sandblast network solution brief.pdf

SandBlast Network

Protection Against Zero-Day Threats

!

Product Benefits

Product Features

Can you Defend Against Zero-Day Threats?

Every day, 8,300 new, previously undiscovered cyber attacks emerge, including zero-day malware, zero-day phishing, and social engineering attacks. With no associated file signatures, anti-virus, firewalls and other core security solutions cannot identify them as malicious and block them from entering the network. In fact, even the best AV solutions detect only half of malware strains in the wild. With no existing indicators of compromise (IOCs), how do you protect against what you do not know?

Common Network Security Approaches Have Limitations

To protect against zero-day threats, organizations use several approaches. These include:


PRODUCT BRIEF SANDBLAST NETWORK

Check Point SandBlast Network— Number One in Zero-Day Protection

Check Point SandBlast Network provides the world’s best zero-day protection, through a combination of evasion-resistant threat emulation, revolutionary AI engines, and threat extraction that pre-emptively sanitizes email and web downloads.

Empowering organizations to take a prevention-first strategy to cyberattacks, SandBlast Network defends against the most devastating attacks, including unknown ransomware, Trojans, phishing, and social engineering.

SandBlast Network deploys with your current infrastructure, offering fully automated policy configuration, without compromising business productivity and agility.

Best Zero-Day Catch Rate

To achieve the world’s best malware catch rate at record speed, SandBlast Network employs numerous innovative, proprietary technologies. These include pre-emptive user protections, a vast network of up-to-the-moment threat intelligence, and revolutionary AI and non-AI engines.

Pre-emptive User Protections

To protect users across email and web, SandBlast Network employs pre-emptive user protections, namely threat extraction and advanced email protections.

ThreatCloud—Dynamic Threat Intelligence Repository

Comprising the largest repository of real-time security intelligence—utilized in four billion security decisions daily—Check Point ThreatCloud examines suspicious files and emails with breakthrough AI engines to determine if they are malicious or benign.

Powering SandBlast Network’s zero-day protection, including anti-phishing and safe browsing, ThreatCloud gleans cyber attack data from:


AI-Generated Threat Emulation Verdicts

Inspecting files and emails for which no threat intelligence exists, SandBlast Network performs deep CPU-level emulation that is resistant to the most evasive attacks, even by nation states. It also employs OS-level inspection to examine a broad range of file types, including executables and documents, and emulates threats across PC and Mac devices, ensuring the best zero-day protection for all enterprise users.

SandBlast Network leverages the power of data science to detect the newest threats with exhaustive AI engines and rich rule-based engines that process millions of parameters collected from runtime behaviors—reaching a single conclusive AI-generated verdict. AI heuristics are continually optimized against the latest threats unleashed to the wild.

Intuitive Management

SandBlast Network offers single-click setup of security policies thanks to out-of-the-box best practice profiles that eliminate the need to manually configure policies for each network segment, e.g. data center, guest network, perimeter, internal network, etc. Network settings are optimized per business need to provide the most effective security while maintaining optimal network performance. By only deploying policies that are relevant to the specific network segment being protected, organizations save on bandwidth and processing power for a more cost-effective zero-day protection strategy.

And thanks to auto-updated threat prevention engines, organizations always run with the latest features, best practice policies, and technology, as these are automatically updated in the background, with no need to push policy updates manually.

Supports Current SIEM and SOC Workflows

SandBlast Network offers advanced network forensics and actionable intelligence that integrate with your SIEM and SOC infrastructure, enabling security teams to:

Compliance and Reporting

Serving as the gold standard for efficient security management, Check Point’s R80 console provides enterprise and government-grade compliance and reporting, including:


Smooth Business Productivity

SandBlast Network is the only zero-day protection solution that does not compromise business productivity, enabling a true prevention-first strategy. Letting users maintain their current email and browsing workflows, SandBlast Threat Extraction cleans email attachments and web downloads in 1.5 seconds, while slashing administration overhead by up to 70%.

Thanks to blazing-speed, AI-generated Threat Emulation verdicts, SandBlast Network protects user activity across email, web, and networks, for powerful zero-day protection against multiple attack vectors.

Flexible Deployment Options

Whether you’re using Check Point Next Generation Security Gateways or a third party’s, SandBlast Network integrates with current security infrastructure for the best security, management, and uptime.

Network Security Controls Covered by Check Point Solutions

TECHNOLOGY NEXT GENERATION THREAT PREVENTION(NGTP PACKAGE) SANDBLAST NETWORK(SNBT PACKAGE)
Firewall √ √
VPN(IPsec) √ √
IPS √ √
Application Control √ √
Content Awareness √ √
URL Filtering √ √
Anti-bot √ √
Anti-Virus √
Anti-Spam √
SandBlast Threat Emulation √
SandBlast Threat Extraction √
Zero Phishing √

SandBlast Network offers flexible deployment options, letting you add zero-day protection to your current security gateways as:


A technical migration path is offered to organizations with third-party security gateways using a simple migration wizard.

SandBlast Service

!

Security Gateways

!

SandBlast Physical TE Appliance

!

SandBlast Inline TE Appliance

!

SandBlast Network Specifications

Emulation Environments

PC: Windows:

Archive Files

Over 70 file types emulated, including: Microsoft Office documents and templates, EXE, DLL, Archives (ISO, ZIP, 7Z, RAR, etc.), PDF, Flash, Java, scripts, ELF executable (MacOS, Linux), and more.

Threat Extraction

Extraction Modes

Web downloads and email attachments in these formats:

File Types

Additional Protections (included in SandBlast Network licenses)

GENERAL
SSL Inspection Included
Identity Awareness Identity-based policies for users, groups and machines supported through integration with Microsoft Active Directory and Cisco Identity Services Engine
Management Single-click policy setup - Supported in R80.40 and above, Threat Extraction for web downloads - R80.30 and above
SUPPORTED PROTOCOLS
Threat Emulation HTTP, HTTPS, SMTP, SMTPS, IMAP, CIFS, SMBv3, FTP
Threat Extraction Web downloads: HTTP, HTTPS, ICAP; Email attachments: SMTP, IMAP, POP3, SMTPS - MTA deployment