CTERA adds Data Exfiltration Prevention

CTERA launches honeypot decoy capabilities to address data extortion and insider threats.

  • Saturday, 20th April 2024 Posted 11 months ago in by Phil Alsop

CTERA has enhanced its award-winning ransomware protection engine, CTERA Ransom Protect, with active protection against data exfiltration using honeypot techniques. This addition bolsters enterprises' defenses against insider threats and the latest extortion tactics employed by ransomware perpetrators.

Double extortion, a tactic that combines data exfiltration and encryption, has become a widespread method used by cybercriminals in ransomware attacks. Threat actors first exfiltrate sensitive information from their targets before launching the ransomware encryption routine, subsequently demanding a ransom payment to regain access to the encrypted assets and threatening to publicly expose the stolen data if the demand is not met promptly.

CTERA Ransom Protect is an AI-powered cyber defense engine integrated into the CTERA global file system, providing zero-day protection against widespread ransomware attacks. The strong demand for Ransom Protect contributed to CTERA's record-breaking results in 2023, solidifying the company's position as a leader in Cyberstorage and earning it a leadership position in GigaOm’s Sonar Report for File-Based Primary Storage Ransomware Protection.

Now enhanced with honeypot capabilities, Ransom Protect utilizes the strategic deployment of decoy files within the organization's file system and enables CTERA to identify and stop unauthorized access or attempts at data theft, effectively neutralizing threats before significant damage can occur.

"Data exfiltration poses a severe risk to organizations, as threat actors can leverage stolen sensitive information for extortion, causing immense financial and reputational damage," said Oded Nagel, CEO of CTERA. "With our new honeypot functionality as part of CTERARansom Protect, we are providing our customers robust active defense against these pernicious attacks, ensuring the protection of their valuable data assets."

Key features of CTERA Ransom Protect include:

Data Exfiltration Prevention: Decoy files enable real-time detection and blocking of data exfiltration attacks.

Real-time AI Detection: Advanced machine learning algorithms identify behavioral anomalies suggesting fraudulent file activity, and block offending users within seconds.

Zero-Day Protection: Does not rely on traditional signature update services.

Incident Management: Administrator dashboard enabling real-time attack monitoring, comprehensive incident evidence logging and post-attack forensics.

Instant Recovery: Near-instant recovery of any affected files from snapshots that are securely stored in an air-gapped, immutable cloud object storage effectively thwarting any manipulation attempts by malicious actors.

One-Click Deployment: Single-click feature activation on CTERA Edge Filers with latest version release.

"Given the escalating prevalence and severity of data exfiltration attacks, we believe advanced cybersecurity features provide significant value and tight integration into storage systems is a top priority," said Whit Walters, analyst at GigaOm. "CTERA's native integration of data exfiltration protection within their edge file services platform represents an important step in this direction. By baking advanced exfiltration defenses directly into their storage architecture, CTERA ensures organizations can proactively safeguard their vital data assets against this insidious threat vector." 

virtualDCS strengthens leadership team

Posted 1 day ago by Phil Alsop
Cloud hosting and cyber resilience specialist virtualDCS has unveiled a new senior leadership team as it enters its next major growth phase, backed...
New integrations, broad marketplace access empower customers using cloud, security, and observability tools with network telemetry and insights.

runZero ushers in a new era of Exposure Management

Posted 2 days ago by Phil Alsop
Expanded platform offers new approach to detecting and prioritizing risk, starting with comprehensive visibility across the total attack surface.

Broadcom teams with Audi

Posted 2 days ago by Phil Alsop
VMware Cloud Foundation helps Audi Modernize IT on the factory floor while reducing cost, complexity and environmental impact.

Infinidat and Veeam team up

Posted 2 days ago by Phil Alsop
Veeam, a leader in Kubernetes data resilience, can now leverage Infinidat’s InfiniBox® high-performance, cyber resilient storage solution to...

Bitdefender and Techs + Together partner

Posted 2 days ago by Phil Alsop
Bitdefender and Techs + Together, a global managed service provider (MSP) community designed to empower MSPs through collective knowledge and shared...
Leaseweb has shared a major update on its contribution to the EU’s Important Projects of Common European Interest on Cloud Infrastructure and...
AI portfolio adds enhancements to Red Hat OpenShift AI and Red Hat Enterprise Linux AI to help operationalise AI strategies.