SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Access · SSE · Live

Advanced Threat Protection

Detect and block access to malicious entities. Enterprise-grade, zero-day threat intelligence feeds, curated by our engineers and operated 24/7.

Overview

Block malicious entities.

Advanced Threat Protection from Open Systems blocks malicious URLs, domains and IPs. It aggregates different threat intelligence feeds, delivering known indicators of compromise (IOCs) in real time.

ATP offers enhanced defense of your important data by adding more protection layers and high-quality, commercial intelligence feeds for zero-day threats, as an add-on to the basic threat protection already included in Secure Web Gateway, DNS Filter and Email Security.

Open Systems Advanced Threat Protection aggregating threat intelligence feeds to block malicious URLs, domains and IPs
Unified threat intelligence for web and email

Benefits.

Quickly catch threats

Commercial threat intelligence feeds designed specifically to catch zero-day threats fast.

High-quality threat intelligence

Third-party databases and feeds deliver verified malicious URLs, domains and IPs in real time.

Threat intelligence management

Our engineers curate the feeds into a first-class set covering different attack vectors.

Commercial, enterprise-grade feeds combine information from many sources to classify URLs and domains: in-house spam traps and honey pots, hosting companies and registries, law enforcement and internet governing bodies, enterprise businesses and ISPs, and independent security researchers.

How it works

Active IOC feed management.

Fast

  • Always the latest IOC information
  • Including zero-day, zero-hour and zero-minute IOCs
  • Automatically updated in the central IOC database for real-time protection

Specific

  • Granular threat information as URLs, not just IPs or domains
  • Diverse sourcing: email vendors and MTAs, DNS servers, ISPs, the security community

Reliable

  • Very low false-positive rate, even for fast-changing threats
  • Regular automated and human reviews of IOCs
  • Reporting and 24/7 support
One platform

Part of the SSE layer.

ATP strengthens Secure Web Gateway, DNS Filter and Email Security with curated zero-day feeds. It works alongside ZTNA and CASB in one managed SSE layer, on 35 years of operational baseline.

FAQ

Questions about ATP.

Isn't threat protection already included in the Secure Web Gateway?

Basic threat protection is, and so it is in the DNS filter and in email security. ATP is the add-on layer on top: commercial, enterprise-grade intelligence feeds aimed specifically at zero-day, zero-hour and zero-minute indicators, curated by our engineers. You buy it when the baseline is no longer the level of exposure you are willing to carry.

Where do the feeds come from, and why does that matter?

From many sources at once: in-house spam traps and honey pots, hosting companies and registries, law enforcement and internet governing bodies, enterprise businesses and ISPs, and independent security researchers. Diversity is the point. A single feed sees a single slice of the internet, and an attacker only has to be unknown to that one slice.

Won't more feeds mean more false positives?

That is exactly why the feeds are curated rather than merged. Our engineers manage them into one first-class set covering different attack vectors, with regular automated and human review of indicators. The design target is a very low false-positive rate even on fast-changing threats, because a web filter that blocks a legitimate supplier is a filter your users will route around.

Do you block by IP, or something more precise?

By URL where possible, not only by IP or domain. That granularity matters when the malicious content is one path on a shared host or a compromised page inside a legitimate site: blocking the whole domain would take a business tool offline, and blocking nothing would leave the path open.

How fast does a new indicator take effect?

In real time. Indicators land in the central IOC database automatically as they arrive, and enforcement follows from there across web, DNS and email. There is no scheduled update window for you to plan around, which is the whole point of a zero-hour feed.

Does ATP cover email as well as web?

Yes. The same curated intelligence strengthens the Secure Web Gateway, the DNS filter and Email Security. An indicator first seen in a phishing mail is therefore already blocked when someone clicks the link, which is the practical advantage of one platform over two products from two vendors.
Resources

Go deeper.

Leave complexity behind.

See how Open Systems runs Advanced Threat Protection and the full SASE Experience for your organization.

Contact us
Already a customerEverything you use today keeps running.