This article is missing information about controversies.March 2023) ( |
Company headquarters | |
Type | Private limited company |
---|---|
Industry | Security software |
Founded | 1 January 1992 | in Slovakia
Founder | Rudolf Hrubý Peter Paško Miroslav Trnka |
Headquarters | , Slovakia |
Area served | Worldwide |
Key people |
|
Products | |
Revenue | €526 million[2] |
Number of employees | 1,831[2] (2020) |
Website | www |
ESET, s.r.o., is a software company specializing in cybersecurity. ESET's security products are made in Europe[3] and provide security software in over 200 countries and territories worldwide, and its software is localized into more than 30 languages.
The company was founded in 1992 in Bratislava, Slovakia. However, its history dates back to 1987, when two of the company's founders, Miroslav Trnka and Peter Paško, developed their first antivirus program called NOD. This sparked an idea between friends to help protect PC users and soon grew into an antivirus software company. At present, ESET is recognized as Europe's biggest privately held cybersecurity company.[4][5][6]
The product NOD was launched in Czechoslovakia when the country was part of the Soviet Union's sphere of influence. Under the communist regime, private entrepreneurship was banned. It wasn't until 1992 when Miroslav Trnka and Peter Paško, together with Rudolf Hrubý, established ESET as a privately owned limited liability company in the former Czechoslovakia. In parallel with NOD, the company also started developing Perspekt.[7] They adopted the name ESET, from the Czech name of Isis, the Egyptian goddess of health, marriage and love, as the company name.
In 2013, ESET launched WeLiveSecurity,[8] a blog site dedicated to a vast spectrum of security-related topics.
December 2017 marked the 30th anniversary of the company's first security product. To mark its accomplishments, the company released a short documentary [9] describing the company's evolution from the perspective of founders Miroslav Trnka and Peter Paško. In the same year, the company partnered with Google to integrate its technology into Chrome Cleanup.[10]
In December 2018, ESET partnered with No More Ransom,[11] a global initiative that provides victims of ransomware decryption keys, thus removing the pressure to pay attackers. The initiative is supported by Interpol and has been joined by various national police forces.[12] ESET has developed technologies to address the threat of ransomware and has produced papers [13][14] documenting its evolution.
ESET became a founding member of Google's App Defense Alliance.[15][16]
Current Management | |
---|---|
Position | Management Member |
Chief Executive Officer | Richard Marko |
Chief Financial Officer | Martin Balušík |
Chief Business Officer | Ignacio Sbampato |
Chief Operating Officer | Palo Luka |
Chief Technology Officer | Juraj Malcho |
Chief Information Officer | Vladimír Paulen |
Chief Sales Officer | Miroslav Mikuš |
ESET operates 22 branches in more than 200 countries. Local distributors are used in other countries.[citation needed]
The first international branch was opened in 1999 in San Diego and the second in the Czech Republic in 2001. Other notable branches include the Buenos Aires office (opened in 2004), Singapore (2013), and Tokyo (2018), which the company used to enter the South American and Asian markets.[citation needed]
ESET provides security products for home and business users. Its products cover all the main operating systems across server, cloud, and mobile deployments.[citation needed]
ESET's first product was NOD, an antivirus program for computers running the MS-DOS operating system. NOD32 1.0 for Microsoft Windows was released in 1998 and version 2.0 in 2003. A third version, ESET NOD32 Antivirus, followed in 2007 along with ESET Smart Security 3, which added antispam and firewall modules.[citation needed]
ESET NOD32 Antivirus and additional related products with a wider suite of security functions, including ESET Smart Security Premium and ESET Internet Security,[17] are upgraded and released on an annual basis.[18] In 2010, ESET released products for macOS, with a business version now called ESET Endpoint Antivirus[19] and a home version called ESET Cyber Security.
ESET also offers products for Android devices. The first version of ESET Mobile Security was announced in 2012.[20] The product offers malware protection and a call filter, an adware detector, payment protection, and theft protection (such as SIM card locking and total data wipes). In 2015, ESET introduced ESET Parental Control,[21] which allows parents to monitor children's use of Android devices.
ESET Smart TV Security, designed to protect Android TV from malware, phishing, and ransomware, was introduced in 2018 at the Mobile World Congress event in Barcelona.[22]
The company offers a full range of solutions to protect corporate data, ranging from workstation and server protection with ESET PROTECT Entry [23] to endpoint detection and response with ESET Enterprise Inspector.[24]
ESET also offers security products that help companies comply with GDPR requirements. These include ESET Secure Authentication, a two-factor authentication solution introduced in 2015,[25] and ESET Endpoint Encryption, which ESET released in 2017 [26] following the integration of DESlock+ products since 2015.[27] ESET Endpoint Encryption offers file, folder, email, and virtual disk encryption, as well as a desktop shredder for secure file deletion.[28]
Along with its individual products and packages, ESET offers services designed mainly for corporations and large companies. These include managed detection and response, premium support, security audits, and incident response.[citation needed]
ESET has 13 R&D centres globally and is an operator in the field of malicious code detection.[29] In 1995, ESET introduced heuristic analysis[30][31] into its detection engine. Heuristic scanners run suspicious files in an in-product sandbox to observe their behavior and assess their risk, meaning that even previously unknown malicious code can be detected.[citation needed]
ESET has been using machine learning in its products, starting with neural networks, since 1997. In 2005, ESET incorporated a machine learning-based technology called DNA Detections, which extracts selected features – called genes – from samples. These genes split samples into clean, malicious and potentially unwanted categories. In 2019, ESET released an Advanced Machine Learning detection layer that can analyze samples locally on endpoints even when offline.[32]
In 2011, ESET replaced ThreatSense.NET with ESET LiveGrid®,[33] a cloud-based reputation system that evaluates unknown or suspicious samples submitted anonymously by millions of ESET-protected endpoints from around the world for machine learning analysis on servers in Bratislava.[33] If a sample is identified as malicious, it is given a low score and this information is shared with all ESET-protected endpoints through the ESET LiveGrid® Reputation System, thus keeping users protected from threats found in other parts of the world.[citation needed]
ESET's Host-Based Intrusion Prevention System (HIPS) monitors system activity and uses predefined rules to recognize suspicious behavior. The HIPS self-defense mechanism stops the offending process from carrying out the harmful activity or – if a more detailed analysis is necessary – performs further inspection via its internal modules. ESET has developed several modules for HIPS, including Advanced Memory Scanner, Exploit Blocker, Ransomware Shield, and Deep Behavioral Inspection.[citation needed]
In 2012, ESET introduced Exploit Blocker,[34] which monitors commonly abused applications for suspicious activity that might indicate an exploit. Monitored applications include web browsers, document readers, email clients, Adobe Flash, Java, and components of Microsoft Office. Exploit Blocker helps to protect users from new and unknown threats and zero-day attacks.
Advanced Memory Scanner was introduced in HIPS in 2013. This module addresses the use of obfuscation and encryption by malware authors to let their code run "in-memory only" and thus avoid detection and further analysis. Advanced Memory Scanner monitors the behavior of this code once it decloaks in memory.[citation needed]
Introduced in 2017, Ransomware Shield[35] monitors and evaluates all executed applications using behavioral and reputation-based heuristics (relying on ESET LiveGrid®). If a behavior that resembles ransomware is identified, such as the encryption of files, Ransomware Shield either blocks the application or notifies the user, who can then choose to block the activity.
In 2019, ESET released Deep Behavioral Inspection,[36] which enables HIPS to thoroughly inspect API calls made by suspicious or unknown processes. If the process is clearly malicious, Deep Behavioral Inspection mitigates the activity and informs the user. If the process is suspicious, HIPS can use the data gathered by Deep Behavioral Inspection to run further analysis via its other components or request additional examination via technologies that are part of the broader ESET scanning engine.
ESET also uses additional security layers including Botnet Protection,[37] Network Attack Protection,[38] Script-Based Attacks Protection,[39] and Brute-Force Attack Protection.[40]
In 2017, ESET became the first security company in the world to implement a UEFI Scanner.[41] UEFI is a firmware that is loaded into a computer's memory during the startup process. The scanner can identify threats while the computer is booting up, before standard detection modules start running.
ESET dedicates part of its operations to malware research, as well as to the monitoring of advanced persistent threat groups and other cybercriminal groups, with 40% of the company's employees working in research.[42]
One of the groups that ESET tracked is Sandworm. After the 2015 attack on the Ukrainian power grid and the global NotPetya ransomware attack in 2017 – both attributed to Sandworm – ESET discovered Sandworm (more specifically, a subgroup that ESET tracks as TeleBots) deploying a new backdoor called Exaramel, which is a version of the main Industroyer backdoor. As Industroyer was used in the 2016 blackout in Ukraine,[43] ESET linked Industroyer to NotPetya, as well as to BlackEnergy, which was used in the 2015 blackout.[44]
At the time of the NotPetya outbreak, ESET and Cisco tracked down the point from which the global ransomware attack had started to companies afflicted with a TeleBots backdoor, resulting from the compromise of M.E.Doc, a popular financial software in Ukraine.[45]
In March 2021, when Microsoft released out-of-band patches to fix the ProxyLogon vulnerability affecting on-premises versions of Microsoft Exchange Server, ESET discovered more than 10 APT groups leveraging the vulnerability to compromise them. ProxyLogon allows an attacker to take over any reachable Exchange server, even without knowing valid account credentials.[citation needed]
In addition, ESET found that multiple threat actors had access to the details of the vulnerabilities even before the release of the patches. Except for DLTMiner, which is linked to a known cryptomining campaign, all of these threat actors are APT groups interested in espionage: Tick, LuckyMouse, Calypso, Websiic, Winnti Group, Tonto Team, ShadowPad activity, The "Opera" Cobalt Strike, IIS backdoors, Mikroceen, DLTMiner,[46] and FamousSparrow.[47]
Another focus of ESET's research is on threats to Android devices. ESET discovered the first clipper malware in the Google Play Store called Android/Clipper.C,[48] which can manipulate clipboard content. In the case of a cryptocurrency transaction, a wallet address copied to the clipboard could be quietly switched to one belonging to the attacker.[citation needed]
In the area of IoT research, ESET discovered the KrØØk vulnerability (CVE-2019-15126) in Broadcom and Cypress Wi-Fi chips, which allows WPA2-encrypted traffic to be encrypted with an all zero session key following a Wi-Fi disassociation.[49] Then ESET discovered another KrØØk related vulnerability (CVE-2020-3702) in chips by Qualcomm and MediaTek, as well as in the Microsoft Azure Sphere development kit, with the main difference being that the traffic is not encrypted at all.[50]
Other notable research includes the discovery of LoJax, the first UEFI rootkit found in the wild, which was used in a campaign by the Sednit (aka Fancy Bear) APT group. LoJax is written to a system's SPI flash memory from where it is able to survive an OS reinstall and a hard disk replacement. LoJax can drop and execute malware on disk during the boot process.[51] In 2021, ESET discovered another UEFI malware called ESPecter,[52] which is the second real-world bootkit after FinSpy[53] known to persist on the EFI System Partition in the form of a patched Windows Boot Manager.
In 2021, ESET released the white paper Anatomy of native IIS malware,[54] which analyzed over 80 unique samples of malicious native extensions for Internet Information Services (IIS) web server software used in the wild and categorized these into 14 malware families — 10 of which were previously undocumented.
Among these families, IIS malware demonstrated five main modes of operation:
ESET also works alongside experts from competitors and police organizations all over the world to investigate attacks. In 2018, ESET partnered with the European Cybercrime Centre — a specialist Europol team that investigates cybercrime — as a member of its Advisory Group on Internet Security.[55][56] ESET partnered with law enforcement agencies worldwide and Microsoft to target the Dorkbot botnet in 2015 [57] and the Gamarue (aka Andromeda) botnet in 2017.[58] Then in 2020, ESET partnered with Microsoft, Lumen's Black Lotus Labs, and NTT Ltd. in an attempt to disrupt Trickbot, another botnet.[59]
Original source: https://en.wikipedia.org/wiki/ESET.
Read more |