Cato Automates Threat Intelligence Feed Assessment, Eliminating False Positives

"Security analysts face a daily flood of security alerts most of which are simply irrelevant," says Elad Menahem, Director of Security at Cato Networks. "These false positives result in alert fatigue that lead security professionals to block access to legitimate business resources or simply disable their defenses, increasing the risk of infection. Using artificial intelligence and machine learning algorithms, Cato's fully automated system solves this problem, allowing them to focus their efforts on stopping genuine threats."
Comunicato Precedente

next
Comunicato Successivo

next

"Security analysts face a daily flood of security alerts most of which are simply irrelevant," says Elad Menahem, Director of Security at Cato Networks. "These false positives result in alert fatigue that lead security professionals to block access to legitimate business resources or simply disable their defenses, increasing the risk of infection. Using artificial intelligence and machine learning algorithms, Cato's fully automated system solves this problem, allowing them to focus their efforts on stopping genuine threats."

Machine Learning Models Leverage Deep SASE Context to Isolate False Positives

The lack of visibility into the broader attack landscape has long constrained the industry when identifying new attacks. Security providers only have access to security data, the Indicators of Compromise (IoCs), of threats stopped by their products. Traditional ISPs have network visibility, but they lack security insight. Enterprises remain constrained by both.

Threat intelligence services fill this gap, collecting IoCs of suspected malicious IP addresses, URLs, and domains from across the Internet. However, the variability in the accuracy of threat intelligence feeds has left enterprises blocking legitimate destinations, interfering with the very business process defended by security systems. As one recent academic paper analyzing threat intelligence feeds concluded, "…[There are] questions on the coverage that services of these vendors actually provide."1

Cato's reputation assessment system eliminates false positives in threat intelligence feeds by leveraging the convergence of security and networking information in its SASE platform. Cato ingests more than 5 million IoCs from nearly 200 open source and commercial threat intelligence sources. IoCs are then scored, and false positives are identified and eliminated using real-time network intelligence gathered by machine-learning models mining Cato's comprehensive data warehouse of SASE flow metadata.

More specifically, Cato's proprietary machine-learning models crowdsource IoC verification by:

An internal study of more than 400 IPS customers over a three-month period shows a total of 7 false positives per month. Statistically, most Cato customers never experience a false positive.

The Cato reputation system is part of Cato security services and is currently available to all Cato customers.  To learn more about Cato IPS and all of Cato's security services, visit https://www.catonetworks.com/cato-cloud#security-as-a-service.

1Bouwman, Xander, et al. "A Different Cup of TI? The Added Value of Commercial Threat Intelligence."www.usenix.org/system/files/sec20-bouwman.pdf. Accessed 26 Oct. 2020.

About Cato Networks 

Cato is the world's first SASE platform, converging SD-WAN and network security into a global, cloud-native service. Cato optimizes and secures application access for all users and locations. Using Cato, customers easily migrate from MPLS to SD-WAN, optimize connectivity to on-premises and cloud applications, enable secure branch Internet access everywhere, seamlessly integrate cloud datacenters into the network, and connect mobile users with Cato SDP all with a zero-trust architecture. With Cato, the network, and your business, are ready for whatever's next. 

Per maggiori informazioni

Ufficio Stampa

 PR Newswire (Leggi tutti i comunicati)
209 - 215 Blackfriars Road
LONDON United Kingdom

Allegati
Slide ShowSlide Show
Non disponibili
;