Attivo Networks Deception Platform for Forensics and Incident Response
公司规模
1,000+
地区
- America
国家
- United States
产品
- Attivo Networks ThreatDefend™
- BOTsink
技术栈
- Deception Platform
- Engagement Server
实施规模
- Enterprise-wide Deployment
影响指标
- Cost Savings
- Customer Satisfaction
- Productivity Improvements
技术
- 网络安全和隐私 - 入侵检测
- 网络安全和隐私 - 恶意软件保护
适用行业
- 医疗保健和医院
适用功能
- 商业运营
用例
- 入侵检测系统
- 远程资产管理
- 远程控制
服务
- 网络安全服务
- 系统集成
关于客户
The customer in this case study is a regional healthcare provider located on the Eastern Seaboard of the United States. This healthcare provider operates multiple hospital locations and is responsible for the health and well-being of a large number of patients. As a healthcare provider, they handle sensitive patient data and are subject to strict regulatory requirements regarding data protection and privacy. The organization has a significant IT infrastructure to support its operations, including numerous endpoint devices and legacy systems. Given the critical nature of their services, maintaining the security and integrity of their network is of utmost importance. The healthcare provider's information security team is tasked with protecting this infrastructure from cyber threats and ensuring compliance with healthcare regulations.
挑战
In early 2016, a regional healthcare provider experienced a cyberattack that had the characteristics of Qakbot, an extremely aggressive form of malware popular in 2011. While Qakbot had appeared to be eradicated, it recently resurfaced with new strains and unknown signatures. Known for its polymorphic behavior, Qakbot spreads quickly through a network to steal critical data from its target. The attack started on a few endpoint machines and while the organization’s traditional security measures were able to detect anomalies the information security team could not action the alerts as they were not specific enough. As more alerts surfaced, they became suspicious and deployed cybersecurity devices to gain additional visibility to the legacy domain in their network. Once these devices were in operation, they raised a large number of high-level alerts, revealing a full Qakbot attack that was rapidly spreading through their network. With several new machines becoming infected every few minutes, the team knew they needed to immediately execute an incident response plan, but needed information to remediate. They needed to know where the malware came from, how it was moving laterally through their network, what credentials the malware had compromised, and much more.
解决方案
The information security team had exhausted traditional measures to identify the malware but remained unable to conclusively identify the attack. Luckily, the regional healthcare provider was completing a proof of value (POV) of the Attivo Networks ThreatDefend™ platform and had deployed an engagement server on multiple VLANs in their network. Having seen the BOTsink’ solution’s analysis and forensic capabilities, the security team detonated Qakbot inside of the deployed Deception Platform. As the malware moved laterally within the Attivo analysis engine, the Deception Platform showed which user accounts were used to deliver and execute the payload, exactly where the files were dropped, what processes were responsible for infection and lateral movement, and what the malware’s next steps would be. With detailed attack analysis and forensics, the information security team limited the spread of Qakbot through their network, block external communication to command and control, and wipe the virus off the already infected end-point devices. Additionally, now that they knew the attacker’s signatures, they were well equipped to prevent Qakbot and similar strains from penetrating their network in the future.
运营影响
数量效益
Case Study missing?
Start adding your own!
Register with your work email and create a new case study profile for your business.
相关案例.
Case Study
Hospital Inventory Management
The hospital supply chain team is responsible for ensuring that the right medical supplies are readily available to clinicians when and where needed, and to do so in the most efficient manner possible. However, many of the systems and processes in use at the cancer center for supply chain management were not best suited to support these goals. Barcoding technology, a commonly used method for inventory management of medical supplies, is labor intensive, time consuming, does not provide real-time visibility into inventory levels and can be prone to error. Consequently, the lack of accurate and real-time visibility into inventory levels across multiple supply rooms in multiple hospital facilities creates additional inefficiency in the system causing over-ordering, hoarding, and wasted supplies. Other sources of waste and cost were also identified as candidates for improvement. Existing systems and processes did not provide adequate security for high-cost inventory within the hospital, which was another driver of cost. A lack of visibility into expiration dates for supplies resulted in supplies being wasted due to past expiry dates. Storage of supplies was also a key consideration given the location of the cancer center’s facilities in a dense urban setting, where space is always at a premium. In order to address the challenges outlined above, the hospital sought a solution that would provide real-time inventory information with high levels of accuracy, reduce the level of manual effort required and enable data driven decision making to ensure that the right supplies were readily available to clinicians in the right location at the right time.
Case Study
Gas Pipeline Monitoring System for Hospitals
This system integrator focuses on providing centralized gas pipeline monitoring systems for hospitals. The service they provide makes it possible for hospitals to reduce both maintenance and labor costs. Since hospitals may not have an existing network suitable for this type of system, GPRS communication provides an easy and ready-to-use solution for remote, distributed monitoring systems System Requirements - GPRS communication - Seamless connection with SCADA software - Simple, front-end control capability - Expandable I/O channels - Combine AI, DI, and DO channels
Case Study
Driving Digital Transformations for Vitro Diagnostic Medical Devices
Diagnostic devices play a vital role in helping to improve healthcare delivery. In fact, an estimated 60 percent of the world’s medical decisions are made with support from in vitrodiagnostics (IVD) solutions, such as those provided by Roche Diagnostics, an industry leader. As the demand for medical diagnostic services grows rapidly in hospitals and clinics across China, so does the market for IVD solutions. In addition, the typically high cost of these diagnostic devices means that comprehensive post-sales services are needed. Wanteed to improve three portions of thr IVD:1. Remotely monitor and manage IVD devices as fixed assets.2. Optimizing device availability with predictive maintenance.3. Recommending the best IVD solution for a customer’s needs.
Case Study
HaemoCloud Global Blood Management System
1) Deliver a connected digital product system to protect and increase the differentiated value of Haemonetics blood and plasma solutions. 2) Improve patient outcomes by increasing the efficiency of blood supply flows. 3) Navigate and satisfy a complex web of global regulatory compliance requirements. 4) Reduce costly and labor-intensive maintenance procedures.
Case Study
Harnessing real-time data to give a holistic picture of patient health
Every day, vast quantities of data are collected about patients as they pass through health service organizations—from operational data such as treatment history and medications to physiological data captured by medical devices. The insights hidden within this treasure trove of data can be used to support more personalized treatments, more accurate diagnosis and more advanced preparative care. But since the information is generated faster than most organizations can consume it, unlocking the power of this big data can be a struggle. This type of predictive approach not only improves patient care—it also helps to reduce costs, because in the healthcare industry, prevention is almost always more cost-effective than treatment. However, collecting, analyzing and presenting these data-streams in a way that clinicians can easily understand can pose a significant technical challenge.