LAS VEGAS — Sophos added capabilities to its cloud security platform and a new product called Intelix based on the vendor’s global threat intelligence and data science team.

Sophos acquired the technology for its Cloud Optix security platform when it bought Avid Secure in January. The two-year-old startup had developed an artificial intelligence (AI)-based cloud security platform that provides analytics and automates governance, risk, and compliance across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform.

The acquisition added key cloud-native technologies to Sophos, a legacy network and endpoint security vendor. And three months later Sophos released the first version of Cloud Optix built on Avid Secure’s technology.

Cloud Optix

This week at AWS re:Invent, Sophos rolled out several new Cloud Optix capabilities to further automate cloud vulnerability and misconfiguration detection and response.

A major new piece, according to Andy Miller, Sophos’ senior director of Global Public Cloud, “is that we moved the product into our Central platform where all of our other products reside.” The cloud-based Central platform allows customers to manage the entire Sophos portfolio, including endpoint, network, mobile, WiFi, email and encryption products, from a central interface. It also lets these products talk to each other to enable information sharing and threat response.

Customers can buy the security platform in AWS Marketplace, and because it’s re:Invent, (and AWS dominates the public cloud market), Sophos added a slew of capabilities that help customers detect threats across AWS and other public clouds. One of these new ones helps customers find security vulnerabilities in Amazon EKS clusters and native Kubernetes Cloud Optix now tracks these, providing inventory and visualization of clusters, nodes, node pools, pods, and containers, and checking them against security benchmarks.

The platform also now monitors daily cloud spend and flags unexpected abnormalities so organizations can take action. “I like to call this the spend monitoring or denial-of-wallet feature,” Miller said. A spending hike could be planned — for example, if a company moves a bunch of new workloads to the cloud. “But if not, it might be an indicator that somebody is using their resources to do things like cryptomining,” which Miller adds is “a bit of a problem for customers.”

Sophos also added new integrations with AWS security products. Cloud Optix integrates with the new AWS Identity and Access Management (IAM) Access Analyzer to provide detail and context needed to determine whether resource policies have been misconfigured. Sophos UTM platfrom (this includes firewall appliances, email protection, and web application firewall) supports the new Amazon Virtual Private Cloud (VPC) Ingress Routing to ensure traffic flowing in and out of VPCs and other virtual appliances is secure. And finally, Cloud Optix now supports the newly launched Amazon Detective threat hunting service.

SophosLabs Intelix

Also at re:Invent, Sophos made available SophosLabs Intelix, a cloud-based threat intelligence and analysis platform. SophosLabs is the company’s global threat intelligence and data science team. The new service “productizes that threat intelligence out to the community,” Miller said.

Developers can make API calls into the platform for threat expertise that assesses the risk of files, URLs, and IP addresses. The platform continuously updates and collates petabytes of real-time and historical intelligence. This includes telemetry from Sophos’ endpoint, network, and mobile security solutions; data from honeypots and spam traps; 30 years of threat research; and predictive insights from machine and deep learning models.