itb-nz logo
Story image

Sophos XG Firewall adds lateral movement protection

03 Dec 2018

Sophos has added lateral movement protection capabilities to its XG Firewall offering. The new capabilities will help to prevent targeted, manual cyber attacks and exploits from further infiltrating a compromised network.

Cybercriminals often gain access through weak entry points and brute-force Remote Desktop Protocol passwords.

From there, they can cause severe damage to systems through lateral movement because they can move around, steal information, disable controls and backups, and more.

Examples like the SamSam ransomware, BitPaymer, Dharma and Ryuk all use similar lateral movement techniques to conduct attacks.

Sophos senior vice president and general manager of products, Dan Schiappa, explains:

“Many organisations are set up to protect against automatic bots, but not interactive, human-driven attacks. If active adversaries get into a system they can ‘think laterally’ to troubleshoot roadblocks, evade detection and move around. It’s hard to stop them unless the right security measures are in place.”

“Most lateral movements happen on the endpoint, which is why synchronizing security is important. Attackers will attempt to advance using non-malware techniques, such as exploits, Mimikatz and privilege escalation. The network needs to know to respond and automatically shut down or isolate infected machines before anyone or anything spreads further.”

He believes that lateral movements can be stopped by sharing intelligence from the firewall and endpoints. Isolation of infected systems is critical for businesses.

 “Unfortunately, many business environments could have blind spots on their network switches or LAN segments, and these can become secret launch pads for attacks.”

Sophos XG Firewall is now able to stop threats from spreading, even when it doesn’t have direct control over traffic.

It also works in conjunction with other Sophos offerings, including the Intercept X Advanced with Endpoint Detection and Response (EDR).

They both connect via a ‘Security Heartbeat’ in Sophos’ Synchronized Security technology that enables the automatic isolation of high-risk endpoints from other endpoints on the same broadcast domain or network segment. 

Additional new and enhanced features in Sophos XG Firewall include: •  Protection Enhancements - Deeper, broader IPS coverage with increased granularity in patterns - JavaScript cryptojacking protection •  Sandstorm Sandboxing Enhancements -   Intercept X integration to identify zero-day threats before they enter the network -  Deep behavioural, network and memory analysis with machine learning, CryptoGuard, and exploit detection •  Networking Enhancements -   New Sophos Connect IPSec VPN client with support for Synchronized Security •   Education Features -   Chromebook client authentication support for user-based policy and reporting -  User/group policy support for SafeSearch and YouTube restrictions

Sophos XG Firewall is available from registered Sophos partners worldwide.

Story image
Check your home network: Demand will congest internet during Covid-19 lockdown
New Zealand Telecommunications Forum says demand for data will increase as New Zealanders use their home networks to access internet to continue working, learning and to entertain themselves once the entire country goes into self-isolation. More
Story image
Worrying gap in local consumer cybersecurity savvy
New research shows A/NZ consumers feel clued in, but there’s clear room for improvement in their education and tools.More
Story image
OnePlace Solutions offers free Microsoft 365 add-on to support remote workers during COVID-19
The offer comes after Microsoft announced that subscribers to Microsoft Office 365 will be able to access a free trial of the Microsoft Teams software.More
Story image
DataRobot offers free AI platform to help fight COVID-19
"We're inspired by the passion of our employees, customers, partners, and the data science community who all have expressed interest in identifying ways to help address this global pandemic."More
Story image
Global lockdowns put pressure on internet infrastructure
With COVID-19 resulting in many countries going into lockdown, more people are transitioning to working and studying remotely, putting more pressure on internet infrastructure around the world.More
Story image
Google offers Hangouts features for free in midst of COVID-19
As businesses make the move to work entirely remotely as countries go into lockdown during the COVID-19 pandemic, Google is offering free upgrades on their G Suite for business, providing certain enterprise features for free for the next few months.More