2017 Security Predictions from FortiGuard Labs Bart Green – Utah Named Account Manager Jesse Alverson – Utah Sales Engineer 2/23/2017
What to Expect in Security This Year? 6 Key Drivers are Shaping Threats & Your Response
Introduction Video Derek Manky – Global Security Strategist with FortiGuard Labs https://fortinet.wistia.com/m edias/0h6ej6xua7
Prediction 1: From Smart to Smarter: Automated and Human-Like Attacks will Demand more Intelligent Defense Past: Dumb Malware – relied on target-specific data or volume for success Present: Smart Malware – will be adaptive & use success- based learning for more successful attacks across platforms in different parts of the network
Prediction 2: IoT Manufacturers will be Held Accountable for Security Breaches Past: IoT devices seen as low- hanging fruit: default passwords, coding errors, back doors & junk code made devices easy targets for simple attacks Present: Device growth will cause IoT attacks to become more sophisticated, increasing Shadownets (IoT Botnets), the IoT Deepweb & Targeted Attacks on OEM Manufactures
Prediction 3: 20 billion IoT and Endpoint Devices are the Weakest Link for Attacking the Cloud Past: Nonexistence of the cloud meant no data moving to cloud = smaller attack surface Present: Millions of remote devices accessing the sensitive data stored in the cloud using trust model – threats will be developed to trick trust model by exploiting endpoints & connected devices
Prediction 4: Attackers will Begin to Turn Up the Heat in Smart Cities Past: Public infrastructure systems not connected to the internet or interconnected with each other Present: Traffic control systems, HVAC, lighting, robots, self driving cars, smart TVs, and thousands of smart devices have constant connections with limited security – will be targets as easy entrance points into a network
Prediction 5: Ransomware was just the Gateway Malware Past: Successful ransomware attacks were difficult, costly, and required advanced social engineering Present: The dramatic increase of RaaS (Ransomware-as-a- Service) means the most basic hacker can deploy attacks on high-value targets (political figures, celebrities) or deploy at scale extorting every day people for more money
Prediction 6: Technology will Have to Close the Gap on the Critical Cyber Skills Shortage Past: Successful businesses were not dependent upon the digital economy Present: Any company, especially in the devolving world, requires an online presence and therefore a network, but there are not enough skilled security professionals to write policy, protect critical assets, and secure those connections. There will be an increase in outsourcing to MSSPs to address this skills gap.
What is FortiGuard Labs? Real-Time Threat Intelligence Intrusion Prevention Service Antivirus Anti-spam Web Filtering IP Reputation Security Database Application Control Vulnerability Management Mobile FortiGuard Labs = A Global Threat Research Team – over 200 top threat analysts FortiGuard Services = Security services offered on all Fortinet devices, deployed through FortiOS, receiving real-time updates with proactive threat defense and new signautes/updates Cloud Sandbox
What Does FortiGuard Labs Do? Every Minute, Every Day:
What Can You Do? Deploy A Security Fabric Routing What Can You Do? Deploy A Security Fabric SECURE ACCESS APPLICATION SECURITY ENTERPRISE FIREWALL CLOUD SECURITY ADVANCED THREAT PROTECTION FortiSandbox DATA CENTER/PRIVATE CLOUD FortiClient Secure Access Point FortiGate NGFW Fortinet Virtual Firewall Top-of-Rack Cloud-IaaS FortiSwitch Switching FortiGate VMX SDN, Virtual Firewall FortiDB Database Protection FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiADC Application Delivery Controller Web Servers IP Video Security FortiWeb Web Application Firewall PUBLIC CLOUD FortiSwitch Switching FortiGate Internal Segmentation FW CAMPUS Email Server FortiCloud AP Management FortiGate DCFW/ NGFW FortiCloud Sandboxing FortiGate/FortiWiFi Distributed Ent FW SCRIPT: Fortinet is the only company with security solutions for the data center, cloud, campus, branch, operations center and remote user access designed to work together as an integrated security fabric to provide true end-to-end protection. FortiMail Email Security Cloud-SaaS FortiClient FortiGate Internal Segmentation FW FortiClient FortiExtender LTE Extension FortiAnalyzer FortiDDoS Protection FortiCloud FortiSandbox BRANCH OFFICE FortiManager FortiSIEM OPERATIONS CENTER