Cloud environments are growing ever more complex as organizations add more cloud providers, users, applications and resources. Most security solutions are not designed for this new world and lack the end-to-end visibility needed to accurately assess risks and alert security teams of advanced attacks, leaving them to deal with both unsecured cloud resources and the cacophony of false-positive alerts. Today’s Prisma Cloud CSPM updates help security teams address these issues.
Varun Badhwar, senior vice president, Prisma Cloud at Palo Alto Networks said, “An ideal CSPM solution needs to offer coverage for all cloud resources, should stay up to date as new resources are introduced, and must effectively detect real attacks while minimizing unnecessary false positives. Prisma Cloud addresses these issues and allows organizations to move quickly while staying secure.”
The five new features of Prisma Cloud are:
Legacy CSPM solutions generate alerts for any overly permissive security group — even if the security group is not publicly exposed. True Internet Exposure provides end-to-end network path visibility between any source and destination, eliminating needless alerts associated with unexposed cloud instances and security groups.
Cloud service providers release and update hundreds of new services for their platforms each year. When organizations use these new services before their CSPM solution supports them, they are left with security blind spots. With Visibility-as-Code, Prisma Cloud can now support new cloud services in days, providing development teams with the freedom to take advantage of the latest cloud services while giving the security teams the security measures they need.
Many basic security solutions solely focus on detecting misconfigurations based on static rules, so they may not be effective when it comes to real security attack objectives, such as data exfiltration. Prisma Cloud uses machine learning to analyze vast amounts of network flow logs and understand the typical traffic pattern of each customer, which is then used to detect and alert on abnormal egress traffic to any IP address, including TOR exit nodes. This allows security teams to focus their remediation efforts on the most dangerous data exfiltration attacks and avoid unnecessary alert storms.
Security teams need an effective way to detect cryptojacking and another abnormal provisioning of computing resources. Anomalous Compute Provisioning Detection can identify the provisioning of an abnormal number of VMs, which can often be attributable to either cryptojacking or resource misuse. The machine learning-based policy also alerts security teams if a user appears to jump from one location to another or tries to hide behind a TOR exit node.
Prisma Cloud assesses resource configuration and enables customers to scan objects in their S3 buckets for public exposure, identify sensitive data and detect malware. Customizable Object-Level Scanning now gives customers a la carte scanning, freeing them to self-select specific scanning capabilities. This saves time and cost while reducing the volume of alerts.