目前位置: 新聞總覽 -> 最新訊息 -> Fortinet advises Cyber Distancing and Network Isolation to protect organizations from cyberattacks.
2021年04月21日
Fortinet, a global player in broad, integrated and automated cyber security solutions, announced that over the past several weeks, FortiGuard Labs has been monitoring a significant spike in COVID-19 related threats. Cybercriminals are unleashing a surprisingly high volume of new threats in this short period of time to take advantage of inadvertent security gaps as organizations are in a rush to ensure business continuity.
Cybercriminals Are Exploiting the Rapid Change to Our Digital World
An unprecedented number of unprotected users and devices are now online with one or two people in every home connecting remotely to work through the internet. Simultaneously there are children at home engaged in remote learning and the entire family is engaged in multi-player games, chatting with friends as well as streaming music and video. FortiGuard Labs is observing this perfect storm of opportunity being exploited by cybercriminals as the Threat Report on the Pandemic highlights:
Solutions and Countermeasures
Organizations should take measures to protect their remote workers and help them secure their devices and home networks. Consider adopting the same strategy for cyber viruses that we are adopting in the real world. Cyber social distancing is all about recognizing risks and keeping our distance. Isolation is all about segmenting networks and quarantining the malware from spreading across the network. Here are a few critical steps to consider:
Endpoint Security: Endpoint Security provides a VPN client to ensure that remote traffic remains secure. For organizations looking for an even more robust endpoint security solution a EDR solution provides advanced, real-time threat protection for endpoints both pre and post-infection, in addition to robust antivirus technologies installed at the kernel to detect and prevent malware infection, it can also respond to device breaches in real-time by detecting and defusing potential threats before they have the chance to compromise the system.
Connectivity: VPN connections can be run and managed independently, organizations with large numbers of remote workers may need the addition of an Enterprise Management Server solution. An EMS solution can securely and automatically share information between endpoint and the network, push out software updates, and assign security profiles to endpoints.
Access to Cloud Applications: Driving all traffic through a VPN tunnel can actually have a doubling impact on network traffic. In addition to all of the remote workers connecting into the network, the network will also need to manage all of the outbound connections to cloud services. However, since this traffic will not be run through the organization’s edge security solutions, these direct connections will require a cloud-based security solution. Cloud Access Security Broker (CASB) will provide visibility, compliance, data security, and threat protection for access to SaaS and other cloud-based services being used by an organization.
Network Access Control: Cybercriminals intend to exploit this rapid transition to a teleworker strategy by hoping to get overlooked by masquerading as a legitimate corporate end-user or IoT device, or by hijacking a legitimate device. Network Access Control tools can see and identify everything connected to the network, as well as control those devices and users, including dynamic, automated responses. Network Access Control enables IT teams to see every device and user as they join the network, combined with the ability to limit devices access in the network, and automatically react to devices that fall out of policy within seconds.
Network Segmentation: Network segmentation ensures that devices, users, workflows, and applications can be isolated to prevent unauthorized access and data loss, as well as to limit exposure if there is a breach at the network perimeter. Next Generation Firewall enables segmentation at the network perimeter further this can be enhanced using an Internal Segmentation Firewall.
Zero-Trust Network Access: The best security posture during this period is to consider that every user and device has already been compromised.
Combining all of the solutions outlined above organizations can ensure that devices and users are limited to access network resources they require to do their job, and nothing more.
Source:
https://www.expresscomputer.in/news/fortinet-advises-cyber-distancing-and-network-isolation-to-protect-organizations-from-cyberattacks/54696/