请输入您要查询的百科知识:

 

词条 Zscaler
释义

  1. History, fundraising, and valuation

  2. Technology

  3. Security-as-a-service platform

  4. Additional products

      Zscaler for Advanced Persistent Threats    Zscaler Private Access    Zscaler Next Generation Firewall    Zscaler Web Security    Zscaler Cloud Application Security    Zscaler Security Preview   Zscaler Mobile Security 

  5. Technology partnerships

  6. Global carrier adoption

  7. SSL traffic considerations

  8. References

{{advert|date=October 2016}}{{Infobox company
| name = Zscaler, Inc.
| logo =Zscaler logo.png
| type = Public
| traded_as = {{nasdaq|ZS}}
Russell 2000 Component
| area_served = Worldwide
| key_people = Jay Chaudhry, CEO
Remo Canessa, CFO[1]
Amit Sinha, CTO
Kailash, founder
Michael Sutton, CISO
| industry = Network security, computer security, Internet security
| products =
| num_employees = 950 (as of 01/31/2018) [2]
| homepage = {{URL|http://zscaler.com/}}
| foundation = {{start date and age|2008}}
| location = San Jose, California
| location_country = United States
}}

Zscaler ({{IPAc-en|ˈ|z|iː|ˌ|s|k|eɪ|l|ər}}) is a global cloud-based information security company that provides Internet security, web security, next generation firewalls, sandboxing, SSL inspection, antivirus, vulnerability management and granular control of user activity in cloud computing, mobile and Internet of things environments.[3] As of 2015, Zscaler provides automated threat forensics and dynamic malware protection against advanced cyber threats, such as advanced persistent threats and spear phishing. It provides a cloud-based approach to security as a service. Zscaler was listed on the NASDAQ on 16 March 2018.

History, fundraising, and valuation

The company was founded in 2008 by Jay Chaudhry, a serial security entrepreneur who previously founded and later sold AirDefense, CipherTrust, CoreHarbor and SecureIT,[4] and Kailash, the former chief architect of NetScaler. The company is unique among the private technology company "unicorns" in being significantly self-funded by the founder himself, is cash-flow neutral, and is on a very fast track of growth year over year.[5][6] In 2012, Zscaler raised $5 million in venture capital from Lightspeed Venture Partners plus received a strategic investment from EMC Corporation as part of a $38 million expansion round.[7] Zscaler has a reported company valuation of "well north of $1 billion."[8] On August 3, 2015, Zscaler announced a $100 million pre-IPO fundraising led by TPG Capital Growth. On September 23, 2015, Zscaler announced that the $100 MM round had been oversubscribed and has been raised to $110 million including a $25 million investment from Google Capital.[9]

Technology

Zscaler is a cloud-based information security platform delivered through what is reportedly the world's largest security cloud of more than 100 global data centers and more than 1,000 points of presence. To use Zscaler, Internet traffic from fixed locations such as branch offices or factories, roaming laptops, tablets and mobile phones and Internet of things devices is routed through Zscaler points of presence before going on to the public Internet. Localized data centers store security policies that can be pushed worldwide in seconds, following users as they travel around the globe to enforce these policies without latency.[10]

Zscaler serves as a cloud-based proxy and firewall, routing all traffic through its software to apply corporate and security policies, eliminating the time and money companies spend managing Web filtering, data leakage protection, SSL inspection, advanced threat protection and security on their own servers. Zscaler is designed to address the challenge of managing security in a world where cloud computing, mobility and the Internet of things are eroding the network perimeter.[4] Zscaler centralizes administration of users and policies on a single Web interface with a simple visualization. Zscaler can provide comprehensive user reports in nearly real-time and is constantly gathering global threat data to protect its customers.[10]

Security-as-a-service platform

Most security products have historically been point solutions deployed as hardware appliances, Zscaler is very different being a cloud-based security-for-a-service platform, that requires no on-premises and on-device hardware or software. Zscaler is a broad platform integrating for many different security applications - from web-security to next generation firewall, SSL decryption and inspection, data leakage protection, intrusion detection, and advanced threat protection, thus it can also be considered a cloud-based, carrier-grade, globally deployed unified threat management system.

Additional products

Zscaler for Advanced Persistent Threats

Zscaler for APTs provides protection from zero-day attacks and advanced persistent threats by combining proactive protection against known threats, file-based behavioral analysis and sandboxing, botnet detection and blocking, data exfiltration detection and blocking, plus security analytics such as threat intelligence feeds.[11] Zscaler for APTs consolidates the commoditized features of existing security appliances to protect, detect and remediate advanced security threats.[12] Zscaler's cloud-based sandboxing is unique in being ultimately based on a terminating proxy - this means that it can quarantine files for inspection instead of only making pass/block decisions. This prevents the "Patient 0" problem associated with sandboxing appliances like FireEye and Next Generation Firewalls like Palo Alto Networks that pass the first instance of an unrecognized new file, allow the infection to take place, and alert later if the file turns out to be malicious.

Zscaler Private Access

Zscaler Private Access, launched in 2016, is a service that enables organizations to provide access to internal applications and services while ensuring the security of their networks. It uses the global Zscaler cloud infrastructure to enable application access independent of network access. It also decouples applications from the physical network to deliver granular, per-user access to application software and services running in the internal corporate network, in a datacenter, or in a public cloud. The service is based on Zscaler's global cloud, so there is no requirement for additional hardware or forklift upgrades of existing hardware, enabling rapid and unobtrusive adoption to support business needs. This enables an enterprise to allow employees, customers and business partners to securely access internal applications without any need for code refactoring or implementing hardware.[13]

Zscaler Next Generation Firewall

Zscaler Next Generation Firewall is an application and user-aware firewall that provides visibility and control over network traffic. It is unique in being entirely cloud-based and does not require any on-premises hardware or software, making it suited for protecting branch offices, retail stores, factories, remote location, mobile devices and Internet of Things deployments. Zscaler Next Generation Firewall also includes traditional firewall capabilities such as control over network ports and protocols.

Zscaler Web Security

Zscaler Web Security is a secure web gateway, which also includes a web filter, that runs on top of the Zscaler Security as a Service platform. In the Spring of 2015, both Gartner Group and Forrester Research ranked Zscaler Web Security at the upper right of their Magic Quadrant and Wave reports, respectively.

Zscaler Cloud Application Security

In 2015, Zscaler introduced Cloud Application Security capabilities designed to provide security, access management, visibility and policy-based controls over SaaS and cloud computing applications. Gartner Group is promoting the acronym CASB (cloud access security broker) to describe this category of functionality. Pure-play CASB vendors also plug into Zscaler's platform to provide additional capabilities such as shadow-IT application discovery.

Zscaler Security Preview

In 2014, Zscaler released a free HTML5-based network security testing tool called Zscaler Security Preview. Zscaler Security Preview runs a suite of automated tests that inspects an organization's network security posture from the perspective of the client device that is running the test. For example, it tests to see whether virus samples hosted on content delivery networks are blocked, it attempts to exfiltrate valid payment card and social security numbers, and it detects whether communications with servers in prohibited countries such as North Korea and Iran are blocked. The tool is useful to quickly understand whether current network security infrastructure is properly implemented and configured.

Zscaler Mobile Security

Zscaler Mobile Security extends its real-time analysis and protection to mobile devices in BYOD environments by routing mobile traffic through its global cloud.[14] Zscaler Mobile Security provides visibility into mobile application traffic, protection from web-based threats and rogue applications and policy enforcement on mobile devices.[15]

Technology partnerships

Zscaler integrates with single sign-on providers including Azure AD, RSA, Okta, OneLogin and Ping Identity to enable simplified cloud application security.[16] Zscaler integrates with mobile device management (MDM) vendors, including AirWatch and MobileIron to enhance MDM with mobile security.[17] Zscaler integrates with security information and event management (SIEM) vendors, including HPE ArcSight, IBM QRadar and Splunk, enabling data analysis, digital security forensics and compliance with industry and government regulations.[18]

Global carrier adoption

Close to 50% of Zscaler's business is touched by one of the global telephone companies. As of 2015, AT&T, Verizon, British Telecom, Orange Business Services and Swisscom are all actively reselling Zscaler as part of their networking and security services. In January 2015, Zscaler closed a nearly $10,000,000 transaction at a Global 100 manufacturing company with British Telecom. Carrier adoption of Zscaler within very large distributed enterprises is tightly tied to cloud-enabled networking, which is the elimination of traffic backhaul across Multiprotocol Label Switching networks, in which network traffic is broken out locally via commodity Internet connections to local Zscaler data centers instead of being backhauled to corporate data centers over MPLS, typically resulting in 80% to 95% reduction in MPLS traffic with commensurate reduction in wide area networking costs.

SSL traffic considerations

The Zscaler service operates by having all of the Internet traffic from its clients sent through Zscaler's network of global data centers.[19] In order to monitor or inspect secure HTTPS connections, Zscaler implements what is known as a man-in-the-middle attack to decrypt SSL traffic for users going through the Zscaler service.[20][21] When a user attempts to open an HTTPS website, Zscaler mimics the website, as the user accesses the server. In response to a CONNECT request by the web browser, the server will send Zscaler a server certificate. Zscaler will then check the validity of the cert and then create a new cert signed by Zscaler. The new cert will be sent to the Web Browser, and assuming that the user has pre-installed a company root cert, the browser will check the validity of the cert and then accept and install the cert and then will continue to access the website. If a root cert has not been installed, then the user will receive an error stating that there is a problem with the website's security certification and user will have the option to continue or not.

Since Zscaler is able to decrypt traffic, they are able to scan the content for any malicious traffic that would have otherwise come in over an encrypted channel while applying policy based on the unencrypted traffic for the user. They can also detect and block outbound attempts to exfiltrate data, such as by botnets, even when connections are encrypted by SSL. While administrators may specify which URL categories or custom domains should not be decrypted in order to ensure user privacy, cautious end-users should assume that personal browsing activity, such as email or online banking, could potentially be intercepted. Zscaler also has the option of blocking access to specific URL categories or customer domains, regardless of whether SSL decryption is enabled or not.

References

1. ^{{cite web|url=https://www.wsj.com/articles/zscaler-hires-cfo-with-ipo-experience-1486729801|title=ZScaler Hires CFO with IPO Experience|date=10 February 2017|publisher=Wall Street Journal|accessdate=22 May 2017}}
2. ^{{cite web|url=https://www.nasdaq.com/markets/ipos/company/zscaler-inc-1046093-86065|title=ZSCALER, INC. (ZS) IPO|publisher=NASDAQ|accessdate=20 Aug 2018}}
3. ^{{cite news|first=Peter|last=Stephenson|authorlink=Peter Stephenson|newspaper=SC Magazine|title=Zscaler Security Cloud|url= http://www.scmagazine.com/zscaler-security-cloud/review/3926/ | accessdate=2013-06-03}}
4. ^{{cite news|first=Brad|last=Stone|authorlink=Brad Stone (journalist)|newspaper=New York Times |title=Web Filtering Moves to the Cloud|url= http://bits.blogs.nytimes.com/2008/08/04/web-filtering-moves-to-the-cloud | accessdate=2008-08-04}}
5. ^{{cite web|url=https://www.pymnts.com/in-depth/2015/a-unicorn-is-born-zscaler-raises-100m-and-snags-a-1b-valuation/|title=A unicorn is born. Zscaler raises $100M and snags a $1B valuation|publisher=pymnts.com|date=5 Aug 2018|accessdate=20 Aug 2018}}
6. ^{{cite web|url=http://fortune.com/2015/08/03/zscaler-raises-100-million-for-cloud-security|title=Zscaler raises $100 million to pulverize security appliances|publisher=fortune.com|date=3 Aug 2018|accessdate=20 Aug 2018}}
7. ^{{cite news|first=Diana|last=Samuels|authorlink=Diana Samuels|newspaper=Silicon Valley Business Journal|title=Zscaler raises $38M for cloud security|url= http://www.bizjournals.com/sanjose/blog/2012/08/zscaler-raises-38-million-for-cloud.html | accessdate=2012-08-29}}
8. ^{{cite news|first=Quentin|last=Hardy|authorlink=Quentin Hardy|newspaper=New York Times|title=A Billion-Dollar Cloud, and Not So Exclusive|url= https://www.nytimes.com/2013/02/05/technology/growing-numbers-of-start-ups-are-worth-a-billion-dollars.html| accessdate=2013-02-04}}
9. ^{{cite news|first=Heather|last=Somerville|authorlink=Heather Somerville|newspaper=Reuters|title=Cyber security firm Zscaler closes $110 million round|url= https://www.reuters.com/article/2015/09/23/zscaler-fundraising-idUSL1N11R2JK20150923| accessdate=2015-09-23}}
10. ^{{cite news|first=Stacey|last=Higginbotham|authorlink=Stacey Higginbotham|newspaper=GigaOm|title=Zscaler finally accepts VC dollars – and gets $38M|url= http://gigaom.com/2012/08/29/zscaler-finally-accepts-vc-dollars-and-gets-38m/| accessdate=2012-09-29}}
11. ^{{cite news|first=Robert|last=Westervelt|authorlink=Rob Westervelt|newspaper=CRN|title=Zscaler’s Cloud Security Platform Has Eye on Advanced Persistent Threats|url= http://www.crn.com/news/security/240161386/zscalers-cloud-security-platform-has-eye-on-advanced-persistent-threats.htm| accessdate=2013-09-17}}
12. ^{{cite news|first=Mike|last=Lennon|newspaper=Security Week|title=Zscaler Launches Cloud-based APT Protection Solution|url= http://www.securityweek.com/zscaler-launches-cloud-based-apt-protection-solution| accessdate=2013-09-17}}
13. ^{{cite web|url=http://www.techrepublic.com/article/zscaler-wants-to-eliminate-vpns-with-cloud-based-private-access-tool/ |title=Zscaler wants to eliminate VPNs with cloud-based Private Access tool |publisher=techrepublic.com |date=2016-04-26 |accessdate=2016-04-26}}
14. ^{{cite news|first=Alan|last=Shimel|authorlink=Alan Shimel|newspaper=Network World|title=Zscaler moves mobile security beyond MDM|url= http://www.networkworld.com/community/node/83234| accessdate=2013-06-17}}
15. ^{{cite news|first=John|last=Dunn|newspaper=CIO|title=Zscaler Fixes BYOD Risk with New Mobile Traffic Cloud Filtering|url=http://www.cio.com/article/734649/Zscaler_Fixes_BYOD_Risk_with_New_Mobile_Traffic_Cloud_Filtering | accessdate=2013-06-08}}
16. ^{{cite news|first=Stefanie|last=Hoffman|authorlink=Stefanie Hoffman|newspaper=Channelnomics|title=Zscaler Boosts Cloud Security with SSO|url=http://channelnomics.com/2013/01/31/zscaler-boosts-cloud-security-sso/| accessdate=2013-01-31}}
17. ^{{cite news|first=SC|last=Magazine|authorlink=SC Magazine|newspaper=SC Magazine|title=Zscaler announces new mobile security solution|url=http://www.scmagazineuk.com/zscaler-announces-new-mobile-security-solution/article/296224/| accessdate=2013-06-04}}
18. ^{{cite news|first=Market|last=Watch|authorlink=Market Watch|newspaper=MarketWatch|title=Zscaler SIEM Integration Accelerates 'Big Data' Analysis for Security and Compliance|url=http://www.marketwatch.com/story/zscaler-siem-integration-accelerates-big-data-analysis-for-security-and-compliance-2013-09-24| accessdate=2013-09-24}}
19. ^{{cite web|url=http://www.enterprisenetworkingplanet.com/datacenter/Zscaler-Cracks-Cloud-Security-3932516.htm |title=Zscaler Cracks Cloud Security |publisher=Enterprisenetworkingplanet.com |date=2011-05-03 |accessdate=2013-10-15}}
20. ^{{cite web|url=https://www.mcnc.org/forums/ncren/web-security/z-scaler-certificate-error-messages-ipad |title=Z-SCALER CERTIFICATE ERROR MESSAGES ON IPAD |publisher=Mcnc.org |accessdate=2013-10-15}}
21. ^{{cite web|url=http://zap.zscaler.com/certinfo.php |title=ZAP - Zscaler Application Profiler |publisher=Zap.zscaler.com |date= |accessdate=2013-10-15}}
{{commons category}}

12 : Computer security software companies|Computer security companies specializing in botnets|Computer forensics|Content-control software|Companies based in San Jose, California|Technology companies based in the San Francisco Bay Area|Technology companies of the United States|Computer security companies|2008 establishments in California|Companies established in 2010|2018 initial public offerings|Companies listed on NASDAQ

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/11/17 19:14:02