{"id":1987,"date":"2015-04-16T08:54:57","date_gmt":"2015-04-16T08:54:57","guid":{"rendered":"http:\/\/www.intelligentcio.com\/?p=1987"},"modified":"2015-04-16T08:54:57","modified_gmt":"2015-04-16T08:54:57","slug":"is-ssl-hurting-more-than-helping-middle-east-organisations","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2015\/04\/16\/is-ssl-hurting-more-than-helping-middle-east-organisations\/","title":{"rendered":"Is SSL hurting more than helping Middle East organisations?"},"content":{"rendered":"<p style=\"color: #222222\">SSL encryption is a double-edged sword for many organisations in the Middle East. It bolsters security by providing confidentiality and message integrity. It also enables organisations to verify the identity of application owners and allows applications to authenticate users with client certificates. Unfortunately, encryption can also be used by attackers to infiltrate enterprises, writes <em>Glen Ogden,\u00a0Regional Sales Director, Middle East at A10 Networks.<\/em><\/p>\n<p style=\"color: #222222\">Encryption puts organisations at risk. Hackers leverage encryption to conceal their exploits from security devices like firewalls, intrusion prevention systems, forensics solutions, and more that can\u2019t keep up with increasing SSL decryption demands or that cannot decrypt SSL traffic at all because of their location in the network.<\/p>\n<p style=\"color: #222222\">According to a recent Gartner\u00a0<a style=\"color: #1155cc\" href=\"https:\/\/wpyadmin.ne.cision.com\/l\/pylhkhsp\/www.gartner.com\/doc\/2635018\/security-leaders-address-threats-rising\" target=\"_blank\">survey<\/a>, \u201cless than 20% of organisations with a firewall, an intrusion prevention system (IPS) or a unified threat management (UTM) appliance decrypt inbound or outbound SSL traffic.\u201d This means that hackers can evade over 80% of an organisation\u2019s network defences simply by tunnelling attacks in encrypted traffic.<\/p>\n<p style=\"color: #222222\">\n<p style=\"color: #222222\"><strong>SSL\/TLS is the new default transportation protocol<\/strong><\/p>\n<p style=\"color: #222222\">SSL usage has become ubiquitous, and many leading websites now encrypt every web request and response. In fact,\u00a0<a style=\"color: #1155cc\" href=\"http:\/\/media.ne.cision.com\/l\/pylhkhsp\/news.netcraft.com\/archives\/2014\/01\/03\/january-2014-web-server-survey.html\" target=\"_blank\">48% more of the million most popular websites use SSL in 2014 than a year earlier<\/a>.\u00a0However, the transition from 1024- to 2048-bit SSL key lengths, combined with growing SSL bandwidth demands, has burdened security devices that decrypt SSL traffic. The impact of decryption on security devices is startling.\u00a0<a style=\"color: #1155cc\" href=\"https:\/\/www.nsslabs.com\/sites\/default\/files\/public-report\/files\/SSL%20Performance%20Problems.pdf\" target=\"_blank\">Analysis by NSS Labs<\/a>\u00a0reveals that 2048-bit SSL ciphers \u201ccaused a mean average of 81% in performance loss\u201d for seven leading next-generation firewalls.<\/p>\n<p style=\"color: #222222\">However, encrypted traffic is often not protected with intrusion protection technology. Cyber tools are not protecting the organisation\u2019s assets and are letting encrypted traffic pass through the network unchecked.<\/p>\n<p style=\"color: #222222\">But wait a minute\u2014didn\u2019t we solve SSL performance problems in the data centre years ago? Specialised appliances, load balancers, application delivery optimisation, and offloading CPU-intensive SSL encryption processes are all aimed to address these issues. However, in addition organisations need modern tools to secure and optimise their modern firewalls and cyber protections.<\/p>\n<p style=\"color: #222222\">To help organisations decrypt and inspect SSL traffic without degrading network performance, third-party security devices can be used to inspect encrypted traffic and eliminate the blind spot imposed by SSL encryption.<\/p>\n<p style=\"color: #222222\">These security devices have the capabilities to:<\/p>\n<p style=\"color: #222222\">\n<ul style=\"color: #222222\">\n<li>Uncover cyberattacks hidden in SSL traffic<\/li>\n<li>Maximise uptime by load-balancing multiple third-party security appliances<\/li>\n<li>Scale performance and throughput to successfully counter advanced threats<\/li>\n<li>Deploy best-of-breed content inspection solutions to fend off attacks and malware<\/li>\n<\/ul>\n<p style=\"color: #222222\">\n<p style=\"color: #222222\">In today\u2019s work environment, more and more network traffic is being encrypted. As information technology managers, we need to ensure the correct information is being protected, while the necessary infrastructure is in place to protect the organisation. Managed correctly, SSL traffic can provide the necessary protections while not exposing the vulnerabilities on the company\u2019s security infrastructure.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SSL encryption is a double-edged sword for many organisations in the Middle East. It bolsters security by providing confidentiality and message integrity. It also enables organisations to verify the identity of application owners and allows applications to authenticate users with client certificates. Unfortunately, encryption can also be used by attackers to infiltrate enterprises, writes Glen [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":1988,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,38],"tags":[247,128,288,10],"class_list":["post-1987","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-networking","tag-a10-networks","tag-data-centre","tag-network","tag-security-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/1987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=1987"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/1987\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/1988"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=1987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=1987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=1987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}