Report | Miercom NGFW Security Benchmark, 2024 | Check Point Software

Report | Miercom NGFW Security Benchmark, 2024

NGFW Firewall Security Benchmark 2024 Firewall Security Efficacy Competitive Assessment Summary Lab Report for Check Point Software January 2024 SR240117C miercom.com/checkpoint

https://miercom.com/checkpoint

Table of Contents

1.0 Executive Summary 2.0 Testing Summary Results 2.1 Malware Prevention and Detection Summary 2.1.1 Malware Prevention vs Detection-Only Zero+1 Day Malware 2.1.2 Malware Prevention Efficacy Zero+1 Day Malware 2.2 Malicious Phishing URLs Prevention and Detection Summary 2.2.1 Phishing and Malicious URL Prevention 3.0 False Positive Detection 3.1 False Positive Testing Summary 3.1.1 False Positive Rate for Malware Detection 4.0 Products Tested 5.0 Test Setup 5.1 Miercom Advanced Offensive Threat Detection 5.2 VirusTotal 5.3 Testing Environment 6.0 About Miercom 7.0 Use of This Report

1.0 Executive Summary

Miercom was engaged by Check Point to conduct competitive security effectiveness testing of the Check Point Next Generation Firewalls (NGFW) as compared to products from Cisco, Fortinet, and Palo Alto Networks. Testing with Zscaler involved their SWG (Secure Web Gateway). Testing included verifying the effectiveness of anti-virus, anti-malware, Intrusion Prevention System (IPS), anti-bot, URL Filtering (URLF), sandboxing, machine learning, and phishing protection. We conducted tests with all security services enabled and challenged each solution’s ability to detect and block modern-day malware.

Modern threats like web-based malware attacks, targeted phishing attacks, application-layer attacks, and others increase the threat level against organizations globally. The majority of new malware and intrusion attempts to exploit weaknesses in applications, as opposed to networking components and services. NGFWs with advanced threat prevention offer the best protection against the latest generation of cyberattacks. Our testing specifically focused on the ability to detect and prevent new malware variants within the first 24 hours of their discovery as well as detecting and preventing new phishing sites.

In this report, Zero+1 Day Malware (one day past Zero-Day discovery) means newly discovered malware on the first day of discovery. These malware samples are less likely to be known by any vendor’s signature detection mechanisms in the first 24 hours.

Key Findings

2.1 Malware Prevention and Detection Summary

2.2 Malicious Phishing URLs Prevention and Detection Summary

3.0 False Positive Detection

4.0 Products Tested

5.0 Test Setup

The testing conducted was designed to determine the strengths and weaknesses of each NGFW product using verified malicious samples for a customized, open-source approach. Over the course of 90 days, we assessed each NGFW solution using AV + Anti-Malware, IPS, anti-bot, URLF, sandboxing, and machine learning inline detection mechanisms.

6.0 About Miercom

Miercom has published hundreds of network product analyzes in leading trade periodicals. Miercom’s reputation as the leading, independent product test center is undisputed.

7.0 Use of This Report

This document is provided “as is,” by Miercom and gives no warranty, representation, or undertaking. All trademarks used in the document are owned by their respective owners.