{"id":40268,"date":"2022-07-20T11:15:00","date_gmt":"2022-07-20T11:15:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/40268"},"modified":"2022-07-20T11:15:00","modified_gmt":"2022-07-20T11:15:00","slug":"cato-aims-to-bust-cyber-myths-as-it-extends-network-protections","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=40268","title":{"rendered":"Cato aims to bust cyber myths as it extends network protections"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/cato-aims-to-bust-cyber-myths-as-it-extends-network-protections.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>As <a href=\"https:\/\/www.computerweekly.com\/blog\/Networks-Generation\/SASE-The-Importance-Of-Spelling-It-Out-In-Full\">secure access service edge<\/a> (SASE) specialist&nbsp;<a href=\"https:\/\/www.catonetworks.com\/\">Cato Networks<\/a> burnishes its cyber credentials with the addition of multiple features to its platform, the company\u2019s senior director of security strategy, Etay Maor, has urged users to challenge some of their preconceptions around security, using data drawn from Cato\u2019s global network to counter some established cyber \u201ctruths\u201d.<\/p>\n<p>In June 2022, Cato became the first SASE supplier to add network-based ransomware protection to its platform, combining <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/heuristic\">heuristic algorithms<\/a> that scan <a href=\"https:\/\/www.techtarget.com\/searchnetworking\/definition\/Server-Message-Block-Protocol\">server message block (SMB) protocol<\/a> flows for attributes such as file properties and network or user behaviours, with the deep insights it already has into its network traffic from its day-to-day operations.<\/p>\n<p>The algorithms were trained and tested against the firm\u2019s existing data lake drawn from the Cato SASE Cloud \u2013 which holds over a trillion flows from Cato-connected edges.<\/p>\n<p>The firm claims this will let it spot and stop the spread of ransomware across an organisation\u2019s network by blocking SMB traffic to and from the source device to prevent lateral movement and file encryption.<\/p>\n<p>Speaking to Computer Weekly, Maor, who joined Cato from <a href=\"https:\/\/intsights.com\/\">IntSights<\/a>, and is also an adjunct professor at the <a href=\"https:\/\/www.bc.edu\/bc-web\/schools\/wcas.html\">Woods College of Advancing Studies at Boston College<\/a>, described <a href=\"https:\/\/www.computerweekly.com\/news\/252521980\/Black-Basta-ransomware-crew-aiming-for-big-leagues\">a Black Basta ransomware attack<\/a> to which he responded, in which the victim \u2013 an unnamed US organisation \u2013 could have benefited from this.<\/p>\n<p>When he gained access to the victim\u2019s security logs, Maor found that all the information that a ransomware attack was incoming was there, the <span>security operations centre (<\/span>SOC) team had just not been able to see it.<\/p>\n<p>\u201cI know it\u2019s cool to get to sit in front of six screens, but what SOC analysts are trying to do is gather so much information and put it all together, so I understand why stuff is missed,\u201d he said.<\/p>\n<p>\u201cIn this case, it was remote desktop [RDP] to an Exchange server. Yes, they said, but that Exchange server doesn\u2019t exist anymore so why attack a server that\u2019s not there? So I had to introduce them to ransomware as a service [RaaS].<\/p>\n<p>\u201cWhat happened was someone else who attacked them sold their network data to someone else who wrote a script to automate the attack. They weren\u2019t there for weeks, they were there for a minute, they didn\u2019t know the victim had changed their Exchange server, but got lucky somewhere else.<\/p>\n<p>\u201cSo if you can see east-west traffic, like an attempt to connect to a server that isn\u2019t there, that should be a red flag to the SOC,\u201d he explained. \u201cWe created our heuristic algorithms to look for these quirks.\u201d<\/p>\n<p>Maor said he wanted to explode the myth \u2013 favoured by presenters at security conferences \u2013 that attackers need to get lucky only once, while defenders need to get lucky all the time.<\/p>\n<p>\u201c<a href=\"https:\/\/www.computerweekly.com\/ehandbook\/MITRE-ATTCK-a-guide-for-businesses-in-2022\">When you look at MITRE ATT&amp;CK<\/a> and see how attackers operate, you soon see that saying is the opposite of the truth. Attackers have to be successful at phishing, gaining an endpoint, lateral movement, privilege escalation, downloading malware payloads, et cetera.<\/p>\n<p>\u201cYou actually realise that attackers need to be right all the time, but defenders need to be right only at one point to protect, defend and mitigate,\u201d he said.<\/p>\n<p>Cato is now going further still, adding a <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/data-loss-prevention-DLP\">data loss prevention<\/a> (DLP) engine to protect data across all enterprise applications without needing to implement \u201ccomplex and cumbersome\u201d DLP rules. It forms part of Cato\u2019s SSE 360 architecture and is designed to solve for what the firm describes as the limitations with which traditional DLP solutions are fraught.<\/p>\n<p>For example, legacy DLP may have inaccurate rules that block legitimate activities \u2013 or, worse still, allow illegitimate ones \u2013 while a focus on public cloud applications is leaving sensitive data in proprietary or unsanctioned applications exposed.<\/p>\n<p>Added to that, investment in legacy DLP solutions does not help provide protection from other threat vectors.<\/p>\n<p>Cato believes it has these problems licked by introducing scanning across the network for sensitive files and data that is defined by the customer. It is capable of identifying more than 350 distinct data types, and once identified, customer-defined rules will block, alert or allow the transaction.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Threat visibility\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Threat visibility<\/h3>\n<p>Since joining Cato, Maor has been creating quarterly threat landscape reports using data drawn from the firm\u2019s global network, and the latest edition of this report also challenges established cyber thinking in many ways.<\/p>\n<p>For example, to spend a few days immersed in the security community, one might reasonably expect that most cyber attacks originate from within countries such as China or Russia, but Cato\u2019s data reveal this is far from the case.<\/p>\n<p>In fact, during the first three months of 2022, the most malicious activity was initiated from within the US, followed by China, Germany, the UK and Japan. Note this data is related to malware <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/command-and-control-server-CC-server\">command and control<\/a> (C2) communications, therefore the data reveals what countries host the most C2 servers.<\/p>\n<p>Maor said that understanding where attacks really originate from should be a crucial part of a defender\u2019s visibility into threats and trends. Attackers know full well that many organisations will add countries such as China or Russia to their deny lists or at the very least closely inspect traffic from those jurisdictions \u2013 therefore, he said, it makes perfect sense for them to base their C2 infrastructure in countries that organisations perceive as safer.<\/p>\n<p>Cato\u2019s report also pulled data on the most-abused cloud applications \u2013 Microsoft, Google, RingCentral, AWS and Facebook in that order \u2013 with Telegram, TikTok and YouTube also in vogue, likely <a href=\"https:\/\/www.computerweekly.com\/news\/252514111\/Use-of-encrypted-Telegram-platform-soars-in-Ukraine-Russia\">as a result of the Russia-Ukraine war<\/a>.<\/p>\n<p>The report also showed the most targeted common vulnerabilities and exposures (CVEs) \u2013 predictably, Log4Shell was the runaway \u201cwinner\u201d here, with more than 24 million exploit attempts seen in Cato\u2019s telemetry,&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2009-2445\">but in second place was CVE-2009-2445<\/a>, a 13-year-old vulnerability in Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) that lets an attacker read arbitrary JSP files via an alternate data stream syntax.<\/p>\n<p>\u201cWith such old vulnerabilities, people are completely unaware of them,\u201d said Maor. \u201c[It shows] the way defenders look at the network is completely different from how attackers do \u2013 defenders will send me a PDF visual file of their servers, <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definitions\/page\/2\">DMZ<\/a>, cloud, et cetera, [but] attackers will say, \u2018Hey, you have a 14-year-old server, that\u2019s interesting\u2019.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>As secure access service edge (SASE) specialist&nbsp;Cato Networks burnishes its cyber credentials with the addition of multiple features to its platform, the company\u2019s senior director of security strategy, Etay Maor, has urged users to challenge some of their preconceptions around security, using data drawn from Cato\u2019s global network to counter some established cyber \u201ctruths\u201d. In [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":40269,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-40268","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/40268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40268"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/40268\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/40269"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=40268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=40268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}