22
Taking Control of Cloud Security Travis Abrams

Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Embed Size (px)

Citation preview

Page 1: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Taking Control of CloudSecurity

Travis Abrams

Page 2: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

DG Technology ConsultingA Unique Perspective on Security

Consulting and Professional Services• Health

checks• Deployment

services

Strategic Partner• VAR Board

Leadership on product feedback

• Technical Advisory Board member on product enhancements

Software Vendor• MEAS-

Mainframe Event Acquisition System

Page 3: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Why Intel?

Page 4: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

The Cloud Brings New Challenges

SECURITY

Increasingly sophisticated

malwareIncreased SSL-encrypted web

trafficAdvanced,

persistent threats

APPLICATIONVISIBILITY

More people & devices connecting to more applications

outside traditional network, often

without IT knowledge

FLEXIBILITY

Need to accommodate

changing business conditions

Protection needs to travel with the user and device rather than stay in the

office

4

Page 5: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

What's holding back the cloud?

Page 6: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

What’s holding back the cloud?

Page 7: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Email Authentication WebData Loss Data Loss

Intrusion Intrusion

Enterprise

MobileUsers

EnterpriseUsers

Private CloudApplications

Partners CloudVendors

Applications Customers

Public Cloud

Cloud Channels

Page 8: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

• Identify all web applications, including shadow IT

• Enforce acceptable usage policy• Control access with SSO and multi-factor

authentication

• DLP Engine‒ Full dictionaries‒ Enforce data leakage policy

• File encryption‒ Protect data on file-sharing sites

• Identify “phone-home” behavior• Aggressive scanning of non-human

initiated requests

eP

Anti-MalwareBotnet Client

Data Leakage

Application Visibility

Content Inspection

SSL Scanning

Web Gateway Meets The Challenge

10

• Signature-based AV• Zero-day malware detection

‒ Dissect, emulate target platform environment

‒ Evaluate code behavior

• Scrutinize HTTPS traffic• Identify malware and

applications hidden in encrypted web session

• Reputation (GTI)• Geo-location (GTI)• URL categorization & filtering (GTI)• Media & file analysis

Outbound TrafficInbound Traffic

Page 9: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

12

Malware Detection

McAfee Beats The Competition

McAfee Web Gateway

Vendor 1 Vendor 2 Vendor 3 Vendor 4

83.9

69.1

57.2

47.8

62.1

Malware Detection Rate (%)

1170 malware samples

Page 10: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

13

McAfee Gateway Anti-Malware Engine Scanning

DISSECT

ANALYZE

EMULATE

• Unique McAfee technology

• Emulation provides real-time protection

• Most effective zero-day protection

Page 11: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

14

Data Loss Prevention

Page 12: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

15

Proactive Encryption

Encryption protects cloud-based files

Page 13: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

16

Security

• Patent pending, outbound detection of botnet client phone-home behavior

• Understand difference between normal user and application-initiated requests

• Dynamically adjust proactive detection level

Block Infected Client Communications

MalwareUnsolicited download Normal responseReal user clicks link

Normal ScanningAggressive

scanning blocks malware

Normal response

Page 14: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Managing Cloud Environments

Page 15: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Managing Cloud Environments

Page 16: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Managing Cloud Environments

Page 17: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

TODAY’S REALITY:More than 80% of

employees worldwide use SaaS applications without IT approval.

– Frost & Sullivan:The Hidden Truth Behind Shadow IT

www.mcafee.com/ShadowIT

Page 18: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

23

Application Discovery

What applicationsare on your network?

How much bandwidth are they

using?

Who are the top users?

Which are blocked?

What applicationsare on your network?

How much bandwidth are they

using?

Who are the top users?

Which are blocked?

Page 19: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

24

Web Application Controls

Enable/Disable specificapplications

Control entitlements, access, data sharing

Apply policy based on application, user, group, risk, …

Page 20: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

26

Application Access

One Time Password

Laptop

Mobile

Internal User

SSO Launch Pad

Single Sign On

Page 21: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

27

The Offer

• McAfee security experts will conduct a free content security risk assessment

• Deploy McAfee Web Gateway 30-day trial

• Transparently collect web traffic (including from your existing SWG vendor) and evaluate:

• Correct URL filtering/categorization• Web traffic containing known and

zero-day malware• Acceptable usage policy enforcement

– Provide you with a results report

Risk Assessment

Free Risk Assessment

Page 22: Taking Control of Cloud Security Travis Abrams. Consulting and Professional Services Health checks Deployment services Strategic Partner VAR Board Leadership

Thank you!

www.McAfee.com/webprotection