Presentation on theme: "Next Generation FWs Against Modern Malware and Threads Hakan Unsal – Technical Security Consultant Tunc Cokkeser – Regional Sales Manager."— Presentation transcript:
Next Generation FWs Against Modern Malware and Threads Hakan Unsal – Technical Security Consultant Tunc Cokkeser – Regional Sales Manager
The Strategic Role of Modern Malware Infection Escalation Remote Control Malware Industry: 1 Trillion Dollar A new unknown MALWARE in each 1,5 sec Hidden in SSL or SSH tunneld / encrypted traffic Resource consuming MALWARE
How a NGFW Should Be!!!Secure Enablement Secure Enablement - Block – e.g. – all P2P applications - Allow - but scan for threats - Allow - but limit app users - Allow - but limit app functions - Allow - but limit apps in a session - Allow - but limit access time - Allow - but shape (QoS) Low High Network Control
How a NGFW Shoud Be!!! Application Identification Algorithm
How a NGFW Should Be!!! A Realtime Application Identification Throughput L3/L4 UDP Packet throupghput is no longer reflects your requirements!!! APP - ID Application Identification Enabled Throughput is important for you!!! L7 Throughput should be considered No Acceptance for Dramatic Performance Decrease !!!