{"id":117847,"date":"2020-08-20T18:00:44","date_gmt":"2020-08-21T01:00:44","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=117847"},"modified":"2020-08-20T11:58:43","modified_gmt":"2020-08-20T18:58:43","slug":"network-advances-in-decryption","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2020\/08\/network-advances-in-decryption\/","title":{"rendered":"Advances in Decryption with PAN-OS 10.0"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">During the launch of the world\u2019s first ML-Powered NGFW with PAN-OS 10.0, we were excited to hear from thousands of customers, many of whom joined us during virtual events for questions and discussion. Some of the questions we\u2019ve received center around advances in decryption features introduced in PAN-OS 10.0, and I\u2019d like to elaborate on this particular functionality.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our customers have been using the decryption capabilities available in PAN-OS over the last 10 years, but the need for simplifying decryption has recently become even more critical. Luckily, PAN-OS 10.0 includes advances in decryption to match the growing challenges for organizations.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Increasing Encryption Raises Security Concerns<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Encrypted data has exploded to around 95% of enterprise traffic.<\/span><span style=\"font-weight: 400;\"> With increasing concerns about end-user privacy, major browsers, content providers and web developers are embracing encryption and pushing for its use on all web properties. While this is great news for the end user, here\u2019s the problem: <\/span><span style=\"font-weight: 400;\">Encryption provides confidentiality and privacy<\/span><span style=\"font-weight: 400;\">, but it does not guarantee the presence of security,<\/span><span style=\"font-weight: 400;\"> and it presents the perfect opportunity for malware to hide. It\u2019s expected that this year <\/span><a href=\"https:\/\/securityboulevard.com\/2020\/04\/keeping-up-with-encryption-in-2020\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">70% of malware will use encryption to evade security measures<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019ve been hearing from our customers that they see an order of magnitude increase in encrypted traffic, primarily driven by the adoption of public cloud and SaaS applications, which increasingly adopt HTTP\/2 over TLS and modern encryption protocols like TLS1.3. The combination of increasing encryption and the security concerns it brings has put deploying decryption projects center stage for most organizations.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">How You Can Deploy Decryption Where It\u2019s Needed<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/07\/network-ml-powered-ngfw\/\">new innovations in PAN-OS 10.0<\/a> address the importance of decryption for our customers by making it easy for you to deploy decryption where it\u2019s needed, and by delivering complete visibility into the details of all your encrypted connections<\/span><span style=\"font-weight: 400;\"> to help you implement and operationalize decryption<\/span><span style=\"font-weight: 400;\">. This visibility empowers you to roll out decryption in a safe and straightforward way that actually works. Here are some of the decryption features in PAN-OS 10.0:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Simplified implementation of decryption policies to provide comprehensive visibility.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Support for TLS 1.3 without downgrading to older insecure protocols.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Support for HTTP\/2 over TLS.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Enhanced performance boost on decryption. <\/span><span style=\"font-weight: 400;\">We\u2019ve also released a new Data Processing Card (DPC) for the PA-7000 series, which offers 33% more compute power than the 100G NPC card, enabling an even further performance boost.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The ability to leverage a variety of mechanisms such as URL categorization to prioritize what to decrypt for security criticality and privacy.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Now you can more quickly implement decryption policies to provide comprehensive visibility and prevent known and unknown threats via the NGFW. You get enhanced security and all the tools you need to overcome the obstacles and challenges posed by decryption to successfully roll out TLS decryption projects, adopt security best practices quickly, and use all the benefits offered by our Next-Generation Firewall to mitigate risks.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To see the workings of these new innovations firsthand, watch this <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/videos\/pan-os-10-0-decryption-demo\"><span style=\"font-weight: 400;\">demonstration<\/span><\/a><span style=\"font-weight: 400;\">, where Mandeep Singh Sandhu shares how you can easily:\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">- Mitigate security risks by controlling the use of legacy TLS protocols.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">- Deploy decryption using purpose-built troubleshooting and visibility capabilities.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">- Secure cloud apps that use modern versions of protocols such as TLS 1.3 and HTTP\/2.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To learn more about all the topics and questions discussed, view the full LinkedIn Live Q&amp;A session on <\/span><a href=\"https:\/\/www.linkedin.com\/video\/live\/urn:li:ugcPost:6681933905844584448\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">Intelligent Network Security<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The need for simplifying decryption has become even more critical. PAN-OS 10.0 advances decryption to match the growing challenges for organizations.<\/p>\n","protected":false},"author":663,"featured_media":117848,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6765],"tags":[5906,151,4321,758,508],"coauthors":[7108],"class_list":["post-117847","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-enterprise","tag-decryption","tag-firewalls","tag-machine-learning","tag-pan-os","tag-ssl","net_sec_category-next-generation-firewalls"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/08\/Trainyard-blog.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/117847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=117847"}],"version-history":[{"count":2,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/117847\/revisions"}],"predecessor-version":[{"id":117862,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/117847\/revisions\/117862"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/117848"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=117847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=117847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=117847"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=117847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}