Necurity Proposes Strategy to Boost External Attack Surface Visibility, “Tracking Hidden IT Assets Too”
TECHWORLD ·
✦ AI Summary
Necurity presented an ASM and threat hunting strategy for identifying externally exposed IT assets of companies.
At the "CONCERT Fall Full Member Workshop" held in Jeju on September 3-4, it introduced security operations strategies and use cases leveraging Censys.
Censys scans more than 8 billion IPv4 and IPv6 addresses and all 65,535 ports every day, and the ASM asset identification engine analyzes more than 100 types of digital information.
Necurity presented an ASM and threat hunting strategy for identifying externally exposed IT assets of companies. The goal is to rapidly track cyberthreats. Necurity said it made the announcement on the 18th.
Necurity participated as an associate member in the "CONCERT Fall Full Member Workshop" held in Jeju on September 3-4, and introduced security operations strategies and use cases leveraging the internet intelligence platform Censys. Through this, it explained the direction of external attack surface management.
The presentation focused on ways to reduce the time and operational burden of individually analyzing various security alerts in the SOC and fragmented external threat data. It also stressed the importance of detecting externally exposed shadow IT that companies do not recognize and of understanding the entire attack surface from an attacker's perspective.
Necurity said that Censys scans more than 8 billion IPv4 and IPv6 addresses and continuously scans all 65,535 ports every day to collect internet infrastructure information. Based on this, the average time required to detect a new service is 8.9 hours, shorter than the comparison target's average of about 62.1 hours, giving it an advantage in new service detection speed over the comparison target.
It also introduced a past data-based breach analysis function. The average lifespan of a short-lived malicious C2 server is 2.5 days, but it said tracking remains possible even after it disappears based on past SSH key records, certificate records, and protocol records. It added that it uses digital fingerprint-based clustering to additionally identify infrastructure that may be related to the same threat actor.
The Censys ASM asset identification engine was also introduced as a function that analyzes more than 100 types of digital information for externally related assets of a company. The company explained that this makes it possible to identify assets directly managed by the parent company, and to continuously search for subsidiary assets and affiliate assets brought in through mergers and acquisitions, new services, and IT assets that are often overlooked in management.
Necurity plans to support faster risk analysis that security personnel actually need to respond to by integrating fragmented external data.
Choi Hong-jun, head of Necurity's Strategic Business Division, said that externally related assets unknown to a company can become security blind spots, and added that the company will support domestic companies in securing visibility into their attack surfaces using Censys's discovery capabilities and in strengthening risk-based security operations systems.
Source: TECHWORLD · Kim Gyeong-ju
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407126
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.