Eighteen months ago, CyberRatings began its testing process for security service edge (SSE) solutions, according to Vikram Phatak, CEO of the nonprofit group that focuses on cybersecurity product evaluations designed to help IT leaders, experts and operators Leaders, Experts, and Operators (LEOs) evaluate, purchase and deploy products to secure the enterprise.
In developing testing for cybersecurity products and services — and SSE, in particular — Phatak said CyberRatings extends its reach to a broad constituency from the security community from cyber risk experts to vendors to users. “Everyone sees [SSE] differently,” Phatak said. “It’s like the three blind men feeling different parts of an elephant. One says it’s a rock, one says it’s a hose, one says it’s a tree.”
Given the scale of SSE deployments and its relative newness to the market, testing brings inherent challenges. “No tools are out there. Nothing really exists in the community. There tends to be a patchwork.” To help with the complex testing methodology, Phatak said CyberRatings partners with Keysight — formerly HP Instruments — to test SSE from a performance standpoint. CyberRatings also, collaborated with vendors themselves to develop its methodology, he said
“It’s basically a breaking test. It’s like dropping a glass to see if it breaks. That stresses out a lot of vendors,” Phatak said.
This is only a test, don’t call the feds Because they are testing services in the cloud, Phatak said, CyberRatings let the vendors know what to expect so they know it’s not an actual emergency. “We let the vendors know it’s us, so they don’t think it is a nation-state attack and call the FBI.”
“The internet is our lab, which means we need to account for various factors. Different times, different days, variances like major sporting events.”
While companies could buy the elements of SSE as separate point solutions, Phatak uses the analogy of buying a car, saying that you could buy the engine from one company, the body from another, the transmission from another ... but you’d “need a lot of mechanics and there are not enough mechanics out there.”
Zscaler leads off the testing Zscaler kicks off the SSE CyberRatings testing. “Zscaler is a market leader and helped create the SSE space,” Phatak said. However, several other leading SSE vendors are in the process of being tested. He wouldn’t identify which vendors but did say it’s a list you’d expect.
Zscaler's Zero Trust Exchange platform was nearly perfect in defending against threats like malware, exploits and evasive attacks, according to the CyberRatings report. During the testing, Zscaler's Zero Trust Exchange stopped 98.0% of threats overall, including 98.05% of exploits, 99.93% of malware samples, and crucially, 100% of evasion attempts. These evasions are tactics used by attackers to bypass security measures, Phatak said.
Phatak said CyberRating’s exploit library also tests a wide range of protocols and applications to see how effectively Zscaler's Zero Trust Exchange platform offers exploit protection for 10 top vendors. Of the companies below only Adobe wasn’t 100 percent protected by Zscaler
- Adobe: 94.12%
- Apache: 100%
- Cisco: 100%
- Foxit: 100%
- Google: 100%
- LibreOffice: 100%
- Microsoft: 100%
- OMRON: 100%
- Oracle: 100%
- VMware: 100%
The testing methodology employed a mix of clear text and encrypted traffic, reflecting real-world network conditions. Zscaler's Zero Trust Exchange successfully defended against a barrage of 205 exploits, 7,140 malware samples and 1,124 evasion techniques across various encryption protocols.
Comments