PAN-OS 8.0: Preventing Credential-Based Attacks

Some security breaches are fairly exotic, requiring the use of sophisticated techniques that would make Rube Goldberg proud. These types of efforts require a hundred things to go right in order to succeed and typically require the time, patience and financial backing of an advanced threat actor.

One might think that sophisticated threat actors prefer sophisticated techniques. On the contrary, although a sophisticated adversary may have the capability to pull off a complicated attack, most people are surprised to learn that the majority of breaches still rely on stolen credentials. It is far easier to steal credentials and use them for covert activities than it is to locate a zero-day vulnerability in an external-facing system. And attackers will take the easiest path to achieve their objectives.

Stolen credentials provide many advantages in the attack lifecycle. Effectiveness goes up, and the risk of getting caught goes down. An attacker doesn’t have to spend as much time getting past security countermeasures designed to stop intruders. The attack does not require getting malware into the environment or finding a way to execute it. The adversary simply uses the stolen credentials to take on the appearance of a trusted user, which reduces the risk of getting caught.

There is no shortage of advice on what to do about password risks, but to date most of them have focused on a problem space that bears little resemblance to the targeted attack. The advice to use filtering solutions to stop malicious links to credential phishing sites in email presumes that a security team knows the link is malicious before the user clicks. It also presumes that the link is coming via email. In a targeted credential phishing attack, one cannot assume either to be true, for there are many ways to cloak a site’s true nature, and many ways to get a link to the victim other than email.

The common practice of using multi-factor authentication to address the threat of stolen passwords is a good idea but hard to implement at enterprise scale. In most cases, organizations have a hard time trying to deploy multi-factor authentication across their application landscape. Political issues crop up when the security teams ask the application owners to make changes to their authentication methods. Application owners care about uptime and functionality, and it can be a hard sell to get them to add more security. Technological issues crop up when dealing with the myriad of resources that use passwords, many of which have little support for third-party authentication servers or plugins.

In PAN-OS 8.0, we’re pleased to announce new features that help organizations prevent the attacker’s ability to use stolen credentials. These new capabilities layer into the Next-Generation Security Platform, making it difficult to steal and use credentials in a successful attack. One of the new innovations that we’ve added to the platform is to stop the leakage of credentials to an unauthorized website. This is because in-line inspection of network traffic by the platform makes it possible to implement policies that restrict the sites to which users can submit their corporate credentials. These measures are important, for they act as the safety net to stop credentials from being submitted to credential phishing sites, including sites that have never been seen before.

In addition, the platform goes a step further to disrupt an attacker’s ability to use a set of stolen credentials to access critical applications. Our next-generation firewall enforces multi-factor authentication policy in the network, thus keeping the adversary away from any interaction with the application at all. This is a revolutionary approach to multi-factor authentication, for it strengthens security without having to make direct changes to the application itself, thus making implementation easier without the pain that can derail pervasive enforcement of multi-factor authentication policy.

Both of these key technologies help organizations prevent targeted credential phishing and the use of stolen credentials for lateral movement.

Learn More About Preventing Credential-Based Attacks with Palo Alto Networks

[Palo Alto Networks Research Center]

Announcing PAN-OS 8.0 – Our Biggest Launch Yet!

It’s no secret that attackers and their methods have become more targeted, sophisticated and automated. What follows is an evolution in the needs and demands of security teams to tackle new threats and risks. To address the ever-changing threat landscape and provide organizations with the best security capabilities possible, security vendors must continue to evolve as well.

With that, we are proud to announce PAN-OS 8.0, the largest product and feature release in the history of Palo Alto Networks.

The launch includes more than 70 new security features that enhance all aspects of our Next-Generation Security Platform. We are building upon the existing capabilities of our natively engineered cybersecurity platform to provide organizations with the ability to safely enable applications, content and users regardless of location, prevent successful cyberattacks, simplify security operations, and safely embrace the cloud.

The new capabilities in PAN-OS 8.0 will help customers:

Enable Cloud Adoption

Enhancements support migration to diverse, multi-cloud environments, providing consistent, scalable and advanced security, as well as industry-leading integration with key providers, such as Amazon Web Services and Microsoft Azure, for operational agility and automated scale out. Greater visibility, policy enforcement and actionable dashboards improve security capabilities for SaaS applications, and an expanded lineup of VM-Series virtual firewalls meet a variety of performance needs and use cases.  The new VM-50, VM-500 and VM-700 provide industry-leading performance of up to 16 Gbps for small remote offices to data centers and service provider deployments.

Detect and Prevent Evasive Malware and Credential Theft

PAN-OS 8.0 includes several first-ever innovations focused on advanced threat prevention techniques and the prevention of credential theft and abuse. These include a new 100 percent custom-built anti-evasion analysis environment for WildFire; a heuristic engine to dynamically steer highly evasive threats to a bare metal analysis environment for full hardware execution; a fully automated, payload-based command-and-control signature generation and delivery mechanism; and the new MineMeld application that’s integrated with AutoFocus for automated action driven by correlated threat intelligence.

Prevent the use and abuse of stolen credentials by providing a policy-based multi-factor authentication framework natively in the next-generation firewall. This new and unique capability makes it very easy to enforce multi-factor authentication from the firewall to stop cyber adversaries from moving laterally in a network and accessing sensitive resources with the help of stolen credentials or compromised endpoints. This is achieved by working at the network level in conjunction with authentication and identity management frameworks, such as single sign-on and multi-factor authentication, and integrating with a number of next-generation identity access management vendors, including Ping Identity, Duo Security, and Okta to enforce policies.

Scale With Predictable Performance Across a Variety of Use Cases

Designed to handle increasing throughput needs due to increased SSL-encrypted traffic and data center consolidation, as well as increased traffic at the internet gateway, six new models of appliances: PA-5260, PA5250, PA-5220, PA-850, PA-820 and PA-220 enable advanced security protections for large data centers to smaller environments and branch offices.

Management features that provide administrators fast and accurate insight delivered by Panorama, and include ingestion of Traps (advanced endpoint protection) logs, as well as additional firewall logs to enrich correlation of indicators of compromise and automate actions to update the next-generation firewall with new automated actions to prevent adversary lateral movement and alert IT via IT service management and security response systems, such as ServiceNow, lowering operational burden for security teams.

Below are links to additional resources to learn more about PAN-OS 8.0

[Palo Alto Networks Research Center]

English
Exit mobile version