ESET與谷歌(Google)合作阻止危險惡意軟體

國際資安大廠ESET為全球企業與個人用戶的電腦資訊安全軟體提供商,於10月16日推出Chrome Cleanup,這是一款用於Google Chrome的新型scanner和cleaner,旨在幫助用戶更安全瀏覽網頁。 Chrome Cleanup適用於在Windows平台上的所有Google Chrome使用者。
 
隨著網路攻擊變得越來越複雜和難以發現,瀏覽網頁可能會導致用戶遇到危險的網站,ESET推出的Chrome Cleanup可以避免惡意軟體安裝至設備上。
 
Chrome Cleanup會在檢測到不必要的軟體時,提醒Google Chrome用戶潛在的威脅並提供刪除該軟體的選項給用戶,Chrome Cleanup於後台運行,完成軟體刪除時也會通知用戶。
 
ESET首席技術長Juraj Malcho說:“使用網路對於每個人來說都應該是一個平穩和安全的體驗。 “三十年來,ESET開發了許多安全解決方案,使用戶能夠安全地享受技術和減輕各種網路威脅。 Chrome Cleanup解決了可能對網路用戶體驗產生負面影響的惡意軟體。“
 
※Chrome Cleanup已包含在最新版本的Google Chrome中。
 
 
 
ESET亞太區總代理  台灣二版(Version 2)
ESET官方網站:www.eset.tw
客服電話:02-7722-6899 
技術支援信箱:support@version-2.tw

關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。

台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟體提供商,其 獲獎產品——NOD32防病毒軟體系統,能夠針對各種已知或未知病毒、間諜軟體 (spyware)、rootkits和其他惡意軟體為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲 得了更多的Virus Bulletin 100%獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳 能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事 處,代理機構覆蓋全球超過100個國家。

ESET與谷歌(Google)合作阻止危險惡意軟件

國際資安大廠ESET為全球企業與個人用戶的電腦資訊安全軟件提供商,於10月16日推出Chrome Cleanup,這是一款用於Google Chrome的新型scanner和cleaner,旨在幫助用戶更安全瀏覽網頁。 Chrome Cleanup適用於在Windows平台上的所有Google Chrome使用者。

隨著網路攻擊變得越來越複雜和難以發現,瀏覽網頁可能會導致用戶遇到危險的網站,ESET推出的Chrome Cleanup可以避免惡意軟件安裝至設備上。

Chrome Cleanup會在檢測到不必要的軟件時,提醒Google Chrome用戶潛在的威脅並提供刪除該軟件的選項給用戶,Chrome Cleanup於後台運行,完成軟件刪除時也會通知用戶。

ESET首席技術長Juraj Malcho說:“使用網路對於每個人來說都應該是一個平穩和安全的體驗。 “三十年來,ESET開發了許多安全解決方案,使用戶能夠安全地享受技術和減輕各種網路威脅。 Chrome Cleanup解決了可能對網路用戶體驗產生負面影響的惡意軟件。“

※Chrome Cleanup已包含在最新版本的Google Chrome中。

新聞原文出處:https://www.eset.com/int/about/newsroom/products/eset-works-with-google-to-halt-dangerous-malware/

關於Version 2 Limited
Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、台灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。 

GREYCORTEX MENDEL DETECTS BADRABBIT

GREYCORTEX is happy to report that it is able to detect the BadRabbit ransomware. This ransomware appeared in Eastern Europe (Russia, Ukraine) but has begun to spread across several countries including South Korea, Poland, the Baltic, and regions. It uses an NSA-based exploit known as “EternalRomance” to enter networks and spreads by SMB port.
MENDEL is able to detect this ransomware in two different ways:

  • MENDEL’s integrated ruleset includes a rule specifically detecting the BadRabbit ransomware.
  • Independent from this IDS rule, MENDEL’s advanced artificial intelligence and machine learning detects the ransomware’s anomalous port sweep activity.

This detection capability demonstrates that MENDEL can identify unknown threats before rules are created in rules-based security tools. MENDEL provides network security teams vital extra time to protect their networks.

GREYCORTEX WINS IN POLAND

The success continues for GREYCORTEX. This time, the team was first overall at the Pitch Competition at the 3rd Annual European Cybersecurity Forum held in Krakow, Poland on October 10th and 11th, 2017. The event featured cybersecurity-focused speakers from government and industry across Europe, as well as several from North America.
The Pitch Competition, held on Monday afternoon, as part of the Forum, featured 16 companies from Central and Eastern Europe. As winners, GREYCORTEX received the chance to present MENDEL on the main conference stage to a full audience. The pitch presentation itself focused on the overall costs of data breach – not only in data loss – but in lost business reputation, opportunity, and brand value, demonstrating GREYCORTEX MENDEL’s ability to detect advanced persistent threats in the network, as well as it’s founding – with generous support from YSoft Ventures – and its membership in the ESET Technology Alliance.

以假亂真的攻擊:切勿輕信您所看到的

就在攻擊者們正尋找新的、日益複雜的攻擊手段,逃避防毒軟體檢測機制之時,他們也在不斷改進作案手法,更好地欺騙和蒙蔽用戶,或至少繞開標準IT安全培訓課上所傳授的主要安全技巧。儘管如此,我們不妨更新一步強化自身安全,歸納攻擊者們所採用的策略,這也正是下文將要探討的內容。

首先,攻擊者們通過使用令人信以為真的圖片或納入內嵌框架,將從真實網頁上提取的內容添加進去,大幅改進了釣魚郵件的設計。同時,由於現如今網上字典和翻譯器的方便,攻擊者們可以設法避免在電子郵件中出現語法和拼寫錯誤。

此外,單單查看電郵或短信寄件者的位址是不夠的,因為攻擊者可以借助身份偽裝技術,通過在資訊資料中弄虛作假,仿冒正規機構的身份。同時還有必要特別關注垃圾郵件所包含的連結,因為假冒網站常常隱藏在縮略或合成位址之後,以致於一眼看上去無法顯露其真實目的。即便如此,我們仍然建議並至今認為這一建議始終管用,那就是檢查網頁是否加密,是否使用HTTPS加密協議,以及最重要的,是否具備安全證書。

網路罪犯與加密網站

雖然多數假冒網站使用HTTPS協定,而真實網站(例如社交網站、網上銀行等)是要求通過HTTPS加密頁面輸入使用者密碼的,但這並不意味著攻擊者無法使用加密頁面。實際上他們可以很容易地將網站改造成HTTPS,獲取完全有效的SSL/TLS證書,無需支付任何費用。

要想以假亂真,攻擊者需要能夠註冊與真實網站看上去盡可能一樣的功能變數名稱,並為新網站獲取證書。其中一種途徑就是尋找拼寫方式一致的功能變數名稱,例如用twiitter.com來仿冒twitter.com ,或用rnercadolibre.com來仿冒 mercadolibre.com等。

還記得讓您填寫缺失字母或不完整語句的拼字遊戲嗎?當您快速閱讀的時候,看上去就像是語句完整無誤的一樣。對於很多人來說,在流覽網址的時候,道理是一樣的。

初看上去,如果快速閱讀的話,這裡的例子能夠矇騙不少人。但您只需要仔細觀察網址的寫法,便能洞察其中的奧妙。攻擊者需要做的是註冊不同位址的網站,使之在用戶看來與真實網站無異。這就是他們所採取的同形異義詞攻擊法。

我們看一個例子,你能判斷這個網站是真實還是假冒網站?

此例是研究人員鄭旭東概念證明的一部分,他註冊了網站 https://www.xn--80ak6aa92e.com/。您可以通過火狐流覽器訪問該連結,查看其原理。

實現假冒的方式是使用了非拉丁書寫系統中的通用字元碼,例如古斯拉夫字母或希臘字母。在這些字母中,我們可以找到與拉丁字母表或網址中類似甚至完全相同的字元。由於功能變數名稱編碼系統的存在,可通過將字元碼編譯為更有限字串,並相容網址的綜合編碼系統,可以使用此類字元註冊網址。

例如可以註冊“xn--pple-43d.com”的功能變數名稱,流覽器將其解析為“apple.com”,但實際上是使用了古斯拉夫字母“a”(U+0430)而非ASCII字元“a”(U+0041)。雖然對於流覽器和安全證書而言,兩個字元裸眼看上去一樣,但實際上是兩種不同的字元,因此代表不同的網站。

此類例子數不勝數,例如“tωitter.com”(功能變數名稱編碼系統中為xn--titter-i2e.com)以及“gmail.com”(功能變數名稱編碼系統中為xn--gmil-6q5a.com)等。您甚至可以使用通用字元碼和通過網址編碼系統轉換器,自行創建貌似一致的網址。

許多最新流覽器都有防範此類攻擊的防禦機制,例如,在火狐或Chrome 流覽器中,如功能變數名稱中含有不同編碼系統中的字元,則會顯示其所對應的通用網址編碼而非通用字元碼。

因此在上例中,位址欄會顯示“xn--pple-43d.com”(通用網址編碼格式)而非“apple.com”,同時“tωitter.com”會顯示為“xn--titter-i2e.com”。

儘管如此,為證明概念,鄭旭東設法只利用古斯拉夫中字母表中的字元,註冊了功能變數名稱“apple.com”,規避了流覽器的保護機制,從而使“xn--80ak6aa92e.com”顯示為“apple.com”。

該研究人員還進一步通過亞馬遜獲取該功能變數名稱的TLS證書,使之初看上去足以以假亂真。

但如果我們仔細觀察網址,便能看到它實際為“xn--80ak6aa92e.com”。

雖然在最新版Chrome和Internet Explorer流覽器中已經修復了這一漏洞,但諸如火狐等其他流覽器中仍存在該問題。火狐用戶可以選擇啟用network.IDN_show_punycode選項,以便始終以通用網址編碼格式顯示字串。

即便如此,上例中的gmail.com網站還設法繞過了Chrome的防護機制,通過只使用拉丁字元,但添加了一個特殊拉丁字元方式(ạ—注意a下方的圓點),使流覽器顯示假冒的功能變數名稱。

需要強化防護

每次發現新的釣魚網站或假冒網頁試圖矇騙使用者時,我們都會重複同一建議:核對發件位址、查看頁面連結、確保拼寫正確,最重要的是使用加密連結(即HTTPS)並具有安全證書。

然而隨著網路罪犯應用日益複雜的技術矇騙用戶,這些防範措施已無法提供充分保障。使用HTTPS和證書,對於攻擊者而言並不屬於其考慮範疇,他們的目的是竊取您的帳戶和密碼,又怎麼會在乎是否使用加密連結?

問題是此類技術的運用給了用戶一種虛假的安全感,使其在相信網站安全性的基礎上輸入帳戶密碼,遵循令人作嘔一般反復強調的安全建議,查看網址前是否有加密鎖圖示,是否為HTTPS連結。但現實中這些措施均無法提供充分的安全保障。

正是由於這一原因,除密切觀察電郵和網站地址之外,我們還建議您仔細查看安全證書,避免訪問電郵中所給出的網址連結(更好的方式是手工輸入網址或通過可信直接連結訪問),並通過使用雙重身份驗證機制(ESET雙重認證安全),為您的帳戶密碼增添一道附加防護屏障。

ESET雙重認證安全(SECURE AUTHENTICATION):

提供公司網路與資料安全、易用的遠端連線雙重認證功能,其採用一次性雙重密碼認證機制(2FA-OTP),密碼隨機而成無法預測或重覆使用,可廣泛搭配各類VPN應用與商業工具,包含Microsoft Sharepoint與Microsoft Dynamics CRM等,透過登錄遠程桌面或VMware Horizon View,大幅提高外出辦公時遠端連線至公司設備瀏覽機密資料的安全性。

原文出處: https://www.welivesecurity.com/2017/07/27/homograph-attacks-see-to-believe/

MENDEL 2.8 RELEASED

We are happy to announce the latest version of GREYCORTEX MENDEL. Version 2.8 includes three new important features: the first is the Event Collector. Released as part of v2.7 (a limited release), the Event Collector offers the opportunity to centrally monitor events from several remote GREYCORTEX MENDEL collectors. The second major new feature is the Correlation Engine. This tool correlates individual, less-serious events – which together may be indicative of attacks within the network, to more effectively alert security analysts. Finally, MENDEL 2.8 includes proxy pairing functionality which identifies source or destination addresses hidden by proxy servers, which will allow security analysts to better identify potential issues on the network and provide even greater visibility.
New Features

  • Added a beta version of the Correlation Engine, including seven tuned rules which further increase security (The feature may be turned on by going to Settings->System Components)
  • Added a proxy pairing feature to display source or destination addresses hidden by a proxy server

Improvements

  • Optimized the display of charts and tables in the Network module
  • Added information about the type of key exchange algorithms in HTTPS and TLS flows
  • Improved the calculation of flow metrics to show values valid for specific parts

Bug Fixes

  • Fixed issues with disabling deep packet inspection and enabling rules in IDS
  • Fixed an issue with updates to older installations
  • Fixed issues with MS-SQL protocol parsing at higher speeds
  • Fixed an issue with displaying current values on the Network Services tab
  • Fixed an issue with displaying multiple VLAN IDs in a single flow
  • Fixed issues with parsing SMB flows
  • Fixed issues with editing export definitions
  • Fixed an issue with pagination results in the Peers graph
  • Fixed issues with restarting services
  • Fixed an issue with filtering by protocol type
  • Fixed an issue with deleting user-defined filters
  • Fixed an issue with saving user-created or user-defined filters
  • Fixed an issue with displaying VLAN statistics in the Analysis module
  • Fixed an issue with exporting records in CEF and Syslog formats
  • Fixed an issue with long hostnames
  • Fixed issues with calculating the minimum and maximum duration of flows
  • Fixed link formatting in Exports
  • Fixed an issue with displaying ASN names in flows
  • Fixed an issue with displaying host information in the Analysis module
  • Fixed the calculation of RTT and ART metrics in long term flows with unfinished communication
  • Fixed an issue with the validation of row counts in Column Manager

GREYCORTEX WINS AGAIN AT CESA 2017

GREYCORTEX took home the top prize in its category at the Czech Finals of the 2017 Central European Startup Awards (CESA). The Czech final,  held on September 25th in Prague, recognized GREYCORTEX as the Best AI Startup in the country.
The Central European Startup Awards is a series of national events in the CEE countries, recognizing and celebrating the entrepreneurial spirit and startup ecosystems of the region. Having been successful in the AI Startup category in the Czech Republic, GREYCORTEX now competes in the Regional Finals, to be held in Sofia Bulgaria on November 23rd. GREYCORTEX was successful at least year’s Regional Final, winning “Best Newcomer” in Ljubljana, Slovenia.
A list of CESA Czech Winners in 2017 may be found at: http://centraleuropeanstartupawards.com/season-2017/czech-republic-national-winners

Petya最新變種須知

最近發生的全球網路攻擊,ESET將其檢測為Win32/Diskcoder.C,而這再次凸顯出過時的系統和不足的安全解決方案仍然普遍存在。

此次攻擊所造成的損失方面存在著許多疑問,ESET資安專家在這裡為您解答。

該病毒的特點是什麼?

  • 加密:只加密特定副檔名的檔,但也會嘗試加密MBR (Master Boot Record)。
  • 傳播:像蠕蟲一樣,他可以透過網路傳播並感染其他台電腦。
  • 利用漏洞:利用了尚未更新和安裝安全更新的電腦中所存在的漏洞。

是否與WannaCryptor具有同樣強的破壞力?

兩者感染後的後果相同,使用者無法讀取系統中存儲的資料。但Diskcoder.C不僅僅加密漏洞電腦上的檔案,更在系統重啟後,使作業系統無法載入,迫使受害者重新安裝系統。

與WannaCryptor傳播方式相同嗎?

部分相同,但不盡然。雖然兩者都利用了美國國家安全局的漏洞入侵工具-永恆之藍,但Win32/Diskcoder.C還利用了其他傳播技術,通過濫用Microsoft Windows所供Sysinternals工具包中的PsExec等合法工具,以及Windows Management Instrumentation Command-line (WMIC)進行傳播;後者是為運行Windows作業系統的本地或遠端電腦提供的一種資料和功能管理資源。

與Mischa和Petya有何類似之處?

將這三種惡意程式家族歸為一類的主要原因,是因為它們除了加密作業系統之中的檔案資料外,還會通過加密MBR的方式,使作業系統無法運行。除這共通性以外,它們之間再沒多少相同之處,所採用的技術和處理機制各有不同。

該病毒的具體工作原理是什麼?

惡意程式運行後,首先會建立在特定時間之後重啟電腦的排程任務,通常不超過60分鐘。

此外,該病毒還會查看是否存在可以複製自身到共用資料夾或隱藏磁碟區。如果存在,則會利用WMIC在遠端設備上運行惡意程式。

接著,該病毒開始加密含有特定副檔名的檔案。需要強調的是,Win32/Diskcoder.C與多數勒索病毒不同,不會在加密每個檔後修改或添加特定副檔名;後者是攻擊者廣泛運用、區別染毒檔的方式之一。

下圖中,可以看到病毒試圖加密的檔案的副檔名:

此外,該病毒還試圖刪除事件日誌、不留下任何線索,並隱藏其行為。使用上述技巧執行命令列的畫面,如下圖所示:

如何傳播?

如上所述,傳播技術是該病毒的主要特徵。一旦成功感染電腦後,病毒會嘗試提取使用者帳戶和密碼,並配合PsExec和WMIC搜索共用資料夾和隱藏磁碟區,然後在通過電腦網路傳播。借助這種方式,便可感染位於其他國家和海外地區的電腦。

多數情況下,跨國公司團隊在通過同一網路連接位於歐洲或亞洲的其他分公司時,便會受到病毒感染。病毒的傳播機制與蠕蟲相同。

如何防範這一病毒?請參考以下五個建議:

1.使用專業可值得信賴的防毒軟體 (ESET NOD32)

在家用和工作電腦上安裝防毒軟體,確保定期更新系統。需正確配置port,明確開放port及其開放原因 – 尤其是WMI和PsExec所使用的135、139、445和1025-1035 TCP port。

 

2.阻止EXE檔案

在資料夾%AppData%和%Temp%中阻止EXE執行,禁用預設ADMIN$帳戶與Admin$共用資料夾。可以的話禁用SMB v1。

 

3.監測網路狀態

確保網路配置正確、分級管理,時刻檢測網路流量並查找異常行為。

 

4.備份資料

找出電腦上的關鍵資料和資料,做好備份 – 將備份檔案離線儲存。一旦您的電腦不幸感染勒索病毒,可將資料資料回復到近期狀態。

 

5.密碼管理

必須認真管理密碼。如果不同管理中心統一使用同一密碼,一旦其中一台電腦染毒,便可洩露管理員帳戶和密碼,從而可導致整個網路染毒。作為防範措施,最好確保不同團隊和管理中心各自使用不同的密碼。

同時啟用【雙重身份驗證機制】(ESET雙重認證安全)也十分重要,因為它為驗證使用者身份的帳戶密碼提供了一道新增安全屏障。一旦某台設備不幸中毒,便能夠在病毒試圖獲取其他電腦管理許可權之時,阻止病毒在網路內部橫向傳播。

已染毒且無法訪問系統,怎麼辦?

可借助取證技術,嘗試在記憶體中運行另一作業系統,以讀取已加密檔。但除了恢復備份,可以避免重裝作業系統外,再沒有其他更好的解決途徑。

對於此病毒,繳交贖金是沒有任何意義的,ESET近期所作的TeleBots調查結果顯示,攻擊背後的疑似駭客團隊表示,Win32/Diskcoder.C並非常規意義上的勒索病毒。

雖然該病毒加密檔並索要300美元解密贖金,但攻擊者實際想要的效果 – 也正是他們的主要目標 – 就是造成損失。因此,他們竭盡全力,使資料幾乎不可能解密。

此外,該病毒還能夠運用自身惡意程式碼,修改MBR。但這種操作方式本身,使主引導記錄根本無法恢復。攻擊者根本無法提供解密金鑰,同時解密金鑰也無法輸入到勒索介面之中,因為所生成的密碼含有非法字元。

缺乏安全意識、公司教育訓練不足和相關網路安全技能缺乏,是造成檔案被勒索的主要原因之一。不幸的是,許多職員仍未意識到網路攻擊對公司經營帶來的潛在危害,直到淪為受害者、被勒索支付贖金,而此時也為時已晚。由於網路罪犯遇到的防禦水準較低,因此他們更有動力持續利用薄弱環節,開發出新的勒索病毒並成功執行攻擊,造成用戶損失。因此擁有資安危機意識是很重要的,預防措施永遠更勝於後續補救,ESET資安產品及企業解決方案能主動偵測已知(如WannaCryptor、Petya)、未知病毒及勒索軟體,抵禦網路攻擊或資安威脅,協助您打造良好的資安環境。

原文出處: https://www.welivesecurity.com/2017/07/06/everything-need-know-latest-variant-petya/

GREYCORTEX JOINS ESET TECHNOLOGY ALLIANCE

Excellent news from Brno!
GREYCORTEX is proud to announce that we have been named as part of the ESET Technology Alliance. In addition to complimenting ESET’s existing endpoint security solutions – by addressing traffic within the network, this relationship means that GREYCORTEX MENDEL is now available through all ESET partners, worldwide. You can read our full press release below:

GREYCORTEX Joins ESET Technology Alliance

Brno, Czech Republic – GREYCORTEX, advanced network security solutions provider, is happy to announce that it has been named as a part of the ESET Technology Alliance which provides holistic protection against advanced cyber threats. Launched in 2013, the ESET Technology Alliance is an integration partnership that aims to better protect businesses by offering a range of complementary IT security solutions. All members of the ESET Technology Alliance are carefully vetted against a set of established criteria to extend “best-in-class” business protection across IT environments.
Through the ESET Technology Alliance partnership, MENDEL, GREYCORTEX’s network traffic analysis solution, is now available to enterprise customers through all ESET partners. MENDEL uses advanced artificial intelligence, machine learning, and data analysis to detect threats to enterprise, government, and critical infrastructure networks that other network security solutions miss. It is able to offer rapid detection and response to network security teams, but also gives them the security to know that they can efficiently monitor network performance and visualize the entire network up to, and including the application layer.
Providing effective network security is continually evolving. Security analysts need to be able to identify not just threats like viruses, but also advanced persistent threats like malware, RATs, Trojans, and Zero-day attacks. Analysts also need to know that they have full network visibility on every device and application in the network. MENDEL provides complete network visibility and detailed insight into application and network performance, so that security teams can identify threats before they do damage,” said Petr Chaloupka, CEO, GREYCORTEX.
GREYCORTEX compliments ESET’s existing endpoint security solutions, by addressing traffic within the network. “There are never enough layers of security for one’s network infrastructure,” said Jeronimo Varela, Director of Global Sales at ESET. “The GREYCORTEX solution provides an analysis of any behavioral anomalies that may go unnoticed. Moreover, the solution is easily integrated into the infrastructure of businesses of any size and can work not only as a detection or monitoring tool, but also to provide visibility into the  functionality of additional security components.”
For more details about GREYCORTEX’s solution MENDEL, please click here.
More information about the ESET Technology Alliance can be found here.
About GREYCORTEX
Built on a decade of extensive industry and academic experience, GREYCORTEX uses advanced machine learning and data analysis to help protect sensitive data, networks, trade secrets, and reputations. In addition to the ESET Technology Alliance, serves customers in over 14 countries through its own distributor network. In 2016 GREYCORTEX received an investment of 1.3 million USD from Y Soft Ventures, a venture capital arm of leading enterprise office solution provider Y Soft.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security, to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real-time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centers worldwide, ESET becomes the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information visit www.eset.com or follow us on LinkedInFacebook and Twitter.