UPDATED 08:00 EDT / APRIL 16 2018

INFRA

Cisco debuts new security capabilities to take on ransomware and fileless attacks

Many of the hacking attempts launched against enterprises go after the target firm’s employees, whose login credentials often represent the most straightforward means of accessing key systems. Cisco Systems Inc. wants to mitigate the threat.

At the RSA Conference today in San Francisco, the networking giant introduced an enhanced version of its cloud-managed Advanced Malware Protection for Endpoints security platform to improve protection of workers from attack. The upgrade significantly expands upon the software’s threat mitigation capabilities.

To start, Cisco has added an antiransomware engine that draws on internal research conducted by its security experts. According to the company, the mechanism is designed to detect any malicious attempts to encrypt the data on a device and automatically terminate the offending process. Cisco said that it can thus not only prevent hackers taking important files ransom, but also stop the malware from spreading further throughout a firm’s network.

The antiransomware engine is joined by a capability that targets another significant threat: fileless attacks. This type of threat is characterized by the fact that no malware has to be downloaded onto the user’s device. Instead, hackers exploit flaws in existing applications, a tactic that Cisco saids AMP for Endpoints can now counter by flagging vulnerable programs ahead of time.

The company unveiled the device protection features alongside an integration with Cisco Visibility, a threat intelligence product, that aims to ease the investigation of security incidents. The tool enables network protection teams to enrich internal incident logs with information about hacker activity sourced from external security feeds. Cisco said the data can make it easier to understand the full scope of a breach and how to fix it.

The enhancements to AMP for Endpoints are part of a broader push by the networking giant to bolster its breach prevention portfolio. In conjunction with the update, Cisco announced a partnership with San Mateo, California-based Agari Data Inc. to make the startup’s email security technology available to its customers.

The collaboration will see the company roll out two new offerings. The first, Cisco Advanced Phishing Protection, uses machine learning to identify emails from malicious senders who try to pass themselves off as someone else. The other product, Cisco Domain Protection, aims to help companies prevent attackers from hijacking their domain names to distribute malicious messages.

Image: Unsplash

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.