Giga Event


Seminar:
Security 1.0 in an Enterprise 2.0 world?

Learning over lunch

Palo Alto Networks Delivers IPS Inside the Leading Next-Generation Firewall on the Market.

·          App-ID technology, in Palo Alto Networks’ next-generation firewalls enable organizations to identify and control over 900 applications in the firewall

·          Using Palo Alto Networks’ Content-ID technology, allowed application traffic can then be scanned for threats and confidential data (e.g., credit card numbers)

·          Palo Alto Networks’ NGFW has the ability to decrypt SSL and unzip compressed content and scan it – all by policy

·          The single-pass, parallel-processing (SP3) architecture enables very high throughput (up to 5 Gbps, even when scanning server-to-client and client-to-server traffic) with a single pass (no redundant packet processing), and specialized, dedicated hardware processors for management, networking, security, and content scanning.

·          Our research team is active – and has been credited with discovering more Microsoft vulnerabilities than any other IPS vendor’s internal team in the last 6 months (the next closest vendor discovered half as many).

·          Finally, the segment coverage of a Palo Alto Networks next-generation firewall is superior – our PA-4050, for example, offers the ability to cover 12 segments with 24 ports – far outstripping the competition on value.

 

Join Palo Alto Networks and GigaNetworks for a Technology Luncheon: Security and Enterprise 2.0

Protecting the network in an Enterprise 2.0 environment:  IPS for Facebook, Twitter, LinkedIn.... 

Date: Thursday, June 3, 2010

Time: 11:30a over lunch

Location:  Texas de Brazil, Dolphin Mall, Miami, Florida

Click the REGISTER NOW link to request attendance

SPACE IS LIMITED

 

Modern Threats Target Users and Applications.

·          Threats increasingly target user-centric applications – through vulnerabilities, SSL, obfuscation, and generally using evasive applications as conduits.

·          Examples include Storm, Mariposa, social networking threats, and data leaks across P2P file sharing networks 

Traditional, Stand-Alone IPS can be considered Limited.

·          Traditional, stand-alone IPS is blind to encrypted and obfuscated application traffic

·          In many deployments, doesn’t scan any server-to-client traffic in the interest of performance – leaving all of the user-centric application traffic unscanned anyway.

The First Thing Enterprises Must Do:  Control the Threat Vector.

·          The first, and most important thing to do is the control the threat vector – applications.  If you limit the number of threat vectors, you can then spend more time scanning the applications you do want on your network.

·          Unfortunately, only blocking “bad” applications won’t help.  Organizations need to scan allowed apps for threats.

Next, Do Intrusion Prevention (plus a bit more) on Allowed Application Traffic.

·          Protection against threats using vulnerability-facing signatures, using a variety of techniques, which include: protocol anomaly detection, stateful pattern matching, statistical anomaly detection, heuristic analysis, blocking of invalid or malformed packets, and IP defragmentation and TCP reassembly (for anti-evasion).

·          Scan and prevent SSL-encrypted and compressed/obfuscated threats

·          High performance is critical.  Multi-Gbps throughput, with low latency – even when scanning traffic in both directions, as required to prevent these new, application-targeted threats.

·          Research and Support from the Vendor:  active research, leadership, and rapid deployment of new protections

·          Increasingly, providing a degree of protection against certain types of data leaks

Increasingly, IPS Functionality Will Be Delivered in Next-Generation Firewalls.

·          The critical new requirements for intrusion prevention actually suggest firewall controls.  The ability to identify and control all application traffic, but an “allow, but scan” policy is beyond the negative security model found in stand-alone IPS products.  Only a next-generation firewall can deliver that policy control and fine-grained response.

·          Gartner has recommended to its clients to move from traditional IPS to next-generation firewalls at the next refresh opportunity.

 

About GigaNetworks, Inc
With the definition of security constantly changing, a trusted company focusing on the needs of the organization is what the market demands. With many successful projects completed in FL and extremely satisfied customers, GigaNetworks, headquartered in Miami, FL, will meet your needs for security, application protection and user control.

To unsubscribe from the GigaNetworks event mailings, either click on this link or send a note with “unsubscribe” in the subject line to events@giganetworks.com.