Gigamon Precryption technology reveals concealed threat activity in the cloud

Gigamon announced a series of cybersecurity innovations to the Gigamon Deep Observability Pipeline in its latest GigaVUE 6.4 software release.

Leading the way, Gigamon Precryption technology enables IT and security organizations, for the first time with an automated solution, to gain unobscured visibility into encrypted traffic across virtual machine (VM) or container workloads to conduct advanced threat detection, investigation, and response across the hybrid cloud infrastructure – all in a highly efficient manner.

While intended for security and privacy, encryption has become a hiding place for cybercriminals, with over 93% of malware now lurking behind encryption. With this announcement, Gigamon is helping IT organizations to eliminate these blind spots by shining a spotlight on this previously concealed threat activity inside encrypted traffic, reinforcing a strong foundation for zero trust.

Undetected threats lurk in encrypted traffic

According to the recent Gigamon survey, over 70% of the 1,000 IT and security leaders surveyed admit they currently don’t inspect the encrypted data flowing across their hybrid cloud infrastructure. This presents grave business risk as encrypted data cannot be sufficiently analyzed, and malware threats cannot be detected by security and monitoring tools alone as encrypted data traverses internally, externally, or laterally across an organization.

“As our reliance on the cloud increases, being able to inspect encrypted communications is critical in keeping the United States Holocaust Memorial Museum and its assets safe and secure from threat actors,” said Michael Trofi, CISO at Trofi Security.

“With Precryption, Gigamon is 10 years ahead of the security industry with technology that detects previously concealed threat activity in a highly efficient manner that allows us to shift away from monolithic firewall architectures and complex decryption standards toward an efficient distributed model where our servers handle the processing without compromising performance. Gigamon Precryption will benefit the security industry as a whole and is a technology that organizations should closely evaluate as they migrate their operations to the cloud,” added Trofi.

Gigamon Precryption technology

Gigamon Precryption technology reveals previously concealed threat activity, including lateral movement, malware distribution, and data exfiltration inside virtual, cloud, and container applications. Its innovative approach leverages eBPF technology inside the Linux kernel to deliver plaintext visibility, capturing traffic before encryption or after decryption. No keys need to be intercepted or sniffed, and no expensive decryption is required. Moreover, Precryption technology runs independently of the application, avoiding the operational challenges of classic agent-based approaches.

“Gigamon Precryption technology addresses the critical security challenge of our ability to see into certain encrypted traffic, which has the potential to expose our multi-cloud environment and business to unseen threats,” said Michael McCann, network manager, Information Systems at Foxwoods Resort Casino. “When I realized that Gigamon Precryption eliminates the complexity of key management and enables us to detect threats with a single view, it became clear this technology will redefine our security processes and significantly advance our security posture.”

“Global enterprises are increasingly successful with unifying security logs in a security data lake, but encrypted traffic poses a real challenge,” said Omer Singer, head of cybersecurity strategy at Snowflake. “Industry advances like Gigamon Precryption technology present a compelling path for organizations to turn encrypted cloud traffic into visibility for better security and compliance across hybrid cloud infrastructure.”

Gigamon Precryption technology addresses a range of advanced security requirements and:

  • Easily enables InfoSec, Network, and CloudOps teams to gain full visibility into encrypted traffic across VM or container workloads.
  • Seamlessly works with modern encryption methods, including TLS 1.3 or TLS 1.2 with perfect-forward secrecy (PFS) enabled, and legacy encryption methods, including TLS 1.2 without PFS.
  • Fully supports organizations with sensitive personal identifiable information (PII) by masking this traffic from view to maintain data security, compliance, and governance.
  • Dramatically reduces the operational complexity associated with decryption by eliminating cumbersome private key management for key sharing, passing, and library updates.
  • Efficiently offloads TLS decryption overhead from cloud, security, and observability tools, greatly boosting their capacity and performance.

“In a recent study of large enterprise IT and security leaders, we found that an alarming 50 percent accept the risk and don’t decrypt traffic today due to technical and cost challenges,” said Christopher Steffen, VP of research at EMA. “At a time when organizations have a Zero Trust goal, it’s clear that half have no hope of achieving it. It’s time to pull visibility into encrypted traffic out of the ‘too hard, impossible, and too expensive bucket.’ With innovations like Gigamon Precryption technology, organizations can get the deep observability they need to meet evolving standards and regulatory compliance and confidently secure their hybrid cloud infrastructure.”

“As cloud adoption accelerates across an expanding number of private and public platforms, organizations must also address the escalating risks of threat activity concealed within encrypted traffic,” said Michael Dickman, CPO at Gigamon. “Until now, decrypting cloud traffic has been arduous and expensive. With Gigamon Precryption technology, we’re turning the tables on cybercriminals by bringing deep observability to encrypted traffic, allowing customers to dramatically improve their security posture across any number of clouds and workloads, without any burden on developers.”

GigaVUE 6.4 delivers security integration across infrastructure and apps

This software release also incorporates several more advanced security capabilities, including:

  • Cloud SSL decryption – extending classic on-prem decryption capabilities to a wide range of virtual and cloud platforms
  • Universal Cloud Tap (UCT) – a single, executable tap for leading platforms, extending across VMs and containers with pre-filtering at the source for maximum efficiency
  • Application Metadata Intelligence (AMI) integration – detection of vulnerabilities and suspicious activities across both managed and unmanaged hosts (e.g., IoT devices)
More about

Don't miss