Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

8/21/2019
04:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

'Box Shield' Brings New Security Controls

New controls and threat detection capabilities built into Box aim to prevent accidental data leakage and misuse.

Box today released a new set of security controls called Box Shield that detects when data hosted by the cloud-based service is accidentally shared or misused as it travels inside and outside an organization.

The idea is to better secure cloud-based content as more businesses move data and operations to the cloud. Many employees use Box to store information and collaborate on projects. Box's goal is not to change the way people around the world use it, says chief product officer Jeetu Patel. It's to simplify security without slowing processes or interrupting employees' jobs.

"With Box Shield, enterprises will receive intelligence alerts and unlock insights into their content security with new capabilities built natively in Box, enabling them to deploy simple, effective controls and act on potential issues in minutes," Patel says of the new tools, which currently are in private beta.

Organizations can automatically or manually label files and folders and then create access policies based on those labels that adhere to one or more security controls. For example, "shared link restriction" dictates who can access shared links and whether links can be shared outside the business. "External collaborator restriction" limits external access to approved domains, or blocks it based on the content. "Download restriction" restricts the downloads of files or folders across specific applications, and "application restriction" limits which third-party and custom apps can download sensitive content from Box.

Box Shield aims to strike the delicate balance between security and user experience. Label-based controls let admins protect content from unauthorized access or sharing without interfering with employees using it.

Admins can also stay in the loop on security alerts. Box Shield sends notifications when it detects data access from suspicious locations, unusual downloads that may signify theft, or a potentially compromised account based on a rapid and unlikely change in employee location. If someone accesses a file from London and sends it from Singapore an hour later, for example, it's likely their account was compromised.

The tool integrates with several security products so contextual alerts from Box Shield can be integrated with SIEM products from Sumo Logic, AT&T Cybersecurity, and IBM, as well as cloud access security broker platforms from Symantec, McAfee, Palo Alto Networks, and Netskope.

Box Shield will be generally available in the fall.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "He's too shy to invite me out face to face!"
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15138
PUBLISHED: 2019-09-20
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
CVE-2019-6145
PUBLISHED: 2019-09-20
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs ...
CVE-2019-6649
PUBLISHED: 2019-09-20
F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
CVE-2019-6650
PUBLISHED: 2019-09-20
F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings.
CVE-2014-10396
PUBLISHED: 2019-09-20
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.