White Paper | R81 Cyber Security Platform

White Paper | R81 Cyber Security Platform

Explore the R81 Cyber Security Platform and its approach to unified security management, threat prevention, policy automation, and operational efficiency. Learn how organizations can strengthen cyber security, simplify administration, and improve visibility across distributed environments.

White Paper | R81 Cyber Security Platform

R81 CYBER SECURITY PLATFORM THREAT PREVENTION AND MANAGEMENT SOFTWARE

FOR THE NEW NORMAL

2CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Table of Contents

Cyber Security Management in 2021 .......................................................... 3 The Need for a New Cyber Security Management ..................................................4

Embracing the New World with New Opportunities .................................. 5 How Deployment and Scalability Work with R81 ....................................................6

The Four Pillars – building blocks of R81 Cyber Security Platform ......... 7 Automated Security ..................................................................................................8

Infrastructure as Code (IaC) .....................................................................................................8 Autonomous Threat Prevention ...............................................................................................8

Consolidated Security ............................................................................................10 Custom Intelligence Feeds ..................................................................................................................10 Consolidated Traffic Monitoring and Improved Indexing Capabilities ...............................................10

Dynamic Security ................................................................................................... 11 Dynamic Objects ..................................................................................................................... 11 HTTPS Inspection ...................................................................................................................13 NAT Policy ...............................................................................................................................13 Generic Data Center ...............................................................................................................13 Data Center Query Objects .....................................................................................................13

Efficient Operations ................................................................................................15 Policy Layers ...........................................................................................................................15 Concurrent Admin Sessions...................................................................................................15 Changes Report (sessions and revisions) ..............................................................................16 Multi Install Policy Sessions ..................................................................................................16 Accelerated Install Policy .......................................................................................................16 Licenses ..................................................................................................................................18

Summary ....................................................................................................18

3CHOOSING THE BEST CYBER SECURITY MANAGEMENT

UNDERSTANDING CYBER SECURITY PLATFORMS IN 2021

Managing all aspects of network security solutions in your environment can be a complex task. Aside from enforcing defense strategies that include access, identity, compliance and threat prevention, it has to take into account all business requirements, allow for rapid changes in the network infrastructure, be able to adapt new technologies and trends seamlessly, and enable agile deployment of applications and services. We are talking about delegating cyber security across our organizations, this means our networks, our data centers, and our multi-cloud environments all need to be working up to par while simultaneously preventing the next attack. There are more connected devices, new applications and sophisticated threats than we could ever imagine. And that was before the changed course for rapid digital transformation and remote work forces took place.

Enter R81 cyber security platform, the industry’s most advanced Threat Prevention and security management software that delivers uncompromising simplicity and consolidation across the enterprise. Whether it is deploying the latest threat prevention technologies or automating the creation of security policies, R81 provides enterprises the most efficient security administration and management.

This whitepaper will cover the key principles needed for a cyber security management platform, ensuring organizations get the most out of their cyber security investments and references Check Point's latest cyber security management platform.

4CHOOSING THE BEST CYBER SECURITY MANAGEMENT

The Need for a New Cyber Security Management The concept of the security perimeter is ever changing. We are in a digital age of hyper-connectivity and processing power converging across our data centers. Our networks continue to grow and the threat landscape continues to become ever more sophisticated. Let alone the increase of remote workers and businesses going mobile only adds to this concern. This means that the infrastructure we must secure is no longer on our physical premises plugged into our physical networks. Applications and on-demand services are automatically provisioned with a click of a button. Cloud, mobile, and IoT devices are rapidly changing the IT landscape, providing tremendous opportunities as well as new risks that must be managed.

Despite the changing landscape, which includes the proliferation of security enforcement points in a number of form factors, the challenge remains the same: how to securely manage this expanding cyber security infrastructure.

To meet these challenges, cyber security management has to be based on 4 pillars:

• Automated security into CI/CD pipelines reducing configuration errors, speeding deployments and enabling the orchestration of operational processes

• Consolidated to enable efficiency, reduce OPEX and CAPEX costs and bring clarity of vision that comes with managing security policy and events under one umbrella that is tightly integrated together

• Dynamic functionality and agility to keep pace with the ever evolving demands in cyber security

• Efficient operations so that the cyber security management doesn’t slow the pace of change

These four pillars, are the foundation of Check Point R81 security management platform, the industry’s most advanced threat Prevention and security management software, managing the security of your entire estate, on-premises networks, cloud networks and workloads, remote users and their access to cloud applications and the Internet and IoT. This document will focus on the network security policy and threat management aspects of the Check Point R81 security management platform.

Headquarters Data Center / Hybrid Cloud

Branch Public Cloud Private Cloud IoT

Figure 1: R81 Deployment

5CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Embracing the New World with New Opportunities

R81 is the industry’s most advanced Threat Prevention and security management software that delivers uncompromising simplicity and consolidation across the enterprise. Providing autonomous prevention, R81 aims to relieve the IT admins daily effort and make managing cyber security the simplest it’s ever been.

R81 offers a simplified approach for managing all network security aspects of a given organization regardless of where the enforcement points are deployed. It could be physical appliances protecting the WAN edges and internal network boundaries, virtual appliances protecting private, public and hybrid cloud environments (both North-South and East-West), or cloud Firewall-as-a-Service to securely connect remote workforces and offices to the modern corporate network.

HIGHLIGHTS

• One console to manage all network security aspects (access to threat prevention

• Highest levels of security with AI-driven autonomous threat prevention.

• Rapid response to changing security needs with super-fast policy installation – Reducing policy installation by 90%.

• Optimal security for SSL traffic: utilizing the latest standards for secure connectivity (TLS 1.3 and HTTP/2).

• Intuitive policy segmentation capabilities (inline shared policy) for better administration.

• Delegation and Collaboration - multiple administrators can work simultaneously on the same rule-base without conflict.

• Zero-touch deployment enabling large enterprise to provision security efficiently.

Figure 2: R81 Unified Policy

6CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Figure 3: R81 Ordered and Inline Policy Layers

Administrators can configure network segmentation and access control, URL filtering, Application Control, Identity Awareness and Data Loss Prevention (inspecting both inbound and outbound traffic) within a single rule and a minimal number of configuration menus for all enforcement points. This imperative approach, along with the use of dynamically-defined

objects throughout the security policy (for both access, HTTPS and NAT policies) answers the ever- changing threat landscape and too the challenges it brings to the organization and improves your overall security posture.

How Deployment and Scalability Work with R81 R81 cyber security management platform can be deployed via virtual appliances, Smart-1 purpose- built appliances, or as a cloud service via the Smart-1 cloud platform available on Check Point’s infinity Portal.

Hardware Appliances R81 management suite can be deployed on Smart-1 600-S | 600-M | 6000-L | 6000-XL dedicated appliances which are optimized for performance and scalability with both Hardware and operating system hardened from the core.

Virtual Appliances

R81 management suite can be deployed as a virtual appliance on VMware ESXi™, KVM, and Microsoft Hyper-V®, or in public cloud environments, including Google Cloud Platform (GCP™), Amazon Web Services (AWS®), AWS GovCloud, Microsoft Azure®, and Azure GovCloud.

Security Management from the Cloud Customized to fit each organization’s unique needs, whether the administrator is at the office or in any other location, Smart-1 Cloud takes the best security management and puts it in the cloud, utilizing the industry’s most advanced threat prevention and security management software for data centers, cloud, mobile, endpoint and IoT.

7CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Managing Platform Updates Once R81 deployed and configured, all additional maintenance aspects related to deploying new packages and security gateway upgrades are taken care of by the central deployment tool.

R81 Central Deployment Tool allows upgrades between major versions (as well as all types of hotfixes) performed natively from the SmartConsole.

Administrators can use this enhancement to reduce operational overhead related to upgrading their VSX gateways, cluster gateways or single sites. Whether major or hotfix installation, when upgrading clusters, it installs on the standby cluster member, reboots that member fails over with no packet loss or traffic degradation and move to the now stand-by member.

Automated Security

Consolidated Security

Dynamic

Efficient Operations

The Four Pillars: Building Blocks of R81 Cyber Security Platform

8CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Automated Security

Cyber security management efficacy is measured by the ability to automate routine security tasks. Automation of security creates agile security that helps administrators in their daily work. It can reduce the workload of the cyber security team and allow them to focus on more strategic missions.

Automation is done through the use of APIs, scripts or playbooks based on best practices and is used to programmatically repeat a variety of security operations. This often starts with common policy modification tasks such as creating objects and policy rules or security profiles. With the proper security tools and cyber security management, complete security architectures can be deployed in cloud environments with a push of a button.

One common use case for automation is to create self-service portals for cyber security operations. By utilizing available APIs, web portals can be created that allow untrained personal such as helpdesk and system administrators to add specific rules to the policy. This helps to improve productivity by creating faster workflows that decrease the time it takes to manage security operations.

Another use case is the strong integration with automation tools like Ansible or Terraform to perform several admin functions in one or more operations (R81 allows adding or deleting up to 27 object types within a single API call) or follow a certain playbook to create a new policy, including

network objects, services and access policy layers such as Application Control and URL Filtering and can install it on selected security gateways.

Autonomous Threat Prevention As security policies become bigger and more sophisticated, the act of configuring the most suited security posture becomes more and more complex. Administrators have to invest additional time to find what is the best security configuration. What if, instead of a lot of manual work, there was a faster, more automated way to define security profiles?

R81 introduces the Industry’s first autonomous threat prevention system powered by Check Point Research called Infinity Threat Prevention.

Infinity Threat Prevention, significantly reduces admin overhead and strengthens the security posture of the organization, by providing five out-of-the-box policy profiles tailored specifically for different segments in the organization’s network. Each profile has different prevention technologies and protections enabled, different protocols scanned all represent the best practices, determined by Check Point as the most relevant per the protected segment.

HIGHLIGHTS

• AI-driven security policy designed to prevent against zero day attacks

• Implement best practices in a single click

• Security Gateways are immediately configured

• Policies are continuously and automatically updated

9CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Figure 4: R81 Autonomous Threat Prevention Curated Policy Profiles

Infrastructure as Code (IaC) Infrastructure as Code (IaC) is the process of managing and provisioning computer data centers through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. Private and public cloud infrastructures are managed by such a process using scripts or declarative definitions in the code, rather than manual processes. IaC is therefore an essential part for the public cloud, used to build complex data centers through the proper modeling of the business process.

Security operations staff daily manage a flood of alerts and may rely on manual and inconsistent processes which simply cannot compete with the evolving technologies used by the bad guys. Security Orchestration, Automation and Response (SOAR) connects security operations center (SOC) staff with Check Point products to streamline every step of detection and response, replacing manual processes with automated workflows that ensure optimized triage, investigation and containment.

10CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Consolidated Security

Only a consolidated security architecture can stand up against the sophistication and volume of today’s cyber attacks, piecing together all security enforcement points from both the management perspective and shared intelligence perspective. Communicating intelligence insights concerning suspicious activities between the different enforcement points (whether residing on-premises, cloud, mobile or endpoint) is immanent to understanding the threat landscape of a given organization and to managing the risk it holds.

R81 cyber security platform is located at the core of Check Point’s consolidated security architecture, enabling the security administrator to grant the same level of security in every segment of the organization. It ensures a unified view of security policy configuration and threat visibility across networks, endpoints, mobile devices, IoT devices and clouds (public, private, and hybrid) and deploys related access and/or threat prevention policies on the relevant enforcement points.

The consolidation principle is also achieved via sharing the same intelligence feeds between all enforcement points when relevant. The ThreatCloud Intelligence data lake is dynamically updated using feeds from a network of global threat sensors, attack information from gateways around the world and Check Point research labs malware feeds. Based on the resulting security intelligence, updated protections and signatures are created and transmitted to all enforcement points.

Custom Intelligence Feeds R81 lets the administrator manage monitor custom monitor intelligence feeds or indicators of compromise (IoCs) with minimal overhead, directly from SmartConsole. Administrators can add, delete, and modify custom feeds according to the organization requirements, providing a designated menu to manage and fetch feeds from a third- party server directly to the Security Gateway, later on to be enforced by the Anti-Virus and Anti-Bot technologies.

Consolidated Traffic Monitoring and Improved Indexing Capabilities Logs and monitoring menu provides a rich and customizable interactive views of all network and security activities recorded on physical/internal gateways, cloud-based gateways, endpoint/mobile devices and IoT. Administrators can use the raw log view pane, or choose to explore any of the predefined views in the views sub menu. Each view is an interactive dashboard comprised of multiple clickable widgets, creating customizable panes, providing the administrator an account of the network and events based on different themes e.g. Remote Users, MITRE ATT&CK (using a graphical representation of an updated MITRE heat map to locate the top techniques and drill down to the most relevant ones) or Threat Prevention.

R81 introduces improved admin experience in searching using keywords due to the Solr 7.7 indexing engine which significantly improves the performance of indexing and reporting mechanisms. Security administrators can perform smooth and fast log queries, reports and view generation using a pre-defined intuitive and simple query syntax.

11CHOOSING THE BEST CYBER SECURITY MANAGEMENT

R81 enables dynamic security via Dynamic Objects by allowing automatic provisioning of security gateways on top of any hypervisor and cloud. Further, as changes happen in the cloud environment, enforcement points in the environment are automatically updated to provide protection in real-time.

Dynamic Objects Using trust APIs, the R81 CloudGuard Controller component connects to the Software-Defined- Data-Center (SDDC) and integrates the virtual cloud environment. All assets including security groups and tags are imported to the management server and can be used as part of the access policy configuration.

Dynamic

Unlike traditional networks, which are static and do not change much, the modern network is virtualized, dynamic and borderless. In the modern network, new applications can be provisioned anywhere; virtual instances can be activated at any time, replicated, replaced or migrated between data centers and clouds. This means that everything becomes dynamic and attributes like IP addresses can change in a blink of an eye. This requires a dynamic way to control, secure and monitor such environments.

Figure 5: R81 Integrated MITRE ATT&CK View

12CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Figure 6: R81 Updatable Objects

The controller infrastructure is also used to integrate the IoT discovery engine of all major vendors for automatic device mapping and classification and ultimately to generate granular IoT policies to be applied across the entire network (for example, a printer from a specific vendor can communicate only with the ePrint service using an authorized protocol).

Identity Tags An enhancement to the Identity and access realm which lets you include external identifiers (such as Cisco® Security Group Tags, or any other groups provided by any Identity Source) in Access Role matching. These external identifiers work like a tag that can be assigned to a certain user, machine or group.

Updatable Objects

R81 relies on Check Point’s cloud service to automatically update IPs for countries and common SaaS services such as Microsoft Office 365. The gateway fetches information regularly so when used in a policy enforcement process, the most accurate data will be used. When a connection is matched on an Updatable Object, the gateway puts the name and flag of that object in special fields on the log. If you double-click a log, you will be able to see them.

The other updatable object mechanism is Check Point’s UI resolving for IPs to countries. This is based on a continuously updated file. The resolving is done upon querying the log server and will return information for any IP, even if not matched by the geo-protection / Updatable Objects.

13CHOOSING THE BEST CYBER SECURITY MANAGEMENT

HTTPS Inspection Starting from R80.40, an HTTPS Inspection policy is available as a layer that can be either reused or stand unique for a given policy package. It also supports updatable objects so administrators are able to consolidate their certificate pinned apps rules using managed updatable objects. Check Point collected a list of HTTPS services which are known to be used in scenarios where HTTPS inspection is unable to establish the trust between the client and the Security Gateway and is therefore unable to inspect the traffic. These HTTPS services are part of "HTTPS services - bypass" updatable object.

NAT Policy R81 introduces a new dynamic NAT rule base, supporting access roles which represent different networks, users or machines by specifying a group or an identity tag, updatable object, domain objects and security zones, to create advance NAT policies with more flexibility and less complexity. For example using an ‘Office365 services’ updatable object to generate a static no-NAT rule where all internal traffic or traffic generated by HR access role is destined to Office365 will not be NATed.

The other updatable object mechanism is Check Point’s UI resolving for IPs to countries. This is based on a continuously updated file. The resolving is done upon querying the log server and will return information for any IP, even if not matched by the geo-protection / Updatable Objects.

Generic Data Center The Updatable Objects feature was introduced in R80.20 and gained popularity very quickly, due to its contribution to operational efficiency (zero maintenance), Updatable Objects represent popular services and public cloud platforms, but it might not be enough.

If the administrator would like to consume custom external IP feeds, create his own feeds or needs to delegate access management to his colleagues, the Generic Data Center is the right answer. Released in R81, this feature uses the dynamic Data Center infrastructure (When data is changed at the source, the security gateway is updated in near real time with the changes).

Use Case: The DevOps teams are creating and deleting machines in massive amounts, this results in high amount of security team effort and ticket bureaucracy. Now Security admins can define an object representing the JSON feed containing all the IPs that need access, this object only needs to be installed once on the policy and then all subsequent changes will be automated. This results in zero tickets and turns the Security admin from business disabler to enabler and more importantly: makes the DevOps teams happy.

Data Center Query Objects With Data Center Query Objects, administrators can now create one query object based on selected attributes across multiple data centers (names, types, IP address or tags).

14CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Example 1: Data Center Query Object

Applies to all current and future data centers.

This is the query logic:

• All assets from type instances OR Load Balancers

• AND

• Tagged with:

"server_type=prod_app"

OR

"server_type=prod_db"

This simplifies and empowers policy rulebase management by giving the ability to represent multiple objects from different Cloud platforms on a single data center query object. Furthermore, administrators can create the policy even before they configure a data center in SmartConsole. This makes it easier to separate responsibilities between security administrators and others teams that may need to create data centers in SmartConsole.

The new query object is used in the same way as Data Center objects. As with Data Center Objects, when the Data Center Query is added to the Rule base, the CloudGuard Controller pulls the assets from all the Data Centers in the query object and updates the security gateway accordingly.

15CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Example 2: Rule Base

Earlier versions require you to use multiple tag objects for multiple accounts.

• Rules must be must be updated for every data center added.

• Rules cannot have the logic for only Instances or Load Balancers.

R81 uses Data Center Query objects:

• No need to update the rule when new data center(s) is added.

• Rule can include complex OR and AND operations to better the policy.

Efficient Operations

Cyber security management platforms have to deal with growing networks, an increasing number of devices, disruptive technologies, and the complexities of IT operations. This demands that cyber security management be done in a smart and efficient way, reducing cyber security management overhead while increasing operational efficiency.

Policy Layers Efficiency can be achieved in many ways . One example is by segmenting the policy into manageable sections. Each section or sub-policy can be aligned to a different network or business function. That sub-policy can be deployed independently, and managed by different administration teams without

granting access to the entire policy. This allows creation of highly secured policies while still allowing load sharing of workload between teams.

Concurrent Admin Sessions Another example of operational efficiency is creating safe workflows, allowing multiple administrators to work simultaneously on the same policy without conflicts. This decreases the time it takes to perform security tasks since they can be done at the same time without risk of overriding each other’s changes and without collisions.

With R81, multiple administrators can work on SmartConsole on the same domain, with the same policies, and even on the same rule and at the same time. To avoid configuration conflicts, all work is done in sessions. Administrators can even have multiple sessions open at the same time.

R80.X

16CHOOSING THE BEST CYBER SECURITY MANAGEMENT

This becomes very helpful when working on a large project and the need arises to make an urgent policy change.

Every session is private and separate from other sessions. Changes cannot be seen by other administrators until the changes are published. To keep the sessions private, objects are locked when an administrator is modifying it. Other administrators will only see that the object is locked; they will not be able to change it. When an object is locked, the name of the administrator working on that object is displayed. This helps administrators coordinate work on shared resources.

When all the modifications have been completed, the administrator publishes the session. Only then will the changes become public and visible to all other administrators. Only public data can be installed on gateways. All modifications are saved instantly in the management server database. If there is an accidental disconnection, no work is lost. Administrators can discard changes during a session, and they can open a new session as they please.

Changes Report (sessions and revisions) In R81 we can generate a Changes report that lists usable audit data of all the changes between two different sessions or from a different revision (marked by the ‘publish’ operation which creates a new revision). This enables us to do comparatives to find out what changes were made to the access control or threat prevention layers before the last publish operation took place. This is extremely

useful for example when someone made a change that caused a certain service to go down and the administrator needs to identify the point in time when the change took place.

Multi Install Policy Sessions Starting in R81, one administrator or more can run different policy installation tasks on multiple gateways at the same time. In earlier versions, you can only run the same policy installation task on multiple gateways at the same time. The maximum number of policy installation tasks (of different policies) that can run at the same time is 5. If more than 5 policy installation requests are sent, any request beyond the first 5 will be placed in a queue. The current running and the queued tasks will conveniently appear in the Recent Tasks window in the same screen.

Accelerated Install Policy R81 introduces the Accelerated Install Policy feature. Due to several infrastructure changes made on the security gateway side, compute power on the management side required for processing the security policy information has decreased dramatically.

To 70% utilization below 20 seconds

From 80% utilization

over 1 minute

17CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Policy installation is accelerated depending on the changes that were made to the Access Control policy since the last installation. It is accelerated only if all changes made since the last installation include all common objects and types of objects (e.g. all actions related to ordered layers and their default columns, hosts and network objects, dynamic and

domain objects, access roles, data center objects, network service and many more). In any other case, the policy installation is not accelerated.

The acceleration process is divided into two main parts, Decision Phase and Policy Dump.

DECISION PHASE

Decision

Post-Publish Pre-Install

An asynchronous thread is executed and mark the current publish if it is eligible for Accelerated install policy flow. This means – all changes complies with supported changes white list*.

*Supported changes white list is found on a configuration file on the machine.

Checks if all publish operations since last policy installation are eligible for Accelerated install policy. If yes, Accelerated install policy flow will be initiated.

MODERN DUMP PHASE

Modern Dump

During Publish During Install

Each object that should be dumped to the GW is converted from its MGMT schema to its GW schema and stored in the DB.

All objects are being used in the policy installed, are dumped to files using their converted objects.

The dump files created mostly by postgres which significantly improves the performance.

Figure 7: R81 Policy Acceleration Process

18CHOOSING THE BEST CYBER SECURITY MANAGEMENT

Licenses – Automatically Activate Licenses and Contracts for all Check Point Products Licenses and Contracts for Check Point products are activated and entitled automatically in most common scenarios, this requires Security Management Server or Security Gateway to be connected to Check Point User Center. If there is still a need for manual license operation, starting R81, an administrator can view, add, and delete licenses directly from the SmartConsole application.

Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com

U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233

www.checkpoint.com

© 2022 Check Point Software Technologies Ltd. All rights reserved.

Summary A complete cyber security platform is the key to maximizing security effectiveness while driving operational efficiency. In the end, your security is only as strong as your ability to manage it.

This whitepaper has described a selection of the key differentiators of Check Point’s cyber security platform and security management features, both to highlight our capabilities, but also to shed light on the broad variety of requirements required for true enterprise class security management. A Cyber security platform has to be based on the 4 pillars described above: Automated Security, Consolidated Security, Dynamic and Efficient Operations.

The reality is that replacing management solutions after deployment is very difficult. Therefore, security professionals must be thorough and methodical in their evaluation of their management requirements, and the capabilities of their prospective vendors.

At Check Point, management has always been a core strength, and we continue to evolve our capabilities in response to the needs of our customers and the market with Check Point's cyber security platform R81.

To learn more about Check Point’s ecurity management, visit the website https://www.checkpoint.com/products/unified-cyber-security-platform/


Item Type: pdf