V-Secure IPS Version 7.0 adds bi-directional, behavior-based protection, taking aim at internal networks
In an effort to thwart never-before-seen attacks, anomaly-based intrusion prevention systems shun the use of signatures and instead apply fancy algorithms to distinguishing illegitimate network traffic from legitimate activity. In the case of the V-Secure IPS, those techniques include comparing the behavior of individual connections to accepted protocol standards, comparing general traffic characteristics to baselines of normal behavior, and using fuzzy logic to determine degrees of anomaly and make blocking decisions in real time.
In a recent demo at InfoWorld’s offices, V-Secure Technologies’ Avi Chesla and Lou Guia showed off the IPS’s ability to block dangerous traffic — including UDP (User Datagram Protocol) and TCP Syn floods and an IP sweep attack — while allowing legitimate traffic (Web server requests in the demo) from the same source IP. According to Chesla, the secret sauce is a “closed loop” filtering process, through which the IPS continually re-evaluates the parameters (source port, packet size, time to live, and so on) being used to block the attack. The closed loop is designed to avoid false positives and allow the IPS to dynamically adjust filters as attacks change.
The software learns normal network behavior automatically, and it adapts to changes in normal traffic over time. Administrators can set rate limits on inbound and outbound TCP, UDP, and ICMP (Internet Control Message Protocol) traffic, and they can configure security policies for the entire network and for specific hosts.
Until now, V-Secure IPS has been geared to blocking attacks at the network gateway. Version 7.0 introduces bi-directional protection and worm defenses (i.e., protection against abnormal port activity), making a case for deployment on internal LAN segments.
V-Secure IPS Version 7.0
Cost: Appliance: V-10, starts at $15,000; V-100, starts at $25,000; V-1000, starts at $40,000; NetVisor management software, starts at $3,000 per server plus $2,000 per managed device
Available: now shipping
You may be better off sticking with Win7 or Win8.1, given a wide range of Win10 trade-offs and...
Those of you who signed up for the Windows 10 upgrade but changed your mind may be able to crawl out
New sources are stepping up questions about Oracle's stewardship of the Java development platform
It’s easy to automate Windows Server configuration management with PowerShell; here’s how
This year’s flock of turkeys underpaid women and African-Americans, exposed users to fraud and...
These unusual gifts won't break the bank, and they'll surely please the geek in your life
When a user's new PC is missing a vital workflow piece that seems lost forever, a stroke of good luck...