Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

LynuxWorks demonstrates its Rootkit Detection System to IT security experts at the Virus Bulletin Conference

October 2013 by Marc Jacob

LynuxWorks, Inc. announced that the company will demonstrate the RDS5201, a new and unique product to help detect the stealthiest of advanced persistent threats (APT), the rootkit,at the Virus Bulletin Conference in Berlin on October 2 - 4. The Virus Bulletin Conference brings together security experts from government and military organizations, legal, financial and educational institutions and large corporations worldwide and covers a wide range of anti-malware and spam-related subjects.

LynuxWorks Rootkit Detection Demonstration:
In the LynuxWorks booth, there will be a demonstration of this new small form factor appliance that has been designed to offer a unique detection capability that complements traditional security mechanisms as they try to protect against the growing number and complexity of cyber threats. Able to detect low-level, zero-day rootkits—the lethal payload of most APTs, the custom-built hardened appliance serves as a smart proactive sensor against APT attacks in IT networks and reduces the agonizing detection of APTs from weeks/months to seconds, and is the first and only technology capable of detecting and alerting against such threats in real-time.
The RDS5201 is built on LynuxWorks LynxSecure 5.2 separation kernel and hypervisor, offering a secure platform to contain and watch these malicious threats.

“Detection of multi-stage APT & sub-OS rootkits calls for new technology and new class of products, specifically designed to deal with these normally undetectable cyber threats,” said Avishai Ziv, vice president of Cyber Security Solutions at LynuxWorks. “The RDS5201 Rootkit Detection System, powered by our unique and innovative secure hypervisor, does that: Real-time detection of all sub-OS infections, coupled with immediate and accurate live forensics data.”

Based on the LynxSecure separation kernel and hypervisor, The RDS5201 offers a non-detectable secure platform that is used to exercise potential infections and with the introduction of the patent pending rootkit detection feature from the 5.2 release. These stealthy threats are revealed as they attack their virtual victim. LynxSecure is the most privileged monitor in the RDS5201 platform, and constantly monitors for malicious and irregular activity in key disk areas (MBR, key blocks and sectors); physical memory areas; CPU instructions and data structures; interrupt data structures etc. This detection is completely OS agnostic, as it’s situated below any of the guest OS. Upon detection, the RDS5201 immediately alerts and sends an automated live forensics report to its dashboard. The report contains visual representation (such as the clean and infected disk sectors in-memory data structures), allowing rapid and focused threat response. The RDS5201 can also be connected to other network protection systems such as SIEM and threat management systems, offering an early warning mechanism that complements and enhances existing security solutions.


See previous articles

    

See next articles












Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts