The speed and sophistication of modern cyberattacks mean security teams need tools that can keep up, from monitoring all aspects of the network, to maintaining security on a vast number of network-connected endpoints, and using actionable threat intelligence to detect and prevent new threats. With that in mind, today we’re announcing a strategic alliance with Tanium that will help security teams accelerate the process of threat detection and response with new levels of effectiveness, accuracy and speed.
Specifically, Tanium will integrate with Palo Alto Networks WildFire, receiving malicious indicators identified by WildFire to automatically assess every endpoint across an organization, confirm active cyber attacks as well as what systems are affected, and remediate those attacks — all within a matter of seconds. What’s more, the information that’s then provided by Tanium back to the Palo Alto Networks next-generation security platform means intelligence is shared among integrated systems, providing consistently better protection for an organization’s network and endpoints and preventing future attacks.
Palo Alto Networks and Tanium are at Black Hat USA 2015 in Las Vegas this week and will be showcasing our integrated solution. Come by Booth 119 (Palo Alto Networks) and Booth 1248 (Tanium) and see how we’re changing the economics of cyber attacks.
On July 31, the FDA issued an alert advising healthcare facilities to stop using Hospira’s Symbiq drug infusion pump due to a security vulnerability. Infusion pumps are used by medical facilities to automatically administer doses of medication to patients based on the amount specified by the caretaker. The vulnerability allows an attacker to change the doses of prescribed medicine and impact patient safety.
Multiple Hospira products have been in the hot seat this year due to similar security vulnerabilities. The US Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued four different alerts for Hospira products this year, including their Symbiq, MedNet, Lifecare PCA, Plum A+ devices.
According to Billy Rios, the security researcher who discovered the vulnerability in one of Hospira’s devices, the pumps connect to the hospital network to download drug libraries used to control the upper and lower limits that the machine can safely deliver. The design flaw is rooted in the fact that the pump does not authenticate communications sent to it. This means that anyone with access to the same hospital network could potentially change the libraries and change the effective doses of medicine administered to the patient.
The ICS-CERT team has advised facilities to perform a risk assessment to determine the impact, and then mitigate the issue by either unplugging the impacted devices or, if they are absolutely necessary, change the default passwords on the devices and use a firewall to selectively monitor and/or block access.
Discoveries like these raise the question of what other medical devices that connect to hospital networks — and patients — are vulnerable to similar attacks. Is the firmware on all those devices up to date? Often medical devices are delivered to hospitals with accompanying vendor-provided Windows machines. Are those all up to date with security patches? Who is managing them? Many hospitals have thousands of medical devices and are now realizing that no one is keeping them up to date.
C-level leadership at healthcare organizations should ask their teams to develop shorter-term tactical and longer-term strategic plans to address the cyber security risks that medical devices present. Strong patch management processes that include medical devices, and network segmentation are the two core elements to the solution. A network segment that is dedicated specifically to medical devices can mitigate the risk of vulnerabilities and zero-days that have not been discovered yet.
Healthcare providers should focus on the following steps to address the cybersecurity risks that medical devices present:
Inventory all medical devices
Build an inventory of all medical devices
Determine which medical device connect to the network (wired or wirelessly)
Determine the business and IT owners for each medical device, and if they’re “unowned,” assign owners
Determine the patch management plan for medical devices
Decide which team is on point to update the medical devices (internal IT vs. a vendor)
Assess network architecture for medical devices
Create a dedicated medical device segment
Ensure the medical device segment is configured to block both inbound and outbound connections (unless specifically allowed)
Develop a plan to migrate medical devices to the medical device segment
This four-step plan could take months to execute, given the size and breadth of many healthcare organizations that have thousands of medical devices across many departments. But the most dangerous risks are those that we don’t yet know about or understand.
Healthcare providers: Assign some staff to wrap their heads around the security risks of medical devices in your environment and develop a plan to mitigate. Your patients will thank you.
Read more about how Palo Alto Networks can help protect healthcare organizations.
Most security vendors talk about how their products are “business enablers,” rather than simply a line item in the budget. This is an admirable goal, but making claims is easy – delivering on them is what counts. The Palo Alto Networks customer count continues to soar to a large extent because of the business value that our solution delivers. Many customers prefer not to publically discuss which products and services they deploy, and that is sometimes the case with cloud providers as well. One such example of how the Palo Alto Networks Security Platform truly serves as a business enabler is worth noting because it is such a great illustration of the value we bring to the cloud.
A regional service provider in Asia Pacific asked for help enabling a new cloud services business they were launching. They had been providing traditional premises-based services, network connectivity, unified communications and hosting to their mid-market customer base. They had a strategic goal to become a cloud-based integrator. This would make their customers’ networks and operations more effective, improve performance, lower costs, and decrease the time to market for more products and services. In short, it would drive new revenue streams by improving business efficiencies for their customers. It would keep them competitive.
Security was a critical success factor for the initiative. Customers are understandably cautious about moving business-critical functions to a cloud service because of security concerns. They have plenty of questions and need lots of assurance. One of the main differentiators that our platform offered was the in-depth visibility and control the provider could offer their customers. This became a big selling point – customers would actually get a higher level of security by moving over to the cloud than they had with their legacy premises-based products.
The other key differentiator, that was a huge business benefit to both the Service Provider and their customers, was the ability to offer complete security services (e.g., URL, threat prevention, and remote access VPN), and the ability to use Panorama to onboard customers quickly and efficiently. Time to revenue is key in this business and our platform and management framework excelled in that respect.
The Bottom Line
Palo Alto Networks delivered everything the customer had hoped for when it made us a key element of their cloud business. In the words of the customer, “We got a complete platform in Palo Alto Networks, which is strategically very important to us, and it’s delivered in all the areas needed. We’ve gotten visibility into threats at the app level, and to see what users are doing. The fact that everything is integrated into one platform with one reporting interface – and that we can scale and onboard customers without any impact on performance, or the need for more overhead – is simply fantastic.”
Favoring a more integrated approach to cybersecurity, businesses are taking a hard look at ways to improve security by increasing spend, developing talent and managing policies. But the price tag associated with these changes begs the question: How much does one need to spend in order to gain footing against attackers?
In a recent column for SecurityWeek, Scott Gainey discusses this question, as well as an initial report released by the World Economic Forum which attempts to develop a common framework qualifying the risk and impact associated with cyberattacks. Read Scott’s full article here.
Want to see for yourself how well our VM-Series firewall works with Amazon Web Services? You can. Head here to access a guided tour of Palo Alto Networks VM-Series using hands-on lab exercises in AWS.
The Test Drive lasts about one hour and allows you to build policies, troubleshoot, execute a simulated attack that is then blocked, and perform forensics. Following your Test Drive, you can view licensing options for the VM-Series to determine the best fit for your needs.
Securing your AWS public cloud is crucial, but you also need to do so without compromising business productivity. Our recently released PAN-OS 7.0 includes the ability to select and purchase pre-defined VM-Series firewall bundles for AWS using hourly or annual subscriptions. Learn more about VM-Series for AWS here.