Modern
Threats Target Users and Applications.
·
Threats increasingly
target user-centric applications – through vulnerabilities, SSL,
obfuscation, and generally using evasive applications as
conduits.
·
Examples include
Storm, Mariposa, social networking threats, and data leaks
across P2P file sharing networks
Traditional, Stand-Alone IPS can be considered Limited.
·
Traditional,
stand-alone IPS is blind to encrypted and obfuscated application
traffic
·
In many deployments,
doesn’t scan any server-to-client traffic in the interest of
performance – leaving all of the user-centric application
traffic unscanned anyway.
The First
Thing Enterprises Must Do: Control the Threat Vector.
·
The first, and most
important thing to do is the control the threat vector –
applications. If you limit the number of threat vectors, you
can then spend more time scanning the applications you do want
on your network.
·
Unfortunately, only
blocking “bad” applications won’t help. Organizations need to
scan allowed apps for threats.
Next, Do
Intrusion Prevention (plus a bit more) on Allowed Application
Traffic.
·
Protection against
threats using vulnerability-facing signatures, using a variety
of techniques, which include: protocol anomaly detection,
stateful pattern matching, statistical anomaly detection,
heuristic analysis, blocking of invalid or malformed packets,
and IP defragmentation and TCP reassembly (for anti-evasion).
·
Scan and prevent SSL-encrypted
and compressed/obfuscated threats
·
High performance is
critical. Multi-Gbps throughput, with low latency – even when
scanning traffic in both directions, as required to prevent
these new, application-targeted threats.
·
Research and Support
from the Vendor: active research, leadership, and rapid
deployment of new protections
·
Increasingly,
providing a degree of protection against certain types of data
leaks
Increasingly, IPS Functionality Will Be Delivered in
Next-Generation Firewalls.
·
The critical new
requirements for intrusion prevention actually suggest firewall
controls. The ability to identify and control all application
traffic, but an “allow, but scan” policy is beyond the negative
security model found in stand-alone IPS products. Only a
next-generation firewall can deliver that policy control and
fine-grained response.
·
Gartner has
recommended to its clients to move from traditional IPS to
next-generation firewalls at the next refresh opportunity.
|