Security Crosses
  the Chasm:
Surfing in Peace

     Shane Rice
  Services Evangelist
Why Web Protection?




     “The Web has become the new threat vector of
    choice by hackers and cyber criminals to distribute
    malware and perpetrate identity theft, financial fraud
            and corporate espionage.” -- IDC




                                                    Easy. Effective. Affordable.
Why Web Protection?

• "Malware” - short for malicious software
   – Refers to any software designed to cause damage to a
     single computer, server, or computer network, whether
     it's a virus, spyware, et al.
• Malicious Web content can expose your
  company to higher costs, lower productivity and
  legal issues



 Effective Web security can safeguard employees
     against online threats and protect network
                    infrastructure


                                                             Easy. Effective. Affordable.
Avenues of Attack

 Top Five Categories for Entering Malware Networks by
 Percentage of Requests




   Source: Blue Coat Security Labs            Easy. Effective. Affordable.
Malware Threat is Growing…

 Malware Delivered by Websites is on the Rise
   •   Cumulative Malware *
       – 2007: 5.8 million
       – 2011: 65 million (as of June)
         1120% Increase

   •   Malicious URLs*
       – 7,300 new malicious URLs per day

   •   Legitimate Websites being Compromised
         80% of Websites with Malicious Code




   *Source: McAfee Labs                         Easy. Effective. Affordable.
…And Growing More Effective

                                    More Malware               Malicious
                                     Variations         133%   Code Threats
                                                               in 12 months




 80%
       Of Malware
       infections are Web               68%
       application exploits          Of top Malware          Increasing
                                        infections        Attack Success!
       Web 2.0
                                         exposed
   is the Catalyst!                 confidential data          Of Vulnerable
                                                         4%    Websites get fixed!




                                    Attack Target
    500%        Increase in
                Phishing Sites!   Users vs Machines

                                                               Easy. Effective. Affordable.
Alarming 2011 Trend

 Unique Web Malware Encounters


                                 297% Increase




   Source: Cisco ScanSafe          Easy. Effective. Affordable.
A Clear and Present Danger




   Source: AppRiver          Easy. Effective. Affordable.
A Clear and Present Danger




   Source: AppRiver          Easy. Effective. Affordable.
A Clear and Present Danger




   Source: AppRiver          Easy. Effective. Affordable.
It’s The Economy Stupid




   Source: http://s0.geograph.org.uk/photos/87/30/873046_db56f88b.jpg   Easy. Effective. Affordable.
It’s The Economy Stupid




   Source: flickr.com User: r-z   Easy. Effective. Affordable.
It’s The Economy Stupid




   Source: flickr.com User: AMagill   Easy. Effective. Affordable.
It’s The Economy Stupid




                          Easy. Effective. Affordable.
Categorization: First Line of Defense
                             Web Filter

                                                                Shopping

                                              Gambling

                                                                Business

                                                IM

                                                         Porn


                                              Security

                                                         Business

                Filtering
                Database
                                    •   Secures The Network Environment
                 Security
               Pornography          •   Enforces Business-focused Internet Access
                Hate Sites
                Gambling            •   Reduces Liability
                Shopping
                Business            •   Manages Bandwidth
                   IM


                                                                           Easy. Effective. Affordable.
Layered Security – Stronger Protection
  Signature based detection is not enough to cover today’s targeted Malware attacks

          Anti-Virus                 Intent Analysis                 Anti-Malware

  • Anti-Virus                 • Authenticode –                • Prevents OS, browser
                                 Checks for Digital              and application exploits
  • However it is only a         Signature on active             as a result of:
    single aspect of the
    complete solution
                                 code                             • Protects from known
                               • Media Type Filter -                malicious code
  • Signature based              verification via “magic          • Protects from
    detection is not
    enough to cover
    today’s targeted Web
    2.0 Malware attacks
                           +     byte” analysis not MIME
                               • Behavioral Malware
                                 detector - scans for
                                                           =        unknown malicious
                                                                    mobile code for
                                                                    which no signature
                                                                    exists
                                 malicious script intent
                                 and removes offending
                                 function calls
                               • Behavioral exploit
                                 detector – inspects
                                 code for hostile
                                 behavior like buffer
                                 overflows, etc.




                                                                         Easy. Effective. Affordable.
Why Web Protection as a Service?

• Diminishing IT Dollars and Resources for a Growing
  Problem
   – IT is constantly asked to do more with a flat budget
   – Many smaller organizations do not have adequate IT
     resources to buy and manage appliances or complex
     deployments


• Web Protection as a Service Offers
   – Lower upfront costs
   – Ease and Speed of Deployment
       • No on-site hardware or software to
         maintain, upgrade, or support
       • Simply redirect Web traffic
   – Fixed operational expense instead of a
     capital expense



                                                            Easy. Effective. Affordable.
SecureSurf Case Study

  Blocking a Keylogger Attack

  • Title company in South Florida
  • Setup SecureSurf week before Labor Day
  • Keylogger attempted to upload keystrokes
    Friday night
  • SecureSurf blocked traffic to suspicious IP
  • AppRiver analysis determined nature of
    attack and notified customer




                                                                           18
                                                  Easy. Effective. Affordable.
SecureSurf Web & Malware Protection




                                      Easy. Effective. Affordable.
SecureSurf Web & Malware Protection

 Cloud-based Web Protection & Endpoint Security

 Features & Benefits
   • Shields networks from malware, adware
     and viruses
   • Protects employees; improves productivity
   • Helps avoid legal/compliance issues
   • Deploys quickly and customizes easily
   • Allows filtering at company or workgroup
     level
   • Enforces safe search on major search
     engines
   • Easy set up and deployment
   • Intuitive browser-based Web Portal Access
     for Administrators
   • Anti-Malware/Spyware Protection –
     proactive intent-based protection that scans
     the active code on a Web site before it
     enters your network
  More details at http://www.appriver.com/services/web-protection/

                                                               Easy. Effective. Affordable.
SecureSurf Web & Malware Protection

 Cloud-based Web Protection & Endpoint Security

 Features & Benefits
  • Shields networks from malware, adware
    and viruses
  • Protects employees; improves productivity
  • Helps avoid legal/compliance issues
  • Deploys quickly and customizes easily
  • Allows filtering at company or workgroup
    level
  • Enforces safe search on major search
    engines
  • Easy set up and deployment



 AppRiver SecureSurf Agent®
  • User/device-level protection
  • Mobile workforce & off-network security
  • Compliance & enforcement at user level


                                                  Easy. Effective. Affordable.
AppRiver at a Glance

               •   Established: 2002
               •   Headquarters: Gulf Breeze, FL
               •   Employees: 150+                   Company
  Company      •   Privately Held, Debt-free, Self-funded
               •   Focus on Email & Web Security with Phenomenal CareTM
               •   Cloud-based Since Inception


               •   45,000 Customers
               •   6,000,000 Mailboxes Managed
  Customers    •   93% Customer Retention Rate
               •   Channel-centric (70% Customer base)
               •   Focus on the SMB



               •   Leading Worldwide Messaging Security SaaS Provider
               •   Named Best SMB Solution for Hosted Message Security Services
    Market     •   Recognized as a Microsoft Top 5 Hosted Exchange Provider
  Leadership   •   Tremendous Customer ROI of AppRiver’s Security Solutions
               •   Identified as Shaping the Future of Technology


                                                                  Easy. Effective. Affordable.
24/7 – The Next Level


     24/7        •   US-Based, Fully Trained AppRiver Employees
                 •                               Company
                     Available 24 Hours a Day, Every Day
  Phenomenal
                 •   By Phone, Live Chat and Email
    CareTM       •   Easy-to-use Web-based Guides & Tools




      24/7
                 • Worldwide Threat Detection System
  Spam & Virus
                 • Sophisticated, Proprietary Software
   Operations    • Real-time Threat Prevention & Instant System-wide Updates
     Center


      24/7
    Malware      • Continuous Threat Protection for SecureSurf Customers
   Protection    • Threat Data Gleaned from/shared with Spam & Virus Operations
   Operation     • >5 Billion Malicious Websites . . . and Counting
    Center

                                                                  Easy. Effective. Affordable.
AppRiver Timeline


                                                                          Company


     Introduced SecureTideTM                                Integrated First Optimized
                                                            Network for Hosted Exchange
                                                            (Akamai)
     Implemented RackSpace
     Infrastructure
         Daily Quarantine Reports                                      Hired 100th Employee             Hired 150th Employee


  2002                 2004              2006                  2008                  2010                    2012

               ARBO Launched
                                         20,000 Hosted    40,000 Hosted  50,000 Hosted        100,000 Hosted 150,000 Hosted
                                         Exchange Seats   Exchange Seats Exchange Seats       Exchange Seats Exchange Seats


                                    Launched Hosted
    Founded AppRiver                Exchange Service



                                                              Launched Email                      Launched Web & Malware
                                                              Encryption Service                  Protection Service

                                                                                                       Easy. Effective. Affordable.
Proven Track Record

• 2011, 2010, 2009, 2008, 2007 Inc. 5000 Fastest
  Growing Private Companies
• 2011, 2010, 2009 Florida Trend Best Companies
  to Work For in Florida
• 2011 CRN Top 20 Cloud Security Vendor
• 2011, 2009, 2006 Network World Fave Raves
• 2010, 2009 MSExchange.org Readers' Choice
  Award Winner
• 2010, 2009 CRN Five-Star Partner Program
• 2010 CRN Coolest Cloud Security Vendor
• 2009 CSIA International Service Excellence Award
• 2009 Deloitte Technology Fast 500™ Winner
• 2009 Business Solutions Best Channel Product
  – Email Security
• 2009 Ernst & Young Florida Entrepreneur of
  the Year - Michael Murdoch, CEO
• 2009 Business Solutions Best Channel Vendor
  – Security


                                                     Easy. Effective. Affordable.
AppRiver Application Mall

    SecureTideTM
    Spam & Virus Protection

    Exchange Hosting
    Secure Hosted Exchange

    CipherPostTM
    Email Encryption

    SecureSurfTM
    Web & Malware Protection

    Office 365
    Microsoft Cloud-based Service

    ECSTM
    Email Continuity Service

    Learn more at http://www.appriver.com/services/

                                                      Easy. Effective. Affordable.
Questions?




         Find SpiceWorld related links from
         AppRiver @ http://bit.ly/arsw2011

                                              Easy. Effective. Affordable.

Spiceworld 2011 - AppRiver breakout session

  • 1.
    Security Crosses the Chasm: Surfing in Peace Shane Rice Services Evangelist
  • 2.
    Why Web Protection? “The Web has become the new threat vector of choice by hackers and cyber criminals to distribute malware and perpetrate identity theft, financial fraud and corporate espionage.” -- IDC Easy. Effective. Affordable.
  • 3.
    Why Web Protection? •"Malware” - short for malicious software – Refers to any software designed to cause damage to a single computer, server, or computer network, whether it's a virus, spyware, et al. • Malicious Web content can expose your company to higher costs, lower productivity and legal issues Effective Web security can safeguard employees against online threats and protect network infrastructure Easy. Effective. Affordable.
  • 4.
    Avenues of Attack Top Five Categories for Entering Malware Networks by Percentage of Requests Source: Blue Coat Security Labs Easy. Effective. Affordable.
  • 5.
    Malware Threat isGrowing… Malware Delivered by Websites is on the Rise • Cumulative Malware * – 2007: 5.8 million – 2011: 65 million (as of June) 1120% Increase • Malicious URLs* – 7,300 new malicious URLs per day • Legitimate Websites being Compromised 80% of Websites with Malicious Code *Source: McAfee Labs Easy. Effective. Affordable.
  • 6.
    …And Growing MoreEffective More Malware Malicious Variations 133% Code Threats in 12 months 80% Of Malware infections are Web 68% application exploits Of top Malware Increasing infections Attack Success! Web 2.0 exposed is the Catalyst! confidential data Of Vulnerable 4% Websites get fixed! Attack Target 500% Increase in Phishing Sites! Users vs Machines Easy. Effective. Affordable.
  • 7.
    Alarming 2011 Trend Unique Web Malware Encounters 297% Increase Source: Cisco ScanSafe Easy. Effective. Affordable.
  • 8.
    A Clear andPresent Danger Source: AppRiver Easy. Effective. Affordable.
  • 9.
    A Clear andPresent Danger Source: AppRiver Easy. Effective. Affordable.
  • 10.
    A Clear andPresent Danger Source: AppRiver Easy. Effective. Affordable.
  • 11.
    It’s The EconomyStupid Source: http://s0.geograph.org.uk/photos/87/30/873046_db56f88b.jpg Easy. Effective. Affordable.
  • 12.
    It’s The EconomyStupid Source: flickr.com User: r-z Easy. Effective. Affordable.
  • 13.
    It’s The EconomyStupid Source: flickr.com User: AMagill Easy. Effective. Affordable.
  • 14.
    It’s The EconomyStupid Easy. Effective. Affordable.
  • 15.
    Categorization: First Lineof Defense Web Filter Shopping Gambling Business IM Porn Security Business Filtering Database • Secures The Network Environment Security Pornography • Enforces Business-focused Internet Access Hate Sites Gambling • Reduces Liability Shopping Business • Manages Bandwidth IM Easy. Effective. Affordable.
  • 16.
    Layered Security –Stronger Protection Signature based detection is not enough to cover today’s targeted Malware attacks Anti-Virus Intent Analysis Anti-Malware • Anti-Virus • Authenticode – • Prevents OS, browser Checks for Digital and application exploits • However it is only a Signature on active as a result of: single aspect of the complete solution code • Protects from known • Media Type Filter - malicious code • Signature based verification via “magic • Protects from detection is not enough to cover today’s targeted Web 2.0 Malware attacks + byte” analysis not MIME • Behavioral Malware detector - scans for = unknown malicious mobile code for which no signature exists malicious script intent and removes offending function calls • Behavioral exploit detector – inspects code for hostile behavior like buffer overflows, etc. Easy. Effective. Affordable.
  • 17.
    Why Web Protectionas a Service? • Diminishing IT Dollars and Resources for a Growing Problem – IT is constantly asked to do more with a flat budget – Many smaller organizations do not have adequate IT resources to buy and manage appliances or complex deployments • Web Protection as a Service Offers – Lower upfront costs – Ease and Speed of Deployment • No on-site hardware or software to maintain, upgrade, or support • Simply redirect Web traffic – Fixed operational expense instead of a capital expense Easy. Effective. Affordable.
  • 18.
    SecureSurf Case Study Blocking a Keylogger Attack • Title company in South Florida • Setup SecureSurf week before Labor Day • Keylogger attempted to upload keystrokes Friday night • SecureSurf blocked traffic to suspicious IP • AppRiver analysis determined nature of attack and notified customer 18 Easy. Effective. Affordable.
  • 19.
    SecureSurf Web &Malware Protection Easy. Effective. Affordable.
  • 20.
    SecureSurf Web &Malware Protection Cloud-based Web Protection & Endpoint Security Features & Benefits • Shields networks from malware, adware and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup level • Enforces safe search on major search engines • Easy set up and deployment • Intuitive browser-based Web Portal Access for Administrators • Anti-Malware/Spyware Protection – proactive intent-based protection that scans the active code on a Web site before it enters your network More details at http://www.appriver.com/services/web-protection/ Easy. Effective. Affordable.
  • 21.
    SecureSurf Web &Malware Protection Cloud-based Web Protection & Endpoint Security Features & Benefits • Shields networks from malware, adware and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup level • Enforces safe search on major search engines • Easy set up and deployment AppRiver SecureSurf Agent® • User/device-level protection • Mobile workforce & off-network security • Compliance & enforcement at user level Easy. Effective. Affordable.
  • 22.
    AppRiver at aGlance • Established: 2002 • Headquarters: Gulf Breeze, FL • Employees: 150+ Company Company • Privately Held, Debt-free, Self-funded • Focus on Email & Web Security with Phenomenal CareTM • Cloud-based Since Inception • 45,000 Customers • 6,000,000 Mailboxes Managed Customers • 93% Customer Retention Rate • Channel-centric (70% Customer base) • Focus on the SMB • Leading Worldwide Messaging Security SaaS Provider • Named Best SMB Solution for Hosted Message Security Services Market • Recognized as a Microsoft Top 5 Hosted Exchange Provider Leadership • Tremendous Customer ROI of AppRiver’s Security Solutions • Identified as Shaping the Future of Technology Easy. Effective. Affordable.
  • 23.
    24/7 – TheNext Level 24/7 • US-Based, Fully Trained AppRiver Employees • Company Available 24 Hours a Day, Every Day Phenomenal • By Phone, Live Chat and Email CareTM • Easy-to-use Web-based Guides & Tools 24/7 • Worldwide Threat Detection System Spam & Virus • Sophisticated, Proprietary Software Operations • Real-time Threat Prevention & Instant System-wide Updates Center 24/7 Malware • Continuous Threat Protection for SecureSurf Customers Protection • Threat Data Gleaned from/shared with Spam & Virus Operations Operation • >5 Billion Malicious Websites . . . and Counting Center Easy. Effective. Affordable.
  • 24.
    AppRiver Timeline Company Introduced SecureTideTM Integrated First Optimized Network for Hosted Exchange (Akamai) Implemented RackSpace Infrastructure Daily Quarantine Reports Hired 100th Employee Hired 150th Employee 2002 2004 2006 2008 2010 2012 ARBO Launched 20,000 Hosted 40,000 Hosted 50,000 Hosted 100,000 Hosted 150,000 Hosted Exchange Seats Exchange Seats Exchange Seats Exchange Seats Exchange Seats Launched Hosted Founded AppRiver Exchange Service Launched Email Launched Web & Malware Encryption Service Protection Service Easy. Effective. Affordable.
  • 25.
    Proven Track Record •2011, 2010, 2009, 2008, 2007 Inc. 5000 Fastest Growing Private Companies • 2011, 2010, 2009 Florida Trend Best Companies to Work For in Florida • 2011 CRN Top 20 Cloud Security Vendor • 2011, 2009, 2006 Network World Fave Raves • 2010, 2009 MSExchange.org Readers' Choice Award Winner • 2010, 2009 CRN Five-Star Partner Program • 2010 CRN Coolest Cloud Security Vendor • 2009 CSIA International Service Excellence Award • 2009 Deloitte Technology Fast 500™ Winner • 2009 Business Solutions Best Channel Product – Email Security • 2009 Ernst & Young Florida Entrepreneur of the Year - Michael Murdoch, CEO • 2009 Business Solutions Best Channel Vendor – Security Easy. Effective. Affordable.
  • 26.
    AppRiver Application Mall SecureTideTM Spam & Virus Protection Exchange Hosting Secure Hosted Exchange CipherPostTM Email Encryption SecureSurfTM Web & Malware Protection Office 365 Microsoft Cloud-based Service ECSTM Email Continuity Service Learn more at http://www.appriver.com/services/ Easy. Effective. Affordable.
  • 27.
    Questions? Find SpiceWorld related links from AppRiver @ http://bit.ly/arsw2011 Easy. Effective. Affordable.