The ISC China Internet Conference has been in full swing until the second day, and today's live popularity is no less than that of yesterday's opening. Without further ado, let me show you the live stuff today! Joint testing, how to verify the firewall capabilities on site verifi

ISC China Internet Conference has been in full swing until the second day, and today's live popularity is no less than that of yesterday's opening. Without further ado, let me show you the live stuff today!

joint test, next-generation firewall capability on-site verification

How to verify firewall capability? Of course, you must face real attacks in a real network environment! Sibolun Global Services helps customers meet complex testing and service assurance needs. At today's Sibolun booth, the theme of "coordination and linkage" has also been vividly demonstrated. Netcom teamed up with Sibolun to simulate the most realistic corporate network environment, showing everyone the attack detection and processing capabilities of Netcom's next-generation firewall in high hybrid throughput.

Sibron simulates a real enterprise network environment, and the traffic contains email, online video, web browsing and other business content. The total throughput reaches 20G and the number of concurrent connections reaches 1.19 million. In the case of high hybrid throughput, the CPU usage rate of Netcom's next-generation firewall is only 32%, which shows that it is very easy to deal with 20G throughput, and there is still more room for actual usage performance.

In the real enterprise network environment, attacks are everywhere. Sibolun simulates more than 10 attack methods including SQL injection, cross-site attacks, HTTP directory traversal attempts, etc. In such a high throughput, can Netcom NGFW perform well? The answer to

is shown in the figure below. NGFW has no omissions, and it accurately identifies various security threats and displays them in an intuitive way. We can see when, where, and what kind of attacks come from whom, which can be described as "visible" of security threats.

Going further, NGFW also lists various security risks according to risk level and severity, which is clear at a glance, providing reliable basis and support for attack handling. The joint test of

.com and Sbolun also attracted the attention of media including Haidian District TV station, IT168, China Information Security and other media. The picture below is a picture of Netcom security expert Xiong Ying introduced the relevant situation to Haidian District TV station.

The most IN UBA technology parsing

Internal threat has become a security risk that enterprises cannot ignore. Former employees take away customer information, current employees collude with internal and external forces to steal technical information, and contractors modify important corporate data... These terrible risks are just the tip of the iceberg of internal threats. Previous methods to solve such problems, such as SOC or SIEM, not only had high false positive rates but also complex operations, and the road to finding internal threats was full of thorns. Because of this, UBA user behavior analysis has become one of the most in-depth solutions in the industry with its advantages of low false positive rate and simple operation.

This afternoon, Chen Tianhang, a technical expert from Netcom, brought to you "User Behavior Analysis and Internal Threat" at the "Big Data Analysis and Security" forum, and gave an in-depth interpretation of UBA's new technology.

The venue was full.

Chen Tianhang said that the technical soul of UBA lies in the context of the Context. Using the context information of the article to infer the future plot of the article or inferring "who is the murderer" is something that each of us will do. UBA simulates the way the human brain thinks, and uses massive context information to judge the upcoming or existing insider threat events.

For example, if the user's role is an engineer or a salesperson, the position is a manager or a VP, the time of work, and even physical health must be included in the context. In addition to users, the terminal situation also belongs to a part of the context, such as what operating system is used by the terminal, and whether the terminal type is a mobile phone or a PC. Users' network access and terminal operation behaviors cannot be missed, and they must be added to the UBA context. The enriched behavioral information will be grouped or analyzed by association, and finally enters the abnormality detection stage, and then converts abnormal behavioral events into human risk coefficients according to the human dimension.

That is, UBA associates massive context information, like forming a dense network, leaving abnormal events and abnormal behaviors with nowhere to hide, and finally finding the "dangerous person".

NetKan booth event continues to be popular, the team grows up

Why are there so many people in theNetKan booth?

.com booth lottery event, with many gifts, many people and great popularity! Many friends won their favorite prizes and returned with a full load~

At this year's ISC conference, who can be more popular than me?

Related reading:

ISC2016, Netcom's live shot!