chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

Forging Better Security Outcomes with Integrated Threat Intelligence

Sep 16 2020

For most companies, security and IT systems are growing in complexity, breadth of scope, and coverage, which consumes budget and staff time. The rapid breakdown of the traditional perimeter in this “new normal” world increases the challenges IT teams and remote users face on a daily basis. 

In light of new, cloud-driven requirements to support remote users and applications, IT teams are undergoing a transformation to build out their new security strategy while maintaining many of their existing investments. The difficulties grow exponentially when it comes to leveraging old and new portions of the security stack to respond in a timely manner to the wide array of new attack vectors. Threat actors target different parts of the enterprise, looking for security gaps between protections in the cloud and the endpoint. Much like the response to any type of crisis, hoarding information in silos is counterproductive to resolution. For our customers, we aim to break the silos down in order to share information about a threat actor’s activities and to build effective defenses and prevention capabilities. 

Challenges with Silos

Each security stack component has its own world view of the threat landscape. For example, an endpoint product might have the latest threat intel on attacks on desktop operating systems, and such information would also be valuable if the threat could be stopped before it reaches the user. SIEM and UEBA engines do a great job of surfacing high-value data (by ingesting information from multiple sources), but they are not designed for the distribution and orchestration of threat information with other systems. Any delay in the time to respond provides a gap in intelligence that threat actors can exploit. To address this need, there are SOAR solutions such as those developed by Netskope partners at Exabeam, SIEMplify, Splunk, Swimlane, Helix, and Workspace One, but sometimes there is a simpler answer.

Netskope wants to help customers and partners scale their own threat intelligence sharing of globally-useful indicators of compromise, which is why we are announcing the availability of the Cloud Threat Exchange. 

Solution – Cloud Threat Exchange

Cloud Threat Exchange (CTE) helps our customers get the most out of all of their security investments by sharing customer-specific intelligence with every other connected component of their stack. This capability complements (rather than replaces) threat sharing functions of any given integrated partner and helps customers maximize the effectiveness of their protection using automation and orchestration to stop an attack. 

CTE improves the opportunity to stop an attack earlier in the kill chain by making sure that every security measure works in conjunction with one another to coordinate a response. This improves the overall effectiveness of the security because it closes the gaps in conventional security stacks by providing the latest information on emerging threats across all of the organization’s defenses. 

Netskope is pleased to announce the availability of Cloud Threat Exchange, with support from a number of ecosystem partners. Netskope CTE is also able to take advantage of public API made available for the Microsoft Cloud Application Security and DefenderATP endpoint protection solutions to exchange IOC with customers’ Microsoft deployments. In addition to the out-of-the-box support, our customers and partners may build their own plug-ins for use in their own unique environments and use cases. 

Integrated Cloud Threat Exchange partner FireEye is excited to have built its own plug-in to utilize this sharing architecture. Phani Modali, Vice President of Global Sustaining Engineering for Cloud SIEM stated, “Organizations need to respond to threats faster to protect themselves and their employees. This integration lets our joint customers aggregate all threats in FireEye Helix, while instantly sharing these insights through network, endpoint, email, and other security tools and back to Netskope to reduce threats seen in the cloud.”

author image
Brian Tokuyoshi
Brian is responsible for platform and threat product marketing. Prior to Netskope, he worked in network security at Palo Alto Networks and data protection at Symantec.
Brian is responsible for platform and threat product marketing. Prior to Netskope, he worked in network security at Palo Alto Networks and data protection at Symantec.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.