October - 2019ENTERPRISE SECURITY| | 19The Evolving Scope of Web Security in the Healthcare Spacee have seen a big change in how we connect to and leverage the internet in our daily lives from both a personal and business perspective. Through the development of technology, we have seen more and more devices now requiring internet connectivity to function, and this increased utilization has changed the way we have looked at web security.Going back ten years, we were primarily focused on blocking malicious websites, scanning for malware, and enforcing human resource policies around acceptable use. This was typically done viathe Internet proxies, through which all outbound internet connectivity went through for corporate assets. Most of the traffic was not encrypted and could be examined in plain text, which helped protect corporate assets as well as reducing the risk of data exfiltration.Over time we have seen a dramatic increase in the development of Software as a Service (SaaS) and Infrastructure as a service (IaaS) platforms that have changed the way we interact with web-based services. At the same time, we have also seen more websites and services leveraging encryption which has made it harder to evaluate the traffic being sent or received.It has become important for organizations to now have a method to decrypt any web traffic being sent or received to ensure that risks are identified and dealt with appropriately. Malicious actors, while traditionally using unencrypted methods to distribute malware or exfiltrate data, have been leveraging encrypted sessions more than ever to try and avoid detection. CXO INSIGHTSWBy Iain Lumsden GSLC, GCTI, GCED, Director of Information Security, Denver HealthDecrypting web traffic is a very important part of any security program these days and even more so when you are talking about Data Loss Prevention (DLP). In the Healthcare industry, like many others, we need to ensure that Protected Health Information (PHI) and Personal Identifiable Information (PII) is being shared appropriately and securely. To ensure this is happening, we need to be able to decrypt internet traffic so it can be analyzed by a DLP system to ensure there is no data exfiltration taking place. Without having that decryption in place, we would be blind as to what data is being uploaded to a secure website, and this is a risk that needs to be addressed.At the same time, we need to be able to decrypt that traffic to help detect and prevent the execution of exploit kits such as Rig, Angler, and Nuclear from delivering malware into our network. These exploit kits have been used to spread Ransomware, Banking Trojans, Keyloggers, and Remote Access Trojans. These exploit kits typically compromise legitimate websites and then redirect
<
Page 9 |
Page 11 >