Skip to content

Monitoring security architecture

Introduction

Do an exercise, ask five IT technicians -of any profile- what SNMP means.. If you’re close with them the better, so that the first thing they do is not go to Wikipedia to boast. Hopefully, they might tell you what they said to me when I was working in networks.

“Security is Not My Problem”

Taking into account that the SNMP protocol is one of the monitoring bases, and a system that has been in use for more than thirty years, this answer, “Security is Not My Problem”, sums up the current monitoring situation quite well: ignorance, laziness and lack of interest in monitoring security.

By the way, we talked about SNMP in another article on our blog and I will give you a teaser in advance, it means Simple Network Management Protocol and it comes from 1987.

Considering that monitoring is “key to the kingdom”, since it allows access to all systems and even access many times with administration credentials, shouldn’t we take security a little more seriously when we talk about it?

Recent vulnerabilities in well-known monitoring systems such as Solarwinds or Centreon make the need to take security seriously in the implementation of monitoring systems increasingly urgent, since these have a very strong integration with systems.

In many cases, security problems are not so much about one piece of software being much safer than another, but about poor configuration and/or architecture. It must be taken into account that a monitoring system is complex, extensive, and in general, it is highly adapted to each organization. Today it was Solarwinds, tomorrow it could be Pandora FMS or Nagios.

No application is 100% secure, nor is any corporate network secured against intrusion, whatever the type. This is an increasingly evident fact and the only thing that can be done about it is to know the risks and assume which ones you can take, which ones absolutely not, and work on the latter.

Safe monitoring architecture

It is essential to keep in mind at all times that a monitoring system contains key information for a possible intruder. If monitoring falls into the wrong hands, your system will be compromised. That is why it is so important to devote time to the architecture of your monitoring system, whatever it may be.

Carry out a first analysis, collecting the requirements and scope of your monitoring strategy:

  • Identify what systems you are going to monitor and catalogue their security levels.
  • Identify which profiles will have access to the monitoring system.
  • Identify how you will obtain information from those systems, whether through probes/agents or remote data.
  • Identify who is responsible for the systems you are going to monitor.

The architecture of a system will have, whatever the chosen software, the following elements and will have to take into account its network topology, its resources and the way to protect them properly:

  1. Information display interface (web console, heavy application).
  2. Data storage (usually a relational database).
  3. Information collectors (intermediate servers, pollers, collectors, etc.).
  4. Agents (optional).
  5. Notification system (alerts, notices, etc.).

Monitoring system securing

No matter how correct the implementation of a system, its architecture and its design as a whole is, if one of the elements that make it up is violated, the damage it may suffer by a malicious attack compromises the entire structure. For this reason, in security there is a saying, “Security is a chain and your real security always depends on its weakest point.”

This list of security concepts applied to the architecture of a monitoring system can be summarized as the features that a monitoring product must have to ensure maximum security in an implementation:

  • Encrypted traffic between all its components.
  • High availability of all its components.
  • Integrated backup.
  • Double access authentication.
  • Delegated authentication system (LDAP, AD, SAML, Kerberos, etc.).
  • ACL and user profiling.
  • Internal audit.
  • Password policy.
  • Sensitive data encryption.
  • Credential containers.
  • Monitoring of restricted areas/indirect access.
  • Installation without superuser.
  • Safe agent/server architecture (passive).
  • Centralized and distributed update system.
  • 24/7 support.
  • Clear vulnerability management policy by the manufacturer.

Monitoring infrastructure basic securing

The management console, monitoring servers and other elements should never be on an accessible public network. The console should always be protected on an internal network, protected by firewalls and, if possible, on a network independent from other management systems.

The operating systems that host the monitoring infrastructure should not be used for other purposes: for example, to reuse the database for other applications, nor the base operating systems to run other applications.

Safe and encrypted traffic

You should make sure that your system supports SSL/TLS encryption and certificates at both ends at all levels: user operation, communication between components or sending data from the agent to the servers.

If you are going to use agents in unsafe locations, it is highly recommended that you force all external agents to use certificate-based authentication at both ends, to avoid receiving information from unauthorized sources and to prevent information collected by agents to not travel transparently.

On the other hand, it is very important for you to activate encryption on your web server to provide an encrypted administration console and prevent any attacker from seeing access credentials, remote system passwords or confidential information.

Full High Availability

For all elements: database, servers, agents and console.

Integrated backup

The tool itself should make this as easy as possible, as settings and data are often highly distributed and consistent backup is complex.

Clear vulnerability management policy by the manufacturer

Every day, dozens of independent auditors test the strengths and weaknesses of all kinds of business applications. They seek to gain a foothold in the sector by publishing an unknown ruling to increase their reputation. Many clients, as part of their internal security management processes, execute external and internal security audits that target their IT infrastructure.

Be that as it may, all products have security flaws, the question is: how are those flaws handled? Transparency, diligence and communication are essential to prevent customers from having problems derived from vulnerabilities in the software they use. It is essential that there is a clear policy in this regard, so that it is known which public vulnerabilities have been reported, when they have been corrected and if a new one is detected, the steps to follow for notification, mitigation and distribution to the end customer.

Dual authentication system

Pandora FMS has an -optional- system based on google authenticator that allows forcing its use for all users for security policies. This will make user access to the administration console much safer, preventing that due to privilege escalation the system can be accessed as administrator, which is, at best, the highest risk that can be run.

Delegated authentication system

Complementary to the previous one, you can delegate management console authentication to authenticate against LDAP, Active Directory, or SAML. It will enable a centralized access management, and combined with the double authentication system your access will become much safer.

ACL and user profiling

Identify and assign different users to specific people. Do not use generic users, assign only the necessary permissions and do not use “super administrators”. They are good practices not only for monitoring tools but for any business software implementation with access to sensitive information.

Nowadays, any professional tool to define an access profile for each user will do so in such a way that no user has “absolute control”, but only has the minimum required access to their functions.

Internal audit system

You must have a system in place to record all user actions, including information on altered or deleted fields. Said system must be able to be exported abroad so that not even the administrator user can alter said records.

Password policy

A basic element that allows you to enforce a strict password management policy for access to application users: minimum password size, password type, their reuse, forced change once in a while, etc.

Sensitive data encryption

The system must allow the most sensitive data to be stored encrypted and safely, such as access credentials, monitoring element custom fields, etc. Even if the system itself contains the encryption “seed”, it will always be much more difficult for a potential attacker to access this information.

Credential containers

Or an equivalent system for the administrator to delegate credential use to other users who use said credentials to monitor elements without seeing the passwords contained in the container.

Restricted area monitoring

In these systems, information will be collected remotely by a satellite server and will be available to be collected from the central system (in Pandora FMS through a specific component called Sync server). That way, data can be collected from a network without access to the outside, ideal for very restrictive environments where the impact is drastically reduced if an attacker takes over the system.

Agent remote management locking system

For critical security environments, where the agent cannot be remotely managed once it is configured. This is especially critical in monitoring, since if a system is compromised and its administration is accessed, by the way the system is configured itself, it will have access to all systems from where it receives information. In critical systems, the remote management capacity must be deactivated, even if that makes administration more tricky. The same applies to automatic updates on the agent.

Design of safe architecture for communication with agents

Sometimes known as passive communication. That way, agents will not listen to a port nor have remote access from the console. They are the ones who will connect to the central system to ask for instructions.

Installation without root

Pandora FMS can be installed in environments with custom paths without running with root. In some banking environments, it is a requirement that we meet.

Notification and reporting system (alerts, notices, etc.)

A monitoring system is only useful if it shows accurate information when it is needed. Alert or weekly report reception is the culmination of all the previous work and for that you will have to take into account some “obvious” points that are often overlooked. Protect those systems, wherever they may be.

Periodic updates

All manufacturers now distribute regular updates, which include both bug fixes and security problems. In our case, we publish updates approximately every five weeks. It is essential to update systems as soon as possible, because when a vulnerability is reported, product managers ask external security researchers who have reported the bug, not to publish anything about the vulnerability until a patch is published. Once the patch is published, the researcher will publish the information in more detail as wished, a fact that can be used to exploit and attack non-updated software versions.

Pandora FMS has a vulnerability disclosure public policy as well as a public catalog of known and reported vulnerabilities. Our policy has maximum transparency and full communication with security researchers, always to mitigate the impact of any security problem and to be able to protect our clients as a top priority.

24/7 support

In our support, the technician who answers the phone has the whole team backing him up. If there is a security issue and a security patch has to be published within hours. We not only have the technology to spread the patch to all our customers, but also the team to develop it in record time.

Base system securing

Hardening or system securing is a key point in the global security strategy of a company. As manufacturers, we issue a series of recommendations to carry out a safe installation of all Pandora FMS components, based on a standard RHEL7 platform or its equivalent Centos7. These same recommendations are valid for any other monitoring system:

Hardening checklist for monitoring base system:

  • System access credentials.
  • Superuser access management.
  • System access audit.
  • SSH securing.
  • Web server securing.
  • DB server securing.
  • Server minimization.
  • Local monitoring.

Access credentials

To access the system, nominative access users will be created, without privileges and with access restricted to their needs. Ideally, the authentication of each user should be integrated with a double authentication system, based on token. There are free and safe alternatives such as Google Authenticator that can be easily integrated into Linux, although outside the scope of this guide. Seriously consider its use.

If it is necessary to create other users for applications, they must be users without remote access (for this, it is necessary to deactivate their Shell or some equivalent method).

Superuser access through sudo

In the event that certain users must have administrator permissions, SUDO will be used.

Base system access audit

It is necessary to have the security log /var/log/secure active and monitor those logs with monitoring (which we will see later).

By default CentOS has this enabled. If not, just check the /etc/rsyslog.conf or /etc/syslog.conf file.

We recommend you to take the logs from the audit system and collect them with an external log management system. Pandora FMS can do it easily and it will be useful to set alerts or review them centrally in case of need.

SSH server securing

The SSH server allows you to remotely connect to your Linux systems to execute commands, so it is a critical point and must be secured by paying attention to the following points:

  • Modify default port.
  • Disable root login.
  • Disable port forwarding.
  • Disable tunneling.
  • Remove SSH keys for remote root access.
  • Investigate the source of keys for remote access. To do this, look at the content of the file /home/xxxx/.ssh/authorized_keys and see which machines they are from. Delete them if you think there shouldn’t be any.
  • Establish a standard remote access banner that clearly explains that the server is a private access server and that anyone without credentials should log out.

MySQL server securing

Listening port. If MySQL server has to provide service to the outside, just check that the root credentials are safe. If MySQL only gives service to an internal element, make sure that it only listens on localhost.

Web server securing

We will modify the configuration to hide the Apache and OS version in the server information headers.

If you use SSL, disable unsafe methods. We recommend the use of TLS 1.3 only.

System service minimizing

This technique can be very exhaustive. It consists simply of eliminating everything that is not necessary in the system. Thus we avoid possible problems in the future with poorly configured applications that we really did not need and that can be vulnerable in the future.

Local monitoring

All the internal monitoring systems would have to be monitored to the highest level, specially information registries. In our case the following active controls in addition to the standard controls are always recommended:

  • Active security Plugin.
  • Complete system inventory (specially users and installed packages).
  • System logs and server security.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

透過X-FORT解構非常規操作行為

內部威脅的範圍可能與一般認知不同,不一定如組織所想像的直接。除了當前的員工和管理人員外,還可能是可以存取特定系統的前員工,第三方顧問或業務合作夥伴都可能是內部威脅。

業界相關研究表明,將近20%的員工可以存取組織內的所有敏感資訊,這意味著,任何知道組織的網路資源和IT生態系如何運作的人,都可能成為內部威脅。阻止內部人員竊取重要資訊是一項非常艱鉅的挑戰,但仍有一些方法可以減輕惡意內部人員相關的風險,並檢測可能洩漏組織關鍵業務和敏感資料的異常行為。

大多數網路安全專業人員可能接觸過,在應對網路攻擊時使用入侵威脅指標(Indicator of Compromise,IoC)的相關訓練。但這種方法的性質屬於事後檢視,偵測使用者行為方面結果並非十分有效。再把場景切換到在家工作模式,則更是令安全專業人員感到挫折,因為它消滅了傳統習慣的明確保護邊境。以往資訊安全防護系統,如 Endpoint Security、SIEM、EDR、IDP、UTM、Firewall等,都是針對外部入侵及攻擊行為所設計,它們也的確很成功。但應用到發掘內部人員威脅活動,可能就存在許多限制:

為了釐清觀念,一般在分析攻擊手法時也會用到行為指標,分析攻擊階段的各種技術手法,來判斷遭到入侵的跡象;但這些系統所觀察的是設備的活動現象,並不是我們討論的使用者行為。

 

內部人員相較於外部攻擊組織,本質屬性有很大的不同

  • 合法的使用者
  • 熟悉內部資訊系統與網路環境
  • 擁有合法的存取權
  • 在工作上常態接觸重要資訊
  • 使用的設備可能不在既有的保護範圍內

基於這些特性,觀察設備活動指標就沒辦法區分內部威脅活動;有些產品具備行為基準線分析,不可否認的,對固定角色的伺服器很有效,很容易分析出異常,但是人的活動就沒那麼單純。

再者,組織內部的業務活動所產生的流量,有65%是在區域網路內(Local traffic),這代表很多行為根本不會經過邊境設備的過濾。

 

事件和行為的差別

對於資安系統來說,每一個事件都是單獨觸發的,詳實記錄系統所發生的事情。然而這樣的記錄本身並不能描述有意義的行為,具備前後上下文(Context)組合才有意義。對於行為指標而言,加入附件、螢幕截圖、貼上截圖、外部收件者這種關連事件組合,才是一個可以理解的觀察行為。

以下是幾個行為描述的例子

  • 使用者從企業內部網路,更改為連接手機分享熱點,然後再次返回。
  • 使用者將程式碼上傳到 Git Hub或未知的雲端儲存。
  • 使用者將內部網站資訊下載到外接儲存裝置。

利用行為指標描述來制定相關偵測規則,將大幅減少需要追查的事件和誤報。依據端點使用者的操作行為和使用者的活動歷史、上下文資訊,動態規則可允許該行為繼續執行。例如在一個會議上,會議召集人想要一份簡報,我們可以存到USB儲存裝置交付。若依照傳統規則,只會單純的禁止存檔至USB ,沒辦法適應業務狀況。

大多數安全解決方案訴求重點在設備事件,而不是以人的行為活動為中心。然而,無論企業資安建置得多麼完善,人員仍然是最不可預期、最獨立的變數。員工必須有效、安全的完成工作,因資訊安全行為,而影響生產力將很難被企業接受。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

FinTech’s popularity signals that it’s time to get serious about apps

The risks surrounding mobile apps have increased, along with the complexities of the solutions they offer. Among today’s top-ranking apps are integrated banking, e-trading, cryptocurrency and even regulatory compliance solutions. These complex applications move very real, personal and valuable data. While apps with lower complexities can still be exploited by malicious actors, the consequences of security breaches from FinTech applications can be considerably worse.

ESET has put both its time and research money where its mouth is for ten years, by helping to lower risks to smartphone users. This is most evident in ESET Mobile Security (EMS), which, since its release in 2011, has performed its protective functions across the many app types in the marketplace. EMS evolved in line with the increasingly complex mix of games, social media, mobile banking, online trading and various messaging platforms that have emerged over the past decade. Based on its popularity, it has taken the sting out of many common user mistakes and carelessness with mobile apps.

Our interest in FinTech can be mapped to a long-term focus on Android banking malware, a topic ESET focused several years of its threat research and product development on. Next, moves were made to collaborate with Google to protect Google Play, and even Chrome itself. And now, we set out to protect and raise consumer and business awareness via a new source – market research. Our FinTech consumer and business surveys set out to quantify and understand the risks people are willing to take to reap the benefits of FinTech.

We surveyed 10,000 consumers and 1,200 business leaders in a variety of industries across the UK, US, Australia, Japan, Mexico and Brazil. Respondents from both consumer and business perspectives were asked an extensive series of questions on the topics of financial technology and cybersecurity, and their impacts on securing finances in a COVIDian world, particularly in light of the coronavirus lockdowns.

While apps continued to increase in popularity, no one could have foreseen the effects of the pandemic on our digital lives. Amid regional and national lockdowns, and restrictions on physical businesses, we turned to our digital devices, and apps, more than ever. The interest in using FinTech platforms and solutions has been magnified, and as a result, it is even more imperative that app security is taken seriously.

Our market research clearly illustrated the popularity of FinTech solutions for both consumers and businesses, with almost two-thirds (62%) of consumers worldwide using some form of FinTech app or platform. In addition, over two-thirds (68%) of business leaders expect their companies’ investments in FinTech to increase in 2021/2022, and 81% of senior managers surveyed agree that COVID-19 has increased the need for improved security of finances.

However, of the 42% of global consumers that use a free FinTech application or platform, half do not know if the app they use sells their data. Additionally, only 31% of people say they read the terms and conditions of a FinTech application before downloading it, and only 29% read the privacy policy. Even among the one in five consumers worldwide who rate themselves as advanced in tech proficiency, 31% do not use a password manager. Although consumers who used four or more FinTech apps were more likely to have security software installed, and therefore, be better protected, information surrounding the risks of FinTech apps is lacking. Only 17% of consumers strongly felt that the quality of information available on the potential risks related to the usage of FinTech applications – such as digital wallets, budgeting apps, or e-trading apps – is adequate​.

For businesses, FinTech solutions offer streamlined, advanced and efficient processes to manage finances, and security is clearly a key priority with 72% of businesses actively investing in new technologies for better security of finances, and 81% of senior business leaders reporting that they adopt a cybersecurity-first approach when investing in new technology solutions. Although both FinTech solutions and cybersecurity are top of mind for many businesses across the world, the risk cybercriminals pose remains weighty.

Over half (58%) of businesses surveyed are confident in their security stances, while acknowledging that they are likely to be impacted by a cybersecurity incident. Of these businesses, those in information, research, and analysis (93%), and accounting, banking, and finance (87%) industries were most likely to think a cybersecurity incident would impact them. With 45% of businesses having experienced a cyber breach in the past, the security of FinTech platforms and apps is paramount to an organization’s financial security, and perhaps more pressingly, to its post-COVID-19 economic recovery.

There is no doubt about it – FinTech apps are here to stay. Whether you’re a casual user of a budgeting app or trading platform, or a global corporation using FinTech solutions to increase efficiency and profit, the security of your financial and personal data is paramount. Applications are able to take complicated concepts and platforms and distill them into user-friendly, easily accessible platforms, and for this exact reason, it can be all too easy to overlook whose hands data is falling into, and how it can be exploited. The security and safety of applications, especially, but not limited to, FinTech, must be considered just as important as overall user experience and benefit. Without comprehensive security, the benefits of FinTech applications cannot be fully appreciated, because the consequences of botched financial security are simply too high.

For more insight into FinTech for business and consumers, check out our blog. For security tips around FinTech, read more at WeLiveSecurity.com.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Scale Computing’s Marlena Fernandez Recognized for Second Consecutive Year on CRN’s 2021 Women of the Channel List and Channel Power 100 List

INDIANAPOLIS – May 10, 2021 – Scale Computing, a market leader in edge computing, virtualization, and hyperconverged solutions, announced today that CRN®, a brand of The Channel Company, has named Marlena Fernandez, vice president of marketing, to its 2021 Power 100 list, an elite subgroup of standout individuals selected from the annual CRN® Women of the Channel list, for the second consecutive year.

The women honored on this year’s list pushed forward with comprehensive business plans, marketing initiatives and other innovative ideas to support their partners and customers, helping them through the uncertainty brought on by the global COVID-19 pandemic. CRN celebrates these exceptional women for their leadership, dedication and channel advocacy.

The CRN editorial team chose the annual Power 100 honorees based on their contributions, expertise and dedication to supporting IT channel success. The Power 100 award recognizes a select group of incredible women who have gone above and beyond — inspiring their peers through their leadership and unwavering commitment to the success of their partners, customers and the entire IT channel.

Fernandez joined the Scale Computing team in 2019 and was the first executive to be named to the CRN Women of the Channel list and the Power 100 list. Over the past year, she helped shift the company’s focus to give Scale Computing’s partners a broader solutions portfolio to share with their end customers. Fernandez was instrumental in driving the company’s commitment to growing its business with the partner community and better enabling them to successfully meet their end users’ IT infrastructure needs. She also played a critical role in expanding Scale Computing’s partner base by nearly double, growing customers and revenue by 45% in 2020.

“Marlena is a key influential member of our executive team, bringing insights from her years of results-oriented global marketing experience to help Scale Computing reach its strategic goals,” said Dave Hallmen, chief revenue officer at Scale Computing. “Her continued commitment to growing our business through our award winning Scale Computing Partner Community and strong leadership makes Marlena very deserving of this recognition for the second consecutive year. For the remainder of 2021 she will help lead our continued focus on bringing edge computing and hyperconverged solutions to large enterprises, solution providers and select industry segments.”

“CRN’s 2021 Women of the Channel list acknowledges accomplished, influential women whose dedication, hard work, and leadership accelerate channel growth,” said Blaine Raddon, CEO of The Channel Company. “We are proud to honor them for their many accomplishments and look forward to their continued contributions to the IT channel.”

The 2021 Women of the Channel and Power 100 award will be featured in CRN Magazine on May 10th and online at www.CRN.com/WOTC.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

阻斷勒索!端點控管讓 EDR 反應更直覺快速

要防範勒索軟體,需要注意三大重點:

  1. 事前阻斷:儘量讓資安問題不要發生。
  2. 平時備份:確保備資料的可用性。
  3. 防止擴散:萬一不幸發生勒索時,要馬上進行止災,防止問題的擴散。

一般來說, 我們就是在前兩項之間不停的循環操作;當問題發生時,進行止災防擴,最後,再將備份的資料,進行有效的還原。

 

事前阻斷

要如何進行事前阻斷呢?推薦使用應用程式控管,阻止未經授權的程序執行,經由精品資安部驗証常見的勒索軟體,都可以有效被阻擋。其中也驗證了勒索軟體大名鼎鼎的勒索軟體,例如:去年 12 月的 DoppelPaymer,對某公司的墨西哥廠勒索 10 億,而另一個 REvil 家族在上個月,竊取蘋果電腦的設計圖,讓某廠因為洩密被勒索 14 億。

我們常說:預防勝於治療,你可以把應用程式控管,想像成隨身戴的口罩,因為口罩是一種非常簡單又有效的預防機制,可以阻斷病毒入侵的管道。

應用程式控管使用全新的白名單技術,用來阻斷惡意程式的運行,也是一種非常早期的預防機制。白名單技術和以往大家熟知的黑名單技術不同,理論上,我們可以使用黑名單,來限制惡意程式的執行;但問題是全世界的程式實在太多了,而且必須事先知道那些程式是惡意的,所以實際上黑名單的設計,本身就是一個後知後覺的機制,無法有效應變惡意程式快速增長的問題。

應用程式控管威力強大,就像是一個雙面刃,不只傷人,也可能妨害自己。如果使用不當,會造成正常的工作軟體無法使用的窘境。所以一定要撘配應用程式白名單的彈性管理,才能有效管理應用程式,不會對自己業務執行人造成妨礙。

應用程式白名單的彈性管理包含下面多種的功能:

  1. 清查:由使用者或管理者發動取得電腦中的應用程式作為白名單
  2. 觀察模式:蒐集使用者執行的程式並列管
  3. 使用者自決:自行新增白名單或停止應用程式控管
  4. 繼承:動態信任應用程式所帶起的子程式
  5. 父行程:防止使用合法的應用程式做為攻擊工具
  6. 自適性:比對應用程式簽章的簽署人,部份字串相同即放行;如:使用 *Microsoft*
  7. 記錄:完整的應用程式執行記錄,可加入為白名單

應用程式控管,可以透過管理良好的白名單,控管任何程式或文件衍伸的執行動作,讓惡意程式在啟動過程中,關鍵的執行點被應用程式控管阻擋,進而達到事前預防的目標。

 

平時備份

面對勒索軟體,備份仍是必要的減災方案,我們推薦使用X-FORT的安全備份功能。

我們瞭解,使用者常常會忘了備份,安全備份定期將資料備份到本機,或是遠端的File Server,在備份的過程中,使用者幾乎沒有感覺,仍可處理日常工作。

FAC(資料夾防護)協助使用者建立安全的工作目錄,限定特定程式,才可以存取此安全的工作目錄,如果惡意程式要存取此安全工作目錄,會被阻擋。

 再把FAC的功能套用在備份的資料夾,形成防護網,確保備份資料的安全性。即使是整個硬碟被勒索軟體破壞,經由 FAC保護的資料仍可保持完好。

 

防止擴散

我們推薦使用EDR ( Endpoint Detection and Response ) 方案,讓問題發生時,可以由端點主動反應防堵,避免災害擴大。

部份的 IT 人員,面臨資安事件,常受限於人力,僅在大問題發生時,才能進行處理。而 EDR 方案,不同於傳統的被動式處理,減輕了 IT 人員的工作負擔,允許在特定的資安事件下,依照自己公司的特色,自動進行一連串的反應。

例如:A公司可以設定,當使用者連到特定國家的 IP 時,自動通知 IT、通知當事人主管,而B公司的控管更嚴格,在相同情形下,還會將此使用者的本機斷網、控管USB、甚至進一步啟動檔案操作記錄,收集使用者的操作歷程。

傳統的資安工具,其規則制定操作,限制了 IT 人員的管理彈性,而EDR 的優點之一,在於可讓 IT 人員因地制宜,在公司的授權範圍下,組合新的資安政策。EDR 的優點之二,在這些政策設定後,即可在特定事件發生時,會自動反應調整政策。不但節省大量人力,以及降低人為操作的疏失。

 

結論

應用程式控管、FAC、EDR 等功能,遠不止對應勒索軟體,也可以用來對應惡意程式、病毒程式,或是防止使用者執行未經授權程式等。X-FORT也提供其他的控管,如SVS安全碟(檔案加密)、控管外接儲存裝置、停用Office巨集、記錄cmd/PowerShell等功能,搭配使用更能全面性防禦勒索軟體 

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。