Skip to content

Five Key Takeaways from the U.S. Executive Order to Bolster Nation’s Cybersecurity

It’s no secret that Nation-State attackers are targeting US government agencies and organizations. As seen inthe Solarwinds breach and the more recentColonial Pipeline ransomware attack, cybercriminals are more motivated than ever to harm US government agencies and their infrastructures.

Continue reading

解構Target Ransom & Malware Steal的技術手法

這幾年Ransomware的新聞頻傳,雖然各個企業也因此提出相當多的對策與防範機制,但Ransomware還是日益猖獗且不斷的進化。Ransomware從一開始的加密受害者的資料,進而勒索贖金;到竊取受害者的資料,再對受害者勒索贖金否則就公開資料進而威脅受害者;到現在Ransomware不只是加資料加密還另外將資料竊取走,再對受害者進行贖金的勒索。不管中那一種勒索病毒,都會讓受害者損失慘重。

Targeted Ransomware這兩年開始出現,更是讓企業氣得牙癢癢的Ransomware攻擊模式,Targeted Ransomware是高度客製化的Ransomware,專門針對被鎖定的企業,對該企業製造客製化的Ransomware,進行嗅探偵測找出脆弱點,潛伏在企業的系統中伺機透過漏洞進行攻擊,進而勒索該企業,若不付贖金就會公布機密資訊的方式,讓各個大企業乖乖就範。

 

大企業都對勒索病毒做了防護?

既然各大企業都對勒索病毒做了防護,那勒索病毒到底是如何進入企業的環境呢?到底是如何突破企業的防護,難道是防毒與防Spam的機制出了問題嗎?我們統計近幾年上百隻的Ransomware,做了分群歸類,研究勒索病毒的攻擊方式與行為,大致分為

  • Targeted Ransomware DLL Injector
  • 無檔案式攻擊(Fileless)
  • APT攻擊方式
  • 宰殺防毒與備份檔案
  • 利用系統白名單進行惡意行為

這些攻擊模式往往無法只靠單純的防毒與Anti-Spam是無法防範的。且除了上述的攻擊方式外,人員往往是在資訊安全最重要的一環,駭客也最常使用社交工程的方式,透過Mail夾帶惡意連結或是檔案,讓防毒與Anti-Spam偵測不出來進行攻擊,再配合上述的攻擊方式,輕易的製造企業內的後門漏洞,進而讓勒索病毒可以大肆的入侵。

 

Mail社交工程來看,駭客往往會寄發釣魚信件

我們就從Mail社交工程來看,駭客往往會寄發釣魚信件來到各大企業的信箱,而這些Mail往往都會夾帶附件或是在內文中嵌入惡意連結,而這些附件已經不是壓縮檔或是執行檔了,因為這些檔案都會被Spam輕易的擋下來,而Mail附件就會以Office的檔案為主,而這些Office檔案看似無害,但只要企業點擊打開,那就會讓駭客可以直接植入後門、病毒…等。而這些駭客到底如何植入這些惡意連結呢?其實很簡單,是利用了Office Macro的功能,Office Macro可以寫入VBA的程式,VBA程式可以呼叫PowerShell或CMD來進行許多的攻擊。最常見的手法是VBA程式中,呼叫PowerShell或CMD,在PowerShell或CMD的指令中進行指令混淆,混淆的Code就是從網路上下載具有惡意攻擊的PS1腳本,而這些腳本內容當然也進行了多層的混淆,這些腳本透過PowerShell的指令直接進入電腦中的記憶體執行,過程中不殘留任何的檔案,這種攻擊方式就是「無檔案式攻擊」。

而腳本的攻擊內容大致分為3大類,第一直接宰殺該電腦的防護機制(防毒),第二刪除該電腦中所有的備份,第三下載Ransomware病毒直接進行加密與竊取。這些腳本是利用Windows的程式(一般稱為白名單),例如:vssadmin.exe、wmic.exe、bcdedit.exe、taskkill.exe等等,用這些Windows程式做攻擊方式,甚至更高深的Ransomware會使用到DLL Injector技術,直接注入到這些程式中,最知名的例子就是Netwalker Ransomware,這支病毒是直接DLL Injector到Explorer.exe中,透過Explorer進行竊取加密,由於Explorer.exe是一般企業不能也不會阻擋的應用程式,剛好駭客就利用這點直接DLL Injector到Explorer.exe。

 

在面對多樣化的勒索病毒威脅要如何防護呢?

現今從勒索病毒的攻擊方式著手,勒索病毒進入公司內部系統後所產生的行為,如同上述的Targeted Ransomware DLL Injector、無檔案式攻擊(Fileless)、APT攻擊方式、宰殺防毒與備份檔案、利用系統白名單進行惡意行為…等。要阻擋這些惡意的攻擊方式,可以使用X-FORT的應用程式控管機制,只有了解Ransomware攻擊與發作的模式,從中進行阻斷,才有辦法阻擋惡意程式,就算Ransomware進入到電腦中,也會因為X-FORT的應用程式控管機制,讓Ransomware無法發作攻擊,以大幅達到預防的效果,甚至搭配FAC(資料夾防護)與安全備份的功能,資料能完全保護住,讓企業達到預防、止災的效果。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

How Does Privileged Access Management Prevent Cyberattacks?

In the digital age we are in, it is essential to protect all the data we have, whether it is our own data or from the users who provided it. No user without permission should have a chance to access sensitive information.

According to Trend Micro’s annual cybersecurity report – A Constant State of Flux -, in 2020, more than 1453 vulnerabilities were identified – that’s just the number of warnings published ⎼, 173 of which consisting of critical severity and 983 of high severity.

Vulnerabilities like these are an open door for cyberattacks to happen. But let’s better understand what they are and how privileged access management prevents cyberattacks.

What are cyberattacks?

Cyberattacks are basically attacks by hackers on a specific computer, system, or computer network.

The goals of an attack like this can vary widely: they range from stealing user data, making modifications to systems, or even bringing down an entire network.

This type of crime can be associated with the category of extortion, considering that it is quite common for hackers to charge an amount of money for the attack to stop, so that important information is not leaked or any other aspect that may be extremely important for the victim.

Perhaps it may seem like something that does not happen very often, given the apparent difficulty of invasion, but Brazil alone has suffered more than 8.4 billion cyberattack attempts in 2020. This shows us that it is essential to always be aware of our system’s flaws and gives us an idea of the size of the risk we are facing.

How do hackers manage to break into systems?

There are several ways to break into a system, and with each passing day, criminals invent new ways to do this. Among them, we can mention:

Ransomware

The term ransomware is a fusion of the terms ransom, which is exactly what it means, and malware, a term referring to malicious software.

It is basically malware that blocks a series of files or an entire system, from which a ransom is charged for their release. It is literally a virtual kidnapping.

Ransomware can gain access to the system in different ways: via email links, social media links, websites, or by installing apps. Once inside, the virus encrypts the data, preventing the user from gaining access.

Generally, the ransom is charged in cryptocurrencies such as bitcoin. This is due to the virtually zero chance of tracking it, making it almost impossible to identify the criminal.

Spyware

This is used as spy malware. It is quite difficult to detect as it works in the background.

It is widely used for stealing confidential information such as passwords, banking, credit card, or any other information that is useful for criminals.

They usually have access by downloading free files or programs from the Internet.

Keylogger

Malware like this has the function of recording everything that is being typed on a keyboard. It is a type of spyware, that is, they are occasionally used in so-called phishing attacks, those designed for identity theft.

A Keylogger can also be hardware, such as a USB cable or a flash drive.

DDoS Attack

Also known as distributed network attacks or distributed denial-of-service attacks. DDoS attacks work by making a large number of requests to an online service to exceed the system’s capacity, preventing it from functioning properly.

They usually do this intending to request an amount to stop the attack. For this to happen, the hacker uses a series of infected computers; the network that these computers are part of is called a zombie network.

What characterizes privileged access?

As its name suggests, users who have this type of access have privileged accounts to access sensitive administrative information. They can change passwords, view user data, modify settings, and perform other related actions.

In general, users like this have accounts with very complex passwords and, in many cases, these accounts are shared among several administrators. But that alone is not enough. It is necessary to closely monitor each credential, especially those that are common among several people.

How does privileged access management prevent cyberattacks?

Privileged Access Management (PAM) is here precisely to help organizations to implement control of privileged actions efficiently.

Users who have this type of access are constantly accessing critical organization resources. Monitoring who joins the system, when that person logs in, and also if they are performing the activities assigned to them is of utmost importance.

A PAM solution is used for this very purpose. Thus, one can guarantee the user is really the one with the authorization, not a hacker who got someone’s credential information.

The solution does this by forcing the person to request a just-in-time authorization, limiting the space they have to work with and also setting a sufficient time limit to perform the required task.

This way, there is no unnecessary exposure of information, ensuring greater security and exponentially reducing the loopholes for hackers to work.

A PAM system can go further and block the user if they are performing unauthorized tasks, which is great for reducing the chances of falling victim to a cyberattack.

It is important to mention that no solution is 100% effective, but the more barriers there are between people and data, the lower the risks.

As we have seen, hackers have a variety of ways to perform their activities. When we talk about users with privileged access, we are dealing with a huge risk for the organization. A hacker can simply steal someone’s authorized credential and use it to break into the administrative system.

A PAM system is essential to put another virtual barrier, reducing the number of loopholes and considerably reducing the vulnerability of a system.

senhasegura is a PAM solution that allows and helps you to secure and protect your data. You can request a demo and learn more about the quality of the service provided. Do not waste time and do not be one more person in the victim statistics!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

訊連科技攜手GIS業成 打造具備口罩偵測、體溫量測及活體辨識功能之3D人臉辨識機

【2021年06月03日,台北訊】 世界級AI臉部辨識技術開發商訊連科技(5203.TW)宣佈旗下FaceMe® AI人臉辨識獲GIS業成(6456.TW)採用,整合至「YouMe 800T 3D人臉辨識機」,打造整合了人臉辨識、口罩偵測、體溫量測及3D活體辨識等多樣化功能一體式門禁機,可適用於辦公大樓、廠房、倉庫、住宅等多種應用場景。

人臉辨識是近年來最熱門的人工智慧應用之一,可整合在門禁管理、差勤打卡等應用中。於COVID-19疫情期間,口罩偵測、體溫量測等功能,更是打造非接觸性門禁系統不可或缺的功能。此外,人臉辨識面對的挑戰之一,是如何進行活體辨識,避免透過臉部相片或影片來進行身分冒用。而於強光、逆光的室外,或是弱光的室內等於環境光源不佳之地點,如何有效進行辨識,也是一大難題。

GIS業成開發的「YouMe 800T 3D人臉辨識機」採用了訊連科技的FaceMe® AI人臉辨識引擎,可進行即時人臉偵測及辨識,因應COVID-19防疫需求,並支援配戴口罩人士進行身份識別及體溫量測,供作門禁、考勤打卡管理使用,為疫情時代功能最齊全的人臉辨識機。「YouMe 800T 3D人臉辨識機」亦內建補光燈,可大幅改進逆光、強光、弱光等極端光源環境下的辨識率。此外,「YouMe 800T 3D人臉辨識機」搭載先進的3D相機,透過景深資訊進行3D活體辨識,100%辨別是否為3D活體、或是以人臉相片、影片等方式冒用身分。

「FaceMe®具有建置彈性、跨作業系統支援等特性,適合建置於各式IoT解決方案中。其中刷臉門禁就是FaceMe®最普遍的應用之一。」訊連科技執行長黃肇雄表示:「很榮幸FaceMe®獲GIS業成採用,於其3D人臉辨識機中,可進一步透過3D景深相機,達到活體辨識功能,打造出更加安全、可靠的智慧門禁及差勤系統。」

FaceMe®可支援各式CPU、SoC及GPU等處理器,亦支援10種以上的作業系統。以「YouMe 800D 3D人臉辨識機」為例,可支援其搭載的的Rockchip RK3399 SoC及Ubuntu作業系統,可提供快速、即時的人臉偵測及辨識。此外,FaceMe®人臉辨識引擎更提供了口罩辨識、配戴口罩的人臉辨識及3D景深資訊的支援,可協助GIS業成加速3D人臉辨識機之開發。

訊連科技FaceMe® AI人臉辨識引擎,在全球知名NIST人臉辨識競賽中,名列全球最精準的刷臉技術之一,在1:1和1:N測試項目中均位居全球前6強、並是排除中、俄廠商後的全球第一。FaceMe®可廣泛支援Windows、Linux(Ubuntu、RedHat、CentOS)、JetPack(Jetson)、iOS和Android等作業系統,並對CPU,GPU,SoC,APU和VPU等各式硬體優化。FaceMe®提供最全面且彈性部屬的解決方案,能將人臉辨識技術應用在各種IoT和 AIoT設備上。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

We present you Pandora FMS Roadmap 2021 – 2023

Pandora FMS presents you our Roadmap 2021 – 2023

In this article, we will introduce you to the new Pandora FMS Roadmap for the next 24 months (June 2021 – June 2023). For its creation, we had the participation of our clients and partners, who, through a survey, helped us choose all kinds of features and their priority.

It’s been really satisfying for us to complete this challenge, as it was one of those enthusiastically proposed among our closest goals.

  • Warp update (Q2).
  • Command center (Q2).
  • New agent inventory report (Q2).
  • Graphic agent installer for Mac (Q2).
  • Services report (Q3).
  • Policy auto-implementation (Q3).
  • New visual console elements (Odometer, Simple graph) (Q3).
  • Netflow: Data monitoring of the flows defined in the filter (Q3).
  • Trend modules (Q3).
  • Capacity planning modules (AI) (Q3).
  • Enhanced anomaly detection (AI) (Q3).
  • Authentication with KERBEROS (Q3).
  • New service view widget for Dashboard (Q3).
  • Basic network computer configuration management (Q4).
  • Centralized agent update (Q4).
  • APM (code application monitoring) (Q4).
  • Security Center (Q4).
  • IPv6 monitoring in SNMP with Satellite server (Q4).
  • ITSM integration: SysAid, Zendesk, OTRS, Redmine, Jira, Zammad, TopDesk (Q4).
  • Impact simulation in service view (2022+).
  • Discovery: Google Cloud.
  • AWS Monitoring improvements with Discovery: RDS for postgreSQL, Autoscaling groups, VPCS, Lampdas.
  • Azure Monitoring improvements with Discovery: Databases, Storage, Data Factory, PostgreSQL, Event hubs.
  • GIS Alerts (2022+).
  • IPAM Report (2022+).
  • Data consultation to agents in real time (2022+).
  • Public/private certificate validation system in remote agent configuration (2022+).
  • Load Balancing in API/Console (2022+).
  • Automatic remote inventory with satellite (SNMP, WMI, SSH/Linux) (2022+).
  • New view to show systems currently affected by a scheduled downtime (2022+).
  • SNMP trap reports (top-N by source, type of trap, etc) (2022+).
  • Desktop application to configure Pandora FMS agent and see its status (2022+).
  • IOT on Satellite server (2022+).

Warp Update

A unified system that allows updating console, server and agents. Fully integrated into the console, which does everything with a single click without having to execute commands, copy files or pray for everything to go smoothly. Fast and centralized, in the case of deployment of centralized updates through the Metaconsole.

Command Center

Command Center is the long-awaited evolution of the Metaconsole, which will allow dozens of nodes to be managed in a totally transparent and centralized way simultaneously, without having to manually synchronize any element.

Security Center

An innovative way to manage server and workstation security, fully integrated with system monitoring.

APM in source code

We want to reach the last frontier of monitoring, the code in applications to measure their times and detect bottlenecks and overloads, combining all the information on the same platform where the infrastructure, servers and application metrics are.

Trend modules

Create a new type of predictive module that compares two time ranges and evaluates, in a percentage or an absolute way, their differences. These modules can be used in alerts, graphs or reports.

E.g.: Access router outbound traffic is 25% higher than last month. This month there are 22 new users compared to the previous month.

Centralized agent update

Update agents centrally from the console. A current enhancement to the remote agent distribution system.

Network computer configuration management

Being able to edit “download” and “upload” full configurations of network equipment through several protocols (TFTP, Telnet, SSH) in order to centrally manage network equipment such as switches and routers. Some of its purposes:

  • Schedule configuration backups, restore trusted configuration versions with a single click.
  • Detect changes in real time and know “who”, “what” and “when” about configuration changes.
  • Upgrading device firmware.
  • Save time by automating time-consuming and repetitive tasks using templates and configuration application scripts.
  • Make sure changes made to running configurations are saved.
  • Compare NVRAM (running) configurations with startup ones (saved) to identify changes that need to be saved.
  • Quickly identify and correct unauthorized or failed changes (restoring backup manually).
  • Compare configurations with base configurations to identify and reverse unwanted changes.

Netflow

Be able to integrate simple data from a Netflow filter as a Pandora FMS numerical module, to be able to, for example, set alarms when the traffic of a certain flow exceeds its threshold or to be able to measure SLA in flow traffic.

Capacity planning modules

Modules that operate like Capacity Planning reports and can estimate in a future time threshold, e.g.: 1 month, 3 months, the value of a given module, estimating its growth based on a statistical analysis of its history.

Policy auto-implementation

Add a policy self-enforcement system (optional) that works well. Either based on the detection of new elements (in the added group or directly in agents in the policy itself) or even just the possibility of scheduling policy application at a certain time interval.

Data consultation to agents in real time

Upon manual request: configuration data, status, hardware status, OS items, logs, etc., in real time, all from a library of predefined elements. Without complementary configuration, it would only need the deployment of an additional agent to that of Pandora FMS. These data are only for screen display, not for making alerts or reports. The data range would be very broad and standard. It requires direct connectivity from the console and the agent that must listen on a specific port.

Service report

Reports to show service SLA compliance, numerically (%) and with a histogram.

IPAM reports

New reports to, among other things, show the usage percentage of each network, and some other information of interest that appears on the IPAM screens but that cannot be included in reports.

GIS alerts

Be able to send alerts when an agent leaves a delimited coordinate zone, which is often called “geo-fencing”.

Load balancing in Console and API

Provide a standard system that allows load balancing in the console and the API, in order to scale and distribute the load. Perfect for environments where the use of the API is intensive or the console is used in multi tenant environments.

IoT

Offer support to the Satellite Server to natively support modbus and MQTT protocols.

It’s been hard work, but thanks to Pandora FMS employees and our partners and clients, we achieved this Roadmap 2021 – 2023 that will make our work easier in the future and speed it up.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×