31
© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved. Fortinet – Fortinet Security Fabric Tomislav Tucibat Major Accounts Manager Adriatics

Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

  • Upload
    ngophuc

  • View
    244

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved.

Fortinet – Fortinet Security Fabric

Tomislav Tucibat Major Accounts Manager Adriatics

Page 2: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

2 / 31

A Global Leader and Innovator in Network Security

Fortinet Quick Facts

Platform Advantage built on key innovations

• FortiGuard: industry-leading threat research

• FortiOS: tightly integrated network + security OS

• FortiASIC: custom ASIC-based architecture

• Market-leading technology: 320 patents, 258 pending

Founded November 2000, 1st product shipped 2002, IPO 2009

HQ: Sunnyvale, California

Employees: 4600+ worldwide

Consistent growth, gaining market share

Strong positive cash flow, profitable

Cash

Revenue

2003 2015

2003 2016

Global presence and customer base

• Customers: 280,000+

• Units shipped: 2.65+ Million

• Offices: 80+ worldwide

Page 3: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

3 / 31

A Global Leader and Innovator in Network Security

Fortinet Rapid Innovation Sets The Pace

Constant platform innovation - new ASICs, OS versions, integrations, and integrated functions

Rapidly expanding product portfolio

Industry firsts, industry bests

Began Global Sales

FortiGate & FortiOS 1.0

1st FortiASIC Content

Processor

FortiManager

FortiOS 2.0

Named WW UTM

Leader

FG-5000 (ATCA)

FortiOS 3.0

1st FortiASIC Network Processor

FortiWiFi FortiOS 4.0

IPO

1st FortiASIC System

On A Chip

FortiAP FortiOS 5.0 & SoC2

1M Units Shipped

1st 40GbE Port Security

Appliance

FortiASIC NP6

FortiSandbox

New HQ

1Tbps Firewall

AWS Utility Support

1st 100GbE Port Security

Appliance

Fortinet Founded

2000 2002 2003 2004 2005 2006 2009 2010 2012 2013 2014

2.0

4.0

5.0

3.0

SoC

CP

NP6

NP

2015

Internal Network Firewall (INFW)

Page 4: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

4 / 31

Fortinet aquires AccelOps

Page 5: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

5 / 31

FortiSIEM

Fortinet Devices

Configuration, Policy & Visualization

Non Fortinet Devices

FortiAnalyser FortiCloud FortiManager FNDN

API

Sandbox

Performance, Compliance & Security Analytics

Holistic Threat Intelligence

& Security Operations

Cloud

Cloud

FortiView

FortiSIEM

Page 6: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

6 / 31

A Global Leader and Innovator in Network Security Fortinet’s Proven Advantages

Accelerating your business FAST » Custom ASICs radically increase throughput 5 – 10X other solutions

» Security is no longer a bottleneck

» Your critical information flows quickly, your users are satisfied

Protecting your business SECURE » Our own global threat research team + all in-house security technologies

= rapid and coordinated response to threats

» Independently validated as highly effective vs. today’s advanced threats

Simplifying your business GLOBAL » Unmatched coverage for all deployment scenarios

» Converged networking and security, consolidated security functions

» One scalable and versatile security platform + one management console

» Global presence and infrastructure to support customers everywhere

» Faster deployment, lower admin burden, fewer security gaps… worldwide

Page 7: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

7 / 31

FW

IPS

Baselin

e

CP 8 NP 6 6Gbps

2Gbps

3.5Gbps

FW

VPN

IPS

40Gbps

25Gbps

FW

VPN

10Gbps

9Gbps

IPS

VPN

10X data center firewall performance

5X NGFW performance

Security that keeps up with

growing bandwidth requirements

Fortinet Advantage – FAST FortiASICs Dramatically Boost Performance

Page 8: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

8 / 31

Awards & Certifications Partnerships & Industry

35 Awards

Founded by Fortinet additional members include Palo Alto Networks, McAfee and Symantec

Fortinet Advantage – SECURE FortiGuard Labs Is An Industry Leader in Threat Research

Page 9: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

9 / 31

Per Minute

72,000 Spam emails intercepted

210,000 Network Intrusion Attempts resisted

68,000 Malware programs neutralized

310,000 Malicious Website accesses blocked

67,000 Botnet C&C attempts thwarted

34 million Website categorization requests

Per Week

53 million New & updated spam rules

100 Intrusion prevention rules

920,000 New & updated AV definitions

1 million New URL ratings

8,000 Hours of threat research globally

Total Database

150 Terabytes of threat samples

17,000 Intrusion Prevention rules

5,800 Application Control rules

250 million Rated websites in 78 categories

151 Zero-day threats discovered

Based on Q4 2014 data

Image: threatmap.FortiGuard.com

Fortinet Advantage – SECURE FortiGuard Labs Threat Research

Page 10: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

10 / 31

CPRL – SECURE

Compact Pattern Recognition Language

•Spots patterns in functionality and behavior (rather than just

patterns of bytes)

•50% new malware detected

AUTO CPRL

• Created 200 signatures/day comparing to 2

signatures/day done by the analyst

Page 11: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

11 / 31

• Built to serve truly global customers

• Follow-the-sun support

• Balanced revenue across regions proves it

38%

EMEA 41%

Americas

21%

APAC

Revenue by Region, Q4 2014

HQ & Development Center

Dev. & Escalation Center

Support Center

FDN server sites

Sales Office

In-country Sales/Support

Fortinet Advantage - GLOBAL Infrastructure Built To Support Enterprises Worldwide

Page 12: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

12 / 31

EMEA Support Team (TAC)

Sophia Antipolis Prague Bangalore

London Dubai Frankfurt

Page 13: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

13 / 31

Unparalleled Independent 3rd Party Certification

Description Fortinet Check Point Cisco Palo Alto Networks

Juniper FireEye

NSS - Firewall NGFW Recommended Recommended Recommended

& Neutral Caution Caution x

NSS - Firewall DC Recommended x x x x x

NSS - Breach Detection Recommended x Recommended x x Caution

NSS - IPS (DC) ✔ ✔ x x Caution x

NSS - IPS (Enterprise) ✔ x Recommended x Caution x

NSS - WAF Recommended x x x x x

BreakingPoint Resiliency Record High - 95 x x Poor - 53 x x

ICSA Firewall ✔ ✔ x ✔ ✔ x

ICSA IPS ✔ ✔ x x x x

ICSA Antivirus ✔ x x x x x

ICSA WAF ✔ x x x x x

VB 100 ✔ Caution x x x x

AV Comparative ✔ x x x x x

Common Criteria ✔ ✔ ✔ ✔ ✔ ✔

FIPS ✔ ✔ ✔ ✔ ✔ ✔

Contains results from the latest published NSS Labs reports as of Sept. 30 2014 X = did not participate, not certified

Page 14: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

14 / 31

NSS Labs NGFW 2016

NGFW

Page 15: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

15 / 31

Gartner Enterprise firewall Web application firewall

E-mail security SIEM

UTM

Wifi

Page 16: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

16 / 31

#1 in Network Security Appliances Unit Share

IDC Worldwide Security Appliances

Tracker, March 2015 (based on annual

unit shipments)

FTNT

CSCO

CHKP

JNPR

PANW

Gaining overall

market share

Gaining share in

higher-end

markets

FortiGate – most deployed security appliance

Page 17: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved.

Security vision

Page 18: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

18 / 31

The Attack Surface Has Increased Dramatically Today’s Security is Borderless

Internal Externa

l

Mobile

Endpoint

Branch

Office

NGF

W

Campus

Data Center

DCFW

UTM

IoT

PoS

Network

Applications

Data

People

Page 19: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

19 / 31

Fortinet Security Fabric – Protecting from IoT to Cloud Scalable

Aware

Secure

Actionable

Open

Client Security

Network Security

Application

Security

Cloud Security

Secure WLAN Access

Alliance Partners

Secure LAN Access

IoT

Fortinet Security Fabric

Global Intelligence

Local

Intelligence

Page 20: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved.

New OS 5.4

Page 21: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

21 / 31

Focus Areas

APT

360o

I

S

F

W

I

S

F

W

Page 22: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

22 / 31

Out of Bounds Drive to ER Call Ambulance

Play Safe! APT

S T A N D A L O N E S A N D B O X

L I M I T E D I N T E G R A T I O N

Time to Protect: ?

F O R T I N E T A N T I - V I R U S

Time to Protect: 4 Hours.

5 . 4 : F O R T I G A T E / W E B / M A I L

+ F O R T I S A N D B O X

Time to Protect: 2-3 minutes.

5 . 4 : E N D P O I N T +

F O R T I S A N D B O X

Time to Protect: 0

Page 23: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

23 / 31

APT Dynamic Protection Ecosystem

File Submission File Submission

Detailed Status Report

FSA Dynamic

Threat DB Update

Control Host Quarantine

F O R T I S A N D B O X

F O R T I C L I E N T F O R T I G A T E

1

2

3b

1

Real-time engine & intelligence updates

Enforce Network Quarantine 3c

File Status result for auto

File Hold & Quarantine

2

FSA Dynamic

Threat DB

Update

1 File submission for Analysis

2 Respective analysis results are returned

4

4

3a

3a

R E M E D I A T I O N

Auto File Quarantine on Host with option to

hold file until result

Q U E R Y

3b Manual Host Quarantine by Admin

3c Manual Source IP Quarantine using

Firewall

P R O T E C T I O N

4 Proactive dynamic Threat DB update to

gateway and host

Page 24: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

24 / 31

… a lot like a walled city…

People establish commerce

Form interactions

Buildings

Roads

Egress point

Page 25: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

25 / 31

Modern attacks happen INSIDE the city

Page 26: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

26 / 31

I S F W

BYOD

WAN

Building Blocks

Access

Cloud

Edge

Gateway

Cloud

Data

Center

WLAN

LAN

Branch

Office

Home Office

Cloud

Cloud

Internet

S E C U R E

A C C E S S

S E C U R

E

E N D P O

I N T

S E C U R

E V M

Page 27: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

27 / 31

FortiView

Page 28: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved.

Product guide

Page 29: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

29 / 31

SECURITY

Complete Network Security Solution

USERS ENDPOINTS ACCESS SEGMENTATION NETWORK APPLICATION DATA

SECURITY

MANAGEMENT

PLATFORM

THREAT INTELLIGENCE

Page 30: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

30 / 31

FortiWeb

FortiDDoS

FortiMail

FortiADC FortiSwitch FortiAP

FortiGate

FortiClient

FortiSandBox FortiAuthenticator FortiAnalyzer FortiManager

FortiToken

FortiExtender

FortiCloud

FortiRecorder

FortiCamera

FortiVoice/

FortiGateVoice

FortiFone

3G/4G WAN

FortiCache

2 Factor OTP Token

DATA CENTER SECURITY OPERATING CENTER

LAN

MOBILE

REMOTE

Cloud based Mgmt.

FortiWAN Security gateway

Mail Security Gateway

Secure Web Caching server

Web App. Firewall

Load Balancer

WiFi Access

IP PBX L2

Switching Remote VPN

Endpoint Security

Site-to-site VPN Secure WiFi

Access

Link Load Balancer

DB Servers

App Servers

Mail Servers

Web Servers

FortiWiFi

Failopen Device

FortiBridge

File Analysis

User ID Mgmt.

Central Log & report

Central Device mgmt.

FortiTeste

r

IP Cam. Recorder

Network Tester

L7 D/DOS Mitigator

DB Security

FortiDB

Page 31: Fortinet Fortinet Security Fabric - Zaštita 2016/prezentacije/08... · Fortinet Security Fabric – Protecting from IoT to Cloud Scalable Aware Secure Actionable Open Client Security

© Copyright Fortinet Inc. All rights reserved. © Copyright Fortinet Inc. All rights reserved.

Thank you! [email protected]