公式動画ピックアップ
AAPL
ADBE
ADSK
AIG
AMGN
AMZN
BABA
BAC
BL
BOX
C
CHGG
CLDR
COKE
COUP
CRM
CROX
DDOG
DELL
DIS
DOCU
DOMO
ESTC
F
FIVN
GILD
GRUB
GS
GSK
H
HD
HON
HPE
HSBC
IBM
INST
INTC
INTU
IRBT
JCOM
JNJ
JPM
LLY
LMT
M
MA
MCD
MDB
MGM
MMM
MSFT
MSI
NCR
NEM
NEWR
NFLX
NKE
NOW
NTNX
NVDA
NYT
OKTA
ORCL
PD
PG
PLAN
PS
RHT
RNG
SAP
SBUX
SHOP
SMAR
SPLK
SQ
TDOC
TEAM
TSLA
TWOU
TWTR
TXN
UA
UAL
UL
UTX
V
VEEV
VZ
WDAY
WFC
WK
WMT
WORK
YELP
ZEN
ZM
ZS
ZUO
公式動画&関連する動画 [Advanced IP Defense: Block Direct-to-IP Attacks and Malicious Infrastructure | InterSECt 2026]
Advanced IP Defense helps organizations block attacker infrastructure at the network layer using real-time IP intelligence, Zero Trust IP correlation and granular security context. Introduced with PAN-OS 12.2 Ceres, it addresses direct-to-IP command-and-control traffic, residential proxy attacks and other threats that bypass traditional DNS, URL and IP reputation controls.
Modern attackers increasingly hide inbound scanning, brute-force attacks and exploitation behind legitimate residential connections. One large-scale campaign reportedly weaponized more than 750,000 household routers and smart devices to disguise malicious activity as consumer traffic.
Attackers are also bypassing outbound DNS and URL inspection by directing compromised endpoints to connect directly to hardcoded IP addresses. Unit 42 research found that nearly one in four malware C2 sessions now use direct-to-IP connections.
In this InterSECt 2026 session, learn how Advanced IP Defense helps organizations:
• Detect command-and-control traffic that connects directly to IP addresses
• Block inbound threats operating through residential proxies and anonymizing infrastructure
• Stop direct-to-IP connections that bypass DNS and URL inspection
• Validate connection intent against DNS-resolution history
• Apply Zero Trust principles to IP-based network traffic
• Replace slow, capacity-constrained IP reputation feeds with cloud-scale intelligence
• Reduce manual blocklist maintenance and false-positive investigations
• Distinguish malicious tenants from legitimate services on shared cloud infrastructure
• Evaluate traffic using more than 40 dynamic security attributes
• Block high-risk attacker infrastructure before it reaches the environment
Traditional IP reputation feeds can take an average of 20 days to reflect newly detected threats. They are also constrained by local firewall capacity, require extensive manual maintenance and provide limited context when malicious activity shares infrastructure with legitimate services.
Advanced IP Defense replaces these static approaches with real-time, cloud-delivered intelligence. Its three foundational capabilities are:
• Real-time IP intelligence that tracks malicious infrastructure throughout the attack lifecycle
• Zero Trust IP correlation that validates connections against DNS-resolution history
• Context-rich enforcement using more than 40 security attributes
Together, these capabilities help security teams stop direct-to-IP C2 traffic, reduce exposure to malicious internet infrastructure and enforce network-layer protection with greater precision.
Explore Advanced IP Defense:
https://www.paloaltonetworks.com/network-security/advanced-ip-defense
Read how Advanced IP Defense blocks attacker infrastructure:
https://www.paloaltonetworks.com/blog/network-security/block-attacker-infrastructure-advanced-ip-defense/
Explore the technical documentation:
https://docs.paloaltonetworks.com/advanced-ip-defense/getting-started
Watch InterSECt 2026 on demand:
https://www.paloaltonetworks.com/intersect?utm_source=youtube&utm_medium=video&utm_campaign=intersect-2026&utm_content=advanced-ip-defense-deep-dive&webinar=eliminate-frontier-ai-exposure
Chapters:
00:00 Cloud-delivered threat protection and emerging gaps
00:36 How attackers circumvent network defenses
00:49 Residential proxy attacks and internet-scale scanning
01:09 The 750,000-device consumer botnet
01:41 Direct-to-IP C2 traffic bypasses DNS
02:03 23% of malware C2 traffic goes direct-to-IP
02:17 OpenClaw direct-to-IP attack example
02:34 Why URL and domain defenses miss evasive traffic
02:51 Blocking attacker infrastructure at the network layer
03:13 Three shortcomings of traditional reputation feeds
03:30 The 20-day feed delay and hardware limitations
03:52 Manual maintenance and false positives
04:15 Why static feeds lack security context
04:35 Introducing Advanced IP Defense
05:06 Real-time IP intelligence and global telemetry
05:33 Zero Trust IP and DNS validation
06:01 More than 40 dynamic security attributes
06:25 Closing the network-layer security gap
#AdvancedIPDefense #DirectToIP #NetworkSecurity
67863
11