White Paper | The Importance of Prevention (Not Detection) in Email Security
This white paper explores the importance of prevention in email security, explaining why being inline, as opposed to relying on detection, is crucial for optimal protection. It compares Avanan’s API-based solution to others and highlights the importance of superior threat intelligence. Download the white paper to learn why prevention should be the cornerstone of your email security strategy.

THE IMPORTANCE OF PREVENTION, NOT DETECTION, IN EMAIL SECURITY
Y O U D E S E R V E T H E B E S T S E C U R I T Y
2THE IMPORTANCE OF PREVENTION
Highlights • In the booming API email security space, there are two modes:
prevention and detection • Detection can only respond to malicious emails and attachments,
allowing them into the environment before removing it • Detection is also limited in the type of features it can offer • Prevention can prevent malicious emails from reaching the inbox,
and offer a slew of other, critical features
Avanan was the first company to use pure-API email security back in 2016. It is a very compelling approach because the deployment is extremely easy, it protects internal email and superior visibility to provide the best security. This differs from what had been the standard of Secure Email Gateways (SEGs), which were designed first for on-prem environments and have made an awkward transition to the cloud.
In 2016, Avanan pioneered the concept of securing Microsoft 365 via API. Back then, customers needed to be educated about this novel approach. Now, it’s becoming mainstream, with scores of new companies popping up all the time, claiming to provide superior security via API.
Here’s the thing: not all API-based security vendors are created equally. All the others can only detect an attack. Only Avanan can prevent attacks from reaching your end- users. It’s a patented process. And that difference is critical.
In this whitepaper, we’ll discuss why prevention is the key to the best security and why being inline allows far more features to be enabled. Before we get into that, think about this story that illustrates the real differences between prevention and detection.
3THE IMPORTANCE OF PREVENTION
One company, using a buzzy API-based email security vendor, saw a threat get delivered to a number of users. It sat in those users' inboxes for eight hours before being removed.
It wasn't just sitting idly by. The threat caused damage and caused the company to be attacked.
This is what we mean when we talk about prevention versus detection.
There are a number of features that are only available to the end-user if the solution is inline. In this whitepaper, we’ll talk about a few key ones, including preventing inbox incursions, DLP, URL scanning, malware sandboxing and more.
4THE IMPORTANCE OF PREVENTION
Inbox Incursions An inbox incursion is when phishing emails are available to the end-user for any length of time. In such cases, the vendor remediates them post-delivery. This is solely how other API vendors operate. This means the email is available for the end-user to open up and click on the link. They may try to convince you that it's "only for a second or so" or that users will "barely notice". Let's be clear, any email phishing email available to the end-user for ANY length of time (5 seconds, 20 seconds, 183 seconds), is not the best that is available. Our research shows the average length of time is 183 seconds.
It should go without saying that any “email security” solution that doesn’t prevent inbox incursions isn’t really providing email security. A better name for these solutions might be email response solutions. It’s akin to buying a Rolex from a guy on the street in a trench coat. Not the real thing. This happens all the time because, due to their architecture, these other API-based solutions cannot block before the inbox. All malicious emails, therefore, reach the inbox. The malicious ones stay there for, on average, three minutes and three seconds. That's more than enough time for a user to click on a phishing link. Allowing malicious emails into the inbox is not providing real security. Allowing malicious emails into the inbox for as long as three minutes and three seconds is not real security.
Letting the email into the inbox for any period of time is not ideal and not the best form of email security. It gives users the ability to make mistakes and in the game of email security, the goal should be to avoid the chances for mistakes.
Avanan avoids this by being inline, scanning emails before the inbox. And it takes advantage of the largest intelligence database available.
The threat intelligence for which the AI/ML is trained is the single most important factor in determining the effectiveness of the AI/ML algorithm. The richer the intelligence, the better the catch rate. For the "stand alone" email security vendors, their intelligence is limited. It's limited in terms of the types and magnitude of their threat feeds. In general, they are only looking at email threat intelligence with a small sample size (only hundreds of customers). This is myopic.
Avanan's AI is powered by the world's most extensive cyber threat intelligence database and extends well beyond email threat data to include threat data from millions of devices including mobile, network, endpoint, and cloud.
5THE IMPORTANCE OF PREVENTION
Compare the difference in threat intelligence datasets below:
Avanan + Check Point ThreatCloud Intelligence
Other Email Security Vendor Threat Intelligence
6THE IMPORTANCE OF PREVENTION
To put the magnitude of Check Point's ThreatCloud intelligence into perspective:
150,000 connected networks—Number of connected networks reporting into Check Point's ThreatCloud with millions of endpoints worldwide
12 Device Types—Number of device types reporting into ThreatCloud including endpoint, mobile, network device, cloud, and email
86 billion—Number of transactions processed by ThreatCloud per day
7,000 detections of zero day threats detected each day
650K suspicious websites detected per day
6.8 Billion malicious website connections blocked last year
185 Million malware downloads blocked last year
778 Million vulnerability exploit attempts last year
200+ of the world’s renowned threat research team—full time threat researchers discovering some of the most significant unknown software vulnerabilities
30+ AI Technologies under one single product
Data Loss Protection (DLP) According to a report from IBM, the average total cost of a data breach has increased by nearly 10%, rising from $3.86 million in 2020 to $4.24 million in 2021.
Beyond that, the cost of not having a data loss protection program in place is staggering. Consider, according to the report: • It takes an average of 287 days to contain a breach • Accidental data loss takes 200 days to identify • Without automation and AI deployed, the average cost of a breach is $6.71 million.
With it, average data breaches cost 80% less • Compromised credentials were responsible for 20% of breaches
Without data loss protection, your organization is at risk for serious losses.
Many API-based solutions do not have data loss protection. That means that organizations either have to go without it or purchase a separate solution.
Avanan's all-in-one solution provides DLP scanning on emails, attachments, files, and other collaboration apps like Teams.
8THE IMPORTANCE OF PREVENTION
Avanan leverages the industry's most advanced tools to identify and mark files containing confidential, financial, and personally identifiable information, including credit card numbers, social security numbers, and bank routing numbers. When necessary, Avanan adds a -classified suffix to the end of confidential messages or files.
Avanan uses cloud-native controls to enforce granular share policies for individual files or folders based on their contents and context. Files can be deleted, quarantined, or encrypted before they become security incidents.
Choose which types of activity to monitor, such as PII or PHI. Select which action to take, whether it's blocking the email entirely or encrypting it for an authorized user. See all matches and activities on the Avanan dashboard.
With email security that reduces phishing reaching the inbox by 99.2%, Avanan is the best way to keep your organization safe from a data breach. Consider the case of the City and County of San Francisco. Within days of deploying Avanan's DLP, the City saw a 30% improvement in the use of data encryption.
If you use an API-based solution, it needs to have DLP built-in.
URL Scanning Many attacks detonate post-delivery, meaning they easily get by email scanners and are only dangerous after the user clicks on the link. URL rewriting, along with time-of- click analysis, allows the security solution to analyze links and block them, as necessary.
Consider a few attacks that Avanan has observed recently.
One is the TattleToken script.
Attackers are using client-side scripts to determine the end user's IP address and alter the URL in order to hide a malicious server from email service providers and security organizations.
9THE IMPORTANCE OF PREVENTION
This effectively bypasses most post-delivery protections like O365 SafeLinks inbox retraction. Instead of putting the malicious URL in the email, hackers link to a redirect server that acts as a gateway, sending queries from a security company to a benign site. Queries from the intended victims are directed to the phishing server.
From the point of view of the security firms, the link in the email is just a simple redirect to a web server like Google. When the victim clicks on the same link, they are redirected to the malicious web server.
There's also the general umbrella of SiteCloak attacks. SiteCloak is a way to bypass the time-of- click scanning by “cloaking” the malicious website. It does this by showing a benign page to the email security solution, but a realistic-looking credential harvesting page to the victim.
Preventing such attacks means analyzing links both when the email is delivered and at click-time. This is important because some attackers enable the malicious content only after the email message has reached the inbox. Additionally, prevention means using the hacker's own obfuscation techniques as a way to identify the attack. Because the web-scanning algorithm looks for known obfuscation methods as Indicators of Attack (IoAs), these sites self-incriminate themselves by their usage of a hacking method.
It also means doing image analysis. Consider the Microsoft Sway attack. Attackers used Sway, a web app for creating presentations and landing pages, to host phishing sites. Since Sway is hosted on office. com, it bypasses URL filters. In the attack, hackers hyperlink to a malicious file or to a spoofed login page. By using OCR to convert images to text, or to parse QR codes and identify the link, our NLP can then identify any suspicious language or malicious links.
It also means doing attachment analysis. We saw its importance on a fairly straightforward tax-related attack that we blocked earlier in 2021.
10THE IMPORTANCE OF PREVENTION
The attackers tried to obfuscate their approach by changing the Reply-to address to eservices@firs.gov, but the actual from address represents the IRS equivalent in Nigeria. By scanning all links in the attachment, we were able to determine with high confidence that the .HTML attachment was Trojan malware.
Proper URL scanning also has the following benefits: • Another layer of post-delivery protection • Anti-malware and enhanced protection for zero-day attacks, as sometimes it takes a few minutes to
detect malicious emails • Forensics
However, not all API-based solutions offer URL scanning. Or, if they do, it's limited in nature. For those who aren't inline, they may claim that they only need to rewrite URLs on malicious emails and not on clean ones. They claim this as a benefit, when in reality it's because their API won't allow them to do it. But that plays right into the hacker's hands. Emails that detonate post-delivery are designed to land in the inbox as clean and are only dangerous after clicking. If you don't re-write every URL, end-users will be affected by this.
Implementing proper URL scanning that can detect the attacks like the ones mentioned above is a crucial part of any security structure.
11THE IMPORTANCE OF PREVENTION
Malware Sandboxing The majority of ransomware and malware starts with phishing. In fact, according to Check Point, more than 70% of malicious email attachments or links were sent via PDF or through Microsoft Office.
Receiving or forwarding a malicious file can wreak havoc on an organization.
That's where Content Disarm & Reconstruction (CDR) comes in. CDR works by removing any executable content, making the file safe for the recipient. It protects the end-user from zero-day threats and does so instantly.
CDR breaks down files into their discrete components, strips away anything that doesn't conform to that file type's original specification, and rebuilds a "clean" version that continues on to the intended destination. This real-time process removes zero-day malware and exploits while avoiding the negative business productivity impact that is typically caused by sandbox detonation and quarantine delays.
According to Gartner, CDR is one of the essential items of any email security solution.
Unfortunately, not all API-based solutions have this feature. In fact, not all Secure Email Gateways have this feature.
By deploying CDR with Avanan, your organization can protect your users from malicious file delivery and do so without hampering employee productivity.
Files can be major weapons in the phishing and ransomware war. With Avanan, unlike some other solutions, you can be protected against executive documents without losing productivity. Other APIs can only do background malware analysis after it’s reached the inbox. While being analyzed, there will only be a warning banner placed on the email, saying analysis is underway. That leaves this exposed to the end-user.
This process prevented the recent Follina vulnerability in Microsoft from reaching inboxes. Other APIs can’t say the same.
12THE IMPORTANCE OF PREVENTION
Conclusion Since our founding, a number of other API-based solutions have popped up. But they are, as Omdia puts it, "helper apps" since they can't replace the full functionality of gateways or native security, or serve as the sole protector of an enterprise.
When looking at the next generation of email security, a few things are must haves: • Prevention of inbox incursions. Any malicious email that gets into the inbox is liable to be clicked on or
acted upon. That leaves your organization at risk • DLP. Data is flowing at record speed and it’s more valuable and personable than ever. A DLP solution
that covers all lines of communication is essential. When baked into the email program, it can cover all the places where data is shared
• URL scanning. Many attacks detonate post-delivery, making it essential that all links that do make it into the inbox are scanned for malware. This applies to attachments and image analysis.
• Content Disarm & Reconstruction. This real-time process removes zero-day malware and exploits while avoiding the negative business productivity impact that is typically caused by sandbox detonation and quarantine delays.
The API-based vendors that can only detect simply can’t do this. Their technology simply won't allow it. That’s why detection is their default positioning.
Prevention is what Avanan brings to the table. Prevention keeps you more secure.
Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com
U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233
www.checkpoint.com
© 2022 Check Point Software Technologies Ltd. All rights reserved.