This is Part 3 of our blog series about NG-Firewalls. See Part 1 here.
Part 3: Challenges of the Typical NGFW
What good is a malicious verdict on something that had already penetrated the system?
There is no system in the world that can stop 100% of attacks/attackers 100% of the time, so infection is an inevitability that must be anticipated. Something WILL get through and when it does, the quality of your threat system and incident response plan will surely be tested. The Cisco Firepower Threat-focused NGFW is designed to understand what has happened through the entire life cycle and to be able to make immediate and automatic adjustments to contain the threat and provide the Practitioner with the forensic details necessary to manage and respond to the incident.
Typical NGFW solutions add on extra defense systems (malware sandboxes, URL gateways, etc.) in an attempt to avoid this altogether with the focus on point-in-time prevention. Whether a Typical NGFW or a Threat-focused one, all use technologies like Threat Intelligence cloud lookups of known malware signatures, or even sandboxing to allow the full progression of an ‘unknown’ to operate in a contained environment and ultimately determine if clean or malicious so it can be given an accurate disposition at the initial point-in-time. How they are used is the critical point. While a threat-focused firewall integrates these functions into its core, the Typical NGFW leverages less-integrated add-on components in order to go back to step 1 and try to deny what shouldn’t get through at first sight – attempting to prevent everything with that binary decision. Great idea, except for a few critical deficiencies: First, most modern malware is sandbox-aware and only used once. Therefore, if it runs in a sandbox it may not execute the same way as it would in the wild. Signatures are only good for the 2nd time malware is seen, so a cloud lookup isn’t, with or without sandboxing, enough to confirm an unknown that only ever has one instantiation.
Continue reading “Threat-Focused NG-Firewall – Who Cares? Part 3”
CONNECT WITH US