Palo Alto Networks Again Revolutionizes Enterprise Security with the Introduction of Advanced Endpoint Protection Offering

Offers Preventative Approach to Stop Cyber Threats at the Endpoint

Palo Alto Networks Santa Clara, CA , Sep 30, 2014 at 5:00:00 AM
Santa Clara, Calif., September 30, 2014 – Palo Alto Networks® (NYSE: PANW), the leader in enterprise security, today announced the availability of Traps, a revolutionary and unique Advanced Endpoint Protection offering designed to prevent sophisticated cyber attacks on endpoints, sparing IT security teams from cumbersome remediation, patching, and often futile recovery scrambles.

Despite major advances in network security, endpoints remain vulnerable to many advanced attacks, especially as increasingly mobile workforces move outside protected enterprise networks.  Legacy endpoint security products require prior knowledge of a threat in order to prevent it, or worse, use an approach that only identifies a new threat after it has compromised the endpoint.

This reactive model results in a never-ending chase after the thousands of new malware attacks that emerge each day, as well as the expanding number of software vulnerabilities that can be used to exploit an endpoint.  These approaches offer little hope or possibility of recovering data that has already been hijacked by an attacker.  Putting an end to the reactive run around, Traps proactively prevents attacks on the endpoint, including unknown malware and zero-day exploits, before they do any damage.

QUOTES

  • “The key differentiator with Traps is its ability to automate the process of protecting the endpoint. Most of the products in the industry today largely deal with informing us that there’s a problem and little more; that leaves us to manually deal with the effort of remediating the endpoint, takes time and leaves us vulnerable.  With Traps, that is done automatically and it is done nearly instantaneously, which is a major win.”

— Golan Ben-Oni, CSO and SVP Network Architecture, IDT

  • “The proven effectiveness of the Traps endpoint capability over other heuristic and signature-based approaches, together with Palo Alto Networks WildFire and next-generation firewall, makes the secure enablement of our entire business possible.”

— Dr. Andres Rohr of RWE Supply & Trading

  • “With the introduction of Traps, we are redefining the endpoint security market much like we did the network security market with our next-generation firewall.  Traps and our platform as a whole are designed to revolutionize enterprise security by putting prevention front and center, closing the door on cyber threats before they can get in and cause damage.”

— Lee Klarich, senior vice president of Product Management at Palo Alto Networks

Since the acquisition of Cyvera and the technology behind Traps, Palo Alto Networks has expanded global support and services operations to meet enterprise customer needs, and completed several key enhancements, including:

  • Integration with Palo Alto Networks WildFire – Traps blocks malware by leveraging the full knowledge of Palo Alto Networks Threat Intelligence Cloud;
  • Added exploitation and malware prevention modules – extends Traps support to include the latest attack techniques; and
  • Enhanced forensics – provides a rich set of reporting for better visibility and understanding of attacks that were prevented.

Natively Integrated Platform Extends Protection Enterprise-wide

The integration of Traps with the Palo Alto Networks Threat Intelligence Cloud brings security of the network and endpoint together under a single common architecture, known as the Palo Alto Networksenterprise security platform, and delivers unparalleled enterprise-wide security and automated threat prevention capabilities, reducing risk across an organization at every stage in the attack kill chain.  It also eliminates management complexity and myopic point product-related security silos that can leave gaping holes in an organization’s security posture.

Availability 

Traps Advanced Endpoint Protection, offered as a subscription service, is available now from authorized Palo Alto Networks channel partners.  The offering is inclusive of all functionality including exploit prevention, malware prevention through WildFire integration, forensics, and premium support.

To learn more about Traps Advanced Endpoint Protection from Palo Alto Networks, visit:

About Palo Alto Networks

Palo Alto Networks is leading a new era in cybersecurity by protecting thousands of enterprise, government, and service provider networks from cyber threats.  Unlike fragmented legacy products, our security platform safely enables business operations and delivers protection based on what matters most in today’s dynamic computing environments: applications, users, and content.  Find out more atwww.paloaltonetworks.com.

Palo Alto Networks and the Palo Alto Networks Logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.

Media Contacts:
Jennifer Jasper Smith
Head of Corporate Communications
Palo Alto Networks
408-638-3280
jjsmith@paloaltonetworks.com

Bob Nelson
Voce Communications
408-201-2402
bnelson@vocecomm.com

The Time Has Come: Advanced Endpoint Protection is Here!

POSTED BY: on September 30, 2014 5:15 AM

FILED IN: Announcement, Cybersecurity, Endpoint, Mobility
TAGGED: ,

It’s not often a company has an opportunity to disrupt an entire industry…. twice.  When we introduced the first next-generation firewall back in 2007 we set out on a path to redefine the network security market.  Today, over 19,000 organizations rely on Palo Alto Networks to protect their networks against the most sophisticated, targeted attacks.

We take our responsibility to those organizations very seriously, and today we’re announcing an important next step: Advanced Endpoint Protection.  If we’ve learned anything from the recent round of breaches, it’s that endpoints remain highly vulnerable to attacks.  Even the most advanced network security architectures can’t protect against every threat vector.  And legacy endpoint security approaches that rely on prior knowledge of the threat, or active scanning, are simply ill equipped to protect organizations from this new era of attacks.

Today marks the official launch of Traps, an Advanced Endpoint Protection solution that truly tears the covers off traditional approaches and exposes them for what they are: misguided attempts at addressing a very real problem.  This isn’t just a product launch. This is the beginning of a new market: a market defined by its ability to turn the tides and rebuild lost confidence, and a market grounded on the principle that attacks can be prevented.

This new Advanced Endpoint Protection market will be defined by solutions that can deliver on the following:

  • Must be able to prevent all exploits, including those utilizing unknown zero-day vulnerabilities
  • Must be able to prevent all malware, without requiring any prior knowledge
  • Must provide detailed forensics against prevented attacks to strengthen all areas of the organization by pinpointing the target and techniques used
  • Must be highly scalable and lightweight to seamlessly integrate into existing operations with minimal to no disruption
  • Must integrate closely with network and cloud security for quick data exchange and cross-organization protection

Carry this list in your back pocket.  As you consider the different approaches to endpoint security we hope you evaluate the underlying technology against these five criteria.  And of course we hope you take the time to evaluate Traps and see for yourself how we’ve delivered not only one of the most advanced approaches in the market, but also one that integrates natively into our Enterprise Security Platform.

 

[Source: Palo Alto Networks]

ISACA International President: Ongoing Diligence is Key to Address Vulnerabilities Such as the One in Bash

Diligence may not be the most exciting items on our to-do lists, but it is a time-honored practice and should be a staple. This thought rises to the top as we read news reports about the security vulnerability in the Bourne Again Shell (Bash), which is now being referred to by many as Shellshock.

Some experts counsel that the impact of this vulnerability will only be moderate and that patches will be applied appropriately. At the same time, the potential severity of this vulnerability is high—it could allow hackers to take control of affected systems, thus allowing unauthorized disclosure of information, unauthorized modification and disruption. In addition, its severity is ranked as 10, while its complexity is considered low, which might not make it a “perfect” storm but at least a “close-to-perfect” storm.

I think we all agree that our future will contain many more vulnerabilities, bugs and other incidents with varying repercussions. Human error, changing times and needs, updates to technology and the ever-present desire in some people to cause havoc will ensure that we are all kept on our toes. A combination of planning, reviewing, monitoring and ongoing diligence is needed so we can be both proactive and prepared for rapid response when needed.

Diligence includes frequently reinforcing that processes and techniques must be in place to ensure that systems are appropriately patched and upgraded. This needs to be extended to the supply chain, including vendors and partners. We need to monitor complex interconnected environments to ensure that devices in manufacturing lines and elsewhere are maintained. Penetration testing is critical and should be regularly undertaken to ensure entry points to the organization are secure and monitored. Security awareness programs should be reviewed to ensure they are thorough, updated and—even more important—exist.

The fact remains that we will never be able to entirely prevent cyber incidents. The only secure machine is the one in the box not yet connected to a network. And even then it is subject to physical theft. If steps aren’t taken, though, the impact is potentially catastrophic—harm to people, compromised systems, lost data/intellectual property/revenue and perhaps even an end to the business. This is one reason ISACA offers the Cybersecurity Nexus (CSX), which provides cybersecurity guidance, career development, education and community for professionals at every stage of their careers.

There was a time, not that many years ago, that security was not a primary issue. Many programs and systems were vulnerable to hacking, and it was still assumed that they were still safe. We now know better.

Robert E Stroud, CGEIT, CRISC
International President of ISACA

[Source: ISACA]

ISACA: Investing in Privacy Training

Ever since Snowden made his first revelations over a year ago, ‘privacy’ has become a bit of a buzzword. Once the prerogative of royals and stars (whose computers and online accounts continue to be among hackers’ favourite targets) in the information age the average consumer struggles to reconcile the benefits of personalised services and tailored advertising with the apprehension of not knowing what personal information about them is held by whom, where it is stored, and how it is used. Forrester calls this the ‘privacy-personalisation paradox’.

Equally, companies and public bodies face a difficult challenge: to paraphrase Voltaire, with big data must come big responsibilities. Get privacy right, and you have gained a competitive advantage. Get it wrong and—well, you’re in trouble. Target’s former CEO and its board of directors know this well. At stake: financial and reputational damages.

Add to the picture the fact that one of the global pillars of privacy legislation, the European Union’s Data Protection Directive 1995, is currently undergoing a substantial overhaul, and recent developments such as the May ruling of the Court of Justice of the EU on the so-called ‘right to be forgotten’, and the scenario becomes even more complicated.

So where to start? Many companies have appointed chief privacy officers (CPOs)—in Europe, data protection officers (DPOs)—whose focus is solely on privacy and data protection. In 2006, Harriet Pearson, then-CPO for IBM, said: ‘A good CPO must do more than just ensure that companies comply with the present-day law. They must also attempt to second-guess future innovation and design company security policies and procedures accordingly’.

Her words are still very contemporary and, as technology and innovation have evolved over the past eight years, so has the role of CPOs and DPOs, who went from almost invisible magicians behind the curtains of compliance to highly sophisticated professionals whose function has consistently been climbing up corporate hierarchies.

In Europe, the current draft of the General Data Protection Regulation, which will replace the outdated 1995 Data Protection Directive, requires the mandatory appointment of DPOs for public-sector entities processing personal data and for private-sector enterprises processing the data of more than 5,000 data subjects in a year. By the way, you may be interested to know that the draft Regulation also introduces fines of up to 1million euro or 2 percent of a company’s global annual turnover, and stipulates that personal data breaches should be notified ‘without undue delay’ to the relevant supervisory authority and, if the breach ‘is likely to adversely affect’ them, also to the data subjects.

Mind you, the Regulation is not yet law, and its text is likely to undergo some changes before it is finalised, but European leaders have made no secret of their intention to make the data protection rights of their citizens a top priority.

Now, if the major data breaches that dominated the headlines in the past years have taught us anything, it is that you can have the best policies and the tightest security measures in place, but nothing can be done against human error. Or can it?

The UK Information Commissioner’s Office released some statistics on data breaches in August 2013 and the data is unequivocal: ‘More than half of the 335 data breach incidents we looked at in the first quarter [of 2013] fall into the ‘disclosed in error’ category’, read an ICO blog post. ‘That covers everything from emails being sent to the wrong people to information erroneously included in freedom of information responses, but invariably they can be described as careless’.

Let’s face it: at any point in time, in any given organisation or public office, data is processed (accessed, shared, managed and transformed) by hundreds or even thousands of employees. These employees can be sitting in any department, and at any point in their career: they can be product developers designing a new product, sales and marketing managers trying to sell it, or human resources professionals handling employee data.

Clearly, the need for privacy training and awareness extends beyond the ‘core’ privacy team (the office of the CPO or DPO) to the entire office or corporation. Investing in privacy training for employees is a fundamental component when managing the risks associated to our data-driven economy. Marketing professionals look at privacy training and awareness through the lens of transparency: ensuring openness and customer control of their own data. Information security professionals, CTOs and CIOs know too well what a difference a robust data governance strategy that aligns security and privacy can make.

Any employee touching data in a significant way poses a risk; yet your biggest assets are your employees. How can you afford not to invest in privacy training?

Rita Di Antonio
Managing Director IAPP Europe

Rita will discuss this concept at ISACA’s European Computer Audit, Control and Security (EuroCACS/ISRM) Conference this September, in her presentation titled, “EU Privacy: Past, Present and Future.”

[Source: ISACA]

The Open Group Architecture Framework (TOGAF®) – Vietnamese Walk of Fame

4

Last Updated: 30-APR-2017

All statistics are based upon personal verification. Please use it at your own risk for reference only. Total number may be different from public list of The Open Group since it includes active, inactive, and suspended & also certification holders who are both local & overseas Vietnamese. If you are a Vietnamese (local & overseas) TOGAF and your name is not in this list, or you claim for wrong information, pls help to contact me. Thank you so much.

Avatar ID Name & Contact Date Certified
#TOGAF-8 NGUYEN ANH DUNG – NGUYỄN ANH DŨNG
Current: IT Specialist at IBM Vietnam (Hanoi, Vietnam)
contact info
27-MAY-2009
#TOGAF-9.1 NGUYEN TIEN DUONG – NGUYỄN TIẾN DƯƠNG
Current:
contact info
MAY-2012
#TOGAF-9.1 NGUYEN MANH CUONG – NGUYỄN MẠNH CƯỜNG
Current: Managed Service Division Director at FPT Information System Services (Hanoi, Vietnam)
03-OCT-2012
#TOGAF-9.1 #108552 NGUYEN TRONG CONG – NGUYỄN TRỌNG CÔNG
Current: Network Security Consultant at FPT Information System Services (Hanoi, Vietnam)
contact info
2016

©2014-2017 Philip Cao. All rights reserved. Please specify source when you copy or quote information from this website (Xin vui lòng trích dẫn nguồn khi bạn sao chép hay sử dụng lại thông tin từ website).

Global Privacy Concerns about the Internet of Things

I have been looking into the privacy risks of the Internet of Things (IoT) for the past few years. I initially became interested through my work with National Institute of Standards and Technology (NIST) while researching the privacy risks of the smart grid and leading the group responsible for NISTIR 7628 Volume 2, and then a new version two years later in NISTIR 7628 Volume 2 Revision 1. Looking into smart meters led to my personal research of looking into smart appliances and then wearables.

For the past year, I have been working with a large medical devices group (and spoke at its conference) to identify the information security and privacy risks that are created by new and emerging medical devices, many of which are “smart” devices, generally meaning they are also part of the IoT. Smart medical devices can bring significant benefits to the associated patients, such as automatically applying medication based upon health readings, or sending alerts to a physician or hospital in the event of a medical emergency. However, they also create privacy risks when inappropriate entities get access to the data and use it for malicious actions. For instance, health insurance companies that use the medical device data as a basis to increase insurance premiums or cancel health insurance coverage; or those with ill intent accessing the medical device to do physical harm to the associated individual.

I also gave a keynote at an international conference in Bogotá, Colombia, about IoT and associated risks. And, I will be speaking on this topic again at a conference in Melbourne, Australia, in October. Privacy and information security of IoT truly is a hot topic around the world. And it is with good reason. Here is just one real-life example of how weak controls within smart devices were exploited and resulted in privacy and/or information security harm:

  • TRENDnet told customers that its web-enabled wireless home security and baby monitoring cameras were secure. However, starting in January 2012 a hacker exploited the lack of security controls in the devices and sent livestream images to multiple Internet sites showing the images and sounds of people and their activities from the rooms where they were used. TRENDnet agreed to a sanction consisting of a 20-year consent decree to implement a comprehensive security and privacy program, and be subject to ongoing audits from the Federal Trade Commission (FTC).

A recent 2014 HP Security Research study determined 70% of these smart IoT connected devices are vulnerable to attack. Why? Three common culprits include: 1) insecure Web interfaces, 2) insufficient software protections and 3) lack of encryption.

Resulting high-level risks (as described within NIST’s draft Privacy Engineering Workshop papers) from these vulnerable IoT devices include:

  • Personal information may be used in ways that exceed the associated individual’s expectation or authorization.
  • The use or dissemination of inaccurate or misleadingly incomplete personal information can lead to breaches or inappropriate actions.
  • Loss of autonomy of the associated individuals through induced disclosure of data from the devices
  • Loss of trust, as well as exposing individuals to economic loss, and stigmatization
  • Tracking or monitoring of personal information that is disproportionate to the purpose of the device
  • Exposure of the associated individual in unexpected way, stigmatization, power imbalance and loss of trust and autonomy
  • Denial of access to the device leading to exclusion, economic loss, loss of trust, or physical harm
  • Inappropriate access leading to changes in device settings, changes to the device data, or misuse of the data, leading to physical harm to the associated individual

While doing research and visiting with others to discuss IoT issues, I have had interesting conversations with many bright and insightful folks. Here are some important recurring points made during these experiences, with which most agree:

  • Current information security and privacy controls are not sufficient for most IoT devices.
  • IoT devices typically collect, share and process data automatically, more often with no human intervention. This makes it essential for the engineers creating the devices to have a good understanding of the related information security and privacy risks, and how to build the devices to appropriately mitigate the risks.
  • We cannot wait for laws or regulations to be created to govern the privacy and security of IoT devices. We must be proactive and establish such controls now, based on our own expertise and cooperative research. This will ensure that the billions of devices that will soon be put into use will not create a security and privacy disaster.

I am encouraged by NIST’s initiative to create privacy engineering standards, and ISACA’s support and participation in that initiative. The goal is to provide privacy engineers with standards to use to build controls into IoT devices—hopefully in the not so distant future. I believe ISACA will play a key role in getting those standards created and communicated and will provide guidance on how to use them for ISACA members worldwide.

If you would like to learn more, please view the video of the April NIST Privacy Engineering Workshop session where I represented ISACA: http://cdnapi.kaltura.com/index.php/extwidget/openGraph/wid/0_eac0g2ra.

Rebecca Herold, CISA, CISM, CISSP, CIPP, FLMI
Owner & CEO, Rebecca Herold & Associates

[Source: ISACA]

English
Exit mobile version