39:51A Paradigm Shift in Cybersecurity…Intelligent Network Security
Download resourcesAbout this session
Ashwath Murthy of the Palo Alto Networks product team presents PAN-OS 10.0, which the company positions as the first machine-learning-powered next-generation firewall, and the three capabilities it leads with. First, IoT security: the firewall feeds telemetry to a cloud ML engine that identifies every connected device, including ones never seen before, scores their vulnerabilities and pushes device-based policy recommendations to existing firewalls with no extra sensors. Second, the CN-Series, a containerized firewall that runs inside Kubernetes to give pod-to-pod, east-west Layer 7 visibility and control that a perimeter firewall cannot see, managed through Panorama alongside hardware and virtual form factors. Third, inline machine learning on the data plane to block unknown file, URL and DNS threats in real time, complemented by WildFire signature delivery cut from minutes to seconds. He closes on TLS 1.3 and HTTP/2 decryption support and argues that with roughly 95% of enterprise traffic now encrypted, decryption is a prerequisite for any of these controls. The talk is a vendor product presentation delivered as a pre-recorded session.
Cyberattacks are ever evolving, increasingly using automation to morph and elude detection. Add to this an ever-expanding attack surface, rapid growth of both cloud adoption and remote users, and a flood of new, hard-to-secure IoT devices. Clearly, the enterprise threat landscape has never been more challenging.
Traditional manual and reactive security approaches are simply overmatched.
So, how do you proactively manage policy changes, protect devices and stop new threats? You need a radical new approach to network security that can scale faster than manual approaches.
Join us as we share our perspective on why cybersecurity needs a radical new approach - from an “always react” mode to a “proactively protect” mode. Our expert will introduce the radical new ML-based innovations in PAN-OS 10.0 along with a slate of brand new capabilities to help your network security stay ahead of threats.
Key takeaways
- Inventory IoT devices from network telemetry you already collect before buying new sensors; agentless discovery scales better than endpoint agents on unpatchable devices.
- A perimeter firewall sees a Kubernetes cluster as one source; to distinguish an ordering pod from a payment pod you need enforcement inside the cluster.
- Signature-only defences lose to polymorphic malware; pair inline ML verdicts with fast signature updates so the first victim is not the sacrificial one.
- With most enterprise traffic encrypted, plan TLS 1.3 decryption now and use it to find legacy apps still on weak ciphers.