HEAT Shield and HEAT Visibility prevent attacks from infiltrating enterprise networks and provide actionable intelligence on threats. Credit: Shutterstock Menlo Security has announced the release of HEAT Shield and HEAT Visibility, a new suite of threat prevention products designed to tackle web browser attacks. Generally available now across Menlo Security's global network, HEAT Shield and HEAT Visibility prevent attacks from infiltrating enterprise networks and provide actionable intelligence to help mitigate threats, according to the vendor. Both use AI/machine learning (ML) technology and are built upon Menlo Security's cloud-based Isolation Core, which monitors and analyzes over 400 billion web sessions annually, the firm said. Web browsers prime attack targets Evasive threats are growing as threat actors evolve how they deploy phishing and malware attacks, targeting users via web browsers. The traditional approach for web security has focused on the server side of the equation, deploying things such as web application firewalls (WAFs) for the purpose. Commonly deployed security infrastructure can be blind to actions occurring inside the browser and fall short in combating web-based attacks. Attackers have spotted that while the front door has been bolted, there's a window round the back that's been left open, and so are finding ways of exploiting that weakness. Hybrid work models and the shift to SaaS/web-based applications have made browsers a prime target for attackers who use malicious websites and file downloads to breach organizations. Findings from the Q1 2023 Watchguard Internet Security Report show phishers leveraging novel browser-based social engineering strategies to carry out attacks. Watchguard detected several common malicious domains using a web browser's notification features to do the same social engineering techniques that had once been done via pop-ups. The firm theorized that this is because browsers' relatively new notification capabilities don't have the same protections in place as for pop-ups. HEAT Shield detects, blocks attacks before they infiltrate enterprise networks HEAT Shield is built to detect and block phishing attacks before they can infiltrate the enterprise network, Menlo said in a press release. It uses AI-based techniques - including computer vision combined with URL risk scoring and analysis of the web page elements - to determine if a link being accessed is a phishing site designed to steal a user's credentials, according to the vendor. It also leverages Menlo's Isolation Core to power dynamic security policies which can be applied to users based on web session events and behavior to prevent attackers from gaining access to the endpoint. HEAT Visibility analyzes web traffic to identify evasive attacks In parallel, HEAT Visibility performs continual analysis of web traffic and applies AI/ML-powered classifiers that identify the presence of evasive attacks. This delivers actionable alerts that enable security teams to reduce mean time to detect (MTTD) and mean time to respond (MTTR) to threats that could be targeting enterprise users, Menlo said. A HEAT attack dashboard then allows customers to receive detailed threat intelligence, which can be integrated into their existing SIEM or SOC platforms, while HEAT alerts sent to SOC teams provide threat visibility to enrich threat intelligence sources and enhance/accelerate incident response capabilities, it added. The web browser is the new desktop Web browser attacks are a significant threat for modern organizations for a host of reasons, Poornima DeBolle, chief product officer and co-founder, Menlo, tells CSO. "With the growth of cloud apps, the browser is the new desktop, with users spending an average of 75% of their workday using the web browser." Given the power embedded within the browser (script execution etc.), it's a tool that threat actors can exploit to maximize the success of their attack campaigns, DeBolle says. "Web content is also an advantage to threat actors as they can use tools such as obfuscation and even CAPTCHA to prevent security solutions from analyzing the content and identifying it as malicious. They unveil the real intent only once it is inside the browser on an endpoint at which time it's too late." Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe