Web Isolation 101: Securing Web Apps against data exfiltration and shielding corporate endpoints from web-borne threats

DefCamp 284 views 8 slides May 31, 2019
Slide 1
Slide 1 of 8
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8

About This Presentation

Alex Negrea in Bucharest, Romania on November 8-9th 2018 at DefCamp #9.

The slides and other presentations can be found on https://def.camp/archive


Slide Content

© 2018 Appsulate, Inc.
Web Isolation 101
Secure your Web Apps against data exfiltration and shield corporate endpoints from attacks coming from the web

Alex Negrea
Co-Founder & CTO @ Appsulate

© 2018 Appsulate, Inc.
PROBLEM
Undesired Interaction
between web and endpoint
Remote Users Cloud apps
Web Content Internal Users
Attacks from
malicious code
Regulated data
stays behind

© 2018 Appsulate, Inc.
WHY IS THIS A BIG PROBLEM?
Attacks often start from the edge of the enterprise
exploiting contractors as the weakest link
Liability under HIPAA/GDPR for data breaches of
contractors/employees - with hefty fines
Financial loss due to inadvertent disclosure of
intellectual property
Compliance
Security
IP Protection

© 2018 Appsulate, Inc.
SOLUTION
Appsulate is a shield between
the web and endpoint
Remote Users Cloud apps
Only Pixels
Security
Compliance
Visibility
NO BYPASSING
Web content Internal Users
Only Pixels

© 2018 Appsulate, Inc.
How can Web isolation help you ?
Security
●Prevent Websites from Delivering Zero-day Malware and Phishing Threats to
Users’ Devices. Protect instead of detect.

●Avoid over blocking Employees Access to Uncategorized and Risky Sites

●Give Privileged Users Additional Protection From Web-Based Threats

●Defeat Phishing Attacks by Rendering Email Links Harmless

●Prevent Ransomware by Isolating URLs With Potentially Unsafe Risk Profiles

© 2018 Appsulate, Inc.
DEMO

© 2018 Appsulate, Inc.
Appsulate Bug Bounty
Security
Total prizes: $1000+

Our contest is centered around 3 major goals:

●Break Appsulate Sandbox and compromise it’s security
●Ability to exfiltrate information from given websites
outside of Appsulate
●Ability to bypass authentication and access a
shielded application from an untrusted endpoint

© 2018 Appsulate, Inc.
THANK YOU