  台灣二版(Version 2)
ESET官方網站:www.eset.tw
客服電話:02-7722-6899
技術支援信箱:support@version-2.tw

ESET Endpoint Security 企業版方案榮獲「最佳企業端點防護方案」

ESET Endpoint Security 企業版方案早前,於《Linuxpilot》舉辦的「Linux & OSS 最佳解決方案編輯大選2017」頒獎禮中,榮獲「最佳企業端點防護方案」。

第十五屆「Linux & OSS 最佳解決方案編輯大選2017」旨在為企業用戶提供具權威的 IT 採購指引,使企業的 IT 投資獲得更大回報。編輯認為ESET NOD32得獎原因是在技術創新方面,做到監察軟體不當行為、雲端偵測技術等,而在商業效益方面,達致保護個人資料不被勒索、佔用資源低等功能。

有關「Linux & OSS 最佳解決方案編輯大選2017」詳情,請瀏覽 http://linuxpilot.com/linux-oss-2017

關於Version 2 Limited
Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。 

GREYCORTEX RELEASES MENDEL V 2.6.1

In the newest version of GREYCORTEX MENDEL (2.6.1) we have implemented several new features to improve performance, including a new flow scheme. This new scheme will also store more flow data and metrics. Existing data will be automatically transferred into this new scheme to ensure its continued usability. This data transfer process will run in the background, allowing you to continue to work with new flow data. Depending on the amount of existing flow data, the transfer may take few days, but it will not affect system usability.
We have also added a new DHCP application parser. This means you can now use DHCP data to identify hosts by their hostnames, giving you better knowledge/information about hosts; for better and more effective action.
Additional Features

  • Added new aggregated flow structures and their visualizations to achieve better performance
  • Added an additional severity decision mechanism for outlier detection to better highlight larger anomalies
  • Added a new DHCP application parser
  • Added the capability to display unfinished flows
  • Added an additional metric:  UET – User Experience Time – to network flows

Improvements

  • Improved database query performance
  • Improved the precision of the Round Trip Time and Server Application Response Time metrics computation
  • Optimized the performance of the Peers graph for faster loading
  • Upgraded the database to achieve greater performance
  • Set default log interval in log reporting to 7 days

Bugs Fixed

  • Fixed SMB protocol identification
  • Fixed network services model calculation
  • Removed queries to root DNS servers
  • Fixed missing DNS server configurations, which occurred in rare cases
  • Fixed settings for RX queues in network drivers
  • Fixed timezone usage
  • Fixed filtering issues in Incident Management
  • Fixed data inconsistency between Peers and Hosts graphs
  • Fixed report generation where data fields did not display correctly
  • Fixed hyperscan support on non-Intel architectures
  • Fixed password escaping issue
  • Fixed custom server certificate handling
  • Fixed system monitoring data propagation
  • Fixed DNS server settings
  • Fixed ICMP event and flow pairing
  • Fixed MS-SQL protocol parser
  • Fixed time handling in False Positives for different time zones
  • Fixed color configuration for Port Sweep detection
  • Fixed flows search in Outlier events
  • Fixed issue with duplicate hostnames
  • Fixed flow search in limit events
  • Fixed network configuration calculation
  • Fixed Url Share functionality in the comments field in Incident Management
  • Fixed filtering issue in Incident Management
  • Fixed pagination in Incident Management
  • Fixed issue in Url Share
  • Fixed transfer data calculation in the Peers graph
  • Fixed firewall autoconfiguration when enabling Netflow source
  • Fixed events filtering by name
  • Fixed subnet traffic calculation
  • Fixed allow/deny configuration description
  • Fixed the “To Filter” button in Peers graph
  • Fixed port and service name filtering
  • Fixed other issues related to Incident Management
  • Fixed subnet icons in Events
  • Fixed vulnerability to CVE-2016-2183
  • Fixed empty service description editing
  • Fixed false positives value editing
  • Fixed ICMP flow filtering on services
  • Fixed the assignment of hosts into incorrect subnets
  • Fixed host information display in the Analysis module
  • Fixed invalid DHCP transaction IDs in individual flows
  • Fixed DHCP parsing issues on flows from the DHCP relay
  • Fixed the password warning message when the password is shown as invalid during installation
  • Fixed the event payload display in IDS events
  • Fixed issues with special characters during installation
  • Fixed an issue with filtering port number and service name together
  • Fixed an issue with flow duration calculation
  • Fixed cancel button functionality in Flows view
  • Fixed calculation of the number of subnets in Events
  • Fixed the use of an incorrect filter in subnet to filter function in the Events tab
  • Fixed the filling service in False Positive
  • Fixed traffic information in incident links

“TALES FROM THE MALWARE LAB” IS LIVE!

Following the success of our video describing the WannaCry ransomware, we are happy to announce an ongoing series of YouTube videos: “Tales from the Malware Lab – Powered by GREYCORTEX.” In it, we will leverage our in-house malware lab, complete with the latest version of GREYCORTEX MENDEL to provide useful information about emerging network security threats in an easy-to-follow visual format.

 The videos will provide an overview of each threat’s activity within the network, and visualize these attacks from the network traffic analysis standpoint. We are releasing these videos as a public service to the greater network security community, which will benefit from this video-based approach to malware.

 The first video, addressing the “EternalRocks” malware, is available here: https://youtu.be/vI1lRi5e-SM