Search This Blog

Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts

Wednesday, May 30, 2012

JUNIPER NETWORKS RELEASES NEW MYKONOS SECURITY SOFTWARE TO STOP WEB ATTACKS

Press release:


JUNIPER NETWORKS RELEASES NEW MYKONOS SECURITY SOFTWARE TO STOP WEB ATTACKS

New Software Offers Improved Protection, Simplified Management and Increased Scalability
SUNNYVALE, CA--(Marketwire - May 30, 2012) - Juniper Networks (NYSEJNPR), the industry leader in network innovation, announced major platform enhancements to its Mykonos Web Security Software, which uses ground-breaking Intrusion Deception™ Technology to defend against web-based threats in real-time. The new release of Mykonos Web Security provides 30 new features and enhancements that strengthen protection against a wider range of attackers and hacking techniques, simplify configuration for security administrators, and boost scalability to help ensure holistic protection as traffic volumes increase.
View a demo of how Mykonos Web Security works here.
Web applications and websites are under constant attack and are the most popular targets for hackers because they remain the largest unprotected threat in corporate networks. A Ponemon Institute survey found 73 percent of organizations have been hacked at least once in the past two years through insecure web applications.
The Mykonos Web Security solution uses deception to create detection points -- or tar traps -- to identify malicious actors in real-time as they attempt to hack their desired target. Once attackers are identified, Mykonos Web Security prevents them from compromising critical information, wastes their time by presenting false vulnerabilities and provides valuable intelligence to thwart future attacks. This active, intelligence-based approach uses Mykonos' Intrusion Deception™ System -- the only system that truly neutralizes threats as they occur -- giving companies the upper hand by using attackers' actions against them without relying on signatures or passively restricting traffic. With Mykonos Web Security, Juniper Networks is transforming the security industry and changing the ROI of hacking by making it costly, time consuming and tedious for attackers to chase after false data.
Release Highlights
  • Enhanced security protections: Mykonos Web Security now detects a wider range of attackers and hacking techniques, protecting against more threats, as well as provides new countermeasures, including:
    • Preventing brute-force authentication attacks that rapidly guess combinations of usernames and passwords to gain access to systems. Mykonos Web Security prevents the attacker from using any compromised credentials even if an attacker happens to 'guess' the correct password.
    • Defending against directory traversal attempts that are used to map websites to gain additional information on how to attack them.
    • Integrating third-party software vulnerability protection into Mykonos Web Security, which helps prevent against known software vulnerabilities typically targeted by automated attack scripts. Mykonos Web Security now integrates a large library of known third-party attack data into its tracking, profiling, and response systems.
  • User-friendly and intuitive interface: A simplified interface unifies the security console and configuration, making it easier for customers to manage systems, as well as provides a new setup wizard tool to quickly deploy without assistance from Juniper Networks.
  • Greater performance clustering: Mykonos Web Security now supports throughput greater than 1Gb/second by enabling customers to add multiple slaves to a clustering model. In effect, this allows for Mykonos Web Security to protect higher-volume web properties.
  • Comprehensive approach to security: The new version of Mykonos Web Security provides a significant new layer of defense against web attacks and builds on the successful SRX and vGW platforms as a key component of Juniper's strategy to deliver a comprehensive and automated approach for data center security.
Supporting Quotes
"Web-based threats have become a major concern and companies require a proactive solution with real-time prevention to augment traditional-network security defenses. Mykonos is the first company to detect hackers during the reconnaissance phase of an attack. We can track, profile and, most importantly, respond to an attacker before the damage is done."
-David Koretz, vice president and general manager, Mykonos Software, a Juniper Networks Company
"Juniper's Mykonos Web Security solution addresses the critical security issues that enterprises face today. At a time when buyers are questioning whether their investment in legacy solutions is providing adequate protection from today's threats, Juniper is providing an innovative solution."
-Jeff Wilson, principal analyst, Infonetics Research
Additional Resources:
About Juniper NetworksJuniper Networks is in the business of network innovation. From devices to data centers, from consumers to cloud providers, Juniper Networks delivers the software, silicon and systems that transform the experience and economics of networking. Additional information can be found at Juniper Networks (www.juniper.net) or connect with Juniper on Twitter and Facebook.
Juniper Networks is a registered trademark of Juniper Networks, Inc. in the United States and other countries. The Juniper Networks logo is a trademark of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners.

Tuesday, May 8, 2012

Cisco Paves Way for CIOs to Fight Costly Voice Fraud, Theft and Service Attacks


PRESS RELEASE

Cisco Paves Way for CIOs to Fight Costly Voice Fraud, Theft and Service Attacks

Enables partners to develop applications that improve the security, visibility and control of the voice network; BT to deliver first service based on the technology

SAN JOSE, Calif. – May 8, 2012 – As IT managers look for ways to thwart voice fraud and other types of malicious activity, Cisco today announced the Cisco® UC Gateway Services API, a Web-based application programming interface (API) that could play a direct role in helping organizations deal with this problem. The API opens up the enterprise voice network edge to enable more voice services on the Cisco Integrated Services Router Generation 2 (ISR G2) router.
The Cisco UC Gateway Services API gives customers and partners easy access to call information—both signaling and media—at the network edge.  This information can be used to detect and thwart malicious activity, including but not limited to: social engineering and identity-theft scams, contact center account takeover fraud, unauthorized network access and service use, and even the telephony denial of service (TDOS) attacks that are often launched to divert attention while cyber-thieves drain bank accounts of cash or steal customer data from contact centers. Once malicious activity is detected, the Cisco UC Gateway Services API allows applications to apply appropriate policy action by the Cisco voice gateway, such as call termination, call redirection or call forking (for recording).
This advancement is important as global telecom fraud losses are estimated to be $40 billion annually, according to the Communications Fraud Control Association (CFCA) Telecom 2011 survey.
The Cisco UC Gateway Services API is supported on the Cisco ISR G2 with the Cisco Unified Border Element (CUBE) for SIP trunks and Cisco TDM Gateways for TDM trunks, both of which provide voice connectivity to the service provider.  Therefore, the services enabled by this API can be extended across all voice gateways throughout the enterprise on a global basis to achieve dramatic improvement in control of the edge of the voice network no matter what technology the enterprise uses for voice connectivity.
KEY HIGHLIGHTS:
  • BT is the first service provider to take advantage of the Cisco UC Gateway Services API by significantly bolstering its BT Assure Cloud Security Service, which until this point has focused mainly on data security services. Now, BT customers will be able to identify threats for voice and data globally in a single dashboard and mitigate these threats proactively. BT will be the only provider to offer a single view based on its ability to monitor and control real-time data and voice activity from the most widely used edge router in the industry, the Cisco ISR G2.
     
  • The BT solution also uses the voice policy and security applications of SecureLogix.  SecureLogix is the first Cisco technology development partner to integrate its applications with the Cisco voice gateways using this new API and deliver a complete solution to help both service providers (like BT) and enterprises achieve a new level of visibility and control of their voice traffic over the network.
     
  • Cisco enables these additional services without requiring additional devices at the network edge.  Third-party applications using the Cisco UC Gateway Services API can be run directly on the Cisco ISR G2 using the Cisco UCS Express server blade built for the router chassis, or can be accessed via the cloud.
     
  • The information made accessible by the Cisco UC Gateway Services API can also be used in non-security-related cases, such as to ensure regulatory compliance via call recording and improve business operations with employee or departmental productivity and efficiency reports showing call volumes, durations, and other details.
     
  • Cisco is also using the Cisco UC Gateway Services API to better integrate its own products into the Cisco TDM Gateway and CUBE.  For example, via the Cisco UC Gateway Services API, Cisco MediaSense can now dynamically select and record specific calls, which is useful in contact centers for quality monitoring purposes.  
SUPPORTING QUOTES:
Mark Lohmeyer, vice president of product management, Cisco
"Cisco has a long history of innovation. Innovative services made possible by the Cisco UC Gateway Services API add value to our session border control and TDM gateway offerings and bring added visibility and control to the voice network."
Jeff Schmidt, global head of business continuity, security & governance, BT Global Services
"With Cisco and SecureLogix, BT can provide the industry's first enterprise-wide security solution for both data and voice, which includes TDM and SIP trunking, integrated onto a single platform - the Cisco ISR G2. Our customers now have a single view of their network that allows them to proactively identify threats and dynamically control the network to prevent attacks."
 
Lee Sutterfield, president, SecureLogix
"Through Cisco's open API for TDM and SIP trunking, we are able to help customers gain control and secure their entire network as they transition to SIP with just a single application.  By integrating our solution on the Cisco ISR using the UCS Express, we were able to help our customers streamline the network edge by eliminating devices."

Cisco UC Gateway Services API (http://developer.cisco.com/web/gsapi)
Cisco Unified Border Element (CUBE) (www.cisco.com/go/cube)
Cisco TDM Gateways (www.cisco.com/go/tdmgateways)
Unified Communications on Cisco ISRs (www.cisco.com/go/uconisr)
Technorati Tags:
unified communications, Cisco Developer Network, collaboration, Cisco Unified Border Element, Cisco TDM Gateways, Cisco Integrated Services Router, ISR G2
About Cisco
Cisco (NASDAQ: CSCO) is the worldwide leader in networking that transforms how people connect, communicate and collaborate. Information about Cisco can be found at http://www.cisco.com. For ongoing news, please go tohttp://newsroom.cisco.com.
# # #
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.