Is SSL Hurting More Than Helping Middle East Organizations?

Regional security expert sheds light on SSL encryption that is being commonly used by organizations in the country
By: A10 Networks
 
April 16, 2015 - PRLog -- Dubai, UAE - SSL encryption is a double-edged sword for many organizations in the Middle East. It bolsters security by providing confidentiality and message integrity. It also enables organizations to verify the identity of application owners and allows applications to authenticate users with client certificates. Unfortunately, encryption can also be used by attackers to infiltrate enterprises.

Glen Ogden, Regional Sales Director, Middle East at A10 Networks says that encryption puts organizations at risk. Hackers leverage encryption to conceal their exploits from security devices like firewalls, intrusion prevention systems, forensics solutions, and more that can’t keep up with increasing SSL decryption demands or that cannot decrypt SSL traffic at all because of their location in the network.

According to a recent Gartner survey (https://www.gartner.com/doc/2635018/security-leaders-address-threats-rising), “less than 20 percent of organizations with a firewall, an intrusion prevention system (IPS) or a unified threat management (UTM) appliance decrypt inbound or outbound SSL traffic.” This means that hackers can evade over 80 percent of an organization’s network defenses simply by tunneling attacks in encrypted traffic.

SSL/TLS is the New Default Transportation Protocol

SSL usage has become ubiquitous, and many leading websites now encrypt every web request and response. In fact,48 percent more of the million most popular websites use SSL in 2014 than a year earlier (http://news.netcraft.com/archives/2014/01/03/january-2014...). However, the transition from 1024- to 2048-bit SSL key lengths, combined with growing SSL bandwidth demands, has burdened security devices that decrypt SSL traffic. The impact of decryption on security devices is startling. Analysis by NSS Labs (https://www.nsslabs.com/sites/default/files/public-report...) reveals that 2048-bit SSL ciphers “caused a mean average of 81 percent in performance loss” for seven leading next-generation firewalls.

However, encrypted traffic is often not protected with intrusion protection technology. Cyber tools are not protecting the organization’s assets and are letting encrypted traffic pass through the network unchecked.

But wait a minute—didn’t we solve SSL performance problems in the data center years ago? Specialized appliances, load balancers, application delivery optimization, and offloading CPU-intensive SSL encryption processes are all aimed to address these issues. However, in addition organizations need modern tools to secure and optimize their modern firewalls and cyber protections.

To help organizations decrypt and inspect SSL traffic without degrading network performance, third-party security devices can be used to inspect encrypted traffic and eliminate the blind spot imposed by SSL encryption.

These security devices have the capabilities to:

·         Uncover cyberattacks hidden in SSL traffic

·         Maximize uptime by load-balancing multiple third-party security appliances

·         Scale performance and throughput to successfully counter advanced threats

·         Deploy best-of-breed content inspection solutions to fend off attacks and malware

In today’s work environment, more and more network traffic is being encrypted. As information technology managers, we need to ensure the correct information is being protected, while the necessary infrastructure is in place to protect the organization. Managed correctly, SSL traffic can provide the necessary protections while not exposing the vulnerabilities on the company’s security infrastructure.

About A10 Networks

A10 Networks  is a leader in application networking, providing a range of high-performance application networking solutions that help organizations ensure that their data center applications and networks remain highly available, accelerated and secure. Founded in 2004, A10 Networks is based in San Jose, Calif., and serves customers globally with offices worldwide. For more information, visit: http://www.a10networks.com (http://ctt.marketwire.com/?release=1170983&id=5283226&type=1&url=http%3a%2f%2fwww.a10networks.com%2f)

A10 Networks, A10 Thunder, A10 Harmony and ACOS are trademarks or registered trademarks of A10 Networks, Inc. in the United States and other countries. All other trademarks are property of their respective owners.
End
Source:A10 Networks
Email:***@brand-form.com Email Verified
Tags:A10 Networks, Glen Ogden, Ssl
Industry:Technology, Telecom
Location:Dubai - United Arab Emirates
Account Email Address Verified     Account Phone Number Verified     Disclaimer     Report Abuse
Brand Form News
Trending
Most Viewed
Daily News



Like PRLog?
9K2K1K
Click to Share