[DDHBOX Introduction Case] Electronic Components Manufacturer / Electronic Components and Semiconductors
Detection of C2 server communication through a blacklist and automatic blocking! A case where explanations during client audits became easier.
We would like to introduce a case where the electronic component manufacturer implemented our exit security solution, "DDHBOX." There was a large amount of development data (drawings/specifications), and the responsibility for the risk of data leakage was significant. The situation was further complicated by the introduction of partner company terminals and the use of VPNs, which increased potential entry points. By installing our product at the exit (inside the FW/UTM), C2 communications are automatically blocked. The source IP is identified through notification emails, allowing for the rapid isolation of the affected terminal. Monthly reports are utilized as documentation for client audits. [Case Overview] ■ Challenge: Lack of budget/personnel to contract a SOC ■ Solution: Share monthly reports with management and use them as documentation for client audits ■ Effects: - An additional layer has been added to stop "external communications after intrusion," increasing peace of mind. - Even when detection occurs, the combination of blocking and notifications has improved initial response times. *For more details, please download the PDF or feel free to contact us.
- Company:ネクフル
- Price:Other