spiceworld 2011 - appriver breakout session

27
Security Crosses the Chasm: Surfing in Peace Shane Rice Services Evangelist

Upload: shane-rice

Post on 13-Jan-2015

719 views

Category:

Technology


1 download

DESCRIPTION

The rise of malware on the web is threatening businesses around the world. This presentation looks at the trends in malware on the web, and how AppRiver is providing protection against this threat.

TRANSCRIPT

Page 1: Spiceworld 2011 - AppRiver breakout session

Security Crosses the Chasm:

Surfing in Peace

Shane RiceServices Evangelist

Page 2: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Why Web Protection?

“The Web has become the new threat vector of choice by hackers and cyber criminals to distribute

malware and perpetrate identity theft, financial fraud and corporate espionage.” -- IDC

Page 3: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Why Web Protection?

• "Malware” - short for malicious software– Refers to any software designed to cause damage to a

single computer, server, or computer network, whether it's a virus, spyware, et al.

• Malicious Web content can expose your company to higher costs, lower productivity and legal issues

Effective Web security can safeguard employees against online threats and protect network

infrastructure

Thomas Buoniello
Last bullet doesn't make sense. Perhaps it should be:"Inappropriate Web usage can expose your emloyees to offensive web content"
Page 4: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Avenues of Attack

Source: Blue Coat Security Labs

Top Five Categories for Entering Malware Networks by Percentage of Requests

Page 5: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Malware Threat is Growing…

Malware Delivered by Websites is on the Rise

• Cumulative Malware * – 2007: 5.8 million– 2011: 65 million (as of June)

1120% Increase

• Malicious URLs* – 7,300 new malicious URLs per day

• Legitimate Websites being Compromised

80% of Websites with Malicious Code

*Source: McAfee Labs

Page 6: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Malicious Code Threats in 12 months

133%

Increase in Phishing Sites!500%

More Malware Variations

Attack TargetUsers vs Machines

Of Vulnerable Websites get fixed!4%

Increasing Attack Success!

Of Malware infections are Web application exploits

80%Web 2.0

is the Catalyst!

Of top Malware infections exposed

confidential data

68%

…And Growing More Effective

Thomas Buoniello
Rename
Page 7: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Alarming 2011 Trend

Source: Cisco ScanSafe

Unique Web Malware Encounters

297% Increase

Page 8: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.Source: AppRiver

A Clear and Present Danger

Page 9: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Source: AppRiver

A Clear and Present Danger

Page 10: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

A Clear and Present Danger

Source: AppRiver

Page 11: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

It’s The Economy Stupid

Source: http://s0.geograph.org.uk/photos/87/30/873046_db56f88b.jpg

Page 12: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

It’s The Economy Stupid

Source: flickr.com User: r-z

Page 13: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

It’s The Economy Stupid

Source: flickr.com User: AMagill

Page 14: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

It’s The Economy Stupid

Page 15: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Categorization: First Line of Defense

• Secures The Network Environment• Enforces Business-focused Internet Access• Reduces Liability• Manages Bandwidth

Shopping

Gambling

Business

IM

Security

Business

Web Filter

FilteringDatabase

SecurityPornography

Hate SitesGamblingShoppingBusiness

IM

Porn

Thomas Buoniello
Maybe first bullet should be: "Secure Your Network Environment"
Thomas Buoniello
Should this be titled "Categorization: First Line of Protection"
Page 16: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

Layered Security – Stronger Protection

Anti-Virus

• Anti-Virus

• However it is only a single aspect of the complete solution

• Signature based detection is not enough to cover today’s targeted Web 2.0 Malware attacks

Intent Analysis

• Authenticode – Checks for Digital Signature on active code

• Media Type Filter -verification via “magic byte” analysis not MIME

• Behavioral Malware detector - scans for malicious script intent and removes offending function calls

• Behavioral exploit detector – inspects code for hostile behavior like buffer overflows, etc.

Anti-Malware

• Prevents OS, browser and application exploits as a result of:•Protects from known

malicious code•Protects from

unknown malicious mobile code for which no signature exists

Signature based detection is not enough to cover today’s targeted Malware attacks

+ =

Thomas Buoniello
Need to make sure we tie this into how it protects web browsing.
Page 17: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Why Web Protection as a Service?

• Diminishing IT Dollars and Resources for a Growing Problem– IT is constantly asked to do more with a flat budget– Many smaller organizations do not have adequate IT

resources to buy and manage appliances or complex deployments

• Web Protection as a Service Offers– Lower upfront costs – Ease and Speed of Deployment

• No on-site hardware or software to maintain, upgrade, or support

• Simply redirect Web traffic– Fixed operational expense instead of a

capital expense

Page 18: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.18

SecureSurf Case Study

Blocking a Keylogger Attack

• Title company in South Florida• Setup SecureSurf week before Labor Day• Keylogger attempted to upload keystrokes

Friday night• SecureSurf blocked traffic to suspicious IP• AppRiver analysis determined nature of

attack and notified customer

Page 19: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

SecureSurf Web & Malware Protection

Page 20: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

Features & Benefits• Shields networks from malware, adware

and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup

level• Enforces safe search on major search

engines • Easy set up and deployment• Intuitive browser-based Web Portal Access

for Administrators• Anti-Malware/Spyware Protection –

proactive intent-based protection that scans the active code on a Web site before it enters your network

Cloud-based Web Protection & Endpoint Security

SecureSurf Web & Malware Protection

More details at http://www.appriver.com/services/web-protection/

Page 21: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

Features & Benefits• Shields networks from malware, adware

and viruses • Protects employees; improves productivity • Helps avoid legal/compliance issues • Deploys quickly and customizes easily • Allows filtering at company or workgroup

level• Enforces safe search on major search

engines • Easy set up and deployment

AppRiver SecureSurf Agent®

• User/device-level protection• Mobile workforce & off-network security• Compliance & enforcement at user level

Cloud-based Web Protection & Endpoint Security

SecureSurf Web & Malware Protection

Page 22: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

Company

Customers

Market Leadership

AppRiver at a Glance

Company

• 45,000 Customers• 6,000,000 Mailboxes Managed• 93% Customer Retention Rate• Channel-centric (70% Customer base)• Focus on the SMB

• Established: 2002• Headquarters: Gulf Breeze, FL• Employees: 150+• Privately Held, Debt-free, Self-funded• Focus on Email & Web Security with Phenomenal CareTM

• Cloud-based Since Inception

• Leading Worldwide Messaging Security SaaS Provider• Named Best SMB Solution for Hosted Message Security Services• Recognized as a Microsoft Top 5 Hosted Exchange Provider• Tremendous Customer ROI of AppRiver’s Security Solutions• Identified as Shaping the Future of Technology

Page 23: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

24/7 Phenomenal

CareTM

24/7 Spam & Virus

Operations Center

24/7 Malware

Protection Operation

Center

24/7 – The Next Level

Company

• Continuous Threat Protection for SecureSurf Customers• Threat Data Gleaned from/shared with Spam & Virus Operations• >5 Billion Malicious Websites . . . and Counting

•US-Based, Fully Trained AppRiver Employees•Available 24 Hours a Day, Every Day•By Phone, Live Chat and Email•Easy-to-use Web-based Guides & Tools

• Worldwide Threat Detection System• Sophisticated, Proprietary Software• Real-time Threat Prevention & Instant System-wide Updates

Thomas Buoniello
What about renaming this slide "24/7 Redefined" or "24/7 - The Next Level"To me this more than just "AppRiver At a Glance"
Page 24: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

AppRiver Timeline

Company

Founded AppRiver

2002 2004 2006 2008 2010 2012

Introduced SecureTideTM

Launched HostedExchange Service

Integrated First Optimized Network for Hosted Exchange(Akamai)

Implemented RackSpaceInfrastructure

Daily Quarantine Reports

40,000 HostedExchange Seats

20,000 HostedExchange Seats

50,000 HostedExchange Seats

ARBO Launched

Hired 100th Employee

100,000 HostedExchange Seats

150,000 HostedExchange Seats

Launched Email Encryption Service

Launched Web & Malware Protection Service

Hired 150th Employee

Thomas Buoniello
Maybe rename this just "AppRiver Timeline" or something similiar, not sure it is good to have 3 straight "At A Glance" slides…
Page 25: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

Proven Track Record

• 2011, 2010, 2009, 2008, 2007 Inc. 5000 Fastest Growing Private Companies

• 2011, 2010, 2009 Florida Trend Best Companies to Work For in Florida

• 2011 CRN Top 20 Cloud Security Vendor

• 2011, 2009, 2006 Network World Fave Raves

• 2010, 2009 MSExchange.org Readers' Choice Award Winner

• 2010, 2009 CRN Five-Star Partner Program

• 2010 CRN Coolest Cloud Security Vendor

• 2009 CSIA International Service Excellence Award

• 2009 Deloitte Technology Fast 500™ Winner

• 2009 Business Solutions Best Channel Product – Email Security

• 2009 Ernst & Young Florida Entrepreneur of the Year - Michael Murdoch, CEO

• 2009 Business Solutions Best Channel Vendor – Security

Page 26: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.Easy. Effective. Affordable.

AppRiver Application Mall

SecureTideTM Spam & Virus Protection

Exchange HostingSecure Hosted Exchange

CipherPostTM Email Encryption

SecureSurfTM Web & Malware Protection

Office 365Microsoft Cloud-based Service

ECSTM Email Continuity Service

Learn more at http://www.appriver.com/services/

Page 27: Spiceworld 2011 - AppRiver breakout session

Easy. Effective. Affordable.

Questions?

Find SpiceWorld related links from AppRiver @ http://bit.ly/arsw2011