

For example, understand usage of application functions, such as audio streaming, remote access, posting documents etc., and then enforce granular controls over usage, such as uploading and posting to Facebook, file sharing on Box and file transfer. An NGFW provides complete visibility into application usage, along with capabilities to understand and control their use.

Security administrators want to have complete control over usage of these apps and set policy to either allow or control certain types of applications and deny others. Some of these apps are sanctioned, some tolerated and others unsanctioned.

Application Usage, Visibility and Control: Users are accessing diverse types of apps, including SaaS apps, from varying devices and locations.A NGFW enforces capabilities like machine learning based analysis and multi-factor authentication (MFA) to prevent credential theft and subsequent abuse – and preserve the user identity. Attackers use stolen credentials to access an organization, move laterally, and escalate privileges for unauthorized applications and data. The 2017 Verizon Data Breach Investigation Report found that 81-percent of hacking-related breaches leveraged weak and/or stolen credentials2. Protecting user identity is equally important. However, the issue of user identity goes beyond classifying users for policy reporting. User Identity Awareness and Protection: The user identity feature on NGFWs identifs users in all locations, irrespective of device types and operating system.By year-end 2019, 90-percent of enterprise internet connections for the installed base will be secured using next-generation firewalls1.Īn NGFW provides the following capabilities:
