Features

November 2005

PRODUCT SPOTLIGHT: SECURITY

Server patch scheduling

The PatchPoint System is an in-line patch proxy for enterprise servers that instantly fixes software vulnerabilities and preserves business uptime, while eliminating the cost and operational risks associated with unscheduled security patching. The system fixes application-specific software vulnerabilities at the root cause, checking for the same conditions and applying the same corrective action as the vendor’s patch. Because PatchPoint resides in the network in front of the server, it requires zero changes to server software and does not risk disturbing the server and its applications. Enterprises can immediately secure their servers and later deploy the vendor’s patch when convenient.

Blue Lane Technologies
www.rsleads.com/511cn-314



Compliant IM services

The Barracuda IM Firewall is an all-in-one instant-messaging appliance that incorporates an instant message (IM) server with native consumer IM traffic filtering, archiving and policy-management technologies. The firewall provides the tools necessary for organizations to secure, monitor and manage all IM communication. The firewall is capable of managing and archiving all public IM traffic, as well as providing a secure internal IM server for internal, and often confidential, corporate communications. Addressing the increasing concerns surrounding IM use and compliance with laws and other industry regulations, the solution features automatic compliant IM logging and complete archiving, including date, time and full text of discussions between parties. It captures and logs all IM traffic, from the internal IM server and public IM services and networks, and provides enough space to log the maximum number of users for five years.

Barracuda Networks
www.rsleads.com/511cn-317



SSH solution

The SSH Tectia Server (M) product fully integrates the well-established secure shell protocol for IBM z/OS mainframes. The product incorporates standards-based secure file transfer protocol functionality to ensure confidentiality, integrity and authentication of critical file transfers. Versatile command-line tools and file-transfer client programs enable easy scripting of automated file transfers, such as overnight job control language batch transfers, log file gathering and database backups. When used in conjunction with SSH Tectia Connector for Windows workstations, it allows transparent tunneling of TN3270 connections, eliminating exposure of plain text passwords and securing the data while in transit. Broad platform support of SSH Tectia, which includes Windows, Unix and Linux, allows it to be used to implement secure, cross-platform connectivity in large-scale enterprise networks.

SSH Communications Security
www.rsleads.com/511cn-316



Create virtual firewalls

VPN-1 Virtual System Extension (VSX) NGX is a virtualized security gateway that provides simplified deployment and management for complex security environments. The integrated VPN/firewall solution is designed for enterprise and service provider customers, protecting multiple networks by utilizing up to 250 virtualized security gateways running on a single hardware platform. The new version has just been added to the NGX platform, a unified security architecture for Check Point’s perimeter, internal and Web security solutions. Dynamic routing maximizes the efficiency of network traffic and eliminates the need for purchasing additional networking devices to achieve end-to-end security. Enhanced application-intelligence protection adapts to new and evolving threats. The system can be managed using a single IP address, reducing management complexity and conserving network resources. A virtual system wizard and creation templates decrease deployment time and simplify the creation of a virtual system.

Check Point
www.rsleads.com/511cn-315



Voice security

The Enterprise Telephony Management System (ETM), version 5.0.1, is a voice firewall and management platform that supports H.323, SIP, T1-CAS, ISDN-PRI and analog telephony traffic. The remotely managed system enables unified, enterprise-wide visibility and control over all voice network access, usage and performance across any multivendor mix of hybrid VoIP/legacy infrastructure. The ETM platform hosts a suite of software modules providing telephony security and management capabilities, including voice application-layer protections to block TDM- and VoIP-specific attacks against telecom and data network resources, such as denial-of-service, toll fraud, service abuse, harassing calls, information theft and tampering, fax and VoIP spam, malformed VoIP packets, modem line back doors into the corporate LAN, and other unauthorized phone traffic. Management applications enable voice service performance/QoS monitoring, policy-based call recording and unified call accounting across mixed TDM and VoIP environments.

SecureLogix
www.rsleads.com/511cn-309



Intrusion defense

Dragon Intrusion Defense 7.1 provides protection for the enterprise IT infrastructure by detecting and mitigating network-borne threats, monitoring and controlling network use, and helping enforce regulatory compliance. It not only mitigates worms and denial-of-service attacks, but also defeats spyware and a wide array of other malicious activities, and helps enterprises comply with stringent data-privacy regulations. By integrating intrusion detection with broader network-management capabilities, it enables network-wide visibility and highly granular control for context in threat detection and response. Dragon’s threat-detection engine uses multiple techniques, including protocol analysis, anomaly detection and signature analysis. The system sits in-line between switches and routers, and with stealth operation is completely invisible to attackers and immune to attacks from malicious traffic.

Enterasys
www.rsleads.com/511cn-310



Secure PC ports

DeviceLock, version 5.7.2, manages end-user access to a wide range of PC equipment and ports (USB, FireWire, Wi-Fi/802.11, Bluetooth), as well as storage devices and media, including CD-ROMs, DVD-ROMs, floppies, ZIP drives, portable hard drives and virtually any kind of device using a flash memory. Access privileges can be assigned by class (e.g., all USB memory devices) or by individual device or port, such as allowing a specific user to use a particular ZIP drive on specified machines. Administrators can discretely set control privileges for IT staff members, ensuring that profiles and policies (including install, uninstall, and permission modification) are tightly controlled at the local level.

SmartLine
www.rsleads.com/511cn-311



E-mail access and control

The Corporate Edition Web Client is available with the company’s Message Server appliance that integrates e-mail routing, storage, access and management with multilayered e-mail security to block hackers, spam and virus threats. The solution enables enterprise organizations to build a secure messaging infrastructure with user-based policy control and a secure Web mail/calendar client with an easy-to-navigate interface to enable secure remote access from any browser. With user-based policy controls, administrators can ensure that users comply with both regulatory and internal policies on acceptable e-mail use.

Mirapoint
www.rsleads.com/511cn-318