| | Websense unveils solution to protect data over email, social web | |
| Announcement / Corporate February 04, 2011, 13:42 IST | |
Customer-proven TRITON solution now enabled with next-generation email security, hybrid deployment, and data loss prevention all from a single management console, single appliance and single vendor - Websense
Websense, Inc.(NASDAQ: WBSN) – In an age of borderless organizations, social media, cloud applications, WikiLeaks, tablets and smartphones – modern, blended security threats from Aurora to Zeus are slipping past standard security products unchecked. With no network perimeter or standard endpoint to secure, only Websense can secure the content itself by identifying, classifying and understanding content in all of its forms and wherever it travels so that it can be protected from attack, theft and misuse. Through this innovative approach, the Websense® TRITON™ solution is unique in its ability to remove threats and risks while enabling organizations to take advantage of rich internet applications, SaaS, social media and mobility.
The Websense TRITON solution stands in marked contrast to traditional firewall UTMs, which do not scale to solve today’s security threats, and other legacy controls like antivirus and URL filters that look only at the file and website. The TRITON solution is the first, and only, content UTM delivering uncompromising security in a consolidated appliance solution. And with the innovation delivered in this release, Websense TRITON marks the beginning of the era of the content-secure enterprise.
The new flagship offering, Websense TRITON Security Gateway Anywhere, combines Websense Web and Email Security Gateway technology, including hybrid deployment and data loss prevention (DLP), into the world’s first unified content security gateway. The TRITON gateway consolidates on-premises email and Web security on a single Websense V-Series™ appliance, complemented by cloud-based SaaS components, for ultimate efficiency and effectiveness, and DLP to prevent the loss of confidential information and aid in compliance.
The TRITON architecture is a modular system, so customers can easily and efficiently expand coverage and services as their needs grow. Included in this release, for example, and ideal for existing Websense Web Filter customers, is support for Websense Web Security on the V-Series appliance. This provides Web Filter customers with enhanced security, consolidation and expandability to other TRITON services. Modular design like this helps organizations build and adapt their TRITON solution, and delivers a platform for the future, supporting soon-to-be announced Websense Mobile DLP™ and Cloud DLP™ services.
The innovative, first of its kind TRITON gateway unites the next generation of email security into the TRITON solution. Based on more than 10 years of proven email security expertise, this revolutionary new email security incorporates enterprise-class DLP, advanced encryption and archiving for email. Unlike “lite” DLP offered by other companies, Websense TruEmail DLP™ uses Websense market-leading DLP technology to accurately identify confidential data, virtually eliminating false positives and negatives and delivering full workflow and reporting. It also benefits from TruHybrid™ deployment capabilities so that spam is filtered in the cloud before it hits customer’s networks and confidential data can be secured on premises before it leaves the network.
“Websense already leads the content security software market,” said John McCormack, president, Websense. “Everybody else is providing a portfolio of point products. Only Websense made a four-year investment to build a platform that truly unifies and consolidates Web security, email security and DLP in a way that is greater than the sum of its parts AND reduces costs.”
The unique way that the TRITON architecture unifies and consolidates security eliminates bloated duplication of systems, saving customers capex and opex. The unified elements also share intelligence with each other for the most effective protection against blended data-stealing attacks and internal threats. Through this unification, Websense TRITON dramatically lowers the total cost of ownership by 45 percent over competitive offerings.
Sharing more than 10 years of real-time intelligence gathered by the Websense ThreatSeeker™ Network and the Websense Advanced Classification Engine (ACE), the TRITON solutions are more effective at battling blended threats that have rendered traditional defenses obsolete. For example, Websense doesn’t just block Web threats in browsers, the malicious links can also be stripped from incoming emails. Also, the Websense Web solution is data aware to stop important documents from being leaked or stolen. ACE combines multiple content analysis services to identify security threats and inappropriate content that bypass traditional security technologies and it does it all in real time.
“Websense hybrid deployments give us the confidence we need as a leading pan-European operator with thousands of remote workers,” said David Rigby, IT Network Manager, P&O Ferrymasters (A Dubai World Company). “It’s all about the right access to the right data for the right people, whether on-premises or off. As a shipping and logistics company, we always have employees at customer sites, and they are entering and communicating confidential data like manifests and invoices. With Websense TRITON-based products, like their Web Security Gateway and email security, we feel confident that our systems stay clean of malware and the integrated DLP helps make sure that sensitive data stays where it should, without fear of data loss.”
“There is no question that the threat landscape is evolving at a rapid pace,” stated Michael Suby, VP of Research at Stratecast (a Division of Frost & Sullivan). “Furthermore, cyber perpetrators will readily pounce on exploitable gaps in legacy security products. What Websense is accomplishing with its TRITON architecture is providing businesses with an extensible and adaptable mechanism to fight fire with fire.”
For more information, watch this Websense TRITON video. Learn more at websense.com.
Fortinet, empresas centrada en la fabricación de appliances de seguridad de red, está observando desde hace algún tiempo cómo está cambiando la seguridad en el entorno móvil. Hablamos con Luis Miguel Cañete, Director de Canal de Fortinet Iberia, sobre la oferta de la compañía, la dificultad que entraña securizar los terminales móviles o la actitud de los usuarios antes los posibles problemas de seguridad que pueden generar los móviles. ¿Cuál la oferta de seguridad para móviles de su empresa? En Fortinet contamos con una solución específica para telefonía móvil, FortiClient Mobile. Esta solución ofrece una gran variedad de funcionalidades de seguridad diseñadas para proteger smartphones basados en plataformas Windows Mobile o Symbian. Entre sus características cabe destacar: el escaneado antivirus, firewall, protección de la agenda de direcciones del Outlook, VPN IPsec, filtrado y antispam de SMS, seguridad del móvil, y filtrado de llamadas. Asimismo dispone de actualizaciones automáticas a través del servicio de suscripción FortiGuard o del appliance FortiManager para asegurarse frente a las últimas amenazas,, a la vez que el FortiManager ofrece un control centralizado. Además, contamos con una solución VPN SSL para Apple iPhone e iPod touch (a través de una aplicación descargable de iTunes App StoreSM). Al incorporar la solución FortiMobile a una red con seguridad Fortinet dotamos de protección adicional a los usuarios móviles que acceden a los recursos de la red a través de dispositivos que se encuentran fuera del perímetro. Así, al desplegar agentes FortiMobile, nos aseguramos que estos usuarios no solo protegen sus móviles y los datos que almacenan sino que tampoco se convierten en una puerta de entrada a amenazas móviles que puedan afectar a la infraestructura corporativa. A la hora de proteger un smartphone, ¿qué es lo más complicado, la cantidad de plataformas, que estén siempre conectados, rendimiento limitado…? En los smartphones confluyen una serie de características que les convierten en dispositivos especialmente propensos a sufrir ataques. Las redes 3G al ofrecer un mayor ancho de banda y permiten acceder a una amplia gama de servicios avanzados. Esto representa una gran vía de entrada de malware ya que los usuarios no sólo utilizan las aplicaciones instaladas de fábrica. Además, la usabilidad de estos dispositivos está favoreciendo el uso de los smartphones tanto para uso personal como profesional lo que entraña otros peligros que afectan ya no sólo al usuario del dispositivo móvil sino también a la propia corporación. El mercado de telefonía móvil presenta una posición única en términos de malware en comparación con el mercado del PC. Las plataformas disponibles en PC son limitadas mientras que el número de plataformas móviles continúa creciendo: Google Android, SymbianOS, Windows Mobile, Palm. Esta amplia variedad de plataformas complica a los fabricantes a la hora de desarrollar soluciones de seguridad para ellas. Actualmente existen una amplia variedad de plataformas móviles, ¿se crearán soluciones de seguridad para todas? ¿cree que el hecho de no contar con productos de seguridad específicos afectarán al éxito de la plataforma afectada? El no contar con una solución de seguridad en nuestro móvil puede suponer un grave perjuicio para el usuario, y como indicábamos anteriormente, también para la empresa si éste lo utiliza como instrumento para acceder a la red corporativa. Es probable que el propio mercado se encargue de reducir el número de plataformas que existen en la actualidad. En este punto, el usuario valorará positivamente que su móvil se encuentre protegido por lo que es probable que opten por plataformas que cuenten con soluciones de seguridad específicas. Los fabricantes iremos adaptando nuestra oferta a las plataformas más demandadas. ¿Cree que los usuarios son conscientes de que sus móviles son una tentación para los hackers? El malware en móviles es un fenómeno todavía desconocido. La mayoría de la gente ni siquiera es consciente de su existencia y los que conocen el problema lo consideran un mal menor porque “hay muy pocos”. Sin embargo se está convirtiendo en un problema real en el que la clave reside no tanto en la cantidad como en su capacidad de propagación y el daño que provocan. Un solo virus puede infectar a cientos de miles de móviles como el caso de los gusanos CommWarrior y Yxes para Symbian. En Fortinet creemos que el uso creciente de los teléfonos inteligentes y otros dispositivos inalámbricos y los nuevos modelos de negocio que permiten, se convertirá en la mayor amenaza para la seguridad de la empresa en un futuro próximo. Los usuarios de móviles ¿cree que está dispuestos a pagar por tener seguridad en sus terminales? Es cuestión de tiempo. En el momento en que el usuario sea consciente del problema que le supone sufrir ataques de phising a través de su móvil, sea objeto de spam a través de SMS, le roben los datos personales de su agenda de contactos, etc. estará dispuesto a invertir en su propia seguridad. ¿Qué consejos daría a los usuarios de smartphones para estás más protegidos? Hay unos sencillos consejos fáciles de seguir: no abra un SMS o MMs procedente de un desconocido, no se descargue una aplicación desconocida, instale un antivirus en su móvil, no conecte su móvil a otro dispositivo que pueda estar infectado y alerte a su operador si sufre un ataque. ¿Cómo cree que evolucionará la seguridad en los móviles en los próximos años? ¿Veremos soluciones de seguridad en las tiendas con más de una licencia? En un futuro cercano, el spyware será la pesadilla de la industria móvil. Fortinet detectó un fuerte incremento de spyware para teléfonos móviles que afecta a todas las plataformas: iPhone, Symbian o Windows Mobile. Nuestro equipo de detección, FortiGuard, ha detectado una importante cantidad y variedad de malware para móviles. Y va en aumento, sobre todo con el desarrollo y la comercialización de suites dirigidas a crear spyware para móviles, productos que son vendidos por cientos o miles de dólares.
You need to manage the privileged identities for every system in your network You need to manage the privileged identities for every system in your network You have security firewalls and antivirus tools. You have role-based access controls and identity management software. You probably even have regulatory compliant applications. But how safe are the servers, storage devices, and network appliances that actually host your data? At this moment can any administrator login to your systems, read and modify records, change device settings, install new code… and more? If there's a breach, will you know who is responsible? How will you track who did what to which system, and when? Without a method for managing the privileged identities for every system in your network, you are vulnerable to all of these threats posed by unauthorised users and malicious programs. Privileged identities are accounts that hold elevated permission to access files, install and run programs, and change configuration settings. They exist on virtually every server and desktop operating system, business application, database, Web service, and network appliance in your organization. The ability to manage the accounts that allow privileged access – whether called privileged account password management (PAPM), privileged user password management (PUPM), or shared account password management (SAPM) – is a subset of the broader Identity and Access Management (IAM) category. However, conventional IAM solutions are designed to manage typical end-user account activities and cannot discover or control privileged identities. Lieberman Software frequently hear complaints that other vendors’ products: • Become slow, unresponsive, or difficult to manage when deployed on large networks; • Don’t complete password changes reliably and fail to report potentially serious error conditions; • Don’t adequately keep up with changes on the customer network, lapsing in coverage even after predictable changes occur in systems and applications; • Are sold with low up-front license fees and the promise of easy implementation, only to turn into vastly more expensive, open-ended services engagements; • Have deployments that result in higher staff workloads and simply fail to perform. • Purchases that led to years of expensive service engagements yet never delivered the agreed scope of work. Today virtually all IT staff enjoy anonymous, unaudited 24/7 access to your datacentre applications, computers and appliances through use of privileged account credentials. More IT auditors are beginning to notice that this lack of accountability has brought organisations out of compliance with key industry mandates – PCI-DSS, HIPAA and others. The hackers have also taken notice, exploiting these all-powerful and often poorly secured credentials. Many organisations seem to grasp too late that implementing a privileged identity management solution is too important a process to delegate to a rubber-stamp Request for Proposal (RFP) or a battle of vendor checkboxes. If handled correctly your implementation can help you close critical security loopholes; help make staff members accountable for actions that affect IT service and data security; and lower the cost of regulatory compliance. Yet the wrong choices too often turn into expensive shelf-ware. The truth is that privileged identity management software is not a commodity and should not be purchased based on checkboxes and up-front fees alone. Vendor claims to the contrary, not all solutions perform equally well under vastly different deployment conditions that can include: • Wide varieties of managed computers – Windows, Linux, UNIX, and mainframes along with numerous network appliance platforms, backup infrastructure, and other hardware to be secured; • Large numbers of frequently changing target systems that can be separated by slow, unreliable, or expensive WAN links; • Significant numbers of custom-designed and legacy applications that might be poorly documented and whose designs may pose significant vulnerabilities if not properly remediated; • Complex organisational structures demanding solutions with the flexibility to handle overlapping and frequently-changing lines of delegation and control. If any of these scenarios sound like your organisation, you should downplay vendors’ claims and instead focus on: • Trial deployments that encompass a test environment with a realistic sampling of your target systems, applications, and user roles; • Engaging in in-depth conversations with reference customers whose deployments realistically match the diversity and scale of your own organisation, and whose managed applications at least reasonably approximate your own; • Getting the facts from those customer references about true timeframes and back-end costs of vendor deployments so that you can budget your project accordingly. As you proceed with your evaluation be aware that many vendor checkboxes simply lie. Craftily written marketing pieces can suggest that a vendor’s capabilities with respect to one target platform, application or deployment scenario extend to all areas where they claim coverage, and salespeople often believe their organisation’s own marketing hype. Ask very explicit questions about how individual target platforms, managed applications and use case scenarios are configured and deployed. In each case was the vendor’s capability delivered out-of-the box, only through custom development, or never at all? Here is a scenario that is guaranteed to go wrong: an organisation needs to remediate its processes for managing privileged accounts following a disastrous auditor finding. The organisation has 30 years’ worth of legacy hardware and software to be secured and an ill-defined organisational structure for controlling access and managing change. Management’s goal is to purchase the lowest-cost, appliance-based solution they can find that offers a money-back guarantee and the promise to eliminate those audit failures. Management assigns a project team to develop an exhaustive RFP spreadsheet that is typically culled from various analysts’ findings. The RFP is sent to a handful of vendors with the request that they provide all information and supporting documentation in two weeks’ time. Your choice of a privileged identity management solution should start with an honest discussion among all process stakeholders including the CSO, CIO, IT administrators, and anyone else involved in the management of sensitive accounts. Your key stakeholders should be those that will suffer the most damage should the solution take too long to implement, unnecessarily add to staff workloads, or provide insufficient coverage. Define your project goals and then determine who on the team is best suited to determine if each proposed solution is really a fit. Privileged identity management requires not only the introduction of technology, but also some fundamental changes in how sensitive credentials are disclosed, changed and attributed to those who use them. Regardless of whether a solution can lower staff workloads, individuals who once enjoyed unlimited, anonymous access will probably resist being held accountable. For this reason the project is likely to succeed only with the active sponsorship of top management. Expect your vendor to provide: • A detailed, written analysis of your organisation’s business goals; • Explicit documentation of your needs with respect to systems, applications, and lines of control; • A trial evaluation of the proposed solution in a realistic test environment; • A clear statement of work that details the time and cost required to bring unsecured privileged accounts present in your target systems and applications under control. Opinion piece submitted by Phillip Lieberman, president and CEO of Lieberman Software
First email security solution with real-time analysis of embedded URLs and attachments for targeted, socially engineered attacks SAN FRANCISCO--(BUSINESS WIRE)--RSA 2011 – FireEye, Inc., the leader in next-generation Malware Protection Systems (MPS), today announced the FireEye Email Malware Protection System that stops targeted email attacks, also known as spear phishing, to prevent malware-induced network breaches and data theft. With the launch of the Email MPS, enterprises and government agencies can protect data and networks from recurring Modern Malware infections and advanced, persistent threats (APTs) that attack using malicious email content and attachments. “Using the FireEye Email MPS, we’ve been able to stop over three dozen separate spear phishing attacks over the course of two weeks” “The Email MPS represents a new generation of messaging security protecting against email attacks using malicious URLs and attachments exploiting zero-day vulnerabilities,” said Ashar Aziz, CEO, CTO and Founder of FireEye. “FireEye's integrated MPS solutions protect organizations across the Web and Email attack vectors. Customers now have the most comprehensive protection against the Modern Malware used to conduct cybercrime, cyber espionage, and cyber reconnaissance attempts.” Highly Scalable, Accurate, and Effective Spear Phishing Security FireEye’s new Email MPS features the Real-time Attachment and URL Analysis engine that evaluates emails for zero-hour malware using virtual machines that run a cross-matrix of operating systems and applications, such as various web browsers and plug-ins. This dynamic analysis enables FireEye to detect and stop spear phishing email attacks aimed at known and truly unknown OS and application vulnerabilities. With global data from the FireEye MAX Cloud Intelligence network, customers get the latest security content about malicious attachments targeting zero-day vulnerabilities, malware callback channels, and URL blacklist updates. The incorporation of real-time, dynamic analysis coupled with global security content enables customers to stop the email-borne Modern Malware infection cycle. With blended attacks using email and the Web on the increase, it is critical to have a zero-hour, signature-less malware protection engine to analyze links in email as well as file attachments, such as PDF documents, Microsoft Office® files, multi-media content, and other file formats. "Using the FireEye Email MPS, we’ve been able to stop over three dozen separate spear phishing attacks over the course of two weeks,” said an IT administrator at a defense contractor, who asked to remain anonymous. “In our case, we’ve seen no false quarantines, and by integrating with our FireEye Web MPS, we can quickly trace a zero-day Web exploit back to its spear phishing email preventing a breach and saving at least 320 hours of forensic analysis for just one of the incidents.” The FireEye Email MPS is an easy-to-deploy appliance that requires no tuning and deploys as an MTA (Message Transfer Agent), SPAN device, or as a BCC destination. The FireEye solution deploys behind existing email control points like antispam gateways. The new Email MPS family comprises the Email MPS 8000 Series for high email volume environments and the Email MPS 5000 Series for mid-to-large email volumes. Pricing and Availability The FireEye Email Malware Protection System will be available in the second quarter of 2011. Pricing begins at $54,950 for the appliance, with per seat licenses starting at $11.68 (for a 5,000 seat organization). SOCIAL MEDIA: About FireEye, Inc. FireEye, Inc. is the leader in malware protection systems and next generation network threat prevention solutions that safeguard valuable data and networks against Modern Malware infiltration and theft in commercial enterprises, higher education, and government institutions. The FireEye Malware Protection System is the industry’s first solution that completely breaks the Modern Malware infection lifecycle by stopping inbound, zero hour, targeted attacks across Web and Email attack vectors, outbound data exfiltration callbacks, and dynamically inoculating networks from future attacks through both local and global intelligence. FireEye finds and blocks the 90% of Modern Malware attacks that conventional defenses miss, at network speeds and near-zero false positive rates, delivering an extremely low security TCO. FireEye is based in Milpitas, Calif. and backed by Sequoia Capital, Norwest Venture Partners, JAFCO Ventures, DAG Ventures, Juniper Networks, and In-Q-Tel. FireEye is a trademark of FireEye, Inc. All other brands, products, or service names are or may be trademarks or service marks of their respective owners.
Contacts
Loughlin/Michaels Group Woody Mosqueda, 408-738-9148 woody@lmgpr.com or FireEye, Inc. Phillip Lin, 408-321-6300 pr@fireeye.com
|