share_log

CyberRatings.org Announces Enterprise Firewall Test Results

CyberRatings.org Announces Enterprise Firewall Test Results

CyberRatings.org宣布企业防火墙测试结果
PR Newswire ·  06/27 08:00

Multiple exploits for each evasion technique were used to measure each product's defense.
Protection rate scores ranged from 37.01% to 99.87%.

M使用多个漏洞来测试每个产品的美国国防航空。
保护率得分为37.01%至99.87%。

AUSTIN, Texas, June 27, 2024 /PRNewswire/ -- CyberRatings.org (CyberRatings), the non-profit entity dedicated to providing confidence in cybersecurity products and services through its research and testing programs, has completed an independent test of eight market leading enterprise firewall vendors. Seven products were Recommended, and one received a Caution rating.

德克萨斯州奥斯汀,2024年6月27日 /美通社/ --CyberRatings.org(CyberRatings)是一个非营利实体,致力于通过其研究和测试计划提供网络安全概念中对于产品和服务的信恳智能。该机构已完成了对八个领先市场的企业防火墙供应商的独立测试。其中七款产品获得推荐,一款获得了警告等级。

Enterprise firewalls are used to protect a trusted network from an untrusted network while allowing authorized communications to pass from one side to the other, thus facilitating secure business use of the Internet. Protection rate tests verified how effectively the firewall protected control network access, applications, and users while preventing threats (exploits and evasions), blocking malicious traffic under extended load, and remaining resistant to false positives.

企业防火墙用于保护信任网络免受来自不信任网络的攻击,同时允许授权的通信从一侧传递到另一侧,从而方便安全地使用互联网进行业务。保护率测试验证了防火墙在保护控制网络访问、应用程序和用户的同时,防止威胁(利用和回避)、阻止扩展负载下的恶意流量并保持对误报的抵抗力。

"An attacker can bypass protection if a firewall fails to detect a single form of evasion." - Vikram Phatak, CEO

"如果防火墙未能检测到一种回避形式,则攻击者可以绕过保护。" -- Vikram Phatak, 思科CEO

Post this
发帖:

Key Findings:

主要结果:

  • When an exploit is blocked by a firewall, applying an evasion technique to that exploit is often easier for an attacker than finding a new exploit that isn't blocked by that firewall.
  • Threat actors apply evasion techniques to disguise and modify attacks to avoid detection by security products. Missing a type of evasion means a hacker can use an entire class of exploits to circumvent the security product. CyberRatings used multiple exploits for each evasion technique to see how each product defended against these combinations.
  • Vendors have made progress towards "Secure by Default." For the products and versions CyberRatings tested, if a vendor's pre-defined high security configuration is selected, then firewall evasion defenses will be on by default. For other security configurations evasion defenses may not be enabled by default.
  • Encryption matters: Roughly 80% of web traffic is encrypted. The top four cipher suites account for over 95% of HTTPS traffic. It should be noted that decryption is not on by default. Firewalls will not see attacks delivered via HTTPS unless configured to do so.
  • Variants from well-known exploits are not always covered by vendors. At times, CyberRatings found multiple signatures/rules for the same Common Vulnerabilities and Exposures (CVE), with some offering more protection than others. Vendors may attempt to provide rapid coverage for high profile vulnerabilities by creating multiple exploit-specific signatures. If vendors don't follow up with more comprehensive defenses, this approach can lead to gaps in protection.
  • 当防火墙阻止一个漏洞时,攻击者往往会将一个回避技术应用到该漏洞上,这比寻找防火墙没有阻止的新漏洞更容易。
  • 网络威胁行为人应用回避技术来掩盖和修改攻击,以避免安全产品检测。如果错过某种回避类型,则黑客可以使用整个漏洞类型来规避安全产品。CyberRatings对每种回避技术使用多个漏洞来查看每个产品对这些组合的防御情况。
  • 供应商已经在"出厂即安全"方面取得了进展。对于CyberRatings测试过的产品和版本,如果选择供应商预定义的高安全配置,则防火墙规避防御将默认开启。对于其他安全配置,回避防御可能并非默认启用的。
  • 加密很重要:大约80%的Web流量是加密的。前四个密码套件占HTTPS流量的95%以上。需要注意的是,解密没有默认开启。如果没有配置,防火墙将看不到通过HTTPS传递的攻击。
  • 来自已知漏洞的变种并不总是由供应商覆盖。有时,CyberRatings会发现同一Common Vulnerabilities and Exposures (CVE)的多个签名/规则,其中一些提供比其他签名/规则更好的保护。供应商可能会尝试通过创建多个特定于漏洞的签名来为热门漏洞提供快速覆盖。如果供应商不跟进提供更全面的防御,这种方法可能导致保护中存在漏洞。

To our knowledge, this was the most comprehensive evasion test performed to date. We have accelerated our research into evasion techniques as attackers increasingly bypass defenses," said Vikram Phatak, CEO of CyberRatings.org. "An attacker can bypass protection if a firewall fails to detect a single form of evasion."

"据我们所知,这是迄今为止进行的最全面的回避测试。随着攻击者越来越多地规避防御,我们加快了对回避技术的研究,"CyberRatings.org的首席执行官Vikram Phatak说。"如果防火墙未能检测到一种回避形式,则攻击者可以绕过保护。"

The following products were tested and rated:

以下产品已测试并获得评级:

Enterprise Firewall

Rating

Protection Rate

Rated Throughput (Mbps)

Price per Protected Mbps

Check Point Quantum Force 19200 plus R81.20

Recommended

98.41 %

12,281

$11.28

Cisco Firepower 2130 Threat Defense v7.3.1 (build 19)

Caution

37.01 %

1,040

$77.34

Forcepoint 3410 NGFW version 7.1.1 build 29059

Recommended

96.89 %

14,961

$7.93

Fortinet FortiGate-900G v7.4.4 GA

Recommended

98.21 %

14,096

$3.25

Juniper Networks SRX4600 JUNOS 22.4X3.1 srx4600

Recommended

99.54 %

7,772

$13.74

Palo Alto Networks PA-450 v11.1.1

Recommended

96.36 %

1,026

$6.52

Sangfor NGAF 5300 AF 8.0.85.1029 Build 20240423

Recommended

97.48 %

5,719

$1.57

Versa Networks CSG5000 versa-flexvnf-22.1.4-B

Recommended

99.87 %

15,811

$2.15

企业防火墙

评级

保护率

额定吞吐量(Mbps)

每保护Mbps的价格

Check PointQuantumForce 19200 plus R81.20

推荐

98.41 %

12,281

$11.28

思科Firepower2130 Threat Defense v7.3.1 (build 19)

注意

37.01%

1,040

$77.34

Forcepoint 3410 NGFW版本7.1.1构建29059

推荐

96.89%

14,961

$7.93

飞塔信息Fortinet FortiGate-900G v7.4.4 GA

推荐

98.21%

14,096

$3.25

瞻博网络Juniper Networks SRX4600 JUNOS 22.4X3.1 srx4600

推荐

99.54%

7,772

$13.74

palo alto networks Palo Alto Networks PA-450 v11.1.1

推荐

96.36%

1,026

$6.52

Sangfor NGAF 5300 AF 8.0.85.1029 Build 20240423

推荐

97.48%

5,719

$1.57

Versa Networks CSG5000 versa-flexvnf-22.1.4-B

推荐

99.87%

15,811

$2.15

Keysight provided their CyPerf and BreakingPoint tools to test performance, TLS functionality and stability. TeraPackets provided their Threat Replayer tool for packet replay, and CyberRatings used its own proprietary tools for live exploits and evasions.

Keysight提供他们的CyPerf和BreakingPoint工具来测试性能、TLS功能和稳定性。TeraPackets提供他们的Threat Replayer工具进行数据包重放,而CyberRatings则使用其自有的专有工具进行现场攻击和逃逸测试。

The Enterprise Firewall Test Reports, Comparative and Security Value Map are available at cyberratings.org.

企业防火墙测试报告、比较和安全价值地图可在cyberratings.org获取。

Additional Resources:

更多资源:

Enterprise Firewall Configuration Guide
Enterprise Firewall Methodology v2.2
Why Firewalls Should be Secure by Default

企业防火墙配置指南
企业防火墙方法论 v2.2
为什么防火墙应该默认安全

About CyberRatings.org

关于CyberRatings.org

CyberRatings.org is a 501(c)6 non-profit organization dedicated to providing confidence in cybersecurity products and services through our research and testing programs. We provide enterprises with independent, objective ratings of security product efficacy to make informed decisions. To become a member, visit and follow us on LinkedIn.

CyberRatings.org是501(c)6非营利性组织,致力于通过我们的研究和测试项目提供网络安全产品和服务的信心。我们为企业提供独立、客观的安全产品有效性评级,以做出明智的决策。要成为会员,访问并关注我们的LinkedIn。

SOURCE CyberRatings.org

来源 CyberRatings.org

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发