技术
- 分析与建模 - 实时分析
- 基础设施即服务 (IaaS) - 云计算
适用功能
- 物流运输
用例
- 网络安全
- 实时定位系统 (RTLS)
服务
- 网络安全服务
关于客户
本案例研究中的客户是全球监管合规权威机构 Exiger 的客户。这些客户遍布各个行业,并依靠 Exiger 的专业知识和工具来管理和减轻其生态系统内的网络安全风险。他们特别关注可能被黑客利用的漏洞,包括与强大民族国家行为者有关的漏洞。 2021 年,这些客户面临来自两个据信与中国政府有关联的网络间谍组织的威胁,该组织创建了超过 16 个不同的恶意软件系列来针对 Pulse Secure VPN。
挑战
2022 年 9 月下旬,IT 安全社区和 Microsoft 确认对一组重要漏洞进行了调查,其中包括两个影响 Microsoft Exchange Server(2013 年、2016 年和 2019 年)的零日漏洞。这些零日漏洞利用非常严重,因为它们是那些应该对其缓解措施感兴趣的人(例如目标软件的供应商)以前不知道的计算机软件漏洞。在漏洞得到缓解之前,黑客可以远程利用几乎任何程序、数据、其他计算机或受影响系统上运行的网络。供应链的网络安全已成为一个关键风险领域,Microsoft Exchange Server 等漏洞以及 SolarWinds 和 Accellion 等最近的漏洞表明软件如何成为特洛伊木马,将防护产品变成整个生态系统的威胁。在过去三年中,Exiger 的客户发现了超过 30 个被黑客攻击的严重漏洞,这些漏洞通常与强大的民族国家行为者有关。
解决方案
为了应对过去十年中最严重的网络漏洞之一,Exiger 的客户利用该公司的实时网络探索工具来识别其生态系统中可能对最近发现的 Microsoft Exchange Server 零日漏洞做出响应的供应商。利用 Supply Chain Explorer Cyber 模块,Exiger 客户能够即时识别和评估其环境中威胁的严重性。 DDIQ 网络分析工具为客户创建了威胁和漏洞的实时视图,允许基于风险的缓解并在最重要的地方阻止威胁。
运营影响
数量效益
Case Study missing?
Start adding your own!
Register with your work email and create a new case study profile for your business.
相关案例.
Case Study
Leading Tools Manufacturer Transforms Operations with IoT
Stanley Black & Decker required transparency of real-time overall equipment effectiveness and line productivity to reduce production line change over time.The goal was to to improve production to schedule, reduce actual labor costs and understanding the effects of shift changes and resource shifts from line to line.
Case Study
Jaguar Land Rover Speeds Order-to-Cash Cycle
At Jaguar Land Rover, vehicles physically move around the facility for testing, configuration setting, rework and rectification, leading to a longer search time to get each vehicle to its next process facility. The main goal is to minimize the vehicles' dwell time between end of line and the delivery chain which was previously a manually intensive process. Jaguar Land Rover's goal was to build on the success of an earlier RFID project and improve the efficiency of delivering vehicles to meet dealer orders.
Case Study
Enel Secures Italian Power Generation Network
Electric energy operators around the world are working to increase the reliability and cyber resiliency of their systems. This includes Enel, a global power company that manages and monitors the Italian power grid. This grid:• Serves 31 million customers• Has a net installed energy capacity exceeding 31 gigawatts• Includes more than 500 power generation plants,including hydroelectric, thermoelectric, and wind• Is managed and monitored by Enel 24/7/365• Is operated by Terna, the Italian Transmission System Operator (TSO)Enel is responsible for the availability of the grid’s underlying ICS and industrial network. It also manages Regional Control Centers and Interconnection Centers which connect with the TSO. The TSO manages the flow of energy to the grid plus controls and remotely regulates the power generation of power plants, increasing and decreasing power production as required. The complex system of interaction and cooperation between Enel and the TSO has strong security implications as well as operational and business challenges.
Case Study
Securing the Connected Car Ecosystem
In-vehicle communications and entertainment system hosts high-value or sensitive applications. API libraries facilitate communication and sharing of vehicle data. These API libraries are vulnerable to reverse engineering and tampering attacks and may even result in loss of passenger safety. Attackers can inject malware that may be able to migrate to other in-car networks such as the controller-area-network (CAN) bus which links to the vehicle’s critical systems. Software provided for dealers to interface with cars through the OBD2 port is vulnerable to reverse engineering and tampering attacks. Hackers may be able to abuse these tools to inject malicious code into the ECUs and CAN bus. Attackers can lift the cryptographic keys used, and use that to build their own rogue apps/software. Their cloned version of the original app/software may have altered functionality, and may intend to gain access to other in-car networks.
Case Study
Improve Postal Mail and Package Delivery Company Efficiency and Service
Postal mail and package delivery company wanted to replace legacy yard management system, increase inbound and outbound yard velocity, improve priority parcel delivery time and accuracy, reduce workload and overtime, reduce driver detention and measure performance and utilization of yard resources.
Case Study
Secure and Cloud-based Data Marketplace
The great promise of new connected concepts of industry like 'Industry 4.0' is their ability to deliver a historically unparalleled level of responsiveness and flexibility. While modern supply chains are already heavily integrated and designed to be fluid and fast moving, a large swathe of manufacturing still remains beholden to economies of scale, large production runs, and careful preplanning.The Industrial Internet of Things (IIoT) is set to change this by allowing small-batch or even custom manufacturing on a truly industrial scale. With machines whose functions are not set in stone, but flexible and determined by their operating software and with a new form of connectivity bringing industrial engineers, product manufacturers, and end users closer together than ever before. Ad-hoc adjustments to automotive parts, for example, during active product runs or the bespoke manufacturing of custom sneakers become very viable options indeed.Much of this remains a theoretical vision, but IUNO, the German national reference project for IT security in Industry 4.0 demonstrates the new capabilities in action with a secure technology data marketplace running a smart drinks mixer.