实例探究 > Aflac, Inc. Uses Deception for Zero-False-Positives Threat Detection

Aflac, Inc. Uses Deception for Zero-False-Positives Threat Detection

公司规模
1,000+
地区
  • America
国家
  • United States
产品
  • ThreatDefend Deception and Response Platform
  • ThreatStrike
技术栈
  • Deception Technology
  • Cybersecurity
实施规模
  • Enterprise-wide Deployment
影响指标
  • Customer Satisfaction
  • Digital Expertise
  • Innovation Output
技术
  • 网络安全和隐私 - 入侵检测
  • 网络安全和隐私 - 网络安全
适用行业
  • 金融与保险
适用功能
  • 商业运营
用例
  • 网络安全
  • 入侵检测系统
  • 远程资产管理
服务
  • 系统集成
  • 测试与认证
关于客户
Aflac, Inc. is a Fortune 500 insurance provider known for its supplemental insurance policies. The company has a mature security posture and has implemented high-end cybersecurity technology into its network. However, Aflac faced challenges in early and accurately detecting new and emerging threats within their network. Despite having high-end prevention devices and practices, they recognized a gap in their ability to quickly detect threats that penetrated their network. This led them to seek a solution that could provide early and accurate threat detection with zero false positives.
挑战
The infosec team saw the ever-changing landscape of threats as the biggest challenge that faced their organization. The threats were everywhere. And with a gap in their ability to detect new strains of attacks, the organization needed a device that was able to catch zero-day and signatureless threats. Additionally, the team found devices that generated a lot of alarms and whistles to be very distracting because of the rate of false positives that were produced – so much so that they were determined to find a solution that generated zero false positives. They didn’t need more alerts, they needed quality alerts.
解决方案
The infosec team chose the ThreatDefend Deception and Response Platform because it allowed them the ability to detect threats inside their network that other technologies missed entirely. Moreover, the level of camouflage that deception technology employs as well as the ability to mimic the hygiene of the network provided complete authenticity – meaning an attacker would not be able to tell the difference between the deceptive assets and the organization’s critical assets. Additionally, the team is using the ThreatDefend solution as a means for early detection of ransomware attacks. The team deployed the ThreatDefend Deception Platform throughout their network and assigned ThreatStrike deceptive credentials to their endpoints in order to detect the threats that were inside their network as well as any misconfigurations that might be present. To test the full detection capabilities of the ThreatDefend, they hired a white hat hacker to run a penetration test on their network. The hacker spent over two hours trying to hack the web services of a decoy system placed in the network. The infosec team caught him very early on and was able to quarantine him and study his attack methods throughout the entire penetration test. By diverting the hacker, the ThreatDefend Solution protected all of the organization's critical assets.
运营影响
  • By deploying the ThreatDefend Deception Platform throughout their network, the team achieved their goal of no false positives and only high-integrity alerts. This greatly reduces the amount of 'noise' their team needs to respond to given that they are not chasing dead ends that other devices generate.
  • The team can be fully confident that the threats that penetrate their network will not only be detected quickly, but also will be diverted away from their critical assets and be quarantined for detailed attack forensics.
  • The ThreatDefend platform identifies any misconfigurations that are present in the organization’s network. This allows them to patch any areas that are especially susceptible to attackers, greatly strengthening their ability to prevent attacks in the future.
  • The ThreatDefend Platform is operationalized and fully integrated into their threat intelligence system. The ThreatDefend takes new information it gathers on threats and feeds it into their overall threat intelligence system, allowing the threat management team to use the information for their hunting efforts.
  • The detailed information provided by the ThreatDefend is also used in conjunction with the organization’s correlation engine and used for overall risk profiling.
数量效益
  • Achieved zero false positives in threat detection.
  • Reduced the amount of 'noise' in alerts, focusing only on high-integrity alerts.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。