SlideShare a Scribd company logo
Imunify360 Webinar
Jan 11, 2016
Hosting Industry Survey revealed...
13%
19%
25%
28%
37%
45%
48%
49%
53%
61%
67%
DNS Poisoning
Information disclosure
Privilege escalation
XSS attacks and similar
Comment SPAM
Website Defacement
Code/SQL Injections
Brute force attacks
Remote exploit
Malware infection
DoS/DDoS
Over 60% reported customers worry about
security. Top reported issues:
The state of security in
hosting
 Distributed attacks are on the rise
○ Not only DDoS
○ Distributed brute force attacks
○ Distributed port scans
○ Distributed OS & Application
fingerprinting
○ Distributed vulnerability scans
 Existing tools are not capable to
handle
○ Single server
○ Dumb
• No history
• No behavior analytics
• No heuristics
The state of security in
hosting
 Too many sources of incidents
 Too many decisions to make
 No way to correlate
Too many decisions to make
 Centralized dashboard
 Herd protection
 Sandboxing
 Heuristics
 Machine learning
 All that without re-inventing the wheel
Imunify360
 Firewall ‒ Herd immunity
○ Machine learning
○ 17K+ IPs blocked
automatically
○ Large # of honeypots
○ Better immunity with each
additional server
Protection Vectors ‒ Firewall
 Reduce false positive
○ Use captcha to automatically unblock
○ Train AI to reduce false positives...
Firewall ‒ Protection Layers
 OSSEC for IDS
o ML to decrease false positives
IDS
 Very popular
 More features than Imunify360
 Huge expertise
We will integrate it into Imunify360
Best of both words:
 Same herd immunity
 Same captcha / training
 Same CSF flexibility
Firewall ‒ CSF
 Mod_security
○ OWASP
○ Comodo
○ Atomic
 Herd immunity → Feeds into
correlation engine → firewall
○ Machine learning
○ Most attacks will not reach WAF, will be
blocked at firewall
WAF ‒ Protection Layers
 Maldet protection scanning
○ Automated scans
○ On upload scans
• PHP
o Attack IP detection (ext attributes)
• FTP
• SSH
○ Backup integration / automated
recovery of infected files
Malware scanning ‒
Protection Vectors
 Patch management
○ KernelCare
• Kernel
• OpenSSL (soon)
• GLIBC (soon)
○ HardenedPHP
○ Security configuration / RPM
version scans
Patch Management ‒
Protection Layers
 Covered by WAF
 Covered by Softaculous
 Covered by Patchman
 Main issues:
o plugins, not web apps
o 0-day vulnerabilities
Outdated web apps?
Reliance on knowing more than attacker
Limit what webapps can do:
 Today webapps can do whatever unprivileged linux user can do
○ Does wordpress need to be able same things as strange, gcc or name server?
○ Filter/limit syscalls available
○ Filter/limit filesystem operations/access
Protection layer ‒ Sandboxing
Different approach
No 0-day privilege escalations
No turning a web app into a ‘bot’ part of the botnet.
 AV vendors know that signatures
don’t work
 Sandboxing & heuristics used on
desktop for 10+ years
 Not used on web servers
 Huge improvement in server
security
Sandboxing ‒ because
signatures don’t work
 Train ML on ‘good behaviors’
 Automatically detect bad
behaviors
 Lock down after training
Sandboxing Stage II:
heuristics + AI
Prevent majority of injection & defacement attacks
 Train on each site individually
 Re-train on upgrades
○ User managed lock/unlock
 Use client’s IP ‘reputation’ for
good vs bad
 Use ‘banking style’ notifications
(e-mail, sms, phone) for site
owner
Sandboxing Stage II: AI
Possible attack against yoursite.com detected
We have detected possible attack against yoursite.com
Attack originated on Jan 5, 2017 at 3:23pm from IP 2.10.100.202 (Orlando, FL, USA) [check your IP]
[+more info on the attack]
Was it you?
‘Bad Action’ Notifications
YES, ALLOW THIS ACTION NO, BLOCK THE ACTION
 Is your IP on any of the
blacklists
○ SPAM
○ Botnet
 Is any of hosted domains on
the blacklists:
○ Malware
○ Phishing
○ SPAM
Reputation management
Why is that important?
Configurable
 Use all related info to detect attacks
 Use machine learning to correlate
information
 Use multiple layers to detect, and defend
against the attacker
 Minimize human involvement
○ Minimize decision making
360° defense
Imunify360 Imunify Sensor
Maximum security with sophisticated attack
detection
Basic security with lightweight attack
detection
Centralized Incident Management
dashboard
Firewall Advanced Firewall with herd immunity Standard Firewall
Smart Intrusion Detection System
IDS/IPS
Patch management
Intelligent Web application sandboxing
KernelCare
HardenedPHP
Complete feature comparison at imunify360.com
Imunify360 vs Imunify Sensor
 Dedicated / VPS
 Shared
 cPanel
 DirectAdmin
 Plesk
Good For Web Servers
Goal: zero
configuration, good
for novice, better
than expert...
Pricing
Imunify360
Retail: $35/month
Service Provider: $9/month
Imunify Sensor
Retail: $9/month
Service Provider: $2/month
Keeping web servers safe and profitable with Imunify360
Resources:
 Imunify360.com
 Imunify360 vs Imunify Sensor:http://www.imunify360.com/web-server-
security-comparison
 Survey: https://www.cloudlinux.com/images/content/resources/Hosting-
Industry-Survey-Results-2016.pdf
Questions?

More Related Content

PPTX
Apache geode
PDF
Run Cloud Native MySQL NDB Cluster in Kubernetes
PDF
ヤフーを支えるフラッシュストレージ
PDF
PostgreSQLの冗長化について
PDF
しばちょう先生による特別講義! RMANバックアップの運用と高速化チューニング
PDF
Load Sharing Internet with MikroTik.pdf
PDF
水素原子に対するSchrödinger方程式の数値解法
PDF
Build a High Available NFS Cluster Based on CephFS - Shangzhong Zhu
Apache geode
Run Cloud Native MySQL NDB Cluster in Kubernetes
ヤフーを支えるフラッシュストレージ
PostgreSQLの冗長化について
しばちょう先生による特別講義! RMANバックアップの運用と高速化チューニング
Load Sharing Internet with MikroTik.pdf
水素原子に対するSchrödinger方程式の数値解法
Build a High Available NFS Cluster Based on CephFS - Shangzhong Zhu

What's hot (20)

PPTX
Linked Dataの基本原則 -LODを公開するときに知っておきたい基本技術-
PPTX
No data loss pipeline with apache kafka
PDF
PGConf APAC 2018 - PostgreSQL HA with Pgpool-II and whats been happening in P...
KEY
IPsecについて
PDF
nginxの紹介
PDF
Cisco ACI: A New Approach to Software Defined Networking
PDF
Galera explained 3
PDF
Oracle Integration Cloud Process Automation概要資料(20200507版)
PDF
[dbts-2014-tokyo] 目指せExadata!! Oracle DB高速化を目指した構成
PDF
Oracle運用Tips大放出! ~ RAC環境のRMANのパラレル化を極める 編 ~ @2016-02-23 JPOUG
PPTX
Pub/Sub Messaging
PDF
"Changing Role of the DBA" Skills to Have, to Obtain & to Nurture - Updated 2...
PDF
MySQL InnoDB Clusterによる高可用性構成(DB Tech Showcase 2017)
PDF
Mikrotik metarouter
PDF
MongoDB Configパラメータ解説
PDF
Data Pipelines with Apache Kafka
PDF
ODA Backup Restore Utility & ODA Rescue Live Disk
PDF
Oracle Cloud Infrastructure:2022年1月度サービス・アップデート
PPTX
Apache kafka
PPTX
Moving Gigantic Files Into and Out of the Alfresco Repository
Linked Dataの基本原則 -LODを公開するときに知っておきたい基本技術-
No data loss pipeline with apache kafka
PGConf APAC 2018 - PostgreSQL HA with Pgpool-II and whats been happening in P...
IPsecについて
nginxの紹介
Cisco ACI: A New Approach to Software Defined Networking
Galera explained 3
Oracle Integration Cloud Process Automation概要資料(20200507版)
[dbts-2014-tokyo] 目指せExadata!! Oracle DB高速化を目指した構成
Oracle運用Tips大放出! ~ RAC環境のRMANのパラレル化を極める 編 ~ @2016-02-23 JPOUG
Pub/Sub Messaging
"Changing Role of the DBA" Skills to Have, to Obtain & to Nurture - Updated 2...
MySQL InnoDB Clusterによる高可用性構成(DB Tech Showcase 2017)
Mikrotik metarouter
MongoDB Configパラメータ解説
Data Pipelines with Apache Kafka
ODA Backup Restore Utility & ODA Rescue Live Disk
Oracle Cloud Infrastructure:2022年1月度サービス・アップデート
Apache kafka
Moving Gigantic Files Into and Out of the Alfresco Repository
Ad

Similar to Keeping web servers safe and profitable with Imunify360 (20)

PPTX
Securing Your Business
PDF
Openbar Leuven // Top 5 focus areas in cyber security linked to you digital t...
PPTX
A Closer Look at Isolation: Hype or Next Gen Security?
PDF
PPTX
Bitglass Webinar - 5 Cloud Security Best Practices for 2018
PPTX
Security O365 Using AI-based Advanced Threat Protection
PPTX
Make Every Spin Count: Putting the Security Odds in Your Favor
PDF
Cisco Security Presentation
PDF
Cyberattacks on the Rise: Is Your Nonprofit Prepared?
PPTX
Operational Security Intelligence
PPTX
Anatomy of an Attack - Sophos Day Belux 2014
PDF
Wfh security risks - Ed Adams, President, Security Innovation
PDF
Cybersecurity Concerns You Should be Thinking About
PPTX
information security awareness course
PDF
Realities of Security in the Cloud
PPT
Anton Chuvakin on Threat and Vulnerability Intelligence
PPT
Active Testing
Securing Your Business
Openbar Leuven // Top 5 focus areas in cyber security linked to you digital t...
A Closer Look at Isolation: Hype or Next Gen Security?
Bitglass Webinar - 5 Cloud Security Best Practices for 2018
Security O365 Using AI-based Advanced Threat Protection
Make Every Spin Count: Putting the Security Odds in Your Favor
Cisco Security Presentation
Cyberattacks on the Rise: Is Your Nonprofit Prepared?
Operational Security Intelligence
Anatomy of an Attack - Sophos Day Belux 2014
Wfh security risks - Ed Adams, President, Security Innovation
Cybersecurity Concerns You Should be Thinking About
information security awareness course
Realities of Security in the Cloud
Anton Chuvakin on Threat and Vulnerability Intelligence
Active Testing
Ad

More from CloudLinux (6)

PPTX
LVE Manager's New UI
PPTX
How lve stats2 works for you and your customers
PDF
Single tenant software to multi-tenant SaaS using K8S
PPTX
How to deploy KuberDock hassle-free
PPTX
How to optimize CloudLinux OS limits
PPTX
Supercharging your PHP pages with mod_lsapi in CloudLinux OS
LVE Manager's New UI
How lve stats2 works for you and your customers
Single tenant software to multi-tenant SaaS using K8S
How to deploy KuberDock hassle-free
How to optimize CloudLinux OS limits
Supercharging your PHP pages with mod_lsapi in CloudLinux OS

Recently uploaded (20)

PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
A Presentation on Artificial Intelligence
PPTX
Tartificialntelligence_presentation.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Getting Started with Data Integration: FME Form 101
PDF
Empathic Computing: Creating Shared Understanding
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
cuic standard and advanced reporting.pdf
PPTX
Machine Learning_overview_presentation.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Machine learning based COVID-19 study performance prediction
Digital-Transformation-Roadmap-for-Companies.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
A Presentation on Artificial Intelligence
Tartificialntelligence_presentation.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
SOPHOS-XG Firewall Administrator PPT.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Getting Started with Data Integration: FME Form 101
Empathic Computing: Creating Shared Understanding
A comparative analysis of optical character recognition models for extracting...
cuic standard and advanced reporting.pdf
Machine Learning_overview_presentation.pptx
Electronic commerce courselecture one. Pdf
Group 1 Presentation -Planning and Decision Making .pptx
Network Security Unit 5.pdf for BCA BBA.

Keeping web servers safe and profitable with Imunify360

  • 2. Hosting Industry Survey revealed... 13% 19% 25% 28% 37% 45% 48% 49% 53% 61% 67% DNS Poisoning Information disclosure Privilege escalation XSS attacks and similar Comment SPAM Website Defacement Code/SQL Injections Brute force attacks Remote exploit Malware infection DoS/DDoS Over 60% reported customers worry about security. Top reported issues:
  • 3. The state of security in hosting  Distributed attacks are on the rise ○ Not only DDoS ○ Distributed brute force attacks ○ Distributed port scans ○ Distributed OS & Application fingerprinting ○ Distributed vulnerability scans
  • 4.  Existing tools are not capable to handle ○ Single server ○ Dumb • No history • No behavior analytics • No heuristics The state of security in hosting
  • 5.  Too many sources of incidents  Too many decisions to make  No way to correlate Too many decisions to make
  • 6.  Centralized dashboard  Herd protection  Sandboxing  Heuristics  Machine learning  All that without re-inventing the wheel Imunify360
  • 7.  Firewall ‒ Herd immunity ○ Machine learning ○ 17K+ IPs blocked automatically ○ Large # of honeypots ○ Better immunity with each additional server Protection Vectors ‒ Firewall
  • 8.  Reduce false positive ○ Use captcha to automatically unblock ○ Train AI to reduce false positives... Firewall ‒ Protection Layers
  • 9.  OSSEC for IDS o ML to decrease false positives IDS
  • 10.  Very popular  More features than Imunify360  Huge expertise We will integrate it into Imunify360 Best of both words:  Same herd immunity  Same captcha / training  Same CSF flexibility Firewall ‒ CSF
  • 11.  Mod_security ○ OWASP ○ Comodo ○ Atomic  Herd immunity → Feeds into correlation engine → firewall ○ Machine learning ○ Most attacks will not reach WAF, will be blocked at firewall WAF ‒ Protection Layers
  • 12.  Maldet protection scanning ○ Automated scans ○ On upload scans • PHP o Attack IP detection (ext attributes) • FTP • SSH ○ Backup integration / automated recovery of infected files Malware scanning ‒ Protection Vectors
  • 13.  Patch management ○ KernelCare • Kernel • OpenSSL (soon) • GLIBC (soon) ○ HardenedPHP ○ Security configuration / RPM version scans Patch Management ‒ Protection Layers
  • 14.  Covered by WAF  Covered by Softaculous  Covered by Patchman  Main issues: o plugins, not web apps o 0-day vulnerabilities Outdated web apps? Reliance on knowing more than attacker
  • 15. Limit what webapps can do:  Today webapps can do whatever unprivileged linux user can do ○ Does wordpress need to be able same things as strange, gcc or name server? ○ Filter/limit syscalls available ○ Filter/limit filesystem operations/access Protection layer ‒ Sandboxing Different approach No 0-day privilege escalations No turning a web app into a ‘bot’ part of the botnet.
  • 16.  AV vendors know that signatures don’t work  Sandboxing & heuristics used on desktop for 10+ years  Not used on web servers  Huge improvement in server security Sandboxing ‒ because signatures don’t work
  • 17.  Train ML on ‘good behaviors’  Automatically detect bad behaviors  Lock down after training Sandboxing Stage II: heuristics + AI Prevent majority of injection & defacement attacks
  • 18.  Train on each site individually  Re-train on upgrades ○ User managed lock/unlock  Use client’s IP ‘reputation’ for good vs bad  Use ‘banking style’ notifications (e-mail, sms, phone) for site owner Sandboxing Stage II: AI
  • 19. Possible attack against yoursite.com detected We have detected possible attack against yoursite.com Attack originated on Jan 5, 2017 at 3:23pm from IP 2.10.100.202 (Orlando, FL, USA) [check your IP] [+more info on the attack] Was it you? ‘Bad Action’ Notifications YES, ALLOW THIS ACTION NO, BLOCK THE ACTION
  • 20.  Is your IP on any of the blacklists ○ SPAM ○ Botnet  Is any of hosted domains on the blacklists: ○ Malware ○ Phishing ○ SPAM Reputation management
  • 21. Why is that important?
  • 23.  Use all related info to detect attacks  Use machine learning to correlate information  Use multiple layers to detect, and defend against the attacker  Minimize human involvement ○ Minimize decision making 360° defense
  • 24. Imunify360 Imunify Sensor Maximum security with sophisticated attack detection Basic security with lightweight attack detection Centralized Incident Management dashboard Firewall Advanced Firewall with herd immunity Standard Firewall Smart Intrusion Detection System IDS/IPS Patch management Intelligent Web application sandboxing KernelCare HardenedPHP Complete feature comparison at imunify360.com Imunify360 vs Imunify Sensor
  • 25.  Dedicated / VPS  Shared  cPanel  DirectAdmin  Plesk Good For Web Servers Goal: zero configuration, good for novice, better than expert...
  • 26. Pricing Imunify360 Retail: $35/month Service Provider: $9/month Imunify Sensor Retail: $9/month Service Provider: $2/month
  • 28. Resources:  Imunify360.com  Imunify360 vs Imunify Sensor:http://www.imunify360.com/web-server- security-comparison  Survey: https://www.cloudlinux.com/images/content/resources/Hosting- Industry-Survey-Results-2016.pdf Questions?