Advanced Solutions Incorporation International

ASI KeyShield

APT Detection and Response

KeyShield is an effective solution running on endpoints to detect, warn and respond activities related to APT attacks. KeyShield is the perfect combination of modern, advanced computer technologies and the skills, knowledge of of cybersecurity experts. Our solution plays an important role in protecting your organization against APT attacks, minimizing damage caused by cyber attacks, and contributing to the 4th Industrial Revolution.

KeyShield Overview

APT Threat Detection
KeyShield applies a variety of effective tactics to identify APT attacks:
  1. Identify abnormal behavior based on behavioral rules (IoA), with machine learning and big data analysis to classify rare behaviors.
  2. Identify attack indicators based on threat intelligence collected from thousands of APT attacks over many years.
  3. The mechanism "Only trust what is trustworthy" enables quick detection of strange elements appearing in the information technology system.
  4. Identify common data leak behaviors found in APT attacks.
 
Compliance and Policy
KeyShield offers the capability to establish information security regulations based on various features:
  1. Control the connection and use of external storage devices.
  2. Control the connection and use of Wifi networks.
  3. Filter and control network for inbound and outbound network traffic.
  4. Control access to the protected file system and registry.
  5. Control the list of installed programs.
  6. Control the list of device drivers.
Terminal users are organized into groups and specific rules are applied to each group. This mechanism enables customized regulations for each specific department of the customer using the solution.
Vulnerability Management

One of the key features of Vulnerability Management is vulnerability scanning. KeyShield scans the endpoints for known/unknown vulnerabilities and compares them against a comprehensive vulnerability database. This process helps identify any outdated software, misconfigurations, or other weaknesses that could be exploited by attackers.

Once vulnerabilities are identified, KeyShield assists in prioritizing them based on their severity and potential impact on the system. This helps organizations focus resources on addressing the most critical vulnerabilities first, thereby reducing the risk of exploitation.

Forensic Investigation
Collected data is stored centrally, thereby reproducing behaviors that took place on the terminal for the necessary analysis. In a cyber investigation, just like in real-world criminal investigations, the investigator can "roll back the security tape" and see what happened in the system. Our solution provides a smart correlation analysis mechanism that forms a Story Line with all the necessary information to help determine the source of the attack. The solution also provides In-depth Investigation and Wide-area Investigation functions to ensure the tracing and hunting of threats; along with many statistical and search features that allow users to have an overview of the network under management. These tasks are done on a single intuitive administration interface.
Real-time Response
One key feature of real-time prevention is the ability to detect and block malicious code or malware that may be part of an APT attack. KeyShield scans files and processes in real time, comparing them against known signatures associated with APT attacks. If any malicious code is detected, KeyShield can immediately block the threat to prevent it from executing and spreading throughout the system. Additionally, real-time prevention capabilities include network traffic monitoring. KeyShield analyze network communications to identify connections to malicious domains, or data exfiltration attempts. By actively monitoring network traffic, KeyShield can detect and block APT attacks that rely on command-and-control communication or data exfiltration to achieve their objectives.  
Effective Prevention
KeyShield provides robust functionality to prevent various types of attacks, including application control and network control features:
  1. Application control is a key component of KeyShield that helps prevent unauthorized or malicious applications from running on endpoints. By leveraging application blacklisting techniques, KeyShield allows organizations to block or restrict the execution of unapproved or potentially harmful applications.
  2. Network control is another crucial function of KeyShield that focuses on preventing attacks originating from network connections. This feature enables organizations to monitor and control network traffic to and from endpoints, thereby reducing the risk of network-based attacks. This helps prevent the spread of malware, stop command-and-control communication, and thwart network-based attacks such as phishing attempts or data exfiltration.
Powerful Management
KeyShield offers powerful management capabilities:
  1. Single tenant deployment refers to KeyShield being implemented for a single organization or customer. This deployment model provides dedicated resources and infrastructure, ensuring that the organization has full control. It allows for customization, tailored policies, and independent data storage, providing a high level of security and flexibility to meet specific organizational requirements.
  2. Multi-tenant deployment enables an KeyShield to serve multiple organizations or customers within dedicated infrastructure. It offers centralized management, scalability, and cost-effectiveness, making it suitable for managed security service providers (MSSPs) or organizations with multiple subsidiaries or departments.
  3. Integration with SIEM systems is a key capability of KeyShield, enabling seamless collaboration and information sharing between the two. KeyShield can send security events, alerts, and detailed endpoint telemetry data to the SIEM system. This integration enhances threat detection and response capabilities by leveraging the correlation and analysis capabilities of the SIEM platform. It allows security teams to have a holistic view of security incidents, combining endpoint-centric visibility with network and system-wide context for comprehensive threat detection and investigation.
  4. KeyShield provide webhooks, which are a mechanism for real-time communication between KeyShield and external systems. Webhooks allow external applications or services to receive notifications or data updates from the KeyShield. This capability enables organizations to integrate with other security tools, ticketing systems, or custom workflows, enhancing automation and enabling faster incident response.

Gain an edge over APT threat actors with KeyShield

Early identification of security weaknesses in information technology systems, activities related to known and unknown APT attacks; counteract attacks in real time, respond as quickly as possible when an incident occurs.

Catch what others miss

Increased detection of APT attack-related activities based on file static analysis and dynamic behavior analysis

A compliance control solution

Control compliance with information security regulations in organizations and enterprises

System vulnerability warning

Warning of weaknesses in the information technology system of organizations and enterprises

Respond as quickly as possible

Prevent and minimize the impact of APT attack activities on organizations and businesses

Strengthen your security portfolio​

Integrate with other security systems to enhance information for security alerts

Compatible with many environments

Works with a variety of operating systems, the ability to deploy in an air-gap network

Advice and Support from Cybersecurity Experts

Security is a process that requires the cooperation of the system (hardware, software), knowledge (about malware, cyber attacks) and people. Well aware of this, ASI builds a team of cybersecurity experts to support the operation of the computer system. KeyShield’s expert team takes charge of incident response and malware hunting, acting as the last line of defense to ensure your organization or business. The threats discovered during these hunts are then integrated back into the solution, enhancing its accuracy and intelligence in analysis and warning information. Our team of experts provides invaluable advice and support throughout the process of handling and investigating problems related to malicious code.

Incident Response Team

Scanning and taking samples of malware at the scene within 24 hours after a security incident

APT Analyst

Perform analysis, report, provide solutions to remove malicious code within 48 hours after a security incident

Technology Support Team

Deploy an operation support team that meets strict criteria to provide the best service quality

Build your own APT attack detection and response system