AskPANW

Cybersecurity Chat
For Cybersecurity Awareness Month, Nir Zuk of Palo Alto Networks will be hosting a chat!
Paul Wasek
I have been noticing that other vendors are starting have a similar feature like wildfire. Is PANW looking to add or enhance current security features?
Nir Zuk
we have already gotten used to the other fw vendors copying everything we do. luckily we are good at staying ahead of them and increasing the gap with every release
Palo Alto Networks
#AskPANW @nirzuk Are company insiders or company outsiders a greater threat to cyber security?
Nir Zuk
there is no much difference anymore, given that the outsiders favorite attack vector is to take over an internal machine and from there jump to the data center. For the purpose of securing the enterprise they are both the same
John Casaretto
@nirzuk We hear much about APT's - how best to mitigate? Analytic security products seem own the headlines but not everyone is ready just yet - Are slow-adopters left to process/technology?
Nir Zuk
the solution will be a combination of processes and technologies all working together. enterprises are still trying to figure out what to do. a quick advise - if you think you found a killer solution - you are probably wrong
Nir Zuk
I think we'll end up with a new network security architecture to deal with modern threats
ilan
Are the enterprise really serious about BYOD?
Nir Zuk
They don't have a choice. End users are not asking them whether it's okay to BYOD. Sensitive coprorate information is making its way to personal mobile devices and something needs to be done to protect it
Pires Fábio
The best PAN appliance has an throughput of 20Gbps (firewall) and 15(threat), but hauwei has 35Gbps (firewall) and 25(threat). is nice to know that pan as GSP support but In an ISP scneario, witch one will be the best appliance to ensure the security ?
Nir Zuk
it's not about how fast you run but rather what you do at that speed. ISPs are trying to provide more than basic firewall and are turning to Palo Alto Networks for help. In any case, we have already said a 100Gbps device is in the works
Pires Fábio Thanks for the repply. So PAN can be applied not only in corporative scnearios but in ISP too, right ? And you a 100Gbps appliance to deal with it. is it? Can you tell me more about anti-spam ? i know palo alto do not support that, but in ISP...
Pires Fábio ... is impossible to have blacklists and block users.. in your opinion, what is the best solution ?
Nir Zuk
I believe anti-spam belongs in a dedicated system rather than in an inline firewall
Palo Alto Networks
#AskPANW @nirzuk Another pre-submitted Q: Of the vertical mkts where PANW has customers, what is hardest 2 protect/why?
Palo Alto Networks
http://twitter.com/PaloAltoNtwks/status/395602095812128768
PaloAltoNtwks
4 minutes ago
Nir Zuk
Contrary to common sense, I think that the hardest verticals to protect would be those that put a lot of restrictions around their users who have become so smart at bypassing security. I'd count financial services and government
John Casaretto
@nirzuk Where do DDoS attacks rank on the threat list for enterprise, mid-size, SMB
Nir Zuk
Apparently not too high. Less than 5% of Network Security spend goes to DDoS with most of it coming from very large enterprises
Palo Alto Networks
#AskPANW @nirzuk Everywhere u look, someone claims to have a next-gen security solution? What is the true PANW difference?
Palo Alto Networks
http://twitter.com/PaloAltoNtwks/status/395602095812128768
PaloAltoNtwks
ilan
what is your take on SDN in security space? Do you think centralized security controller will reduce capex and opex?
Nir Zuk
SDN is a big word with very little definition behind it. For me, SDN is providing a software API to the network, security included. Centralized controllers have existed since the mid-90's. APIs to managing security are new.
Nir Zuk
I think that providing APIs to network security is not about saving money but rather enabling the participation of network security in a virtualized data center where things come, go, and more around all the time
Mike Lutgen
Is there one thing that most companies are forgetting or not realizing about network security, and how do they deal with it?
Nir Zuk
I think that many companies forget that network security is not a product but a solution. A single technology, such as IPS, Sandbox, filtering, etc is not going to keep the bad guys out. It's the combination of these technologies that will help