Over the weekend, on-prem Microsoft SharePoint servers were targeted in a massive hack that severely disrupted businesses and governments across the globe – locking away critical systems and exfiltrating sensitive data, opening them up to potential millions in damages and liabilities.  

Hackers exploited a ‘zero-day’ vulnerability, manipulating an overlooked error in a recent security patch, according to reporting by the Washington Post. These types of attacks have become a fact of life for businesses as hackers are constantly on the lookout for even the most minor of exploitable vulnerabilities in commonly used programs like SharePoint.  

As Microsoft and affected agencies scramble to recover from the data breach, it’s important to remember that more effective architecture and security measures could have prevented this. Among the many potential improvements that could have significantly reduced potential damage are data diodes – hardware that has become a key feature of modern high-security server architecture.  

How data diodes prevent cybercrime 

These devices are designed to enforce strict one-way data flow between networks from a high-security network to a less-secure network, or vice versa. Unlike traditional firewalls or software-based solutions, a data diode physically prevents data from traveling bidirectionally to or from an air-gapped network, only allowing information to flow in one direction. Only specialized solutions, like Connecting Software’s, can work with explicitly one-way lines to give them full functionality securely. 

Solutions like these stop unauthorized data exfiltration (the theft or leaking of sensitive information) because bidirectional direct communication is impossible – meaning that while authorized employees can exchange data, attackers don’t receive a response from a request to steal it. 

Data diodes are also known for preventing lateral movement, as attackers can’t move within the network, traveling from one system, server, or segment to another, usually to locate sensitive data or escalate privileges after gaining an initial foothold. If an attacker were to gain a foothold in a less secure network connected to a high-security network via a data diode, commands can be sent but they will not receive a response since the information comes through a separate on-way communication channel. 

How data diodes could have prevented this hack  

If data diodes had been used in this instance, they could have prevented key sensitive information from being exfiltrated through the network, given that the SharePoint server itself would have had no direct network connection to external untrusted networks such as the internet. 

There are limitations to this approach – the physical measures would have only stopped these hackers from attempting their attack if their data diodes explicitly prevented any inbound network connections from untrusted networks to the vulnerable SharePoint instance. Regardless, the speed at which hackers were able to access critical networks and gain access to sensitive information underlines the importance of a well-designed physical architecture paired with stringent zero-trust configurations. 

The Connecting Software approach 

Data Diodes are an increasingly vital part of modern security to prevent large scale hacks like these but can be quite inconvenient for organizations without the proper software. Because data diodes enforce one-way communication, it can be extremely inconvenient to synchronize useful data like shared files, contact information, and calendar events across these networks.  

Connecting Software has developed a suite of software designed to bridge this gap – with products designed to synchronize critical information while maintaining the critical security of data diode. These products offer a truly ‘best of both worlds’ approach, letting you maintain the overall security of your network while retaining the ease of synchronization and network communication that you would have with a two-way connection.  

To learn more about these products, visit the product pages here: 
https://www.connecting-software.com/connect-bridge-for-air-gapped-networks/  

https://www.connecting-software.com/secure-sync-for-sharepoint/  

Über die Connecting Software s.r.o. & Co. KG

Connecting Software has been providing software solutions to synchronize data and connect enterprise systems for over two decades. It serves over 1000 customers globally, particularly in highly regulated sectors such as finance, public service, and defense.

Connecting Software’s solutions work automatically in the background to increase productivity, improve security, and ensure compliance. They easily connect with popular business applications like Microsoft Dynamics, O365/M365, SharePoint, and Salesforce. They also incorporate proven, cutting-edge technologies such as blockchain for data integrity and authenticity, and data diodes for unidirectional secure data transfer in sensitive environments. This strategic application of advanced technologies ensures effectiveness and reliability for clients’ critical operations.

Firmenkontakt und Herausgeber der Meldung:

Connecting Software s.r.o. & Co. KG
Gumpendorfer Straße 19
A1060 Wien
Telefon: +43 (1) 3707200
http://www.connecting-software.com

Ansprechpartner:
Elliot Settle
PR Lead
E-Mail: elliot@connecting-software.com
Für die oben stehende Story ist allein der jeweils angegebene Herausgeber (siehe Firmenkontakt oben) verantwortlich. Dieser ist in der Regel auch Urheber des Pressetextes, sowie der angehängten Bild-, Ton-, Video-, Medien- und Informationsmaterialien. Die United News Network GmbH übernimmt keine Haftung für die Korrektheit oder Vollständigkeit der dargestellten Meldung. Auch bei Übertragungsfehlern oder anderen Störungen haftet sie nur im Fall von Vorsatz oder grober Fahrlässigkeit. Die Nutzung von hier archivierten Informationen zur Eigeninformation und redaktionellen Weiterverarbeitung ist in der Regel kostenfrei. Bitte klären Sie vor einer Weiterverwendung urheberrechtliche Fragen mit dem angegebenen Herausgeber. Eine systematische Speicherung dieser Daten sowie die Verwendung auch von Teilen dieses Datenbankwerks sind nur mit schriftlicher Genehmigung durch die United News Network GmbH gestattet.

counterpixel