Global enterprises expose a new, serious security vulnerability every 12 hours, according to Palo Alto Networks’ latest attack surface data released today.
“That means if you’re a Fortune 500 company, twice a day you have something that shows up,” said Tim Junio, SVP of products for Cortex at Palo Alto Networks. “Maybe you take it down pretty quick and it’s a blip. But nevertheless, if we’re able to catch it in our data, that means so are the bad people.”
Junio co-founded and previously served as CEO at Expanse, an attack surface management vendor that Palo Alto Networks acquired for $670 million late last year. He’ll deliver an RSA Conference keynote today about how enterprises can better understand the threat landscape and boost their security.
Also to help organizations shore up their attack surfaces, Palo Alto Networks today announced several new zero-trust security products and capabilities. This includes secure access across all software-as-a-service (SaaS) applications, a Cloud Identity Engine to authenticate and authorize users, advanced URL filtering, and new hardware firewalls.
“We are introducing complete zero trust network security,” Palo Alto Networks SVP Anand Oswal said. This includes technologies that ensure “secure access to the right applications, secure access to the right users, and making enhanced security universally available across new hardware platforms,” he added.
Palo Alto Networks Zero Trust SecurityPalo Alto Networks, like most networking and security vendors, expect companies to retain a hybrid work environment even after their employees are vaccinated and we enter the post-pandemic new normal. This means organizations will need to ensure that employees and users have secure access to the right data and applications both on and off of the campus network, Oswal explained.
In other words: a zero-trust approach to security will be key. Zero trust essentially assumes a breach will happen. It provides a framework to ensure that only verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis.
Leading security vendors including IBM and Microsoft rolled out new playbooks and technologies to support zero trust ahead of the annual RSA Conference. And today, Palo Alto Networks joined the party with four new products and updates.
The new Cloud Identity Engine plays a big role in Palo Alto Networks’ latest zero-trust push. This allows customers to authenticate and authorize their users across enterprise networks, clouds, and applications, regardless of where their identity stores live.
“It can be hard for enterprises to consistently verify and enforce identity-based security all the time,” Oswal said. “We’re making it really easy with this Cloud Identity Engine that talks to our network security platforms, and it is really a foundational requirement to achieve zero trust.”
Second, the vendor announced an integrated cloud access security broker (CASB) to extend secure access across all SaaS applications including those never seen before. As organizations migrate to the cloud, “we’ve seen an explosion of SaaS applications, and the traditional CASB vendors fall short,” Oswal said.
The new integrated CASB “is architected to scale. It automatically discovers and controls new SaaS applications, allowing customers to have granular, application risk-based visibility and control of shadow IT,” Oswal said. Additionally, machine-learning models stop both known and unknown threats, he said, and the CASB is integrated across Palo Alto Networks’ security architecture so customers can use it across all its firewall form factors: hardware, software, and cloud-delivered.
Palo Alto Networks also announced an advanced URL filtering service that it says prevents zero-day attacks with inline machine learning capabilities.
And finally, the vendor announced two new machine-learning powered firewall models. The PA-400 series targets small branch offices, and the PA-5450 platform is designed for large campuses and hyperscale data centers.
Attack Surface Threat ReportIn addition to the product news, Palo Alto Networks released new threat data at the RSA Conference that shows adversaries are working a lot faster than defenders to find and exploit vulnerabilities.
“The results are pretty surprising,” Junio said. It’s surprising because security teams know that attackers scan the internet for unpatched vulnerabilities. While this used to take weeks or months, newer scanning algorithms enable global internet scanning at a rate of 1,500 times faster than earlier methods.
“We’ve known about these methods since 2012, when open source research started getting published,” he said. “And here we are, nine years later, still seeing that major organizations are still not batting down the hatches.”
For this report, the Palo Alto Networks Cortex Xpanse research team studied the public-facing internet attack surface of Fortune 500 companies. From January to March the team monitored scans of 50 million IP addresses associated with 50 global enterprises to understand how quickly adversaries can identify vulnerable systems for fast exploitation.
They found that these global enterprises display new vulnerabilities to the public-facing internet every 12 hours, or twice daily. These include insecure remote access such as remote desktop protocol (RDP) issues, and in fact, the team found that RDP was the most common security issue and accounted for almost one-third (32%) of overall security issues.
RDP Security FlawsThis echoes findings from VMware’s latest threat intelligence report, which found more than 75% of security events in which attackers moved laterally through a network were conducted using RDP.
Palo Alto Networks found constant RDP scanning for port 3389, which is reserved for RDP, and this is “particularly worrisome because [RDP is] a top gateway for ransomware,” the report says.
“We see a lot of RDP show up in cloud environments, and even though it’s best practice to not have RDP accessible over the public internet, mistakes happen all the time, Junio said.
Other commonly exposed vulnerabilities included misconfigured database servers, exposure to high-profile zero-day vulnerabilities from vendors such as Microsoft and F5, along with insecure remote access through Telnet, Simple Network Management Protocol (SNMP), Virtual Network Computing (VNC), and other protocols.
The threat researchers also found that cloud footprints were responsible for 79% of the most critical security issues we found in global enterprises. As large companies transition at least some of their workloads to the cloud, “it’s still kind of a greenfield for what cloud security is going to look like,” Junio said. “Customers are still piecing together different products and solutions to try and come up with an answer, but there isn’t a common framework that is being applied. That’s part of why we’re seeing so much activity in the cloud and so many exposures in the cloud.”
The COVID-19 pandemic and sure in remote work also plays a role in cloud-security risks because it expanded corporate attack surfaces, he added.
Attackers Work Faster Than Security TeamsPlus, threat actors work a lot faster than enterprise security teams. The data found that threat actors scan the internet for vulnerable assets once per hour and even more frequently — every 15 minutes at least — following CVE disclosures. With the Microsoft Exchange Server zero-day vulnerabilities, attackers launched scans within five minutes of Microsoft’s March 2 announcement.
Enterprise security teams, on the other hand, need an average of 12 hours to find vulnerable systems — assuming that they even know about all of the assets on the network.
The speed at which threat actors find vulnerabilities also illustrates the need for defense in depth and a zero-trust security framework. “So just one internet-facing exposed device shouldn’t be enough to ruin your day,” Junio said. “You should have two-factor authentication, so username and password shouldn’t be enough alike for someone to guess.”
Zero-trust enabling technologies like multi-factor authentication and segmentation make it more difficult for an attacker to move deeper into the network after compromising one device.
But often in ransomware attacks or major data breaches, “there were other problems and the internet-accessible asset was kind of a starting point,” Jumio said. “And then because some other aspect of security was not well configured, it was a matter of time until some criminal or government-actor discovered the next step and was successfully able to do things like extract data or move within the network and escalate the attack.”
“So having exposed internet assets is not automatically a disaster, when it’s combined with something else it’s the beginning of a disaster,” Junio added. “It’s the beginning of something that’s much more expensive.”
Comments