3-2-1, Takeoff. The STARWatch Cloud Security Management Application Has Launched

Compliance, assurance and vendor management are becoming more and more complex and resource-intensive issues, so we created STARWatch, a Software as a Service (SaaS) application designed to provide organizations a centralized way to manage and maintain the integrity of the vendor review and assessment process. Today, we’re excited to announce its official launch. Even more exciting is that we are emerging from Beta with more than 250 active licenses activated.

STARWatch delivers the content of the CSA’s de facto standards Cloud Control Matrix (CCM) and CSA’s Consensus Assessments Initiative Questionnaire v3.0.1 (CAIQ) in a database format, enabling users to manage compliance of cloud services with CSA best practices. It was designed to provide cloud users, providers, auditors and security providers with assurance and compliance on-demand. Additionally, it provides users the ability to:

  • manage all cloud service providers and their own private clouds to assure a consistent security baseline is maintained;
  • build and maintain a CSA Security Trust and Assurance Registry (STAR) entry and provide customers with rapid responses to their compliance questions;
  • perform audits and assessments of cloud services/provider security;
  • have a clear reference between CCM controls and the corresponding controls in other industry standards;
  • leverage the STARWatch solution database format and technical specifications for integration within an organization’s cloud environment; and
  • enabling sharing and peer reviewing of cloud services security assessments.

CSA STARWatch is free to CSA corporate members. Non-members may purchase licenses starting at $3,000 annually for an Expert license and $5,000 annually for Enterprise licenses. Learn more about CSA STARWatch.

STARWatch is part of the larger CSA STAR program, the industry’s most powerful program for security assurance in the cloud, which encompasses the key principles of transparency, rigorous auditing and harmonization of standards, with continuous monitoring. Currently there are 230 Cloud Service Providers in the STAR program, which includes STAR Self-Assessment, STAR Certification, STAR Attestation and C-STAR Assessment.

Daniele Catteddu, Chief Technology Officer, Cloud Security Alliance

[Cloud Security Alliance Blog]

PAN-OS 8.0: Preventing Credential-Based Attacks

Some security breaches are fairly exotic, requiring the use of sophisticated techniques that would make Rube Goldberg proud. These types of efforts require a hundred things to go right in order to succeed and typically require the time, patience and financial backing of an advanced threat actor.

One might think that sophisticated threat actors prefer sophisticated techniques. On the contrary, although a sophisticated adversary may have the capability to pull off a complicated attack, most people are surprised to learn that the majority of breaches still rely on stolen credentials. It is far easier to steal credentials and use them for covert activities than it is to locate a zero-day vulnerability in an external-facing system. And attackers will take the easiest path to achieve their objectives.

Stolen credentials provide many advantages in the attack lifecycle. Effectiveness goes up, and the risk of getting caught goes down. An attacker doesn’t have to spend as much time getting past security countermeasures designed to stop intruders. The attack does not require getting malware into the environment or finding a way to execute it. The adversary simply uses the stolen credentials to take on the appearance of a trusted user, which reduces the risk of getting caught.

There is no shortage of advice on what to do about password risks, but to date most of them have focused on a problem space that bears little resemblance to the targeted attack. The advice to use filtering solutions to stop malicious links to credential phishing sites in email presumes that a security team knows the link is malicious before the user clicks. It also presumes that the link is coming via email. In a targeted credential phishing attack, one cannot assume either to be true, for there are many ways to cloak a site’s true nature, and many ways to get a link to the victim other than email.

The common practice of using multi-factor authentication to address the threat of stolen passwords is a good idea but hard to implement at enterprise scale. In most cases, organizations have a hard time trying to deploy multi-factor authentication across their application landscape. Political issues crop up when the security teams ask the application owners to make changes to their authentication methods. Application owners care about uptime and functionality, and it can be a hard sell to get them to add more security. Technological issues crop up when dealing with the myriad of resources that use passwords, many of which have little support for third-party authentication servers or plugins.

In PAN-OS 8.0, we’re pleased to announce new features that help organizations prevent the attacker’s ability to use stolen credentials. These new capabilities layer into the Next-Generation Security Platform, making it difficult to steal and use credentials in a successful attack. One of the new innovations that we’ve added to the platform is to stop the leakage of credentials to an unauthorized website. This is because in-line inspection of network traffic by the platform makes it possible to implement policies that restrict the sites to which users can submit their corporate credentials. These measures are important, for they act as the safety net to stop credentials from being submitted to credential phishing sites, including sites that have never been seen before.

In addition, the platform goes a step further to disrupt an attacker’s ability to use a set of stolen credentials to access critical applications. Our next-generation firewall enforces multi-factor authentication policy in the network, thus keeping the adversary away from any interaction with the application at all. This is a revolutionary approach to multi-factor authentication, for it strengthens security without having to make direct changes to the application itself, thus making implementation easier without the pain that can derail pervasive enforcement of multi-factor authentication policy.

Both of these key technologies help organizations prevent targeted credential phishing and the use of stolen credentials for lateral movement.

Learn More About Preventing Credential-Based Attacks with Palo Alto Networks

[Palo Alto Networks Research Center]

Announcing PAN-OS 8.0 – Our Biggest Launch Yet!

It’s no secret that attackers and their methods have become more targeted, sophisticated and automated. What follows is an evolution in the needs and demands of security teams to tackle new threats and risks. To address the ever-changing threat landscape and provide organizations with the best security capabilities possible, security vendors must continue to evolve as well.

With that, we are proud to announce PAN-OS 8.0, the largest product and feature release in the history of Palo Alto Networks.

The launch includes more than 70 new security features that enhance all aspects of our Next-Generation Security Platform. We are building upon the existing capabilities of our natively engineered cybersecurity platform to provide organizations with the ability to safely enable applications, content and users regardless of location, prevent successful cyberattacks, simplify security operations, and safely embrace the cloud.

The new capabilities in PAN-OS 8.0 will help customers:

Enable Cloud Adoption

Enhancements support migration to diverse, multi-cloud environments, providing consistent, scalable and advanced security, as well as industry-leading integration with key providers, such as Amazon Web Services and Microsoft Azure, for operational agility and automated scale out. Greater visibility, policy enforcement and actionable dashboards improve security capabilities for SaaS applications, and an expanded lineup of VM-Series virtual firewalls meet a variety of performance needs and use cases.  The new VM-50, VM-500 and VM-700 provide industry-leading performance of up to 16 Gbps for small remote offices to data centers and service provider deployments.

Detect and Prevent Evasive Malware and Credential Theft

PAN-OS 8.0 includes several first-ever innovations focused on advanced threat prevention techniques and the prevention of credential theft and abuse. These include a new 100 percent custom-built anti-evasion analysis environment for WildFire; a heuristic engine to dynamically steer highly evasive threats to a bare metal analysis environment for full hardware execution; a fully automated, payload-based command-and-control signature generation and delivery mechanism; and the new MineMeld application that’s integrated with AutoFocus for automated action driven by correlated threat intelligence.

Prevent the use and abuse of stolen credentials by providing a policy-based multi-factor authentication framework natively in the next-generation firewall. This new and unique capability makes it very easy to enforce multi-factor authentication from the firewall to stop cyber adversaries from moving laterally in a network and accessing sensitive resources with the help of stolen credentials or compromised endpoints. This is achieved by working at the network level in conjunction with authentication and identity management frameworks, such as single sign-on and multi-factor authentication, and integrating with a number of next-generation identity access management vendors, including Ping Identity, Duo Security, and Okta to enforce policies.

Scale With Predictable Performance Across a Variety of Use Cases

Designed to handle increasing throughput needs due to increased SSL-encrypted traffic and data center consolidation, as well as increased traffic at the internet gateway, six new models of appliances: PA-5260, PA5250, PA-5220, PA-850, PA-820 and PA-220 enable advanced security protections for large data centers to smaller environments and branch offices.

Management features that provide administrators fast and accurate insight delivered by Panorama, and include ingestion of Traps (advanced endpoint protection) logs, as well as additional firewall logs to enrich correlation of indicators of compromise and automate actions to update the next-generation firewall with new automated actions to prevent adversary lateral movement and alert IT via IT service management and security response systems, such as ServiceNow, lowering operational burden for security teams.

Below are links to additional resources to learn more about PAN-OS 8.0

[Palo Alto Networks Research Center]

New COBIT 5/CMMI Tool Goes Beyond Traditional Mapping

ISACA and CMMI each have a deep well of expertise and rich sources of guidance and leading models in the areas they cover: ISACA in the world of governance of enterprise IT (GEIT) with COBIT, and CMMI in the world of enterprise process maturity.

Together, we have teamed up to create a new product that leverages the deep guidance available within each of the models. Specifically, COBIT 5 and the CMMI maturity models each have extensive guidance in establishing practices that permit users to better align stakeholder requirements with the utilization of IT-enabled investments; using them both together can yield a resultant value that is greater than the sum of their respective parts.

Many users of framework products look for mapping tools to assist them in using both models or to reduce initial planning and implementation resources needed to bring the second model into use. Mapping tools serve a useful purpose in that regard but have always had one significant drawback: They only attempt to reveal direct connection points between the models being mapped. That serves to speed up implementation time for the second model, but is limiting in the degree to which it unlocks the additional value that using that second model could bring.

The other issue that comes up with traditional mapping tools is that they are designed to be used in one direction only. That is, a user looks up an element in model A and finds which element or elements in model B relate are related. What if you want to start with an element in model B? That element likely exists in multiple places throughout the map and isn’t easy to isolate to determine what in model A is related. These traditional maps are unidirectional.

ISACA and CMMI saw an opportunity in this gap to produce a tool between COBIT 5 and the CMMI maturity model. Called the COBIT 5 CMMI Practices Pathway Tool, users will now be able to quickly and easily navigate from either COBIT 5 or CMMI and uncover relevant guidance in the other model. This bidirectional capability is unique and will permit users greater flexibility in deriving value from the tool.

The tool is built in Excel to provide access to a larger number of people. It takes advantage of native functionality in Excel and uses filtering to provide a quick and easy means of selecting elements of interest. There also is a guidance document with the tool to better describe its function and use.

The end result will be the ability for business IT practitioners to deliver additional value to their stakeholders.

Peter Tessin, Technical Research Manager, ISACA

[ISACA Now Blog]

Traps Named A Visionary in Gartner’s Magic Quadrant for Endpoint Protection Platforms

Gartner has just released its 2017 Magic Quadrant for Endpoint Protection Platforms (EPP), and we’re honored that Palo Alto Networks is named a Visionary in this report. This marks the first year that Palo Alto Networks has been included in the EPP report – we believe this is further proof of Traps’ recognition by top-tier, independent third parties and analysts.

Here are a few highlights from the report that should be of interest to endpoint security professionals:

  1. Gartner’s report cautions customers against overreliance on reactive indicators of compromise. According to Gartner, “With the exception of some of the emerging Visionary vendors, too many EPP solutions’ malware detection techniques remain overly reliant on reactive indicators of compromise (i.e., IP address, URL, file hash, partial hash, registry key values). These static indicators are the easiest part of the kill chain for the attackers to change rapidly.”
  2. The report offers guidance to customers on what endpoint protection capabilities they should assess when evaluating potential solutions. Gartner observes that “Most attacks exploit well-known unpatched vulnerabilities, use social engineering to trick users to install trojan malware, or use interpreted code such as Java or Visual Basic to download and install malware.“
  3. Gartner reflects on the utility of standard testing and the need for improvements in their test by stating that, “Standardized testing, such as AV comparatives and AV tests, are still the best indicators of effectiveness; however, they still overreward reactive solutions and undertest detection of new attacks.”

Our view at Palo Alto Networks is that enterprises will continue to seek more effective endpoint security offerings that can prevent security breaches, whether they are initiated through the exploitation of application vulnerabilities or via new and unknown malware.

I encourage you to read the complete Magic Quadrant report to learn about all of Gartner’s findings.

Gartner Magic Quadrant for Endpoint Protection Platforms, Eric Ouellet, Ian McShane, Avivah Litan, January 2017. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

[Palo Alto Networks Research Center]

English
Exit mobile version