Why Armis
Why Armis
2. Agentless
By 2021, up to 90% of these devices will be unmanaged and IoT devices. These new
devices include everything from smart TVs, security cameras, digital assistants,
printers, and HVAC systems, to industrial control systems and PLCs, to medical
devices, and more. These devices can’t take an agent. Armis is an agentless device
security platform. This means that Armis works with all types of devices, even those
that can’t accommodate agents - while also working with traditional managed
devices, such as desktops, laptops, and servers. Because we do not use an agent,
Armis can be deployed in as little as minutes to hours, not weeks.
Growth of unmanaged devices connected to enterprise networks which can’t accommodate an agent
Beyond devices in the office, in hospitals and in manufacturing plants, the network
infrastructure is also at risk. Unmanaged devices like switches, routers, and access
points can be easily reached by a remote attacker via a technique known as DNS
rebinding. Switches, routers, and IP phones and cameras using the Cisco Discovery
Protocol were also found to be vulnerable to exploit, allowing an attack to
compromise network traffic, even breaking network segmentation. The continuous
behavioral monitoring of unmanaged devices, combined with automated threat
response and establishment of data encryption tunnels whenever possible, are the
new requirements for strong security.
5. Passive Monitoring
Traditional network discovery tools probe your network intrusively. This approach can
disrupt or even crash many kinds of devices, particularly sensitive equipment such as
medical devices or operational technology. Armis takes a completely passive
approach to monitoring devices. We won’t crash or tip over devices; and we don’t
negatively impact network performance, or your users.
Context is critical to know the correct behavioral profile of a device. These device
insights enable Armis to classify devices and detect threats with a high degree of
accuracy. Armis compares real-time device state and behavior to “known-good”
baselines for similar devices we have seen in other environments. When a device
operates outside of its baseline, Armis issues an alert or can automatically disconnect
or quarantine a device.
WHY ARMIS — ©2020 ARMIS, INC. — 6
Alerts can be triggered by a policy violation, a misconfiguration, or abnormal
behavior like inappropriate connection requests or unexpected software running on
a device. The Device Knowledgebase tracks all managed, unmanaged, and IoT
devices Armis has seen across all our customers.
COMPROMISED TABLET
Unauthorized Video Streaming
● Every conference room had a tablet to control the video system on
the guest network.
● The tablet in one conference room was streaming video and audio
● This represented a leakage of sensitive conversations.
COMPROMISED SMART TV
Smart Device Attempting to Infect Other Devices
● Boardroom was equipped with a Smart TV that had malware on it.
● Malware on the Smart TV was trying to infect nearby devices via
Bluetooth
● Monitors Bluetooth ● The Smart TV was ● The Smart TV was ● The Smart TV was
& network traffic whitelisted on the not sending out not sending out
● Correlated traffic NAC, so it let the TV anything through anything over the
and activity to onto the network. the gateway. network.
devices and ● Post-admission, NAC ● The FW cannot ● The IPS cannot see
locations. does not monitor see external external wireless
● Large amounts of behavior or external wireless connections from
WiFi wireless connections connections from devices
& Bluetooth traffic devices
detected.
● TVs were beaconing
to infect nearby
devices
About Armis
Armis is the leading agentless, enterprise-class device security platform, designed to protect organizations
from cyberthreats created by the onslaught of unmanaged and IoT devices. Fortune 1000 companies trust
our real-time and continuous protection to see and control all managed, unmanaged, un-agentable and IoT
devices – from traditional devices like laptops and smartphones to new smart devices like smart TVs,
webcams, printers, HVAC systems, industrial control systems and PLCs, medical devices and more. Armis
provides passive and unparalleled asset inventory, risk management, and detection & response. Core to
our platform is the Armis Device Knowledgebase. It is the world’s largest cloud-based, crowd-source
device behavior knowledgebase tracking 230 millions devices, and growing. Armis is headquartered in
Palo Alto California.
armis.com 20200325-1