© Copyright Fortinet Inc. All rights reserved.
La sécurité Globale de votre SI
du Poste de Travail au Cloud
BOULEIMEN Kamel
Manager System Engineer
3Fortinet - Confidential
2015: Another Record Year of Security Breaches
V-Tech
4.3 M exposedUS Federal
Government
OPM
21.5M +
IRS
100,000 + Taxpayer
personal information
T-Mobile
15M customers at
risk for personal and
social security data
Anthem
One-thirAmricans
affected
Hacking
Team
Ashley Madison
37M Innocent
Cheaters
Carphone
Warehouse
2.4M Users - 4% of
UK Population
UCLA Health
Twitter
Scottrade
4.6M customers
Excellus
BlueCross BlueShield
10M Patient Records
Talk Talk
157,000
customers,
21,000 bank
details stolen
British Gas
2,000
customer data
Hello Kitty
Personal information
for 3.3 million
accounts
Source: DataBreaches.net
4Fortinet - Confidential
Economic Crimes in the World
TOP FOUR
Cybercrime is Now One of the
5Fortinet - Confidential
COMPOUNDED CYBERCRIME
CRIMEWARE PRODUCERS
Source
Code
Junior
Developers
Copy & paste
Senior
Developers
Exploits Packers Special
Platforms
Mobile
CRIME SERVICES ENABLERS
Quality Assurance
Crypters / Packers
Scanners
Hosting
Infections / Drop
Zones
Management
Botnet Rentals
Installs / Spam /
SEO / DDoS
Money Mules
Accounts Receivable
Consulting
Affiliates
Criminal
Organizations
Sales, Licensing,
Maintenance
Partnerships
Affiliate Programs
FakeAV / Ransomware / Botnets
Victims
Bank
Accounts
Credential
s & Data
Digital
Real
Estate
Cybercriminal Ecosystem
6Fortinet - Confidential
Infrastructure. Constant Change.
Green
Google’s 13 data
centers use 0.01%
of global power
SDN/NFV
Software-defined
everything. SD WAN
SaaS
On average, companies
have 10+ applications
running via the Cloud
IaaS
Security still the
No.1 inhibitor
IoT
35B devices, mostly
headless attaching
to the network
Virtualization
80% of data center
apps are virtualized
Mobile
No control of
endpoints (BYOD)
Social
Bandwidth ever
increasing
Bandwidth
Wi-Fi speeds rival LANs.
100G networks here
Analytics
Big Data
Internet 2
100 Gbps and
UHDTV
5GWireless
FUTURE
100G
7Fortinet - Confidential
CLOUD SPEEDIoT
Infrastructure. Constant Change.
20 Billion
IoT devices
connected
by 2020
82%
of Enterprises
have a
multi-cloud
strategy
4X
Growth
in
100G ports
8Fortinet - Confidential
VOLUME COMMERCIALADVANCED
Security. Moving Landscape.
500,000
IPS
Attacks
Per
Minute
Item Cost
Zero Day $5K - $50K
Exploit Kit $1K - $20K
Botnet Rental 10 cents
Spam 100,000 $120
Kill Chain
Reconnaissance
Further Exploitation
Host Infection
Malware Action
1
Infiltration Vector
Exfiltration Vector
2 3
456
9Fortinet - Confidential
Per Minute
35,000 Threat events
21,000 Spam emails intercepted
545,000 Network intrusions resisted
95,000
Malware programs
neutralized
170,000 Malicious websites blocked
310,000
Botnet C&C attempts
thwarted
43M
Website categorization
requests
Per Week
46M
New & updated
spam rules
100
Intrusion prevention rules
generated
1.8M New & updated AV definitions
1.4M New URL ratings
8,000
Hours of threat research
globally
Total Database
290
Terabytes of threat
samples
18,000 Intrusion prevention rules
5,800 Application control rules
250M
Rated websites in
78 categories
312 Zero-day threats discovered
Threats. Huge Volumes.
10Fortinet - Confidential
REGULATORY CERTFICATIONGOVERNMENT
Regulatory Compliance. Evolving Requirements
11Fortinet - Confidential
Accidental Architecture
Routers
Switches
Wireless Access
NETWORK
TEAM
MESSAGING
TEAM
SECURITY
TEAM
OS
TEAM
Firewall
IPS
Web Application
Desktop OS
Antivirus
Mobile Device Mgmt
Email
Instant Messaging
Voice
Unified
Communication
Many Isolated Point Solutions
13Fortinet - Confidential
The attack surface has increased dramatically, everywhere,
inside and out.
PoS
IoT
UTM
NGFW
Campus
Mobile
Endpoint
Data Center
DCFW
Branch
Office
Internal External
14Fortinet - Confidential
End-to-End Segmentation
Branch
Office
PoS
IoT
UTM
Data Center
Cloud
SDN Orchestration
NGFW
Campus
Mobile
Endpoint
Data Center
DCFW
Internal
External
15Fortinet - Confidential
Fortinet Security Fabric – Protecting from IoT to Cloud
Client Security
Network Security
Application
Security
Cloud Security
Secure WLAN Access
Alliance Partners
Secure LAN Access
IoT
Fortinet
Security Fabric
Global Intelligence
Local
Intelligence
16Fortinet - Confidential
Fortinet Security Fabric
AccessEndpoint Application Cloud
NOC/SOC
Advanced
Threat Intelligence
Network
Fabric Ready
• Scalable
• Aware
• Secure
• Actionable
• Open
18Fortinet - Confidential
Parallel Path Processing (PPP)
Packet
Processing
Content
Inspection
Policy
Management
Scalable - The Fabric covers the entire network attack
surface (From IoT to Cloud)
Slow is Broken
CPU Only
Policy Management
Packet Processing
Deep Inspection
More Performance
Less Latency
Less Power
Less Space
CPU
Optimized
SoC
CP 9 SoC 3
19Fortinet - Confidential
Scalable - The Fabric scales from IoT to Cloud
Access
PointEndpoint
Distributed
Firewall
NGFW
Data Center
Firewall
Carrier Class
Firewall
Email & Web
Security
Private & Public
Cloud Security
Switch
1 Tbit/s
1 Gbit/s
21Fortinet - Confidential
Aware - The Fabric gives you complete visibility enabling
network segmentation
Visibility Segmentation
Automated
Operation
Fabric wide policy control
Synchronized configuration
Discovery
Data Flow
All Elements
Connectivity
22Fortinet - Confidential
Aware – Visualization of the Security Architecture
Internal Segmentation FW
NGFW
Data Center FW
Distributed
Firewall
Cloud
Firewall
Access Point
Switch
Access Point
Internal Segmentation FW
Internal Segmentation FW
Endpoint
Endpoint
Endpoint
Global
Management
Real-Time Network Topology and Interaction (Physical/Functional)
23Fortinet - Confidential
Aware - The Fabric gives you complete visibility
24Fortinet - Confidential
Aware - The Fabric gives you complete visibility
25Fortinet - Confidential
Secure – The Fabric shares Global and Local Threat
Intelligence and Mitigation Information
Global
Threat Intelligence
Cooperation
Rapid CommunicationUnknown ThreatsKnown Threats
Local
Threat Intelligence
26Fortinet - Confidential
Secure - Rapid Cooperation to Stop Threats across the
Entire Attack Surface
Global
Intelligence
Local
Intelligence
FortiMail
(Email Security)
FortiWeb
(Web Application)
FortiGate
(Firewall)
FortiClient
(Endpoint Security)
27Fortinet - Confidential
Device Access Network Cloud
Distributed
Enterprise
Edge Segmentation
Branch
Data Center
North-South
Carrier Class
SDN/NFV Private Cloud IaaS/SaaS
WLAN / LAN
Rugged
Embedded System on a Chip Packet and Content Processor ASIC Hardware Dependent
Device
>1G
Appliance
>5G
Appliance
>30G
Appliance
>300G
Chassis
>Terabit
Virtual Machine
SDN/NFV
Virtual Machine
On Demand
Client
Endpoint/IoT
Applicatio
n
Security
FLOW
Appliance
Virtual
Cloud
Secure – The Fabric cover all the possible attack vectors such
as Network, Endpoint Access, Web, Email and Cloud
Security
Updates
IPS AVAPPFW VPN
28Fortinet - Confidential
Actionable – The Fabric provides real time Security
Alerts, Recommendations and Audit Reports
5
Fabric
Element
Alert
Audit
Report
Critical5
Critical4
Critical3
Rank Severity Recommendation
Zero Day Vulnerability
Not connected to Fabric
Logging Disabled Regulatory
Template
29Fortinet - Confidential
FortiMail
FortiClient
FortiGate
Advanced
Threat
Protection
Appliance Virtual Cloud
App Control Antivirus Anti-spam
IPS Web App Database
Web
Filtering
Vulnerability
Management
Botnet
Mobile
Security
Cloud
Sandbox
Deep
App Control
Partner
FortiWeb
Actionable – The Fabric cuts Time to Protect from hours
to seconds
30Fortinet - Confidential
Continuous Monitoring and Analytics
Prepare
Segmentation
Processes
Training
Prevent
Harden
Isolate
Network
Application
Endpoint
Detect
ATP
SIEM
TIS
Respond
Contain
Remediate
Clean
1
2
3
4
31Fortinet - Confidential
End-to-End Security Operations
Sandbox to SIEM
Automation
Custom Feed
Security Analysts
Sandbox IOC
Extraction
Samples Sent for
Automated Extraction
Restful
API
Telemetry Flow
2M+ Sensors
50B+ Daily
Events
FortiGuard Global CTI
FP Reduction
Global Context
Global CTI
Database
Value-
Added
Services
Customers
QA
CTI
Platform
SIEM
SOC /
MSS
001001
101100
100011
Respond
32Fortinet - Confidential
Actionable – The Fabric provides real time Security
Audits and Recommendations
Security
Audit
Recommendations based
 on security posture
 Policy Audit
 Vulnerability awareness
33Fortinet - Confidential
Open – The Fabric allows integration of existing security
solutions
SIEM
Private
Cloud
(SDN)Endpoint
Public
Cloud
Vulnerability
Management
34Fortinet - Confidential
Open– The Fabric allows integration of other security
technologies
SDN/NFV Cloud Endpoint
Management Systems Integrator SIEM
Alliances Partners
THE FORTINET SECURITY FABRIC
REALIZED
37Fortinet - Confidential
FORTINET SECURITY FABRIC
DDoS Protection
Database
Protection
Web Application
Firewall
Application
Delivery
Controller
Top-of-Rack
BRANCH
OFFICE
Distributed Ent FW
LTE Extension
Endpoint
Protection NGFWSecure Access
Point
IP Video
Security
Email
Server
Web Servers
SDN, Virtual
Firewall
DCFW/
NGFW
Sandbox
Internal
Segmentation
FW
Sandbox
Switching
Internal
Segmentation FW
Email
Security
Internal
Segmentation
FW
CAMPUS
Internal
Segmentation FW
DATA CENTER/PRIVATE CLOUD
Virtual
Firewall
FortiCloud
Client Devices
Client Devices
PUBLIC CLOUD
OPERATIONS CENTER
38Fortinet - Confidential
FORTINET SECURITY FABRIC
DDoS Protection
Database
Protection
Web Application
Firewall
Application
Delivery
Controller
Top-of-Rack
BRANCH
OFFICE
LTE Extension
Endpoint
Protection
FortiGate
NGFW
Secure Access
Point
IP Video
Security
Email
Server
SDN, Virtual
Firewall
FortiGate
DCFW/
NGFW
Sandbox
FortiGate Internal
Segmentation FW
Sandbox
Switching
FortiGate Internal
Segmentation FW
Email
Security
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
CAMPUS
Client Devices
DATA CENTER/PRIVATE CLOUD
Web Servers
ENTERPRISE
FIREWALL
FortiGate/FortiWiFi
Distributed Ent FW
Client Devices
FortiManager
FortiAnalyzer
FortiSIEM
OPERATIONS CENTER
Virtual
Firewall
FortiCloud
PUBLIC CLOUD
39Fortinet - Confidential
FORTINET SECURITY FABRIC
DDoS Protection
Database
Protection
Web Application
Firewall
Application
Delivery
Controller
Top-of-Rack
BRANCH
OFFICE
LTE Extension
CAMPUS
Secure Access
Point
IP Video
Security
Switching
FortiGate
NGFW
FortiGate
DCFW/
NGFW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate VMX
SDN, Virtual
Firewall
DATA CENTER/PRIVATE CLOUD
Web Servers
ENTERPRISE
FIREWALL
Client Devices
CLOUD SECURITY
Client Devices
Endpoint
Protection
Email
Server
Sandbox
Sandbox
Email
Security
OPERATIONS CENTER
Fortinet
Virtual Firewall
FortiManager
FortiAnalyzer
FortiSIEM
FortiCloud
PUBLIC CLOUD
FortiGate/FortiWiFi
Distributed Ent FW
40Fortinet - Confidential
FORTINET SECURITY FABRIC
DDoS Protection
Database
Protection
Application
Delivery
Controller
Top-of-Rack
BRANCH
OFFICE
LTE Extension
CAMPUS
FortiClient
Secure Access
Point
IP Video
Security
Switching
FortiGate
NGFW
FortiGate
DCFW/
NGFW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate VMX
SDN, Virtual
Firewall
DATA CENTER/PRIVATE CLOUD
Web Servers
CLOUD SECURITYADVANCED THREAT
PROTECTION
ENTERPRISE
FIREWALL
FortiClient
FortiSandbox
FortiClient
FortiSandbox
FortiMail
Email Security
Email
Server
FortiWeb
Web Application
Firewall
OPERATIONS CENTER
FortiManager
FortiAnalyzer
FortiSIEM
Fortinet
Virtual Firewall
FortiCloud
PUBLIC CLOUD
FortiCloud Sandboxing
FortiGate/FortiWiFi
Distributed Ent FW
41Fortinet - Confidential
FORTINET SECURITY FABRIC
Top-of-Rack
BRANCH
OFFICE
LTE Extension
CAMPUS
FortiClient
Secure Access
Point
IP Video
Security
Switching
FortiGate
NGFW
FortiGate
DCFW/
NGFW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate VMX
SDN, Virtual
Firewall
FortiDDoS Protection
FortiWeb
Web Application
Firewall
FortiADC
Application
Delivery
Controller
DATA CENTER/PRIVATE CLOUD
Web Servers
FortiGate Internal
Segmentation FW
APPLICATION
SECURITY
ENTERPRISE
FIREWALL
FortiClient
FortiSandbox
FortiClient
FortiSandbox
FortiMail
Email Security
FortiDB
Database
Protection
CLOUD SECURITYADVANCED THREAT
PROTECTION
Email
Server
OPERATIONS CENTER
FortiManager
FortiAnalyzer
FortiSIEM
Fortinet
Virtual Firewall
FortiCloud
PUBLIC CLOUD
FortiCloud Sandboxing
FortiGate/FortiWiFi
Distributed Ent FW
42Fortinet - Confidential
FORTINET SECURITY FABRIC
FortiWeb
Web Application
Firewall
FortiADC
Application
Delivery
Controller
Top-of-Rack
BRANCH
OFFICE
FortiExtender
LTE Extension
CAMPUS
FortiClient
Secure Access
Point
IP Video
Security
FortiGate
NGFW
FortiGate
DCFW/
NGFW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate Internal
Segmentation FW
FortiGate VMX
SDN, Virtual
Firewall
FortiDDoS Protection
FortiGate Internal
Segmentation FW
DATA CENTER/PRIVATE CLOUD
Web Servers
SECURE ACCESS APPLICATION
SECURITY
ENTERPRISE
FIREWALL
FortiClient
FortiSandbox
FortiClient
FortiSandbox
FortiMail
Email Security
FortiSwitch
Switching
CLOUD SECURITYADVANCED THREAT
PROTECTION
FortiSwitch
Switching
Email
Server
FortiDB
Database
Protection
OPERATIONS CENTER
FortiManager
FortiAnalyzer
FortiSIEM
Fortinet
Virtual Firewall
FortiCloud
PUBLIC CLOUD
FortiCloud Sandboxing
FortiCloud AP Management
FortiGate/FortiWiFi
Distributed Ent FW
Fortinet k

Fortinet k

  • 1.
    © Copyright FortinetInc. All rights reserved. La sécurité Globale de votre SI du Poste de Travail au Cloud BOULEIMEN Kamel Manager System Engineer
  • 2.
    3Fortinet - Confidential 2015:Another Record Year of Security Breaches V-Tech 4.3 M exposedUS Federal Government OPM 21.5M + IRS 100,000 + Taxpayer personal information T-Mobile 15M customers at risk for personal and social security data Anthem One-thirAmricans affected Hacking Team Ashley Madison 37M Innocent Cheaters Carphone Warehouse 2.4M Users - 4% of UK Population UCLA Health Twitter Scottrade 4.6M customers Excellus BlueCross BlueShield 10M Patient Records Talk Talk 157,000 customers, 21,000 bank details stolen British Gas 2,000 customer data Hello Kitty Personal information for 3.3 million accounts Source: DataBreaches.net
  • 3.
    4Fortinet - Confidential EconomicCrimes in the World TOP FOUR Cybercrime is Now One of the
  • 4.
    5Fortinet - Confidential COMPOUNDEDCYBERCRIME CRIMEWARE PRODUCERS Source Code Junior Developers Copy & paste Senior Developers Exploits Packers Special Platforms Mobile CRIME SERVICES ENABLERS Quality Assurance Crypters / Packers Scanners Hosting Infections / Drop Zones Management Botnet Rentals Installs / Spam / SEO / DDoS Money Mules Accounts Receivable Consulting Affiliates Criminal Organizations Sales, Licensing, Maintenance Partnerships Affiliate Programs FakeAV / Ransomware / Botnets Victims Bank Accounts Credential s & Data Digital Real Estate Cybercriminal Ecosystem
  • 5.
    6Fortinet - Confidential Infrastructure.Constant Change. Green Google’s 13 data centers use 0.01% of global power SDN/NFV Software-defined everything. SD WAN SaaS On average, companies have 10+ applications running via the Cloud IaaS Security still the No.1 inhibitor IoT 35B devices, mostly headless attaching to the network Virtualization 80% of data center apps are virtualized Mobile No control of endpoints (BYOD) Social Bandwidth ever increasing Bandwidth Wi-Fi speeds rival LANs. 100G networks here Analytics Big Data Internet 2 100 Gbps and UHDTV 5GWireless FUTURE 100G
  • 6.
    7Fortinet - Confidential CLOUDSPEEDIoT Infrastructure. Constant Change. 20 Billion IoT devices connected by 2020 82% of Enterprises have a multi-cloud strategy 4X Growth in 100G ports
  • 7.
    8Fortinet - Confidential VOLUMECOMMERCIALADVANCED Security. Moving Landscape. 500,000 IPS Attacks Per Minute Item Cost Zero Day $5K - $50K Exploit Kit $1K - $20K Botnet Rental 10 cents Spam 100,000 $120 Kill Chain Reconnaissance Further Exploitation Host Infection Malware Action 1 Infiltration Vector Exfiltration Vector 2 3 456
  • 8.
    9Fortinet - Confidential PerMinute 35,000 Threat events 21,000 Spam emails intercepted 545,000 Network intrusions resisted 95,000 Malware programs neutralized 170,000 Malicious websites blocked 310,000 Botnet C&C attempts thwarted 43M Website categorization requests Per Week 46M New & updated spam rules 100 Intrusion prevention rules generated 1.8M New & updated AV definitions 1.4M New URL ratings 8,000 Hours of threat research globally Total Database 290 Terabytes of threat samples 18,000 Intrusion prevention rules 5,800 Application control rules 250M Rated websites in 78 categories 312 Zero-day threats discovered Threats. Huge Volumes.
  • 9.
    10Fortinet - Confidential REGULATORYCERTFICATIONGOVERNMENT Regulatory Compliance. Evolving Requirements
  • 10.
    11Fortinet - Confidential AccidentalArchitecture Routers Switches Wireless Access NETWORK TEAM MESSAGING TEAM SECURITY TEAM OS TEAM Firewall IPS Web Application Desktop OS Antivirus Mobile Device Mgmt Email Instant Messaging Voice Unified Communication Many Isolated Point Solutions
  • 11.
    13Fortinet - Confidential Theattack surface has increased dramatically, everywhere, inside and out. PoS IoT UTM NGFW Campus Mobile Endpoint Data Center DCFW Branch Office Internal External
  • 12.
    14Fortinet - Confidential End-to-EndSegmentation Branch Office PoS IoT UTM Data Center Cloud SDN Orchestration NGFW Campus Mobile Endpoint Data Center DCFW Internal External
  • 13.
    15Fortinet - Confidential FortinetSecurity Fabric – Protecting from IoT to Cloud Client Security Network Security Application Security Cloud Security Secure WLAN Access Alliance Partners Secure LAN Access IoT Fortinet Security Fabric Global Intelligence Local Intelligence
  • 14.
    16Fortinet - Confidential FortinetSecurity Fabric AccessEndpoint Application Cloud NOC/SOC Advanced Threat Intelligence Network Fabric Ready • Scalable • Aware • Secure • Actionable • Open
  • 15.
    18Fortinet - Confidential ParallelPath Processing (PPP) Packet Processing Content Inspection Policy Management Scalable - The Fabric covers the entire network attack surface (From IoT to Cloud) Slow is Broken CPU Only Policy Management Packet Processing Deep Inspection More Performance Less Latency Less Power Less Space CPU Optimized SoC CP 9 SoC 3
  • 16.
    19Fortinet - Confidential Scalable- The Fabric scales from IoT to Cloud Access PointEndpoint Distributed Firewall NGFW Data Center Firewall Carrier Class Firewall Email & Web Security Private & Public Cloud Security Switch 1 Tbit/s 1 Gbit/s
  • 17.
    21Fortinet - Confidential Aware- The Fabric gives you complete visibility enabling network segmentation Visibility Segmentation Automated Operation Fabric wide policy control Synchronized configuration Discovery Data Flow All Elements Connectivity
  • 18.
    22Fortinet - Confidential Aware– Visualization of the Security Architecture Internal Segmentation FW NGFW Data Center FW Distributed Firewall Cloud Firewall Access Point Switch Access Point Internal Segmentation FW Internal Segmentation FW Endpoint Endpoint Endpoint Global Management Real-Time Network Topology and Interaction (Physical/Functional)
  • 19.
    23Fortinet - Confidential Aware- The Fabric gives you complete visibility
  • 20.
    24Fortinet - Confidential Aware- The Fabric gives you complete visibility
  • 21.
    25Fortinet - Confidential Secure– The Fabric shares Global and Local Threat Intelligence and Mitigation Information Global Threat Intelligence Cooperation Rapid CommunicationUnknown ThreatsKnown Threats Local Threat Intelligence
  • 22.
    26Fortinet - Confidential Secure- Rapid Cooperation to Stop Threats across the Entire Attack Surface Global Intelligence Local Intelligence FortiMail (Email Security) FortiWeb (Web Application) FortiGate (Firewall) FortiClient (Endpoint Security)
  • 23.
    27Fortinet - Confidential DeviceAccess Network Cloud Distributed Enterprise Edge Segmentation Branch Data Center North-South Carrier Class SDN/NFV Private Cloud IaaS/SaaS WLAN / LAN Rugged Embedded System on a Chip Packet and Content Processor ASIC Hardware Dependent Device >1G Appliance >5G Appliance >30G Appliance >300G Chassis >Terabit Virtual Machine SDN/NFV Virtual Machine On Demand Client Endpoint/IoT Applicatio n Security FLOW Appliance Virtual Cloud Secure – The Fabric cover all the possible attack vectors such as Network, Endpoint Access, Web, Email and Cloud Security Updates IPS AVAPPFW VPN
  • 24.
    28Fortinet - Confidential Actionable– The Fabric provides real time Security Alerts, Recommendations and Audit Reports 5 Fabric Element Alert Audit Report Critical5 Critical4 Critical3 Rank Severity Recommendation Zero Day Vulnerability Not connected to Fabric Logging Disabled Regulatory Template
  • 25.
    29Fortinet - Confidential FortiMail FortiClient FortiGate Advanced Threat Protection ApplianceVirtual Cloud App Control Antivirus Anti-spam IPS Web App Database Web Filtering Vulnerability Management Botnet Mobile Security Cloud Sandbox Deep App Control Partner FortiWeb Actionable – The Fabric cuts Time to Protect from hours to seconds
  • 26.
    30Fortinet - Confidential ContinuousMonitoring and Analytics Prepare Segmentation Processes Training Prevent Harden Isolate Network Application Endpoint Detect ATP SIEM TIS Respond Contain Remediate Clean 1 2 3 4
  • 27.
    31Fortinet - Confidential End-to-EndSecurity Operations Sandbox to SIEM Automation Custom Feed Security Analysts Sandbox IOC Extraction Samples Sent for Automated Extraction Restful API Telemetry Flow 2M+ Sensors 50B+ Daily Events FortiGuard Global CTI FP Reduction Global Context Global CTI Database Value- Added Services Customers QA CTI Platform SIEM SOC / MSS 001001 101100 100011 Respond
  • 28.
    32Fortinet - Confidential Actionable– The Fabric provides real time Security Audits and Recommendations Security Audit Recommendations based  on security posture  Policy Audit  Vulnerability awareness
  • 29.
    33Fortinet - Confidential Open– The Fabric allows integration of existing security solutions SIEM Private Cloud (SDN)Endpoint Public Cloud Vulnerability Management
  • 30.
    34Fortinet - Confidential Open–The Fabric allows integration of other security technologies SDN/NFV Cloud Endpoint Management Systems Integrator SIEM Alliances Partners
  • 32.
    THE FORTINET SECURITYFABRIC REALIZED
  • 33.
    37Fortinet - Confidential FORTINETSECURITY FABRIC DDoS Protection Database Protection Web Application Firewall Application Delivery Controller Top-of-Rack BRANCH OFFICE Distributed Ent FW LTE Extension Endpoint Protection NGFWSecure Access Point IP Video Security Email Server Web Servers SDN, Virtual Firewall DCFW/ NGFW Sandbox Internal Segmentation FW Sandbox Switching Internal Segmentation FW Email Security Internal Segmentation FW CAMPUS Internal Segmentation FW DATA CENTER/PRIVATE CLOUD Virtual Firewall FortiCloud Client Devices Client Devices PUBLIC CLOUD OPERATIONS CENTER
  • 34.
    38Fortinet - Confidential FORTINETSECURITY FABRIC DDoS Protection Database Protection Web Application Firewall Application Delivery Controller Top-of-Rack BRANCH OFFICE LTE Extension Endpoint Protection FortiGate NGFW Secure Access Point IP Video Security Email Server SDN, Virtual Firewall FortiGate DCFW/ NGFW Sandbox FortiGate Internal Segmentation FW Sandbox Switching FortiGate Internal Segmentation FW Email Security FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW CAMPUS Client Devices DATA CENTER/PRIVATE CLOUD Web Servers ENTERPRISE FIREWALL FortiGate/FortiWiFi Distributed Ent FW Client Devices FortiManager FortiAnalyzer FortiSIEM OPERATIONS CENTER Virtual Firewall FortiCloud PUBLIC CLOUD
  • 35.
    39Fortinet - Confidential FORTINETSECURITY FABRIC DDoS Protection Database Protection Web Application Firewall Application Delivery Controller Top-of-Rack BRANCH OFFICE LTE Extension CAMPUS Secure Access Point IP Video Security Switching FortiGate NGFW FortiGate DCFW/ NGFW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate VMX SDN, Virtual Firewall DATA CENTER/PRIVATE CLOUD Web Servers ENTERPRISE FIREWALL Client Devices CLOUD SECURITY Client Devices Endpoint Protection Email Server Sandbox Sandbox Email Security OPERATIONS CENTER Fortinet Virtual Firewall FortiManager FortiAnalyzer FortiSIEM FortiCloud PUBLIC CLOUD FortiGate/FortiWiFi Distributed Ent FW
  • 36.
    40Fortinet - Confidential FORTINETSECURITY FABRIC DDoS Protection Database Protection Application Delivery Controller Top-of-Rack BRANCH OFFICE LTE Extension CAMPUS FortiClient Secure Access Point IP Video Security Switching FortiGate NGFW FortiGate DCFW/ NGFW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate VMX SDN, Virtual Firewall DATA CENTER/PRIVATE CLOUD Web Servers CLOUD SECURITYADVANCED THREAT PROTECTION ENTERPRISE FIREWALL FortiClient FortiSandbox FortiClient FortiSandbox FortiMail Email Security Email Server FortiWeb Web Application Firewall OPERATIONS CENTER FortiManager FortiAnalyzer FortiSIEM Fortinet Virtual Firewall FortiCloud PUBLIC CLOUD FortiCloud Sandboxing FortiGate/FortiWiFi Distributed Ent FW
  • 37.
    41Fortinet - Confidential FORTINETSECURITY FABRIC Top-of-Rack BRANCH OFFICE LTE Extension CAMPUS FortiClient Secure Access Point IP Video Security Switching FortiGate NGFW FortiGate DCFW/ NGFW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate VMX SDN, Virtual Firewall FortiDDoS Protection FortiWeb Web Application Firewall FortiADC Application Delivery Controller DATA CENTER/PRIVATE CLOUD Web Servers FortiGate Internal Segmentation FW APPLICATION SECURITY ENTERPRISE FIREWALL FortiClient FortiSandbox FortiClient FortiSandbox FortiMail Email Security FortiDB Database Protection CLOUD SECURITYADVANCED THREAT PROTECTION Email Server OPERATIONS CENTER FortiManager FortiAnalyzer FortiSIEM Fortinet Virtual Firewall FortiCloud PUBLIC CLOUD FortiCloud Sandboxing FortiGate/FortiWiFi Distributed Ent FW
  • 38.
    42Fortinet - Confidential FORTINETSECURITY FABRIC FortiWeb Web Application Firewall FortiADC Application Delivery Controller Top-of-Rack BRANCH OFFICE FortiExtender LTE Extension CAMPUS FortiClient Secure Access Point IP Video Security FortiGate NGFW FortiGate DCFW/ NGFW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate Internal Segmentation FW FortiGate VMX SDN, Virtual Firewall FortiDDoS Protection FortiGate Internal Segmentation FW DATA CENTER/PRIVATE CLOUD Web Servers SECURE ACCESS APPLICATION SECURITY ENTERPRISE FIREWALL FortiClient FortiSandbox FortiClient FortiSandbox FortiMail Email Security FortiSwitch Switching CLOUD SECURITYADVANCED THREAT PROTECTION FortiSwitch Switching Email Server FortiDB Database Protection OPERATIONS CENTER FortiManager FortiAnalyzer FortiSIEM Fortinet Virtual Firewall FortiCloud PUBLIC CLOUD FortiCloud Sandboxing FortiCloud AP Management FortiGate/FortiWiFi Distributed Ent FW