risk 2018, hillstone · zte telecommunication. ... parameter 1 sample parameter 2 ... completekill...

25
www.hillstonenet.com Security That Works! Lingling Zhang, SVP of Product & Marketing 03/15/2018

Upload: phamkhue

Post on 13-May-2018

234 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

Security That Works!

Lingling Zhang,SVPofProduct&Marketing03/15/2018

Page 2: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

NSSLabsRecommendedNGFWwiththeBestValue!

2

99.60%BlockRate inStatictest

98.32%BlockRateinLiveTest

NSS Labs 2016

Page 3: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

PositionedinThree GartnerMQs forVision& Execution

3

…...

MagicQuadrantforEnterpriseNetworkFirewalls

MagicQuadrantforUnifiedThreatManagement(SMBMultifunctionFirewalls)

MagicQuadrantforIntrusionDetectionandPreventionSystems

Page 4: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

DemonstratesBroadCompatibilityinETSI’sNFVPlugtests

• 8 MANO(15)

4

• 5 VIM (7)

• 2 NFVI

Page 5: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

UseCase1:Ransomware Protectionw/iNGFW

Page 6: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

Ransomwareiseverywhere!

350% yearlygrowth– Cisco2017AnnualCyberSecurity Report

$5Billion in2017– CybersecurityVentures

40%spamemailscontainransomwarelinks in 2017,lessthan1%in2015– IBMSecurity

Average $1,077, 266%from2015– SymantecResearch

Page 7: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

Defending Ransomware w/Hillstone iNGFW

7

PTSinamas SecuritiesFinance

PTPGASSolutionEnergy

WOORI BankFinance

Krungthai BankComputerServicesFinance

EmtelcoISP

Speednet,BelizeISP

China Everbright BankFinance

UniversityofCórdoba,SpainEducation

NationalUniversityofCostaRicaEducation

PSG,HollandEducation

PacificLightEnergy

Madonald‘sFood

Tsinghua University,ChinaEducation

PEPSIManufacturing

ZTETelecommunication

Page 8: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

WannaCry detectedbyHillstoneAnti-virus

8

Page 9: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

WannaCry detectedbyHillstoneCloudSandbox

9

Page 10: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

WannaCry detectedbyHillstoneABDEngine

10

Page 11: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

UniqueDetectionEngineI:AbnormalBehaviorDetection(ABD)Engine

11

Threat & Risk IdentificationAbnormal behavior AnalysisBehavior Learning & Modeling

• Host/server behavior modeling by adaptive machine learning

• Layer 4-7, hundreds of behavior dimensions

• Real time Behavior Model and rules • Identify abnormal dimensions by behavior

partnering

• Quantitate risk severity and certainty by correlation analysis

• Threat forensics including suspicious and relevant PCAP

Page 12: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

UniqueDetectionEngineII:AdvancedThreatDetection(ATD)Engine

12

Machine LearningKnown malware

Samples

Malware Behavior Learning

Malware Behavior set 1

Malware Behavior set 2

Malware Behavior set 3

ClusteringModeling

Unknown Malware Behavior Patterns

Identify Malware Variants

Unknown Malware

Sample Parameter 1

Sample Parameter 2

Sample Parameter 3

Hillstone IntelligentNext-Generation Firewall

Malware Attributes

MalwareActions

Family 1

Family 2

Family 3

Family n

Page 13: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

ThreatCorrelationAnalyticsEngine

13

Page 14: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

14Complete KillChainMapping

• Mapthreateventsintoeachof7cyberkillchainstages

• Showthreatname,type,source/targetIP,severity,certaintyetc.

• Tracethethreatovertimethroughitsfulllifecycle

14

Page 15: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

UseCase2:Micro-SegmentationinaVirtualizeddatacenter

Page 16: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

BoundaryBlurredintheVirtualWorld

16

Page 17: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

SegmenttheVirtualNetworkwithCloudHive

OnevSOM,TwovSCMs,Upto200vSSMs,OneorMultiplevDSM

17

Page 18: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

CloudHive ProvidesDeepVisibilitytoEast-WestTraffic

18

Page 19: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

UseCase3:AutomatetheDeploymentofNFVandServiceChain

Page 20: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

WhyNFV?

20

NFV

Technology Vendors

Service Provider

Industry Standard

AutomaticDeploymentandHighCompatibility

ScalabilityandElasticity OpenAPIandSoftwareOrchestration

HigherEfficiency LowerOPEX BusinessContinuity VendorIndependence

Page 21: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

CloudEdge for NFV Solutions

21

Orchestrationbasedoncloudplatform

OrchestrationbasedonOpenStack FWaaS

OrchestrationbasedonopensourceMANO

Page 22: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

22

CloudEdge Automatic Deployment

Database192.168.1.14

Web Server192.168.1.11

vRouter

Virtual Firewall192.168.1.19

OpenStack

PastUnpack

Onboard

Power Connect

Configure Address

Change Password

Configure Policies

Online

NowUse Image

Deploy VM

Start VM

Acquire Address

Change Password

Configure Policies

Online

Tenant 1

Hillstone

One click deployment

Prepare Catalog

Page 23: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

HSAHillstoneSecurityAuditPlatform

ManagementCloudServerPerimeter

Security as a Service

ContinuousInnovationandImprovementofProductPortfolio

23

I-SeriessBDSServerBreach

DetectionSystem

S-SeriesNIPSIntrusionPreventionSystem

E-SeriesNGFW

T-SeriesIntelligentNGFW

X-SeriesDataCenterFW

HSMHillstoneSecurity

ManagementPlatform

Security Management& Analytics Platform

Page 24: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

Keep in touch with us

24

Address:

E-mail:

Website:

Phone:

5201 Great America Pkwy, #420, Santa Clara, CA 95054

www.hillstonenet.com

[email protected] +1-800-889-9860

THANK YOU!

Page 25: RISK 2018, Hillstone · ZTE Telecommunication.  ... Parameter 1 Sample Parameter 2 ... CompleteKill Chain Mapping

www.hillstonenet.com

Hillstone ataGlance

• Foundedin2006 byfoundingengineers fromNetscreen

• 15,000+ customersin50+countries:financial,telecom,educationetc.

• 700+ employeesglobally,>40% inengineering

Beijing

Singapore

SiliconValley

Dubai

LatinAmerica

Czech

Suzhou •ExperiencedleadershipfromNetscreen,Cisco,Juniper,Intel

WorldClassTeam

25

Mexico