INDEPENDENT VALIDATION OF FORTINET SOLUTIONS. NSS Labs Real-World Group Tests



Similar documents
How To Get A Fortinet Security System For Free

FortiGuard Security Services

Fortinet FortiGate App for Splunk

The Fortinet Advanced Threat Protection Framework

MSSP Advanced Threat Protection Service

Use FortiWeb to Publish Applications

WHITE PAPER. Protecting Your Network From the Inside-Out. Internal Segmentation Firewall (ISFW)

WHITE PAPER. Protecting Your Network From the Inside-Out. Internal Segmentation Firewall (ISFW)

The Enterprise Cloud Rush

Protecting against DoS/DDoS Attacks with FortiWeb Web Application Firewall

SDN Security for VMware Data Center Environments

FortiVoice Enterprise

5 ½ Things That Make a Firewall Next Gen WHITE PAPER

Improving Profitability for MSSPs Targeting SMBs

WHITE PAPER. Protecting Your Network From the Inside-Out. Internal Network Firewall (INFW)

Securing the Data Center

WHITE PAPER. Protecting Your Network From the Inside-Out. Internal Segmentation Firewall (ISFW)

FortiGate 100D Series

Fortinet Partner Program

ENTERPRISE EPP COMPARATIVE REPORT

FortiGate 200D Series

Overview. Where other. Fortinet protects against the fullspectrum. content- and. without sacrificing performance.

FortiWeb Web Application Firewall. Ensuring Compliance for PCI DSS requirement 6.6 SOLUTION GUIDE

FortiCore A-Series. SDN Security Appliances. Highlights. Securing Software Defined Networking (SDN) Architectures. Key Features & Benefits

Keeping the Store Open: Fighting the Cyber Criminal in the Retail World

FortiVoice Enterprise

WHITE PAPER. Empowering the MSSP. Part 1: Real World Customer Needs

Transforming Your WiFi Network Into A Secure Wireless LAN A FORTINET WHITE PAPER. Fortinet White Paper

FortiGate/FortiWiFi 60D Series

Purchase and Import a Signed SSL Certificate

Internal Network Firewall (INFW) Protecting your network from the inside out

Secure Access Architecture

FortiGate/FortiWiFi 90D Series

FortiGate/FortiWiFi -60C Series Integrated Threat Management for Small Networks

NEXT GENERATION FIREWALL COMPARATIVE ANALYSIS

SOLUTIONS GUIDE. Secure Wireless LAN Solutions Guide. Complete Wi-Fi Security for Any Network Topology

FortiSwitch. Data Center Switches. Highlights. High-performance and resilient managed data center switch. Key Features & Benefits.

Same great products, different brand name

SOLUTION GUIDE. Hybrid WAN Solutions with FortiWAN. The cost-effective way to deliver the WAN bandwidth and redundancy your organization demands

Fortinet Secure Wireless LAN

WEB APPLICATION FIREWALL COMPARATIVE ANALYSIS

WHITE PAPER. Empowering the MSSP. Part 2: End To End Security Services Ecosystem

Place graphic in this box

Internet Explorer Exploit Protection ENTERPRISE BRIEFING REPORT

DATA CENTER IPS COMPARATIVE ANALYSIS

FortiSandbox. Multi-layer proactive threat mitigation

FortiAuthenticator TM User Identity Management and Single Sign-On

Fortinet Presence Analytics Solution

FortiGate. Accelerated security for mid-enterprise and branch office. Designed for today s network security requirements

WHITE PAPER. Securing ICS Infrastructure for NERC Compliance and beyond

Fortinet s Data Center Solution

Load Balancing Microsoft Exchange 2013 with FortiADC

Fortinet s Partner Programme

The Fortinet SDN Security Framework

Load Balancing Microsoft Exchange 2013 with FortiADC

Protecting the Cloud. Fortinet Technologies and Services that Address Your Cloud Security Challenges WHITE PAPER

Fortinet Advanced Threat Protection- Part 3

Securing Next Generation Education A FORTINET WHITE PAPER

FortiAP Wireless Access Points

Configuring FortiVoice for Skype VoIP service

Next Generation Firewalls and Sandboxing

FortiWeb. Web Application Firewall. Unmatched Protection for Web Applications. Emerging Threats Create New Challenges. FortiWeb DATA SHEET

What s New for FortiMail 5.2.0

FortiGate/FortiWiFi -90D Series Enterprise-Grade Protection for Smaller Networks

FORTINET SURVEY The Fortinet Security Census 2014

FortiVoice Enterprise Phone System GA Release Notes

2011 Forrester Research, Inc. Reproduction Prohibited

Managed Security Service Provider Program.

Mobile Configuration Profiles for ios Devices Technical Note

High Performance NGFW Extended

Can Consumer AV Products Protect Against Critical Microsoft Vulnerabilities?

FortiAnalyzer VM (VMware) Install Guide

Market Guide for Network Sandboxing

Disaster Recovery with Global Server. Load Balancing

The New PCI Requirement: Application Firewall vs. Code Review

Securing your IOT journey and beyond. Alvin Rodrigues Market Development Director South East Asia and Hong Kong. What is the internet of things?

WHITE PAPER. Empowering the MSSP. Part 3: Monetizing Fortinet s Ecosystem in a Multi-Tenant Cloud Service

BUSINESS OPPORTUNITY 4 CONNECTED UTM FOR SMALL OFFICES 6 SECURE COMMUNICATIONS FOR SMALL OFFICES 10 COMPETITIVE COMPARISONS 15

By John Pirc. THREAT DETECTION HAS moved beyond signature-based firewalls EDITOR S DESK SECURITY 7 AWARD WINNERS ENHANCED THREAT DETECTION

Load Balancing Microsoft Exchange 2013 with FortiADC

FortiFone QuickStart Guide for FON-370i

Protection Against Advanced Persistent Threats

The Hillstone and Trend Micro Joint Solution

FortiSwitch B and C-Series

FortiGate RADIUS Single Sign-On (RSSO) with Windows Server 2008 Network Policy Server (NPS) VERSION 5.2.3

FortiOS Handbook - Hardening your FortiGate VERSION 5.2.3

Supported Upgrade Paths for FortiOS Firmware VERSION

FortiGate 3700D. The Fortinet Enterprise Firewall Solution. One Enterprise Firewall Solution across the Extended Enterprise. Highlights. forti.

Transcription:

INDEPENDENT VALIDATION OF FORTINET SOLUTIONS NSS Labs Real-World Group Tests

INDEPENDENT VALIDATION OF FORTINET SOLUTIONS Introduction Organizations can get overwhelmed by vendor claims and alleged silver bullets when evaluating solutions that can reduce the risk of a data breach. An IT security purchase made solely based on vendor claims is likely to lead to regret. In a recent survey by Forrester Research i of next-generation firewall purchase decision makers, 71% surveyed would do more comprehensive testing during the evaluation process if they could do it over again, and 61% would also consider a broader selection of vendors. How do you navigate it all to make good decisions then? 71% Would do more comprehensive testing during evaluation 61% Would consider a broader selection of vendors Fortinet believes that independent, third-party tests provide a critical and impartial measure of the quality of a product, and a mandatory reference for anyone making an IT Security purchase decision. Fortinet is committed to participation in unbiased credible testing so customers can see how we compare to alternative solutions and select the solution that is right for their needs. This commitment is why we consistently submit our products to a large number of third party independent tests for evaluation. There are many analysts, researchers, and test houses who make it their business to provide their take on the various security solutions available. However, a relatively small number actually evaluate products in real-world, independent conditions. The leader in the independent testing space is NSS Labs. Fortinet requires the following criteria to be met to participate in a review, test or assessment: Published, clearly defined methodology with customer and vendor input Enterprise customer environment with real-world traffic and current threats Not vendor sponsored or pay to play Report and ratings based on quantified criteria and demonstrated performance Who is NSS Labs? 1 2 3 4 5 6 World s leading security product testing laboratory Focused exclusively on IT security In-depth security product test reports, research, and analyst services Public methodologies open for vendor review and input Tests conducted regularly and free of charge -- no compensation required for vendor participation CEOs, CIOs, CISOs, and information security professionals rely on NSS to evaluate their security investments i Your Best Defense: Next-Generation Firewalls Enable Zero Trust Security Best Practices For Evaluating And Implementing A NGFW Forrester Research Inc. July 2015 2 www.fortinet.com

How NSS Rates Products: Understanding The NSS Labs Security Value Map NSS Labs assesses the security effectiveness and performance-adjusted total cost of ownership for each product. They typically publish their findings in a number of different reports starting, at the highest level with a summary of results called a Security Value Map or SVM. The SVM illustrates the relative value of security investment options by mapping security effectiveness and relative value of tested products. Each technology area NGFW, IPS, WAF, Sandbox etc. has its own SVM. Security Value Map (SVM) Average Neutral Recommended Neutral Security Effectiveness Caution Better Security Average Price Performance Better Value X-AXIS: 3 year TCO per protected unit of measure (Megabit per second, Connection per second) Y-AXIS: Security Effectiveness (block rate) 4 QUADRANTS: Upper-right: Recommended, products that provide an above average level of security effectiveness and value for money Lower left: Caution, products that offer below average value and security effectiveness Upper left/lower Right: Neutral, may still be worthy of consideration depending on budget limitations. The following is a review the most current SVMs across several key IT security technologies and offerings. SVMs pictured are the most current version as of date of publication of this document. www.fortinet.com 3

INDEPENDENT VALIDATION OF FORTINET SOLUTIONS Next-Generation Firewall Test (2014) FortiGate 1500D and 3600C Capabilities Tested: Firewall Intrusion Prevention Systems (IPS) Application Control Reputation Services Both products Recommended Industry s Best Value Next-Generation Intrusion Prevention Test (2015) FortiGate 1500D Capabilities Tested: Intrusion Prevention Systems (IPS) Application Control Reputation Services ü ü Recommended Industry s best value 99.2% exploit block rate 4 www.fortinet.com

Breach Detection Systems (BDS) Security Value Map Cisco Trend Micro Lastline Check Point Fortinet Blue Coat Average Fidelis 100% 90% 80% 70% 60% Breach Detection Systems Test (2015) FortiSandbox 1000D v1.43 Build 0120 Capabilities Tested: Malware Indentification Network Traffic Analysis Sandboxing Browser Emulation Reputation Services ü ü Recommended FireEye 50% August 2015 *McAfee *See Security Value Map Comparative Report $600 $500 $400 $300 $200 $100 $0 TCO per Protected Mbps Average 40% Web Application Firewall Test (2014) FortiWeb 1000D Tested against: Cookie Manipulation URL Manipulation SQL Injection Cross-site Scripting Evasion Tests ü ü Recommended 99.85% block rate www.fortinet.com 5

INDEPENDENT VALIDATION OF FORTINET SOLUTIONS Product Block Rate NSS Lab Rating F-Secure Client Security Premium 11.60 100.00% Recommended Kaspersky Endpoint Security 10.2.2 100.00% Recommended Symantec Endpoint Protection 12.1 100.00% Recommended ESET Endpoint Antivirus 6.1 98.79% Recommended Fortinet FortiClient 5.2 98.79% Recommended Trend Micro OfficeScan 11.0 98.79% Recommended G Data Endpoint Protection 13.1 94.84% Neutral Sophos Endpoint Security and Control 10.3 89.18% Neutral Bitdefender Endpoint Security 5.3 85.34% Neutral Endpoint Vulnerability Exploit Test (2015) FortiClient Endpoint Protection Tested against: Live/Real-time Malware Live/Real-time Drive-By Exploits Live/Real-time Social Exploits/Document- Jacking ü ü Recommended 98.79% average block rate of Web-based exploits Consistency: Rated at 100% for the first 13 out of 15 days No SVM was produced for the Endpoint Vulnerability Test Real-Time NSS Labs Validation Now Available NSS CAWS NSS Labs product and comparative test reports represent one test period in time. For real-time results, NSS Labs has recently launched its Cyber Advanced Warning System (CAWS). CAWS is the world s first and only security as a service (SaaS) solution that pinpoints active exploits, measures your security efficacy immediately, and spotlights actual asset risk continuously. In the CAWS portal, you can see security vendor product efficacy in real-time, against the latest threats, and see trends in solution efficacy over time. Being effective versus threats during one period of time is good, but consistency over time is critical to maximize your organizations protection against threats. CAWS can give you that insight to help you evaluate your choices. Contact a Fortinet sales representative to give you a tour through CAWS and a look at real-time results, or simply visit www.nsslabs.com for more information on the Cyber Advanced Warning System. 6 www.fortinet.com

Putting It All Together The Only Edge to Endpoint Solution Recommended by NSS Labs By participating in these tests, enterprises and Fortinet, have an indepedent measure of how our products rate against real-world enterprise requirements as well as alternative offerings. Earning Recommended ratings in each of the preceding NSS Labs tests, Fortinet stands out as the only vendor to provide an Advanced Threat Protection Solution that is NSS Labs Recommended from the edge to the endpoint. Fortinet is the only vendor to earn individual NSS Labs Recommendations for NGFW, NGIPS, WAF, BDS and EPP. - Mike Spanbauer of NSS Labs Looking at the 5-year summary of Fortinet ratings in NSS Labs group tests, a pattern emerges of consistent improvement and excellence, a growing list of Recommended ratings, and our ongoing commitment to participation in all relevant NSS Labs tests. Product 2011 2012 2013 2014 2015 Firewall Neutral Recommended NGFW Neutral Recommended Recommended IPS Recommended Neutral Data Center IPS Neutral NGIPS Recommended Breach Detection Recommended Recommended Web Application Firewall Recommended Endpoint Protection Five years of historical data provided where available Cell color indicates NSS rating ( Recommended, Neutral, Caution) Recommended As of September 2015 www.fortinet.com 7

INDEPENDENT VALIDATION OF FORTINET SOLUTIONS Real-world third-party validation is an essential resource for enterprises considering security products to help cut through confusion caused by vendor marketing, NSS Labs testing continues to demonstrate Fortinet s commitment to meet high industry standards for security detection, performance, reliability, management and value. - Fortinet CEO Ken Xie Fortinet s Unparalleled Commitment To Independent Testing Earning a Recommended rating from NSS Labs indicates that a product has performed well and deserves strong consideration. Only the most effective and best value products earn a Recommended rating from NSS regardless of vendor market share, size or brand recognition. In a broad set of the most recent NSS Labs reports, Fortinet has consistently earned Recommended ratings. In NSS Labs CAWS realtime service, customers can also see how Fortinet consistently delivers highly effective security over time. Fortinet s commitment to independent testing and certification even extends beyond NSS Labs. ICSA, AV Comparatives, Virus Bulletin and other independent testing organizations have also consistently validated the effectiveness of Fortinet solutions. At the 2015 ICSA Labs awards reception, Fortinet was honored with ICSA s prestigious Excellence in Information Security Testing (EIST) award. Fortinet was recognized for outstanding achievement in information security certification testing for 10 years running. Recommendation And Conclusion To avoid the regret expressed by a majority of IT security purchasers in the Forrester study, avoid biased sources of information during your next IT security purchase evaluation. Consult independent, objective sources like NSS Labs to separate the truth from the hype. Conduct a bake off either in-house or outsourced to a testing specialist. Test with real-world traffic loads to ensure the products can meet your requirements with the appropriate features activated. Select based on your criteria effectiveness, ease of use, performance, price, vendor history and more may have a role to play. Since its inception, Fortinet has committed to consistently proving the efficacy of its solutions through stringent independent testing and certification. The company has received more certifications to validate its solutions than any other network security vendor. These test results are proof that in real world traffic and deployment scenarios our products will beat the competition and perform as advertised. GLOBAL HEADQUARTERS Fortinet Inc. 899 Kifer Road Sunnyvale, CA 94086 United States Tel: +1.408.235.7700 www.fortinet.com/sales EMEA SALES OFFICE 120 rue Albert Caquot 06560, Sophia Antipolis, France Tel: +33.4.8987.0510 APAC SALES OFFICE 300 Beach Road 20-01 The Concourse Singapore 199555 Tel: +65.6513.3730 LATIN AMERICA SALES OFFICE Paseo de la Reforma 412 piso 16 Col. Juarez C.P. 06600 México D.F. Tel: 011-52-(55) 5524-8428 Copyright 2015 Fortinet, Inc. All rights reserved. Fortinet, FortiGate, FortiCare and FortiGuard, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.