Kaspersky official blog 2024年07月06日
Kaspersky Expertise Centers | Kaspersky official blog
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

卡巴斯基拥有多个专业领域的安全专家团队,致力于研究网络威胁,开发创新技术,并提供专业服务,为企业和个人提供全方位的安全保障。从全球研究与分析团队(GReAT)到威胁研究中心,以及人工智能技术研究团队和安全服务部门,卡巴斯基的专家们在不同领域发挥着重要作用,共同构建强大的网络安全防御体系。

📢 **全球研究与分析团队(GReAT)**:专注于研究高级持续性威胁(APT)攻击、网络间谍活动以及国际网络犯罪趋势。该团队拥有来自世界各地的专家,深入了解不同地区的网络安全现状,并提供全球视角,帮助卡巴斯基及时掌握最新的网络威胁。GReAT团队不仅识别高级威胁,还分析与APT攻击相关的网络事件,并监控超过200个APT组织的活动。他们的工作成果为卡巴斯基客户提供了更强大的反高级威胁工具,以及独家发布的APT和犯罪软件情报报告,其中包含攻击策略、技术和程序(TTP)以及攻击指标(IoC),帮助客户构建可靠的防御体系。

💻 **威胁研究中心**:该中心负责研究攻击者的策略、技术和程序,并推动新的网络安全技术的开发,是卡巴斯基产品防护机制的基础。威胁研究中心主要负责分析新的网络威胁,确保卡巴斯基产品能够有效识别和阻止这些威胁。该中心包含反恶意软件研究团队(AMR)和内容过滤研究团队(CFR)两个部门。AMR负责分析攻击者使用的软件,包括恶意软件、合法软件用于恶意目的(LolBins)、灰色软件等;CFR则负责分析与互联网通信相关的威胁,例如钓鱼攻击和垃圾邮件。

💬 **人工智能技术研究团队**:该团队利用数据科学和机器学习技术来检测各种网络威胁,包括恶意软件、钓鱼攻击和垃圾邮件,每天检测超过40万个恶意对象。该团队还致力于开发基于生成式人工智能(GenAI)的威胁情报,帮助安全分析师应对海量信息,自动化日常任务,并更快地获得洞察,提升分析能力,专注于调查复杂案件和研究复杂威胁。此外,该团队还利用人工智能技术保护复杂的工业系统,例如,卡巴斯基机器学习异常检测(MLAD)解决方案可以检测工业环境中的异常,帮助识别潜在入侵的早期迹象。

👨 **安全服务部门**:该部门为全球最大的企业提供免费的信息安全服务,其服务组合围绕安全部门的主要任务展开,即解决事件及其影响:检测、响应、演练和流程运营卓越。该部门拥有全球紧急响应团队,分布在各大洲,每年参与数百起事件响应。此外,该部门还提供托管检测和响应服务(MDR),由卡巴斯基安全运营中心(SOC)专家监控客户基础设施中的可疑活动,并及时响应事件,将影响降至最低。该部门还提供各种安全评估服务,帮助企业评估其安全成熟度,为现实世界中的攻击做好准备,发现漏洞等。

📡 **工业控制系统安全研究中心(ICS CERT)**:该中心是一个全球性项目,其主要目标是帮助制造商、业主和运营商以及研究团队确保工业自动化系统和其他机器对机器(M2M)解决方案(楼宇自动化系统、交通运输、医疗系统等)的网络安全。ICS CERT专家不断分析各种产品和技术,评估其安全级别,向制造商报告漏洞信息,并告知使用漏洞解决方案的用户相应的风险。除了寻找零日漏洞外,该中心还分析公开的ICS产品漏洞信息,发现并消除其中的错误,并提供减少最终用户风险的建议。此外,该中心还识别和研究针对工业领域的攻击,提供事件响应和数字取证方面的协助,并根据研究结果分享攻击分析信息以及攻击指标数据流。

When writing about threats, vulnerabilities, high-profile investigations or technologies, we often mention our experts of various specializations. Generally speaking, Kaspersky’s experts are highly qualified employees specialized in their particular field who research new cyberthreats, invent and implement breakthrough methods to combat them, and also help our clients and to deal with the most serious of incidents. There are many fields for using their talents; most of them fall within the competence of one of our five so-called “centers of expertise”.

Kaspersky Global Research and Analysis Team (GReAT)


Our best known team in the cybersecurity industry is the Global Research and Analysis Team (GReAT). It’s a tightly knit collective of top-notch cybersecurity researchers specializing in studying APT attacks, cyber espionage campaigns, and trends in international cybercrime. Representatives of this international team are strategically located in our offices around the world to ensure immersion into regional realities and provide the company with a global perspective of the most advanced threats emerging in cyberspace. In addition to identifying sophisticated threats, GReAT experts also analyze cyber-incidents related to APT attacks, and monitor the activity of more than 200 APT groups. As a result of their work, our clients receive improved tools to combat advanced threats, as well as exclusive Kaspersky APT and Crimeware Intelligence reports, containing tactics, techniques and procedures (TTP), and indicators of compromise (IoC) useful for building reliable protection.

Kaspersky Threat Research

Kaspersky Threat Research are the experts whose work lies at the foundation of our products’ protective mechanisms – as they study all the details of attackers’ tactics, techniques and procedures, and drive the development of new cybersecurity technologies. These experts are primarily engaged in analyzing new cyberthreats and are responsible for ensuring that our products successfully identify and block them (detection engineering). Threat Research includes (i) Anti-Malware Research (AMR), whose experts deal with software (including malware, LolBins, greyware, etc.) used by cyberattackers; and (ii) Content Filtering Research (CFR), which is responsible for analysis of threats associated with communication via the internet (such as phishing schemes and spam mailings).

Attackers work hard to circumvent protective technologies, which is why we pay special attention to the security of our own products. The Threat Research expertise center also includes the Software Security team, which mitigates the risks of vulnerabilities in Kaspersky solutions. In particular, they’re responsible for the secure software development life cycle (SSDLC) process, bug bounty program, and for ensuring that our secure-by-design solutions (our own operating system – KasperskyOS – and products based on it) really are truly secure.

Kaspersky AI technology research


We all know how hyped AI technology is today, and how popular the topics of AI in cybersecurity and Secure AI are on the market. Our team provides a range of options in our solutions from ML (machine learning) and AI-enhanced threat discovery and triage alerts to prototype GenAI-driven Threat Intelligence.

For over two decades, our products and services have incorporated aspects of artificial intelligence to enhance security, privacy, and business protection. Kaspersky AI Technology Research applies data science and machine learning to detect various cyberthreats, including malware, phishing and spam on a large scale – contributing to detection of more than 400,000 malicious objects daily.

To detect more complex, targeted attacks, you have to juggle massive numbers of events and alerts coming from different levels of the IT infrastructure. Proper aggregation and prioritization of these alerts are crucial. Without AI-powered automation, it’s easy for a security-operations-center analyst to get overwhelmed and overlook critical alerts amid the multitude of security notifications. Better alert triage and prioritization – especially with machine learning – is top priority for our detection and response solutions (EDR, SIEM, XDR and MDR services).

Generative AI (GenAI) technologies open up new possibilities in cybersecurity. Kaspersky researchers are working on applying GenAI to various tasks in products ranging from XDR to Threat Intelligence to help cybersecurity analysts cope with the daily deluge of information, automate routine tasks, and get faster insights, amplifying their analytical capabilities and enabling them to focus more on investigating complex cases and researching complex threats.

We also use artificial intelligence to protect complex industrial systems. Our Kaspersky Machine Learning for Anomaly Detection (MLAD) solution enables our products to detect anomalies in industrial environments – helping identify early signs of potential compromise.

As AI systems are inherently complex, Kaspersky AI Technology Research also works on identifying potential risks and vulnerabilities in AI systems – from adversarial attacks to new GenAI attack vectors.

Kaspersky Security Services


Kaspersky Security Services experts provide complimentary services for information security departments at the largest enterprises worldwide. Its service portfolio is built around the main task of security departments – addressing incidents and their impact: detection, response, exercises, and process-wise operations excellence.

Whenever organizations face a security crisis, our team is dedicated to building a complete picture of the identified attack, and sharing recommendations for response and impact minimization. Our Global Emergency Response Team is located on all continents and is involved in hundreds of incident responses yearly.

For organizations that require continuous incident detection, there’s our Managed Detection and Response service. The Kaspersky SOC experts behind this service monitor suspicious activity in the customer’s infrastructure, and help to timely respond to incidents and minimize impact. Our MDR operates worldwide and is top-rated by customers.

Developing and measuring security maturity, preparing for real-world attacks, discovering vulnerabilities and more are the goals of our various Security Assessment services. Among other things, they can: evaluate SOC readiness to protect critical business functions with attack simulations (red teams); assess attackers’ chances of penetrating your network and gaining access to critical business assets with penetration testing service; and identify critical vulnerabilities by deeply analyzing complex software solutions with our application security service.

If a company needs to build its own SOC, or assess the maturity level or development capabilities of an existing one, our SOC Consulting experts share their vast experience in security operations gained while working with different industries, organizations of different sizes and with different budgets.

Before, during and after an attack, cybercriminals leave traces of their activities outside the attacked organization. Our Digital Footprint Intelligence experts identify suspicious activities on cybercriminal marketplaces, forums, instant messengers and other sources to timely notify an organization about compromised credentials, or someone selling access to their internal corporate network or data from their internal databases, and so on.

Kaspersky ICS CERT

Our industrial systems cybersecurity research center (Kaspersky ICS CERT) is a global project whose main goal is assisting manufacturers, owners and operators, and research teams in ensuring the cybersecurity of industrial automation systems and other M2M (machine-to-machine) solutions (building automation systems, transportation, medical systems and so on).

Kaspersky ICS CERT experts constantly analyze various products and technologies, evaluate their security level, report information about vulnerabilities to their manufacturers, and inform users of vulnerable solutions about the corresponding risks. In addition to searching for zero-day vulnerabilities, our CERT team analyzes publicly available information on vulnerabilities in ICS products, finds and eliminates multiple inaccuracies in it, and adds its own recommendations for reducing the risks to end-users.

Also, Kaspersky ICS CERT specialists identify and study attacks on organizations in the industrial sector, provide assistance in incident response and digital forensics, and share analytical information about attacks as well as indicators-of-compromise data feeds based on the results of their research.

In addition, our experts contribute to the engineering of sectoral and governmental regulations in the field of industrial cybersecurity, transportation, and the industrial Internet of Things; develop and conduct training for information-security specialists and employees of industrial organizations; and provide various consulting services.

Kaspersky spends huge amounts of resources – including a significant portion of its profits – on developing its expertise. Our experts research cyberthreats relevant to even the most remote corners of the globe, and understand the specific needs of all customers – no matter where they are. Thanks to the contribution of the above-listed centers of expertise, our services and solutions are constantly being improved and so always remain ready to counter the most non-trivial of attacks and identify the latest cyberthreats.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络安全 卡巴斯基 安全专家 威胁研究 人工智能
相关文章