The latest defense against increasingly sophisticated and sophisticated cyber attacks! What are the IT Infrastructure Safety Measures Proposed by Fujitsu? --Nikkei Cross Tech Special
Increased attacks on firmware for which countermeasures have been delayed
In the "Information Security 10 Major Threats 2021" announced by IPA (Information-technology Promotion Agency), the top two were the damage of ransomware in the first place and the theft of confidential information by the targeted attack in the second place. Of particular note is the targeting of ransomware. Ransomware, which used to be an attack method for indiscriminately delivering virus emails, invades corporate / organizational networks with the same clever technique as targeted attacks, and demands a ransom by encrypting data and stealing information. .. Since there are cases where related companies are used as a stepping stone, defense against attacks is required regardless of the size of the company.
Targeted ransomware countermeasures require defense-in-depth from the OS to hardware and networks not only for PCs but also for servers that carry IT infrastructure. So far, various countermeasures against cyber attacks have been taken, such as network countermeasures such as firewalls, server OS countermeasures with patch patches, and monitoring and removal with security software. However, in recent years, attacks targeting firmware, which has been a blind spot in defense in depth, have increased rapidly, and countermeasures against it are urgently needed.
The firmware that controls the hardware is the basis of the server. One of the firmware, BIOS (Basic Input / Output System), operates before the OS boots, so even if the BIOS is infected and tampered with, it cannot be detected by security software running on the OS. By tampering, it is possible to start and stop the OS, hide malware in the BIOS, invade the system, and steal confidential information. In addition, since it is difficult to repair from the OS, it takes time to take measures after infection, and there is concern about the spread of damage.
Microsoft's March 2021 report, Security Signals, states that 80% of companies have experienced a firmware attack once every two years. Fujitsu has been using the latest server OS "Windows Server 2022" and "FUJITSU Server PRIMERGY" 3rd generation Intel® Xeon ® scalable processor-equipped server (hereinafter referred to as PRIMERGY) as the OS for the hardware area where safety measures have been delayed. We are making proposals that utilize new technologies from both hardware.