
UTM or standalone proxy: what are the risks of relying on a single solution for security?
Cyber newsIn January 2019, CESIN published its corporate cybersecurity barometer, which revealed that 80% of companies had suffered a cyberattack in the previous 12 months. Cases are on the rise, and even large companies, reputed to be ultra-secure, are not immune, as demonstrated by the recent attack on Airbus, which confirmed "unauthorized access" to its computer networks, allowing hackers to access employees' professional contact details and login credentials.
Strengthening cybersecurity effectiveness is a strategic priority for the IT department.
This priority is also reinforced by the digital transformation being carried out by these same IT departments, as it encourages the emergence of new risks with the widespread use of the cloud, SaaS applications, and, above all, interconnectivity between internal and external IT systems. The Payment Services Directive (PSD2), which has been in force since September 2019, is a perfect example of this in the banking sector.
It is therefore essential to build and maintain a comprehensive web security chain within the company, effectively protecting users, the information system, and all the IT resources that comprise it, from internal or mobile workstations to connected objects. Despite this, CIOs and CISOs must contend with budget constraints that are not always in line with the increasing sophistication of the malware used and the resurgence of attack attempts.
Budgets obviously weigh heavily in the debate: we have to do as much, if not more, with less. When the question of upgrading equipment arises, it is sometimes convenient to consider replacing the standalone proxy with the filtering functions built into the UTM and firewall. At first glance, this seems more economical and easier to implement and maintain... but is it really a good idea to rely on a single solution to protect your information system?
We could also ask the question differently by wondering whether it is really reasonable to put all your eggs in one basket when it comes to cybersecurity. In any case, this is not one of the recommendations made by ANSSI, which instead advocates decentralizing the various cybersecurity processes across several machines.
UTM VS PROXY: a debate that cannot ignore the issue of performance
The performance aspect, with the increase in HTTPS internet traffic, should also be taken into account in the debate. The UTM device has more and more processing to perform, and adding SSL-TLS decryption would increase its resource consumption to the point of slowing it down, which could then affect its main function: the firewall. Moreover, the resurgence of DDOS attacks in recent months could quickly penalize it, and the rest of the operations it is supposed to manage would be further degraded. The scalability of UTM is therefore sometimes quickly limited, whereas the standalone Olfeo Proxy can be installed in virtualization, which makes it easy to increase its processing capacity without any additional licensing costs for the customer, since the price is calculated per user and not per appliance.
The standalone proxy is therefore a valuable ally for the firewall: by handling web filtering, SSL-TLS decryption, and even DNS filtering, it enhances the firewall's effectiveness. With a security architecture based on both a firewall and a standalone proxy working in complete synergy, tasks and risks associated with cyber threats are better distributed.
Discover Damien Billy's tips, pre-sales consultant at Olfeo, to strengthen your cybersecurity chain with your UTM and a standalone proxy:
For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.
The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.
For your cybersecurity strategy, this involves implementing real-time protection to distinguish legitimate network traffic from suspicious traffic that must be filtered by the DNS server, thereby ensuring optimal protection for the information system.
The Olfeo web security gateway meets this need precisely and offers several integration modes that can be implemented very quickly. This allows you to activate a DNS filtering service that will contain users and access, whether for uncontrolled or connected devices, and apply filtering rules. Thanks to the quality of the Olfeo URL database, the 2% of unknown websites are blocked at the DNS server level.
Web filtering remains one of the pillars of a cybersecurity strategy, and UTM cannot do everything (well).
Today, we can no longer be complacent about cybersecurity. Attacks are inevitable, and malware can disrupt business operations, as was the case this year for the Fleury Michon agri-food group, which was hit hard enough to have to disconnect all of its systems to prevent the threat from spreading. Web filtering and SSL-TLS decryption of HTTPS traffic, which help to better detect malicious code, are therefore essential for an effective cybersecurity strategy.
Furthermore, we must not forget the legal and liability issues associated with internet use, which are part of the challenges of web filtering. UTMs based on international categories do not offer the same level of quality as our URL database, which has been built up by a French team over the past 16 years. The result is often that the lack of precision in the categories and URLs leads to certain sites being blocked unfairly because they have been incorrectly classified by robots. With Olfeo, the Pornic town hall website or the Paris-Expo website will not be classified as pornography, and a doctor researching the male reproductive system will not be blocked. On the contrary, there are many different categories in Olfeo, and the granularity of the URLs is highly appreciated by our customers for customizing their user rules.