Solution Brief | Check Point Endpoint Security Enhances Ransomware Protection with Intel vPro

Solution Brief | Check Point Endpoint Security Enhances Ransomware Protection with Intel vPro

Learn how Check Point Endpoint Security and Intel Threat Detection Technology (Intel TDT) help detect and stop ransomware faster. Protect against fileless, zero-day, and virtual machine-based attacks with AI-driven, hardware-assisted cyber security.

Solution Brief | Check Point Endpoint Security Enhances Ransomware Protection with Intel vPro

Ransomware attacks on the rise Ransomware attacks are increasing globally, and cybercriminals are becoming more sophisticated.1 Many ransomware groups operate like regular businesses, taking advantage of ransomware-as-a-service (RaaS) and targeting specific victims to maximize return.1 Cybercriminals also take advantage of the growth in numbers of remote workers to exploit vulnerabilities like unsecured networks or third-party application access policies. And they are employing novel approaches like disguising ransomware in client virtual machines (VMs) where it is difficult to detect. The rise in ransomware increases pressure on IT teams to protect enterprise data.

To stay one step ahead of cyber criminals, organizations are adopting more comprehensive security strategies. This includes protection at both the software and hardware layers. And they look to industry leaders like Check Point Technologies, a multinational provider of cyber security solutions, for help.

Check Point Technologies has enhanced its endpoint protection platform for customers battling ransomware by integrating Intel Threat Detection Technology (Intel® TDT)—which is available on Intel vPro—into Check Point Harmony Endpoint. Intel TDT augments Harmony Endpoint with hardware-based ransomware detection capabilities. These capabilities utilize CPU telemetry and machine learning (ML) heuristics to detect the presence of ransomware, even when it uses advanced obfuscation techniques to hide itself. With Intel TDT, Harmony Endpoint can detect sophisticated ransomware threats sooner during an attack. Faster detection helps deliver faster responses and faster remediation. The following three use cases illustrate the benefits of Harmony Endpoint with Intel TDT.

Detecting ransomware attacks on unprotected VMs Ransomware attacks on client PC VMs are increasing.2 And these types of attacks are more difficult to detect. To identify these types of attacks sooner, Harmony Endpoint benefits from telemetry data provided by Intel TDT running on Intel vPro. By profiling and detecting ransomware at the CPU level, Intel TDT can alert Harmony Endpoint about malicious code cloaked in a VM more quickly (see Figure 1).

Check Point Harmony Endpoint expands its anti-ransomware capabilities by integrating Intel® Threat Detection Technology for accelerated detection.

Check Point Harmony Endpoint with Intel TDT offers an expanded protection platform and faster time-to-detection. For users with Intel vPro, it helps protect users against:

• Ransomware attacks on unprotected client VMs

• Fileless ransomware attacks on client memory

• Zero-day ransomware attacks on enterprises

Solution Brief Endpoint Security Intel vPro®

Check Point Technologies Enhances Ransomware Protection with Intel vPro

Detecting fileless ransomware attacks on memory

Fileless ransomware runs in client PC memory. By using trusted tools rather than files to execute its attack, fileless ransomware is difficult to detect and remove. With Intel TDT, Harmony Endpoint is able to detect fileless ransomware faster and to begin the remediation process sooner.

Intel TDT tracks encryption at the CPU level using telemetry from the performance monitoring unit (PMU). Intel CPU telemetry is immune to most bypasses and can recognize derivative variants. ML heuristics allow Intel TDT to recognize ransomware encryption as being different from other types of encryption. Using this information, Harmony Endpoint recognizes ransomware encryption commands earlier in the attack flow and can block the attack before it reaches the operating system (OS).

Figure 2 shows the location of the Intel PMU beneath applications, the OS, and virtualization layers.

Solution Brief | Check Point Technologies Enhances Ransomware Protection with Intel vPro

Figure 1. Check Point Harmony remediates the ransomware cloaked as a lightweight VM once it receives the alert from Intel TDT

Figure 2. The Intel PMU gathers telemetry data generated by the CPU

Check Point Harmony Endpoint software

Intel TDT

ML model detected threat

AI runtime threat heuristics

PMU telemetry

CPU: System on chip (SoC)

Intel® CPU

VM (malicious)

Windows (Host OS)

VMM (Type-2)

Ransomware

Apps

OS Intel TDT

2

Protecting enterprises and remote workforces

Harmony Endpoint is a complete endpoint security solution built to protect enterprises and their remote workforces from today’s complex threat landscape. Key benefits of Harmony Endpoint include:

• Complete endpoint security. Harmony Endpoint offers 360-degree endpoint protection capabilities, advanced endpoint detection and response (EDR), and zero-day attack prevention.

• Automation from prevention through remediation. Harmony Endpoint delivers automated detection, investigation, and remediation, integrating artificial intelligence (AI) for increased accuracy.

• Outstanding total cost of ownership (TCO). Endpoint protection is available in a single, efficient solution, managing all operating systems and simplifying security operations.

Solution Brief | Check Point Technologies Enhances Ransomware Protection with Intel vPro

Helping discover zero-day ransomware attacks

Zero-day attacks target vulnerabilities for which a software provider has not yet created a patch. Because the vulnerabilities are not yet known, these exploits are often successful. Harmony Endpoint now has enhanced capabilities for discovering zero-day ransomware attacks faster with Intel vPro.

Intel TDT uses hardware-based telemetry to help detect the presence of ransomware. Once a threat is detected, Intel TDT can send a signal alerting Harmony Endpoint so that remediation workflows can be triggered.

Check Point’s anti-ransomware, which is included in Harmony Endpoint, offers runtime protection with instant automated remediation and Behavioral Guard capabilities. It can identify, block, and remediate the full cyber-attack chain. Once an attack has been detected, the infected device can be automatically quarantined to prevent lateral infection movement, and it can then be restored to a safe state. With the integration of Intel TDT, Harmony Endpoint further enhances its ransomware-detection capabilities with Intel vPro.

Figure 3. Harmony Endpoint offers instant, full remediation

3

Intel technologies may require enabled hardware, software or service activation.

No product or component can be absolutely secure.

Your costs and results may vary.

Intel does not control or audit third-party data. You should consult other sources to evaluate accuracy.

© Intel Corporation. Intel, the Intel logo, Intel vPro and other Intel marks are trademarks of Intel Corporation or its subsidiaries. Other names and brands may be claimed as the property of others.

Printed in USA 0323/MG/PRW/PDF Please Recycle 354667-001US

1 Cybersecurity & Infrastructure Security Agency. “2021 Trends Show Increased Globalized Threat of Ransomware.” February 2022. cisa.gov/uscert/ncas/alerts/aa22-040a. 2 TechTarget. “Secure your infrastructure against VM ransomware.” July 2022. techtarget.com/searchitoperations/tip/Secure-your-infrastructure-against-VM-ransomware.

Solution Brief | Check Point Technologies Enhances Ransomware Protection with Intel vPro

Learn more about Harmony Endpoint with Intel TDT:

checkpoint.com/harmony/advanced-endpoint-protection/

Processor support

Harmony Endpoint enhances ransomware detection for devices built on Intel vPro and powered by 10th Generation Intel® Core™ processors or newer.

IT teams that use Harmony Endpoint and Intel vPro are better equipped to combat the ever-increasing threat of ransomware attacks. They can benefit from faster time-to-detection and the resulting accelerated response time.

4


Item Type: pdf