Showing posts with label Microsoft Security. Show all posts
Showing posts with label Microsoft Security. Show all posts

Friday, 24 July 2015

Microsoft Launches New Security Product In August


Microsoft will next month launch a new security product which sophisticated attacks must stop and previously used deep packet inspection (DPI). Advanced Threat Analytics (ATA), such as the solution is called, uses a combination of behavior analysis by real-time detection.

It focuses on Active Directory-related network traffic and information from Security Information and Event Management (SIEM). On this basis, behavioral profiles of users, machines and other prepared 'resources'. The solution may then detect behavior that is different from these profiles. "After researching many incidents in my previous job, I realized that network logs are not sufficient to find sophisticated attacks," says Microsoft's Idan Plotnik.

He states that the analysis of log files is similar to finding a needle in a haystack. "Even if you find a clue, is figuring out when, how and where something happened almost impossible. With ATA Microsoft therefore taken a different path." Our secret is a combination of DPI, Active Directory information and analysis of specific events "Plotnik says.

Microsoft emphasizes that ATA is a very simple and user-friendly solution, which is used in local businesses. There are no rules, policies or agents required. There only needs to be a port configured to send a copy of all Active Directory-related traffic to the solution. Something that should be arranged within a few hours. A preview version of Microsoft Advanced Threat Analytics can be for some time to download . The full version will be published next month. Price information is not yet available.

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .