Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

Cato Networks SASE Report Finds Enterprise Risk Assessment Undermined by Amazon Sidewalk; Device ID at Risk by Novel Use of Houdini Malware
  • USA - English
  • Deutschland - Deutsch
  • France - Français


News provided by

Cato Networks

17 Aug, 2021, 15:30 IDT

Share this article

Share toX

Share this article

Share toX

Dark web cloud services make spoofing device identities easier, helping attackers infiltrate companies protected by zero-trust network access (ZTNA) policies. The report also finds risk assessment compromised by Amazon Sidewalk and other consumer applications 

TEL AVIV, Israel, Aug. 17, 2021 /PRNewswire/ -- Cato Networks, the provider of the world's first SASE platform, announced today the results of its quarterly analysis of global enterprise networks. The Cato Networks SASE Threat Research Report Q2, 2021 analyzed 263 billion enterprise network flows between April and June 2021. Cato researchers showed a novel use of Houdini malware to promote the spoofing of a device. The report also documents how Amazon Sidewalk and other consumer applications operate on many enterprise networks, undermining effective risk assessment.

"Cybersecurity risk assessment is based on visibility to threats as much as visibility to what is happening in the organization's network," says Etay Maor, senior director of security strategy at Cato Networks. "With lines blurring between the home office and the corporate network - more devices and applications find their way to the organization's network but not necessarily to the organization's risk assessment."

Houdini Exploits Network Layer to Exfiltrate Device Configuration Information

For years, enterprises have relied on device identity to authenticate users. More recently, the development of ZTNA and SASE architectures called for using device ID (in addition to user identity and location) to decide user access rights to corporate resources. Spoofing device IDs has been a top priority for attackers, evolving from simple point solutions to cloud-based services. As such, device identification verification became crucial for strong user authentication.

Our research suggests that device identity spoofing threatens to become far more prevalent. Houdini is a well-known remote access trojan (RAT), but our research shows this particular use is novel. Houdini exfiltrated data within the user agent field, an approach often undetected by legacy security systems. Cato Research Labs only identified such threats by cross-correlating security and network information.

Spoofing-as-a-Service offerings, where cybercrime forums provide virtual or physical machines based on specified requirements for attackers to launch an attack. "With cybercriminals offering, a hard-to-come-by solution is now more widely available," says Maor. "The bar for launching attacks against organizations is lower -- enabling and motivating newcomers in the cybercrime field."  For additional information about Spoofing-as-a-Service and its implications, read this blog.

Amazon Sidewalk, Consumer Applications Undermine Enterprise Risk Assessment

In addition, the report found that the rapid move to work-from-home and adoption of bring-your-own-device have blurred the lines between professional and personal networks. Cato Research Labs found hundreds of thousands of Sidewalk flows, with some enterprises having hundreds of such devices. "How can you possibly assess company risk when there is no visibility to what devices and applications truly reside on the network?" asks Maor.

To read the report in full, visit https://go.catonetworks.com/Q221-SASE-Threat-Research-Report.html

About Cato Networks

Cato is the world's first SASE platform, converging SD-WAN and network security into a global, cloud-native service. Cato optimizes and secures application access for all users and locations. Using Cato, customers easily migrate from MPLS to SD-WAN, optimize connectivity to on-premises and cloud applications, enable secure branch Internet access everywhere, and seamlessly integrate cloud datacenters and mobile users into the network with a zero-trust architecture. With Cato, the network, and your business, are ready for whatever's next.

Modal title

Also from this source

Cato Networks Extends Zero Trust Access to Any Device with New Browser Extension

Cato Networks, the SASE leader, today announced the Cato Browser Extension, a lightweight onramp to the Cato SASE Cloud Platform. The extension...

Cato Networks Named to 2025 Forbes Cloud 100 for a Second Consecutive Year

Cato Networks, the SASE leader, today announced it has been named to the 2025 Forbes Cloud 100 list for a second year in a row. According to Forbes,...

More Releases From This Source

Explore

Computer & Electronics

Computer & Electronics

Networks

Networks

Networks

Networks

Telecommunications Industry

Telecommunications Industry

News Releases in Similar Topics

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2025 Cision US Inc.