Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Crime Security IT Linux

Halcyon Announces Anti-Ransomware Protection for Enterprise Linux Environments (linux-magazine.com) 8

Formed in 2021 by cybersecurity professionals (and backed by high-powered VCs including Dell Technologies Capital), Halcyon sells an enterprise-grade anti-ransomware platform.

And this month they announced they're offering protection against ransomware attacks targeting Linux systems, according to Linux magazine: According to Cynet, Linux ransomware attacks increased by 75 percent in 2023 and are expected to continue to climb as more bad actors target Linux deployments... "While Windows is the favorite for desktops, Linux dominates the market for supercomputers and servers."
Here's how Halcyon's announcement made their pitch: "When it comes to ransomware protection, organizations typically prioritize securing Windows environments because that's where the ransomware operators were focusing most of their attacks. However, Linux-based systems are at the core of most any organization's infrastructure, and protecting these systems is often an afterthought," said Jon Miller, CEO & Co-founder, Halcyon. "The fact that Linux systems usually are always on and available means they provide the perfect beachhead for establishing persistence and moving laterally in a targeted network, and they can be leveraged for data theft where the exfiltration is easily masked by normal network traffic. As more ransomware operators are developing the capability to target Linux systems alongside Windows, it is imperative that organizations have the ability to keep pace with the expanded threat."

Halcyon Linux, powered through the Halcyon Anti-Ransomware Platform, uniquely secures Linux-based systems offering comprehensive protection and rapid response capabilities... Halcyon Linux monitors and detects ransomware-specific behaviors such as unauthorized access, lateral movement, or modification of critical files in real-time, providing instant alerts with critical context... When ransomware is suspected or detected, the Halcyon Ransomware Response Engine allows for rapid response and action.... Halcyon Data Exfiltration Protection (DXP) identifies and blocks unauthorized data transfers to protect sensitive information, safeguarding the sensitive data stored in Linux-based systems and endpoints...

Halcyon Linux runs with minimal resource impact, ensuring critical environments such as database servers or virtualized workloads, maintain the same performance.

And in addition, Halcyon offers "an around the clock Threat Response team, reviewing and responding to alerts," so your own corporate security teams "can attend to other pressing priorities..."

Halcyon Announces Anti-Ransomware Protection for Enterprise Linux Environments

Comments Filter:
  • Halcyon Linux monitors and detects ransomware-specific behaviors such as unauthorized access, lateral movement, or modification of critical files in real-time, providing instant alerts with critical context.

    While not the same use case years ago the government site I worked with pushed McAfee for Linux on us and it was a performance killer. It also had "real-time" monitoring. Wonder how this stacks up to that software.

    • by ls671 ( 1122017 )

      It's probably not the same thing. The only way to offer real, fail-safe "ransomware protection" is to use snapshots and backups that can't be compromised. We have replicated snapshots taken every minute but of course we also try to not get hit in the first place and have measures in place for that too.

      Selling a solution where you rely exclusively on not getting hit in the first place wouldn't be really serious IMHO.

  • by Anonymous Coward
    Raise your hand, here --
  • by ffkom ( 3519199 ) on Saturday October 12, 2024 @02:35PM (#64859469)
    That "enterprise-grade anti-ransomware" is probably a mediocre $$$$$$ "remote backup" service that comes with some "agent" software expected to be installed with root privileges on the systems to "protect", while actually creating a huge additional attack surface.

    I'll stick to proven free backup software that writes to devices that are stored offline.
  • The vendor states "protecting these systems is often an afterthought". No, what would be an afterthought would be to install some (probably priviledged) system agent with no evidence of it resulting in a net security gain. Add-on agents are most often at best a new of for tech debt. I once ran across a server which had five management/"security" agents, several of them with CVEs. Unfortunately, if we don't start questioning this, it will likely get worse, as I've ranted about here: https://troelsarvin.blogs [blogspot.com]
  • At least that is what I get from this "description". Not trust-inspiring at all.

New York... when civilization falls apart, remember, we were way ahead of you. - David Letterman

Working...