HPE SRX Series Next-Generation Firewalls & Threat Prevention
Discover how the SRX firewall portfolio secures networks of any size. We’ll dive into AI-Predictive Threat Prevention (AI-PTP), which neutralizes zero-day attacks with a proxy-less, real-time, on-device AI engine. We’ll also cover how a Machine Learning detection pipeline continuously provides automatically generated signatures for emerging threats, delivering stronger security without compromising firewall performance.
The session outlines a security philosophy focused on making security easier to operationalize, from the user edge to the data center. The speakers explain that with the rise of device proliferation, distributed applications, and Gen AI, the threat landscape has become more complex. HPE’s approach is to use a comprehensive threat detection pipeline, heavily leveraging AI and machine learning, directly on their SRX firewalls. This strategy aims for a high detection rate and a very low false positive rate without sacrificing performance. The core of the presentation centers on a feature called AI-Predictive Threat Prevention (AI-PTP), which represents a shift from traditional reactive, signature-based models to a proactive approach for identifying both known and zero-day malware.
The AI-PTP system operates using a two-stage process. First, machine learning models are trained in HPE’s ATP Cloud using vast datasets of malicious and benign files. These trained models are then deployed to the SRX firewalls, where the “inference” or detection happens directly on the device. A key differentiator is its inline, proxy-less architecture, which analyzes just the initial portion of a file as it’s being downloaded to quickly determine if it’s malicious. This allows the firewall to block threats in real-time. This on-box capability is part of a defense-in-depth strategy, augmented by cloud-based analysis, including multiple sandboxing methods. During the demonstration and Q&A, it was clarified that this process has a negligible performance impact, can update threat signatures across all customers in minutes, and can automatically place an infected host on a blocklist that is shared across the entire HPE security ecosystem, including NAC and switching solutions.
Presented by Kedar Dhuru, VP of Product Management, Mounir Hahad, Sr. Director of Engineering, HPE Networking Threat Labs Leader, and Pradeep Hattiangadi, Sr. Technical Marketing Engineer. Recorded live at Security Field Day 14 in Silicon Valley on September 24, 2025. Watch the entire presentation at https://techfieldday.com/appearance/hpe-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://www.hpe.com/us/en/networking/hpe-aruba-networking.html for more information.
Transcript
Good morning everybody. Uh, my name is Kru. I, uh, run product management for the Juniper, uh, side of the HP networking and HP security, uh, portfolio, uh, along with Uni, haha, and, uh, Pradeep.
Um, Hatari, um, three of us will cover, um, AI predictive threat prevention, and I'll set a little bit of context, and Pip's gonna get into the more of the details and, uh, uni, uh, leads, uh, threat labs, and between the three of us, we can help answer questions in this area. Um, so when it comes to security, the approach that, uh, Juniper has taken and what we bring also to, uh, HPE security is we look at how, uh, to make it easy for customers to operationalize security. And when it comes to doing that, it, uh, it focuses on helping securely connect your users who typically sit at the edge, whether it's a branch, whether it's a device, whether it's a user connecting remotely, all the way to, uh, um, the, the other part of the network, which is your data center, which houses your crown jewels and, uh, your applications and your data, which not only your users need to access or your partners need to access, but, uh, things that, um, um, you know, threat actors and, um, uh, attackers are looking to, uh, exploit or get a hold of.
And, uh, in order to help protect, um, your users accessing the applications, um, we have a variety of different security applications that run, uh, either on, uh, at the edge or within the data center to be able to detect threats, to be able to detect the right kind of access. Um, Madani mentioned a number of different, um, uh, products in our portfolio that help us do that. Uh, but all of these security, um, um, uh, services and security applications are running on top of the firewall and running in, in many of these different areas to be able to identify threats as they outcome.
Uh, we think this is important because when you have an organization that is truly looking to, uh, help secure their users and secure their data, you need to have visibility from, uh, end to end-to-end, uh, in order to understand what's happening in your, uh, network before you can even take any kind of mitigating action. And when we look at what, uh, trends, uh, that, uh, that occur in this environment with the, with device proliferation, with your applications, moving into, uh, a more distributed environment like, uh, clouds or even, um, on premises in, in, um, um, um, in, in, in various other data centers or co-location facilities. And with the advent of, uh, things like gen ai, um, compromises are obviously common, but compromises can continue to happen rather quickly.
So, um, whether it's compromised endpoints being part of botnets, whether it is supply chain security or the, uh, identifying threats within a data center, we tend to make use of, um, AI and machine learning in order to be able to detect, um, uh, as many of these threats as possible. We use, uh, this comprehensively across our entire threat detection pipeline, uh, to be able to identify everything from, you know, more complex attacks, uh, things like IPS and, and, um, real, um, using real time emulation to be able to find these attacks. As well as, uh, identifying zero day threats.
Uh, in, in, um, and this is one of the areas that we will be covering today. Uh, the, the use of, um, a comprehensive threat detection pipeline and the ability to ident, uh, make use of machine learning to keep, um, performance high has been, uh, an important piece that has helped differentiate, uh, Juniper security, uh, portfolio in the last few years. Uh, we focused on a high detection rate and a very low false positive rate to give, um, important, um, or to give, um, um, you know, uh, the best security effectiveness to our customers.
Um, in order to be able to run all of these security applications, sorry, I'll build this out. Uh, we use a number of different security services across the entire, um, threat detection pipeline. Uh, the majority of those that use machine learning and AI fall into the, uh, fall into our ability to detect complex and zero data attacks.
One of those called, uh, AI termed ai, predictive threat prevention, um, definitely makes use of this. And Pradeep is gonna take us through what's covered under A-I-P-T-P, um, how it works, and then, uh, demonstrate, um, how we are able to detect, uh, a threat and show you, um, how to investigate, um, you know, what has happened and in, in order to be able to once, um, a threat is detected and it has been blocked. Hey, good morning delegates.
Uh, and I appreciate the time to present, uh, AI predictive threat prevention. Uh, just to, you know, touch upon what, uh, Kahar mentioned, we're talking about more AI as of today. Now, AI isn't just a buzzword, but a key aspect that is needed as part of cybersecurity, and that's what we are gonna dwell in right now.
And what AI productive threat prevention really is. It's an advanced security solution that's provided by, uh, that's, that's provided by the SRX series firewalls that allows us to kind of, uh, use artificial intelligence and machine learning in order to, you know, detect, uh, um, um, zero day malwares and known malwares known malware in, in, in what is there in the wild today, right? This is a combination engine where we lead with the machine learning detection that allows us to deploy a machine learning model on the firewall that can be used as an inference model for us to, you know, do the zero day detection and also mitigation based on what what has been detected so far.
We augment all of these using what we call as a flow AV engine. This engine focuses specifically on looking at AI generated signatures and using AI generated signatures to detect malware in the wild for also known, uh, signatures that we are generating. We are also focusing on making sure a single signature, one signature is good enough to also detect polymorphic malware in, in its nature, polymorphic can say, you know, if you say what polymorphic is, in that case, polymorphic is more of, uh, uh, any kind of characteristics behavior, a malware changes, you know, we are able to detect all of this using a single AI generated signature that is delivered to the firewall.
And, uh, all of this space, the key differentiator on why AI productive threat prevention is really important, kind of shifts the focus on our approach from a reactive approach, where we are looking at traditional signature based models, trying to detecting a malware to proactive, where we can now deploy a machine learning model where we are going look at, uh, heuristics of a file, a ma look at behaviors, look at anomalies that can bring in the aspect of ca capturing metadata, and also detecting if that particular file that is passing through the firewall is a good file or in, in a mal, or it's malicious in its intent, or a probably a malware. Right Now in, in that perspective, when you look at it, if you see a file being downloaded across the firewall, we see that, you know, the file needs to be captured. We need to analyze the file and kind do so some kind of analysis on it to identify if it is a malware.
But here in this perspective, we only need a early portion of the file in, in, in aspect where it's only a partial file that is needed for us to do detection. And that is kind of, uh, uh, very enormous in terms of doing detection while the file is being downloaded. We are able to now, uh, detect if that's a malware or not.
And that's what I'm gonna dive into furthermore on the next couple of slides. But before setting, going into the aspect of machine learning and, you know, the detection, what I explained just now with a productive threat, you know, what I want to kind of zero in on is why ML is really needed here and why artificial intelligence is really required. Right?
There are two, uh, points that we have to, you know, commonly talk about when we are using ML in terms of doing threat detection. One is training, the other is inference, right? In the training phase, we are looking at capturing a lot more details like behavioral data.
We are looking at static content, we are looking at information that is available across, uh, you know, various aspects of a file for us to analyze if a particular, uh, uh, file is a malware or it has a good file. And we also have accumulation of all of these good files and bad files or malware files that we actually use as data sets for us to train these machine learning models. That is done.
Now, again, all of this is used user supervised, uh, machine learning. The point is it takes a lot of compute, and that is where we have augmented all of this in the cloud with the, our within, uh, HP Juniper, we call this as a TP cloud, and this is our threat e ecosystem where all of these models are trained. Once these models are trained and the models are available, then we allow this model to be deployed to the firewall where it can download as an update and use that for, you know, update as, uh, uh, you know, detecting malwares.
And that is the model that we use for inference that we have, uh, configured on the firewall for us to do malware detection. Again, all of this is done in dynamic where they can download these updates and then automatically use them to, uh, detect and mitigate any, uh, malwares right when the file is being downloaded. And that's the process of ml.
And now digging deep into how this all works, now that we understand we have created a train model, we have deployed that to the firewall, how does it really work in conjunction, right? So here, there's a couple of things that we want that I want to kind of focus in on. The first thing, this is an inline detection engine that allows us to, uh, look at information much before the file is being downloaded.
That is, I only need a early portion of the file for me to make a determination whether this particular file that is passing through the firewall is a malware or is it a good file, right? Irrespective of all that information being captured while the file is being traversed. If I identify this to be a malware, then I will drop it, take certain action to block it, and also capture information that allows me to send data to a TP cloud that ensure that I can run, run through creating a, a dynamic AI signature that can be deployed across all the srx that is part of the ecosystem.
And I'm not just talking one customer or one, uh, uh, customer that has, you know, identified it. Any customers that is enrolled into a DP cloud using that particular feature is now allowed to download that signature and block any kind of emerging threats right in line while the file is being downloaded. So we can cater to, uh, emerging threats that are coming down, we can block them right away and also help all the customers that are part of that ecosystem to gain that signature to make sure we are able to block that in line, and that is what we are gonna see as part of the demo.
Uh, Monique, can we go back a minute? Uh, help me understand something. So first off, when we talk about the data being in line mm-hmm.
That means we're doing like TLS decryption or, or how are you capturing the file? Uh, absolutely. Without TLS decryption, I don't think we can really get to know the content.
Yeah. We have to have s decryption in place, So it's gotta be in line. All right.
Second thing is, you know, one of the, if you go back one slide, one of the major problems that people have who go down this path mm-hmm. Is the dataset component, right. Does HPE have any advantage or does your training model have any advantage over competitors?
Because, you know, we all have a limited amount of, uh, malware samples and what have you. Talk to me about that training side of things. Okay.
Uh, more than side effects probably. Yeah, I would probably lean that down to, uh, We'll tap in. All right.
Uh, next question. Alright, go forward one, please. So I, I'm a little bit concerned about this idea that you're only using a small portion of the file.
Mm-hmm. If I look at polymorphic techniques, if I look at evasion techniques, uh, it is very easy to generate nearly unlimited malware files. Mm-hmm.
Um, that don't pass triggers or don't match known parameters. Yeah. So what is, what is special about HP that's avoiding, um, these types of evasion techniques that are prevalent right now?
Um, I will definitely defer that to Monet in terms of, you know what, Keep kicking over to him. Good. Two, Explain.
You got Me. Alright. Thank you.
But the point I wanted to bring in is our capability on doing defense on, uh, defense in layers where we look, take a layered approach for us to, uh, run through this process of malware detection. We, we know AI is a buzzword, you know, it's imported in sapo security, but AI can't solve all the problems. So we want to make sure we have a defense in depth approach that allows us to layer multiple engines together, not just on the box, but also in the cloud to make sure we have the ability to do early detection.
We have the ability to make sure that the performance is good. We also have the ability to ensure that whatever threat or data that we have captured and detected, we're also able to share that threat intelligence across the customer ecosystem. Right.
Uh, and the point of we, me talking about using early detection is basically using a proxy list architecture where you know, the file when it's being downloaded and our client clicks on a file, it's being downloaded. I'm able to now just take that portion and make a detection if it is, uh, you know, a malware or a good file. So as part of that, uh, layering, are you looking at things like sandboxing?
Are you, uh, inspecting it for later if they come through through execution? Yes, absolutely. And this is the kind of thing we don't do on the next generation firewall because it's just too time consuming.
So these kind of files are actually streamed to the cloud where we have our advanced threat prevention cloud, and that's where another series of engines kick in. And one, one of them, I would say one of them, that's not true. We have like five different sandboxing methods that are happening in the cloud.
So each one of these files go through the entire gamut of, uh, sandboxing and we build m models on the behavioral analysis, uh, this time and we produce verdict with that as well. And all that is fed back into these engines in order to be more effective the next time, so that you don't have to wait for the sandboxing results. Okay.
Thank you. You're welcome. Now, before you start another question, uh, sorry.
Uh, Jack er with Paradigm Technica, uh, you said you're running, running the inference on the firewall itself. So what's the performance impact? Are you measuring that and, uh, you know, yes, go ahead.
Oh, you, You, you can bet this was like our first thing. You know, when, when you're building a firewall, your number one goal is to make sure, uh, speeds and feeds are there. So, um, our, our, um, performance impact is actually negligible near next to the fact that you have to extract the file content.
Mm-hmm. So as soon as you're deciding I'm gonna do L seven, uh, type of inspection, the inferencing itself is ridiculously small. We we're talking like sub millisecond per file of interest.
Right. Remember, you not every connection on through a firewall is going have a file of interest. Mm-hmm.
So it's, it's really minimal. Again, the impact is when you decide to turn on layer seven inspection, because now you, you you're getting some additional modules into play, now you're having to decrypt, potentially you're gonna have to extract the, uh, portions of the file that by itself for any layer seven application is gonna take some time. Right.
The inferencing itself is negligible. Well, no, it's, it's not a, from my perspective, I'm looking more at what's the, like the CPU load and how, at what point do you just run outta CPU and memory? You, you don't think Me, memory we don't, because again, it's very small.
And remember when you, when you look at, um, the percentage of flows that would have a file of interest is extremely small. Mm-hmm. So you're not adding a lot of load, you're not adding a lot of memory requirements.
There is a little bit, I'm not saying it's zero. There is a little bit, but honestly it's negligible. Okay.
It, it really didn't impact, the one thing that we had to do is make sure that we're not just taking Python code and running it on the firewall. We actually did a lot to take that Python code, turn it into something else that can run really fast. Right.
So we did that work. Yeah, for sure. Thank you.
Okay. All right, sir. Thanks you.
I'm sorry. Thanks. You're doing different protocol analysis, right?
Any different Types of protocols too? Yeah, of course. Yeah.
Mm-hmm. Yeah. I mean H-T-P-S-M-B, um, you know, Ssap Yeah.
All major protocols that are really needed for detection, where we see a process of where malware can get in. All of those protocols are covered for sharing. We use SMB where SMTP, we can use HCTP on also IMAP as well.
And sometimes protocols are within protocols, right. When they're traveling. I mean, do you do deep packet inspection of those protocols?
Absolutely. You're right. And that is more involved in how do we decrypt the packet in terms of looking at, uh, protocol within a protocol.
Like for example, uh, uh, we are doing, uh, you kind of TLS over a DNS like for example, we want to now unravel that packet and then do, there are other methodologies and features that we employ to make sure we are able to decrypt the packet in order to do the detection. Okay. Yeah.
If, if not anything, you know, if you see a packet and packet or a protocol and protocol, it's good to either just drop it right in case if it is not needed, they will still back down. If you look at, for example, encrypted DNS, right? If you, if the browser initiates an encrypted DNS connection, if I'm not able to, uh, and I don't want to that specific connection to pass through, I drop it, it'll fall back to a normal DNS request that it'll go through because it definitely has to resolve and in some point, so the idea would be to extract and kind of decrypt and extract.
One more question, Michael Davis. So from the time you detect a new threat, how long on average, is it the signature model update to other customers dispersed? No.
So, um, that depends, but let me explain a couple of scenarios. Let's say, um, let's say we don't detect a file by either of these engines on the, on the device, right? Mm-hmm.
And, and the file has to go into the cloud. Once it goes into a cloud, it goes through a pipeline. We have other ML engines in the cloud that use the entire file instead of just a portion of the file.
And that takes about a second to, uh, issue a verdict, and then it goes into additional engines, and then it goes into the sandboxing as well. Sandboxing can take minutes, right? But as soon as we have a solid verdict of something being malicious, that particular file is sent into an engine that start generating the signatures that get pushed back.
The turnaround time on that is probably about five minutes because the firewall is kind of ping and asking for, uh, for that in some situations where, um, the verdict is available to us prior to, to that event because some, you know, some file could be seen somewhere else, or we have something in an old database or something, then that signature is immediately pushed to the device. We, we have a, um, a permanent connection between the device and the cloud. So the cloud can actually push signatures immediately.
So turnaround time could be anywhere between seconds up to five minutes. Okay. And, And, and I'm, I'm kind of skipping some of the details because some customers may not even have the advanced threat prevention connection, which is a mistake in my opinion, but let's say you don't, then those signatures come from, uh, content delivery network and that's where the five minute delay happens.
Okay. And to, and to a point what UNE said in that point of view, if I detect, uh, uh, a malware within the machine learning engine and I with the demo, I can really, you know, give you a overview on how that really pans out on how fast the signature gets updated for any other detection that's trying to download a similar file. It actually picks in and the signature is pretty fast.
Okay. Uh, let me start with, uh, uh, security Data cloud. This is our configuration management platform.
And I have here in my demo environment an SRX that is deployed at the perimeter edge that is catering to all traffic that is leading out to the internet. And I do have a simulated, uh, malware environment as well where I would initiate downloads. Uh, so I'm just going to, uh, run through the demo part of it, which shows this ability to, uh, uh, in fact, uh, see how a malware that is being downloaded is detected in line and blocked right away.
So I have one of my clients here, the client, uh, is trying to download a specific file. So if I click on the malware sample file, you can see the output has immediately failed. That means it only got apart whichever it was able to download, because now we are looking at an early part of the file for us to do detection.
We knew now we know that the file is already not downloaded. We only has got a corrupted set of file, which is not executable in, in any way. Right?
Uh, how do we really pan that out for an administrator, security administrator? He wants to know exactly what's going on and how the detection happens. We have a couple of ways to kind of identify that.
We see the file immediately came through. We saw that it was detected by one of the pipeline engines that's there on the firewall. We are able to get more details that, that it was a threat level 10 that was detected.
The file that was there was probably malicious in its intent based on its behavior heuristics that it has calculated, and it kind of gives you the information on all the IOCs that are needed for an administrator to take action, right? That information is already available. I look at the engine, I look at the data that gives me data on the source, the firewall where it was downloaded gives me the d the URL from where the, the malware was downloaded and a few other information that is, uh, part of that, uh, uh, IOC that we need for us to take any action as an administrator, right?
We see the action, the action is taken. The unique differentiator on what the SRX provides is auto mitigation. Now that we see a user has downloaded something malicious, we want to block him right away, right?
And we want take action. And, and all of that is under the system administrators control or the security administrators control. So if you look at the configuration management tool, this particular host automatically adds this user that I initiated this download from into a list called as the infected hosts.
This list is a global list that is applied across all the firewalls. So if the user is detected on one part of the customer environment, downloading something malicious, the user is blocked across all the other firewalls that he might get into. He might plug out, go to a different uh, area, try to plug in, you know, he blocked right away if there's a S RX that is catering to.
So you can, uh, if you kind of dive deep into it, you get more details on the timeline on where this detection has happened and what category of detection that you can see. You can also see various aspects of how the detection has occurred and what information it really hit. Right?
You can get various aspects of it. This is basically a incremental engine wherein the user is not risked right away. If it is done multiple, uh, uh, malicious behavior.
Where is intent is multiple, where he has done, you know, multiple activities of those malicious intent. That is where we start incrementing the score for the user to be, uh, blocked in its perspective. All of that is controlled by a policy that is delivered on the firewall to make sure it's all under the security administrator's control because he controls what is the risk level and what bucket I want to put that user in.
Okay. That is how we kind of pan it out to kind of dig a little more deeper into, uh, what that information is. Uh, and I talked about, uh, you know, showing you, uh, analogy on how it works.
So if you look at one of these files here, uh, once there is a detection, uh, let me grab the right one. Okay, this is good. Once we see a detection on one of the pipeline engine that is there, we are able to now see any the same files being downloaded by various other sources immediately have a signature.
And if you look at the timeline, it is very minimal in terms of what and how a signature can be detected and can be deployed across these firewalls. It's very minimal when we know, and, you know, kind of mentioned, we have a pipeline of detection engines that are there, right? These detection take the call on how fast we can generate the signature and deploy, and you can see that right away on board, on your, uh, you know, dashboard that you see an engine detected, but you can have a signature right away pushed onto all the firewall that is probably downloading the same file across multiple parts of a customer network.
I had one quick question. Sure. Lina.
So right there, where I see, you know, it breaks it down by signature id, and I know like all these different platforms have something, can you base, and I don't know how granular it can go, but can you base it off of a signature ID or a file name? Like you could create custom policy sets around that. So then, so like pretty much if you notice a pattern, right?
It's almost like, like leveraging the AI and ML piece, you start seeing a particular pattern, maybe 1, 2, 3 files. Can you build a policy set around that to then just block specific set file types like that, that you can deploy across? Absolutely.
And, and that is an excellent question. We have a feature on the SRX called as the adaptive threat profiling. Okay.
This basically profiles and has got unlimited users on what you can and how you can build this feature across in a customer environment. It can be based on IP addresses, it can be based on user IDs. It can be based on a signature that you detect where you can actually build, if you look at the, uh, uh, the engine that is actually, uh, pointing toward what really blocks or what really, uh, is used basically either an IP or a user that is the bare bone that we use for us to do some kind of mitigation.
And we can utilize this in any way, either through an application signature, either through a threat signature or either through, uh, you know, looking at these IOCs, we can start building those threat intelligence. Okay. Thank you.
Let's suppose I wanted one of my analysts to check out one of these files. Mm-hmm. Throw in our sandbox, figure out what hardening we would've needed if it had made pass Absolutely.
This control. Am I able to do that from here? Absolutely.
You have this, uh, aspect of manual uploads. You can actually just put in this data, submit it to the cloud, cloud, will run through it all the engine pipelines, and then give you a worded. This is without having any, uh, anything affected on your network, you can do a manual upload and then see what it is worth and then take a call.
If you see such kind of file types, you also have the ability to add in some sort of signature. Well, I can submit files to you. Yep.
Can I get files out of the tool? Yes, absolutely. And that's a good question as well.
And that's my, That's downloads. I'll upload some downloads. Oh, sure.
Okay. That was my next update. So if I detect a particular file, yeah.
I look at a specific file, I am able to go through all of its sandboxing capability, uh, gives all the IOCs that I need, right? It runs through a multiple pipeline engine. Yeah.
One is static analysis. It goes through several aspects of looking at what file did it touch on a file system for me to detect that this is what is malicious, right? And it also looks at behavior analytics, where it looks at heuristics, it actually draws a threat score on every single behavior that it does on a file system for me to know, okay, this is something that is bad, that is doing across a file system and you know, rates that it also captures network activity.
If it is hitting a C nnc, if it is hitting some, some domain, which is not good, captures all that information, looks at DNS activity, contacted domains, and also behavior details. Details says this, if it's, you know, kind of depicted a specific set of behaviors, it'll align that and also show information that, you know, it deployed a command. T XE ran a particular broker file and gives you more information around what that broker file really did.
Right. And, uh, at first, you know, if nothing is without visualization for a security administrator, it is very, uh, very much needed for him to know exactly what kind of, uh, value I get out of this detection. And that is where we introduced the Mitre attack framework that allows us to proposition this on the right threat level and in aspects of what, what it really delivers in that aspect.
Uh, so Question we go high level, uh, to amount, um, TechOps have challenges with collecting the data mm-hmm. And providing it for CSO reporting is, uh, are you able to show us a bit of capability around that? And, and second question is around integration with ITSO and solutions mm-hmm.
Uh, for tracking incidents, Um, Et cetera. And that's, that's, that's a really good question. Uh, if I, I just want to, you know, kind of draw your attention towards the dashboard.
This dashboard is, gives that value, it kind of collates for all SecOps administrator that are there in the organization. I want them to now visualize and understand what's going on in your network. So we deliver multiple personas in that nature.
This is a general persona. This is a security persona. This persona, a persona actually maps on to every single, uh, uh, feature set that has been kept in, in your environment, gives you details of how much was permitted, what was denied, if there was any, uh, you know, uh, events that were detected in it.
In our case, you know, we have the anti-malware or the, you know, malware based signature that we ran through. It gives you overall details on the number of malwares and also gives you the ability to filter out, uh, based on application, based on the source host that it is detected from the IP address where it originated from all of that information in a single dashboard. Right.
And this information can be boiled down to a report where, you know, SecOps administrator can run what we call as a threat assessment report and can schedule it to get generated every week. And that's in the reporting module that is, uh, kind of defined here. So if you see the reporting here, you can actually run through a definition that gives you various aspects of creating different kinds of security reports that can be automated as well.
Okay. The, the last thing you know that I want to leave you guys with is the ability, the, I just want to summarize the point, the key point to take away from this AI productive threat, a very advanced engine that is there on the firewall, it utilizes a machine learning model as inference that is deployed to the firewall that can block threats in line, right? It is in line where you're looking at just a portion of the file and then we are able to determine if it is good or bad.
And also this is done in a pro list design. That means we are looking at the file while it is being downloaded, and predominantly make sure we have the right performance and value that a customer would need for him to protect against any damage that a malware can, uh, uh, the malware can cause in defense in depth approach. This is not the only engine that we have.
We have multiple engines that is layered together that allows us to give the necessary depth to identify a malware. Even if one engine is not able to identify it, we are still able to leverage it, uh, run through some AI and ML capabilities to make sure we have a dynamic signature to protect them from emerging threats. In a question here, in a couple of your different screens, you had different ways of showing risk.
Mm-hmm. Can you give us an idea of what, you know, what, how you're measuring risk and what the parameters are? Yeah, That, that's a good question as well.
Every single, like I talked about, uh, looking at a malware, it looks at behavior, uh, obfuscation and heuristics to understand every uh, uh, behavior it does within a sandbox environment has got a threat level associated with it. That threat level is what defines the risk. These threat levels within the, uh, SRX firewall ranges from one to 10 and one being the lowest and 10 being the highest for every behavior that is put put across.
And we actually, uh, allocate a score to that specific aspect. Now, in this case, I download a malware or threat level 10, but the user would be tagged with a different risk level depending on the incremental score. The user would, uh, align based on the behavior that the user would kind of, uh, see on the network or do on the network.
What I'm trying to figure out more is what is it that makes you think something is risk level 10 versus, or or threat level 10 versus threat level One? Yeah. Like what are indicators or what are things that this will break down and go like, this is a one, how do you like classify it, I guess?
And I think that is based on Indian, uh, yeah. Yeah. Uh, I'd probably have have a better answer to that, but the point is, it's all based on the heuristics that I talked about.
It's all based on the behavior and identification of what it really provides when we are looking at a specific Yeah. So I'll, I'll just, uh, add a little bit to that. In terms of, um, scoring threat levels, um, there are a couple of things that go into play.
One, one of it is the confidence that something is indeed malicious. The second one is, well now that you know, how bad is it, right? Is it ransomware?
Is it adware? Um, the way we do these things is, uh, in a couple of ways. Sometimes when we build in threat intelligence, actually the threat researchers tag a particular threat score to every threat we know of.
So when we import things, that threat score comes with it. When it comes to things we identify on the fly, it's the machine learning itself basically that identifies some of the behaviors that we saw here. And in aggregate, it'll associate both a confidence and a threat severity to the one thing.
I think we call it threat score, but you know, I've, I don't know yet how we can combine these two things together very well and tell people, look, we're telling you that we are really confident it's malware, but it's also adware so you shouldn't worry about it. That thing is really difficult to get because a lot of people tell us, ah, I don't wanna deal with two metrics. I only want one.
Alright, how do you define that one? So, but ideally it's the machine learning model that brings a lot of the, um, features that contribute to a threat, uh, score. Eventually.
This is Marian on that threat scoring. Uh, as a customer, can I, uh, customize that in my environment? Say I'm using NIST or, uh, have a different business acceptance of risk?
Yeah. Yeah. I'll take that question, Mariana.
Absolutely. Uh, yeah, we have a risk profile that is, that can be configured and the customer can define different buckets on where to put specific set of threat scores. And you can define it on a per feed basis as well.
In the instance of, oh, sorry, Sarah Nolan, in the instance of something like a false positive where I see something come from my environment and it's a, a tool that could potentially be a problem, but we use it regularly. Um, are exceptions created on a by user basis? Is it across the environment and in the situation where I have a multiple tenant set up, do I do it from like the top level or are they one-offs?
Okay. Uh, for exceptions we have what we call as the allow list and the block list, basically white list and, uh, you know, the black list that we have, and we have this for various engines that can be delivered based on ip, based on domain and based on a hash as well. Right.
And yeah, this can be on a global basis depending on the role of the firewall. If the firewall has a multiple, multiple tenants that are there, and each of the tenants can also enroll into different, uh, realm, what we call as the A TP realm, and then that can get its own set of, uh, uh, you know, um, you know, allow list and block list as well. Um, Vitri talked about SOC and analysts actually, it's really hard for them right now, right?
Because they have so many different tools. So how many different tools can, can Juniper bring in to try to minimize, um, some of the workload from, you know, and so you don't have several panes of glass, right? So less, you know, a single pane of glass.
Mm-hmm. And how long does it take to tune this box? Okay.
Like if you were to drop it in? Okay, That's an, that's a good question as well. Uh, looking at, uh, the management platform, it needs to provide the ability to start looking at APIs, and that's how we have, uh, built our management platform and the not, not just management platform.
Every other ecosystem that we are built is based on APIs. Any third party vendor can use those APIs to get that information to capture IOCs all that relevant information can be got from these APIs in order to have that integration across any other tools that that comes in. I've got a question, kind of same question, but different lens.
Beginning of the presentation talked about how you bring a product suite of tools to the table, not just the SR X, but many other things across the organization. Um, you mentioned going into an infected list and that passes to the other sxs, right? Does that also pass to your other tool?
So like, can, can that drive your N tool or other tools that would isolate that host more directly rather than just across the SRX? Absolutely. Yeah.
And that infected feed is a very unique feed that gets integrated across our entire ecosystem for us to block it at the switch, block it at the virus, and point all of that delivered through, uh, you know, API request as, and when the detection happens and the data is there, They were to want to bring this into an environment. Mm-hmm. What is the recommended time that you're putting this for implementation in like a simulation mode to pull down data from my environment before, you know, to avoid having a bunch of false positives or having, you know, useful data blog.
Uh, so let me understand the question in perspective, you are talking about deploying our firewall in your environment mm-hmm. Just to see, you know, how it really does detection. Yes.
Okay. And we have multiple features that are there on the SRX itself from what we call a tap mode that allows us to just integrate it into your environment without affecting your current traffic profile. Mm-hmm.
And then run through the entire metrics of L seven, uh, capabilities. Okay. Whatever I showed across is available on the tap mode so that we can give you all the necessary metrics much before deploying the firewall in the N one.