The Problem PHISHING ISOLATION SOLUTION

PHISHING ISOLATION SOLUTION BRIEF
The Problem
Phishing has become the weapon of choice for cyber
criminals. Despite operating a full spectrum of email
security solutions including anti-spam, anti-virus, data
security and encryption, enterprises continue to be
impacted by targeted spear phishing that results in
credential theft and malware exploits.
Legacy email security solutions rely on a ‘good vs. bad’
determination provided by third party data feeds or
internally via large-scale email traffic and data analysis.
Because spear phishing attacks target specific individuals
within an organization, the email link is usually unique, as
is the target user. Therefore, no third party reputation data
is available, nor is there enough data to analyze internally
to make an accurate determination. If the determination is
incorrect, the first targeted “patient-zero” individuals are
sent directly to a site where credentials can be stolen, or
malware can be downloaded to an endpoint. A single error
can facilitate a costly and damaging cyber attack.
1
• Can’t keep pace with millions of variants
• Generates false positive/negatives
• Complex infrastructure leaves vulnerabilities
Secure Web Gateway
WWW
Antivirus Signatures
IDS/IDP
Firewall
Network Sandbox
Big Data Analysis
s
s
INFECTED
WEBSITES
s
WEAPONIZED
DOCUMENTS
ALLOW
OR
BLOCK?
s
PHISHING
s
@
ALLOW
OR
BLOCK?
USER
s
MALICIOUS
EMAIL
MS
EXCHANGE
Secure Email Gateway
2
12%
CLICK
• SEGs difficult to tune to detect advanced phishing attacks
• Rely on reputation and data analysis, no “patient-zero” protection
against spear-phishing
3
• 12% of trained
users still click on
suspicious links or
attachments*
• No APBM ties to
infrastructure
security policies
*Verizon’s 2016 Data Breach Investigations Report
PHISHING ISOLATION SOLUTION BRIEF
About Menlo Security
The Solution: Phishing Isolation
Menlo Security is making it safe to click
with isolation, protecting organizations
from cyber attack by eliminating the
threat of malware from web and email.
Security based on isolation technology avoids the problems of trying to
distinguish between legitimate and malicious content. Isolation inserts
a secure, trusted execution environment, or isolation platform, between
the user and potential sources of attacks. By executing user sessions away
from the endpoint and delivering only safe rendering information to user
devices, users are protected from malware and malicious activity.
Menlo Security is trusted by some of the
world’s largest enterprises. The company
was founded by security industry veterans,
in collaboration with acclaimed researchers
from the University of California, Berkeley.
Backed by General Catalyst, Sutter Hill
Ventures and Osage University Partners,
Menlo Security is headquartered in Menlo
Park, California.
WEAPONIZED
DOCUMENTS
Eliminates drive-by exploits
by isolating all email links
INFECTED
WEBSITES
WWW
s
1
Menlo Security’s Phishing Isolation solution eliminates credential theft
and drive-by exploits caused by email attacks. By integrating cloudbased Phishing Isolation with existing mail server infrastructure such as
Exchange, Gmail, and Office 365, all email links can be transformed to
pass through the Menlo Security Isolation Platform. When users click on
an email link, they are 100% isolated from all malware threats, including
ransomware. Websites can also be rendered in a read-only mode which
prevents individuals from entering sensitive information into malicious
web forms.
Secure Web
Gateway
s
@
PHISHING
MS
EXCHANGE
s
MALICIOUS
EMAIL
USER
Secure Email
Gateway
2
By opening all email links in safe isolation sessions,
MSIP eliminates “patient-zero” infections
For more information,
visit menlosecurity.com or
[email protected].
3
Enables teachable moments
With their users safely isolated, administrators can monitor behavior
statistics, and provide customizable time-of-click messages that help
reinforce anti-phishing awareness training. Administrators can also
define workflow policies for groups or individuals that determine if or
when web input field restrictions can be relaxed. With zero dependency
on on error-prone threat detection methods, such as data analytics,
Menlo Security Phishing Isolation is the only email security solution that
protects every email user the instant it’s deployed.
934 Santa Cruz Avenue
Menlo Park, CA 94025
Tel: 650 614 1795
[email protected]
© 2016 Menlo Security. All Rights Reserved.