Operations

4/16/2018
09:20 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

BluVector, Endace Announce Partnership at RSA to Provide Attack Detection, Analytics and Response Solution

LONDON -- April 16, 2018 – AI-driven network security company BluVector and high-speed network recording, playback and analytics hosting company Endace today announced a partnership to host BluVector® Cortex™ advanced threat detection on Endace’s EndaceProbe Analytics Platform. The two companies will showcase the combined solution at RSA Conference in San Francisco at BluVector’s Booth 1615, South Expo.

The solution gives both network operations (NetOps) and security operations (SecOps) highly effective AI-based threat detection alongside the definitive packet-level evidence they need to make better-informed and more confident decisions to resolve issues quickly.

“The sophistication and evolution of today’s cyber adversaries continues to accelerate, as does the number of successful intrusions. This makes network security even more important in today’s connected world,” said Stuart Wilson, CEO, Endace. “But an intrusion doesn’t have to lead to a major breach or cyber incident. The partnership between BluVector and Endace combines state-of-the-art threat detection with the accurate packet-level evidence needed to investigate, respond to and neutralise cyber intruders quickly and efficiently.”

The combined solution collects information from thousands of disparate data sources, then analyzes and prioritises the data and events. The resulting information becomes instantly available to SecOps teams, delivering the contextual data they need to quickly understand the threat and its severity. Endace’s powerful API integration with BluVector streamlines investigations, allowing analysts to swiftly click from an alert directly to the related packet history to see precisely what transpired.

Customers can deploy BluVector Cortex directly onto EndaceProbes, a hosting platform for analytics applications. This eases installation and maintenance for customers by allowing them to deploy a common hardware platform that combines full packet capture with the ability to host BluVector’s advanced threat detection solution alongside other network security and performance analytics solutions.

“Information security teams must increase their visibility and analytics capabilities to detect intruders faster and respond to them quickly and efficiently to avoid high-impact cyber incidents,” said Kris Lovejoy, CEO of BluVector. “Our partnership with Endace brings together the best in the ability to flag, record and replay attacks so IT and security teams have sufficient quality information about the incident, the data and systems affected, and the company’s relative exposure to respond accurately. And they have all this capability on a single platform.”

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.