East Security Strengthens Alyac's Detection for Linux Servers
IT DAILY ·
✦ AI Summary
East Security has updated Alyac for Linux servers with behavior-based ransomware detection.
The new feature counters ransomware by combining file tampering detection, system anomaly analysis, and 'decoy tampering detection.'
Alyac for Linux servers also provides a 'monitoring mode' for stable operations.
East Security, the security-focused subsidiary of ESTsoft, is pushing ransomware defense aimed at the Linux OS. East Security has strengthened its response by updating Alyac for Linux servers with behavior-based ransomware detection. The change took effect on the 28th, industry sources said.
The update is seen as an effort to extend behavior-detection technology built over the past 10 years to Linux. East Security has broadened its ransomware response coverage by adding behavior-based detection to its Linux server security product.
The new feature works by combining file tampering detection with analysis of abnormal system behavior. Behavior-based detection is regarded as an important method in ransomware defense.
This stands in contrast to the Signature-based pattern detection used in traditional antivirus software. Signature-based detection stores the unique patterns of known malware in a DB and then scans systems to check for matches.
However, traditional antivirus Signature-based pattern detection has limits when it comes to detecting new and variant threats. The photo was provided by East Security.
As ransomware threats have increased through RaaS and other channels, the limits of Signature-based detection have become apparent, boosting the need for Signature-free ransomware detection technology based on behavioral pattern analysis. Alyac first applied its behavior-based ransomware blocking feature in December 2015.
According to the company, the free public version of Alyac is offered to individual users at no cost, and it blocked 43,747 attacks in the second quarter of this year with its behavior-based ransomware blocking feature.
With this update, behavior-based ransomware detection has been added to Alyac for Linux servers. The detection method comprehensively analyzes multiple abnormal behavior signals, including 'decoy tampering detection,' and those signals include the use of bait files, consecutive changes to multiple files, renaming, extension changes, abnormal deletion, and file changes across multiple directories.
In critical server environments, stability is as important as security. To that end, Alyac for Linux servers provides a 'monitoring mode' to support stable operations. The feature was designed as a safeguard to prevent false positives and service disruptions when the solution is introduced.
The 'monitoring mode' is designed to enable the safe application of customized security policies for each server environment by taking into account differences in application and file access patterns across enterprise servers. In this mode, suspicious processes are not blocked immediately. Instead, administrators are guided to assess the practical impact of the detection results.
Administrators can run monitoring for a set period of time. Afterward, they can confirm normal operation and adjust protection paths, exception items, and response methods. The system was designed to require an impact review and policy adjustment rather than immediate blocking.
Ransomware attacks have mainly targeted the Windows OS, which is used by many users. Compared with Windows, Linux is seen as a relatively safe haven from ransomware. There are many types of Linux, including Ubuntu and Debian, and even within the same OS, system configurations differ depending on the kernel version. Attackers, by contrast, mainly target Windows because it has a broad user base and relatively low diversity.
Ransomware has shown a shift from a Windows-centered model to one that uses Linux variants. A representative example is the June 2017 Internetnayana incident. At the time, 153 web servers and backup servers were infected with the ransomware Erebus, which was originally for Windows only, but a Linux variant was used in that case. Since then, Linux variants have appeared in several other ransomware strains, with Mallox and Qilin cited as examples.
Ransomware attacks on Linux servers cause major damage to organizations because Linux server environments concentrate core enterprise data and services, including web servers, DBs, and business systems. For this reason, attackers are spending more time developing separate Linux variants, and the fact that attacks on Linux servers can inflict large-scale damage is seen as the background for that shift.
Recent ransomware attacks have raised the level of coercion through 'double extortion.' In the past, the main tactic was to encrypt data and demand a ransom, but recently attackers have first stolen sensitive information and then threatened to leak or delete it. As a result, data backups and the deployment of security solutions that can preempt ransomware attacks are needed in response.
Baek Sang-min, head of the Security Response Center at East Security (ESRC), said that decryption after a ransomware infection is nearly impossible as a post-incident measure, and that recent attack patterns are expanding into threats involving stolen data. He said infection prevention should be the top priority, and cited security solutions, infrastructure, and thorough backups as conditions for system protection.
Lee Ji-han, head of product development at East Security, said that the key elements for responding to advanced cyberthreats are the latest security technologies, patch updates, and security policies optimized for operating environments. He also said the company plans to continue advancing technologies to help customers maintain stable business environments.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241266
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.