WHAT THE SUNDAY TERROR ATTACK MEANS FOR MALI—AND A... » WHAT THE SUNDAY TERROR ATTACK MEANS FOR MALI—AND AFRICA? At least two people have been killed in a ... Need to "Repeal the Perpetual Illegal Wars" » Charlie Savage of the New York Times reports in "Senators Wrestle With Updating Law Authorizing War ... After Terrorist Attack, Spain Rejected Its Hawks. ... » Email: sam@accuracy.org Husseini is communications director with the Institute for Public Accuracy.... Cisco includes Italtel’s enterprise SDN applicat... » Milan: Italtel has announced its Netwrapper application has been included in the official Cisco GPL ... InfinityQS upholds ISO 9001:2015 & ISO 27001:2013 ... » InfinityQS® International, Inc. (InfinityQS) has announced that it has successfully sustained its ce... New PT Application Firewall easier to deploy, co... » London: Cybersecurity expert Positive Technologies has announced a new version of its web applicatio... Logicalis acquires Packet Systems Indonesia to g... » London: Logicalis, an international IT solutions and managed services provider, together with Metrod... Revolutionary new AI event to launch in London -... » London: With discussion around artificial intelligence (AI) at an all-time high, MACHINA Summit.AI i... Basefarm acquires The unbelievable Machine Compa... » LONDON: Basefarm has announced their acquisition of the Berlin-based The unbelievable Machine Compan... PhishMe takes home SC Europe Awards 2017 » LONDON, UK: PhishMe® Inc. has announced that PhishMe Simulator™ and PhishMe Reporter® were recognise...

CLICK HERE TO

Advertise with Vigilance

SOCIAL BOOKMARK

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

NEW YORK CITY:  Balabit has been listed as a representative vendor in Gartner’s Market Guide for User and Entity Behaviour Analytics (UEBA). Gartner identified Balabit as a stand–alone UEBA Platform.

According to Gartner; “Buyers are primarily focused on monitoring for external attackers that have breached an organization's defences and have compromised users' accounts, and for insider threats that increase risk to an organization through unauthorized or illegal activities.”(1)  Balabit’s Blindspotter is specifically designed to address these customer needs.

Gartner’s Market Guide for User Entity Behaviour Analytics also observed: “Stand-alone UEBA vendors still need to mature their offerings for enterprise use by implementing access controls, user interfaces for rule management, richer reporting and workflow.”(1)  Balabit’s Blindspotter is tightly integrated with the company’s Privileged User Monitoring tool, Shell Control Box as part of its Contextual Security Intelligence platform. Blindspotter can terminate a privileged user’s connection should his risk score exceed a predefined threshold.

Within the UEBA market, Balabit has a particular focus on privileged users; those users who represent the greatest risk of an insider attack, and whose credentials are most valuable to external attackers. Blindspotter builds profiles of these users and monitors their behaviour in real-time.

“We are focusing on effectively monitoring privileged users rather than adding further access controls that can impede business processes, so we provide market proven security without burdening users with additional constraints” said Zoltán Györkő, co-founder and CEO at Balabit. “Because attack methods evolve constantly, Blindspotter goes beyond pre-set rules and uses machine learning to recognize the digital footprints of users and identify deviations from baseline behaviours that signal threats.”

Balabit's Shell Control Box records much more granular data about privileged users than log management systems. This granular data about privileged users enables Balabit to deliver unique features including:

Keystroke Dynamics Analysis and Mouse Movement Analysis – to both identify breaches and serve as an additional and continuous layer of biometric authentication;

Command Analysis and Window Title Analysis – driven analytics that build a baseline behavior profile of the individual privileged user’s regularly issued commands and applications used;

Automated Intervention – Aside from sending alerts to security analysts or notification of suspicious behavior to users, Blindspotter can leverage Shell Control Box during real-time events to terminate the connection of a potentially hijacked account or malicious insider;

Tamper-Proof Audit Trails - Shell Control Box Audit Trails are the most important data sources of Blindspotter – and unlike logs, are completely tamper-proof and cannot be erased or modified by attackers.

“Our solution is unique because of the granularity of the data that we record and analyse. The audit trails of Balabit's session recording module - Shell Control Box - enable a video-like playback of user activities which are tamper proof so they cannot be erased by attackers. The UEBA module, Blindspotter, processes these audit trails to its analytics and provides continuous authentication based on biometric identification capabilities – such as keystroke analysis” added Zoltán Györkő.