benny czarny president and ceo | opswat, inc. · gartner estimates that this market grew 87% from...

120
Benny Czarny President and CEO | OPSWAT, Inc.

Upload: others

Post on 22-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Benny Czarny

President and CEO | OPSWAT, Inc.

Page 2: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

What is NAC?

Benny Czarny Benjamin Czarny

Page 6: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Endpoints

Page 7: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Control Endpoint Security

Health State

Page 8: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common NAC Use-Cases

Page 10: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Create Business Segmentation

Page 12: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Prevent Network Worms

Page 14: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

W32.Blaster.Worm WormExploits of DCOM RPC

vulnerability, no user interaction was required to spread.

DOS attack to Windowsupdate download site

Page 15: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Control

Remote Access Users

Page 17: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Health Insurance Portability and

Accountability Act (HIPAA)

Page 18: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Protect Management's Ass

Page 19: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Gartner estimates that this

market grew 87% from 2006 to a

total of $225 million in 2007.

Gartner anticipates approximately

100% growth in 2008 (3/08)

Page 20: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

$3.2 billion in 2010, up

from just $526 million in

2005

- IDC report (6/07)

Page 21: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Source: 2006 Infonetics Research, Enforcing Network Access Control:

Market Outlook and Worldwide Forecast

Page 23: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common NAC Framework

Architectures

Page 25: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Could be delivered as Software

Page 26: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

or Hardware

Page 27: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

NAC Concepts

Page 29: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common Network Detection

and Quarantine Technologies:

• ARP

• 802.X

• DHCP proxy

• Special Hardware

• SNMP

• Virtual Networks

• Frameworks (NAP,TNC)

Page 31: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Check Endpoint Health

Page 32: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common Health Check Verticals

Page 33: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

• Many security applications

• Several operating systems

• Security applications keep changing

• Security application keep evolving

Health Agent

Technology Challenges

Page 35: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common Anti-malware control

• Features Activity

• Product and Signature Currency

• Threat history

• Authenticity checks

Page 38: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Pre-Admission

Page 39: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Post-Admission

Page 41: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Common Remediation Actions

• Trigger AV real time protection

• Update AV

• Perform full system scan

• Patch endpoint

• Turn on firewall

• Block firewall port

Page 42: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Source: 2007 BT INS IT Industry Survey

Page 43: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Health Agent Technology

Page 44: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

via Network Monitoring

Page 45: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

<Server Name="etrustdownloads.ca.com" Port="80" Protocol="TCP">

<Http Secure="0">

<Request Type="GET">

<Path>/updates/eav/arclib/arclib.idx</Path>

<Path>/updates/eav/base/etrust_antivirus_base.idx</Path>

<Path>/updates/eav/drvupdi/drvupdi.idx</Path>

<Path>/updates/igateway/igateway.idx</Path>

<Path>/updates/eav/inoeng/ino_engine.idx</Path>

<Path>/updates/eav/eavlocgui/eavlocgui.idx</Path>

<Path>/updates/caupdate/caupdate.idx</Path>

<Path>/updates/eav/veteng/vet_engine.idx</Path>

<UserAgent Random="0">CAUpdate</UserAgent>

</Request>

</Http>

</Server>

</QueryInfo>

<UpdateProg>

<!-- updating -->

<Server Name="etrustdownloads.ca.com" Port="80" Protocol="TCP">

<Http Secure="0">

<Request Type="GET">

<Path>

/updates/eav/

<Format>STRING</Format>

.pkg

</Path>

<!--ie. GET /updates/eav/veteng/vet_incr_3492.pkg HTTP/1.0

<UserAgent Random="0">CAUpdate</UserAgent>

</Request>

<Response Encrypted="1">

<HttpVersion>1.0</HttpVersion>

<StatusCode>200 OK</StatusCode>

<ContentType>text/plain</ContentType>

</Response>

</Http>

</Server>

</UpdateProg>

Monitor Antimalware Update network signature

Page 46: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Via Code Running on Endpoint

Page 47: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

• Browser plug-in

• Executable (process)

• Application

• Windows Service/Linux demon

• RPC Calls

Common Health Agent Technologies

Page 48: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Health Agent Pre Admission

Post Admission

Post Admission afterreboot

Worksas Guest

Update Process

Browser Plug-in√ × × √

Executable√ √ × √

Application √ √ √ ×

Daemon√ √ √ ×

RPC√ √ √ ×

Page 49: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Why should

Anti-malware companies

Partner with NAC?

Page 50: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Interoperability = more BU$INESS

Page 52: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Competitive Defense

Page 56: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

NAC Agent does not detect

Antimalware application

Page 57: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

User is directed to

Remediation Screen

Page 59: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

NAC Vendors

Page 60: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Branding

Page 66: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Be there or be

Page 68: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Real Antivirus I look like an Antivirus

Page 69: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Spoof Antimalware

digital Identity

Page 70: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Spoof Binary Identity

Page 74: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

1. Endpoint connects to the network

2. NAP Client collects endpoint health state.

3. Endpoint health state is communicated to NPS

4. Security policy decision is passed to network infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 75: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Partner with Microsoft

Page 77: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Develop SHA

Page 78: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Develop SHV

Page 80: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Market

Page 87: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

1. Endpoint connects to the network

2. TNC client collects endpoint health state.

3. Endpoint health state is communicated to TNC Server

4. Security policy decision is passed to network infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 91: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Market

Page 96: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Slow adoption.

Page 97: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Development Costs $

Page 98: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Cisco NAC and

Other Frameworks

Page 99: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

1. Host assessment via OESIS Framework

2. Host info sent to Policy Server

3. Policy Server validates policy against application management server settings

4. Results are communicated to the network device infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 100: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Submit applications to

OESISOK™

Page 101: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Upload Anti-malware Packages

Page 103: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Get listed in the support charts

Page 108: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

$0 Development Cost

Page 109: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

“Cisco’s NAC Appliance holds a commanding

47% market share in the cluttered NAC”

- Network world

Page 111: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

only.

Page 113: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Other OESISOK™ based

NAC Frameworks

Page 115: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Other Options

Page 117: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Future Development

Page 118: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Enforcing Network Access by

Quality of Anti-malware applications

Page 120: Benny Czarny President and CEO | OPSWAT, Inc. · Gartner estimates that this market grew 87% from 2006 to a total of $225 million in 2007. Gartner anticipates approximately 100% growth

Questions ?

Benny Czarny

CEO and Founder OPSWAT, Inc.