NGFW: MARKET GROWTH, DEPLOYMENTS, AND NSS TEST RESULTS

GoNSSLabs 633 views 16 slides Apr 20, 2016
Slide 1
Slide 1 of 16
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16

About This Presentation

Are you planning to deploy a next generation firewall system? Do you want to understand what it is, and how it can help keep your organization secure?


Slide Content

NGFW: MARKET GROWTH,
DEPLOYMENTS, AND NSS
TEST RESULTS
NSS Labs Research
03/17, 2016
Thomas Skybakmoen
Research VP
Mike Spanbauer
VP of Security,
Test & Advisory

Slide 2
NSS Labs
The World’s Leading Security Insight Company

Slide 3
Unmatched Security Testing Expertise

Slide 4
Agenda
• The NGFW market and growth
• Driving the deployments in the enterprise
• NSS Labs’ 2016 NGFW Group Test results
• TCO
• Security Effec,veness
• Performance
• Q&A

Slide 5
NGFW Defined
• TradiSonal “first generaSon firewall” features, such as:
• Basic packet filtering
• Stateful mulS-layer inspecSon
• NAT
• VPN
• “Next generaSon firewall” features, including:
• ApplicaSon awareness/control
• User/group control
• Integrated intrusion prevenSon system (IPS)
• Ability to operate at Layer 3 (“tradiSonal”)
• External intelligence to enhance blocking decisions (i.e., “reputaSon services”)

Slide 6
State of the Market
• Market Size
• US$4.4B in 2015
• US$5.1B in 2016 (NSS est.)
• Current buyers
• Large enterprise made up
38% of sales in 2015
• Evolving +
Expanding market
0%
5%
10%
15%
20%
25%
$0
$1,000
$2,000
$3,000
$4,000
$5,000
$6,000
$7,000
$8,000
$9,000
$10,000
2015 2016 2017 2018 2019 2020
NGFW Revenue NGFW Growth

Slide 7
Deployment Drivers
• Security EffecSveness
• Increasingly complex threat landscape
• ConSnued drumbeat of high profile breaches
• Availability of high performance products
• Total Cost of Ownership
• Lower TCO compared to mulSple products
• Security management through a single plaeorm
• Internal firewall opens up new deployment (distribuSon switch displacement)
• Improve security workflow/IntegraSon
• IntegraSon with SIEM, incident response
• Cloud and virtual deployments, common policy

Slide 8
NGFW Group Test
• Individual products tested per the
methodology
• Product Reports released
• ComparaSve Reports released
• Live TesSng Security ComparaSve results from NSS
Cyber Advanced Warning System
• SVM
Security
Value
Map
Vendor
A
Vendor
B
Vendor
C
Vendor
D
Vendor
E
Security
EffecNveness
Performance
Total Cost of
Ownership
Product Reports
ComparaNve Reports

Slide 9
Group Test Results : Definitions
• TCO
• Purchase
• Maintenance - incl. subscripSon fees
• AdministraSon – incl. installaSon and tuning
• Security EffecSveness
• EquaSon: Exploit Block Rate*FW Policy*App Control*Evasions* Stability
& Reliability
• TCO per Protected Mbps
• EquaSon: (3-Year TCO)/(Security EffecSveness x NSS Tested Throughput)

Slide 10
Group Test Results: Protection and TCO
Map TCO per Protected Mbps against Security Effec,veness
Further up and right is best
Above line = above
average security
Security Recommended

Slide 11
Group Test Results: SVM
NGFW v6.0
Barracuda
Check Point
Cisco ASA
Cisco FirePOWER
Cyberoam
Dell SonicWALL
Forcepoint
F}??v?Hillstone
HuaweiJuniper
Palo Alto Networks
WatchGuard
100%
90%
80%
70%
60%
50%
40%
$100 $80 $60 $40 $20 $0
TCO per Protected Mbps
S??]?? E+??v??
Average
Average
• 2000 unique exploits
• 2 months of live data
• 750+ exploits
• Dec 2015 – Jan 2016

Slide 12
Group Test Results: Breakdown
• Security
• Security EffecSveness from 58.1% to 99.6%
• Average Security EffecSveness: 96.3%
• CAWS: no single product blocked all anacks
(77.12% to 99.97%)
• Evasion effecSveness: 100%
• Performance
• Throughput from 2,477 to 42,324 Mbps
• TCO (10 devices + 1 CMS)
• 3-year TCO ranged from $312,746 to $12,573,800
• Average 3-year TCO was $2,579,457
• TCO per Protected Mbps
• Average TCO per Protected Mbps:US$27
• Ranged from US$6 to US$97

Slide 13
SVM Toolkit: Cyberoam Retest
NGFW v6.0
Barracuda
Che ck Poi nt
Ci s co ASA
Cisco FirePOWER
Cybe roa m
Dell SonicWALL
Forecepoint
Fortinet
Hillstone
Huawei
Juniper
Palo Alto Networks
WatchGuard
Cyberoam Retest
40%
50%
60%
70%
80%
90%
100%
$0$20$40$60$80$100
Security Effectiveness
TCO per Protected -Mbps

Slide 14
CAWS
TM
Brings Continuous Live Exploit Testing to Group Tests
Announced February 18, 2016
2016 GROUP TEST ROADMAP
CAWS
CAWS
CAWS
CAWS CAWS

Slide 15


QuesNons?

Thank you!
Go to www.nsslabs.com
to download the free NGFW
Security Value Map Graphic
*Click the the second button bottom left.