Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Friday, July 14, 2017

A New Compute Experience: An Exploration of HPE’s Gen10 Servers

By Rod Knowles

Is your business finding it difficult to adapt to industry and marketplace shifts, analyzing the customer experience and/or innovating products and services rapidly?  If so, then you’re probably not thinking about, or have a plan in place for your digital transformation.  In today’s economy, digital transformation is the key to a businesses success and remaining ahead of the competition.  Through 4 key transformation areas:  Protecting the digital enterprise, Empowering the data-driven organization, Enabling workplace productivity and Transforming to a hybrid infrastructure, companies can increase profits, agility, flexibility, employee productivity and the customer experience while reducing costs and risk.  For businesses to thrive and easily adapt to their digital transformation, they need a computing environment that will deliver a Hybrid IT infrastructure providing agility, security and economic control.  HPE’s new Gen10 server line accomplishes just that.  Automation, optimized performance of workloads, secure compute lifecycle and flexible capacity are just a few of the benefits your company can gain from switching to an HPE Gen10 server.  In the next few sections, I will break down the benefits on the Gen10 line as its related to agility, security, and economic control.

Obtaining a more agile infrastructure

Manual IT operation processes can be slow and error-prone.  With the new iLO5, being introduced in all Gen10 servers, you will be able to accelerate maintenance tasks, at scale, with automated scheduling and rollback.  iLO5’s RESTful API helps automate and operate server components in all Gen10 servers from staging and updating the server BIOS, iLO, Secure Boot and TPM.  With iLO5’s intelligent provisioning, IT departments can perform initial setup tasks 22% faster than with previous versions of IP on Gen9 servers. Gen10's new Intelligent Systems Tuning can harness the power of the next generation of Intel Xeon processors and balance workloads which allows you to run more workloads on more cores, up to 28 on Intel's New Xeon Platinum processors, resulting in reduced licensing costs and more power/cooling efficiency. Couple that with HPEs new NVDIMMs to utilize the fastest persistent memory available, while realizing the real-world benefits of memory backup power, OS & Application support, reduction of database licensing costs and the fastest tier of storage on HPE Servers.

Increasing security awareness and control

Gen10 security, a better way to stay one step ahead of increasingly sophisticated attacks and protect your business utilizing the world’s most secure industry standard servers. Let’s talk about that for one quick moment, “The World’s Most Secure Industry Standard Servers”.  As recently announced at HPE Discover 2017, HPE engaged InfusionPoints to conduct an independent assessment of the security of the Gen10 Server’s hardware and platform firmware against three of HPE’s competitors. The test consisted of attacks against physical interfaces, platform firmware, and network interfaces.  The results showed that HPE Gen10 servers are a significant step ahead of their competitors and that HPE’s introduction of silicon root of trust will set new standards in providing auditable control of the integrity of platform firmware.

The new Gen10 family of servers provides a host of security features:  firmware protection, run time attack detection, behavioral risk mitigation, data protection, compliance planning and End of Life disposal.  HPE’s new firmware protection is backed by HPE’s own silicon fingerprint unique to each and every server.  With HPE’s silicon root of trust, Gen10 servers WILL NOT boot unless the firmware matches the fingerprint and is protected through the entire supply chain: manufacturing, distribution, shipping, configuration, and installation. It’s locked and HPE is the only vendor who can do this.  When the server boots, millions of lines of firmware code run and verify before the operating system even boots.  Additionally, the firmware is checked every 24 hours verifying validity and credibility of UEFI, CPLD, iLO, IE and ME and reports any malware or compromised code.  Firmware can also be checked and validated on drives, NICs and other HPE server options containing firmware. When a detection of compromised firmware is discovered, the ability to send alerts and quickly recover to a good known state can be set to occur automatically or you can choose to take the compromised server offline.  The ability to recover other server settings can also be recovered as well as the future ability to recover operating systems. 
HPE’s Gen10 servers also offer advanced machine learning that identifies any malicious behavior.  Think of it like this:  The system endlessly trains itself and learns behavioral patterns.  It then analyses and identifies changes in these patterns that may relate to suspicious activity and informs you if there is a threat.  This advanced machine learning technology utilizing Niara’s behavioral analytics protects your organization from inside attacks.  Gen10 servers are protected from inception to their demise. When your server(s) are being disposed of, its embedded data cannot be reconstructed or accessed any longer, forever, utilizing enhanced data protection and encryption.

Managing Your Time and Money Productively

In addition to the Gen10’s server line agility and security features, Economic Control helps you control costs with over-provisioning, out-of-control public cloud costs and the pressures of transforming without the appropriate budget.  Utilizing HPE Flexible Capacity will help align your costs with monthly usage and requires no upfront payments.  Pay only for what you use and scale in minutes, not months.  If you're currently a legacy Gen9 server owner, there are several options for transitioning to a Gen10 server by utilizing one of HPE’s investment models for transforming from legacy IT to a hybrid IT model.

For more information on HPE Storage and Networking, please contact Convergent Technologies Group at 888-353-5307 or via our contact us page



 Rod Knowles is a solution architect with Convergent Technologies Group.

Thursday, April 23, 2015

Kidnapping Your Data

Ransomware attacks at several of our customers over the past several weeks – including two in the past five days alone - speaks to the urgency with which you should understand and take action.

Ransomware, sometimes known by the names CryptoLocker or CryptoWall, are exploits that encrypt your data and then demand money to free it. So far, we've had some luck in mitigating the data loss for some customers that have been hit. Good backup practices in those cases saved the day.

First response is essential

I can't stress this enough: Call us immediately – but don’t wait for us to arrive before starting the first steps outlined below. 

The key first step is to right click the ransom note (usually a text file in the same directories as the encrypted files), select properties, and whomever owns that text file, well, that is the one that's infected.

Next, get any machine(s) off whatever network that file owner might have been using around the date/time that the file was created. Turn it off. Don't turn it back on until the operating system has been reloaded.

We'll want to look at every ransom note text file on the drive to make sure you don't have more than one infected machine. Do not delete those ransom note files: They're not infected, and they'll tell us how far the malware got before it stopped. They also hold important information should your worst case recovery option – paying the hackers - becomes the only option

Now that you’ve (hopefully) mitigated the problem’s spread, start lining up your recovery options.

1. Do you have a good recent backup? A good backup solution can reduce the amount of data lost to hours, or, at worst, days. Days might not be a big deal depending on the volume of changes to a file. The proposal you wrote a year ago? Not a biggie. Your accounting database? Probably a biggie.

2. Pay the ransom. Unfortunately, you might have to balance the ransom cost with the value of that hijacked data. At least you won't have ABC News doing a story on you, like a certain sheriff's department in that link above. The good news is that these efforts are specifically intended to generate revenue. In an odd bout of honor among thieves, they’ll want to unlock your files after payment because, if they don’t, then no one will pay.

Why? Why? Why?!! (or should that be How?? How?? How??!!)

The first thing we hear is "How did this happen? I have anti-virus running!" That doesn't really matter. In fact, we've seen in one case that anti-virus programs were blocking less than 20 percent of malware.

The latest efforts have gotten even more sophisticated. Where once you had to actually do something – such as click on a link or ad, go somewhere potentially suspect, or download software – now you just need to visit your favorite well-known website (think big trusted organizations with ads on their sites). This has gotten pervasive enough to get its own name: malvertising. Yes, those flashy (pun intended) ads that pop up and try to get your attention are the vector for this exploit. I'll skip repeating what other news stories or blogs say, and we can go on to some good suggestions to avoid this issue.

How to avoid ransomware

While you might be tempted to move to a remote cabin in Montana or disconnect the Internet entirely, you do have other viable options. But they come with some trade-offs, such as Web pages not rendering how they're intended or having to occasionally let scripts run on a site that requires it. Get hit once and lose critical data, and those trade-offs become more tolerable.

1. Choose your browser wisely. I rarely use Internet Explorer unless a vendor’s site is still locked in to some proprietary Microsoft Web things. Consider switching to FireFox or Chrome. Most of the security analysts I know and listen to use FireFox as their primary browser.

2. Add some extensions (add-ons) to your browser. Add and enable Flash and script blockers, which will stop ads and scripts from automatically running and potentially delivering the malware to your machine. For FireFox, I have FlashBlock and NoScript running. Each gives me the option to enable the Flash or scripts on a case-by-case basis, but nothing runs automatically, For Chrome I use FlashControl and ScriptSafe.

3. Stop clicking on shortened URLs. Those things can take you anywhere, and you won't know until it's too late. I know that kitten pic that someone tweeted about is incredibly tempting. Don't do it. At least not on a company PC.

4. Keep your applications and operating systems up-to-date. When you receive security patches and updates, be sure you are routinely running them.

5. User Awareness is paramount. You can’t take adequate precautions without being aware of the dangers. Given the ever-changing threat landscape of the Internet, make awareness a recurring theme. Over the next few months, we'll be putting together a regular published newsletter that you can forward to your employees.

6. Good backups are the answer. That statement probably stands on its own. Whether it's some outsider encrypting your data or a disk drive failing, you want to be able to get that data back.

The bad guys are getting more creative, and your traditional firewalls and anti-virus are no longer enough to hold off the horde. CTG is ready to come in and consult on ways to better protect your data from thieves, vandals and kidnappers.

 Jeff Garell is co-founder of CTG.