<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Satorys.com</title>
	<atom:link href="http://www.satorys.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.satorys.com</link>
	<description>The Power to Understand</description>
	<lastBuildDate>Mon, 26 Mar 2012 08:41:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>La cybersécurité, marché en plein boom pour les industriels de la défense &#8211; AFP</title>
		<link>http://www.satorys.com/la-cybersecurite-marche-en-plein-boom-pour-les-industriels-de-la-defense-afp/</link>
		<comments>http://www.satorys.com/la-cybersecurite-marche-en-plein-boom-pour-les-industriels-de-la-defense-afp/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 13:39:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2098</guid>
		<description><![CDATA[De Patrick RAHIR (AFP) PARIS — Attaques de pirates, espionnage industriel et virus destructeurs ont fait de l&#8217;internet la cinquième dimension de la défense et les industriels se bousculent sur ce marché en plein boom. Les Etats-Unis ont inculpé mardi cinq pirates, dont certains affiliés au groupe de hackers Anonymous accusés d&#8217;attaques qui auraient fait [...]]]></description>
			<content:encoded><![CDATA[<p>De Patrick RAHIR (AFP)</p>
<p>PARIS — Attaques de pirates, espionnage industriel et virus destructeurs ont fait de l&#8217;internet la cinquième dimension de la défense et les industriels se bousculent sur ce marché en plein boom.</p>
<p>Les Etats-Unis ont inculpé mardi cinq pirates, dont certains affiliés au groupe de hackers Anonymous accusés d&#8217;attaques qui auraient fait au total un million de victimes, dont des gouvernements et de grandes entreprises.<span id="more-2098"></span></p>
<p>Les pertes causées par ces attaques ont renforcé la prise de conscience de la vulnérabilité des réseaux et l&#8217;importance de la cybersécurité, pour les Etats comme pour les entreprises.</p>
<p>La firme britannique Ultra Electronics évalue à 50 milliards de dollars par an le marché mondial de la cybersécurité.</p>
<p>&#8220;Et ce marché croit de 10% par an, deux fois plus vite que l&#8217;ensemble du secteur des technologies de l&#8217;information&#8221;, souligne Denis Gardin, directeur de Cassidian Cyber Security Solutions, une unité du géant européen de l&#8217;aéronautique et la défense EADS.</p>
<p>C&#8217;est presque une ruée sur le secteur, baptisé cinquième dimension de la défense, après la terre, la mer, l&#8217;air et l&#8217;espace.</p>
<p>&#8220;Depuis un an, les industriels de la défense ont acquis des firmes de technologie à un rythme frénétique pour renforcer leurs capacités dans la cybersécurité&#8221;, relève Guy Anderson, analyste en chef chez Jane&#8217;s IHS, une société américaine d&#8217;études et de conseil.</p>
<p>&#8220;La cybersécurité a été perçue commme un bateau de sauvetage pour l&#8217;industrie quand les dépenses de défense dégringolaient dans les pays occidentaux: c&#8217;était un des derniers secteurs de croissance&#8221;, ajoute-t-il.</p>
<p>Une arme de guerre</p>
<p>L&#8217;Otan a pris conscience du problème depuis que des attaques lancées de Russie ont saturé les sites du gouvernement estonien en 2007, lors d&#8217;une crise entre Moscou et Tallinn.</p>
<p>La même année, Israël avait piraté le réseau syrien de défense antiaérienne, prenant le contrôle des écrans radars pendant que l&#8217;aviation détruisait une centrale nucléaire en construction, affirme dans son livre Cyberwar Richard Clark, ancien conseiller de la Maison Blanche.</p>
<p>Depuis, les attaques sont de plus en plus sophistiquées, passant des vols de propriété intellectuelle à la destruction physique de machines.</p>
<p>&#8220;A partir de 2009 on va recupérer de l&#8217;information en pénétrant dans les systèmes les plus sensibles&#8221;, relève Philippe Cothier du Centre d&#8217;étude et de prospective stratégique.</p>
<p>En 2010, le mystérieux virus Stuxnet s&#8217;attaque aux centrifugeuses du programme nucléaire iranien.</p>
<p>&#8220;C&#8217;était une bonne idée&#8221;, commente un ancien directeur de la CIA, Michael Hayden. Mais elle a créé un précédent dangereux: &#8220;Aux yeux du reste du monde, elle a légitimé ce type d&#8217;activité.&#8221;</p>
<p>Les gouvernements occidentaux renforcent donc leurs défenses, le Pentagone s&#8217;est doté d&#8217;un &#8220;Cyber Command&#8221;, et les chiffres les plus fantastiques circulent sur des bataillons de hackers formés par la Chine.</p>
<p>La cybersécurité ne concerne pas seulement la défense. &#8220;Les réseaux sont les systèmes nerveux de la société&#8221;, souligne Stanislas de Maupéou, du groupe français Thales.</p>
<p>&#8220;Le monde du cyber est devenu absolument énorme&#8221;, dit Philippe Cothier. Même les réfrigérateurs ont des adresses IP, numéro d&#8217;identification attribué à chaque branchement d&#8217;appareil relié au réseau internet.</p>
<p>&#8220;En 2008 il y avait dans le monde 2 milliards d&#8217;adresses IP, aujourd&#8217;hui il y en a 30 milliards, quatre fois la population mondiale&#8221;, souligne-t-il.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/la-cybersecurite-marche-en-plein-boom-pour-les-industriels-de-la-defense-afp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Abandoned Traditional Security Metrics</title>
		<link>http://www.satorys.com/abandoned-traditional-security-metrics/</link>
		<comments>http://www.satorys.com/abandoned-traditional-security-metrics/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 15:51:32 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2087</guid>
		<description><![CDATA[An interesting argument made by Joshua Corman during the conference debate &#8220;Metrics are Bunk!?: A Zombie Apocalypse, Football/Soccer &#38; Security Metrics&#8221; at the RSA Conference on October 13th 2011 is strongly convergent with Satorys&#8217; position that security intelligence must be empirically extracted from real-life data, rather than dogmatically devised from theoretical studies. We add that [...]]]></description>
			<content:encoded><![CDATA[<p>An interesting argument made by Joshua Corman during the conference debate <em>&#8220;Metrics are Bunk!?: A Zombie Apocalypse, Football/Soccer &amp; Security Metrics&#8221;</em> at the RSA Conference on October 13th 2011 is strongly convergent with Satorys&#8217; position that security intelligence must be empirically extracted from <strong>real-life data</strong>, rather than dogmatically devised from theoretical studies. <span id="more-2087"></span></p>
<p>We add that the &#8220;observe, orient, decide and act&#8221; loop must underly a real-time Incident Management workflow whereby intelligence is gathered in real-time and relies on deterministic risk behaviour identification.</p>
<p> <a title="Infosec 'needs warrior cryptoboffins' to beat hackers" href="http://www.theregister.co.uk/2011/10/11/faith_based_security_fail/" target="_blank">More on Joshua&#8217;s contribution</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/abandoned-traditional-security-metrics/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SCADA systems increasingly among APT targets</title>
		<link>http://www.satorys.com/scada-systems-increasingly-among-apt-targets/</link>
		<comments>http://www.satorys.com/scada-systems-increasingly-among-apt-targets/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 09:25:52 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2077</guid>
		<description><![CDATA[Industrial control systems, just like other IT systems, have growing connectivity and usability requirements &#8211; proportionally, their vulnerability is growing. When you factor in that cyber-attacks are increasingly being sponsored by governments, you understand news such as Stuxnet, Duqu, or the one mentioned below.  &#8221;Intruders compromised a water utility network last week and destroyed a pump, [...]]]></description>
			<content:encoded><![CDATA[<p>Industrial control systems, just like other IT systems, have growing connectivity and usability requirements &#8211; proportionally, their vulnerability is growing. When you factor in that cyber-attacks are increasingly being sponsored by governments, you understand news such as Stuxnet, Duqu, or the one mentioned below.<span id="more-2077"></span></p>
<p> &#8221;Intruders compromised a water utility network last week and destroyed a pump, according to a state government report cited by a critical infrastructure security expert today.&#8221; <a title="Was U.S. water utility hacked last week? by Elinor Mills" href="http://news.cnet.com/8301-27080_3-57327030-245/was-u.s-water-utility-hacked-last-week/" target="_blank"> Read more here</a>.</p>
<p>Read about APT: <a title="Advanced Persistent Threat by Satorys" href="http://www.satorys.com/apt-cyber-attacks-to-the-next-level/" target="_blank">Advanced Persistent Threat</a>.</p>
<p>Here is an interesting piece on the topic by El Reg &#8211; <a title="Hacktivists pose growing threat to industrial computing" href="http://www.theregister.co.uk/2011/10/18/anonymous_threatens_scada/" target="_blank">Hacktivists pose growing threat to industrial computing</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/scada-systems-increasingly-among-apt-targets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major data-theft attack highlights effectiveness of targeted client-side APTs</title>
		<link>http://www.satorys.com/major-data-theft-attack-highlights-effectiveness-of-targeted-client-side-apts/</link>
		<comments>http://www.satorys.com/major-data-theft-attack-highlights-effectiveness-of-targeted-client-side-apts/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 08:58:04 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2074</guid>
		<description><![CDATA[Recent news is highlighting once again how devastating targeted client-side attacks can be (Advanced Persistent Threats). I&#8217;ve explained in my article A New Computer Security Gold Standard why such attacks are possible. The most important reason is reliance of security schemes upon signature databases, an approach nowadays utterly anachronistic.  &#8221;Data from Norway&#8217;s oil and defense industries [...]]]></description>
			<content:encoded><![CDATA[<p>Recent news is highlighting once again how devastating targeted client-side attacks can be (Advanced Persistent Threats). I&#8217;ve explained in my article <a title="A New Computer Security Gold Standard by Marco Ricca, CEO at Satorys" href="http://www.satorys.com/a-new-computer-security-gold-standard/" target="_blank">A New Computer Security Gold Standard </a>why such attacks are possible. The most important reason is reliance of security schemes upon signature databases, an approach nowadays utterly anachronistic.<span id="more-2074"></span></p>
<p> &#8221;Data from Norway&#8217;s oil and defense industries may have been stolen in what is feared to be one of the most extensive data espionage cases in the country&#8217;s history, security officials said [...]&#8220;. <a title="Norway hit by major data-theft attack" href="http://www.google.com/hostednews/ap/article/ALeqM5iAvgP5Zk3TdsAsZZWC4QWReqkbsQ?docId=969c2188eada447c8a48bf0f4215a233" target="_blank">Read more here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/major-data-theft-attack-highlights-effectiveness-of-targeted-client-side-apts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Satorys positively contributed to debates that gathered corporate executives and policy makers during ITU&#8217;s World Telecom 2011</title>
		<link>http://www.satorys.com/satorys-positively-contributed-to-debates-that-gathered-corporate-executives-and-policy-makers-during-itus-world-telecom-2011/</link>
		<comments>http://www.satorys.com/satorys-positively-contributed-to-debates-that-gathered-corporate-executives-and-policy-makers-during-itus-world-telecom-2011/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 16:21:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2036</guid>
		<description><![CDATA[Satorys contributes to debates at ITU World Telecom 2011. Marco Ricca&#8217; contribution on Data: Free and Priceless: Marco Ricca, CEO at Satorys, was speaker on Wednesday 26, October 2011 for “Data: Free and Priceless: Data is the new currency of the online world, with some observers suggesting that free access to data could drive fresh [...]]]></description>
			<content:encoded><![CDATA[<p>Satorys contributes to debates at ITU World Telecom 2011.</p>
<p><strong>Marco Ricca&#8217; contribution on </strong><a title="Data: Free and Priceless - Marco Ricca speaker" href="http://forum.world2011.itu.int/sessions/f11-data-free-and-priceless" target="_blank">Data: Free and Priceless</a>:</p>
<p><a title="Marco Ricca, CEO at Satorys" href="http://www.satorys.com/about-satorys/satorys-management-team/" target="_blank">Marco Ricca</a>, CEO at Satorys, was speaker on Wednesday 26, October 2011 for “<a title="Data: Free and Priceless - Marco Ricca speaker" href="http://forum.world2011.itu.int/sessions/f11-data-free-and-priceless" target="_blank">Data: Free and Priceless</a>: Data is the new currency of the online world, with some observers  suggesting that free access to data could drive fresh economic growth  and entrepreneurialism. Governments are starting to experiment with the  potential of open data in making government more accessible, responsive  and useful to their citizens.<span id="more-2036"></span></p>
<p>An entire ecosystem of start-ups is blooming around the <strong>abundance of  data available on the Internet</strong> &#8211; businesses that analyse, visualise and  combine data to identify emerging trends. In the best-case scenario,  data is used responsibly to improve future interactions through  customization, recommendations, personalised offers and relevant  advertising. Social networking tools can help customize and improve  interactions with peers and colleagues. In other cases, data may be  used, shared or altered without permission, <strong>challenging individuals’  rights to privacy or protection</strong> of their online profile and identity.</p>
<p><strong> What are the full benefits to business and society of open data and  public service data reuse? </strong>How can we develop mechanisms that ensure the  sustainability of these innovative processes? Can government agencies  link data sources coherently to enable citizens to find what they need?  Can data be presented in a way that informs decision-makers in a  meaningful way, yet allows the public to have a <strong>real impact on  policy-making</strong>?</p>
<p>&nbsp;</p>
<p><strong>Florent Batard&#8217; contribution on</strong> <a title="Heads in the Cloud" href="http://forum.world2011.itu.int/sessions/f20-heads-in-the-cloud" target="_blank">Heads in the Cloud</a> :</p>
<p>Florent Batard, R&amp;D manager at Satorys, asked about <strong>Security issues in the Cloud</strong> on Wednesday 26, October 2011 for <a title="Heads in the Cloud" href="http://forum.world2011.itu.int/sessions/f20-heads-in-the-cloud" target="_blank">Heads in the Cloud</a>: The rapid spread of <strong>cloud computing</strong> has drawn significant attention and  scrutiny in the media over recent months. It has also raised policy  questions concerning how people, organizations, and governments handle  information and interactions in the cloud environment. While moving to  the cloud offers recognized benefits of cutting capital expenditure and  enabling the more efficient use of computing resources, questions of  <strong>information security, data privacy, interoperability, reliability and  liability </strong>persist and need to be considered carefully and addressed  rigorously. Lack of interoperability and portability between providers  makes it difficult to migrate data from one service to another &#8211; good  for <strong>cloud service providers</strong>, but not necessarily good for end-users.  What happens if the business goes bust, or decides to change?</p>
<p>&nbsp;</p>
<p>Press book links:  <a title="Satorys in the press for ITU World Telecom 2011" href="http://www.satorys.com/satorys-is-recognised-by-several-international-news-outlets-as-one-of-the-leading-exhibitors-having-presented-groundbreaking-innovation-during-itus-world-telecom-2011/" target="_blank">Satorys in the press</a> for ITU World Telecom 2011.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/satorys-positively-contributed-to-debates-that-gathered-corporate-executives-and-policy-makers-during-itus-world-telecom-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Satorys is recognised by several international news outlets as one of the leading exhibitors having presented groundbreaking innovation during ITU&#8217;s World Telecom 2011</title>
		<link>http://www.satorys.com/satorys-is-recognised-by-several-international-news-outlets-as-one-of-the-leading-exhibitors-having-presented-groundbreaking-innovation-during-itus-world-telecom-2011/</link>
		<comments>http://www.satorys.com/satorys-is-recognised-by-several-international-news-outlets-as-one-of-the-leading-exhibitors-having-presented-groundbreaking-innovation-during-itus-world-telecom-2011/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 15:53:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2029</guid>
		<description><![CDATA[ITU Telecom World 2011 will play host to participants from across the globe and from all walks of the industry including some 250 global leaders spanning Heads of State and Government, Ministers, city mayors, industry CEOs and technology gurus, who will come together to share their vision and knowledge, shape global industry policy and collaborate [...]]]></description>
			<content:encoded><![CDATA[<p>ITU Telecom World 2011 will play host to participants from across the  globe and from all walks of the industry including some 250 global  leaders spanning Heads of State and Government, Ministers, city mayors,  industry CEOs and technology gurus, who will come together to share  their vision and knowledge, shape global industry policy and collaborate  on a Manifesto for a connected world. As the leading UN Agency for ICT  issues, ITU will use its strengths to gather a mix of leaders of  government and industry. <span id="more-2029"></span></p>
<p>Key industry players represented at the event include Alcatel-Lucent,  AT&amp;T, China Mobile, China Potevio, Cisco, Datang, Ericsson,  Fiberhome, Fujitsu, Huawei, Intel, NTT, NTTDoCoMo, RIM, Samsung,  <a title="Satorys" href="http://www.satorys.com/" target="_blank">Satorys</a>, Swisscom, Telkom SA, Turk Telecom, TDIA, ZTE and more.</p>
<p>The event will also feature over 25 National Pavilions showcasing the  ICT industry of countries and regions including Algeria, Angola,  Argentina, Azerbaijan, Belarus, Burundi, China, Czech Republic, Ghana,  Japan, Kenya, Korea, Malawi, Malaysia, Namibia, Nigeria, Poland, Rwanda,  South Africa, Spain, Switzerland (Geneva area), Tanzania, Uganda and  Zambia.</p>
<p>Satorys&#8217; Highlights:</p>
<p><a title="world2011.itu.int - Highlights: See and Experience at ITU Telecom World 2011 - 2011.10.24-27" href="http://world2011.itu.int/highlights" target="_blank">World2011.itu.int &#8211; Highlights: See and Experience at ITU Telecom World 2011 &#8211; 2011.10.24-27</a></p>
<p><a title="L'Agefi - Promotion économique au salon Telecom 2011 par Julio Jaton - 2011.10.27" href="http://www.satorys.com/wp-content/uploads/2011/11/2011.10.27-LAgefi-Promotion-économique-au-salon-Telecom-2011-par-Julio-Jaton.pdf" target="_blank">L&#8217;Agefi &#8211; Promotion économique au salon Telecom 2011 par Julio Jaton &#8211; 2011.10.27</a></p>
<p><a title="Menafn.com - International Telecommunication Union (ITU): ITU Telecom World 2011 sets new paradigm for top-level networking, knowledge-sharing - 2011.11.27" href="http://www.menafn.com/qn_news_story.asp?storyid={674ea854-abf6-41f0-8df7-23bdd295deec}" target="_blank">Menafn.com &#8211; International Telecommunication Union (ITU): ITU Telecom World 2011 sets new paradigm for top-level networking, knowledge-sharing &#8211; 2011.11.27</a></p>
<p><a title="The Jakarta Post - Inequality a thorny issue in ITU Telecom World - 2011.10.25" href="http://www.thejakartapost.com/news/2011/10/25/inequality-a-thorny-issue-itu-telecom-world.html" target="_blank">The Jakarta Post &#8211; Inequality a thorny issue in ITU Telecom World &#8211; 2011.10.25</a><br />
<a title="TheStarOnline - Malaysian pavilion is the largest at ITU Telecom meeting in Geneva by Choong En Han - 2011.10.27" href="http://biz.thestar.com.my/news/story.asp?file=/2011/10/27/business/9777971&amp;sec=business" target="_blank"><br />
TheStarOnline &#8211; Malaysian pavilion is the largest at ITU Telecom meeting in Geneva by Choong En Han &#8211; 2011.10.27</a></p>
<p><a title="http://www.ubifrance.com/my/Posts-3948-Meeting-between-MCMC-&amp;-ARCEP-at-Telecom-World-2011-conference-in-Geneva" href="http://www.ubifrance.com/my/Posts-3948-Meeting-between-MCMC-&amp;-ARCEP-at-Telecom-World-2011-conference-in-Geneva" target="_blank">Ubifrance &#8211; Meeting between MCMC &amp; ARCEP at Telecom World 2011 conference in Geneva by Juliette Mallez &#8211; 2011.10.27</a></p>
<p><a title="ThisDayLive - ITU Seals Partnership Deal with Satorys on Cybersecurity - 2011.11.03" href="http://www.thisdaylive.com/articles/itu-seals-partnership-deal-with-satorys-on-cybersecurity/101942/" target="_blank">ThisDayLive &#8211; ITU Seals Partnership Deal with Satorys on Cybersecurity &#8211; 2011.11.03</a></p>
<p><a title="TDG - Telecom 2011 - Les autorités genevoises se profilent sur des compétences pointus - 2011.10.27" href="http://www.satorys.com/wp-content/uploads/2011/11/2011.10.27-TDG-Telecom-2011-_-les-autorités-genevoises-se-profile-sur-des-compétences-pointues.pdf">TDG &#8211; Telecom 2011 &#8211; Les autorités genevoises se profilent sur des compétences pointues &#8211; 2011.10.27</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/satorys-is-recognised-by-several-international-news-outlets-as-one-of-the-leading-exhibitors-having-presented-groundbreaking-innovation-during-itus-world-telecom-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMPACT, the cybersecurity executing arm of the ITU, enters into a strategic partnership with Satorys</title>
		<link>http://www.satorys.com/impact-the-cybersecurity-executing-arm-of-the-itu-enters-into-a-strategic-partnership-with-satorys/</link>
		<comments>http://www.satorys.com/impact-the-cybersecurity-executing-arm-of-the-itu-enters-into-a-strategic-partnership-with-satorys/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 15:21:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2025</guid>
		<description><![CDATA[Satorys’ unique ability to combat modern threat is recognised by a major global player Geneva, Switzerland, on October 26th 2011 – Satorys, a leading IT Security company, has established during the ITU World Telecom 2011, a strategic partnership with IMPACT (International Multilateral Partnership Against Cyber Threats). Satorys is a leading IT Security Provider that enables, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Satorys’ unique ability to combat modern threat is recognised by a major global player</strong></p>
<p><strong> </strong></p>
<p><strong><em>Geneva, Switzerland, on October 26th 2011</em></strong> – Satorys, a leading IT Security company, has established <strong>during the ITU World Telecom 2011</strong>, a strategic partnership with <a title="IMPACT-ALLIANCE" href="http://www.impact-alliance.org/partners/industry.html" target="_blank"><strong>IMPACT</strong></a> (International Multilateral Partnership Against Cyber Threats).</p>
<p><span id="more-2025"></span></p>
<p><a title="Satorys Managed Security Service Provider" href="http://www.satorys.com/" target="_blank">Satorys</a> is a leading IT Security Provider that enables, by leveraging its world-class proprietary technology, enterprises, telecommunication operators and governments to fight modern cyber-threats. Satorys’ proven capacity to detect the <strong>Stuxnet</strong> Worm, or modern Distributed Denial of Service Attacks such as the one that affected <strong>WikiLeaks</strong>, has propelled it to a leading role in the world since early 2011.</p>
<p>It unique ability stems from its innovative approach, whereby threats are detected according to their behaviours – unlike anti-virus software for example that look for mere signatures. To identify threatening behaviours, Satorys correlates millions of observations collected every second on a global scale – this <strong>collective intelligence</strong> is what makes its offering so compelling to its customers.</p>
<p>IMPACT is the cybersecurity executing arm of the United Nations&#8217; specialised agency &#8211; the <strong>International Telecommunication Union</strong> (ITU). IMPACT brings together governments, academia and industry experts to enhance the global community’s capabilities in dealing with cyber threats. Based in Cyberjaya, Malaysia, IMPACT is the operational home of ITU’s <strong>Global Cybersecurity Agenda</strong> (GCA). As ITU’s cybersecurity executing arm, IMPACT provides ITU’s 193 Member States access to expertise, facilities and resources to effectively address cyber threats, as well as assisting United Nations agencies in protecting their ICT infrastructures. Today, with a 137 Member States that have joined the ITU-IMPACT coalition, it has become the <strong>largest cybersecurity alliance of its kind in the world</strong>.</p>
<p>In addition to the many industry partners, ITU-IMPACT can further provide increasingly valuable insight to its member states and partners, through Satorys’<strong> ability</strong> to collect, parse and present global cyber-threats – as they are nowadays increasingly short-lived, heterogeneous and <strong>deadly</strong>, Satorys’ global observation capacity has become a vital addition and value added service from ITU-IMPACT.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/impact-the-cybersecurity-executing-arm-of-the-itu-enters-into-a-strategic-partnership-with-satorys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Le Parti Pirate suisse porte plainte contre un cheval de Troie étatique</title>
		<link>http://www.satorys.com/le-parti-pirate-suisse-porte-plainte-contre-un-cheval-de-troie-etatique/</link>
		<comments>http://www.satorys.com/le-parti-pirate-suisse-porte-plainte-contre-un-cheval-de-troie-etatique/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 10:15:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2015</guid>
		<description><![CDATA[Après l’Allemagne, la Suisse est à son tour touchée par une polémique sur un cheval de Troie installé par la police sur les ordinateurs des citoyens. Cette fois, nos voisins de l&#8217;autre côté des Alpes l’ont utilisé à quatre reprises dans le but d’arrêter des pédophiles. La méthode fait débat en Suisse, au point que [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Après <a title="Pc Impact" href="http://www.pcinpact.com/actu/news/66279-loppsi-ccc-cheval-de-troie-faille-malware.htm" target="_blank">l’Allemagne</a>,  la Suisse est à son tour touchée par une polémique sur un cheval de  Troie installé par la police sur les ordinateurs des citoyens. Cette  fois, nos voisins de l&#8217;autre côté des Alpes l’ont utilisé à quatre  reprises dans le but d’arrêter des pédophiles. La méthode fait débat en  Suisse, au point que le <a title="Partie Pirate" href="http://www.pcinpact.com/link.php?url=http%3A%2F%2Fwww.partipirate.ch%2F" target="_blank">Parti Pirate Suisse</a> (PPS) a décidé de porter plainte contre X cette semaine.<span id="more-2015"></span></strong>Le problème n’est ici pas l’arrestation des personnes pédophiles, mais  l’utilisation de logiciel intrusif sur des ordinateurs de personnes qui à  la base ne sont que des suspects. Le doute sur une utilisation bien  plus large que celle officiellement avouée (quatre cas) est forcément  levé.</p>
<p>« <em>L’usage de ces programmes est abusif et trop intrusif</em> » a ainsi dénoncé Pascal Gloor, le vice-président du PPS, qui s’est confié au site <a href="http://www.pcinpact.com/link.php?url=http%3A%2F%2Fwww.lematin.ch%2Factu%2Fsuisse%2Fles-pirates-portent-plainte" target="_blank">Lematin.ch</a>. La semaine dernière, le PPS s’était déjà indigné de la nouvelle et avait affirmé qu’il « <em>en tirera toutes les conséquences </em>». Cette plainte contre X était donc plus ou moins annoncée.</p>
<p><strong>Un flou juridique</strong></p>
<p>« <em>L&#8217;utilisation d&#8217;un logiciel espion (Cheval de Troie) sans aucune  base juridique n&#8217;est pas justifiée, même pour combattre le terrorisme</em> » affirme le Parti Pirate Suisse. Pour ce dernier, « <em>on  court le risque que les preuves recueillies sur l’ordinateur soient  modifiées. Avec l’informatique, on est dans le virtuel. Il y est donc  possible de torpiller un ordinateur ou de piéger une personne. (…) Notre  Constitution est sans équivoque, le droit est la base et la limite de  l’activité de l’État. </em>»</p>
<p>Effectivement, comme le relève la <a href="http://www.pcinpact.com/link.php?url=http%3A%2F%2Fwww.tdg.ch%2Flogiciels-espions-suisse-joue-feu-2011-10-18" target="_blank">Tribune de Genève</a>,  un flou juridique entoure l’utilisation des chevaux de Troie. Aucune  règle liée à l’usage de tels logiciels n’est présente dans la loi  fédérale. Malgré son but initial peu critiquable, un tel usage est donc  considéré comme une atteinte à la sphère privée.</p>
<p><strong>Et si les preuves étaient falsifiées ?</strong></p>
<p>« <em>Sans cadre juridique, ces programmes deviennent des armes redoutables</em> » a d’ailleurs prévenu <a title="Marco Ricca, directeur de la société Satorys" href="http://www.satorys.com/about-satorys/satorys-management-team/" target="_blank">Marco Ricca</a>, directeur de la société genevoise  de sécurité informatique <strong>Satorys</strong>, interrogé par la Tribune de Genève.</p>
<p>«<em> Comment être sûr que ce logiciel ne sera utilisé que dans le cadre du mandat délivré par le juge ?</em> » questionne Stéphane Koch, vice-président de High-Tech Bridge, une société de hacking éthique. «<em> Si le programme tombe entre les mains d’un détective privé ou d’une  organisation criminelle, si un policier l’utilise de manière plus  étendue que son mandat ne le permet, il y a danger ! </em>»</p>
<p>Au final, le Parti Pirate Suisse craint que le logiciel ait été développé « <em>avec le même amateurisme constaté en Allemagne</em> », qui, pour mémoire, permet de télécharger et d’exécuter des logiciels  à distance. On imagine dès lors les dangers que pourrait créer un tel  logiciel entre des mains malveillantes. Une personne innocente pourrait  par exemple être déclarée coupable preuve à l’appui, ceux manipulant le  cheval de Troie ayant créé lesdites preuves… De la paranoïa ? Dans le  doute, le PPS préfère en avoir le coeur net.</p>
<div>Source : Merci Malborg &#8211;  Par <a title="PC impact Nil Sanvas" href="http://www.pcinpact.com/actu/news/66540-parti-pirate-suisse-cheval-de-troie.htm?vc=1" target="_blank">Nil Sanyas</a> &#8211; Le 21-10-2011 à 07:37:00</div>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/le-parti-pirate-suisse-porte-plainte-contre-un-cheval-de-troie-etatique/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A New Computer Security Gold Standard</title>
		<link>http://www.satorys.com/a-new-computer-security-gold-standard/</link>
		<comments>http://www.satorys.com/a-new-computer-security-gold-standard/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 14:02:02 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=2003</guid>
		<description><![CDATA[published on Banking Solutions 2011 The financial and IT security industries have one thing in common: they are both undergoing a major paradigm shift. Have mainstream beliefs been wrong after all? Have supposedly unshakable edifices been standing on clay feet? Both communities are looking for their 21st century gold standard. Lately, it seems as if [...]]]></description>
			<content:encoded><![CDATA[<p><em>published on Banking Solutions 2011</em></p>
<p>The financial and IT security industries have one thing in common: they are both undergoing a major paradigm shift. Have mainstream beliefs been wrong after all? Have supposedly unshakable edifices been standing on clay feet? Both communities are looking for their 21st century gold standard.</p>
<p><span id="more-2003"></span>Lately, it seems as if the world has been experiencing a marked uptrend in criminal computer activity. In dozens of instances, prominent organizations were breached, and sensitive data was leaked. Lockheed Martin, Sony, Google, RSA, Citigroup, the IMF – just to name a few protagonists of recent high-profile hacking stories – have experienced the news as profound humiliations.</p>
<p>The turning point seems to have been the WikiLeaks episode of US diplomatic cables being released for everyone to look at. Ever since, security vendors have been scrambling to explain why the supposed fortresses they have helped their customers build suddenly seem as vulnerable against hackers as the ancient city of Troy ended-up being against the Greek army. The analogy is actually not as far-fetched as it may seem. To understand what most of these recent high-profile computer breaches have in common, it is important to understand what the buzz expression Advanced Persistent Threat means exactly. But first, and to stick with the fortress analogy, consider the following: for an invading army that aims to kidnap the princess, two sets of techniques exist. First, it can try to enter by knocking down the walls with a battering ram. This is usually the first approach one thinks of. It may work, but presents a number of downsides; not only does it lack discretion, but it also happens to be the one against which defences are the strongest. Therefore, it requires large resources and lacks effectiveness. In computer hacking, the same kind of approach exists; a “frontal attack” consists in targeting outward-facing servers, i.e. the ones that provide services on the Internet – Web or email servers are typical targets. This approach, even if successful, rarely gives access to the sensitive data a hacker might typically be looking for. The second set of methods, more discrete, is only limited by the attackers’ imagination. In the fortress example, they consist in offering a wooden horse to the king, digging a tunnel under the ramparts (or catapulting oneself above them) – or even seducing the princess and convincing her to voluntarily surrender. In computer hacking, these methods are called “client-side” hacking approaches. They involve targeting end-user platforms (desktops, laptops, smartphones) rather than servers, leveraging social and human components (convincing users to involuntarily adopt a dangerous behaviour), and, if successful, they readily give access to the prime target. To come back to the definition, an Advanced Persistent Threat most of the time means a targeted, client-side attack. Human behaviour is often part of the vulnerability; perimeter walls are utterly useless and prized data is immediately available after the network has been breached.</p>
<p>&nbsp;</p>
<p><strong>Pragmatic approach</strong></p>
<p>As the general public has recently established for itself, supposedly impregnable fortresses are apparently blatantly unprotected, because their builders have assumed invaders will attack them frontally using battering rams. They have built high walls, made of indestructible brick, which attackers don’t even notice. They have focused on piling-up security technology, can roam freely once they’re in. The irrelevance of these classic protection schemes is well illustrated by the very way end-user platforms are still protected against client-side attacks. Namely, so-called “anti-virus” software. In a nutshell, such software relies on a pre-established list of known signatures. These signatures are individual DNAs of the threats they are supposed to counter. Each one of them is uncovered, understood and registered by anti-virus vendors; new signature entries are then regularly downloaded by antivirus software worldwide. In the nineties, when most hacking attacks were carried-out frontally, and when the quantity of new client-side signatures was a mere hundred per year, high perimeter walls and anti-virus software on laptops and desktops worked well enough. In 2011, few attacks are frontal anymore, and the quantity of signatures amounts to more than 70,000 per day. The protection paradigm has, however, hardly evolved since the nineties. This explains the overall vulnerability, and the recent streak of incidents that has rendered it obvious. So what does the new IT security paradigm look like?</p>
<p>What solutions must security officers consider to protect their organizations’ information assets, given this newfound reality? For starters, the philosophical approach needs to finish changing; it is not technology that provides safety – it rather supports an underlying set of policies that are necessarily devised high-up in the organization. Furthermore, the approach needs to be holistic, as technology alone cannot prevent all risks; user awareness training, security constraint minimization, impact mitigation through data segregation, prevention rather than reaction, are all necessary principles, part of a required pragmatic approach. Additionally, organizations have to stop focusing on building higher walls and stronger drawbridges; in parallel, they need to renounce the dream that a significant number of threats will be registered before they hit them. For client-side protection, they indeed need to embrace the preferred alternative – behavioural-based, systemic detection.</p>
<p>&nbsp;</p>
<p><strong>A very good illustration</strong></p>
<p>The decision to rely on identifying the threats’ behaviours, rather than their signatures, rests upon a stark reality: the quantity of possible signatures is infinite. For example, it is possible nowadays to download the source code of ZeuS, probably among the most sophisticated computer Trojan horses ever devised, and thus to easily generate a cyber-weapon bearing a totally unique signature – therefore, it is naïve to hope that a targeted client-side attack may be countered through advance DNA enumeration. To devise a payload that bares a new behavior is, however, much more difficult; there is not an infinite number of ways to propagate, to leak data, or to communicate with an Internet-based “Command Centre”. Therefore, behaviour-based detection has a much better chance of countering Advanced Persistent Threat attacks.</p>
<p>Although technologies that work in such a way are highly innovative, the principle in itself is not. Actually, the financial industry provides a very good illustration of how it has been effectively leveraged for a long time, albeit for a different purpose. That example applies to how stolen or copied credit cards are detected and blocked: rather than relying on a hopeful list of stolen card numbers, purchasing behaviour is correlated, and malicious activity thus detected. If, for example, you pay for lunch in Zürich, and dinner in Melbourne on the same day, your card will be blocked, because it is unlikely you have teleported.</p>
<p>Similarly, by comparing different events across a large network segment, infection, propagation, data leakage or malicious communication can be uncovered. In conclusion, thanks to recent news, sensitive organizations worldwide, and Swiss financial institutions for that matter, have borne witness to the anachronistic nature of the traditional computer security approach. Fortunately, a better alternative exists, and innovators that have foreseen this paradigm shift are already providing them with the preferred alternative.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/a-new-computer-security-gold-standard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>La cybercriminalité a coûté 114 milliards de dollars en 2010</title>
		<link>http://www.satorys.com/la-cybercriminalite-a-coute-114-milliards-de-dollars-en-2010/</link>
		<comments>http://www.satorys.com/la-cybercriminalite-a-coute-114-milliards-de-dollars-en-2010/#comments</comments>
		<pubDate>Tue, 20 Sep 2011 12:52:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1965</guid>
		<description><![CDATA[AFP &#8211; 7 sept. 2011 La cybercriminalité a coûté 114 milliards de dollars (environ 81 milliards d&#8217;euros) et fait 431 millions de victimes dans le monde en 2010, selon une étude publiée mercredi par le fabricant d&#8217;un logiciel antivirus Symantec.Selon le rapport établi par Symantec, qui produit le logiciel antivirus Norton, 74 millions d&#8217;Américains ont [...]]]></description>
			<content:encoded><![CDATA[<p>AFP &#8211; 7 sept. 2011</p>
<p>La cybercriminalité a coûté 114 milliards de dollars (environ 81 milliards d&#8217;euros) et fait 431 millions de victimes dans le monde en 2010, selon une étude publiée mercredi par le fabricant d&#8217;un logiciel antivirus Symantec.<span id="more-1965"></span>Selon le rapport établi par Symantec, qui produit le logiciel antivirus Norton, 74 millions d&#8217;Américains ont été victimes l&#8217;an passé de cybercrimes, qui leur ont coûté au total 32 milliards de dollars (23 milliards d&#8217;euros) de pertes financières directes. En Chine, ce coût a atteint 25 milliards de dollars (18 milliards d&#8217;euros), et il a représenté 15 milliards au Brésil (11 milliards d&#8217;euros), 4 milliards en Inde (2,8 milliards d&#8217;euros). Selon Symantec, 69% des internautes adultes interrogés ont été victimes au cours de leur vie d&#8217;un cybercrime, un taux qui grimpe jusqu&#8217;à 85% en Chine et 84% en Afrique du Sud.</p>
<p>L&#8217;étude souligne également le développement croissant des infractions de ce type sur les téléphones portables. &#8220;La cybercriminalité est bien plus développée que ce qu&#8217;imaginent les gens&#8221;, a commenté Adam Palmer, conseiller en cybersécurité chez Norton.<br />
&#8220;Au cours des douze derniers mois, le nombre d&#8217;adultes interrogés pour l&#8217;étude victimes de cybercrimes est trois fois plus important que celui des victimes de crimes dans la vie&#8221;, souligne-t-il. &#8220;Et pourtant, moins d&#8217;un tiers des personnes interrogées pensent qu&#8217;elles ont plus de chance d&#8217;être victimes d&#8217;un cybercrime que d&#8217;une infraction dans la vie physique&#8221;, poursuit M. Palmer.</p>
<p>L&#8217;étude, menée auprès de 20.000 personnes dans 24 pays, a été réalisée aux mois de février et mars 2011 et portait sur les douze mois précédents, selon Symantec.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Du côté français.. Plus de 9 millions de Français victimes de la cybercriminalité en 2010</strong></p>
<p>Plus de neuf millions de Français ont été victimes de la cybercriminalité au cours de l&#8217;année 2010, pour une facture totale estimée à 1,8 milliard d&#8217;euros, indique le rapport annuel de la société de sécurité informatique Symantec. &#8220;9,4 millions de victimes en France, c&#8217;est près d&#8217;une victime toutes les trois seconde&#8221;, souligne Symantec, l&#8217;éditeur du logiciel de sécurité Norton, qui a publié jeudi la partie française de son étude mondiale sur la cybercriminalité en 2010. Ces attaques &#8220;ont engendré près de 872 millions d&#8217;euros en pertes effectives directes des cybercrimes et 850 millions en temps perdu à résoudre les incidents, selon les estimations des victimes&#8221;, indique Symantec. Un peu plus de la moitié (54%) sont des attaques en ligne provenaient de virus ou de logiciels malveillants, suivies par les escroqueries en ligne (11%) et via les spams (10%).</p>
<p>&#8220;La menace de la cybercriminalité n&#8217;est pas suffisamment prise au sérieux par les internautes, alors qu&#8217;elle est pourtant omniprésente. Six adultes sur dix ont déjà été victimes d&#8217;un cybercriminel durant leur vie&#8221;, résume Laurent Heslault, directeur des stratégies de sécurité chez Symantec. &#8220;50% des adultes ne se sentent pas à l&#8217;abri d&#8217;un acte de cybercriminalité lorsqu&#8217;ils sont en ligne. Pourtant, la moitié d&#8217;entre eux ne prennent pas les mesures préventives qui s&#8217;imposent. 49% avouent que leur logiciel de sécurité censé protéger leurs informations n&#8217;est pas à jour&#8221;, selon lui. Moins de la moitié des internautes majeurs (47%) vérifie régulièrement ses comptes à la recherche d&#8217;une éventuelle fraude à la carte bancaire et 60% n&#8217;utilisent pas de mots de passe complexes ou n&#8217;en changent pas régulièrement, indique également Symantec.</p>
<p>Toujours selon cette étude, 23% des Français indiquent ne &#8220;pas pouvoir vivre sans internet&#8221; et 25% d&#8217;entre eux pensent qu&#8217;ils &#8220;perdraient contact avec leurs amis&#8221; s&#8217;ils devaient se passer des réseaux sociaux de type Facebook et Twitter.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/la-cybercriminalite-a-coute-114-milliards-de-dollars-en-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA Attack Analysis: Lessons Learned</title>
		<link>http://www.satorys.com/rsa-attack-analysis-lessons-learned/</link>
		<comments>http://www.satorys.com/rsa-attack-analysis-lessons-learned/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 07:14:06 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1936</guid>
		<description><![CDATA[Last week was published an interview lead by Kapersky team to debate about the RSA targeted attack that took place some weeks ago. This interview is very valuable because RSA participate to this interview and is totally honest about what happened and how the attack succeeded. It’s very rare to have such Post Mortem analysis [...]]]></description>
			<content:encoded><![CDATA[<p>Last week was published an interview lead by Kapersky team to debate about the <a title="RSA - targeted attack" href="http://www.securelist.com/en/blog/538/Lab_Matters_Anatomy_of_the_RSA_targeted_attack" target="_blank">RSA</a> targeted attack that took place some weeks ago. This interview is very valuable because RSA participate to this interview and is totally honest about what happened and how the attack succeeded. It’s very rare to have such Post Mortem analysis with honest answers from the company targeted. Therefore we decided to sum up this interview for you to take advantage of ones mistake and learn from this recent targeted attack.</p>
<h1><span id="more-1936"></span></h1>
<h1> </h1>
<h1>Turning to client-side</h1>
<p> A highly interesting point which rises from this interview is the change of paradigm in the defense strategies. RSA confirm that the threat came from the client-side of their network and that all the frontal measures they have taken was therefore totally useless. This dimension that Satorys defend for several years now finally reaches international companies’ through the <a title="Advanced Persistent Threat - Cyber attacks to the next level" href="http://www.satorys.com/apt-cyber-attacks-to-the-next-level/" target="_blank">Advanced Persistent Threat</a>.</p>
<p>Human factor become central in the new cyber defenses strategies. Social Engineering always existed but the recent growth of social media and community made much easier to attain employees personally and professionally. RSA testifies that an employee was attained by a <a title="Phishing attack - wikipedia" href="http://en.wikipedia.org/wiki/Phishing" target="_blank">phishing attack </a>that was used to download a malicious payload via the flash plugin of the client browser. These actions allowed the attacker to install a remote administration tool to begin farming the data.</p>
<p>These new means for attacks were used wisely by attackers and finally confirm that being focused on frontal attacks is a completely outdated reasoning. Attackers are now looking for indirect access to resources and overuse the possibilities and credulity of end-users to gain access to private data. Once settled in the network attackers can easily reach the outside world from internal network and go look for orders to know which data to leak.</p>
<p>This change of paradigm is quite striking, indeed as RSA confess, the new postulate is that the internal perimeter should be considered compromised as used to be outside networks. We should take benefit from this experience at RSA to begin changing our approach and focus on the client-side of the network.</p>
<p>This is something Satorys has been claiming for several years and develop technologies focused on client-side for security detection. By analyzing internal connections and interactions Satorys has developed state of the art behavioral detection to determine the vulnerability and potentially compromised clients.</p>
<h1> </h1>
<h1>Ineffectiveness of signature based detection</h1>
<p>Another interesting point revealed by RSA is the skills deployed to perform this attack. No more script kiddies and bruteforce on regular frontal services. The attack was indirect, performed by skilled and trained developer who designed specific software for this attack and at least generated a new signature of the software.</p>
<p>We can therefore notice with this assertion that any security appliance or software based on signature was anachronistic at this point and that finally the network was defense-less. As majority of security products are based on heavy and incomplete signature databases they can never keep up with the pace of new signatures publishing. Even if the database were up to date any software developed exclusively for the attack couldn’t be detected.</p>
<p>Once again, Satorys stood long time ago on the fact that signature-based will fail on short terms due to the exponential publish pace of the malicious softwares. Therefore Satorys focused its technology not to run behind the crowd for signatures updates but to work on a different paradigm: <strong>behavioral detection</strong>. As it exists a finite set of behaviors to attack and compromise clients, this new reasoning won’t fall into the exponential law as for signatures. By analyzing attacks by their behavior and not their signatures anymore we ensure that it will be always recognized.</p>
<h1> </h1>
<h1>Lessons learned</h1>
<p>The lessons we can learn from such very interesting interview is that there is an increasing need for unparallel visibility on client-side and for traceability inside the information system. As RSA describes, they discovered the attacks quite by chance as few machines did few strange actions. Hopefully RSA analyst was skilled enough to investigate these actions and detect the leakage which could have been totally invisible in another context. I’m sure RSA analyst critically needed this unparallel visibility to investigate and search among their whole client-side infrastructure.</p>
<p>Once again we’re relieved to confirm that the choices made by Satorys actually fit the increasing need for visibility and client-side analysis. <a title="TrueBoard - Satorys' product" href="http://www.satorys.com/solutions/trueboard/" target="_blank">Trueboard</a> allows to have such visibility and client oriented architecture and detection to simplify the work of analysts as RSA’s. Additionally, to deal with client-side attacks, it allows to identify and hopefully to train employees to security best practices to finally reach a high level of security.</p>
<p>We can sum up this video to some key points corporate and security manager should keep in mind:</p>
<ul>
<li>Consider the internal perimeter as compromised</li>
<li>Human factor is the key for security enhancement especially concerning social networks</li>
<li>Security level of partners and providers should be considered thoroughly</li>
<li>Attackers are now trained, skilled and ready to develop one shot tools</li>
<li>Signature-based is anachronistic considering the previous statement</li>
<li>Attackers stop attacking frontally but use the client-side backdoors</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/rsa-attack-analysis-lessons-learned/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hacker ‘Armageddon’ Forces Symantec, McAfee to Seek Fixes</title>
		<link>http://www.satorys.com/hacker-%e2%80%98armageddon%e2%80%99-forces-symantec-mcafee-to-seek-fixes-satoryscomment/</link>
		<comments>http://www.satorys.com/hacker-%e2%80%98armageddon%e2%80%99-forces-symantec-mcafee-to-seek-fixes-satoryscomment/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 13:52:46 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>
		<category><![CDATA[TrueFlow]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1923</guid>
		<description><![CDATA[This insight from Bloomberg confirms what we&#8217;ve been stating, and that now the industry readily acknowledges: - The signature-based protection paradigm is overly anachronistic &#8211; relying on &#8220;a priori&#8221; enumeration of threats for one&#8217;s safety doesn&#8217;t make any sense anymore. - The preferred alternative is &#8220;behavior based&#8221;; by understanding &#8211; and detecting &#8211; threats&#8217; behaviors [...]]]></description>
			<content:encoded><![CDATA[<p>This insight from <a title="Hacker ‘Armageddon’ Forces Symantec, McAfee to Seek Fixes" href="http://www.bloomberg.com/news/2011-08-04/hacker-armageddon-forces-symantec-mcafee-to-search-for-fixes.html" target="_blank">Bloomberg</a> confirms what we&#8217;ve been stating, and that now the industry readily acknowledges:</p>
<p>- The signature-based protection paradigm is overly anachronistic &#8211; relying on &#8220;a priori&#8221; enumeration of threats for one&#8217;s safety doesn&#8217;t make any sense anymore.<span id="more-1923"></span></p>
<p>- The preferred alternative is &#8220;behavior based&#8221;; by understanding &#8211; and detecting &#8211; threats&#8217; behaviors one stands a much better chance of achieving better safety. There are indeed an infinite number of threat signatures possible, while the set of possible threatening behaviors is finite.</p>
<p>- Client-side security approaches nowadays make poor sense as <a title="Satorys explains Cloud Computing concept" href="http://www.satorys.com/resources/cloud-computing/" target="_blank">cloud computing</a> is gaining traction &#8211; a preferred approach is systemic, network-centric.</p>
<p>- Building increlevant.</p>
<p>Fortresses have never been so expensive &#8211; and walls have never been as tall.<br />
This has not prevented highly protected organizations such as Google, RSA,<a title="Les abonnés PlayStation de Sony piratés" href="http://www.satorys.com/sony-pirate/" target="_blank"> Sony</a>, the European Parliament, <a title="Lockheed Martin IT network attacked &amp; Protection paradigm" href="http://www.satorys.com/lockheed-martin-it-network-attacked-protection-paradigm/" target="_blank">Lockheed Martin</a>, the American Senate, Nintendo, Citigroup, the IMF, etc. from being breached. A better approach consists of building watchtowers instead of walls, i.e. of focusing on security visibility and intelligence rather than on blind protection schemes.</p>
<p>Satorys is expecting the current momentum underlying its activity and technological vision to gain further traction as news further corroborates these modern realities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/hacker-%e2%80%98armageddon%e2%80%99-forces-symantec-mcafee-to-seek-fixes-satoryscomment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Satorys in the BigData Trend</title>
		<link>http://www.satorys.com/satorys-in-the-bigdata-trend-innovation/</link>
		<comments>http://www.satorys.com/satorys-in-the-bigdata-trend-innovation/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 15:55:43 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1906</guid>
		<description><![CDATA[We live in digital world challenged by burgeoning quantities of data; according to IDC, the world’s data doubles every 18 months. This strongly exponential growth presents massive opportunities and serious challenges. Among this information jungle, the BigData trend is refered as the ability to deal with huge amount of data from different source and expressing [...]]]></description>
			<content:encoded><![CDATA[<p>We live in digital world challenged by burgeoning quantities of <strong>data</strong>; according to IDC, the world’s data doubles every 18 months. This strongly exponential growth presents massive opportunities and serious challenges.<span id="more-1906"></span></p>
<p>Among this information jungle, the <a title="BigData Trend" href="http://en.wikipedia.org/wiki/Big_data" target="_blank">BigData trend</a> is refered as the ability to deal with huge amount of data from different source and expressing different information. Difficulties include capture, storage, search, sharing, analytics and visualizing. <a title="BigData trend for the future" href="http://pro.01net.com/editorial/535404/big-data-la-prochaine-revolution-informatique/" target="_blank">Big Data requires exceptional technologies </a>to efficiently process large quantities of data within tolerable elapsed times. Technologies being applied to Big Data include massively parallel processing (MPP) databases, datamining grids, distributed file systems, distributed databases, MapReduce algorithms, cloud computing platforms, the Internet, and scalable storage systems.</p>
<p> To leverage such opportunities, the challenge obviously consists in converting data into useful business information; being “data rich and information poor” is not helpful. This is where Satorys innovation and technology can help. From the very beginning, Satorys has positionned itself in this innovative field and developed methodologies to deal with such problem with new ways of parsing, normalizing, aggregating, correlating, and mining this stupendous volume of data.</p>
<p>Without such innovation, the risk is information overload – or otherwise called, “infobesity”. According to Jonathan Spira, chief analyst at Basex Inc. and author of the book Overload, the challenge is real : in 2010 infobesity cost 997 billion to the US economy, as the average worker wasted 25% of his workday dealing with useless data.</p>
<p>Thanks to its proprietary technology, <a title="BigData Innovation" href="http://www.scribd.com/fullscreen/59437791?access_key=key-27pmxw99g7xcai3rfsio" target="_blank">Satorys is a key player of the BigData trend</a>, as it extracts understanding from huge amounts of IT logs. These logs, transformed into semantically valuable events, are indeed leveraged to generate useful and accurate security alarms and activity reports. Satorys&#8217; services therefore enable decision makers to act upon systemic, purposeful and efficient Security intelligence.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/satorys-in-the-bigdata-trend-innovation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Réaction a la publication du 20 juin 2011 de Q1Labs</title>
		<link>http://www.satorys.com/q1labs-20-juin-2011/</link>
		<comments>http://www.satorys.com/q1labs-20-juin-2011/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 13:49:42 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1830</guid>
		<description><![CDATA[Dans l’article Q1 Labs : 41% des atteintes à la sécurité ont laissé des traces dans les logs, un éditeur SIEMS «Q1Labs » réagit sur le sujet du Log Management et notamment sur le fait que près de 41% des brèches sont visibles clairement dans les logs. 41% des brèches sont identifiées et loggées sans [...]]]></description>
			<content:encoded><![CDATA[<p>Dans l’article <a title="Article from Q1 Labs commented by Satorys" href="http://www.satorys.com/q1labs-20-juin-2011/" target="_blank">Q1 Labs </a>: 41% des atteintes à la sécurité ont laissé des traces dans les logs, un <strong>éditeur SIEMS «Q1Labs »</strong> réagit sur le sujet du <strong>Log Management</strong> et notamment sur le fait que près de 41% des brèches sont visibles clairement dans les logs.<span id="more-1830"></span><br />
41% des brèches sont identifiées et loggées sans être interprétées ou exploitées. Les SIEMS classique permettent d’accéder à ces 41% et de réagir en conséquence. Cela est très bien résumé par notre confrère de Q1Labs. <em>« Pourtant, le problème des sociétés qui estiment que la gestion des logs est simplement un besoin en terme de conformité et non un système de détection active de cyber-menaces, persiste ».</em> Chris Poulin</p>
<p>C’est dans cette situation que les solutions de Satorys prennent tout leur sens et plus particulièrement <a title="TrueBoard" href="http://www.satorys.com/solutions/trueboard/" target="_blank">TrueBoard</a>. Non seulement TrueBoard va permettre de rendre visible et exploitable ces 41% de brèches mais il va également analyser le reste des logs pour déterminer les 59% de brèches restantes avec un système de corrélation et de détection comportementale.<br />
<em><br />
« En réalité, beaucoup d’entreprises déploient des systèmes de sécurité intelligente ou de gestion des logs pour cocher la case des conformités telles que PCI, FISMA, GLBA, SOX ou GPG 13, et n’ont par la suite pas les ressources nécessaires ou l’expertise technique pour rechercher les alertes et y apporter une réponse efficace »</em>.</p>
<p>Une fois de plus nous ne pouvons qu’aller dans le sens de notre confrère. Bien qu’un outil comme TrueBoard soit un gros avantage pour la mise en conformité d’une entreprise, il permet bien plus. En effet, il utilise ces ressources souvent inutilisées pour en tirer de l’intelligence et présenter une <strong>information claire</strong>, pertinente et précise sur les problèmes de sécurité. Toute action malicieuse laisse une trace sur les ressources de l’entreprise, TrueBoard est là pour flairer cette trace et remonter le fil des évènements en confrontant plusieurs données et enfin en tirer une<strong> analyse fine </strong>pour déterminer la nature de la menace.<br />
En conclusion nous pouvons dire que le service de Sécurité Trueboard permet de gérer les problèmes de <strong>sécurité client-side </strong>et exogènes mais également de remplir toutes les obligations réglementaire liées à la conformité.</p>
<p>Article: <a title="Q1 Labs : 41% des atteintes à la sécurité ont laissé des traces dans les logs" href="http://www.globalsecuritymag.fr/Q1-Labs-41-des-atteintes-a-la,20110620,24403.html" target="_blank">Q1 Labs : 41% des atteintes à la sécurité ont laissé des traces dans les logs</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/q1labs-20-juin-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lockheed Martin IT network attacked &amp; Protection paradigm</title>
		<link>http://www.satorys.com/lockheed-martin-it-network-attacked-protection-paradigm/</link>
		<comments>http://www.satorys.com/lockheed-martin-it-network-attacked-protection-paradigm/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 09:25:59 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>
		<category><![CDATA[TrueFlow]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1804</guid>
		<description><![CDATA[Ces dernières années, nous sommes rentrés dans un nouveau paradigme de cyber-sécurité. C&#8217;est l&#8217;émergence de ce nouveau paradigme qui explique la multitude de cas similaires à celui de Lockheed Martin publiés ces derniers mois (Google, Sony, Parlement Européen, Stuxnet, attaques Chinoises, Nonghyup, et beaucoup d&#8217;autres). Ce nouveau paradigme en deux points : 1) Les attaques [...]]]></description>
			<content:encoded><![CDATA[<p>Ces dernières années, nous sommes rentrés dans un nouveau paradigme de cyber-sécurité. C&#8217;est l&#8217;émergence de ce nouveau paradigme qui explique la multitude de cas similaires à celui de Lockheed Martin publiés ces derniers mois (Google, <a title="Sony piraté" href="http://www.satorys.com/sony-pirate/" target="_blank">Sony</a>, Parlement Européen, <a title="Stuxnet" href="http://www.satorys.com/recrudescence-des-cyberattaques-visant-a-paralyser-des-sites-web-et-a-causer-du-tort-aux-prestataires-de-services/" target="_blank">Stuxnet</a>, attaques Chinoises, Nonghyup, et beaucoup d&#8217;autres).<span id="more-1804"></span></p>
<p>Ce nouveau paradigme en deux points :</p>
<p>1) Les attaques informatiques sont ciblées et prennent aujourd&#8217;hui la forme d&#8217; <a title="Advanced persistent Threats" href="http://www.satorys.com/apt-cyber-attacks-to-the-next-level/" target="_blank">Advanced Persistent Threats</a> &#8220;client-side&#8221;. Seule une approche systémique et comportementale permet de les contrecarrer.</p>
<p>2) Les attaques informatiques sont éminemment éphémères, personalisées par cible, et ambitionnent de provoquer des scénarios de &#8220;Data Leakage&#8221;. Seule une approche systémique et comportementale permet de les contrecarrer.</p>
<p>C&#8217;est dans le même contexte que nous lisons récemment que plusieurs gouvernements investissent massivement dans leur <strong>capacité cyber-défensive</strong>. De facon similaire, le secteur privé a décuplé sa compréhension à cet égard ces derniers mois, notamment grâce aux différents épisodes de hacking haut-niveau qui ont eu lieu. Cette réalité démontre le niveau de maturité grandissant sur ces questions, et la compréhension de plus en plus rigoureuse du marché sur les problématiques modernes de cyber-défense.</p>
<p>C&#8217;est dans la perspective de ce surcroît de compréhension et de conscience que <a title="About Satorys" href="http://www.satorys.com/about-satorys/" target="_blank">Satorys</a> travaille depuis plusieurs années. A l&#8217;époque où la société a démarré (en 2006), le marché (privé et public) était *loin* du niveau de compréhension actuel. Malgré cela, la société a pris le risque d&#8217;investir dans une <a title="TrueFlow Technology" href="http://www.satorys.com/solutions/trueflow/product-factsheet2/" target="_blank">technologie</a> largement en avance sur son temps &#8211; avec l&#8217;espoir que la demande surviendrait rapidement.</p>
<p>2010 a confirmé l&#8217;intuition de Satorys, 2011 est en train de la pérenniser. Le succès et la demande que connaissent Satorys en ce moment sont incommensurables. Comme expliqué plus haut, ses interlocuteurs ont désormais compris que nous avons changé de paradigme, que la menace a évolué, et que les approches classiques sont largement inadéquates.</p>
<p><strong>Du fait de sa vision en avance sur son temps, Satorys est donc en mesure de proposer aujourd&#8217;hui une technologie qui répond à ce changement de paradigme. Sa capacité à observer les réseaux de facon *systémique*, et de *reconnaitre les comportements* des menaces, est tout à fait unique. Satorys ne peut donc être qu&#8217;un interlocuteur *privilégié* de quiconque a subi cette prise de conscience récente, et d&#8217;investir les moyens de se défendre, de facon moderne, contre les menaces modernes. Ceux qui fonctionnent sur l&#8217;ancien paradigme ne peuvent pas comprendre la valeur ajoutée de Satorys, et ne font pas partie de nos cibles.</strong></p>
<p>En deux mots, &#8220;l&#8217;intelligence collective&#8221; que Satorys déploie est *indispensable* à une lutte efficace contre les menaces modernes.</p>
<p>Un excellent exemple de cette réalité est le cas <strong>Stuxnet</strong>. La raison pour laquelle il a échappé à la détection est la même pour laquelle l’immense majorité des logiciels infectieux échappent désormais aux anti-virus, même les plus performants : les <strong>anti-virus </strong>et autres protections classiques fonctionnent sur un modèle qui consiste à identifier et répertorier les « signatures » des menaces (<strong>signature-based model</strong>).</p>
<p>Ce modèle fonctionnait bien il y a encore quelques années, lorsque la quantité de nouvelles signatures émergeant chaque jour était limitée. En revanche, les menaces aujourd’hui apparaissent et disparaissent exponentiellement plus vite. A titre d’illustration, les statistiques révèlent que pendant l’année 1999 moins de 2 nouvelles signatures de menaces étaient détectées par jour, alors que cette quantité est de 73&#8217;000 par jour en moyenne pour les trois premiers mois de 2011. En conclusion, le modèle signature-based dont dépendent les solutions de protection classique est parfaitement anachronique, désuet et obsolète.</p>
<p>De surcroît, les protections classiques sont embarquées sur les plateformes qu’ils ont la charge de protéger (<strong>host-based model</strong>). Ce modèle présente plusieurs désavantages, qui rendent ces solutions souvent inefficaces. Tout d’abord, ces solutions – du fait de leur caractère éminemment décentralisé – sont incapables de bénéficier d’une « intelligence collective » efficace.</p>
<p>En effet, il est impensable que chacun de ces programmes communique à un système central une information sur ce qu’il « voit » ; cela présenterait trop d’inconvénients en termes de performance, d’utilisation de bande passante, et de confidentialité. Ils exploitent donc des flux d’informations et de mises à jour unidirectionnels, et sont incapables d’utiliser un effet de volume comme levier.</p>
<p>Ensuite, ces solutions classiques se retrouvent en concurrence avec la menace elle-même, puisque les deux logiciels (la menace et la protection) fonctionnent sur le même système en même temps – il est donc beaucoup plus aisé pour le ver ou le virus d’interrompre l’anti-virus, ou de contourner le mécanisme de protection. Finalement, puisque par définition tout le monde peut télécharger la protection, il est aisé pour le criminel de s’assurer que son logiciel malveillant échappe bien à la protection qui est censée la détecter, avant de le diffuser.</p>
<p>La technologie de Satorys identifie et contrecarre les menaces informatiques en s’appuyant sur un paradigme différent de celui décrit ci-dessus : sa technologie utilise un modèle « network-centric » et « behavior-based ». Cela a les implications suivantes:</p>
<p>- <strong>Network-centric</strong>: la protection se fait de façon éminemment centralisée. C’est-à-dire qu’un seul système a la charge de filtrer l’ensemble des menaces potentielles. En effet, l’ensemble du trafic sensible converge vers un seul et même point. La capacité d’observation et de protection est donc centrale, et une mesure de protection, lorsqu’elle est mise en œuvre, affecte instantanément l’ensemble des plateformes en même temps. L’effort préventif, aussi bien que curatif, prend donc effet en temps réel. Ensuite, puisque la protection est centralisée, aucun criminel, terroriste ou attaquant ne peut la « télécharger » et tester l’efficacité de l’arme qu’il créé ; il se lance donc forcément dans ce cas à l’aveuglette, sans connaître à l’avance l’efficacité de son logiciel. Finalement, ce type d’architecture permet d’exploiter le principe « d’ <strong>intelligence collective </strong>» ; l’ensemble des observations passées et/ou effectuées par ailleurs contribue à l’effort de lutte contre les menaces futures – un tel système est donc d’autant plus efficace qu’il protège un grand nombre de plateformes, et qu’il est déployé depuis longtemps.</p>
<p>- <strong>Behavior-based</strong>: c’est la caractéristique essentielle de la technologie, qui la distingue de tout le reste. C’est le comportement de la menace qui est décelé, et non sa signature. La différence est essentielle. En effet, alors que pour échapper à une détection classique la menace doit, dans le cas d’une solution signature-based, simplement changer d’ADN (et, comme on l’a vu, c’est devenu simplissime), pour échapper à une détection de type behavior-based, la menace doit modifier substantiellement son comportement ; elle doit par exemple se propager de façon radicalement nouvelle, ou communiquer avec le criminel, le terroriste ou l’attaquant en utilisant un modèle jamais vu auparavant.<br />
La quantité d’innovation nécessaire et donc l’investissement à mettre en œuvre, pour créer une souche ayant une chance de se propager efficacement, sont supérieurs de plusieurs ordres de grandeur.</p>
<p>En conclusion, les attaques modernes ne peuvent être contrecarrées efficacement qu’en employant une approche centralisée, s’appuyant sur un principe de « <strong>détection comportementale</strong> » et « d&#8217;intelligence collective»- c’est à ce prix-là que la protection devient préventive en plus d’être curative, que la probabilité de détection devient maximale, qu’une intelligence collective peut être exploitée, que l’investissement criminel, terroriste ou belliqueux doit être substantiellement plus important pour devenir efficace, et que, de façon générale, un système critique peut être efficacement protégé.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/lockheed-martin-it-network-attacked-protection-paradigm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>APT: Cyber Attacks to the next level</title>
		<link>http://www.satorys.com/apt-cyber-attacks-to-the-next-level/</link>
		<comments>http://www.satorys.com/apt-cyber-attacks-to-the-next-level/#comments</comments>
		<pubDate>Fri, 06 May 2011 10:27:48 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1770</guid>
		<description><![CDATA[APT Advanced Persistent Threat is a really popular term lately in the cyber security ecosystem. What is it concretely? The key of APT lies in its name: Advanced: Attacks uses various advanced techniques to perform these tasks. Persistent: Attackers give priority to sustainability in the victim network rather than immediate gain and exposure. Threat: Attackers [...]]]></description>
			<content:encoded><![CDATA[<p>APT <a title="Advanced Persistent Threat - Wikipedia" href="http://en.wikipedia.org/wiki/Advanced_Persistent_Threat" target="_blank">Advanced Persistent Threat</a> is a really popular term lately in the cyber security ecosystem. What is it concretely?<span id="more-1770"></span></p>
<p>The key of APT lies in its name:</p>
<ul>
<li><strong>Advanced</strong>: Attacks uses various advanced techniques to perform these tasks.</li>
<li><strong>Persistent</strong>: Attackers give priority to sustainability in the victim network rather than immediate gain and exposure.</li>
<li><strong>Threat</strong>: Attackers clearly target a specific victim with a defined goal, rather than infect randomly networks.<img title="More..." src="http://www.satorys.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /></li>
</ul>
<p>This kind of attack combines the good old methods (Trojan and vulnerabilities) to target a specific system. The best example is <strong>StuxNet</strong> which targeted the Iranian nuclear systems.  We can define attacks as APT when it satisfies the following criteria:</p>
<ul>
<li>Organized by a group preferably abroad</li>
<li>Organized with funds and means adapted to the target spotted</li>
<li>Fully incorporated in an intelligence process toward the target</li>
<li>It can’t be settled by a single hacker even super-motivated</li>
</ul>
<p>This new trend in cyber attacks shows clearly that attacks have reached a new level. They are now organized and have tremendous funds to perform significant attacks over the network. These undergrounds organizations redirects to governments or very wealthy criminals regarding the amount of resources used.</p>
<p>A <a title="Mandiant" href="http://www.mandiant.com/products/services/m-trends" target="_blank">report</a> published by the company “Mandiant” has defined the processes of an APT:</p>
<ul>
<li>System and ecosystem recognition (scanning, social engineering)</li>
<li>Stealth infiltration in the spotted network</li>
<li>Backdoor installation on the targeted systems</li>
<li>Privilege escalation towards critical systems in the spotted network</li>
<li>Installation of tools for data leakage and long-term stealth</li>
<li>Privilege escalation over all the spotted network</li>
<li>Massive data leakage using covert channels for example</li>
<li>Adapting the victim ecosystem for long-term exploitation by the attacker</li>
</ul>
<p>Analyzing these steps we can clearly see APT attacks will be most of time launched at client side. Attackers will have help internally or gain access and perform attacks from the client-side to be as stealth as possible and fly under the radar settled by security administrators.</p>
<p>Through the last months we’ve seen a recrudescence of these attacks in the news beginning with StuxNet in 2009. In the early 2010 the press coverage over Google accusing the Chinese government of a massive attack emphasized this type of attacks. More recently we can refer to the attacks over the French Economy Minister, RSA servers and Sony data leakage.</p>
<p>We are facing an evolution of cyber attacks based on data leakage and sustainability which companies and administration need to be aware of and prepared to handle. Currently they are equipped with classical security detection system with the efficiency we know… no APT mitigated, discover threat by luck and provide little visibility or comprehension of their network. I know propose to compare this classical security paradigm with the one developed here at Satorys.</p>
<h1>Classical Detection</h1>
<p>Stuxnet worm has been detected by surprise after a long period of data leakage and privilege escalation in the targeted network. The reason this worm could evade the detection is the same as for APT can infect any targeted network protected by traditional security system:</p>
<ul>
<li>Anti-virus and other protection systems work on a model consisting of identifying threat based on their signature (<em>signature-based</em> <em>model</em>). This model was working fine years ago, but now that threats and malware grow exponentially we can clearly see the shortcoming of such model. Tools exist to generate different signature for the same malware and therefore evade any classical detection system. In conclusion the signature-based model on which current detection system rely is totally obsolete and will definitely not catch up and mitigate the current and future attacks methods.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>The classical protection systems are embedded on the platforms they’re meant to protect (<em>host based model</em>). This model presents several shortcomings resulting in the total inefficiency of the detection tools. First of all, being host-based, these solutions are not capable of using collective intelligence in an effective way. Indeed it requires communicating in real-time with a central entity to update and evaluate the current level of threat. What’s more these classical detection systems are in competition with the malware itself of the platform. Indeed it’s much easier for the malware to block or evade a security system when malware have access to it. We’ve seen example of malware stopping or mitigating the host-based security system to gain privilege stealthy. Finally the protection widely released is available for all, even the attackers. They can therefore find techniques to evade the mitigation system of the security system.</li>
</ul>
<p>&nbsp;</p>
<h1>Satorys Detection</h1>
<p>Satorys identifies and mitigate cyber threats based on a different models than those quoted above. Its technology uses behavior-based and network centric models. Consequently it has the following advantages:</p>
<ul>
<li><strong>Behavior-based</strong> : It’s the essential characteristic of the technology on which everything rely. It’s the behavior of the threat that is analyzed and not its signature. This difference is crucial, indeed in the case of signature-based model, the malware could easily change its signature millions times. Whereas malware won’t have an infinity of behavior to infect systems and perform illegitimate actions on a system. Attackers will have to redefine a whole new behavior for each malware detected and will shortly be out of resources.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li><strong>Network-centric</strong> : Satorys security system gathers information from all the systems present in the network. While gathering in real-time events for all the systems, it performs correlation and detection to filter all potential threats and reverberates its analysis towards all the systems of the network. Since all the events converge toward a single centralized security system, none of the attacker can download or have access to the detection method used to mitigate them. What’s more this model has the great advantage to be perfectly adapted for effective collective intelligence. The whole set of observed events (past or from other sources) contribute to the effort of detection for future threats. Therefore the system will as much efficient as it will protect a large number of systems.</li>
</ul>
<p>&nbsp;</p>
<p>Finally we see that APT can’t be mitigate using classical method, and we’ll discover more and more through these APT the limitations of classical security methods and appliances. In conclusion if you want to know more about APT we recommend the following links:</p>
<ul>
<li><a title="Wired - Apt hacks - 2010.02" href="http://www.wired.com/threatlevel/2010/02/apt-hacks/" target="_blank">Wired &#8211; Apt hacks &#8211; 2010.02</a></li>
<li><a title="Wired - Hack for oil - 2010.01" href="http://www.wired.com/threatlevel/2010/01/hack-for-oil/" target="_blank">Wired &#8211; Hack for oil &#8211; 2010.01</a></li>
<li><a title="Commandfive - Threats" href="http://www.commandfive.com/threats.html" target="_blank">Commandfive &#8211; Threats</a></li>
<li><a title="Unisex - Daly" href="http://www.usenix.org/event/lisa09/tech/slides/daly.pdf" target="_blank">Usenix &#8211; Daly</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/apt-cyber-attacks-to-the-next-level/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recrudescence des cyberattaques visant à paralyser des sites Web et à causer du tort aux prestataires de services</title>
		<link>http://www.satorys.com/recrudescence-des-cyberattaques-visant-a-paralyser-des-sites-web-et-a-causer-du-tort-aux-prestataires-de-services/</link>
		<comments>http://www.satorys.com/recrudescence-des-cyberattaques-visant-a-paralyser-des-sites-web-et-a-causer-du-tort-aux-prestataires-de-services/#comments</comments>
		<pubDate>Mon, 02 May 2011 10:17:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1672</guid>
		<description><![CDATA[Confédération Suisse &#8211; Berne, 19.04.2011 &#8211; Les cyberattaques visent toujours en priorité à rendre les sites Web inaccessibles ou à les infecter par des maliciels. Mais les mobiles ont changé: les actes de vengeance, la volonté de nuire à la concurrence ou les agressions à mobiles politiques ont pris le relais du simple vandalisme. Le [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a title="Confédération Suisse - MELANI" href="http://www.satorys.com/pressroom/membership/confederation-suisse/" target="_blank">Confédération Suisse</a> &#8211; Berne, 19.04.2011 &#8211; Les cyberattaques visent toujours en priorité à rendre les sites Web inaccessibles ou à les infecter par des maliciels. Mais les mobiles ont changé: les actes de vengeance, la volonté de nuire à la concurrence ou les agressions à mobiles politiques ont pris le relais du simple vandalisme. Le ver Stuxnet montre encore que presque tout système est exposé à des cyberattaques. Ces thèmes et d’autres sont au cœur du douzième rapport semestriel de <a title="MELANI - Situation en Suisse et sur le plan international - Rapport semestriel 2010/II (juillet à décembre)" href="http://www.melani.admin.ch/dokumentation/00123/00124/01122/index.html?lang=en&amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ad1IZn4Z2qZpnO2Yuq2Z6gpJCDdIF7hGym162epYbg2c_JjKbNoKSn6A--" target="_blank">MELANI</a>.<span id="more-1672"></span></strong></p>
<div id="xmlWrapper">
<p>Comme dans le passé, la plupart des cyberattaques enregistrées au deuxième semestre 2010 cherchaient à rendre inaccessibles les sites Web et les réseaux. Mais les mobiles ont visiblement changé, comme l’explique dans son nouveau rapport la Centrale d’enregistrement et d’analyse pour la sûreté de l’information (<a title="MELANI - Situation en Suisse et sur le plan international - Rapport semestriel 2010/II (juillet à décembre" href="http://www.melani.admin.ch/dokumentation/00123/00124/01122/index.html?lang=fr&amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ae2IZn4Z2qZpnO2Yuq2Z6gpJCDdIF7hGym162epYbg2c_JjKbNoKSn6A--" target="_blank">MELANI</a>).</p>
<h3>Augmentation des attaques DDoS à mobiles financiers ou idéologiques</h3>
<p>Dans le cyberespace, les <strong>attaques par déni de service distribué de sites Web </strong>ou <strong>attaques DDoS </strong>(Distributed Denial of Service) ont plusieurs finalités. Au début, elles relevaient du simple vandalisme envers d’autres groupes cybercriminels ou à l’égard des autorités de poursuite pénale. Les mobiles ont changé entre-temps. On observe ainsi des attaques DDoS servant d’instrument de vengeance, visant à nuire à la concurrence, s’inscrivant dans une stratégie de racket ou poursuivant des desseins politiques. Cette dernière variante a beau ne pas être nouvelle, la sophistication des moyens utilisés et les dommages collatéraux qui s’ensuivent laissent songeur – même en Suisse. Il suffit de penser aux actes de représailles menés contre plusieurs entreprises suisses jugées hostiles au fondateur de <a title="TDG - Marco Ricca - Wikileaks - 2010.12.03" href="http://www.satorys.com/wp-content/uploads/2011/02/Tribune-de-Geneve-Wikileaks-2010.12.03.pdf" target="_blank">Wikileaks</a>.</p>
<h3>Infections de sites Web</h3>
<p>Les infections de sites Web constituent en ce moment le vecteur de diffusion de <strong>maliciels</strong> le plus répandu. Des sites sont compromis pour infecter le système des internautes de passage (drive-by download). Toujours plus d’incidents impliquent le site Web de grandes entreprises. Diverses campagnes de sensibilisation, fruit d’initiatives tant privées qu’étatiques, cherchent à combattre cette évolution et à améliorer le niveau de protection actuel.</p>
<h3>Stuxnet – attaque contre les systèmes de contrôle</h3>
<p>Il a beaucoup été question en 2010 de Stuxnet. C’était en effet le premier ver informatique à s’en prendre aux <strong>systèmes SCADA </strong>(Supervisory Control And Data Acquisition) servant à la surveillance et à la gestion des processus industriels, dans le secteur énergétique notamment. La problématique des cyberattaques visant les systèmes SCADA, dont les milieux spécialisés discutent depuis longtemps, a bénéficié pour la première fois d’une audience planétaire.<br />
L’incident impliquant Stuxnet a montré que pour peu que les cyberpirates soient motivés et leurs ressources suffisantes, presque tout système risque un jour d’être infiltré et saboté. Tout indique que des attaques similaires se reproduiront.</p>
<p>Le présent rapport semestriel de MELANI s’intéresse encore à l’essor des attaques visant les <a title="2011.04.21 -RSR journal Le 12h30- iPhone Spyware M.Ricca" href="http://www.satorys.com/wp-content/uploads/2011/04/2011.04.21.-RSR-journal-iPhone-Spyware-MRicca.mp3" target="_blank">Smartphones</a>, à l’informatique dans les nuages (<strong>cloud computing</strong>), ainsi qu’à l’évolution du marché clandestin et à l’adaptation qui s’ensuit des modèles d’affaires des cybercriminels.</p>
<p>Have a look on <a title="Satorys'Techniology - Malware Infections and User Privacy Protection" href="http://www.satorys.com/corporates-governements/" target="_blank">Satorys&#8217;Technology</a> fighting against <strong>Malware Infection </strong>and promoting the <strong>User Privacy Protection</strong>.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/recrudescence-des-cyberattaques-visant-a-paralyser-des-sites-web-et-a-causer-du-tort-aux-prestataires-de-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.satorys.com/wp-content/uploads/2011/04/2011.04.21.-RSR-journal-iPhone-Spyware-MRicca.mp3" length="3478857" type="audio/mpeg" />
		</item>
		<item>
		<title>The importance of Agile software development methods in MSSP</title>
		<link>http://www.satorys.com/agile-software-mssp/</link>
		<comments>http://www.satorys.com/agile-software-mssp/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 09:42:49 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1639</guid>
		<description><![CDATA[Agile software development is a group of software development methodologies based on iterative and incremental development, where requirements and solutions evolve through collaboration between self-organizing, cross-functional teams. Concretely for MSSP such as Satorys it means that it allows to be very reactive to take into account new inputs and updates about security functionnalities and vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>Agile software development is a group of software development methodologies based on <strong>iterative and incremental development</strong>, where requirements and solutions evolve through collaboration between self-organizing, cross-functional teams.</p>
<p>Concretely for MSSP such as Satorys it means that it allows to be very reactive to take into account new inputs and updates about <strong>security functionnalities and vulnerabilities </strong>to integrate it into our software release.<span id="more-1639"></span></p>
<p>Satorys uses one of this methodology to develop its software internally : SCRUM agile method. SCRUM allows Satorys to be in constant evolution of take into account in its development process any update concerning vulnerabilities, new ways of security detection. It also helps to provide regular and constant software release to provide new functionnalities, improved performance and bug fixes.</p>
<p><a href="http://www.satorys.com/wp-content/uploads/2011/04/SCRUM.agile_1.png"><img class="size-medium wp-image-1642" title="The importance of Agile software development methods in MSSP" src="http://www.satorys.com/wp-content/uploads/2011/04/SCRUM.agile_1-300x139.png" alt="The importance of Agile software development methods in MSSP" width="400" height="200" /></a><br />
Satorys SCRUM development process<br/></p>
<ul>
<li>Satorys can therefore be very flexible to take into account customer feedbacks and integrate it into the development process of the product. The same applies to security vulnerabilities to be integrated very quicly in Satorys products.</li>
<li>The daily meeting identifies customer feedbacks and security vulnerabilities and prioritize it before integrating it into the development process and the planning of the next release.</li>
</ul>
<p>As SCRUM defined, Satorys uses the principle of self organization to let Satorys experts deal with high-level problems without interfering or constantly micro-manage them. What&#8217;s more every collaborator has a voice concerning the possibilities of improvement or security update in the products. Satorys uses a <strong>Knowledge Base </strong>developed with the help of its collaborators to consider all aspects of problems and potentially integrate newly featured security updates.</p>
<p>From my point of view, agile development is crucial and should be considered in every MSSP to provide the best performance and updates in product release. In security,<strong> reactivity </strong>is a crucial factor and it&#8217;s useless to deal with an attack released 6 month earlier in a new product release.</p>
<p><em>Batard Florent, R&amp;D Manager,</em> at Satorys.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/agile-software-mssp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Les abonnés PlayStation de Sony piratés</title>
		<link>http://www.satorys.com/sony-pirate/</link>
		<comments>http://www.satorys.com/sony-pirate/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 09:17:46 +0000</pubDate>
		<dc:creator>fbatard</dc:creator>
				<category><![CDATA[E-Banking & E-Commerce]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1634</guid>
		<description><![CDATA[Le géant au pied d&#8217;argile Sony a vu ses systèmes piratés avec un vol d&#8217;information très important en terme de quantité (77 millions d&#8217;utilisateurs impactés) que de qualité (données personnelles et bancaires des utilisateurs). De nouveau cette affaire relance le débat sur la protection de la vie privée et surtout la sécurité des informations sensibles [...]]]></description>
			<content:encoded><![CDATA[<p>Le géant au pied d&#8217;argile <a title="LMI - Sony incapable de protéger ses abonnés PlayStation contre un piratage massif" href="http://www.lemondeinformatique.fr/actualites/lire-sony-incapable-de-proteger-ses-abonnes-playstation-contre-un-piratage-massif-33540.html" target="_blank">Sony</a> a vu ses systèmes piratés avec un vol d&#8217;information très important en terme de quantité (77 millions d&#8217;utilisateurs impactés) que de qualité (données personnelles et bancaires des utilisateurs).<span id="more-1634"></span></p>
<p>De nouveau cette affaire relance le débat sur la protection de la vie privée et surtout la <strong>sécurité des informations sensibles dans les systèmes d&#8217;information</strong>. Le fait de stocker en clair les mot de passe ainsi que de stocker tout l&#8217;historique d&#8217;achat et données bancaire sur la même plateforme ne nous rassure pas sur les normes de sécurité interne chez Sony.</p>
<p>Des normes existent notamment pour les données bancaires telles que PCI-DSS qui assure un minimum de prise de risque et d&#8217;exposition de ces données.<br />
Les antivirus et autre IDS/IPS en place chez Sony ont été incapable de traiter ces attaques ciblés car les signatures de ces attaques ne sont pas référencées. Cet échec de sécurité chez Sony est aussi l&#8217;échec du modèle traditionnel de sécurité basé uniquement sur ces signatures. Une analyse comportementale couplé à une politique sur la gestion des données sensibles aurait eu un bien meilleur effet pour percevoir cette fuite de donnée.</p>
<p>De plus cette attaque nous montre une fois de plus la nouvelle tendance de fuite de données (Data Leakage). Des informations importantes sortent du système d&#8217;information sans contrôle et l&#8217;attaque est découverte quand les pirates diffusent ces informations en ligne. En résumé, les DSI doivent se poser la question de leur <strong>politique de gestion des données</strong> (Knowledge Management) et évaluer les solutions disponibles pour prévenir et empêcher ces fuites de données avec des méthodes plus efficaces que les solutions actuelles basées sur les signatures d&#8217;attaque.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/sony-pirate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ENISA &#8211; Botnets Detection, Measurement, Disinfection &amp; Defence</title>
		<link>http://www.satorys.com/enisa-botnets-detection-measurement-disinfection-defence/</link>
		<comments>http://www.satorys.com/enisa-botnets-detection-measurement-disinfection-defence/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 15:10:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1628</guid>
		<description><![CDATA[Batard Florent, R&#38;D manager at Satorys: The European Network and Information Security Agency has released a great report concerning the botnets and the way to mitigate them. I particularly liked the detection section from page 41 as it concerns Satorys business. I completely agree on their approach concerning the drawbacks of the IDS/IPS solutions hosted [...]]]></description>
			<content:encoded><![CDATA[<p><em>Batard Florent, R&amp;D manager</em> at Satorys:</p>
<p><a title="The European Network and Information Security Agency" href="http://www.enisa.europa.eu/act/res/botnets/botnets-measurement-detection-disinfection-and-defence" target="_blank">The European Network and Information Security Agency</a> has released a great <a title="ENISA -Botnets Detection, Measurement, Disinfection &amp; Defence" href="http://www.satorys.com/wp-content/uploads/2011/04/ENISA_Botnets_Measurement_Defence.pdf" target="_blank">report</a> concerning the botnets and the way to mitigate them.<span id="more-1628"></span></p>
<p>I particularly liked the detection section from page 41 as it concerns Satorys business. I completely agree on their approach concerning the drawbacks of the IDS/IPS solutions hosted in the customer network cf p.42. It&#8217;s really hard to scale up and know where to position these IPS/IDS.  </p>
<p>What&#8217;s more they highlight clearly the drawback of having signature-based detection as the payload can easily be changed and attackers can easily bypass this security. cf p.42</p>
<p>On contrary the other passive methods exposed confirm the choices Satorys have made concerning analysis of flow records, log flow analysis and DNS based recognition. cf p.43-50</p>
<p>They also encourage initiative such as <strong>HoneyNet</strong> to source the knowledge base to detect popular and automatic botnet spreading. Once more Satorys have applied this method and built its own HoneyNet across the globe to be aware of new security trends and events globally. cf p.50-53</p>
<p>Finally they consider distributed anti-virus as an interesting idea to detect botnet in future. This typically refers to a collective intelligence to be aware and reactive to new threats that emerge in the world and the capacity to automatically update other user to make them benefit of new updates. cf p.54</p>
<p>Once more we&#8217;re comforted to see that Satorys follow this good path and agree the European agency about the way to detect and mitigate botnets.</p>
<p>This report also presents a wide variety of counter-measures to mitigate botnets for individuals, collectivities and ISPs. This is a very interesting analysis that should be considered by network and system administrators dealing with botnets issues. Satorys integrated these solutions into its knowledge base for escalation against botnets attacks and trained security analyst to efficiently deploy these solutions into customer networks.</p>
<p>They also give hints about the different national and international initiatives you can refer to concerning botnets issues. cf p.96-103</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/enisa-botnets-detection-measurement-disinfection-defence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guide to Computer Security Log Management</title>
		<link>http://www.satorys.com/guide-to-computer-security-log-management/</link>
		<comments>http://www.satorys.com/guide-to-computer-security-log-management/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 14:04:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=1618</guid>
		<description><![CDATA[The American National Institute of Standards and Technology published in 2006 a good guide regarding log management. This guide provides a wide set of recommendations to get familiar and enpower your log management. It embeds all the basics to begin with log management and to have a robust log handling architecture. Satorys&#8217; TrueBoard provides an [...]]]></description>
			<content:encoded><![CDATA[<p><a title="The American National Institute of Standards and Technology 2006" href="http://www.satorys.com/wp-content/uploads/2011/04/NST-Guide-to-Computer-Security-Log-Management.pdf" target="_blank">The American National Institute of Standards and Technology</a> published in 2006 a good guide regarding log management. This guide provides a wide set of recommendations to get familiar and enpower your log management. It embeds all the basics to begin with log management and to have a robust log handling architecture.</p>
<p><span id="more-1618"></span></p>
<p><a title="Satorys'TrueBoard" href="http://www.satorys.com/solutions/trueboard/" target="_blank">Satorys&#8217; TrueBoard </a>provides an implementation to deal with all the issues quoted in the document and helps cutomer to be compliant with these recommendations. What&#8217;s more TrueBoard logging platform provides an answer to all the challenges highlighted in this document (cf p.2-8):</p>
<ul>
<li><strong>Log Storage :</strong> with TrueBoard Cloud Log Management, you can archive TeraBytes of logs</li>
<li><strong>Log Protection :</strong> logs are transported through encrypted channel and securedly stored on disks</li>
<li><strong>Log Analysis :</strong> TrueBoard dashboard and logflow capabilities offer a wide toolset to analyze log and highlight interesting events.</li>
</ul>
<p>TrueBoard also ensures that customers have access to graphical interface, security knowledge base, incident tracking and reporting capabilities and asset information and storage correlation(cf p.3-10).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/guide-to-computer-security-log-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware Infections and User Privacy Protection</title>
		<link>http://www.satorys.com/corporates-governements/</link>
		<comments>http://www.satorys.com/corporates-governements/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 13:05:55 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Corporates & Governments]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Protection]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.farner4.ch/satorys/?p=50</guid>
		<description><![CDATA[This post aims at presenting a concrete setting of the TrueFlow product, adopted recently by a national telecommunication carrier Abuse Management to detect malware-infected customers. The challenge in this setting was the critical requirement of not relying on logs that contain any kind of nominal or personal customer information. The DNS Query Logs are therefore [...]]]></description>
			<content:encoded><![CDATA[<p>This post aims at presenting a concrete setting of the TrueFlow product, adopted recently by a national telecommunication carrier Abuse Management to detect malware-infected customers.<span id="more-50"></span></p>
<p>The challenge in this setting was the critical requirement of not relying on logs that contain any kind of nominal or personal customer information. The DNS Query Logs are therefore ideal, as they can be leveraged using Satorys’ Behavioral Security technology and Collective Intelligence sourcing system.</p>
<p>DNS Query Logs are sent by non-authoritative DNS servers and report on requests that were sent to them by customers. These requests can be of various types, whether users are requesting a Mail Exchanger, the IP address for a Website, etc. Although they give insight on Internet activity, they divulge no personal information whatsoever.</p>
<p>Satorys leverages DNS Query Logs by using a highly innovative, massively distributed HoneyNet.</p>
<p>For example, many dozen pairs of MX Honeypots are replicated throughout the Internet, over four continents.  They feed into proprietary, highly reliable blacklists, that increase the detection reliability of spambots.</p>
<p>Satorys’ highly distributed and modular Cloud relies on No-SQL (Google-like indexing) to parse and retrieve terabytes of logs in a matter of milliseconds.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/corporates-governements/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Marco Ricca presents the New TrueBoard Interface</title>
		<link>http://www.satorys.com/new-e-banking-risks/</link>
		<comments>http://www.satorys.com/new-e-banking-risks/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 09:55:23 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Risks]]></category>

		<guid isPermaLink="false">http://www.farner4.ch/satorys/?p=48</guid>
		<description><![CDATA[We are proud to present TrueBoard’s brand new, re-designed interface. A new integration functionality allows defining “LogFlows”, selecting any subset of logs, events and intelligent alarms for viewing, monitoring, reporting, charting and interfacing with a third-party platform. We have prepared a short presentation video we are happy to share with you today.]]></description>
			<content:encoded><![CDATA[<p>We are proud to present TrueBoard’s brand new, re-designed interface.</p>
<p><span id="more-48"></span>A new integration functionality allows defining “LogFlows”, selecting any subset of logs, events and intelligent alarms for viewing, monitoring, reporting, charting and interfacing with a third-party platform.<br />
We have prepared a short presentation video we are happy to share with you today.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/new-e-banking-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One Third of EU Citizens Caught Virus in 2010</title>
		<link>http://www.satorys.com/one-third-of-eu-citizens-caught-virus-in-2010/</link>
		<comments>http://www.satorys.com/one-third-of-eu-citizens-caught-virus-in-2010/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 08:00:16 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[Internet Carriers]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.satorys.com/?p=909</guid>
		<description><![CDATA[An EUROSTAT study out recently reveals that In the EU27 in 2010, almost one third of individuals (31%) who used the Internet reported that they caught a virus or other computer infection resulting in loss of information or time. 4% reported that they suffered from an abuse of personal information sent on the internet or [...]]]></description>
			<content:encoded><![CDATA[<p>An EUROSTAT study out recently reveals that In the EU27 in 2010, almost one third of individuals (31%) who used the Internet reported that they caught a virus or other computer infection resulting in loss of information or time. 4% reported that they suffered from an abuse of personal information sent on the internet or other privacy violations.<span id="more-909"></span></p>
<p>All this while 84% of internet users use IT security software for protection.</p>
<p>This study is yet another illustration of the incompleteness, and anachronistic nature, of signature-based, host-based security solutions. Only behavioral-based approaches, based on collective intelligence sourcing, nowadays stand a chance to fight modern malware.</p>
<p>See the entire study :</p>
<p><a title="Eurostar Press Release" href="http://europa.eu/rapid/pressReleasesAction.do?reference=STAT/11/21&amp;type=HTML" target="_blank">http://europa.eu/rapid/pressReleasesAction.do?reference=STAT/11/21&amp;type=HTML</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/one-third-of-eu-citizens-caught-virus-in-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TrueChannel Leveraged for Internet Freedom</title>
		<link>http://www.satorys.com/safer-internet/</link>
		<comments>http://www.satorys.com/safer-internet/#comments</comments>
		<pubDate>Mon, 14 Mar 2011 07:40:48 +0000</pubDate>
		<dc:creator>mricca</dc:creator>
				<category><![CDATA[E-Banking & E-Commerce]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TrueChannel]]></category>

		<guid isPermaLink="false">http://www.farner4.ch/satorys/?p=46</guid>
		<description><![CDATA[Big news was announced this week-end ! On the occasion of Reporters without Borders’ World Day Against Cyber Censorship, Satorys’ R&#38;D Lab presented a customized version of TrueChannel called SafetyOverIP, offered for free to selected journalists and NGOs in the world. Still in pilot phase, this project aims at proposing an effective, fast and easy [...]]]></description>
			<content:encoded><![CDATA[<p>Big news was announced this week-end ! On the occasion of Reporters without Borders’ <em>World Day Against Cyber Censorship, </em>Satorys’ R&amp;D Lab presented a customized version of TrueChannel called SafetyOverIP, offered for free to selected journalists and NGOs in the world.<span id="more-46"></span></p>
<p>Still in pilot phase, this project aims at proposing an effective, fast and easy way to access the Internet safely worldwide. Several features of TrueChannel are leveraged :</p>
<p>-  The seamless TLS/SSL tunnel is used to evade traffic tampering and censorship</p>
<p>-  Strong encryption protects against surveillance and eavesdropping</p>
<p>-  World-Class Managed Security provisions protect against data leakage and client-side attacks</p>
<p>-  A distributed SOC allows fast, broadband Internet access despite the tunnel overhead</p>
<p>Announcement event website : <a title="Act for Freedom.org" href="https://www.actforfreedom.org/" target="_blank">https://www.actforfreedom.org/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.satorys.com/safer-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

