Friday, January 1, 2016

Microsoft failed to warn victims of Chinese email hack: former employees



By Joseph Menn
1 January 2016
 
If DLP (Data Loss Protection) is deployed, such diversion of data and email will have been discover, monitor and protected very much earlier - through data fingerprinting of abnormally of data diversion.

DLP ensure data integrity.
 
If DLP is used in conjunction with WAF (Web Application Firewall) to protect web vulnerabilities - should have stopped such hacking.


And the WAF should also be supported by IPS (Intrusion Prevention System) - which also should detect and prevent the anomaly.


If APT (Advanced Persistent Threat) is also in place, virtual patching with anomaly behaviour that detonate in sandbox will also have identified the anomaly early and prevented the attack.
Finally, a SOC (Security Operation Centre) with SIEM (Security Incident Events Monitoring) System that monitor security events and incidents will have detected the hacking.

No comments:

Post a Comment