Kaspersky Security Solutions For Enterprise 2017 - Cyber360

Transcription

Kaspersky Enterprise CybersecurityKasperskySecurity Solutions for Enterprise2017#TrueCybersecurity

Kaspersky Enterprise Security SolutionsTechnologicalBy Industries

Securing the EnterpriseKaspersky Lab is a global cybersecurity company celebrating its 20 year anniversary in 2017. Kaspersky Lab’s deep threatintelligence and security expertise is constantly transforming into security solutions and services to protect businesses,critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolioincludes leading endpoint protection and a number of specialized security solutions and services to fight sophisticatedand evolving digital threats.Taking enterprise security seriouslyThe costs of a security breach are substantial:In Kaspersky Lab’s 2016 Global IT SecurityRisks Survey, we found that the average directrecovery cost to an enterprise is US 861,000.To avoid these costs and the disruption associated with them, enterprises must strengthen the type and level of protection withintheir IT infrastructure.services – all underpinned by world-leading security intelligence – to help businesses detecttargeted attacks and mitigate the risk at an earlier stage, before severe damage is caused.By addressing every possible stage of IT incidents, Kaspersky Lab solutions deliver a holistic,adaptive and strategic approach to enterprise security. Our philosophy is straightforward: thebest intelligence combined with the best technologies delivers the best protection.Based on the security intelligence which isfundamental to all our products and services,Kaspersky Lab solutions provide prediction,prevention, detection and responsecapabilities across a variety of enterpriseinfrastructure segments and emergingtechnologies: endpoints, online and mobile,virtual infrastructure, data centers, industrialcontrol systems, and more.Kaspersky Lab is a pioneer in helping businesses to upgrade their security strategiesto better defend against the latest advancedthreats and targeted attacks. We offer aunique combination of technologies and1

Anti Targeted AttackComprehensive multi-vector discovery and risk mitigationof advanced threats and targeted attacksTargeted attacks are long-term processes that compromise security and give the attacker control over the victim’s IT,while evading detection through traditional security technologies.While some attackers use Advanced Persistent Threats (APTs), which can be very effective but expensive to implement,other ‘targeted attacks’ are much cheaper to mount and can be just as devastating. These targeted attacks, using basictechniques – social engineering, stolen employee credentials, legitimate software or even malware covered by astolen certificate – may not make the headlines, but they’re everywhere.Most enterprises have already made a majorinvestment in traditional IT security solutions, located primarily at gateway level.However, while these preventative securitytechnologies can be very effective in protecting against common threats – includingmalware, data leakage, network attacks andmore – they are clearly not enough: the overall number of business security incidents andbreaches has not decreased one iota.Today even with innovative technologieslike Sandbox, EDR and other ‘next gen’ solutions, the challenge stays the same - how tochoose the right incident and which incidentrelates to the most critical threats. Specialized discovery solutions play a core role inidentifying those incidents that most warrantfurther investigation and response.Advanced, targeted threats can typically remain undetected for 200 days or more, whilecybercriminals silently gather valuable information and / or impact vital business processes.According to Kaspersky Lab statistics, even a single targeted attack incident can cost an enterprise more than 2.5 million,compared to a starting point of 80k for the average small tomedium business. Left unchecked, a targeted attack is likely to cause severe damage to the business, including:Substantial financial lossesLoss of critical dataRemote control by the attacker of apparently ‘authorized’ business processesStealth manipulation of dataIn a survey of Enterprise organizations conducted by Kaspersky Lab in 2015, 1 in4 organizations (23%) confirmed that they had already been subjected to at least onetargeted attack.2

The Solution: Kaspersky AntiTargeted AttackThe Kaspersky Anti Targeted Attack Platformis part of an adaptive, integrated approach toenterprise security. Monitoring network traffic, combined with object sandboxing andendpoint behavior analysis, delivers detailedinsights into precisely what’s happeningright across a business’s IT infrastructure.This adaptive security approach protectsbusinesses against the most sophisticatedthreats, targeted attacks, new malware – including ransomware and crimeware – and ofcourse APTs. Multi-layered sensor architecture – for ‘all-round’ visibility. Through a combinationof Network Sensors, Web and Email Sensors and Endpoint Sensors, the Kaspersky AntiTargeted Attack Platform provides advanced detection capabilities at every level of yourcorporate IT infrastructure. Advanced Sandbox – to assess new threats. The result of over 10 years of continuousdevelopment, our Advanced Sandbox offers an isolated, virtualized environment, wheresuspicious objects can be safely executed and their behavior observed. Powerful analysis engines – for rapid verdicts and fewer false positives. Our TargetedAttack Analyzer assesses data from network and endpoint sensors, rapidly generatingthreat detection verdicts for your security team.Kaspersky Anti Targeted Attack PlatformBy correlating events from multiple layers –including network,endpoints and the globalthreat landscape – the Kaspersky Anti Targeted Attack Platform delivers near real-timedetection of complex threats, as well asgenerating critical forensic data to empowerthe investigation process.Our industry-leading Global Security Intelligence is one reason why we can deliver thissuperior detection performance. No othersecurity vendor can match the quality andbreadth of our security intelligence, enablingus to protect businesses from an ever-widening range of threats.Network ndpoint SensorsBut Global Security Intelligence is just thebeginning – the Kaspersky Anti TargetedAttack Platform also incorporates powerfuldetection and analysis technologies,including:3

Kaspersky Private Security NetworkThe comprehensive threat intelligence database for isolatednetworks and stringent data-sharing restrictionsIt takes up to four hours for standard security solutions to receive the information needed to detect and block the almost310,000 new malicious programs discovered by Kaspersky Lab every day. Threat intelligence sharing via KasperskyPrivate Security Network provides this information in 30-40 seconds.Cybercrime is growing not just in volume,but in sophistication, too: while 70% ofthreats faced by enterprises every day areknown, 30% are unknown, advanced threatsthat traditional, signature-based securityalone can’t tackle.Kaspersky Security Network deliversKaspersky Lab’s security intelligence toevery system connected to the internet,ensuring the quickest reaction times andlowest false positive rates, and maintainingthe highest level of protection – even againstunknown, advanced threats.While all information processed byKaspersky Security Network is completelyanonymized and disassociated from source,we recognize that some enterprises requireabsolute data lock-down. Traditionally thishas meant that such enterprises haven’tbeen able to avail themselves of cloudbased security solutions.The Solution: Kaspersky Private Security NetworkFor customers with these specialized needs, Kaspersky Lab has developed Kaspersky PrivateSecurity Network, allowing enterprises to take advantage of most of the benefits of cloudassisted security without releasing any data whatsoever outside their controlled perimeter.It’s an enterprise’s personal, local and completely private version of Kaspersky SecurityNetwork.Kaspersky Private Security Network addresses critical enterprise cybersecurity concernswithout a single piece of data leaving the local network. Kaspersky Private Security Network: Provides access to global statistics of URLs and Files Categorizes URLs and files with specific verdicts for malicious and whitelisted objects Minimizes the damage caused by cybersecurity incidents through real-time threatawareness Allows the addition of unique customer specific and 3rd party threat source verdicts (filehashes) Reduces false positives Complies with strict regulatory, security and privacy standards.4

Kaspersky Private Security Network applies our unique threat intelligence and information not just to Kaspersky Lab security solutions butto other solutions the enterprise may be running: including SIEM, risk management and compliance. All these capabilities can be integratedthrough SDK, direct calls and the API of Kaspersky Private Security Network, delivering a unique insight into your organization’s securityand threat readiness.Secured perimeterKasperskyPrivate SecurityNetworkKasperskySecurity NetworkKasperskySecurityCenterReputationupdates file reputation url reputation putationrequests/answers

Endpoint SecurityThe leading multi-layered endpoint protection platform, based ontrue cybersecurity technologiesThe threat environment is advancing exponentially, putting critical business processes, confidential data and financialresources at ever-increasing risk from zero-day attacks. To mitigate the risk to your organization, you need to be smarter,better equipped and better informed than the cyber-professionals targeting you. But one simple fact is true – the majority of enterprise cyber-attacks are initiated through the endpoint. If you can effectively secure every corporate endpoint,static and mobile, you have a strong foundation for your overall security strategy.With the growth of digital business, enterprise IT environments have become evermore complex. Meanwhile, cybercriminalsare adopting increasingly sophisticatedmethods of attack, creating new ways toinfiltrate corporate infrastructure.data protection tools including Integrated Encryption, Automated Patching and MobileEndpoint Protection – all managed together through Kaspersky Security Center.The majority of enterprise cyber-attacksare initiated through the endpoint. Withouteffective Global Threat Intelligence andMachine Learning, traditional security technologies can’t protect from highly sophisticated threats.The Solution: Kaspersky Endpoint SecurityWe deliver zero-second protection againstunknown and advanced threats and targetedattacks through our Advanced Detectiontechnologies, drawing on a combination ofmachine learning and threat intelligence.Protection against advanced threats isfurther enhanced by powerful control andAll components are developed in-house and form a common platform which can be easilyadapted to meet the changing needs of the organization.Fully securing every endpoint against every form of advanced cyber-threat is critical. Traditional antivirus protection is nowhere near enough. Only through employing a cutting-edgesecurity platform including machine learning for dynamic and static detection, while adopting a multi-layered approach, can you hope to fully protect every single endpoint within andbeyond your perimeter.Based on unequalled sources of real-time threat intelligence, our technologies continuallyevolve to protect your business from even the latest, most sophisticated threats, includingzero-day exploits. By aligning your security strategy with the world leaders in advancedthreat discovery, you are choosing to adopt best of breed endpoint protection, now andin future.There is no better security posture for your organization.6

Kaspersky Endpoint reProtection usingMachine LearningAutomaticExploitPreventionUnprecedented proven protection for allforms of endpointOur advanced protection technologies secure enterprise organizations and their ITinfrastructures, however complex, includingevery endpoint, from physical and virtualdesktops and servers to mobile devices.Behavior analysis using Machine Learning toprotect your businessOur solution uses Machine Learningbased on both static and dynamic datatechnologies. This is how we protect youeven from future threats.Powerful Global Threat IntelligenceAll our technologies are powered by ourproven Global Threat Intelligence. We havemade more APT discoveries than any othersecurity vendor, so we have an unequalledunderstanding of the nature of modernthreats, and can help you to better protectagainst them.ServerProtectionWeb,Applicationand yptionAutomatic real-time responseAt the instant a threat is detected, the systemwill automatically roll back any changes themalware has already instigated, as detectedby our dynamic behavior monitoring engine.Continuous dynamic protection from zero-day threats and exploitsAutomatic Exploit Prevention has beendeveloped to prevent cybercriminals fromtargeting application vulnerabilities onprotected machines. Automated PatchManagement adds a further layer of security.FIPS 140-2 Certified Data ProtectionPowerful, user-transparent encryption fullysecures confidential and sensitive data onthe move, on portable devices and at rest.Reliable protection against ransomwareKeep your data safe, avoid funding cybercriminals through ransom payments andprotect shared folders from advanced cryp-7AutomatedPatchManagementProtection forCollaboration Servers,Mail Servers andInternet Gatewaysto-lockers with our anti-ransomware technologies.A lower TCO and a higher ROI throughunified & centralized managementManage multiple platforms and all endpointdevices from the same console – increasingvisibility and control with no additionalinvestment in software, equipment orhuman resources.

Embedded Systems SecurityAll-in-one security specifically designed for Embedded systemsOperating as they do with real money and credit card credentials, Embedded systems are targets of choice for cybercriminals, so require the highest levels of focused, intelligent protection. Now is the time to apply well-proven technologies likeDevice Control and Default Deny as a first line of defense.Today we see embedded systemseverywhere: in ticketing machines, ATMs,kiosks, Point of Sale systems, medicalequipment the list goes on.Embedded systems are a particular securityconcern as they tend to be geographicallyscattered, challenging to manage and rarelyupdated. But systems working with cashand customer credentials have to be faulttolerant and resistant. Embedded devicesmust not just be protected against threatsin themselves, but must be inaccessible bycybercriminals or by an inside attacker as anentry point into the corporate network.Standard security regulations for embeddeddevices tend to cover only antivirus basedsecurity or system hardening, which isnot enough. A purely antivirus approachis of limited effectiveness against currentembedded systems threats, as has beenamply demonstrated in recent attacks.Default Deny for Applications, Drivers and Libraries, boosted by Device Control functionality,is the only approach which can ensure the safety of obsolete critical systems still in use.The Solution: Kaspersky Embedded Systems SecurityKaspersky Lab has created a security solution specifically for organizations operatingembedded systems, reflecting their unique functionality and OS, channel and hardwarerequirements, while focusing on the specific threat environment faced by these systems andfully supporting the Windows XP family.Kaspersky Embedded Systems Security offers a ‘Default Deny only’ operational mode, wheresystem requirements start from 256Mb of RAM and 50Mb HDD space for Windows XP forlow-end hardware systems.There’s also an on-demand scan mode supplied by an optional Antivirus module, including afirewall management. This module is powered by the Kaspersky Security Network, with patchmanagement facilities if required.So this single solution meets three key objectives: Efficient security for ‘difficult to manage’ systems Compliance with PCI DSS requirements 5.1, 5.1.1, 5.2, 5.3 and 6.2 A soft timeline for obsolete systems and hardware replacement8

The solution has been designed specifically to mitigate cybersecurity risks to systems based on Embedded operating systems, protecting theattack surfaces unique to these architectures while respecting related hardware and efficiency considerations. A single intuitive console givesyou the control and visibility you need to manage effective multi-layered security for your endpoints, your critical systems and your whole ITinfrastructureDefault DenyDevice ControlDriversApplicationsAntivirusUSB StoragesLibrariesKasperskyEmbedded SystemsSecurityApplicationsDriversLibrariesUSB Storages9

Cybersecurity ServicesThreat Intelligence, Security Training, Incident Response andAssessment from the world leader60% of large enterprises plan to utilize threat intelligence services in their security strategy.Sophisticated threats are constantlyemerging, and cybercriminals are developinginnovative techniques to outsmartestablished security technologies. Traditionalsecurity solutions such as antivirus, firewalland intrusion prevention systems aloneare no longer enough for comprehensiveprotection – today, a new security approachbased on threat intelligence and extensiveexpertise is required to fill this security gap.By sharing our up-to-the-minuteintelligence with our customers, KasperskyLab helps enterprises to guard againstthreats. Our broad range of intelligenceservices helps ensure your SecurityOperations Center (SOC) and/or IT securityteam is equipped to protect the businessfrom the latest online threats.Cybersecurity TrainingCybersecurity awareness and education are critical requirements for enterprises faced withincreasing volumes of constantly evolving threats.Your in-house security specialists need to be skilled in the advanced security techniques thatform a key component of effective enterprise threat management and mitigation strategies,while all employees should have a basic awareness of the dangers, and of how to worksecurely.We offer a portfolio of Cybersecurity Awareness training, as well as a broad curriculum oftraining programs ranging from basic to expert level in digital forensics and malware analysis. Cybersecurity Awareness helps enterprises improve their employees’ security skills – and,as a result, their corporate security. Security Education for IT Security Professionals, at all levels, improves the skills of yourin-house security experts and minimizes the risk of incidents.10

Threat IntelligenceExpert ServicesDoes your SIEM system have adequatecyberthreat detection capabilities? Can yoube sure that you’ll be warned in good timeabout the most dangerous threats? Ourportfolio of Threat Intelligence Services isdesigned to equip enterprises to managethese risks:Is your in-house expertise sufficient to resolve a cyber-incident? Is your IT infrastructureand are your specific applications fully secured against potential cyber-attack? Our ExpertServices are designed to mitigate and resolve these risks: Threat data feeds: enhance your SIEMsolution and improve forensic capabilitiesusing our up-to-the-minute cyberthreatdata. Application Security Assessment Uncover vulnerabilities in applications, from largecloud-based solutions, ERP systems, online banking and other specific business apps toembedded and mobile apps on different platforms. APT Intelligence Reporting deliversexclusive, proactive access todescriptions of high-profile cyberespionage campaigns, includingIndicators of Compromise (IOCs). Penetration Testing: Learn how to identify the weakest points in your infrastructure andavoid damage caused by cyberattacks. Ensure compliance with government, industry andcorporate standards (e.g. PCI DSS). Digital Forensics and Malware Analysis: Reconstruct a detailed picture of any incidentusing comprehensive reports, including incident remediation steps. Customer-specific Threat IntelligenceReporting identifies externally availablecritical components of your network.11

Cybersecurity AwarenessBuilding a safe corporate cyber-environment with gamified trainingMore than 80% of all cyber-incidents are caused by human error. On average, enterprises pay 861,000 to recover from asecurity breach, while SMBs spend 86,500. Phishing attacks alone cost up to 400 per employee per year.Enterprises lose millions recoveringfrom staff-related incidents – but theeffectiveness of traditional trainingprograms intended to prevent theseproblems is limited, and they usually failto engender the desired behavior andmotivation.Kaspersky Lab has launched a family of computer-based training products that leveragemodern learning techniques and address alllevels of the organizational structure. Ourtraining program has already proved its effectiveness – both for our customers and for ourKaspersky Lab partners: Up to 90% decrease in the number ofincidents 50-60% reduction in potential monetarylosses associated with cyber-risks Up to 93% probability of knowledge beingused in daily life 86% of participants would recommendtheir course to colleagues.Kaspersky Security AwarenessTraining ProductsSenior ManagersLine ManagersAll EmployeesIT Security andSpecialists12KIPSStrategy andcorporate supportCyberSafetyManagement GamesEmployee SkillsTraining PlatformCyberSafety Culture AssessmentChanging Hearts and MindsCyber-safebusiness decisionsPersonal cyberhygiene skillsUnderstanding,measurementand persuasion

Winning ApproachHow It Works Building behavior, not just deliveringknowledge: the learning approachinvolves gamification, learning-by-doing,group dynamics, simulated attacks,learning paths, automated reinforcementof skills, etc. This results in strongbehavioral patterns and produces longlasting cybersecurity improvements; The training covers a wide range of security issues – from data leakage and ransomwareto internet-based malware attacks, safe social networking and mobile security. Serious, practical content (based on thepower of Kaspersky Lab R&D) deliveredas a series of interactive exercises finetuned to meet the business needs andtime/format preferences of differentorganizational levels: senior managers,line managers, average employees; Training features analytical and reporting tools that measure employee skills and learningprogress, as well as program effectiveness on a corporate level. The continuous learning methodology fuels a constant reinforcement of skills and drivesmotivation deep into the organization. Training courses which address different organizational levels and functions togethercreate a collaborative CyberSafety culture, shared by everyone and driven from the top. Educational plans and best practices provided by Kaspersky Lab facilitate programimplementation and help the customer’s IT Security and T&D teams get the most out ofSecurity Awareness initiatives. Real-time measurement, painlessprogram management: purpose-builttraining software delivers automatedtraining assignments, skills assessments,and reinforcement through repeatedsimulated phishing attacks and autoenrolment in training modules. Coursescan be managed and delivered byKaspersky Lab partners or by thecustomer’s own T&D teams (Trainthe-Trainer programs and support areprovided by Kaspersky Lab).13

Cloud SecurityBorderless security engineered for your hybrid cloudWhen it comes to virtual systems security, enterprises look for the right balance between protection and performance,as well as the most advanced security capabilities to keep business-critical processes safe.On average, data breaches involving virtual systemsare more than twice as costly as those involvingphysical machines.Total Direct Damages and CostTotal Reactive Spend 942K 454KNo InvolvementInvolvingvirtual systemsEnterprisesSource: KasperskyLab Global Risks Survey 2015As enterprises continue to roll out virtualizedenvironments across more of their IT estate,there is an increasing need for securitydesigned specifically for virtualization. Butfinding a solution which provides securitycapabilities both for your growing VirtualDesktop Infrastructure (VDI) and your virtualserver environment, while retaining all theperformance benefits of virtualization, is noteasy. With all its advantages, virtualizationalso creates additional ‘attack surfaces’,presenting cybercriminals with even moreopportunities to target very large businesses.solutions. Scanning and update storms arenow eliminated, together with windowsof vulnerability or ‘instant-on’ gaps. Withadditional layers of protection combinedwith network attack blocking mechanisms,Kaspersky Lab’s solution takes corporatevirtualization platform security to a new level.The solution securing your virtualizedinfrastructure should deliver uninterruptedprotection, providing enhancedfunctionality while still preserving theefficiency of your virtual infrastructure.While an attack on physical nodes leads to thetemporary loss of access to business-criticalinformation in 36% of incidents reported, thisrises to 66% when the breach affects virtualservers and desktops.The unique architecture of Kaspersky Lab’sspecialized solution provides efficient multilayered virtual machine (VM) protectionwithout sacrificing performance. Theresult is significantly higher consolidationratios than with traditional anti-malware14For a large Enterprise, the average cost ofrecovering from a virtual security breach isover US 940.000, twice as much as for acomparable incident involving only physicalinfrastructure.

The Solution: Kaspersky SecurityFor VirtualizationKaspersky Lab offers two technologieswhich allow you to achieve that perfectbalance of optimum security and preservedperformance.While our agentless solution operates inharness with core hypervisor technologies(such as VMware NSX), our light agent solution offers additional layers of protection toeach VM.To protect VMs, enterprises need only deploy a single Security Virtual Machine (SVM),to which file-level scan tasks can be offloaded. This SVM provides centralized anti-malware protection for all VMs on the host withno extra resource consumption. Built-infault tolerance and redundancy gives yoursecurity solution the reliability you need forsuccessful business operations.Deploying a Light Agent on each VM meansthat multi-layered protection and feature-rich security controls can be addedto the mix. Security for your VMs, whetheragentless, light agent based or both, canbe managed, together with your physicalendpoints servers and your mobile devices,from a single console.Kaspersky lab’s unique Light Agent technologyLight AgentSecurity Virtual Machine (SVM) Enhanced security for servers and VDI Memory and Processes protection Apps, Device, Web and Mail control Exploit Prevention & Anti-ransomware For Windows and Linux servers Full scanning enqine Complete full-sizes AV databases Scan task orchestration Redundancy and fault-toleranceKaspersky Security for Virtualization is tightly integrated with most popular virtualizationplatforms — VMware vSphere with NSX, KVM, Microsoft Hyper-V and Citrix XenServer.Our security solution is optimized to safeguard platform performance by fully exploitingyour hypervisor’s own core technologies – complementing and enhancing security in, forexample, VMware Horizon and Citrix XenDesktop VDI.Kaspersky Security for Virtualization can be licensed in two ways, depending on your business needs and the characteristics of your virtual infrastructure:by the number of virtual machines (desktops plus servers) or by the number of host server physical processor cores.15

Data Center SecurityEmpowering your data center to detect and respond to the mostadvanced cyberthreatsSoftware-defined data centers need just as much protection as their traditional counterparts. Fail in this, and your virtualizedsystems and data storages become the weakest link in your data center security chain.Large enterprises are processing ever-increasing levels of data. To keep pace withthis escalation, organizations need to rethinknot just how they store and access data, buthow they preserve its safety and integrity.The larger the infrastructure, the greater thequantity of sensitive business data retained,and the more power and reliability demanded of the security solution protecting it.with your existing IT environment, or it will drag down data center performance levels andreduce overall operational efficiency as you grow.Regardless of whether you operate yourown data center or use the services of thirdparty (through Infrastructure-as-a-Serviceor IaaS), your security solution should notonly protect all critical data effectively andcontinuously: it should also preserve theperformance of data center infrastructure. Security specifically built for major virtualization platforms, including VMware with NSX,Citrix, Microsoft and KVM. Security for network attached storage (NAS) systems including EMC, NetApp, DELL, IBM,Hitachi and Oracle.Any data center offers numerous attacksurfaces vulnerable to potential exploitation. And as your data center grows insize, it’s bound to grow in complexity also,offering even more opportunities to thecybercriminal fraternity. Your security solution must step up to the challenge and scaleeffectively, which means fully integratingThe Solution: Kaspersky Security For Data CentersWe offer solutions that focus on protecting the two essential areas of your data center: yourvirtual infrastructure and your

Kaspersky Security Network Kaspersky Mobile Security Kaspersky Security Center file reputation url reputation patterns . Management Server Protection Web, Application and Device Controls Enterprise Mobility Management Data Encryption Automated Patch Management Protection for Collaboration Servers, Mail Servers and