Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Thursday, December 12, 2019

A10 Networks extends carrier-class firewall product lineup with a container offering, new 5G network ready features

A10 Networks announced Wednesday that it is extending the capabilities of the Thunder Convergent Firewall (CFW), part of the A10 Orion 5G Security Suite, to support the coming cloud-native 5G requirements. The container-based carrier-class firewall delivers up to 180 Gbps throughput, one of the fastest in the industry. 


A10 is also releasing a new version of its Advanced Core Operating System (ACOS) 5.1, which includes multiple 5G-ready updates. Thunder CFW running ACOS 5.1 brings functionality, performance and scale of the existing physical and virtual appliances to the container firewall, helping to prepare service provider customers in their transition to cloud-native 5G infrastructures.


The Thunder containerized firewall was recently demonstrated as part of the Linux Foundation’s end-to-end cloud-native 5G network proof of concept at KubeCon + CloudNativeCon. This first of its kind proof-of-concept (PoC) was a fully containerized, end-to-end 5G non-stand-alone (NSA) distributed cloud network, which paves the way for commercial deployments in mobile operator networks globally.


The Thunder CFW includes functionality that helps ensure the security, reliability and availability of 5G networks as they transition from physical network functions to be completely cloud native. It can be broadly deployed in mobile networks at the SGi, roaming and radio access network (RAN) interfaces. 



The A10 vThunder virtual network function (VNF) package has been integrated and validated with leading NFV-MANO solutions, including Ericsson Cloud Manager, NEC Netcracker HOM, Red Hat OpenStack, and tested in recent ETSI NFV Plugtests for end-to-end VNF lifecycle operation capabilities.



“The Thunder CFW release is an integral foundational element to our comprehensive A10 Orion 5G Security Suite. With the ACOS 5.1 release, A10 has integrated comprehensive feedback from multiple proven deployments in tier-one mobile operators over the last year. These production networks have required hyperscale, lower latency, automation, and advanced security,” said Yasir Liaqatullah, vice president, product management at A10 Networks. “As 5G adoption increasingly requires multi-terabit performance on the Gi-LAN, we continue to provide industry-leading scale in virtual network functions (VNFs), cloud-native network functions (CNFs) and physical network functions (PNFs), including scale-out agile deployments with containerized solutions for virtual mobile edge compute requirements.”



In addition to the release of the high-performance containerized firewall CNF, A10 Networks also released new PNFs with its 7600 series models, delivering up to 385 Gbps throughput in a compact RU physical appliance.


The A10 Orion 5G Security Suite is available now. Thunder CFW with ACOS 5.1 and the new CNF and PNF form factors will be available later this month.

Tuesday, December 10, 2019

API Fortress releases unlimited API monitoring for internal APIs

API Fortress announced Monday unlimited internal API Monitoring license, which allows companies to run any number of functional API monitors without paying additional metered usage fees. 

Metered usage pricing has contributed to a significant increase in QA costs for enterprises as their testing centers of excellence have encountered rapidly growing numbers of APIs. Modern apps and platforms need many more APIs, which involve an increasingly complex array of API calls to work properly.


Just because an API monitor returns a 200 does not mean that the API is working. Some APIs even use a 200 to indicate that there is an issue. In this eBook of API Horror Stories from actual API Fortress customers, one of the world's largest retailers believed that their retail app was functioning properly. Then they were mystified by a dip in revenues from certain product lines. 

When they ran API Fortress functional uptime monitors, they became aware of an API bug that their uptime monitors could never have detected - the cache function of their API management platform was causing the wrong data to populate certain product listings.


“Continuous delivery with CI/CD was the start of an important trend for test automation. That trend has continued to evolve, and now companies are asking why can't their functional API tests constantly test and monitor business-critical APIs? With API Fortress, they can,” said Patrick Poulin, CEO and co-founder of API Fortress. "With our unlimited monitoring, companies can detect API flaws early and diagnose API flaws quickly. You can schedule API monitoring on our platform without a CI (continuous integration) platform. We also let our customers deploy monitors on-premises, keeping all test and monitor data behind the firewall."

Sunday, November 17, 2019

FireMon’s 2019 State of the Firewall report shows lack of automation as underlying security challenge in digital transformation initiatives

FireMon released its 2019 State of the Firewall report, the annual benchmark of current issues in firewall management. The latest report finds that enterprises are slow to abandon manual processes — despite being short staffed — and that the lack of automation, increasing network complexity, and limited visibility contribute to costly misconfigurations and increased risk. 


The 2019 State of the Firewall report features feedback from nearly 600 respondents, including nearly 20 percent from the executive ranks, detailing their enterprise firewall operations in the spectrum of digital transformation initiatives. With this analysis, FireMon maps the latest industry trends to reveal the pulse of the changing security policy management landscape. 

Technology initiatives –micro-segmentation, zero trust, containers, SDN, cloudetc. all fall under the same boardroom theme: Digital Transformation. Whether the goal is to be more agile, competitive or to super-charge the supply chain, digital transformation is the glue driving the mission to be more responsive while closing the gap on security.


The sixth annual State of the Firewall Report for 2019 shows the impact that hybrid cloud is having on firewalls and firewall security, looks at key issues in automation, compliance, the influence of digital transformation, and much more, including six out of 10 enterprises have firewalls deployed in the cloud, but only three out of 10 have at least 80 percent of real-time visibility into network security risks and compliance. 


Three out of 10 respondents manage more than 100 firewalls and over half use three or more different vendors for enforcement points on their network, while 95 percent of respondents said that the firewall will be as critical or more critical than ever in the next five years.

Highlighting this scenario, the 2019 State of the Firewall report reveals that cloud adoption is up significantly – 72 percent of respondents are managing some form of hybrid cloud environment today, compared to the 53% cited in the 2018 report.


The 2019 State of the Firewall report’s findings on the lack of automation being used across the industry highlight the need to deploy this missing solution. Finding the correct approach of security automation for each enterprise helps to improve real-time visibility and control over network security processes and to comply with regulations. 

The best approach to automation will enable an organization to minimize human error, increase efficiency and close the gap between driving transformation initiatives and maximizing security resources and agility. 

Thursday, November 14, 2019

CloudVector introduces API Threat Protection with automated and continuous discovery

CloudVector announced launch of its namesake solution, which discovers, monitors and secures APIs to prevent data breaches. The proliferation of APIs have encouraged threat actors to target this new attack vector, increasing the risk of major data breaches. 

Existing Web Application Firewall (WAF) and API Management gateways are unable to provide API Threat Protection because of inherent limitations in their architectures.

To move beyond the gateway, CloudVector encourages organizations to adopt an API Threat Protection solution that is able to automatically discover APIs, monitor for deviant behavior, and secure data from exfiltration. CloudVector is the first API Threat Protection platform to deliver this full feature set.


CloudVector is purpose-built for modern application architectures, and is deployed with zero impact to inline performance, with no changes required to applications or DevOps processes. In fact, CloudVector eliminates the need for manual API specification to deliver immediate time to value.

The CloudVector’s API Threat Protection platform include discover with API Inspection Modules (AIM) that provide fully automated microsensor modules enable the continuous discovery of all APIs connected to enterprise assets—even shadow APIs. 

It also monitors with Deep API Risk Trackers (DART) that apply proven machine learning to customer-specific API blueprints that drive automatic identification of API risks and, real-time detection of reconnaissance attempts, and provide real-time response modules enforce targeted policies against API abuse—the only solution to entirely address the OWASP API Security Top 10.


CloudVector, which was formerly known as ArecaBay, also announced the appointment of Ravi Khatod as co-founder and CEO. Ravi is a seasoned Silicon Valley security executive with more than 15 years of experience focused on building foundational teams and strategy, driving sales success and customer excellence, and delivering growth at category-defining vendors including IronPort, CipherTrust, and AppSense. Prior to CloudVector, he served as CEO of Agari, a next-generation email security company, where he drove 300 percent in revenue run rate growth in three years.

“APIs have become mission critical for organizations as they move to the cloud and embrace digital transformation initiatives. Attackers have also recognized this new and broad attack surface. As we’ve seen with recent high profile data breaches API security has become a predominant challenge,” said Khatod. “The shortcomings of existing gateways represent a multi-billion dollar market opportunity for CloudVector, which is advancing the state of the API Threat Protection market with its solution.”

CloudVector has raised more than US$5 million in seed funding round led by SignalFire, which it is aggressively investing in the growth of its R&D, sales and marketing teams.


“CloudVector delivers API Threat Protection we couldn’t find in any other vendor, without negatively impacting DevOps—it automates tedious manual processes to discover APIs and secure them,” said Abhijit Oak, vice president, Software Development, Katerra. “This product enables us to simplify our security structure and spend.”

Saturday, November 2, 2019

Fortinet’s FortiGate 60F sets new benchmark for security compute ratings; boosts performance for integrated security and SD-WAN

Fortinet announced the FortiGate 60F Next-Generation Firewall, its latest desktop secure SD-WAN appliance. With over 1.5 million units sold worldwide, the FortiGate 60 series is the best-selling next-generation firewall and now includes Fortinet’s purpose-built system on a chip 4 (SOC4) security processor to achieve the highest Security Compute Ratings in the industry to support customers’ WAN edge transformation.

Digital innovation and rapid cloud adoption is changing the face of today’s business and has created significant challenges for organizations, such as poor user experience due to network bandwidth constraints and increased security risks with branches connected to the internet. 



Software-defined wide area networks (SD-WANs) have emerged as the favored solution to solve these issues while also reducing the costs associated with MPLS connections. 

However, not all SD-WAN solutions have risen to the requirements of existing WAN edge. Many SD-WAN solutions on the market are incomplete and do not adequately provide the right performance, visibility, or security to ensure a secure connection and high quality of user experience.

To continue its focus on supporting enterprises’ WAN edge transformation and delivering Secure SD-WAN, Fortinet is announcing the latest next-generation firewall to include its patented SOC4 security processor - the FortiGate 60F. 


FortiGate 60F now consolidates SD-WAN, advanced routing, and advanced security capabilities into a single appliance that enables network leaders to deploy Secure SD-WAN, while reducing complexity by consolidating point products into a single offering. This allows high performance and improved user experience at an optimal total cost of ownership (TCO).
 
To help customers maintain high quality user experience for their business critical traffic (be it SaaS, multi-cloud, or unified communications), FortiGate 60F delivers ideal application steering, giving visibility to all traffic (even if encrypted) without impacting performance and ensuring all critical applications are routed to their best path.
 
FortiGate 60F leverages Security-Driven Networking principals – powered by Fortinet’s patented SOC4 security processor – to deliver the fastest deep inspection of SSL/TLS encrypted traffic (including the industry’s first support for TLS 1.3) at 750Mbps, 11 times greater than the industry average. 

The FortiGate 60F offers comprehensive threat prevention with IPS, application control, and anti-malware at 700Mbps, four times greater than the industry average, to help customers protect their network without impacting performance.


Fortinet security processors radically increase the performance, scalability, and value of Fortinet solutions while greatly improving user experience and shrinking space and power requirements. Security Compute Rating is a benchmark that compares the performance of Fortinet’s purpose-built ASIC-based next-generation firewall appliance to other NGFW and SD-WAN vendors in that same price range that utilize generic CPUs for networking and security capabilities. 

“We hear from an increasing number of customers who are struggling to achieve the required level of user experience, visibility, and security at their WAN edge to support key business applications,” said John Maddison, EVP of Products and CMO at Fortinet. “With today’s introduction of the FortiGate 60F powered by our latest security processor, Fortinet continues its commitment to security innovation, setting industry records for performance to empower network leaders to truly transform their WAN edge.”

Thursday, October 31, 2019

F5 Networks, Rakuten Mobile come together to support cloud-native mobile network, prepare for 5G-ready service rollout

F5 Networks announced that it has partnered with Rakuten Mobile, the mobile network subsidiary of Rakuten Group, to support the company’s October launch of the initial fully virtualized, cloud-native mobile network and its future deployment of 5G. The carrier will leverage F5’s network functions virtualization (NFV) capabilities to optimize its new mobile network and accelerate its path to 5G services in 2020.

Through this partnership, Rakuten Mobile, Inc. is collaborating with F5 to scale and evolve their cloud-native network design architecture to increase scalability and flexibility without sacrificing control. 


F5 has provided a full-suite N6/SGi-LAN solution consisting of virtualized CGNAT, SGi Firewall, DNS Transparent Cache, and IP Traffic Optimization Functions to deliver enhanced Mobile Broadband (eMBB) services. 

F5’s NFV capabilities and offerings enabled Rakuten Mobile to simplify and optimize service orchestration; ensure application availability, performance, and security; deliver improved freedom and agility in deployment of services; and enable a higher throughput, low-latency network and allow predictable scaling for services.


Earlier this year, F5 announced several new solutions and enhancements designed to allow service providers to launch 5G services. These offerings enable service providers to maximize the investments in their current 4G networks, while optimizing their infrastructures with the scale to securely deploy emerging 5G.


Rakuten has also been making headlines in Japan with its forays into 5G innovation, in partnership with firms such as Nokia, Altiostar, Cisco, Mavenir, Intel, Qualcomm, Quanta and NEC. The fact that Rakuten, unlike existing telecommunication companies, has no outdated and legacy infrastructure to maintain is a significant advantage. 

Tuesday, October 29, 2019

Zyxel introduces ZyWALL ATP100 Firewall that uses threat intelligence and cloud-based security for small businesses

Zyxel Communications announced on Monday launch of the ZyWALL ATP100 Firewall, an advanced firewall designed for small businesses. The ATP100 draws real-time intelligence from a continually-expanding global database of cybersecurity threat data to provide businesses with an unprecedented level of protection from the risk of cyberattacks.

Designed for small businesses with fewer than 25 employees, the new ZyWALL ATP100 Firewall leverages Zyxel’s cloud-based security services to provide multi-layer protection against a variety of threats, such as attacks from botnets, malware, web attacks, exploits, and sources of spam. A continuously growing database of global threat information is analyzed by an AI-driven algorithm to identify and stop active threats before they can spread.



The ZyWALL ATP100 Firewall features self-evolving cloud intelligence that meets the requirements of unknown files and user patterns from all deployed Zyxel ATP firewalls are added to the threat database and the most top-ranked threat signatures are pushed into all ATP firewalls giving them a seamless defense shield against new unknown threats. Real-time cloud device synchronization feeds a continuously-growing, self-evolving defense ecosystem that adapts to external attacks and keeps all ATP firewalls in sync at all times.


An isolated cloud environment contains unknown files that cannot be identified by existing security services. Unknown files are emulated in isolation to determine whether they are malicious or not, providing protection against zero-day attacks of all sorts.

The firewall also guards against threats with multiple vectors through a comprehensive array of security features including botnet filtering, sandboxing, app patrol, content filtering, reputation filtering, anti-malware, and Intrusion Detection and Prevention (IDP).


When an unknown file appears, Cloud Query quickly checks the file ID in Zyxel Security Cloud’s database to check if it is malicious, maximizing network traffic by providing strong malware coverage with minimal network resources.


A user-friendly dashboard gives visual traffic summary and threat statistics. The SecuReporter suite of analysis and reporting tools includes network security threats identification/analysis, security services, security events, application usage, website usage, and traffic usage. Botnet filter analytics/reports and IP Reputation analytics provide valuable insight into identified and potential threats.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...