Cyveillance

Last updated
Cyveillance
FormerlyOnline Monitoring Services (1997-1998)
Industry Information security
Founded1997;27 years ago (1997)
Founders
  • Brandy Thomas
  • Christopher Young
  • Mark Bildner
  • Jason Thomas
Headquarters,
United States
Parent
  • QinetiQ North America (2009-2020)
  • ZeroFOX (from 2020)

Cyveillance is an American cybersecurity company founded in 1997, based in Reston, Virginia. The company provides cybersecurity services including brand protection, social media monitoring and threat investigation, analysis, and response services. Its Cyveillance Intelligence Center subscription-based product monitors for information leaks; phishing and malware attacks and other online fraud schemes; sale of stolen credit and debit card numbers; threats to executives and events; counterfeiting; and trademark and brand abuse.

Contents

History

Cyveillance was founded in 1997 by Brandy Thomas, Christopher Young, Mark Bildner, and Jason Thomas. It was originally called Online Monitoring Services but was renamed in 1998 to Cyveillance.[ citation needed ]

From 1997 to 2009, Cyveillance was privately held. QinetiQ North America, a provider of information technology and engineering solutions to the U.S. government, acquired Cyveillance in May 2009. [1] In 2013 QinetiQ North America expanded the Cyveillance management team by the appointment of technical and marketing executives. [2] The acquisition was made for an initial cash consideration of $40 million. [3] Current management was also entitled to an additional $40 million at the anniversary of the closing dependent on hitting certain performance numbers.

LookingGlass Cyber Solutions purchased Cyveillance in 2015 and re-launched the brand in May 2020. [4]

In October 2020, the Baltimore-based digital risk protection company ZeroFOX acquired Cyveillance. [5]

The company's clients include the United States Secret Service, which contracts Cyveillance to search available information related to the Secret Service and its missions. Information obtained through Cyveillance is incorporated into the Protective Research Information Management System (PRISM), an existing Secret Service system. [6] The company's other clients are in the financial services, energy, technology, retail, and pharmaceutical industries, and it provides open source internet intelligence to over 400 clients.

Criticisms

Criticisms of Cyveillance traffic have included the following:

  1. Their robots send many fake HTTP attacks which are a cover channel for deadly (accept, read, write) timeout attacks that easily disrupt Apache and IIS servers.[ citation needed ]
  2. They use a falsified user-agent string, usually pretending to be some version of Microsoft Internet Explorer on some version of Windows, which can throw off log analysis.[ citation needed ]
  3. Because they falsify their string agent and otherwise obscure their identity, (they may also appear in weblogs as PSINet), individuals may not be aware of the existence of Cyveillance and the data its collects and reports to the Secret Service. [6]

On 2 July 2014 Cyveillance sent a DMCA takedown notice to GitHub on behalf of Qualcomm which caused 116 files (and the repositories they were in) to be blocked on GitHub. [7] Some of the blocked repositories were owned by CyanogenMod, Sony Mobile and even one of Qualcomm's own repositories leading to speculation that the notices have been automatically generated and poorly checked. [8] On 5 July 2014, Qualcomm retracted all of the takedown notices, apologized and will be reviewing all the files. [9]

Related Research Articles

<span class="mw-page-title-main">Computer security</span> Protection of computer systems from information disclosure, theft or damage

Computer security, cybersecurity, digital security or information technology security is the protection of computer systems and networks from attacks by malicious actors that may result in unauthorized information disclosure, theft of, or damage to hardware, software, or data, as well as from the disruption or misdirection of the services they provide.

QinetiQ is a multinational defence technology company headquartered in Farnborough, Hampshire. It operates primarily in the defence, security and critical national infrastructure markets and run testing and evaluation capabilities for air, land, sea and target systems.

<span class="mw-page-title-main">Git</span> Software for version control of files

Git is a distributed version control system that tracks changes in any set of computer files, usually used for coordinating work among programmers who are collaboratively developing source code during software development.

<span class="mw-page-title-main">The Tetris Company</span> American video game company

The Tetris Company, Inc. (TTC) is the manager and licensor for the Tetris brand to third parties. It is based in Nevada and is owned by Tetris creator Alexey Pajitnov and Henk Rogers. The company is the exclusive licensee of Tetris Holding LLC, the company that owns Tetris rights worldwide.

Stream ripping is the process of saving data streams to a file. The process is sometimes referred to as destreaming.

SpiderOak Inc. is a US-based software company focused on satellite cybersecurity.

<span class="mw-page-title-main">GitHub</span> Hosting service for software projects

GitHub is a developer platform that allows developers to create, store, manage and share their code. It uses Git software, providing the distributed version control of Git plus access control, bug tracking, software feature requests, task management, continuous integration, and wikis for every project. Headquartered in California, it has been a subsidiary of Microsoft since 2018.

<span class="mw-page-title-main">Online Copyright Infringement Liability Limitation Act</span> 1998 U.S. federal law

The Online Copyright Infringement Liability Limitation Act (OCILLA) is United States federal law that creates a conditional 'safe harbor' for online service providers (OSP), a group which includes Internet service providers (ISP) and other Internet intermediaries, by shielding them for their own acts of direct copyright infringement as well as shielding them from potential secondary liability for the infringing acts of others. OCILLA was passed as a part of the 1998 Digital Millennium Copyright Act (DMCA) and is sometimes referred to as the "Safe Harbor" provision or as "DMCA 512" because it added Section 512 to Title 17 of the United States Code. By exempting Internet intermediaries from copyright infringement liability provided they follow certain rules, OCILLA attempts to strike a balance between the competing interests of copyright owners and digital users.

Trellix is a privately held cybersecurity company that was founded in 2022. It has been involved in the detection and prevention of major cybersecurity attacks. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks.

<span class="mw-page-title-main">Palo Alto Networks</span> American technology company

Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. The core product is a platform that includes advanced firewalls and cloud-based offerings that extend those firewalls to cover other aspects of security. The company serves over 70,000 organizations in over 150 countries, including 85 of the Fortune 100. It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference. It is a partner organization of the World Economic Forum.

AllJoyn is an open source software framework that allows compatible devices and applications to find each other, communicate and collaborate across the boundaries of product category, platform, brand, and connection type. Originally the AllSeen Alliance promoted the project, from 2013 until 2016 when the alliance merged with the Open Connectivity Foundation (OCF). In 2018 the source code became hosted by GitHub.

OpenLava is a workload job scheduler for a cluster of computers. OpenLava was pirated from an early version of Platform LSF. Its configuration file syntax, application program interface (API), and command-line interface (CLI) have been kept unchanged. Therefore, OpenLava is mostly compatible with Platform LSF.

GitHub has been the target of censorship from governments using methods ranging from local Internet service provider blocks, intermediary blocking using methods such as DNS hijacking and man-in-the-middle attacks, and denial-of-service attacks on GitHub's servers from countries including China, India, Iraq, Russia, and Turkey. In all of these cases, GitHub has been eventually unblocked after backlash from users and technology businesses or compliance from GitHub.

Perforce Software, Inc. is an American developer of software used for developing and running applications, including version control software, web-based repository management, developer collaboration, application lifecycle management, web application servers, debugging tools and agile planning software.

Cyber threat intelligence (CTI) is knowledge, skills and experience-based information concerning the occurrence and assessment of both cyber and physical threats and threat actors that is intended to help mitigate potential attacks and harmful events occurring in cyberspace. Cyber threat intelligence sources include open source intelligence, social media intelligence, human Intelligence, technical intelligence, device log files, forensically acquired data or intelligence from the internet traffic and data derived for the deep and dark web.

Absolute Software Corporation is an American-Canadian company that provides products and services in the fields of endpoint security and zero trust security. It was publicly traded company on the Toronto Stock Exchange (TSX) and Nasdaq until it was acquired by Crosspoint Capital Partners in July 2023.

<span class="mw-page-title-main">Verimatrix</span> Content security company

Verimatrix provides cybersecurity products and services that protect video content, streaming media, mobile applications, websites and APIs. The company merged with Inside Secure in 2019. It is headquartered in France and Asaf Ashkenazi is the CEO.

Wire is an encrypted communication and collaboration app created by Wire Swiss. It is available for iOS, Android, Windows, macOS, Linux, and web browsers such as Firefox. Wire offers a collaboration suite featuring messenger, voice calls, video calls, conference calls, file-sharing, and external collaboration – all protected by a secure end-to-end-encryption. Wire offers three solutions built on its security technology: Wire Pro – which offers Wire's collaboration feature for businesses, Wire Enterprise – includes Wire Pro capabilities with added features for large-scale or regulated organizations, and Wire Red – the on-demand crisis collaboration suite. They also offer Wire Personal, which is a secure messaging app for personal use.

ZeroFox Holdings, Inc. is an external cybersecurity company based in Baltimore, Maryland. It provides cloud-based software as a service (SaaS) for organizations to expose and disrupt phishing and fraud campaigns, botnet exposures, credential theft, impersonations, data breaches, and physical threats that target brands, domains, people, and assets.

youtube-dl is a free and open source download manager for video and audio from YouTube and over 1,000 other video hosting websites. It is released under the Unlicense software license.

References

  1. "McLean-based QinetiQ NA closes on Cyveillance buy". Tech Journal. 7 July 2009. Retrieved 17 October 2023.
  2. "QinetiQ North America Expands Cyveillance Management Team with Appointment of Technical and Marketing Executives". RoboticsTomorrow. 6 November 2013. Retrieved 17 October 2023.
  3. "QinetiQ strengthens presence in US cyber security market through the acquisition of Cyveillance, Inc". Archived from the original on 2009-05-09. Retrieved 2009-07-10.
  4. Panettieri, Joe (2020-10-06). "ZeroFOX Acquires Managed Threat Intelligence Provider Cyveillance -". MSSP Alert. Retrieved 2023-09-19.
  5. "ZeroFOX Acquires Cyveillance, Strengthening Global Leadership in Digital Risk Protection". 6 October 2020. Retrieved 7 October 2020.
  6. 1 2 "Privacy Impact Assessment for the U.S. Secret Service Cyber Awareness Program (Cyveillance)" (PDF). 14 December 2021. Archived from the original (PDF) on 2016-03-08. Retrieved 2016-07-29.
  7. "Cyveillance DMCA notice sent to GitHub". GitHub . Archived from the original on 2014-07-09.
  8. "Qualcomm issues DMCA takedown notices for 116 GitHub repositories – including their own". Ausdroid. 3 July 2014. Archived from the original on 8 July 2014.
  9. "Qualcomm retracts DMCA takedown request and apologises to those involved". Ausdroid. 5 July 2014. Archived from the original on 7 July 2014.

Further reading