MS VULNERABILITIES EXPOSED BY GOOGLE

Google has disclosed the latest of several unpatched flaws in Microsoft software. GREYCORTEX MENDEL’s advanced machine learning and predictive analysis can identify these attacks.
Google’s “Project Zero” team recently disclosed a second unpatched Microsoft Windows security flaw, after Microsoft failed to fix the bug within Google’s set 90 day window. The vulnerability is identified as CVE-2017-0037, and is classed as a “type confusion flaw” in a module of Microsoft Edge and Internet Explorer. This flaw can lead to arbitrary code execution, and be used to crash IE or Edge, and allow hackers to execute code and gain administrator privileges on infected systems.
Advanced hackers may have either already exploited this flaw or they may soon exploit it. Network security solutions like GREYCORTEX that identify anomalous behaviour within your network are especially important in this situation. These solutions mean your IT team can identify malware by its anomalous movement within the network, and identify it as it replicates. GREYCORTEX MENDEL identifies such anomalous behavior, offers deep network visibility, and differentiates between human and machine behavior, meaning you can find infected devices within your network and secure your company’s data and reputation even without relying on Microsoft to fix vulnerabilities in its browsers.

You can read more about the vulnerability here: http://thehackernews.com/2017/02/google-microsoft-edge-bug.html

GREYCORTEX ATTENDS CEE INNOVATORS SUMMIT

The team from GREYCORTEX was selected as one of only five Czech high technology companies to attend the CEE Innovators Summit in Warsaw, Poland on March 27-28 2017. The conference focused on innovation ecosystem in the Visegrad Four (V4) countries – Czech Republic, Slovakia, Poland, and Hungary. It’s purpose was to highlight the need for greater innovation and investment in the V4 Group, and included a signing by the Prime Ministers of each of the four countries of the “Warsaw Declaration” – a statement of intent by each of the V4 countries to undertake the development of an innovative economy in the region.
The event brought together not only government officials, but press, investors, innovators, and other interested groups to the Służewiec Racetrack in Warsaw. At the conference, GREYCORTEX was represented by Pavel M. Chmelař and Milan Kaděra, who presented GREYCORTEX MENDEL, our innovative network security solution based on artificial intelligence and machine learning, which finds network threats that traditional security network security solutions miss.

If you are interested in finding out more about the conference itself, you can find it here: http://ceeinnovatorssummit.pl/en/

Press coverage from the Czech Republic can be found here: http://domaci.ihned.cz/c1-65675460-visegradska-ctyrka-se-ma-stat-rajem-inovaci-premieri-domlouvaji-spolecnou-podporu-vedy-i-start-upu (in Czech)

GREYCORTEX LOOKS FORWARD TO FUTURE COLLABORATION WITH KONICA MINOLTA

Following its inclusion in the Berlin-based global release of Konica Minolta’s new Workplace Hub, GREYCORTEX is looking forward to working with Konica Minolta, in the future, to provide its performance monitoring and advanced network traffic analysis, solutions as an extension of the Konica Minolta Workplace Hub.

Konica Minolta’s newest offering – Workplace Hub – is an innovative new enterprise IT solution, which unifies an organization’s technology into single centralized platform. Designed to future-proof workplaces of every size as they work towards digital transformation, Workplace Hub directly addresses growing IT complexity by providing more efficient and effective management of the disparate array of tools, services, and devices used by modern organizations.

Konica Minolta is one of the leading innovators in the technology sector. We are looking forward to working with them in the future, to offer network performance monitoring and advanced traffic analysis solutions as an additional extension of Workplace Hub. We believe the partnership will be a good fit because of our advanced artificial intelligence, machine learning, and data mining functionality which will help users identify threats to their emerging businesses.” Petr Chaloupka, CEO of GREYCORTEX.
GREYCORTEX MENDEL enables users to monitor their unified network for attacks and also events like poor performance and unauthorized access. MENDEL is based on 10 years of extensive academic research and is designed using the same technology which surpassed all competitors in four consecutive US-based NIST Challenges. Released in 2014, MENDEL is already an integral part of network security at companies like T-Systems, Kiwi.com, and the Czech National Security Authority.

About Konica Minolta Laboratory Europe:

KMLE is the hub where innovative solutions in the field of ICT come to life to transform the next generation of products and services from Konica Minolta. KMLE is the catalyst for development of business opportunities and innovative applications for Digital Workplace, Sensor Information and Automation, Digital Healthcare and Smart Data Systems. As a research organization, KMLE is eager to share innovative projects and ideas with its network of academic and industrial partners.

GODMODE DDOS ATTACKS INCREASING

Indian network security researchers have noticed an increase in DDoS attacks from a Windows OS and Windows Explorer vulnerability. The attack allows hackers to deliver a malware payload which spreads across the network to infect other machines, and can be controlled by a Command and Control (CnC) server.
In this case, the malware installs via user access to a malicious website. After checking for compatibility, the malware, as part of its penetration into the system, disables restricted VBScript functionality within the browser. This process; which involves changing the safemode flag within the browser, is also known as the “GodMode” exploit. Once “GodMode” is exploited, the virus is downloaded, then the virus payload connects to a remote CnC server, downloads  additional malware executable files, copies itself into C:WINDOWS, and deletes itself to avoid detection. Once installed, the malware spreads throughout the network, and executes DDoS attacks specified by the CnC server. To avoid this infection, researchers suggest immediately installing the latest system and browser updates.
Would you be able to tell if your network was infected with this attack? Updating your browser and operating system might stop future infection, but what about if the infection has already happened, and the malware is lying in wait? GREYCORTEX MENDEL identifies threats like the one described here because its advanced artificial intelligence and machine learning identify communication between the malware and its CnC server. MENDEL is unique in the industry because it can distinguish malware communication with a CnC server from human communication. MENDEL can also identify the threat through flow analysis. Because it analyzes all network flow data (rather than just a specific profiled flow – like Netflow or IPFIX), its IDS engine can identify the malware’s signature, even though it is encrypted.
To learn more about how GREYCORTEX can help you identify attacks of this nature, contact your IT Security professional, or GREYCORTEX directly.
The original research on the attack can be found here: http://blogs.quickheal.com/ddos-attacks-spreading-godmode-exploit-cve-2014-6332/

GREYCORTEX IS A STARTUP TO LOOK FOR IN 2017

Leading European start-up blog “EU-Startups.com” has identified GREYCORTEX as one of “7 Czech Startup to Look For in 2017.” The website, an authority on the European startup ecosystem, has published a list of its selections for leading Czech startups since 2015, and has included well-known companies like Kiwi.com (formerly “Skypicker”) in previous editions. Article author Pavel Curda notes the advanced artificial intelligence, machine learning, and big data analysis components of GREYCORTEX MENDEL which set us apart from other network security products.
Developed after several years of academic and market research, and based on technology which won four US-based NIST Challenges in a row, MENDEL uses artificial intelligence and machine learning tools to identify advanced persistent threats which commonly deployed network security solutions often miss. While several other solutions in the market which claim to focus on meeting advanced threats, MENDEL is unique in that it provides exceptionally deep network visibility, combined with the ability to differentiate between human and machine behavior. This allows IT security teams to spot more threats as they emerge, and take action.
You can read the full article here: http://www.eu-startups.com/2017/02/7-czech-startups-to-look-out-for-in-2017/

NEW VERSION 2.4.1 RELEASED

GREYCORTEX has launched version 2.4.1 of its MENDEL solution. This release adds a couple of new features and several bug fixes to help you better and more efficiently identify threats within your network.
The full list of additional features, improvements, and repairs is provided here:
Features

  • New background report generation with historical download capability
  • Extended IDS signature information with integrated description

Bugs Fixed

  • Fixed DNS cache parameters to improve hostname record display in network flows
  • Fixed system timeout issue during transmission of large reports via email
  • Fixed data update when downloading via proxy server
  • Fixed false positive detection for specific time periods
  • Fixed boundary display in network model
  • Fixed invalid time window in incident management link
  • Fixed data traffic display for selected hosts in graphs displayed on the Peers tab
  • Reduced system load following upgrade, including service restart
  • Fixed issue with IDS service restart after system reboot
  • Fixed database upgrade

GREYCORTEX IS THE NATIONAL WINNER IN THE CESAWARDS 2016

GREYCORTEX won the national round in the Central European Startup Awards (CESAwards) 2016. Subsequently, GREYCORTEX is going to compete with other national winners from CEE that have also shown a promising growth, in the Grand Finale held on the 1st of December, 2016 in Ljubljana, Slovenia.
The Central European Startup Awards is a competition of startup enthusiasts, serial entrepreneurs, investors and ecosystem in ten Central and Eastern European countries.
National Winners 2016: http://centraleuropeanstartupawards.com/national-winners-2016

GREYCORTEX WINS AT CESA 2016

GREYCORTEX took home the top prize in its category at the 2016 Central European Startup Awards (CESA) Grand Finale. The Grand Finale, held on December 1st in in Ljubljana, Slovenia, recognized GREYCORTEX as having the most promising growth ahead of startups from nine other Central European countries including Austria, Poland, and Slovakia.
The Central European Startup Awards is a series of national events in the CEE countries, recognizing and celebrating the entrepreneurial spirit and startup ecosystems of the region. CESA regional winners must first win their category in their home country to be eligible for the regional title. Regional winners, like GREYCORTEX, are automatically shortlisted for the World Startup Awards, held this year in Kuala Lumpur, Malaysia.
A list of CESA Grand Finale Winners in 2016 may be found at: http://centraleuropeanstartupawards.com/cesa-2016-winners

NEW VERSION 2.4 RELEASED

GREYCORTEX has launched version 2.4 of its MENDEL solution. This release features several changes to help you better and more efficiently identify threats within your network. We have added a new incident management feature, as well as new MS-SQL and SIP parsers, multiple false positive elimination in IDS/NBA categories, and support for connecting multiple sensors to one collector. We have enhanced the detection and performance capabilities of our Network Behavior Analysis and Intrusion Detection System engines.
The full list of additional features, improvements, and repairs is below.
Additional Features

  • Added a brand new incident management feature
  • Added MS-SQL and SIP parsers
  • Added multiple false positive elimination in IDS/NBA categories
  • Added support for connecting multiple sensors to one collector
  • Added support for separate modification of IDS signatures per sensor
  • Added dynamic dashboard responsiveness
  • Added support for fail-safe connection and data recovery for remote sensors
  • Added support for deployment in Hyper-V virtualization environment
  • Added license change and renew capabilities
  • Added support for HTTP fields in IPFIX format
  • Added an automatic validity check for ISO installation files

Improvements

  • Highlighted parsed L7 data in flows
  • Improved detection and performance of NBA methods
  • Improved the IDS core engine
  • Optimized Netflow processing up to 100,000 flows per second
  • Improved support for Netflow processing for most Cisco, Mikrotik, HP, and other network devices
  • Improved logging capabilities using syslog-ng
  • Improved the flow searching algorithm for the event detail field
  • Added a cookies field in HTTP parsers
  • Improved time synchronization using ntpd
  • Added a sensor column in network services
  • Tuned NBA method settings for DNS services
  • Improved dashboard descriptions

Bugs Fixed

  • Fixed update planning to avoid updating too frequently
  • Fixed an error in saving flows caused by data truncation
  • Fixed an export issue in CEF format
  • Fixed the filter for ipv6, ipv4 protocols, and tunneled traffic
  • Fixed network model visualization for the selected subnet/host
  • Fixed bigger packet processing
  • Fixed the displaying filter in dashboard component settings
  • Fixed severity for IP addresses in top lists by traffic
  • Fixed searching in false positive management
  • Fixed report generation
  • Fixed event calculation in dashboards
  • Fixed network configuration for setting IP address, network mode, and dns servers
  • Fixed editing network metric limits for hosts
  • Fixed user data export/import
  • Fixed typos in the event status monitor
  • Fixed the license information display
  • Fixed firewall editing rules