Synchronized Security Paul Zindell SE, Mountain Region “I didn’t understand it but the half hour wasn’t boring to a technologically impaired person. I actually listened to the whole thing.” – Fela, Paul’s Mom “Much of the high tech terminology was beyond my understanding, but your expertise and command in computer security is impressive.” – Larry, Paul’s Dad Andy Thomas – original member of N Sync I Can Feel Your Heartbeat Don’t Turn Me Red Keep ‘em Isolated 2015 – Launched Sync Sec 2016 – Partner Momentum (New Accounts, Cross-sell NW/End) 2017 – Customer Traction
Increasing attacks, increasing sophistication Attack surface exponentially larger Attacks are more sophisticated than defenses Threat landscape is constantly changing Average user had 3 devices and both user and device are mobile Everything will be Cloud Managed IoT Attackers coordinate and combine tecniques to improve thier strike rate. Resuable code, online tools, it’s easy Soccer/Football – Red Cards (7 player minimum) Laptops/Desktops Phones/Tablets Virtual servers/desktops Cloud servers/storage IoT Syndicated crime tools Zero day exploits Memory resident Polymorphic/metamorphic Multilevel botnets
Synchronized Security Admin | Manage All Sophos Products Self Service | User Customizable Alerts Partner | Management of Customer Installations Sophos Central In Cloud On Prem Next-Gen Firewall Next-Gen Endpoint Wireless Mobile Email Server Web Encryption How do we solve this issue? Our Vision/Strategy/Ref Architecture All products working together in a system (security services) Best of Breed vs. Integrated System – old thinking Heartbeat, Cloud Intelligence, Analytics – for Action, not Info Managed by Sophos Central (Easy, Scale, Service) Who is using it? POLL Cloud Intelligence Analytics | Analyze data across all of Sophos’ products to create simple, actionable insights and automatic resolutions Sophos Labs | 24x7x365, multi-continent operation | Malware Identities | URL Database | Machine Learning | Threat Intelligence | Genotypes | Reputation | Behavioral Rules | APT Rules | App Identities | Anti-Spam | DLP | SophosID | Sandboxing | API Everywhere
Synchronized Security Best of breed security system that enables your defenses to be more coordinated than the attacks. Unparalleled Protection Automated Incident Response Real-time Insight and Control Breach Prevention Reduce Breach Impact Simplify IT Management Rest of presentation – IN ACTION Demos Customers How it’s being sold
Next-Gen Endpoint Protection Synchronized Security Device And App Control Reputation Security Signatures Genes Prevention Exploit Behavioral Detections Memory Scanning CryptoGuard Sophos Central Mgmt. pre- --> <-- post- Machine Learning Root Cause Analysis Malicious Traffic Detection .exe Malware Malicious URLs Non-.exe Malware Exploits Sync Security is broader than Heartbeat Technologies within the Endpoint work together One tech spots suspicious, can kick off another tech to scan Script-based Malware Removable Media Phishing Attacks Unauthorized Apps
Next-Gen Endpoint + Network Protection Web Protection Email Protection Sandboxing Application Protection User identity Encrypted Traffic Inspection Advanced Threat Protection IPS Synchronized Security Device And App Control Reputation Security Signatures Genes Prevention Exploit Behavioral Detections Memory Scanning CryptoGuard Sophos Central Mgmt. pre- --> <-- post- Machine Learning Root Cause Analysis Malicious Traffic Detection .exe Malware Malicious URLs Non-.exe Malware Exploits ATP finds bad URL, bad traffic, but unknown Asks endpoint for detail – run a scan, or give me the process info Script-based Malware Removable Media Phishing Attacks Unauthorized Apps
Security Heartbeat Available Now Admin | Manage All Sophos Products Self Service | User Customizable Alerts Partner | Management of Customer Installations Sophos Central In Cloud On Prem Security Heartbeat™ UTM/Next-Gen Firewall Next-Gen Endpoint Server Encryption Cloud Intelligence Analytics | Analyze data across all of Sophos’ products to create simple, actionable insights and automatic resolutions Sophos Labs | 24x7x365, multi-continent operation | URL Database | Malware Identities | File Look-up | Genotypes | Reputation | Behavioural Rules | APT Rules Apps | Anti-Spam | Data Control | SophosID | Patches | Vulnerabilities | Sandboxing | API Everywhere
Bad guy’s trilemma Leaves Sophos Security alone Disable Disable Heartbeat Sophos sees everything they do Intercept X blocks attack Red Health sent through HB FW Isolates Endpoint FW detects Missing Heartbeat FW Isolates Endpoint
Lateral Movement Detection and Prevention XG Firewall Endpoints Security Heartbeat™ Security Heartbeat™ Internet Servers Detection and Isolation
Lateral Movement Detection and Prevention XG Firewall Endpoints Security Heartbeat™ Security Heartbeat™ Internet Servers Detection and Isolation – Endpoint Stonewalling
Lateral Movement Detection and Prevention Security Heartbeat™ XG Firewall Endpoints Security Heartbeat™ Security Heartbeat™ Internet Servers Detection and Isolation – Wireless Heartbeat
Lateral Movement Detection and Prevention XG Firewall Endpoints Security Heartbeat™ Internet Servers Detection and Isolation – Destination Based Rules
Automated Incident Response Available Next Security Heartbeat Intercept X Server Heartbeat Synchronized Encryption Credential Theft Detection Synchronized Email Endpoint Stonewalling Synchronized Mobile Wireless Heartbeat Isolation Lateral Movement Detection and Prevention
Reporting and Analysis Infrastructure visibility Machine, Process, User Threat chain visibility Security Heartbeat Active Threat ID Root Cause Analysis
Dynamic Application Control – Coming Soon Automatically identifies unknown app traffic Better visibility than any other Firewall on the market Risk Reduction Morphing Apps attempting to avoid Firewalls/Sandboxing Suspicious Applications Performance improvement Bandwidth storms
Synchronized Security Security Heartbeat™ UTM/Next-Gen Firewall Next-Gen Endpoint Wireless Mobile Email Server Encryption Web “It only took 2 minutes to find out that everything was under control. Sophos XG Firewall detected the threat and Security Heartbeat allowed the infected host to be immediately identified, isolated and cleaned up. Instead of going into fire drill mode, we were able relax and finish our lunch.” DJ Anderson, CTO, IronCloud