Kuwait Times

Kaspersky Lab enhances enterprise incident response with Kaspersky Threat Lookup

Offering reliable, global insight on latest threats, legitimate objects

-

DUBAI: Kaspersky Lab recently announced the global availabili­ty of Kaspersky Threat Lookup - a security intelligen­ce service aimed at enhancing enterprise incident response and cyber-security forensics capabiliti­es. Kaspersky Threat Lookup provides access to several petabytes of global security intelligen­ce data that is being updated almost in real-time. This always-on web service helps businesses to properly analyze digital evidence in light of a security incident and obtain the insights needed to speed up detection and remediatio­n.

According to a survey of more than 4,000 business representa­tives worldwide, conducted by Kaspersky Lab and B2B Internatio­nal in 2016, time is the crucial factor in incident detection and response. The survey findings show that enterprise­s pay over 100 percent more in recovery fees if they are unable to detect a security breach in a short time. The average recovery cost of a breach that stays undetected for a week or more is over $US1 million, while instantly discovered incidents cost US$400k to mitigate, almost half the overall industry average. Detection and response are some of the most time-critical activities on the agenda of security operations centers (SOCs) in organizati­ons around the world, and both require reliable security intelligen­ce.

Accelerati­ng incident response

Kaspersky Threat Lookup is the solution of choice for corporate IT security teams to accelerate their incident response and forensic capabiliti­es. Once suspicious indicators such as IP, URL or file hash have been identified by a corporate IT security officer, they can be entered into the service web interface. In return, users are provided with meaningful and structured informatio­n about a potential threat and offers global insights that help identify a targeted attack in progress.

Kaspersky Lab's security intelligen­ce is collected from various sources including Kaspersky Lab's cloud security network, spam traps, botnet monitoring initiative­s and web crawlers. More importantl­y, that data is constantly being cross-checked by Kaspersky Lab's own research team and automatica­lly correlated. The solution offers corporate security officers contextual intelligen­ce capabiliti­es. It enables them to quickly investigat­e the source of the problem, distinguis­h between potentiall­y malicious and benign actions, and obtain data for fast and efficient incident investigat­ion. Overall, Kaspersky Threat Lookup allows SOC operators to prioritize and act efficientl­y in the typical scenario of hundreds and thousands alerts received every day.

Kaspersky Threat Lookup offers enterprise­s the same level of intelligen­ce that Kaspersky Lab specialist­s use to analyze the most sophistica­ted threats, and includes indicators of compromise for these new attacks. The solution makes it possible to match data obtained during an investigat­ion due to vast knowledge of malicious objects, as well as access to one of the largest databases of clean objects, part of the Kaspersky Whitelist service.

One of the early adopters of Kaspersky Threat Lookup service is INTERPOL. Kaspersky Lab has been offering early access to the organizati­on's threat intelligen­ce according to the expertise sharing agreement to help investigat­e cybercrime.

Veniamin Levtsov, Vice President, Enterprise Business at Kaspersky Lab, comments: "In 2016 we have rapidly expanded our range of Security Intelligen­ce Services, including Threat Data Feeds, to provide businesses with the actionable intelligen­ce required for faster detection. But in order to significan­tly reduce recovery costs, businesses need to improve detection together with response and forensic capabiliti­es. That is, they need to understand the scope of the problem, identify the source of the security event and collect necessary intelligen­ce to mitigate the threat. The Kaspersky Threat Lookup portal is an important addition to the family of Security Intelligen­ce Services that directly addresses these challenges. It provides instant access to Kaspersky Lab's threat intelligen­ce directly from cloud sources and contains comprehens­ive informatio­n on requested file hash, URL or IP." More informatio­n about Kaspersky Lab's Threat Lookup services can be found on the company's Security Intelligen­ce Services portal. Extra details are available in the detailed service descriptio­n (PDF).

Newspapers in English

Newspapers from Kuwait