CORE IMPACT Pro Presentation - Presentation Transcript
2009 CORE IMPACT Pro Demonstration Matt Hines, Marketing Manager Matt Koch, Sales Engineer
Situation Analysis – The Threat Environment Threats are … Increasingly sophisticated Well-funded and staffed Complex in breadth and depth IT environments are … Increasingly dynamic and interconnected Incorporating new technologies (i.e., potential threat vectors) Becoming mission-critical for revenue and customer service Security spending continues to increase exponentially, however: Traditional security strategies are imperfect and fragmented Organizations can’t measure overall security effectiveness or efficiently mitigate risk Organizations can’t just keep throwing money at point solutions. Need to measure what’s working, what’s not and what to do about it to assess ROI and plan future security investments
Re-thinking Vulnerability Management Traditional security testing results in data overload Network Scanners (i.e., Nessus, Retina, Qualys, etc.) identify potential flaws on your network Web Application Scanners (Watchfire, SPI, Cenzic, etc.) identify potential vulnerabilities (code issues) in applications Need to identify where critical, operational risks are Vulnerability (network and/or web application) scanning does not: Show or exploit linkages between information systems and assets Allow for cross-asset vulnerability assessment Reveal the impact of loss of information assets (only shows the "outer layer" of the onion) such as theft of intellectual property, leakage of internal communications, etc. Being 100% patched is unrealistic Patches can break critical applications Money is wasted in dealing with false positives and unnecessary patches
Penetration Testing: Think Like an Attacker Penetration Testing – Actively exploits vulnerabilities, evaluating and testing the effectiveness of security solutions by safely launching real-world attacks Looks at your network, endpoints, applications and users from the perspective of an attacker Without physically penetrating the host, application or network, there is no way to quantify / qualify an organization’s true exposure Perform penetration testing against: Servers, patches Web Applications IPS/IDS/Firewalls Client applications/users Advantages Enables you to be proactive with informed security decisions Provides efficient, precise, cost-effective remediation information Exploits vulnerabilities and exposes resources that are at risk Highlights the efficacy of defensive mechanisms
IMPACT Pro for Commercial-Grade Penetration Testing Emulates attacker behavior Launches real-world attacks in a safe & controlled manner demonstrates exactly what an attacker can do, including escalation of privileges Emulates threats against (and between) networks, applications and clients Multiple levels of control Automated modes speed previously manual, expensive processes Rapid Penetration Test (RPT) One-step testing modules: Network, Endpoint, Vulnerability Validation Manual testing mode for targeted, granular control Fully customizable exploits (Python) + add your own exploits Commercial-grade capabilities for ongoing, repeatable testing against new threats Professionally developed, commercial-grade exploits (10-20 per month) Innovative agent technology Powerful user interface for conducting, sorting and managing large tests Standard and custom reporting = actionable data Complete log of all activities Remediation information Backed by ongoing development, support and training
Web Application Testing Client-Side Testing Network Testing IMPACT Pro for Multistaged Security Testing First product to integrate security testing across three top attack avenues, replicating multistaged attacks Databases compromised during Web App testing … …can be farmed for email addresses and other personal info to use in IMPACT Client-Side Tests, which assess end-users against social engineering attacks Servers compromised via Web App Testing and workstations compromised during Client-Side testing … …can be used as beachheads from which to launch IMPACT Network Tests, which identify and validate OS and services vulnerabilities on backend systems
- CONFIDENTIAL - Trusted Vulnerability Research & Leading Threat Expertise The Knowledge Behind Our Products CoreLabs (R&D) Filtering of known vulnerabilities for operational risks Discovery of new vulnerabilities before criminals do Collaboration with software vendors to remediate Publishing of research papers and advisories Core Security Consulting Services (Core SCS) Front-line risk assessment and custom analysis Early identification of new threat vectors Defining attack patterns & point solutions exposures Core Engineering Commercial-Grade exploit creation Core Products CORE IMPACT Pro CORE IMPACT Essential
IMPACT Pro V9: New Capabilities V9 provides unprecedented visibility into overall IT security posture with: First Automated Penetration Testing Attack Graph report Visual representation of multi-staged attack behavior Central workspace repository for multiple consoles Updated PCI report with explicit CVSS vulnerability severity info New FISMA report for government entities and external contractors New Web application testing capabilities Support for DB2 as a SQL injection target – expands test coverage Fingerprinting of web application infrastructure – enables users to run known exploits for COTS, in addition to IMPACT’s dynamically created exploits Client-Side Autopwn: all, by app, by browser – increases automation by running multiple exploits at once Pre/post exploitation Password and cookie gathering – provides further evidence of at-risk assets Additional, improved OS fingerprinting – assists with attack selection v9
How Customers Use IMPACT Perform efficient, safe and cost-effective network, web application and client-side penetration testing Optimize the vulnerability management process – focus on critical issues first Verification of security defenses (e.g., IDS/IPS ) Prove security compliance with industry and internal regulations (e.g., FDIC, HIPAA, SOX, PCI, etc.) “Penetration testing that goes beyond simple vulnerability scanning needs to be performed frequently.” - John Pescatore, VP Distinguished Analyst, Gartner
CORE IMPACT Pro Comprehensive security testing software solutions based on independent, trusted vulnerability research and leading-edge threat expertise. Matt Hines matt.hines@coresecurity.com Core Security Technologies www.coresecurity.com
This is a short slide deck that serves as a brief o more
This is a short slide deck that serves as a brief overview of the value proposition of automated penetration testing and Core Security's CORE IMPACT Pro software solution. less
0 comments
Post a comment