SlideShare una empresa de Scribd logo
1 de 2
Descargar para leer sin conexión
Case Study



A Large Multi–Program National Laboratory
Stays Ahead of Next–Generation Malware
By Deploying FireEye Web Malware
Protection System

                                                                                                                     Summary
     Company               Multi-Program National Laboratory

        Industry           Government

    Description            U.S. National Laboratory tasked with advancing scientific discoveries in the disciplines of
                           energy, the environment and national security.

     Challenge             Need to continually enhance effectiveness of protection against escalating global cyber
                           threats such as advanced malware, zero-day and targeted APT attacks that target
                           sensitive data.

        Solution           Deployment of FireEye Web Malware Protection System 7000 Series appliance.

        Benefits           Rapid appliance deployment facilitated dramatic increase in speed of threat detection,
                           notification and resolution. Appliance accuracy and low false positive rates have elevated
                           usability and productivity, without adding network or security management overhead.




Chartered with enhancing the scientific foundations of a broad spectrum of national programs for fundamental research and
innovation, this multidisciplinary laboratory is at the very center of ensuring that the lives of U.S citizens can be conducted in an
environment that is safe, secure and sustainable. On a daily basis, the Laboratory handles a huge portfolio of national secrets and
sensitive data, making it a prized target for highly motivated and sophisticated cyber criminals. Given this role, the organization
places great emphasis on providing an uncompromising and robust infrastructure to support the stringent requirements of its
own team of world renowned scientists and engineers. To achieve this, the Laboratory employs seasoned security experts to
ensure that all aspects of the facility remain impervious to the most insidious and malevolent of assaults.




“FireEye is stellar! We were able to clearly demonstrate what the FireEye appliance was doing for our response times
and for our abilities to expediently remediate and protect the environment from advanced malware, zero–day and
targeted APT attacks.”
– Laboratory Lead Analyst, Cyber Defense Team



FireEye, Inc. | 1390 McCarthy Blvd. Milpitas, CA 95035 | 408.321.6300 | 877.FIREEYE (347.3393) | info@fireeye.com | www.fireeye.com
Case Study



Staying One Step Ahead                                                         FireEye Provides the Winning Edge
To guard against the ever-escalating threat of                                 The FireEye team was able to pass the stringent legal,
malicious attacks the Laboratory deployed a                                    contractual and technical prerequisites for working
comprehensive range of enterprise-class security                               with a sensitive National entity. Taking just one day to
protection components, including firewalls,                                    implement a full-scale pilot to monitor network traffic, it
intrusion prevention systems, and anti-virus solutions.                        showed immediate positive results. Within a few hours
As part of its due diligence to stay ahead of the                              of having the FireEye solution installed, alerts were
increasingly sophisticated tactics of today’s                                  generated by malicious code that was not being
criminals, such as zero-day and targeted APT                                   detected by any of the existing cyber defense tools.
attacks, the Laboratory’s cyber defense team                                   A key aspect of the implementation for the Laboratory
procured a FireEye Web Malware Protection System                               has been the significant reduction in time between the
(MPS) appliance, the FireEye Web MPS 7000 Series,                              introduction of a potential threat into the environment and
to complement the preventative measures that                                   the creation of a notification announcing its presence.
were already implemented.                                                      In similar circumstances, more traditional defenses can
                                                                               take multiple days before generating a comparable alert.
The FireEye Web MPS 7000 Series is specifically
designed for large networks and offers integrated                              One of the Laboratory’s cyber defense team members,
inbound and outbound blocking of zero-day                                      a fifteen-year network security industry veteran, stated,
malware. The suite of FireEye Web MPS network                                  “Working with the FireEye team has been great. Its support
security appliances prevents signature-evading                                 model is outstanding. In fact, it is probably one of the
threats from exploiting system weaknesses in order to                          most responsive vendors that I have ever worked with.”
exfiltrate sensitive data. Because the FireEye Web                             Through its thorough multistage testing of suspicious code,
MPS appliances are typically implemented inline,                               the FireEye Web MPS appliances restrict alerts to legitimate
the use of fast-path blocking inhibits known inbound                           issues. This accuracy promotes usability and productivity.
attacks and malware callbacks. A full-fledged virtual
execution engine (VX Engine) accurately detects
zero-hour attacks in suspicious code and Web objects
and promptly halts their progress.




Key Component
FireEye Web Malware Protection System 7000 Series appliance


FireEye is the world leader in combating advanced malware, zero-day and targeted APT attacks that bypass
traditional defenses, such as Firewalls, IPS, AV, and Web gateways!
© 2011 FireEye, Inc. All rights reserved. FireEye, Inc. and all FireEye, Inc. products are either trademarks or registered trademarks of FireEye, Inc.
Other product and company names mentioned herein may be the trademarks of their respective owners. -- CS.WMPS7000.052011



FireEye, Inc. | 1390 McCarthy Blvd. Milpitas, CA 95035 | 408.321.6300 | 877.FIREEYE (347.3393) | info@fireeye.com | www.fireeye.com

Más contenido relacionado

Más de FireEye, Inc.

Más de FireEye, Inc. (16)

M-Trends 2015 セキュリティ最前線からの視点
M-Trends 2015 セキュリティ最前線からの視点M-Trends 2015 セキュリティ最前線からの視点
M-Trends 2015 セキュリティ最前線からの視点
 
M-Trends 2015 : Les nouvelles du front
M-Trends 2015 : Les nouvelles du frontM-Trends 2015 : Les nouvelles du front
M-Trends 2015 : Les nouvelles du front
 
5 Reasons Cyber Attackers Target Small and Medium Businesses
5 Reasons Cyber Attackers Target Small and Medium Businesses 5 Reasons Cyber Attackers Target Small and Medium Businesses
5 Reasons Cyber Attackers Target Small and Medium Businesses
 
Connected Cares: The Open Road For Hackers
Connected Cares: The Open Road For HackersConnected Cares: The Open Road For Hackers
Connected Cares: The Open Road For Hackers
 
M-Trends® 2013: Attack the Security Gap
M-Trends® 2013: Attack the Security GapM-Trends® 2013: Attack the Security Gap
M-Trends® 2013: Attack the Security Gap
 
M-Trends® 2012: An Evolving Threat
M-Trends® 2012: An Evolving Threat M-Trends® 2012: An Evolving Threat
M-Trends® 2012: An Evolving Threat
 
M-Trends® 2011: When Prevention Fails
M-Trends® 2011: When Prevention Fails M-Trends® 2011: When Prevention Fails
M-Trends® 2011: When Prevention Fails
 
M-Trends® 2010: The Advanced Persistent Threat
 M-Trends® 2010: The Advanced Persistent Threat M-Trends® 2010: The Advanced Persistent Threat
M-Trends® 2010: The Advanced Persistent Threat
 
SANS 2013 Report: Digital Forensics and Incident Response Survey
SANS 2013 Report: Digital Forensics and Incident Response Survey  SANS 2013 Report: Digital Forensics and Incident Response Survey
SANS 2013 Report: Digital Forensics and Incident Response Survey
 
SANS 2013 Report on Critical Security Controls Survey: Moving From Awareness ...
SANS 2013 Report on Critical Security Controls Survey: Moving From Awareness ...SANS 2013 Report on Critical Security Controls Survey: Moving From Awareness ...
SANS 2013 Report on Critical Security Controls Survey: Moving From Awareness ...
 
2013 Incident Response Survey
2013 Incident Response Survey2013 Incident Response Survey
2013 Incident Response Survey
 
The Internal Signs of Compromise
The Internal Signs of CompromiseThe Internal Signs of Compromise
The Internal Signs of Compromise
 
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The BreachFireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
FireEye Cyber Defense Summit 2016 Now What - Before & After The Breach
 
Proatively Engaged: Questions Executives Should Ask Their Security Teams
Proatively Engaged: Questions Executives Should Ask Their Security TeamsProatively Engaged: Questions Executives Should Ask Their Security Teams
Proatively Engaged: Questions Executives Should Ask Their Security Teams
 
FireEye Advanced Threat Protection - What You Need to Know
FireEye Advanced Threat Protection - What You Need to KnowFireEye Advanced Threat Protection - What You Need to Know
FireEye Advanced Threat Protection - What You Need to Know
 
FireEye Advanced Threat Report
FireEye Advanced Threat ReportFireEye Advanced Threat Report
FireEye Advanced Threat Report
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Último (20)

"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 

National Laboratory Deploys FireEye Web Malware

  • 1. Case Study A Large Multi–Program National Laboratory Stays Ahead of Next–Generation Malware By Deploying FireEye Web Malware Protection System Summary Company Multi-Program National Laboratory Industry Government Description U.S. National Laboratory tasked with advancing scientific discoveries in the disciplines of energy, the environment and national security. Challenge Need to continually enhance effectiveness of protection against escalating global cyber threats such as advanced malware, zero-day and targeted APT attacks that target sensitive data. Solution Deployment of FireEye Web Malware Protection System 7000 Series appliance. Benefits Rapid appliance deployment facilitated dramatic increase in speed of threat detection, notification and resolution. Appliance accuracy and low false positive rates have elevated usability and productivity, without adding network or security management overhead. Chartered with enhancing the scientific foundations of a broad spectrum of national programs for fundamental research and innovation, this multidisciplinary laboratory is at the very center of ensuring that the lives of U.S citizens can be conducted in an environment that is safe, secure and sustainable. On a daily basis, the Laboratory handles a huge portfolio of national secrets and sensitive data, making it a prized target for highly motivated and sophisticated cyber criminals. Given this role, the organization places great emphasis on providing an uncompromising and robust infrastructure to support the stringent requirements of its own team of world renowned scientists and engineers. To achieve this, the Laboratory employs seasoned security experts to ensure that all aspects of the facility remain impervious to the most insidious and malevolent of assaults. “FireEye is stellar! We were able to clearly demonstrate what the FireEye appliance was doing for our response times and for our abilities to expediently remediate and protect the environment from advanced malware, zero–day and targeted APT attacks.” – Laboratory Lead Analyst, Cyber Defense Team FireEye, Inc. | 1390 McCarthy Blvd. Milpitas, CA 95035 | 408.321.6300 | 877.FIREEYE (347.3393) | info@fireeye.com | www.fireeye.com
  • 2. Case Study Staying One Step Ahead FireEye Provides the Winning Edge To guard against the ever-escalating threat of The FireEye team was able to pass the stringent legal, malicious attacks the Laboratory deployed a contractual and technical prerequisites for working comprehensive range of enterprise-class security with a sensitive National entity. Taking just one day to protection components, including firewalls, implement a full-scale pilot to monitor network traffic, it intrusion prevention systems, and anti-virus solutions. showed immediate positive results. Within a few hours As part of its due diligence to stay ahead of the of having the FireEye solution installed, alerts were increasingly sophisticated tactics of today’s generated by malicious code that was not being criminals, such as zero-day and targeted APT detected by any of the existing cyber defense tools. attacks, the Laboratory’s cyber defense team A key aspect of the implementation for the Laboratory procured a FireEye Web Malware Protection System has been the significant reduction in time between the (MPS) appliance, the FireEye Web MPS 7000 Series, introduction of a potential threat into the environment and to complement the preventative measures that the creation of a notification announcing its presence. were already implemented. In similar circumstances, more traditional defenses can take multiple days before generating a comparable alert. The FireEye Web MPS 7000 Series is specifically designed for large networks and offers integrated One of the Laboratory’s cyber defense team members, inbound and outbound blocking of zero-day a fifteen-year network security industry veteran, stated, malware. The suite of FireEye Web MPS network “Working with the FireEye team has been great. Its support security appliances prevents signature-evading model is outstanding. In fact, it is probably one of the threats from exploiting system weaknesses in order to most responsive vendors that I have ever worked with.” exfiltrate sensitive data. Because the FireEye Web Through its thorough multistage testing of suspicious code, MPS appliances are typically implemented inline, the FireEye Web MPS appliances restrict alerts to legitimate the use of fast-path blocking inhibits known inbound issues. This accuracy promotes usability and productivity. attacks and malware callbacks. A full-fledged virtual execution engine (VX Engine) accurately detects zero-hour attacks in suspicious code and Web objects and promptly halts their progress. Key Component FireEye Web Malware Protection System 7000 Series appliance FireEye is the world leader in combating advanced malware, zero-day and targeted APT attacks that bypass traditional defenses, such as Firewalls, IPS, AV, and Web gateways! © 2011 FireEye, Inc. All rights reserved. FireEye, Inc. and all FireEye, Inc. products are either trademarks or registered trademarks of FireEye, Inc. Other product and company names mentioned herein may be the trademarks of their respective owners. -- CS.WMPS7000.052011 FireEye, Inc. | 1390 McCarthy Blvd. Milpitas, CA 95035 | 408.321.6300 | 877.FIREEYE (347.3393) | info@fireeye.com | www.fireeye.com