Aggregating Real-time Streams of DNS Logs Provides a Simple and Cost-effective Solution for Gaining Access to Critical Network Threat Intelligence
ATLANTA – February 29, 2012 – Damballa Inc., the company transforming the fight against cyber threats, today announced the successful deployment of its integration of Damballa Failsafe with HP ArcSight Logger for capturing real-time streams of DNS logs. DNS traffic often provides critical evidence that can help network security professionals discover stealthy and targeted attacks on corporate networks.
Damballa Failsafe hunts for undetected threats by correlating a variety of observed network behaviors to identify malware-infections on any type of server or endpoint device including PCs, Macs, Unix, smartphones, iPads, or embedded systems. The Damballa advanced threat protection solution analyzes suspicious downloads and monitors egress, proxy and DNS traffic to detect criminal network activity in real-time - rapidly and automatically pinpointing infected network devices under criminal control. The new feature, delivered in Damballa Failsafe 5.0 and recently deployed in production in customer environments, integrates with HP ArcSight Logger enabling Damballa Failsafe to "consume" streaming, aggregated DNS logs from DNS servers located anywhere within the enterprise network. This provides a cost effective and easy-to-deploy solution for Damballa customers to collect this vital evidence used to detect stealthy threats.
"It is well established that analyzing DNS traffic is a critical aspect of monitoring network behavior to identify truly stealthy attacks," stated Lawrence Orans, research director for Gartner.
HP ArcSight Logger is the first Universal Log Management solution that unifies searching, reporting, alerting, and analysis across any type of enterprise log data for use cases around cybersecurity, IT operations, compliance, and application development. HP ArcSight Logger supports multiple deployment options and can be deployed as an appliance and as software. Damballa customers can test this integration today by downloading a free version of HP ArcSight Logger here.
"In addition to identifying zero-day malware downloads, Damballa Failsafe monitors egress, proxy and DNS traffic behavior to discover hidden infections," said Stephen Newman, vice president of product management for Damballa. "While this traffic is typically easy to access and monitor at main corporate egress points, many enterprise networks have highly distributed DNS server environments and need creative ways to obtain DNS visibility for remote locations. With integration to HP ArcSight Logger there is now a large and rapidly growing set of companies for which implementing Damballa becomes a very easy exercise."
"HP ArcSight Logger has rapidly become the leading log management product for Fortune 1000 companies," said Varun Kohli, director of product marketing for Enterprise Security Products at HP. "Many of our customers use HP ArcSight Logger to capture and manage their DNS logs as they know DNS traffic can contain vital telltale indicators of criminal activity. The ability for Damballa Failsafe to easily consume these real-time DNS traffic streams using HP ArcSight Logger makes adopting Damballa Failsafe easy and provides a powerful deterrent to advanced threats and targeted attacks."
About Damballa
Damballa is a pioneer in the fight against cybercrime. Damballa provides the only network security solution that detects the remote control communication that criminals use to breach networks to steal corporate data and intellectual property, and conduct espionage or other fraudulent transactions. Patent-pending solutions from Damballa protect networks with any type of server or endpoint device including PCs, Macs, Unix, smartphones, mobile and embedded systems. Damballa customers include mid-size and large enterprises that represent every major market, telecommunications and Internet service providers, universities, and government agencies. Privately held, Damballa is headquartered in Atlanta. http://www.damballa.com
Media Contacts:
Ann Conrad, 404-961-7402
Damballa Inc.
press@damballa.com
Bill Keeler/Davida Dinerman, 781-684-0770
Schwartz MSL
damballa@schwartzmsl.com
Full article located here
ReplyDeleteVery knowledgeable post thank you for sharing Tableau Online Training
Thanks for providing recent updates regarding the concern, I look forward to read more.
ReplyDeleteOn Device AI Based Cognitive Detection of Bio Modality Spoofing in Medical Cyber Physical System Project For CSE
Operator Suspicion and Human Machine Team Performance Under Mission Scenarios of Unmanned Ground Vehicle Operation Project For CSE
MLP XSS An Integrated XSS Based Attack Detection Scheme in Web Applications Using Multilayer Perceptron Technique Project For CSE
Detecting Malicious Social Bots Based on Click stream Sequences Project For CSE
Emotion Classification and Crowd Source Sensing; A Lexicon Based Approach Project For CSE