Modern Security Game




                Being Outside and feeling Inside
                    Being Safe Everywhere

Guy Eilon – Websense Mediterranean Regional Manager




© 2010 Websense, Inc. All rights reserved.            web security | data security | email security
Web Technology Trends
Dynamic, interactive Web 2.0 technologies have transformed
the Web into a core business application platform

Employees are working from everywhere




Data now lives outside your network, more
so if you use SaaS applications.
Along with Web 2.0, however, comes new risk as traditional URL
filtering and antivirus are rendered ineffective.
Blocking access is not the answer – increasingly the business needs broad
Web access to compete and enable employees to get the job done.


                                                                     © 2010 Websense, Inc. All rights reserved.
Today’s Webscape

              • Constantly changing content
              • Billions of varied pages per site
              • Web 2.0 attacks are here
              • Data Leakage problems with bad business                 • Junk, personal, scam, adult, etc.
              practices                                                 • Million of new sites appear daily
              • Advanced Persistent Threats using Web 2.0
Web Traffic




                                                                        • Targeted attacks hosted here
                                                                        and send their data here
                              • Current events, regional, genre sites
                              • Less user-generated content
                              • Highest volume of compromised sites




                                                                          Source: Alexa Internet, Inc. , January 2010




                                                                                © 2009 Websense, Inc. All rights reserved.   3
Static URL Filtering is Dead


                                                                Traditional URL
                                                                filters, classify
                                             Auctions           this as “Search”
       Gambling        Video or Audio
                                                                Is it really?
                         Streaming

                                          Inappropriate
                                             Content
        Social
      Networking




Understanding the URL is not enough. You must understand
and control the content on the page.

                                                           © 2010 Websense, Inc. All rights reserved.
Without Websense




                   6
With Websense




                7
Antivirus Can’t Keep Up
Number of Web viruses not detected by top 5 AV engines each day




                                                                      No AV protections
                                                                     exist for hundreds of
                                                                      emergent threats
                                                                            each day




                         http://securitylabs.websense.com/

 AV is a baseline “known threat” Web security layer – but AV alone is not the solution


                                                                        © 2010 Websense, Inc. All rights reserved.
Compromised Sites


 71% of Malicious Websites
 are compromised websites
 Just 1 attack = 82,000
 compromised sites!




                             ©2010 All Rights Reserved. Websense, Inc.   10
Threats Span Multiple Vectors



 Email with URL   Website downloads   Confidential data    Hacker collects
                   Trojan malware       harvested          data from web
                                                                 site




  User visits     Website downloads   Confidential data    Hacker collects
  popular site     Trojan malware       harvested         data via IRC chat




                    USB dropped in    Confidential data   Hacker collects
                      car park          harvested         data with SMTP
                                                              engine


                                                            © 2010 Websense, Inc. All rights reserved.
Example 1 – Blended Threat




                             12
Example 2 – Social Network scams




                                   13
Don’t Trust Search Results




User Trust Targeted Attacks
13.7 percent of searches for
trending news/buzz words (as
defined by Yahoo Buzz & Google
Trends) will lead to malware.


Search engine optimization (SEO)
poisoning attacks target the top
searches enabling hackers to drive
traffic to their sites.




                                     14
Threat Landscape


Confidential Data    Customer Data



                                      35 percent of malicious
                                      Web attacks include
                                      data stealing code
                                      58 percent of data
                                      stealing attacks are
                                      conducted over the Web



Regulated Data       Financial Data




                                                                15
The Issues you Face

 Today’s Web is powerful and has strong business
 value
 The use of Web 2.0 technology has dramatically
 expanded dynamic content and the attack surface
 Our Users and Data lives Everywhere
 Attackers are actively utilising the new Web in order
 to get into your sensitive Data
 Traditional security technologies are not effectively
 addressing today’s issues
 New detection methods are needed for modern
 threats
                                     © 2010 Websense, Inc. All rights reserved.   16
Rising Total Cost of Ownership
Websense




  What does this all lead to ???



      ?             Introducing…




                           © 2010 Websense, Inc. All rights reserved.   18
The TRITON Architecture

                    Web             Data              Email
   Unified         Security        Security           Security
   Solution
                         Unified Content Security


                  SaaS           Appliance            Software
   Unified
   Platform



   Unified
 Management

                                              © 2010 Websense, Inc. All rights reserved.
The TRITON Unified Management




                                © 2010 Websense, Inc. All rights reserved.
TRITON: The First and Only TruHybrid™ Solution

             On-premise



                          In-the-cloud
How Not to Unify Technology




                              © 2010 Websense, Inc. All rights reserved.
London Headquarters

                                              New York
San Diego

                                                                                                   Tokyo

                                                           Mumbai




                                Sao Paulo
                                                   Cape                       Sydney
                                                   Town




 © 2010 Websense, Inc. All rights reserved.                              web security | data security | email security
London Headquarters

                                              New York
San Diego

                                                                                                   Tokyo

                                                           Mumbai




                                Sao Paulo
                                                   Cape                       Sydney
                                                   Town




 © 2010 Websense, Inc. All rights reserved.                              web security | data security | email security
Unparalleled Visibility
        Where Your Users are Going




                Where Your Data is Going




                               Where You Are at Risk
Key Takeaways

 Websense delivers the best security
  – The only solution with real-time protection
    against zero-day and scripted malware
  – The only solution with real-time content
    classification across all 95 categories
  – Enterprise-class Security against Blended
    Threats including Web, Email and DLP

 At the lowest cost of ownership
  – The only solution with unified management of
    on-premise and SaaS deployment platforms
  – The only unified Web, data, and email security
    solution

 Websense is a strategic choice
  – Firmly established leadership across Web, data
    and email segments
  – Unified platform that can meet multiple
    challenges today and scale for tomorrow



                                                     © 2010 Websense, Inc. All rights reserved.   28
…And remember
                    Your Data’s Security and
                    Your Web’s Security are
                    Critical Anywhere and at Anytime.




© 2010 Websense, Inc. All rights reserved.    web security | data security | email security
Websense Delivers




                    © 2010 Websense, Inc. All rights reserved.   30

גיא אילון Websense

  • 1.
    Modern Security Game Being Outside and feeling Inside Being Safe Everywhere Guy Eilon – Websense Mediterranean Regional Manager © 2010 Websense, Inc. All rights reserved. web security | data security | email security
  • 2.
    Web Technology Trends Dynamic,interactive Web 2.0 technologies have transformed the Web into a core business application platform Employees are working from everywhere Data now lives outside your network, more so if you use SaaS applications. Along with Web 2.0, however, comes new risk as traditional URL filtering and antivirus are rendered ineffective. Blocking access is not the answer – increasingly the business needs broad Web access to compete and enable employees to get the job done. © 2010 Websense, Inc. All rights reserved.
  • 3.
    Today’s Webscape • Constantly changing content • Billions of varied pages per site • Web 2.0 attacks are here • Data Leakage problems with bad business • Junk, personal, scam, adult, etc. practices • Million of new sites appear daily • Advanced Persistent Threats using Web 2.0 Web Traffic • Targeted attacks hosted here and send their data here • Current events, regional, genre sites • Less user-generated content • Highest volume of compromised sites Source: Alexa Internet, Inc. , January 2010 © 2009 Websense, Inc. All rights reserved. 3
  • 4.
    Static URL Filteringis Dead Traditional URL filters, classify Auctions this as “Search” Gambling Video or Audio Is it really? Streaming Inappropriate Content Social Networking Understanding the URL is not enough. You must understand and control the content on the page. © 2010 Websense, Inc. All rights reserved.
  • 5.
  • 6.
  • 7.
    Antivirus Can’t KeepUp Number of Web viruses not detected by top 5 AV engines each day No AV protections exist for hundreds of emergent threats each day http://securitylabs.websense.com/ AV is a baseline “known threat” Web security layer – but AV alone is not the solution © 2010 Websense, Inc. All rights reserved.
  • 8.
    Compromised Sites 71%of Malicious Websites are compromised websites Just 1 attack = 82,000 compromised sites! ©2010 All Rights Reserved. Websense, Inc. 10
  • 9.
    Threats Span MultipleVectors Email with URL Website downloads Confidential data Hacker collects Trojan malware harvested data from web site User visits Website downloads Confidential data Hacker collects popular site Trojan malware harvested data via IRC chat USB dropped in Confidential data Hacker collects car park harvested data with SMTP engine © 2010 Websense, Inc. All rights reserved.
  • 10.
    Example 1 –Blended Threat 12
  • 11.
    Example 2 –Social Network scams 13
  • 12.
    Don’t Trust SearchResults User Trust Targeted Attacks 13.7 percent of searches for trending news/buzz words (as defined by Yahoo Buzz & Google Trends) will lead to malware. Search engine optimization (SEO) poisoning attacks target the top searches enabling hackers to drive traffic to their sites. 14
  • 13.
    Threat Landscape Confidential Data Customer Data 35 percent of malicious Web attacks include data stealing code 58 percent of data stealing attacks are conducted over the Web Regulated Data Financial Data 15
  • 14.
    The Issues youFace Today’s Web is powerful and has strong business value The use of Web 2.0 technology has dramatically expanded dynamic content and the attack surface Our Users and Data lives Everywhere Attackers are actively utilising the new Web in order to get into your sensitive Data Traditional security technologies are not effectively addressing today’s issues New detection methods are needed for modern threats © 2010 Websense, Inc. All rights reserved. 16
  • 15.
    Rising Total Costof Ownership
  • 16.
    Websense Whatdoes this all lead to ??? ? Introducing… © 2010 Websense, Inc. All rights reserved. 18
  • 18.
    The TRITON Architecture Web Data Email Unified Security Security Security Solution Unified Content Security SaaS Appliance Software Unified Platform Unified Management © 2010 Websense, Inc. All rights reserved.
  • 19.
    The TRITON UnifiedManagement © 2010 Websense, Inc. All rights reserved.
  • 20.
    TRITON: The Firstand Only TruHybrid™ Solution On-premise In-the-cloud
  • 21.
    How Not toUnify Technology © 2010 Websense, Inc. All rights reserved.
  • 22.
    London Headquarters New York San Diego Tokyo Mumbai Sao Paulo Cape Sydney Town © 2010 Websense, Inc. All rights reserved. web security | data security | email security
  • 23.
    London Headquarters New York San Diego Tokyo Mumbai Sao Paulo Cape Sydney Town © 2010 Websense, Inc. All rights reserved. web security | data security | email security
  • 24.
    Unparalleled Visibility Where Your Users are Going Where Your Data is Going Where You Are at Risk
  • 25.
    Key Takeaways Websensedelivers the best security – The only solution with real-time protection against zero-day and scripted malware – The only solution with real-time content classification across all 95 categories – Enterprise-class Security against Blended Threats including Web, Email and DLP At the lowest cost of ownership – The only solution with unified management of on-premise and SaaS deployment platforms – The only unified Web, data, and email security solution Websense is a strategic choice – Firmly established leadership across Web, data and email segments – Unified platform that can meet multiple challenges today and scale for tomorrow © 2010 Websense, Inc. All rights reserved. 28
  • 26.
    …And remember Your Data’s Security and Your Web’s Security are Critical Anywhere and at Anytime. © 2010 Websense, Inc. All rights reserved. web security | data security | email security
  • 27.
    Websense Delivers © 2010 Websense, Inc. All rights reserved. 30