Traditional security solutions seek to detect malware at the point of initial infection, which is largely ineffective for detecting zero-day attacks. Further complicating the problem, current advanced malware products are limited to either relying on signatures or the Command and Control traffic at the network edge. Once attackers find a way past the enterprise edge, these solutions have limited ability to disrupt advanced attackers.
Argon Secure is designed to address the current gap in security solutions by identifying advanced malware both at, and after, the point of initial infection when it attempts to propagate, find valuable data and exfiltrate that data from the network. By leveraging visibility into endpoints, internal network traffic and the network edge, Argon Secure can detect malware in places where other solutions cannot.
Argon Secure addresses the advanced malware problem by leveraging Juniper’s innovative Intrusion Deception approach to detect attacks and prevent data exfiltration. The service uses the firewall features of the SRX Series platform as an enforcement engine to instantly take malware-infected machines off the network before they can steal sensitive information.
Juniper Argon Secure
· Argon Secure for the SRX Series will enable enterprises to identify and mitigate malware inside a network, detecting and removing infected devices before data is lost.
· Like Juniper Networks WebApp Secure for the data center, Argon Secure will leverage Intrusion Deception to identify malware including zero-day threats that try to propagate to additional systems, look for corporate data, or attempt to send data outside the company network.
· The solution will include more than 50 deception techniques embedded in the network infrastructure to force malware to expose itself even after entering a network. For example, malware once installed will start scanning the internal network in search of files that look useful. This action provides an opportunity to detect an attacker in the enterprise by creating a fake network process that emulates network share drives so when malware touches the files, Argon Secure can instantly identify them and push fake files.
· Argon Secure will integrate with Juniper Networks Spotlight Secure to provide threat information in real time to companies, helping to quickly stop new attacks.
· Argon Secure is a service that is available as a subscription for the SRX Series Services Gateways and will be generally available in Q3 2014.