This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

High amount of evasions -- Are they fixed?

Hi,

 

according to the lastest NSS Labs test, the Sophos XG Firewall blocks only ~25% of threads due to the high amount of evasions.

Last year Sophos gave us the NSS Labs report for free as download and told us that the two evasions that were discovered through the NSS Labs tests have been fixed.

I would appreciate if we could get more informations about these poor test results, and if Sophos could tell us if the evasions have been fixed!

Are there countermeasures against these evasions?

 

Regards

Dwayne Parker



This thread was automatically locked due to age.
Parents
  • Hi Dwayne, the graphic and the results you've seen can be a little misleading as the actual Sophos results were strong and consistent with last year: we had an exploit block rate of 94.5% and an evasion block rate of 93.7% and a TCO (price-per-protected-Mbps) very similar to last year also.

    The evasion detections, which were part of a single class, have been addressed with a signature change that will be coming soon to all customers in a regular update.  

    The result you see on their SVM chart is due to how they weight the evasion block rate which exaggerates small differences and makes it look much worse than reality.  Rest assured XG Firewall performed well and consistent with our results last year but we are constantly enhancing protection and performance with every release and Sophos Labs is continuously monitoring and enhancing our protection every day against the latest threats.  For example, we've recently added the best tech from our next-gen Intercept X product like deep learning, exploit detection and CryptoGuard into our Sophos Sandstorm sandboxing. It’s unfortunate that these great protection features as well as APT and PUA blocking, and Synchronized Security are not part of the scope of this test.  

    Please note that we did not purchase marketing rights this year to their report so we don't have distribution rights.

    Regards,

    -Chris.

Reply
  • Hi Dwayne, the graphic and the results you've seen can be a little misleading as the actual Sophos results were strong and consistent with last year: we had an exploit block rate of 94.5% and an evasion block rate of 93.7% and a TCO (price-per-protected-Mbps) very similar to last year also.

    The evasion detections, which were part of a single class, have been addressed with a signature change that will be coming soon to all customers in a regular update.  

    The result you see on their SVM chart is due to how they weight the evasion block rate which exaggerates small differences and makes it look much worse than reality.  Rest assured XG Firewall performed well and consistent with our results last year but we are constantly enhancing protection and performance with every release and Sophos Labs is continuously monitoring and enhancing our protection every day against the latest threats.  For example, we've recently added the best tech from our next-gen Intercept X product like deep learning, exploit detection and CryptoGuard into our Sophos Sandstorm sandboxing. It’s unfortunate that these great protection features as well as APT and PUA blocking, and Synchronized Security are not part of the scope of this test.  

    Please note that we did not purchase marketing rights this year to their report so we don't have distribution rights.

    Regards,

    -Chris.

Children