Gigamon announces the availability of its new Precryption technology

Issue 7 2023 Information Security, Security Services & Risk Management

Gigamon recently announced a series of breakthrough cybersecurity innovations to the Gigamon Deep Observability Pipeline in its latest GigaVUE 6.4 software release. Gigamon Precryption technology enables IT and security organisations, for the first time with an automated solution, to gain unobscured visibility into encrypted traffic across virtual machine (VM) or container workloads, to conduct advanced threat detection, investigation, and response across the hybrid cloud infrastructure.

While intended for security and privacy, encryption has become a hiding place for cybercriminals, with over 93% of malware now lurking behind encryption. With this announcement, Gigamon is helping IT organisations eliminate these blind spots by shining a spotlight on this previously concealed threat activity inside encrypted traffic, reinforcing a strong foundation for Zero Trust.

Undetected threats in encrypted traffic

According to the recent Gigamon 2023 Hybrid Cloud Security Survey, over 70% of the 1000 IT and security leaders surveyed admit they currently do not inspect the encrypted data flowing across their hybrid cloud infrastructure. This presents grave business risk as encrypted data cannot be sufficiently analysed, and malware threats cannot be detected by security and monitoring tools alone as encrypted data traverses internally, externally, or laterally across an organisation.

Gigamon Precryption technology reveals previously concealed threat activity, including lateral movement, malware distribution, and data exfiltration inside virtual, cloud, and container applications. Its innovative approach leverages eBPF technology inside the Linux kernel to deliver plaintext visibility, capturing traffic before encryption or after decryption. No keys need to be intercepted or sniffed, and no expensive decryption is required. Moreover, Precryption technology runs independently of the application, avoiding the operational challenges of classic agent-based approaches.

“Global enterprises are increasingly successful with unifying security logs in a security data lake, but encrypted traffic poses a real challenge,” said Omer Singer, Head of Cybersecurity Strategy at Snowflake. “Industry advances like Gigamon Precryption technology present a compelling path for organisations to turn encrypted cloud traffic into visibility for better security and compliance across hybrid cloud infrastructure.”

Gigamon Precryption technology addresses a range of advanced security requirements, including:

• Easily enables InfoSec, Network, and CloudOps teams to gain full visibility into encrypted traffic across VM or container workloads.

• Seamlessly works with modern encryption methods, including TLS 1.3 or TLS 1.2 with perfect-forward secrecy (PFS) enabled, and legacy encryption methods, including TLS 1.2 without PFS.

• Fully supports organisations with sensitive personal identifiable information (PII) by masking this traffic from view to maintain data security, compliance, and governance.

• Dramatically reduces the operational complexity associated with decryption by eliminating cumbersome private key management for key sharing, passing, and library updates.

• Efficiently offloads TLS decryption overhead from cloud, security, and observability tools, greatly boosting their capacity and performance.

“In a recent study of large enterprise IT and security leaders, we found that an alarming 50% accept the risk and do not decrypt traffic today due to technical and cost challenges,” said Christopher Steffen, Vice President of Research at EMA. “At a time when organisations have a Zero Trust goal, it is clear that half have no hope of achieving it. It is time to pull visibility into encrypted traffic and out of the ‘too hard, impossible, and too expensive bucket’. With innovations like Gigamon Precryption technology, organisations can get the deep observability they need to meet evolving standards and regulatory compliance, and also confidently secure their hybrid cloud infrastructure.”

“As cloud adoption accelerates across an expanding number of private and public platforms, organisations must also address the escalating risks of threat activity concealed within encrypted traffic,” said Michael Dickman, Chief Product Officer at Gigamon. “Until now, decrypting cloud traffic has been arduous and expensive. With Gigamon Precryption technology, we are turning the tables on cybercriminals by bringing deep observability to encrypted traffic, allowing customers to dramatically improve their security posture across any number of clouds and workloads, without any burden on developers.”

Seamless security integration

The software release incorporates several more advanced security capabilities, including:

• Cloud SSL decryption – extending classic on-premises decryption capabilities to a wide range of virtual and cloud platforms.

• Universal Cloud Tap (UCT) – a single, executable tap for leading platforms, extending across VMs and containers with pre-filtering at the source for maximum efficiency.

• Application Metadata Intelligence (AMI) integration – detection of vulnerabilities and suspicious activities across both managed and unmanaged hosts (e.g., IoT devices).

Read the Gigamon 2023 Hybrid Cloud Security Survey at www.securitysa.com/*gigamon1




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Partnership addresses fire hazard mitigation
Brigit Fire (a Division of Hudaco Trading) Elvey Security Technologies Fire & Safety Security Services & Risk Management
Brigit Fire has partnered with the Elvey Group. The collaboration will see Brigit Fire distributing both the advanced C-TEC addressable fire detection systems (CAST Technology) and GreenMist lithium extinguishers.

Read more...
Fire protection for a solvent extraction plant in Africa
FS Systems Fire & Safety Security Services & Risk Management Mining (Industry)
A prominent mining site operates a state-of-the-art solvent extraction (SX) plant, integral to separating and purifying metals from ores, which pose significant fire risks, as SX processes involve highly flammable organic solvents and elevated operating temperatures.

Read more...
Taking fire safety seriously
G2 Fire Editor's Choice Fire & Safety Security Services & Risk Management
To gain insights into how fire systems must be designed, installed and maintained, SMART Security Solutions asked Nichola Allan, MD of G2 Fire, for some insights into the local fire market.

Read more...
SMARTpod talks to The Risk Management Forum
SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Videos Training & Education
SMART Security Solutions recently released its first SMARTpod podcast, discussing the upcoming Risk Management Forum Conference 2024, which will be held on 26 September 2024 at the Indaba Conference Centre in Fourways, Johannesburg.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
Get proactive with cybersecurity
Information Security
The ability to respond effectively to a cybersecurity breach is critical, but the missing piece of the puzzle is a thorough, proactive evaluation to ascertain weaknesses and identify any hidden threats.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
How to securely manage your digital footprint
Information Security Training & Education
Managing your online presence is critical to safeguarding your privacy and security. It is imperative to take a proactive approach, including using robust cybersecurity best practices.

Read more...