Resources

Contact Us

Cyveillance IP Block List™

A growing threat

Web and Internet based threats and malicious activity continue to grow at an explosive rate in both volume and complexity. Users are “Phished” or conned by social-engineering attacks into revealing everything from banking logins to corporate information. Mass infection of both servers and desktop PCs by malware and “bot” software has given criminals, hackers and “bot herders” access to both proprietary data or systems and a huge and constantly changing base of free infrastructure on which to run, control and host their activities.

Shortcomings of Existing Solutions

Existing desktop-based or network-based solutions such as anti-virus and anti-spyware systems provide some protection against malware. However, they lack the ability to protect against unknown zero-day attacks that exploit the time between when an application security vulnerability is detected and when the vulnerability is patched.

The Cyveillance Solution

While the increase in online threats such as malware and Phishing can make securing your network a daunting task, these activities still require a host - a physical asset connected to the Net - to pose a threat to vital systems. Cyveillance IP Block List™ is designed to keep internal networks, e-commerce sites, authentication systems, and users informed and protected with up-to-the-minute information about the hosts, domains, Web pages, malicious payloads and IP addresses involved in a wide range of nefarious online activities.

Unique Approach

Unlike many security applications based on known signatures, or URL blacklists that periodically catalog known and/or dedicated ‘bad boxes”, Cyveillance IP Block List™ provide timely, accurate warning of high-risk IP addresses, including detailed information about the malicious activities in which they are engaged right now. This intelligence is used to prevent users or applications from accessing or connecting with those resources, thus, greatly reducing the possibility of compromise of either human users or network assets. Additionally, outbound connections to IP addresses delivered via Cyveillance IP Block List™ could be used to detect a bot infection, insider (i.e. employee) threat or attempted infiltration.

The Benefit

By informing local threat management and network defense applications with real-time, “from the wild” data on what is happening beyond the perimeter, these feeds allow a more proactive security posture. Enterprise networks are aware of the latest threats before they land at the door, rather than hoping to recognize them when they arrive.

Implementation

Cyveillance IP Block List™ is available as a real-time feed or via Web service. The CSV or XML formats are easily consumed by a variety of applications, and specific elements can easily be integrated into firewalls, sensors, mail and Web gateway devices or network infrastructure.

Service Benefits

  • Reduced successful phishing of employees’ identity, financial and (potentially) work-related information, logins and passwords
  • Reduced rate of malware/virus infections and lower remediation costs
  • Proactive approach to securing the network - blocking malware weeks or months before traditional anti-virus/security solutions
  • Reveal connections from compromised network assets to known dangerous hosts