Palo Alto Networks added five new capabilities to the cloud security posture management (CSPM) side of its Prisma Cloud platform including a visibility-as-code feature and two new threat detection capabilities to protect customers against data exfiltration and cryptojacking attacks.
“The CSPM market, when it began, was very rule- and policy-based, and very centered around misconfiguations in the cloud,” said Varun Badhwar, Palo Alto Networks SVP of products for Prisma Cloud.
Badhwar is also co-founder and former CEO of RedLock, one of the original CSPMs that Palo Alto Networks acquired in 2018. Palo Alto Networks that same year acquired cloud services infrastructure protection startup Evident.io, and used these two companies’ technologies as its CSPM capabilities as part of Prisma Cloud.
And while these processes and tools helped companies avoid cloud misconfigurations that can lead to data leakage, the early CSPMs that got their start five-ish years ago didn’t take into account today’s emerging threats, Badhwar said. This includes attackers using companies' compute capacity to mine for cryptocurrency and stolen credentials to access sensitive data, Badhwar said.
“And that really forces the industry to think about: How do you move above and beyond a rule-based engine? Where we really excel is, not just to look at configurations of what could go wrong, but really highlighting for our customers what threats are actively being exploited in their environment, and what is going wrong, right this second,” he said.
Prisma Cloud Gets 5 CSPM UpdatesToday’s Prisma Cloud update, which is available now to the platform’s more than 2,000 enterprise customers, addresses businesses' increasingly complex cloud environments that may include multiple cloud providers, users, applications, and resources by providing better visibility and threat detection, Badhwar said.
The update includes five new features, and the first one provides end-to-end network path visibility between any source and destination. This eliminates needless alerts associated with unexposed cloud instances and security groups.
The second new feature, visibility-as-code, is related in that it aims to reduce customers’ blind spots in their cloud services. “This addresses the cloud provider innovation speed problem,” Badhwar said. While cloud providers release updates to hundreds of new services for their platforms each year, it usually takes CSPMs a few months to support them and provide security for these new services.
With visibility-as-code, “internally, we are able to very rapidly, within a matter of days, support any new cloud provider service or feature set,” Badhwar said. “And in the future, we will open that up for customers where they don’t even have to talk to us, so they can support that cloud service on their own without our involvement.”
The next two new Prisma Cloud CSPM capabilities focus on detecting emerging threats. Instead of using static rules to detect cloud misconfigurations, Prisma Cloud uses machine learning to analyze network flow logs, understand typical traffic patterns, and then detect and alert customers on abnormal egress traffic to any IP address including TOR exit nodes. This can alert security teams to data exfiltration attacks while eliminating noise from unnecessary alerts.
Another new feature provides anomalous compute provisioning detection, which also uses machine learning to detect abnormal compute provisioning, which may be related to cryptojacking and other resource misuse.
Finally, Palo Alto Networks added customizable object-level scanning for Amazon Web Services S3, which allows customers to self-scan objects in their S3 buckets for public exposure, identify where their most sensitive data lives, and detect malware.
Comments