share_log

CyberRatings.org Announces Enterprise Firewall Test Results

CyberRatings.org Announces Enterprise Firewall Test Results

CyberRatings.org宣佈企業防火牆測試結果
PR Newswire ·  06/27 08:00

Multiple exploits for each evasion technique were used to measure each product's defense.
Protection rate scores ranged from 37.01% to 99.87%.

M使用多個漏洞來測試每個產品的美國國防航空。
保護率得分爲37.01%至99.87%。

AUSTIN, Texas, June 27, 2024 /PRNewswire/ -- CyberRatings.org (CyberRatings), the non-profit entity dedicated to providing confidence in cybersecurity products and services through its research and testing programs, has completed an independent test of eight market leading enterprise firewall vendors. Seven products were Recommended, and one received a Caution rating.

德克薩斯州奧斯汀,2024年6月27日 /美通社/ --CyberRatings.org(CyberRatings)是一個非營利實體,致力於通過其研究和測試計劃提供網絡安全概念中對於產品和服務的信懇智能。該機構已完成了對八個領先市場的企業防火牆供應商的獨立測試。其中七款產品獲得推薦,一款獲得了警告等級。

Enterprise firewalls are used to protect a trusted network from an untrusted network while allowing authorized communications to pass from one side to the other, thus facilitating secure business use of the Internet. Protection rate tests verified how effectively the firewall protected control network access, applications, and users while preventing threats (exploits and evasions), blocking malicious traffic under extended load, and remaining resistant to false positives.

企業防火牆用於保護信任網絡免受來自不信任網絡的攻擊,同時允許授權的通信從一側傳遞到另一側,從而方便安全地使用互聯網進行業務。保護率測試驗證了防火牆在保護控制網絡訪問、應用程序和用戶的同時,防止威脅(利用和迴避)、阻止擴展負載下的惡意流量並保持對誤報的抵抗力。

"An attacker can bypass protection if a firewall fails to detect a single form of evasion." - Vikram Phatak, CEO

"如果防火牆未能檢測到一種迴避形式,則攻擊者可以繞過保護。" -- Vikram Phatak, 思科CEO

Post this
發帖:

Key Findings:

主要結果:

  • When an exploit is blocked by a firewall, applying an evasion technique to that exploit is often easier for an attacker than finding a new exploit that isn't blocked by that firewall.
  • Threat actors apply evasion techniques to disguise and modify attacks to avoid detection by security products. Missing a type of evasion means a hacker can use an entire class of exploits to circumvent the security product. CyberRatings used multiple exploits for each evasion technique to see how each product defended against these combinations.
  • Vendors have made progress towards "Secure by Default." For the products and versions CyberRatings tested, if a vendor's pre-defined high security configuration is selected, then firewall evasion defenses will be on by default. For other security configurations evasion defenses may not be enabled by default.
  • Encryption matters: Roughly 80% of web traffic is encrypted. The top four cipher suites account for over 95% of HTTPS traffic. It should be noted that decryption is not on by default. Firewalls will not see attacks delivered via HTTPS unless configured to do so.
  • Variants from well-known exploits are not always covered by vendors. At times, CyberRatings found multiple signatures/rules for the same Common Vulnerabilities and Exposures (CVE), with some offering more protection than others. Vendors may attempt to provide rapid coverage for high profile vulnerabilities by creating multiple exploit-specific signatures. If vendors don't follow up with more comprehensive defenses, this approach can lead to gaps in protection.
  • 當防火牆阻止一個漏洞時,攻擊者往往會將一個迴避技術應用到該漏洞上,這比尋找防火牆沒有阻止的新漏洞更容易。
  • 網絡威脅行爲人應用迴避技術來掩蓋和修改攻擊,以避免安全產品檢測。如果錯過某種迴避類型,則黑客可以使用整個漏洞類型來規避安全產品。CyberRatings對每種迴避技術使用多個漏洞來查看每個產品對這些組合的防禦情況。
  • 供應商已經在"出廠即安全"方面取得了進展。對於CyberRatings測試過的產品和版本,如果選擇供應商預定義的高安全配置,則防火牆規避防禦將默認開啓。對於其他安全配置,迴避防禦可能並非默認啓用的。
  • 加密很重要:大約80%的Web流量是加密的。前四個密碼套件佔HTTPS流量的95%以上。需要注意的是,解密沒有默認開啓。如果沒有配置,防火牆將看不到通過HTTPS傳遞的攻擊。
  • 來自已知漏洞的變種並不總是由供應商覆蓋。有時,CyberRatings會發現同一Common Vulnerabilities and Exposures (CVE)的多個簽名/規則,其中一些提供比其他簽名/規則更好的保護。供應商可能會嘗試通過創建多個特定於漏洞的簽名來爲熱門漏洞提供快速覆蓋。如果供應商不跟進提供更全面的防禦,這種方法可能導致保護中存在漏洞。

To our knowledge, this was the most comprehensive evasion test performed to date. We have accelerated our research into evasion techniques as attackers increasingly bypass defenses," said Vikram Phatak, CEO of CyberRatings.org. "An attacker can bypass protection if a firewall fails to detect a single form of evasion."

"據我們所知,這是迄今爲止進行的最全面的迴避測試。隨着攻擊者越來越多地規避防禦,我們加快了對迴避技術的研究,"CyberRatings.org的首席執行官Vikram Phatak說。"如果防火牆未能檢測到一種迴避形式,則攻擊者可以繞過保護。"

The following products were tested and rated:

以下產品已測試並獲得評級:

Enterprise Firewall

Rating

Protection Rate

Rated Throughput (Mbps)

Price per Protected Mbps

Check Point Quantum Force 19200 plus R81.20

Recommended

98.41 %

12,281

$11.28

Cisco Firepower 2130 Threat Defense v7.3.1 (build 19)

Caution

37.01 %

1,040

$77.34

Forcepoint 3410 NGFW version 7.1.1 build 29059

Recommended

96.89 %

14,961

$7.93

Fortinet FortiGate-900G v7.4.4 GA

Recommended

98.21 %

14,096

$3.25

Juniper Networks SRX4600 JUNOS 22.4X3.1 srx4600

Recommended

99.54 %

7,772

$13.74

Palo Alto Networks PA-450 v11.1.1

Recommended

96.36 %

1,026

$6.52

Sangfor NGAF 5300 AF 8.0.85.1029 Build 20240423

Recommended

97.48 %

5,719

$1.57

Versa Networks CSG5000 versa-flexvnf-22.1.4-B

Recommended

99.87 %

15,811

$2.15

企業防火牆

評級

保護率

額定吞吐量(Mbps)

每保護Mbps的價格

Check PointQuantumForce 19200 plus R81.20

推薦

98.41 %

12,281

$11.28

思科Firepower2130 Threat Defense v7.3.1 (build 19)

注意

37.01%

1,040

$77.34

Forcepoint 3410 NGFW版本7.1.1構建29059

推薦

96.89%

14,961

$7.93

飛塔信息Fortinet FortiGate-900G v7.4.4 GA

推薦

98.21%

14,096

$3.25

瞻博網絡Juniper Networks SRX4600 JUNOS 22.4X3.1 srx4600

推薦

99.54%

7,772

$13.74

palo alto networks Palo Alto Networks PA-450 v11.1.1

推薦

96.36%

1,026

$6.52

Sangfor NGAF 5300 AF 8.0.85.1029 Build 20240423

推薦

97.48%

5,719

$1.57

Versa Networks CSG5000 versa-flexvnf-22.1.4-B

推薦

99.87%

15,811

$2.15

Keysight provided their CyPerf and BreakingPoint tools to test performance, TLS functionality and stability. TeraPackets provided their Threat Replayer tool for packet replay, and CyberRatings used its own proprietary tools for live exploits and evasions.

Keysight提供他們的CyPerf和BreakingPoint工具來測試性能、TLS功能和穩定性。TeraPackets提供他們的Threat Replayer工具進行數據包重放,而CyberRatings則使用其自有的專有工具進行現場攻擊和逃逸測試。

The Enterprise Firewall Test Reports, Comparative and Security Value Map are available at cyberratings.org.

企業防火牆測試報告、比較和安全價值地圖可在cyberratings.org獲取。

Additional Resources:

更多資源:

Enterprise Firewall Configuration Guide
Enterprise Firewall Methodology v2.2
Why Firewalls Should be Secure by Default

企業防火牆配置指南
企業防火牆方法論 v2.2
爲什麼防火牆應該默認安全

About CyberRatings.org

關於CyberRatings.org

CyberRatings.org is a 501(c)6 non-profit organization dedicated to providing confidence in cybersecurity products and services through our research and testing programs. We provide enterprises with independent, objective ratings of security product efficacy to make informed decisions. To become a member, visit and follow us on LinkedIn.

CyberRatings.org是501(c)6非營利性組織,致力於通過我們的研究和測試項目提供網絡安全產品和服務的信心。我們爲企業提供獨立、客觀的安全產品有效性評級,以做出明智的決策。要成爲會員,訪問並關注我們的LinkedIn。

SOURCE CyberRatings.org

來源 CyberRatings.org

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論