PAN-OS 8.0: Preventing Credential-Based Attacks

Some security breaches are fairly exotic, requiring the use of sophisticated techniques that would make Rube Goldberg proud. These types of efforts require a hundred things to go right in order to succeed and typically require the time, patience and financial backing of an advanced threat actor.

One might think that sophisticated threat actors prefer sophisticated techniques. On the contrary, although a sophisticated adversary may have the capability to pull off a complicated attack, most people are surprised to learn that the majority of breaches still rely on stolen credentials. It is far easier to steal credentials and use them for covert activities than it is to locate a zero-day vulnerability in an external-facing system. And attackers will take the easiest path to achieve their objectives.

Stolen credentials provide many advantages in the attack lifecycle. Effectiveness goes up, and the risk of getting caught goes down. An attacker doesn’t have to spend as much time getting past security countermeasures designed to stop intruders. The attack does not require getting malware into the environment or finding a way to execute it. The adversary simply uses the stolen credentials to take on the appearance of a trusted user, which reduces the risk of getting caught.

There is no shortage of advice on what to do about password risks, but to date most of them have focused on a problem space that bears little resemblance to the targeted attack. The advice to use filtering solutions to stop malicious links to credential phishing sites in email presumes that a security team knows the link is malicious before the user clicks. It also presumes that the link is coming via email. In a targeted credential phishing attack, one cannot assume either to be true, for there are many ways to cloak a site’s true nature, and many ways to get a link to the victim other than email.

The common practice of using multi-factor authentication to address the threat of stolen passwords is a good idea but hard to implement at enterprise scale. In most cases, organizations have a hard time trying to deploy multi-factor authentication across their application landscape. Political issues crop up when the security teams ask the application owners to make changes to their authentication methods. Application owners care about uptime and functionality, and it can be a hard sell to get them to add more security. Technological issues crop up when dealing with the myriad of resources that use passwords, many of which have little support for third-party authentication servers or plugins.

In PAN-OS 8.0, we’re pleased to announce new features that help organizations prevent the attacker’s ability to use stolen credentials. These new capabilities layer into the Next-Generation Security Platform, making it difficult to steal and use credentials in a successful attack. One of the new innovations that we’ve added to the platform is to stop the leakage of credentials to an unauthorized website. This is because in-line inspection of network traffic by the platform makes it possible to implement policies that restrict the sites to which users can submit their corporate credentials. These measures are important, for they act as the safety net to stop credentials from being submitted to credential phishing sites, including sites that have never been seen before.

In addition, the platform goes a step further to disrupt an attacker’s ability to use a set of stolen credentials to access critical applications. Our next-generation firewall enforces multi-factor authentication policy in the network, thus keeping the adversary away from any interaction with the application at all. This is a revolutionary approach to multi-factor authentication, for it strengthens security without having to make direct changes to the application itself, thus making implementation easier without the pain that can derail pervasive enforcement of multi-factor authentication policy.

Both of these key technologies help organizations prevent targeted credential phishing and the use of stolen credentials for lateral movement.

Learn More About Preventing Credential-Based Attacks with Palo Alto Networks

[Palo Alto Networks Research Center]

Announcing PAN-OS 8.0 – Our Biggest Launch Yet!

It’s no secret that attackers and their methods have become more targeted, sophisticated and automated. What follows is an evolution in the needs and demands of security teams to tackle new threats and risks. To address the ever-changing threat landscape and provide organizations with the best security capabilities possible, security vendors must continue to evolve as well.

With that, we are proud to announce PAN-OS 8.0, the largest product and feature release in the history of Palo Alto Networks.

The launch includes more than 70 new security features that enhance all aspects of our Next-Generation Security Platform. We are building upon the existing capabilities of our natively engineered cybersecurity platform to provide organizations with the ability to safely enable applications, content and users regardless of location, prevent successful cyberattacks, simplify security operations, and safely embrace the cloud.

The new capabilities in PAN-OS 8.0 will help customers:

Enable Cloud Adoption

Enhancements support migration to diverse, multi-cloud environments, providing consistent, scalable and advanced security, as well as industry-leading integration with key providers, such as Amazon Web Services and Microsoft Azure, for operational agility and automated scale out. Greater visibility, policy enforcement and actionable dashboards improve security capabilities for SaaS applications, and an expanded lineup of VM-Series virtual firewalls meet a variety of performance needs and use cases.  The new VM-50, VM-500 and VM-700 provide industry-leading performance of up to 16 Gbps for small remote offices to data centers and service provider deployments.

Detect and Prevent Evasive Malware and Credential Theft

PAN-OS 8.0 includes several first-ever innovations focused on advanced threat prevention techniques and the prevention of credential theft and abuse. These include a new 100 percent custom-built anti-evasion analysis environment for WildFire; a heuristic engine to dynamically steer highly evasive threats to a bare metal analysis environment for full hardware execution; a fully automated, payload-based command-and-control signature generation and delivery mechanism; and the new MineMeld application that’s integrated with AutoFocus for automated action driven by correlated threat intelligence.

Prevent the use and abuse of stolen credentials by providing a policy-based multi-factor authentication framework natively in the next-generation firewall. This new and unique capability makes it very easy to enforce multi-factor authentication from the firewall to stop cyber adversaries from moving laterally in a network and accessing sensitive resources with the help of stolen credentials or compromised endpoints. This is achieved by working at the network level in conjunction with authentication and identity management frameworks, such as single sign-on and multi-factor authentication, and integrating with a number of next-generation identity access management vendors, including Ping Identity, Duo Security, and Okta to enforce policies.

Scale With Predictable Performance Across a Variety of Use Cases

Designed to handle increasing throughput needs due to increased SSL-encrypted traffic and data center consolidation, as well as increased traffic at the internet gateway, six new models of appliances: PA-5260, PA5250, PA-5220, PA-850, PA-820 and PA-220 enable advanced security protections for large data centers to smaller environments and branch offices.

Management features that provide administrators fast and accurate insight delivered by Panorama, and include ingestion of Traps (advanced endpoint protection) logs, as well as additional firewall logs to enrich correlation of indicators of compromise and automate actions to update the next-generation firewall with new automated actions to prevent adversary lateral movement and alert IT via IT service management and security response systems, such as ServiceNow, lowering operational burden for security teams.

Below are links to additional resources to learn more about PAN-OS 8.0

[Palo Alto Networks Research Center]

Traps Named A Visionary in Gartner’s Magic Quadrant for Endpoint Protection Platforms

Gartner has just released its 2017 Magic Quadrant for Endpoint Protection Platforms (EPP), and we’re honored that Palo Alto Networks is named a Visionary in this report. This marks the first year that Palo Alto Networks has been included in the EPP report – we believe this is further proof of Traps’ recognition by top-tier, independent third parties and analysts.

Here are a few highlights from the report that should be of interest to endpoint security professionals:

  1. Gartner’s report cautions customers against overreliance on reactive indicators of compromise. According to Gartner, “With the exception of some of the emerging Visionary vendors, too many EPP solutions’ malware detection techniques remain overly reliant on reactive indicators of compromise (i.e., IP address, URL, file hash, partial hash, registry key values). These static indicators are the easiest part of the kill chain for the attackers to change rapidly.”
  2. The report offers guidance to customers on what endpoint protection capabilities they should assess when evaluating potential solutions. Gartner observes that “Most attacks exploit well-known unpatched vulnerabilities, use social engineering to trick users to install trojan malware, or use interpreted code such as Java or Visual Basic to download and install malware.“
  3. Gartner reflects on the utility of standard testing and the need for improvements in their test by stating that, “Standardized testing, such as AV comparatives and AV tests, are still the best indicators of effectiveness; however, they still overreward reactive solutions and undertest detection of new attacks.”

Our view at Palo Alto Networks is that enterprises will continue to seek more effective endpoint security offerings that can prevent security breaches, whether they are initiated through the exploitation of application vulnerabilities or via new and unknown malware.

I encourage you to read the complete Magic Quadrant report to learn about all of Gartner’s findings.

Gartner Magic Quadrant for Endpoint Protection Platforms, Eric Ouellet, Ian McShane, Avivah Litan, January 2017. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

[Palo Alto Networks Research Center]

Exploit Kits: Protect Yourself Before You Wreck Yourself

Exploit kits have become go-to tools for attackers to take control of victims’ machines or steal information. To protect yourself from this type of attack, it’s important to understand how exploit kits work, what their process is, and what vulnerable parts of your organization they are targeting. Our brief, Exploit Kits: A Series of Unfortunate Events, breaks down the sequence of events an exploit kit must complete to successfully execute an attack.

Most endpoint security solutions use signatures to prevent known threats that have already successfully penetrated networks. But attackers of varying skillsets can bypass signatures using inexpensive, automated tools that produce countless unique and unknown attacks.

Palo Alto Networks Traps advanced endpoint protection provides multi-method exploit prevention by focusing on the core exploitation techniques used in exploit attacks, rather than relying on signatures to prevent already-known threats. The result is several layers of protection to block known, unknown and zero-day threats before they compromise an endpoint.

Traps recognizes and proactively blocks exploit techniques that:

  • Manipulate the operating system’s normal memory management mechanism for applications used to open up compromised data files
  • Would allow an exploit to manipulate an operating system’s normal application process and execution mechanisms
  • Would allow malicious code embedded in an exploit file to execute

Traps integration with Palo Alto Networks WildFire, our cloud-based threat intelligence service, provides further protection by preventing known malware execution and uploading unknown malware for dynamic analysis and rendering a verdict within five minutes. Once malware is known, it can be prevented at the network by Palo Alto Networks Next-Generation Firewalls or on any endpoint running a Traps agent.

Organizations that use Traps can continue to use applications, including those built in-house, legacy systems, and software running on unsupported operating systems for example Windows XP or Windows Server 2003.

Learn more about how Traps prevents malware and exploits.

[Palo Alto Networks Research Center]

Is Your Security Team Ready For Cloud?

A version of the following article originally appeared in Dark Reading.

By now, most of us in IT are well aware of the technical and business advantages that moving to a cloud-based data center provides. But there is still a lingering hesitancy among some organizations considering a move to the cloud.

In my experience, most concerns boil down to two factors: a reluctance to put trusted data on a network that’s not on the premises, and confusion around the costs and complexity of moving to the cloud. If that’s what’s keeping an organization from the cloud, I have a few points to share that should help them clear up the “cloudiness” (pun intended) and shine light on the possibilities.

When It Comes To Security, The Cloud Is Ready
If there is one roadblock that keeps IT teams leery about the cloud, it’s cybersecurity. And while cybersecurity will always be a concern, when it comes to the cloud, the industry is well-prepared. Leading public cloud providers, like Amazon AWS and Microsoft Azure, have made significant investments in securing their cloud environments and both companies offer robust security resources to cloud customers via the Microsoft Azure Trust Center or Amazon’s AWS Cloud Security.

Cloud providers are also building an expansive ecosystem of security technology partners who can provide cybersecurity solutions for the public cloud and Software-as-a-Service. These solutions, if implemented as a cohesive platform and not an ad hoc collection of security devices that don’t work well together, can provide a consistent and seamless security experience to both cloud-based and physical networks through consistent visibility, policy, and enforcement across the network regardless of a user’s location. Another plus is the Cloud Security Alliance, an industry consortium of companies that provides excellent resources to help cloud adopters address security concerns and stay up to date on the latest developments in cloud technology.

Are You Ready for the Cloud? Read Frank’s full article at Dark Reading.

[Palo Alto Networks Research Center]

English
Exit mobile version