Connect with us

Artificial Intelligence

Tenable Integrates AI-Fueled Identity Security into Exposure Management Platform

Published

on

Tenable has announced the addition of several new identity-aware features that harness the power of artificial intelligence (AI) and machine learning to provide a unified view of all user identities and entitlement risks, whether on-prem or in the cloud. Tenable Identity Exposure now gives customers the most advanced vulnerability and asset risk prioritization capabilities to identify and disrupt attack paths through Active Directory (AD). The solution is fully integrated within the Tenable One Exposure Management Platform.

According to a study conducted by Forrester Consulting on behalf of Tenable, half (50%) of surveyed IT and security professionals globally say they lack an effective way to integrate user privilege data into their vulnerability management practices. This is a problem, as AD is typically the central source of truth for most critical business applications and services within an enterprise. Compromising AD and abusing access are popular methods used in ransomware and other attacks.

Traditional AD security tools provide point-in-time scans and aggregate millions of event logs only to deliver out-of-date visibility into the security posture of directory services. Tenable Identity Exposure enables organizations to address the gaps that have existed in AD security for decades. It helps customers reduce the attack surface of their AD, providing continuous AD assessment, real-time attack detection, AI-driven exposure and risk prioritization, and detailed remediation instructions.

Tenable Identity Exposure now allows companies to manage their AD security posture across hybrid cloud environments at all times and visualize any active threats to their identities. New Tenable Identity Exposure features include:

  • Identity Unification and Identity Explorer – a view of entitlements across on-premises and cloud-based AD deployments. This provides the most accurate assessment of identity risk and unmatched intelligence to help prevent exploited identity exposures. This feature provides the most complete understanding of how to prevent identities from being used for privilege escalation or other attack vectors.
  • Identity Risk Score (powered by Tenable’s Artificial Intelligence and Data Science Engine) – a new capability that uses mature AI and machine language models to quantify the risk of an asset by combining the vulnerability, exposure and identity entitlements of an asset, leveraging Tenable’s industry-leading exposure management data.
  • Azure Active Directory support – extended support for protecting public and hybrid cloud Azure Active Directory deployments, so customers can unify identities across environments and manage cloud identity risk with Indicators of Exposure specific to Azure AD. With the shift of business applications to the cloud, alongside Active Directory, Azure AD has become a critical access control point.

Full integration of these capabilities within the Tenable One Exposure Management Platform includes single sign-on, data sharing and app switching between solutions, providing identity awareness for vulnerability, attack path analysis, cloud posture and web application security practices.

“Access misconfiguration and weak identities are at the heart of ransomware attacks and corporate data breaches. Threat actors are only one identity vulnerability away from breaking into SaaS applications and stealing data. By leveraging modern AI techniques, Tenable can now quickly identify and prioritize identity and entitlement-related problems across AD and Azure AD,” said Nico Popp, chief product officer. “The ability to safeguard identities both on-prem and in the cloud is essential for empowering customers to prevent attacks rather than just clean up the aftermath.”

Artificial Intelligence

The 43rd Edition of GITEX GLOBAL to Take Place From 16th to 20th October 2023

Published

on

The surge in international demand has rallied the world’s largest tech and start-up event to scale even higher and bigger in 2023, spearheading a global tech takeover across two Dubai mega venues next month. The 43rd edition of GITEX GLOBAL will take place from 16-20 October 2023, the blockbuster tech showpiece once again reaching full capacity at the Dubai World Trade Centre as it prepares to host more than 6,000 exhibitors, while Expand North Star, the world’s largest start-up event hosted by Dubai Chamber of Digital Economy, will kick-off its largest ever edition from 15-18 October 2023 at the new Dubai Harbour venue, featuring 1,800 start-ups from 100-plus countries at the Middle East’s biggest iconic superyacht hub.

GITEX GLOBAL and Expand North Star will comprise a combined 41 halls spanning 2.7 million sq. ft of exhibition space – a 35 per cent increase over the previous year – converging the best minds and most visionary companies to scrutinise, challenge, define, and empower the digital agendas of the world. GITEX GLOBAL will present the year’s largest AI showcase and summit, its record growth fuelled by the AI innovation wave currently gripping the globe’s imagination, as 3,500 AI-infused exhibitors reveal how this next big technology shift is transforming lives, governments, businesses, and society.

Trixie LohMirmand, Executive Vice President, Events Management, DWTC

The AI boom has also added another layer of complexity to protecting digital assets and critical IP infrastructure, with the elevated GITEX Cyber Valley taking the fight directly to the dark cyber-criminal underworld, gathering leading info-sec brands and global experts at the year’s biggest cyber security showcase. Amplifying this growth, the launch shows GITEX Impact and Future Urbanism Expo promise to be the epicentre of ground-shaking shifts in climate technology while advancing sustainable cities, and co-creating a net zero future ahead of the UN climate change summit, COP28.

“The intense demand for involvement in GITEX from the global tech and start-up community is an acknowledgement of the strong impetus to learn, exchange, debate and challenge the recent developments in the tech sphere,” said Trixie LohMirmand, Executive Vice President of Events Management at DWTC, the organiser of GITEX GLOBAL and Expand North Star. “From AI, and cyber to the mounting interest in clean tech, GITEX converges public and private sector leaders from more than 170 countries to explore the new unknown paradigms of the future digital economy.”

Steven Yi, President, Huawei MIddle East and Central Asia

Expand North Star hosted by the Dubai Chamber of Digital Economy will scale to a record size in 2023, featuring 1,800 start-ups start-up exhibitors this year to connect, inspire, and extend engagements in one of the world’s most innovative and entrepreneurial ecosystems. More than 1,000 investors from 70 countries with $1 trillion under management will also converge at the new Dubai Harbour venue, as they look to ramp up the momentum in start-up investment after a year of tepid achievements.

Saeed Al Gergawi, Vice President of the Dubai Chamber of Digital Economy, said, “Expand North Star is set to drive the next era of digital entrepreneurship and inspire the next generation of innovators and thinkers. This landmark event will serve as a strategic catalyst to expand the future of Dubai’s digital economy, creating an unrivalled platform to gather key stakeholders from the global start-up community here in the emirate.”

GITEX GLOBAL 2023 welcomes the biggest tech names delving into the latest trends, risks, challenges, and opportunities that are redefining entire industries, spearheaded by returning titans including Dell Technologies, e&, Google, Huawei, HP, IBM, Microsoft, and Tonomus. Among the debut exhibitors supercharging their international growth strategies and forging new connections are Salesforce, Broadcom, Beyon, and Deloitte.

Saeed Al Gergawi, Vice President of Dubai Chamber of Digital Economy

Steven Yi, President of Huawei Middle East & Central Asia said: “At Huawei, GITEX GLOBAL continues to hold great importance to our business year after year.  This year, our theme, ‘Accelerate Intelligence,’ demonstrates our commitment to delve into the transformative power of AI, networks, and cloud technologies. Together, we will explore how these converging forces are reshaping our world and how we can unleash the full capabilities of AI-powered solutions to reshape industries worldwide with cyber security, privacy protection and safeguarding our customer’s digital transformation journey remaining our top priorities.”

More information is available at www.gitex.com and www.expandnorthstar.com

Continue Reading

Artificial Intelligence

F5 to Show Off Multi-Cloud Networking and AI Solutions at GITEX 2023

Published

on

F5 is set to highlight a series of new solutions at GITEX Global 2023. Key developments in the spotlight include new multi-cloud networking (MCN) capabilities that extend application and security services across one or more public clouds, hybrid deployments, native Kubernetes environments, and edge sites.

The solutions represent the next evolutionary step for the F5 Distributed Cloud Services platform, which enables customers to easily integrate network operations, application performance optimization and troubleshooting, and visibility through a single management console.

The new offerings include Distributed Cloud App Connect, which provides an integrated stack approach through a single console to combine comprehensive app networking with full app security, faster provisioning, and ease of use. In addition, Distributed Cloud Network Connect makes it highly secure and simple to deploy connectivity across cloud locations and cloud providers.

The solutions come hot on the heels of F5’s 2023 State of Application Strategy (SOAS) report, which found that 85% of organizations operate distributed application deployments, spanning traditional and modern architectures and multiple hosting environments. “Distributed deployments add operational complexity and cost, obscure visibility, and increase the surface area for potential cyberattacks,” said Mohammed Abukhater, RVP for META at F5. “F5 can now deliver a platform-based approach that is cloud-agnostic and purpose-built to meet the needs of traditional and modern apps—all without increasing complexity or losing granular control and necessary visibility.”

F5 will also showcase its latest security capabilities, including new machine learning enhancements to provide F5’s cloud security portfolio with advanced API endpoint discovery, anomaly detection, telemetry, and behavioural analysis. “F5 customers can now strengthen their security posture with a continuously improving analysis engine and unified policy enforcement. These capabilities enable secure app-to-app communications through validated and monitored APIs, thereby reducing the time security teams spend correcting false positives and accelerating time-to-deployment for new services,” the company said.

Highlights include:

  • Enhanced API Security Provides Greater Protection for Modern Apps. F5 delivers API auto-discovery, policy enforcement, and anomaly detection as part of a unified WAAP service, simplifying operations and enforcement through a single console for both app and API protection. Since static signature-based controls are insufficient for protecting API endpoints due to their dynamic, evolving nature, F5 Distributed Cloud API Security utilizes optimized machine learning for automatic API discovery, threat detection, and schema enforcement.
  • AI as an Essential Element of App Security. F5 has introduced AI-driven web application firewall (WAF) capabilities, including unique malicious user detection and mitigation capabilities that create a per-user threat score based on behavioural analysis that determines intent. This enables security operations to choose between alerting or automatic blocking to mitigate an attack that would otherwise go undetected by static signatures. All traffic is monitored and proactive defences are applied based on malicious user behaviour that can be correlated across Distributed Cloud WAAP deployments. The new functionality also provides false positive suppression, making it easier to block bad traffic without accidentally blocking legitimate users, and streamlines operations by reducing the time necessary to enable specific app protections.

F5 is expanding its managed service offerings via:

    • Distributed Cloud WAAP Managed Services, enabling F5 customers to access the experience and expertise of the F5 SOC to manage WAF, bot defence, and DDoS protection. Through a shared console, customers have the ability to seamlessly move between a self-service or managed service model as the needs of their apps and approach to app security change.
    • Distributed Cloud Managed Service Portal, enabling F5 service provider partners to build and tailor their own managed service offerings based on the leading security capabilities of F5 Distributed Cloud WAAP. This approach lets partners manage Distributed Cloud WAAP on behalf of their customers without sacrificing visibility, resulting in new revenue sources and value-added services while extending the overall reach of the solution.

“F5 is increasingly standing out for its ability to secure apps in a multi-cloud environment,” said Abukhater. “On the one hand, you have networking players that have multi-cloud capabilities, but they don’t have security. Then you have security players that have capabilities in SaaS and in the cloud, but they are not multi-cloud. To get their security capabilities, you have to put your apps in their walled garden, which is not sufficient either because apps are more and more distributed to ensure the best performance. Digital services that don’t meet the expectations of end-users cost companies millions of dollars in lost sales. F5 was built to solve this problem.”

In other news set to inform the GITEX agenda, F5 NGINX has announced a new subscription option that adds enterprise-level capabilities and support to the hugely popular NGINX Open Source web server, which currently powers over 400 million websites. The Open Source Subscription is a bundle that includes enterprise support to navigate regulatory requirements, enterprise features to address a wide range of traffic management and identity use cases, as well as fleet management for risk reduction via simplified NGINX administration.

“NGINX Open Source is known as the developer’s Swiss army knife,” added Abukhater. “Whether you need a web server, reverse proxy, API gateway, Ingress controller, or cache, NGINX has you covered. However, there was one thing NGINX Open Source users kept telling us was needed: enterprise support. This is why we expect our subscription option to have a big and immediate impact across the world.”

Continue Reading

Artificial Intelligence

CyberKnight Brings Traceable AI to the Middle East

Published

on

CyberKnight has become the value-added-distributor for Traceable, which allows for discovery and security posture management, threat protection and threat management, across the entire SDLC. Traceable is a Zero Trust API Access (ZTAA) solution, which claims to actively reduce organizations’ attack surface by minimizing or eliminating implied trust for APIs.

“Besides the exponential growth of the API security market, we have observed how integral APIs have become to organizations business objectives. APIs present a fundamental challenge for legacy security tools, such as web application firewalls (WAFs) and API gateways, which cannot detect attacks against APIs. We are thrilled to partner with Jyoti, Sanjay and Traceable, the most robust API Security platform in the market, mapped to the industry’s first API Security Reference Architecture for Zero Trust.”, commented Wael Jaber, Chief Strategy Officer at CyberKnight.

“APIs are now a universal attack vector. Nowadays adversaries can simply exploit an API, obtain access to sensitive data, and not even have to exploit other areas. This is why organizations need to take API security seriously and make it an integral part of their cybersecurity strategy. Through the partnership with CyberKnight, a leading cybersecurity VAD in the Middle East, we aim to extend our regional coverage and help customers achieve comprehensive API protection,” added Jyoti Bansal, Co-Founder & CEO at Traceable.

Continue Reading
Advertisement

Follow Us

Trending

Copyright © 2021 Security Review Magazine. Rysha Media LLC. All Rights Reserved.