Evaluation of the Next Generation Firewall with Breach and Attack Simulation
摘要
Cyberattacks that are becoming increasingly complex have prompted organization to implement comparably advanced levels of security control. Next-generation firewalls (NGFWs) address this issue by merging numerous security technologies onto a single platform to provide a single pane of glass into multiple areas of security functionality. Even though, implementing a Next-Generation Firewall alone does not guarantee security if systems are not validated for appropriate operation or if a developing threat avoids a tool that is operating well but was not built for that level of detection. The automated security testing approach Breach and Attack Simulation (BAS) have emerged recently with automation, continuous simulation across the entire kill chain, and more effective integration with threat intelligence for better enterprise security posture in prevention and detection. This paper aims to research the automation approach to the security testing and the evaluation to the next generation firewalls with breach and attack simulation tool, including MITRE ATT&CK framework, and scenario base testing to ensure that firewalls are truly defending the organization. The attack simulation results show that the BAS tool makes it simple to mimic a variety of complex cyberattacks, and the NGFW is effective at identifying signatures based known attacks. However, sophisticated methods such as pivoting and lateral movement can trick NGFW. The contribution of this study is to encourage the security professional and organization to test and analyze the gaps of the security posture in the dynamic changing threat landscape.