Palo Alto Networks introduced software-as-a-service (SaaS) Security Posture Management and new SD-WAN appliances to its Prisma secure access service edge (SASE) platform. 

The Prisma innovations will help alleviate escalating security threats posed by the proliferation of hybrid work and SaaS applications. According to Palo Alto Networks, the average business now has over 115 SaaS applications to secure.  

“There's a great risk to this misconfiguration of SaaS applications by the CISO, IT, etcetera,” Palo Alto Networks SVP of Network Security Anand Oswal told SDxCentral.

As part of its SSPM, Palo Alto Networks’ next-generation cloud access security broker (CASB) allows users to view and configure security settings for SaaS apps in a "single, unified business SASE portal," Oswal said. The CASB helps remediate detected misconfigurations and prevents configuration drift by locking critical security settings in place, reducing remediation time by up to 90%, according to the vendor. 

[caption id="attachment_121128" align="aligncenter" width="400"] Anand Oswal, SVP of network security, Palo Alto Networks[/caption]

Prisma Integrates Next-Gen ZTNA, Automation

Prisma SASE will also have new ZTNA 2.0 security capabilities including machine learning- (ML) powered advanced URL filtering and advanced threat prevention, and what Palo Alto Networks claims is the “industry’s first native AIOps solution for SASE.” 

New URL filtering capabilities prevent what Oswal says are a growing number of “evasive” phishing, ransomware, and other web-based attacks. Traditional URL filtering has used internet crawlers that put URLs in a database and assign risk-based scores to each URL, but Oswal explained that this "conventional database-driven approach" is too slow for today's threat landscape. 

“What's happened the last couple of years is that the attackers are getting very, very smart,”  he added. 

To stay ahead of attackers, Palo Alto Networks added ML features to stop unknown command-and-control (C2) attacks, and bring security analysis from “offline” to “online” using cloud compute for artificial intelligence (AI) and deep learning techniques. 

ML and AI capabilities, along with the cloud, enable scalability so Palo Alto Networks can “look at metadata of URL strings content to stop 6 million more phishing attacks than ever before, to prevent 76% of the malicious URLs,” Oswal said. 

The AIOps integration provides automated root cause analysis, quick problem remediation, and guided best practice adoption. Predictive analytics enable more efficient capacity planning and anomaly detection, preventing business disruptions. 

With a growing volume of alerts and incidents hitting IT teams’ desks, “manual operations lead to more errors,” Oswal noted. “We need to use the power of automation to do faster remediation.”

Palo Alto Networks also announced new SD-WAN hardware appliances – ION 1200-S and ION 3200– to help organizations modernize their small to midsize branches. These new appliances include a fully integrated switch and power over ethernet (POE) ports to connect and power endpoints within the local area network.

The ION 1200-S and fiber ports on the ION 3200 have integrated WAN capabilities like 5G and LTE.