29
Seeing the Future: Sophos Introduces Deep Learning into its Synchronized Security Portfolio Malay Upadhyay Senior Sales Engineer 19/04/2018

Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Seeing the Future: Sophos Introduces Deep Learning into its Synchronized Security Portfolio

Malay UpadhyaySenior Sales Engineer

19/04/2018

Page 2: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Threat Landscape

2

Page 3: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

The Threat Landscape Has Shifted

Ransomware26%

Advanced Malware 20%

Email Malware20%

Web Malware

12%

Generic Malware

12%

Cryptocurrency/Financial Malware

8%

Privilege Escalation

1%Bots1%

Exploits

Most organizations have no exploit prevention^

83% agree it has become more difficult to stop threats ^

Advanced Threats

Ransomware

54% of organizations hit twice on average in 2017^

^Source: The State of Endpoint Security Today SurveySource: SophosLabs

Page 4: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

75%

75% of the malicious files SophosLabs detects are found

only within a single organization.

400,000

SophosLabs receives and processes 400,000 previously unseen malware

samples each day.

Threats are unknown, making them harder to detect

Source: SophosLabs

Page 5: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Predictive Security with Deep Learning

Page 6: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Machine Learning Vs. Deep LearningD

EEP

LEA

RN

ING

Interconnected Layers of Neurons, Each Identifying More Complex Features

INPUT OUTPUT

OUTPUT

MA

CH

INE

LEA

RN

ING

Decision Tree

INPUT

Random Forest

OUTPUTINPUT

Page 7: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Sophos Deep Learning

• Based on deep neural networks – comparable to the human brain

• Detects known and unknown threats without signatures

• Extremely fast – typical detection in < 20ms

• No internet connection needed – works offline

• Works out-of-the-box, no training on customer environment necessary

• Very reliable – lowest False Positive rate

• Profits from 30 years of experience and 100s of millions of samples

• Proven – very effective in independant tests!

“One of the best performance scoreswe have ever seen in our tests”

Maik Morgenstern, CTO, AV-TEST

Page 8: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized Security

8

Page 9: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized Security

Linking Network and Endpoint security to deliver unparalleled protection by automating threat

discovery, analysis, and response.

Page 10: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Endpoint

Firewall

Page 11: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Endpoint

Firewall

Next-Gen Endpoint

XG Firewall

Accelerated Threat DiscoveryNext-gen endpoint and firewall communicate to rapidly find infected hosts across your company

Active Source IdentificationShare security intelligence to positively identify infected users, systems and processes

Automated Incident ResponseAutomatically isolate, or limit the access, for compromised systems until they are cleaned up

Synchronized Security

Page 12: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Next-Gen Firewall

Wireless

Web

Email

Next-Gen Endpoint

Mobile

Server

EncryptionSophos Central

Security Heartbeat™

Sophos Synchronized Security

Page 13: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

13

Synchronized Security

Sophos Central Mgmt.

Root Cause Analysis

Script-based Malware

Phishing Attacks

.exe Malware

Non-.exe Malware

Malicious URLs

RemovableMedia

UnauthorizedApps

Exploits

Next-Gen Endpoint

Page 14: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized Security

Sophos Central Mgmt.

Root Cause Analysis

Next-Gen Endpoint + Network Protection

14

Script-based Malware

Phishing Attacks

.exe Malware

Non-.exe Malware

Malicious URLs

RemovableMedia

UnauthorizedApps

Exploits

Page 15: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized Security Products

15

Page 16: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Accessing Synchronized Security

16

NEXT-GENENDUSER SECURITY

NEXT-GENNETWORK SECURITY

SOPHOS CENTRAL-MANAGED ENDPOINT

• SOPHOS ENDPOINT ADVANCED (CEA)

• SOPHOS ENDPOINT INTERCEPT X (CIX)

NEXT-GEN XG FIREWALL

• NETWORK PROTECTIONMODULE

• ENTERPRISEGUARD LICENSE

• ENTERPRISEPROTECT BUNDLE

NEXT-GENENCRYPTION

SAFEGUARD ENCRYPTION

• ENTERPRISE ENCRYPTION

• FILE ENCRYPTION ADVANCED

Page 17: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Sophos XG FirewallSolving today’s top problems with existing Firewalls

Central ManagementSimpler to manage Instant visibility Synchronized security Top performance

✓ Streamlined workflows✓ Unified policies✓ Policy templates

✓ New control center✓ User & App Risk✓ On-box reporting

✓ Linking firewall & EP✓ Security Heartbeat™✓ Dynamic app ID

✓ Industry-leading HW✓ FastPath optimization✓ High-performance proxy

✓ Full-featured & consistent✓ Cloud or on-premise✓ Free for partners

Complete protection

✓ Firewall & Wireless✓ Web, APT, Apps✓ Email and WAF✓ Sandboxing

Page 18: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Sophos

ZERO DAYEXPLOITSAnti-Hacker

• Signatureless Protection against Zero-Day attacks

• Exploit Detection

• Anti-Hacker technologies

• Credential Theft Protection

BEGRENZTESICHTBARKEIT

• Graphical analysis of malware infection and propagation

• What has happened?

• What is affected?

• How do I prevent this in the future?

Root Cause Analysis

RANSOMWARE

• Deep Learning detects unknown Malware

• CryptoGuard detectsEncryption and restores the original files

Protection againstRansomware & Co

• Signatureless Removalunknown Malware

• Restores original files

Extended Cleanup

Page 19: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

SafeGuard Enterprise – Encryption everywhere

Headquarter

Homeoffice & Roadwarriors Branch Office

Data everywhere

Page 20: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized SecurityScenarios

20

Page 21: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Security Heartbeat – Malware Detection

Malware

RemoveKeys

Isolate Client

Page 22: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Security Heartbeat – Botnet C&C-Traffic Detection

C&C Traffic

RemoveKeys

Isolate ClientStopProcess

Page 23: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Malware

Security Heartbeat – Server Heartbeat

Isolate Server

Server

Clients

Page 24: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

24

What Firewalls See Today What XG Firewall Sees

All firewalls today depend on static application signatures to identify apps. But those don’t work for most custom, obscure, evasive, or any apps using generic HTTP or HTTPS. You can’t control what you can’t see.

XG Firewall utilizes Synchronized Security to automatically identify, classify, and control all unknown applications. Easily blocking the apps you don’t want and prioritizing the ones you do.

Synchronized App ControlA breakthrough in network visibility and control

Page 25: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Synchronized App Control in Action

Security Heartbeat™Synchronized App Control

Unknown ApplicationXG Firewall sees app traffic that does not match a signature

Endpoint Shares App InfoSophos Endpoint passes app name, path and even category to XG Firewall for classification

Internet

XG Firewall

Sophos Endpoints

1 2

Application is Classified & ControlledAutomatically categorize and control where possible or admin can manually set category or policy to apply.

3

Page 26: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

26

Automated Incident Response

Unparalleled Protection

Real-time Insight and Control

Synchronized Security Benefits

Best-of-breed products packed with next-gen technology actively work together to detect and prevent advanced attacks like ransomware and botnets.

Security information is shared and acted on automatically across the system, isolating infected endpoints before the threat can spread and slashing incident response time by 99.9%.

See - and control - what's happening in real-time for simpler, better IT security management.

Page 27: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Free Tools

27

Page 28: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

Free Tools

28

Sophos gives out free tools that check for security risk, remove viruses and protect home networks

Sophos Home

Free 30-day trial ofHitmanPro and HitmanPro.Alert

Mobile Security for iOS

Mobile Security for Android

UTM Home Edition

XG Firewall Home Edition

Antivirus for Linux

Page 29: Seeing the Future: Sophos Introduces Deep Learning into ...Security Heartbeat™ Synchronized App Control Unknown Application XG Firewall sees app traffic that does not match a signature

29