Tips to Protect Enterprise Networks and Resources Against Mozi

By: Amr Alashaal, Regional Vice President – Middle East at A10 Networks

Malware has been playing an important role in the expansion of botnets, automating the process of bot infection and recruitment. These botnets are then used to launch large scale DDoS attacks. One highly prevalent malware in the DDoS world is Mozi.

Mozi is a DDoS-focused botnet that utilizes a large set of Remote Code Executions (RCEs) to leverage CVEs in IoT devices for infection. These IoT devices include readily available and commonly used DVRs and network gateways. Once infected, the botnet uses peer-to-peer connectivity to send and receive configuration updates and attack commands. Mozi was first identified in 2019 and has been evolving and increasing in size ever since. It can now persist on network devices by infiltrating the device’s file system, remaining functional even after the device has been rebooted. During the first half of 2021, Mozi topped out at over 360,000 unique systems using more than 285,000 unique source IP addresses, likely due to address translation.

In order to protect their networks and resources, organizations need to take the following steps to block systems infected by Mozi and the malicious traffic generated by them:

  1. Never Trust, Always Verify: Incorporate the Zero Trust model and its key principles into your security strategy. Create micro-perimeters within your networks. Limit access to your resources and invest into modern, AI/ML-based solutions. Ensure visibility into not only the endpoints and network nodes, but also into users, their activities, and workflows.
  2. Investigate Whether You are Already Infected: The initial infection of Mozi comes in the form of RCEs sent using ports 80, 8080, 8443, etc. This can make initial infections stand out, which can help in tracking them with low false positives. If your network devices suddenly start generating abnormal amounts of TCP or UDP traffic, immediately isolate suspicious devices and limit the traffic originating from them. If this is not possible, then apply global rate limiting on all traffic until you track the source.
  3. Observe and Block Commonly Exploited Ports: Incorporate the Zero Trust Closely monitor any traffic using TCP ports 60001, 37215, 5555, 52869, 49152, both before or after a suspected infection. While these aren’t the only ports Mozi uses, they may help find the needle in the haystack. As a general good practice, monitor and block sources that send TCP SYNs to ports 23 and 2323 as most malwares use Telnet to initiate IoT device infections.
  4. Take a Closer Look at the Payloads: If your network devices are generating large amounts of traffic, look at the payloads (i.e., the HTTP POST as shown on page 13). RegEx can be used to filter these malicious traffic requests out and block them before they infect other devices.
  5. Block BitTorrent: Since BitTorrent is one of the most common peer-to-peer networks used by Mozi for Command and Control (C2) communications, any BitTorrent traffic coming into or going out of the network should be blocked. The sheer amount of BitTorrent traffic could be a dead giveaway of an infection depending on your customer type.
  6. Ensure Your Security is up to Date: Make sure your security infrastructure is updated regularly and that your IoT devices are running the latest version of firmware with all the necessary security patches applied. Keep track of CVEs for your network devices and seek out help if there are any patches available. If fixes are not readily available, take appropriate action based on the particular CVEs.
  7. Employ or Review DDoS Baselining and AI/ML Techniques: Using modern DDoS techniques like baselining to see anomalous behavior versus historical norms, and AI/ML techniques, for detection and zero-day attack prevention, can be a force multiplier for your security team as manual tasks can be discovered and dealt with efficiently and 24×7.

Hybrid Workers Bring Dangerous Hybrid Habits: New Aruba Survey Uncovers Emerging Security Threats Linked to ‘Generation Novel’

Business leaders must strike a balance between flexibility and security to address risky behaviours and evolving expectations of today’s tech-savvy workforce

After years of responding to the needs of Gen X and Gen Y, a new study from Aruba, a Hewlett Packard Enterprise company, suggests employers have a whole new generation to grapple with post-pandemic – with 85% of hybrid workers saying they identify with the traits of the emerging Generation Novel (Gen-N).

Coined by digital anthropologist Brian Solis, Gen-N describes a cross-generational cohort of people who thrive on digital-first experiences, and place greater value on personalization, customization, and transparency from the brands they buy from, work for, and support. Above all else, they also understand, use and demand more from technology than ever before – both at home and work.

According to the study of 5,018 hybrid workers across EMEA, 78% of respondents say they use technology more now than they did before COVID-19, and 75% consider themselves to be ‘digitally savvy’. Sixty-nine percent of respondents agree they now have more of an opinion on the technology they use at work and 71% feel it’s important to be able to customize their workplace tech set-up to suit their individual preferences.

The survey also revealed the risks this new generation will bring to the workplace if their expectations continue to go unmet. As it stands, only 38% of respondents say they have any significant choice in their workplace technology. Without the right technology, workers indicated they will experience decreased productivity (35%) and a poorer work/life balance (23%). Gen-N’s expectations around increased flexibility and confidence in their technical abilities also opens businesses up to a number of security risks relating to where, when, and what employees connect to the network – with 50% of respondents, for example, claiming they are more likely to try to resolve a tech issue themselves now than they would have been before the pandemic.

Additional key findings from the report reveal:

Hybrid workers have a new perspective on the role of workplace technology:

  • 80% of our respondents say their company must maintain policies that encourage healthy technology use.
  • While 73% believe technology has a role to play in fostering an inclusive environment in the new hybrid workplace, 44% believe it is not currently doing so.

Hybrid workers bring new risks to the workplace if their needs go unmet:

  • When encountering a tech issue at work, nearly three quarters (74%) of hybrid workers say they expect it to be resolved in 20 minutes or less – and over two fifths (42%) in under 10 minutes.
  • Over half (55%) of our survey respondents admit to connecting to a non-password protected public network at least once a week, but only a third (33%) consistently think of the security risks in doing so.
  • Meanwhile, as many as 82% are still using their personal mobile device to access work information.

“Our research suggests that this emerging generation of hybrid workers, with its evolving behaviours and heightened expectations, will put new demands on employers when it comes to workplace technology,” said Morten Illum, Vice President, EMEA for Aruba, a Hewlett Packard Enterprise company. “In order to mitigate the security risk that Gen-N poses, as well as boost efficiency within their workforce and support their employees, businesses must address these new needs. Striking the balance between an open but secure network will afford employees the flexibility, freedom and personalization they now seek, without compromising on security.”

To read the full report, including recommendations on the actions business leaders much take to meet the needs of Gen-N in a hybrid workplace, visit https://www.arubanetworks.com/assets/eo/eBook_Hybrid-Workplace-Generation-Novel.pdf

Nutanix is Named for the First Time in 2021 Gartner® Magic Quadrant for Distributed Files and Objects Storage as a Visionary

Company Recognized for its Ability to Execute and Completeness of Vision

Nutanix (NASDAQ: NTNX), a leader in hybrid multicloud computing, announced today it has been has been named as a Visionary in Gartner, Inc.’s October 2021 Magic Quadrant for Distributed Files and Objects Storage. This is the first time the company has been recognized in this report. Nutanix believes that the company continues to expand the use cases for its technology and the inclusion in this Magic Quadrant demonstrates how Nutanix addresses additional critical functionality for enterprises.

“We believe being named in the Gartner Magic Quadrant for Distributed Files and Objects Storage is a significant recognition of Nutanix’s storage offerings, which aim to simplify and lower operating costs. Our software-defined storage provides a solution for customers looking to modernize and unify their unstructured data storage, including those not ready to move to HCI,” said Rajiv Mirani, Chief Technology Officer at Nutanix. “Of course Nutanix Files and Objects also builds on the rest of the Nutanix Cloud Platform that thousands of customers rely on for their entire compute, network, and storage needs in an easy-to-operate platform that reduces the cost of management.”

The Nutanix unstructured data storage offerings, well suited for hybrid cloud and cloud native application storage, were recognized for product ease of use, simplicity of management, and for delivering rich data analytics and security tools that help customers monitor and report on abnormal user behavior, performance anomalies, and audit trails. Customers also benefit from built-in ransomware protection with the ability to detect and block attacks. Nutanix Files and Nutanix Objects also offer existing HCI users an easy way to enable enterprise-grade software-defined distributed file or object services at any scale.

In March, Nutanix was also designated as a 2021 Gartner Peer Insights Customers’ Choice vendor for Distributed File Systems and Object Storage. Today, Nutanix Files and Nutanix Objects hold an average of 4.8 out of 5 star rating as of October 4, 2021*.

Nutanix customers frequently highlight simplicity as a key benefit to enable easier day-to-day management, faster deployment, and reduced maintenance activity. Data analytics and security are also frequently mentioned, along with flexibility, including the ability to support a wide range of deployments. Finally, customers identify a robust feature set to rival any enterprise storage system, including space reduction and efficiency technologies, integrated resilience features, and data lifecycle management capabilities.

Nutanix continues to build its offerings outside of the core HCI software, including unstructured data storage. Notably, in its most recent fiscal quarter the company saw 100+% Y/Y growth in New ACV Bookings1 from emerging products. Additionally, last month, the company announced strengthened data services for structured and unstructured data, including accelerated performance for modern analytics applications, unstructured data tiering from on-premises to cloud and a new unstructured data governance service, Nutanix Data Lens.

More information on Nutanix and a complimentary copy of the report are available at: www.nutnaix.com/gartner

1 New ACV Bookings, for any given period, is defined as the sum of the New ACV booked during the given period. New ACV is defined as the ACV pertaining to sales to a new customer, or any up-sell / expansion sales to an existing customer. Annual Contract Value, or ACV, is defined as the total annualized value of a contract, excluding amounts related to professional services and hardware. The total annualized value for a contract is calculated by dividing the total value of the contract by the number of years in the term of such contract, using, where applicable, an assumed term of five years for contracts that do not have a specified term.

Source:

Gartner, Magic Quadrant for Distributed File Systems and Object Storage,Julia Palmer, Jerry Rozeman, Chandra Mukhyala, Jeff Vogel , October 1, 2021.

Disclaimer:

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Gartner and Magic Quadrant are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

*Ratings and reviews are current as of October 4, 2021. Gartner Peer Insights Customers’ Choice constitute the subjective opinions of individual end-user reviews, ratings, and data applied against a documented methodology; they neither represent the views of, nor constitute an endorsement by, Gartner or its affiliates.

GITEX 2021: Riverbed Showcases End-to-End Visibility to Deliver Actionable Insights for Customers, and Leading Network and Acceleration Solutions

With organizations rapidly accelerating digital transformation initiatives due to the pandemic, and the dramatic market shift to cloud services, SaaS apps, and hybrid/work-from-anywhere environments, businesses are now challenged with significantly increased IT complexity. As a result, the need for end-to-end visibility to ensure the productivity and performance of the business and digital services has never been more critical.

With strong growth in its visibility portfolio over the last couple of quarters, Riverbed recently reunited with Aternity, an independent division of Riverbed, to meet customer demand and fill a void in the market for full-fidelity, end-to-end visibility for the digital and hybrid enterprise. By joining best-in-breed technologies, Riverbed | Aternity delivers the most comprehensive offering with end-to-end visibility across networks, apps, cloud, and down to the end-users to provide actionable data insights that drive real business outcomes.

At GITEX, Riverbed will use its participation at the Middle East’s largest technology event to showcase industry-leading end-to-end visibility and network and acceleration solutions. Under the theme ‘Visibility, Security and Performance for the Modern, Hybrid Enterprise’, Riverbed intends to educate customers and prospects about how they can capitalise on new opportunities, address vulnerabilities, and fundamentally rethink how their organizations and employees can thrive in a world that’s digital-first, and hybrid by design.

“Riverbed sees GITEX as one of the main trade shows in our regional events calendar and this year is especially exciting given this announcement and its implications on the expansion and augmentation of our solution portfolio. This will translate to new and enhanced capabilities in end-to-end visibility and application acceleration solutions for our customers. It also means more, innovative use cases that our channel partners can deliver through the Riverbed portfolio,” said Mena Migally, Regional Vice President, META at Riverbed.

At the show, Riverbed will co-sponsor the participation of its regional distributors – Mindware and StarLink – and will have kiosks at each of their stands. By doing so, the company aims to demonstrate its firm commitment to its channel partners. “Our intention is to educate technically proficient resellers and integrators on how they can then leverage the full scope of the Riverbed portfolio to deliver comprehensive IT solutions for the needs of the modern enterprise,” explained Migally.

Top executives from Riverbed’s regional leadership, sales, and pre-sales teams will be attending GITEX 2021. Attendees can meet them at the dedicated Riverbed kiosks on the stands of value-add distributors Mindware (E1 in Hall 3) and StarLink (C1 in Hall 1).

eufy Security introduces the new Outdoor Cam Pro C24 (Wired) to its innovative range of Smart Home Security Cameras

Adding to its wide range of Smart Home Security Cameras, eufy Security by Anker has introduced the new ‘Outdoor Cam Pro’. This latest offering from eufy Security is loaded with superior technology to make it a Mini but Mighty Wired Security Camera.

With ULTRA 2K resolution and F2.0 aperture, Outdoor Cam Pro gives stunning colours and details during any part of the day. At night, with its built-in spotlight it illuminates the surrounding area when motion is detected and captures the footage in vivid colour. (Colour Night vision Feature is the added advantage).

With IP67 weatherproof-rating, the Outdoor Cam Pro stays safe with greater protection even during extreme weather. It’s also equipped with 32GB memory card and can be extended up to 128GB thus giving a subscription free security all-round the year.

The advanced built-in AI also smartly detects the unknown person and alerts only when any event occurs that actually requires attention. This avoids unnecessary false alarms with every moment that the camera captures. The camera facilitates two-way audio to communicate with the person in front of the camera even if you are not at your home. Outdoor Cam Pro also supports smart integration with Google Assistant and Alexa for extra convenience.

The magnetic mount and 20ft Cables allows one to easily install the camera anywhere in their property. This amazing security camera from eufy Security is priced at AED 299 and is available at all leading electronics stores – Jumbo electronics, Sharaf DG, Virgin Megastore & Lulu Hypermarket etc.

You can buy the products from Amazon and Noon.

Kodak Alaris Claims First Ever BLI PaceSetter Award in Distributed Capture from Keypoint Intelligence

Keypoint Intelligence, the world’s leading independent provider of testing services and analytical information to the document imaging industry, today announced that Kodak Alaris has won the Buyers Lab (BLI) 2021-2022 PaceSetter Award in Distributed Capture. Based on research conducted in the North American market, this accolade recognizes the OEM with the leading distributed capture technology portfolio, including single-function scanners, capture software, and professional services offerings.

For this study, Keypoint Intelligence invited all leading document imaging OEMs to complete an exhaustive questionnaire detailing their industry vision, strategy, product portfolio, professional services offerings, and value proposition as it relates to distributed capture technology. After gathering this data, Keypoint Intelligence analysts used a proprietary rating scale to determine the BLI PaceSetter Award winner.

Kodak Alaris makes it easy for businesses to unlock pertinent business information trapped in paper documents and send it where it’s needed next—all in an instant, from anywhere on the globe. Kodak Alaris combines an outstanding lineup of document scanners with workflow automation, distributed capture, and remote monitoring and management solutions to help businesses get the most out of their digital transformation investments.

“We are very impressed with Kodak Alaris’s distributed capture technology portfolio,” said Lee Davis, Associate Director of Software/Scanners. “The entire breadth of the company’s hardware is best characterized by its ease of use, media-handling capabilities, and image quality—a perfect fit in shared scanning environments. Meanwhile, Kodak Alaris’ Info Input Solution and INfuse Smart Connected Scanning Solution equip organizations with powerful OCR, forms recognition, document classification, intelligent data extraction, and workflow automation capabilities.”

“Claiming the first ever BLI PaceSetter Award for Distributed Capture is a tremendous honor,” said John Blake, Senior Vice President, Marketing & Product Management for the Alaris division of Kodak Alaris. “We continue to invest in distributed capture solutions that extend our scanners’ capabilities beyond hardware to include software, solutions, and services that create significant value for our customers and partners.”

For more information, please visit the Kodak Alaris website.

HealthTech innovators selfologi launch new platform set to revolutionise the cosmetic treatments industry

The digital start-up launches a game-changing platform, which will transform the way consumers discover, learn about, and book cosmetic treatments in the UAE, with plans for regional expansion

In-depth content available in Arabic and English developed by global industry experts

Acquired seed funding of $17.5 million in June this year

selfologi, a Dubai-based digital start-up has launched a first-of-its-kind healthtech website, which enables users to discover and learn about cosmetic treatments in the UAE and KSA.

The new platform provides rich original content on cosmetic treatments allowing users to discover and compare treatments and clinics.

Consumers will now have access to articles and editorial features developed by global industry experts in Arabic and English, detailing everything they need to know to make informed decisions, with confidence. The website will serve as the go-to place for trusted information related to cosmetic treatments from fillers to skin rejuvenation, liposuction to laser hair removal.

According to google search data, more than a million searches are conducted each month on cosmetic treatments in the Middle East. Based on proprietary data, selfologi estimates that over $2.2B worth of cosmetic treatments are taking place across the region annually. However, a huge proportion of the consumers surveyed said that they cannot find the right information to book a treatment online.

In June 2021, selfologi secured $17.5 million in seed funding, led by selfologi’s founder, Tamer Wali and Xenel International group.

“Currently, almost all cosmetic treatments are booked offline, with consumers not having access to updated, regionally-relevant information that can aid their decision-making when it comes to something as personal as cosmetic treatments and procedures. selfologi was born with the vision of offering consumers an unparalleled platform that informs, educates, and helps consumers make the right choice for themselves, and realise their full potential” said Tamer Wali, Founder of selfologi.

Rob Pye, CEO of selfologi added: “At selfologi, we aim to revolutionise the cosmetic and healthtech industry by providing a consumer-centric destination for cosmetic treatments and procedures. With support from the region’s leading experts in aesthetic technologies, alongside some of the best digital brains in the business, selfologi is set to be a game-changer and a pioneer in the multi-billion-dollar cosmetic treatments industry”.

Starting early 2022, users will be able to book cosmetic treatments directly on selfologi.com in the UAE and KSA, with the vision to become the ultimate destination for consumers and cosmetic clinics across the region. Cosmetic clinics and practitioners can join the platform to enhance their visibility and allow clients to book appointments directly online.

Cosmetic treatment professionals can learn more about selfologi at MEIDAM 2021 (Middle East International Dermatology Aesthetic Medicine Conference and Exhibition), taking place September 23-25 at Intercontinental Dubai Festival City.

Dubai Blockchain Leader to Launch its first Cutting-Edge Tokenization Platform

ZENIQ’s vision paves the way to Dubai’s position as “Center of the sixth era of world creativity”

ZENIQ Technologies Ltd, a provider of blockchain-based decentralised applications, will launch a tokenization project in Dubai on Tuesday to revolutionise the trading of digital assets. To mark the occasion, members of the public will be invited to view for the first time a unique show of digital artworks displayed on the world’s largest façade screen of the Burj Khalifa.

The project will see the establishment of non-fungible token (NFT) trading platforms for real estate, gold and precious metals, gemstones and digital art. The launch will take place at “The Future of Digital Assets” conference at the Armani Hotel in the Burj Khalifa, Dubai, on Tuesday, 21 September, under the patronage of Sheikh Saeed bin Hasher Al Maktoum, chairman of ZENIQ Technologies. The public exposition of art on the Burj Khalifa will take place at 9:10 pm.

The ZENIQ Art NFT will be the first of several tokens, which are in effect digital stamps of ownership and provenance. Dubai has been selected as the launch venue for the ZENIQ Art NFT because of the city’s increasing role as a global centre for investment in digital art.

“We believe that Dubai will be the focus for the sixth era of world creativity,” said Erwin Dokter, founder and CEO of ZENIQ Technologies.

Distinguished authors believe in the idea that along the history of humanity, some cities were the center of world creativity. Remarkable examples are Athens, Hangzhou, Florence, Edinburgh and, most recently, Silicon Valley.

Paco Bree, professor of innovation at Deusto Business School, digital artist and cofounder of Paradima.io, a company specializing in Digital Art Knowledge, also argues that Dubai is fast emerging as the sixth centre of creativity throughout human history. Some of the factors that nurture this vision be include the commitment to invest and promote creativity and exponential technologies to solve global challenges for a better world. It is no coincidence that Dubai has just announced a new Dubai Creative Economy Strategy, with the aim of doubling its number of creative companies in the next five years. ZENIQ is very proud to be part of that.

The ZENIQ Art NFT will facilitate the authentication, sale and transfer of digital artworks in a safe digital environment. “We are convinced that the ZENIQ Art NFT, used in conjunction with our secure blockchain platform, will stimulate uptake from artists, buyers and dealers alike and grow the market for digital artworks both in Dubai and internationally,” Mr Dokter said.

Blockchain is a system in which a growing list of records is linked and encrypted to protect the security and privacy of users, applications and assets. Blockchain is maintained on multiple computers that are linked on a peer-to-peer network. The ZENIQ ecosystem and its blockchain is designed to provide unprecedented security standards for these assets.

ZENIQ Technologies was conceived in AREA 2071 of the Dubai Future Foundation. AREA 2071 is a physical manifestation of the drive to make Dubai the world’s leading city in terms of innovation, and ideas with positive global impact.

Nutanix Appoints Adam Tarbox as Vice President of EMEA Channel Sales

Hybrid Multicloud Leader Continues Channel Investment with Strategic Hire To Drive Company Growth

Nutanix (NASDAQ:NTNX), a leader in hybrid multicloud computing, today announced the promotion of Adam Tarbox to Vice President of EMEA Channel Sales. This senior promotion demonstrates Nutanix’s continued investment in the channel as it looks to accelerate the company to its next level of growth and support partners and customers in their journey to hybrid multicloud.

In this role, Tarbox will lead all routes to market, spearheading channel activities in all the European countries, Middle East and Africa region and will draw upon his extensive industry experience to play a strategic role in supporting Nutanix’s expansion in EMEA. Assuming overall responsibility for Nutanix’s go-to-market strategies with resellers, distributors, OEM platform partners, system integrators and technology partners in the EMEA region, he will be key in driving the continued growth and success of the company’s already enviable channel and alliance ecosystem.

Commenting on his appointment, Tarbox said: “Partners have and will continue to be an integral part of our success, and I’m inspired by the passion and drive of Nutanix’s channel team. My commitment is to listen, learn and lead through our partners so they can continue delivering business outcomes, best-in-class transformational solutions and a digital-first customer experience. I am looking forward to building upon our deep relationships with partners to help reach the next level of mutual growth.”

Prior to his new role, Adam was Director of Global System Integrator (GSI) Business for EMEA, where he was responsible for developing and executing an overarching regional alliance strategy for Nutanix’s GSI partners. Adam successfully led a team distributed across the EMEA region focused on driving go-to-market activities with GSIs around joint offerings for both horizontal markets and industry verticals.

Christian Alvarez, Senior Vice President of Worldwide Channels at Nutanix said: “As Nutanix continues to transform to a subscription model, we continue to invest in the channel while retaining the best and brightest talent in the industry. Adam has a proven track record of driving transformational change and implementing successful strategies to deliver growth. By harnessing both Adam’s strategic abilities and experience, we can enable our partners of today and tomorrow to gain maximum benefit from our highly innovative solutions portfolio.” He continued: “I look forward to working closely with Adam to deliver our shared vision of assisting partners to accelerate their business by delivering the freedom of choice that enables true hybrid multicloud computing. As the channel is going through digital transformation to cloud, Nutanix is one of the only multicloud, multi-product companies carrying the torch to light the way ahead. Adam is the person best suited to do this, while executing on our mission to help both our partners and customers on their journey to hybrid multicloud.”