{"id":1306,"date":"2019-07-24T12:46:35","date_gmt":"2019-07-24T04:46:35","guid":{"rendered":"https:\/\/greycortex.hk\/?page_id=1306"},"modified":"2019-08-19T12:18:53","modified_gmt":"2019-08-19T04:18:53","slug":"use-case-infected-smart-tv","status":"publish","type":"page","link":"https:\/\/greycortex.hk\/zh\/use-case-infected-smart-tv\/","title":{"rendered":"Use Case &#8211; Infected Smart TV in Corporate Headquarters"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1306\" class=\"elementor elementor-1306\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-88bc722 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"88bc722\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9c5ca76\" data-id=\"9c5ca76\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-74b4c2c elementor-widget elementor-widget-heading\" data-id=\"74b4c2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Infected Smart TV in\nCorporate Headquarters<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e905edb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e905edb\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c410c8d\" data-id=\"c410c8d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-6304589 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6304589\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b6e2d22\" data-id=\"b6e2d22\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bf0698d elementor-widget elementor-widget-text-editor\" data-id=\"bf0698d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Industry:<\/strong><\/p><p>Medium Enterprise<\/p><p><strong>Entry Point:<\/strong><\/p><p>Infected IoT device<\/p><p><strong>Objective:<\/strong><\/p><p>Data theft<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-499a7e8\" data-id=\"499a7e8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b770188 elementor-widget elementor-widget-text-editor\" data-id=\"b770188\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Primary Detection:<\/strong><\/p><p>Anomalies, and repetitive machine-like behavior detected by behavioral analytics features within MENDEL<\/p><p><strong>Attack Stopped by:<\/strong><\/p><p>Firewall Integration<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-8c8f2d6 elementor-widget elementor-widget-text-editor\" data-id=\"8c8f2d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>MENDEL was installed to monitor the network at the headquarters of a commercial enterprise. As part of an office renovation, the company installed a smart TV in their employee cafeteria. As an IoT device, endpoint security was not installed, but it could still communicate over the entity\u2019s network. MENDEL was able to monitor the device by analyzing its network communications.<\/h5><h5>MENDEL identified periodic, repetitive communication, including a higher than expected volume of data transfer outbound from the network taking place at this device. MENDEL automatically alerted the security team, who usedMENDEL\u2019s firewall integration to block communications from the device prior to investigation. Using MENDEL\u2019s incident management tools, the team was able to coordinate investigation of the device. The television contained malicious apps which were the cause of the problem, and which were pre-installed on the TV. They were removed.<\/h5><h5>IoT devices are notoriously dangerous to the larger network over which they communicate. They often feature easily breakable passwords which are unknown to the end user and which are rarely changed (and in some cases, are available via Google search). Endpoint security clients often cannot be installed on IoT devices and they are frequently overlooked by network administrators. MENDEL detects threats from IoT devices just like it detects those from \u201ctraditional\u201d devices \u2013 by modeling their normal behavior and identifying anomalous and possibly malicious events as the threats attempt to take action within the network.<\/h5>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b2d1d69 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b2d1d69\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-2f28003\" data-id=\"2f28003\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e48cb2f elementor-widget elementor-widget-image\" data-id=\"e48cb2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"254\" height=\"300\" src=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?fit=254%2C300&amp;ssl=1\" class=\"attachment-medium size-medium wp-image-948\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?w=1594&amp;ssl=1 1594w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=254%2C300&amp;ssl=1 254w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=768%2C906&amp;ssl=1 768w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=868%2C1024&amp;ssl=1 868w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=600%2C708&amp;ssl=1 600w\" sizes=\"(max-width: 254px) 100vw, 254px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-7766cb7\" data-id=\"7766cb7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1dbc071 elementor-hidden-desktop elementor-hidden-tablet elementor-widget elementor-widget-spacer\" data-id=\"1dbc071\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e982910 elementor-widget elementor-widget-heading\" data-id=\"e982910\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u4f60\u6709\u4ec0\u9ebc\u554f\u984c\u55ce\uff1f<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a1d42ea elementor-widget elementor-widget-text-editor\" data-id=\"a1d42ea\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;,&quot;_animation_delay&quot;:200}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u8acb\u7559\u4e0b\u60a8\u7684\u806f\u7d61\u65b9\u5f0f\uff0c\u4ee5\u4fbf\u6211\u5011\u6839\u64da\u60a8\u516c\u53f8\u7684\u9700\u6c42\u63d0\u4f9b\u500b\u6027\u5316\u7684\u670d\u52d9\u3002<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-f0de5f7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f0de5f7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-49d84c3\" data-id=\"49d84c3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-641e948\" data-id=\"641e948\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Infected Smart TV in Corporate Headquarters Industry: Medium Enterprise Entry Point: Infected IoT device Objective: Data theft Primary Detection: Anomalies, and repetitive machine-like behavior detected by behavioral analytics features within MENDEL Attack Stopped by: Firewall Integration MENDEL was installed to monitor the network at the headquarters of a commercial enterprise. As part of an office [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-templates\/fullwidth-content.php","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","_crdt_document":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"footnotes":""},"class_list":["post-1306","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/PaZ0Rf-l4","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/comments?post=1306"}],"version-history":[{"count":25,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1306\/revisions"}],"predecessor-version":[{"id":1926,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1306\/revisions\/1926"}],"wp:attachment":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/media?parent=1306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}