OPSEC Partners
Skybox Security, Inc.
Product Version Certified: Skybox View 3.5
Certified for use with: Check Point NG, NG AI, and NGX
Product Description: The Skybox View® platform provides analytical and predictive capability, simulation, workflow management, what-if, and decision-support analysis. As a result, Skybox View can assess and manage massive quantities of data generated by network and security infrastructure point products. This data is analyzed in order to generate accurate assessments, reports and prioritized action plans.
Skybox View is an integrated Security Risk Management software platform designed to: Automate the process of risk management and security compliance Turn information overload into accurate, timely, and prioritized action plans Leverage information from across the organization to facilitate reliable decisions
The suite incorporates two IT risk management applications:
Skybox Secure
for risk assessment and mitigation planningSkybox Assure
for network security compliance, firewall auditing and change management assurance
Company Description: Skybox Security, Inc. is a privately held company founded in 2002. The company is recognized as the pioneer in quantifying security risk and automating labor-intensive threat analysis and security control assessment processes. The company's award-winning product suite, Skybox View, has driven the creation and development of the Security Risk Management (SRM) market.
Key Features and Benefits
- Automated IT Security Modeling – Skybox View builds a virtual network model by collecting configurations from network devices. The virtual model enables the user visualization of the real network and serves as a basis for access and attack simulation.
- Network Access Simulation - Based on information provided by the virtual network model, Skybox View Access Analyzer calculates network access privileges between any two given points, as determined by firewall and routing policies within the infrastructure.
- Firewall Auditing - Skybox View can automatically and non-intrusively audit firewall rulebases and compare them to internal policies and/or industry best practice standards such as NIST 800-41. Within minutes, it can uncover policy violations or errors that cause security holes and provide guidance as to how to close them.
- Network Security Policy Validation - The whole network can be audited holistically based on the virtual network model and the best practice standards (or customized policies). The user may tag areas in the network for being Internal, External, DMZ, B2B etc. and an exhaustive network access simulation will be performed to find policy violations, as well as policy metrics.
This process can save the need for auditing one firewall at a time, and enable to focus on end to end connectivity and exposure analysis. - Configuration Change Assurance - Network change requests can be monitored within Skybox View. The user may realize the changes done in the firewalls automatically and continuously, as well as analyze interactively differences in the rulebases. What-If sandbox can be used to test changes in the rulebase before deploying them.
- Attack Simulation & Vulnerability Prioritization - Skybox View conducts exhaustive, non-intrusive attack simulations against the virtual network model to measure the effectiveness of potential threats in penetrating security defenses.
The user can then focus on resolving the exposed vulnerabilities which impose risk on the most critical business applications. This enables the user to postpone or eliminate the need to fix the majority of the vulnerabilities – e.g. the ones which are not exposed to potential attackers. - Business Impact Analysis & Risk Metrics - In Skybox View, the user may map (or import) the business applications and assign business impact rules. Based on the attack simulation Risk metrics are automatically generated for every business asset, which can be presented to managers and used for prioritizing remediation efforts.
- Workflow Management - A built-in easy to use ticketing system enables to manage workflow for remediation of security problems from vulnerability to policy violations. The workflow system can be integrated with an enterprise ticketing system such as Remedy® by BMC.
- Reports & Dashboard – Skybox Secure provides executive and workflow reports for business and technical users. Reports can be customized and may be generated automatically. Skybox View Dashboard provides top to bottom view for security risk metrics via intuitive web interface.
OPSEC Integration
Skybox View utilizes OPSEC CPMI API to read the firewall and VPN configuration. This data is one of the building blocks of Skybox View virtual network model that enables customers to run access analysis and attack simulation, taking into consideration the traffic rules of the firewall (ACL, NAT etc.).
Skybox View also utilizes OPSEC LEA API in order to read activity log records and report on utilization of firewall rules and objects. Skybox View is able to highlight rules and objects that have not been used, which are candidates for clean up, as well as presenting hit counts that can be used for optimization of the firewall policy.
This technology enables the user various benefits, including firewall auditing, holistic network policy compliance and connectivity enforcement, as well as exposure based security assessment.
Additional Information
