36

Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

  • Upload
    vucong

  • View
    222

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)
Page 2: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Boaz Litai, Regional Director - EMEAMarch 2018

Data Sanitization (CDR): Stripping Threats out of Your Organization

Søren Elnegaard Petersen – Sales Director, Arbit Security March 2018

Show casing:

How to protect high security networks with integrated OPSWAT Metadefender & Arbit Arbit Cross Domain Solution

&

Page 3: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Boaz Litai

I have 15 years of experience in cyber security addressing verticals such

as telecommunications, mobile, large enterprises, and governments.

I joined OPSWAT in April 2017 with the goal of developing an aggressive,

proactive go-to-market and outbound sales operation across EMEA, via

channel partners and building a direct sales organization.

Why OPSWAT?

OPSWAT is an exciting, growing security software company

headquartered in San Francisco with offices around the world.

It is a place where I can make my mark while improving safety and

helping make organizations secure around Europe.

Page 4: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Agenda

Who is OPSWAT?

State of Cyber Security Today

What is Content Disarm & Reconstruction (CDR)?

How is CDR implemented?

Page 5: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

2002 Founded

5 Global Offices

1,000+ Direct Customers

6 Patents granted

24/7 Global Support

300 Technology Partners

175+ Worldwide Employees

Page 6: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Protecting Organizations from Advanced Threats3 synergistic technologies

Stops known and unknown threats

Consists of: Multi-scanning Data Sanitization App Vulnerability Scanning

Page 7: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Large and Loyal Customer BaseMarket leadership validated by marquee customer base across multiple critical infrastructure industries

GOVERNMENT DEFENSE ENERGY FINANCE MANUFACTURING TECHNOLOGY

Page 8: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Agenda

Who is OPSWAT?

State of Cyber Security Today

What is Content Disarm & Reconstruction (CDR)?

How is CDR implemented?

Page 9: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Five Primary Sources of ThreatsState of Cyber Security Today

State Sponsored Government-Funded Espionage

Cyber Criminals Well-Funded Criminals

Terrorists Zealots with Strong Views

Hacktivists Protesters with an Axe to Grind

Insider Threats Employees

Page 10: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Increasing ”Mega” Hacks/BreachesState of Cyber Security Today

Year 2013 and 2014

Number of Records

Data at Risk

Company

2015 2017

3 billion 78.8 million 143 million

Names DOB Email addresses Phone numbers Encrypted/unencrypted security questions and answers

Names DOB Email addresses SSN Addresses Employment information

Names DOB SSN Driver’s license numbers Credit card numbers

Page 11: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

• Iran nuclear facilities were attacked by Stuxnet malware in 2010

• Saudi Aramco was attacked by Shamoon malware in 2012

• Ukraine power grid was attacked by BlackEnergy malware in 2015

• More than 80 Ukrainian and Russian companies initially were attacked by Petya malware

in 2017

• Early 2017 – US nuclear facilities hacked by nation/state

• Current – discussion of N. Korean nuclear plans for EMG pulse to knock out electrical

Increasing Prevalence of Critical Infrastructure AttacksState of Cyber Security Today

Page 12: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

1. Phishing for credentials

2. Ransomware

3. Malvertising

4. Fraud targeting CEO

5. Vishing (phone phishing)

Top TacticsState of Cyber Security Today

6. Web application attacks

7. Disclosure by 3rd Parties

8. Data loss through email

9. Data loss through unauthorized cloud usage

10. Sabotage

Page 13: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

The Cost of Data BreachesPer Capita Cost by Industry Classification Chart Title

Public sectorResearch

MediaTransportation

HospitalityEntertainment*

ConsumerEnergy

IndustrialCommunications

RetailTechnologyLife science

EducationServices

FinancialHealth

US$0 US$100 US$200 US$300 US$400

FY 2017 (USD$)4-year average (USD$)

*Historical data is not available for all yearsSource: Ponemon Institute

Page 14: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Agenda

Who is OPSWAT?

State of Cyber Security Today

What is Content Disarm & Reconstruction (CDR)?

How is CDR implemented?

Page 15: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

What Is Data Sanitization (CDR)?The underlying technology has been around for a while

ExeFilter developed by French MoD for NATO, with goals of: To protect sensitive networks against attacks involving files, e-mails and active content. To ensure that only known and controlled file formats enter the system To filter all unwanted active content from external sources”

Certification requirement from NISA for portable solution vendors

Content Disarm & Reconstruct” used in NISA certification guidelines dated 2012 for deployment of stand-alone Kiosks “to scan files from an external source in order to find, block and disrupt malware before it can penetrate the corporate network.”

2004

2012

Page 16: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

What Is Data Sanitization (CDR)?The technology becomes popular in 2015 – or at least gets a popular name…

Gartner recommends CDR to protect against phishing attacks (Fighting Phishing: Optimize Your Defense)

About 1,520,000 articles, 1,410 under “News,” on Google

2016

March, 2018

Page 17: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

What Is Data Sanitization (CDR)?Synonyms

CDR Gartner Data Sanitization OPSWAT

Disarm feature

Symantec

Threat Extraction Check Point

Clean Content Oracle

Safe File Mimecast

DvC Solebit

Advanced CDR Votiro

* January 2018, USA Department of homeland security performed a Data Sanitization penetration test comparing OPSWAT Data Sanitization as well as 4 other solutions. OPSWAT achieved the best result among the select vendors!!

Page 18: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

What Is Data Sanitization?Content Disarm and Reconstruction

It’s like boiling water

Page 19: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

What Is Data Sanitization (CDR)?Content definition in Wikipedia

Removes potentially malicious code from files

It’s not malware analysis

Does not determine or detect malware's functionality

Removes all file components that are not approved within the system's definitions and policies

Page 20: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Why Is Data Sanitization Important?Block file types

.adp .fxp .mag .msc .prf .tmp .class

.app .gadget .mam .msh .prg .url .grp

.asp .hlp .maq .msh1 .pst .vb .jar

.bas .hpj .mar .msh2 .reg .vbe .mcf

.bat .hta .mas .mshxml .scf .vbp .ocx

.cer .inf .mat .msh1xml .scr .vbs .pl.chm .ins .mau .msh2xml .sct .vsmacros .xbap.cmd .isp .mav .msi .shb .vsw.cnt .its .maw .msp .shs .ws.com .js .mda .mst .ps1 .wsc.cpl .jse .mdb .ops .ps1xml .wsf.crt .ksh .mde .osd .ps2 .wsh.csh .lnk .mdt .pcd .ps2xml .xnk.der .mad .mdw .pif .psc1 .ade.exe .maf .mdz .plg .psc2 .cla   

Symantec Recommends

Page 21: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Why Is Data Sanitization Important?Block file types

But probably not these if productivity is to be maintained:

Documents (DOC, DOCX, PDF, etc.)

Images (TIFF, JPG, PNG, etc.)

HTML files

Archive files (RAR, ZIP, etc.)

Other productivity files (CAD, SketchUp, XML, etc.)

Page 22: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Agenda

Who is OPSWAT?

State of Cyber Security Today

What is Content Disarm & Reconstruction (CDR)?

How is CDR implemented?

Page 23: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Data Sanitization ImplementationAn example with a Microsoft Office document

• Embedded objects

• OLE objects

• Attachments

• Embedded binary files

• Script-enabled ActiveX controls

• Macros

• Hyperlinks

Page 24: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Data SanitizationExample of PDF > PDF sanitization

Original File

PDF

Sanitized File

PDF

Page 25: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Data SanitizationExample of DOCX > DOCX sanitization

Original File

DOCX

Sanitized File

DOCX

Page 26: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

MetadefenderProtecting Organizations from Advanced Threats

Page 27: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Søren Elnegaard Petersen – Sales Director, Arbit Security March 2018

Show casing:

How to protect high security networks with integrated OPSWAT Metadefender & Arbit Arbit Cross Domain Solution

Page 28: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Internet Company Isolated Network

Page 29: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Page 30: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Case OK:

Page 31: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Case OK:

Page 32: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Page 33: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Case REJECT: User file rejected

Page 34: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Page 35: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

© Arbit Security ApS 2018 – All rights reserved

Page 36: Boaz Litai, Regional Director - EMEA - summit.confent.com · Boaz Litai I have 15 years of experience in cyber security addressing verticals such ... Documents (DOC, DOCX, PDF, etc.)

Thank You