Tag: Barracuda

Barracuda announces threat predictions for 2022

By – James Forbes – May, Vice President, Barracuda Networks APAC

Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, revealed predictions that will shape the future of the cybersecurity and tech space in the coming year.

Ransomware will still be a problem

Ransomware would continue to dominate the news for being the most lucrative way of making money for the bad guys. However, there will be a renewed focus on the governments prioritizing cybersecurity initiatives, building alliances with vendors, and sharing data with other countries. This level of collaboration will help improve security for everyone.

In this post-breach era, ransomware attackers have been ahead of their targets since they have their hands on stolen data, including credentials. These attacks range from extortion on valuable data to penetrating the software supply chain. It has gone beyond disrupting business operations and goes as far as revealing information to discredit a corporation and destroy the trust chain. Figuring out how to slow that down by encouraging collaboration between governments and developing alliances with vendors will be critical in the year ahead.

Critical infrastructures are expected to face the greatest security challenge

The COVID-19 pandemic has shown that cybercriminals are willing to exploit the crisis to attack critical infrastructures like healthcare and the vaccine supply chain. It will be necessary for hospitals and healthcare organizations to understand the three steps of ransomware protection: avoiding credential leaks, securing access to their applications and infrastructure, and backing up their data.

In 2022, critical infrastructure will continue to face significant security challenges. This also includes everything from energy and financial services to education and healthcare. For example, there have been numerous stories about how ransomware attacks that hit hospitals affect patient treatment and even lead to deaths. Attacks on critical infrastructure have the most direct impact on people’s lives, so security will be a challenge as cybercriminals continue to focus on these vulnerable areas.

Privacy requirements will drive security decisions

In 2022, privacy will dominate the security conversation because data can no longer be leveraged without accountability. Almost 75% of countries have some type of privacy regulation. So, all businesses must protect and enrich any data they collect from customers in a way that respects their privacy requirements.

These conversations about privacy policy also come up in the context of digital transformation. Companies are adopting many SaaS technologies, downloading apps and software, but they should be aware of the privacy implications of all of the technologies that are being used. In 2022, companies will be making decisions about which products to use, based on whether or not the data compliance is sufficient for their customers.

Having the tools in place to ensure compliance will become more important as well, especially for small and mid-sized businesses. While leveraging SaaS solutions like OneDrive, SharePoint, and Teams, they would need to understand what their teams are doing and make sure they have the tools to secure the data and are also compliant.

Forensics and XDR are new skills IT security executives would need in 2022

IT security executives would need to develop the ability to understand forensics and incident response. Many large and small IT security organizations, working with a managed service provider, are still struggling with too many tools and not getting the signals to work together.

Detection and response will be the keywords to help IT security executives achieve what they need to in 2022 and beyond. Improving in this area will require an Open XDR platform or managed XDR solution through a service provider. Those tools will enable IT, security executives, to respond more efficiently than they are now.  Right now, most enterprises are investing in tools to protect multiple attack surfaces. It will be essential to capture the signals from each tool and correlate the data for actionable insights.  From prevention, detection to response, it will require forensics and security analytics skills to defend against today’s cyberattacks.  With the existing shortage of cybersecurity skillset, utilizing a managed SoC (Security Operations Center) with XDR capabilities could be the answer for all small and medium enterprises.

Data consolidation is expected to see in 2022 by the security market

Consolidation on data-driven platforms is one change that is expected to occur in 2022 as the market shifts to more of a service-driven kind of tooling, including XDR and managed detection and response.

Detection and Response, skillset many organizations are missing will get more complex. Many companies, especially SMBs or small-to-medium-sized enterprises, will need this skill set to respond efficiently and effectively to survive these cyber-attacks without investing so much in building an in-house team.  So, they will have to rely on managed security service providers. At an enterprise level, it will mean getting to know the tools being used, identifying the signals received from those tools and consolidating those signals to make detection and response easier for the team.

Security talent shortage turns into a security crisis and creates new opportunities

The small and mid-sized companies were already short-staffed and were experiencing trouble hiring the staff they needed to protect themselves from security risks. The “Great Resignation” will make those challenges even more acute, especially in tech and healthcare. This will make a tough situation worse.

As a result, in 2022 businesses will rely more on their vendors to provide automated tools and services, like XDR and MDR. Managed services providers will become a critical resource as well. Gartner predicted 40% of mid-sized companies will leverage MDR by 2024. From a mid-market perspective, companies will need a service provider to help them successfully leverage SOC / NOC / XDR capabilities and stay secure. Increasingly, only large enterprise organizations will be able to manage their security needs internally.

The year 2022 will also see more security positions filled by people from unexpected backgrounds or with different skills. Due to the nature of the threats and the complexity of the environments, companies cannot go back to just hiring who they’ve hired before. Addressing security challenges constantly requires fresh thinking in the face of ever-changing attacks and overwhelming alerts. This is a great opportunity to bring in different perspectives and the cybersecurity or IT space that will play a prominent role in how companies secure themselves.

New security roles are expected to emerge over the next few years

Cybersecurity Champion is a new role that we will emerge in the next few years, especially in developing software. These security champions will focus on what we call shifting left because now it is about the developers, software development, and the software supply chain, including Open-Source libraries and other third-party libraries. On the very left of the entire software development lifecycle, getting that level of security attention at the developer level is where those roles will start to add value.

Security Analyst is another role expected to be at the forefront in the next few years. They will effectively detect and respond to threats by understanding the correlation of these different signals and execute on responding to these threats.

Sharing his insights on the predictions, James Forbes-May, Vice President, Barracuda Networks APAC, said, “With security now starting to be prioritized, the reporting structure will depend on the organization’s maturity and the leadership they have in place, such as if there is a CISO involved. Many of the IT teams won’t naturally be reporting to a CISO because their approach to security is event-driven. By being predictive and preventative and having the right tools and resources, one can have plans and programs to prevent incidents. So instead of having an event-driven approach to security, organizations will need to proactively shift to putting the measures and stopping those attacks from ever happening or stopping it earlier in the attack chain, so there’s less damage. Without a security practice at the very top, it will be challenging to bring this kind of change.”

Barracuda researchers detected millions of bad bots attacks on eCommerce websites during the holiday shopping season

Come holiday season and online shopping spree begins with full force, making the eCommerce websites an attractive target for cybercriminals to launch attacks. This November, Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, detected millions of bad bots attacks that were been used by the attackers to run distributed denial of service (DDoS) attacks, make fraudulent purchases, and scan for vulnerabilities they can exploit.

Barracuda researchers in the middle of the month, ran the Barracuda Advanced Bot Protection in front of a test web application, and detected a staggering number of bad bots in just a few days with millions of attacks coming in from thousands of distinct IP addresses. When viewed by the time of day, the researchers found that the bots don’t just wait until the middle of the night to attack. In fact, the bot activity peaks late morning and goes on until 5 p.m., which indicates that the cybercriminals aka “bot herders” follow a regular working day.

Bad bot personas are bots that have been identified as malicious based on their pattern of behavior. They are grouped by User-Agent, some of which are good. For example, GoogleBot, which crawls sites and adds them to search rankings, is good and should not be blocked. Cybercriminals have been using different ways to spoof good User-Agents to conduct the attacks. The bad bots spoof these known good User-Agents, which would need deeper scrutiny to tell them apart.

To identify a bot as being bad when the User-Agent claims to be a good search engine, Barracuda researchers use different methods; Injecting honeytraps like hidden URLs and JS challenges; Using rDNS (reverse DNS lookup) to verify bots coming from a claimed source; Inspecting whether the client is trying to access URLs used by common app fingerprinting attacks; and analysing further with ML, in case the methods don’t work out. HeadlessChrome, yerbasoftware, and M12bot are some of the bad bot personas that showed an increase in numbers.

Speaking on the threat, Murali Urs, Country Manager-India, Barracuda Networks, commented, “While analysing which Internet System Provider or Autonomous System Number has been the source of this bad bot activity, our researchers identified Indian mobile provider Airtel’s subnet ranges in the mix, as well as some of the big public cloud providers like Google Cloud, Amazon. This shows that even though the source of bots is international, it would depend on the bot and the site it is targeting.”

With the holiday shopping season expected to continue in full swing till the New Year, eCommerce teams should start taking necessary steps to safeguard their applications against bad bots. They must install a well-configured web application firewall as a service solution and make sure that the application security solutions include anti-bot protection to effectively detect advanced automated attacks. eCommerce websites should further turn on credential stuffing protection to prevent account takeover.

Barracuda Acquires Fyde, a Zero Trust Network Access (ZTNA) Innovator

Barracuda, a trusted partner and a leading provider of cloud-enabled security solutions, today announced it has acquired Fyde, a ZTNA provider based in Palo Alto, Calif., and Porto, Portugal to expand the Barracuda CloudGen SASE platform with ZTNA capabilities. The Fyde solution is available immediately as Barracuda CloudGen Access to businesses of all sizes. It will be available in the coming weeks for Managed Service Providers.

According to Gartner: “ZTNA improves the flexibility, agility, and scalability of application access enabling digital businesses to thrive without exposing internal applications directly to the internet, reducing the risk of attack.”1

Fyde’s innovative Zero Trust solution enables secure, reliable, and fast access to cloud or on-premises applications and workloads from any device and location. Fyde’s ZTNA solution addresses the security risks associated with traditional remote access by continuously verifying that only the right person, with the right device, and the right permissions can access company resources. The solution is ideal to connect users directly to cloud-native and legacy corporate applications deployed in hybrid and multi-cloud environments.

“Remote work is here to stay, cloud migrations are accelerating, and traditional corporate perimeters have disappeared,” said BJ Jenkins, President and CEO at Barracuda. “Fyde offers a powerful ZTNA solution that works on any infrastructure, any device, and with any application on a corporate network. With this acquisition, Barracuda is providing distributed businesses a new way to modernize remote access, enforce global security and access policies, and achieve seamless connectivity without compromising productivity.”

Barracuda provides a broad and growing portfolio of cloud-enabled network and application security solutions. In July of this year, Barracuda launched CloudGen WAN, the industry’s first global SD-WAN service built natively on Microsoft Azure. With the acquisition of Fyde, Barracuda now offers ZTNA solutions that use a modern approach to securing applications and devices by providing identity-aware access control and device-based contextual security policies. This acquisition expands the capabilities of Barracuda’s SASE offering to help customers with digital migrations to the public cloud.

With this acquisition, Barracuda expands its differentiated capabilities for today’s complex IT environments, enabling security teams to address many use cases, including:

· Secure single sign-on to SaaS applications

· Secure access to applications from BYOD devices

·Simultaneous access to applications located on-premises and on multiple clouds

· Mobile device security monitoring and protection against malicious websites

· Simplified privileged access and much more

The financial terms of the deal were not disclosed.

Resources: 

Get more information about Barracuda CloudGen Access: https://www.barracuda.com/products/cloudgen-access

Get more information about Barracuda CloudGen WAN: https://www.barracuda.com/products/cloudgenwan

Read the blog post: An inside look at Barracuda, Fyde, and Barracuda CloudGen Access: http://cuda.co/42476

Register for the webinar: Zero-Trust Network Access: Security for the Remote, Distributed Workforce: http://cuda.co/wbr111720

 Resources: 

Gartner, “Market Guide for Zero Trust Network Access”, Steve Riley, Lawrence Orans, Neil MacDonald, 8 June 2020.

71% Indian Organisations say security has taken back seat with remote working despite increasing threats; New Study by Barracuda Networks

Barracuda, a trusted partner and leading provider of cloud-enabled security solutions, today released key findings from a report titled “Brave the new normal: How companies in India are overcoming security challenges in a remote workplace”. The research revealed that 53% of organizations surveyed in India do not have an up-to-date security strategy or solutions covering all the vulnerabilities posed by remote working, while 71% admitted that security has taken a back seat in the shift to this mode of working.

The market report was commissioned by Barracuda and conducted by independent research firm Censuswide in July 2020. 1,055 business decision-makers in Australia, New Zealand, Singapore, Hong Kong and India were surveyed to gain insights into their current mindset about the future of work trends resulting from the COVID-19 pandemic.

“While organizations are riding a wave of digital transformation to support the shift to remote working, many have been impacted by major security concerns that have emerged. Despite this, security has taken a back seat in many organizations due to budget and resource constraints. Threat protection must get the attention it deserves to avoid causing reputational and financial damage at a time when most companies can least afford it,” said Murali Urs, Country Manager India, Barracuda Networks.

The report revealed that 62% of Indian organizations surveyed cut their cybersecurity budgets to save costs as they responded to the pandemic. In addition, 42% lacked IT resources or time to upgrade their IT infrastructure in the shift to a remote working model. This highlights the need for organizations to find ways to prioritize spending on critical controls, whether that involves consolidating vendors, investing in SaaS-based tools or assessing how automation could help free budget and resources for security.

This is critical given employees may often be more distracted when working remotely, coupled with a lack of protection on home devices and networks, making them more susceptible to cybersecurity attacks. 66% of organisations surveyed reported at least one data breach or cybersecurity incident since shifting to remote working, with 67% reporting that employees had experienced an increase in email phishing attacks. 70% are concerned about unknown threats that will cause business disruption in the next 6 months.

According to the report, 61% of respondents said their employees are not properly trained in the cyber risks associated with remote working. In addition, 54% are not confident in the security of their web applications, which is another major target for malicious third parties seeking to access corporate data.

The good news is that most Indian decision-makers are aware of the problems relating to their remote working security posture and have a clear idea of how they can improve it. 85% believe that cross-industry collaboration is key to improving security standards. 92% said that they will need to upgrade their IT infrastructure to improve visibility and productivity. 87% plan to provide improved online cybersecurity training and awareness for remote working staff.