About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 
 

NEWS

 
Remote workers armed with CyberArmor

By Mandy Andress, For InfoWorld Test Center
August 29, 2000


The growth of distributed networks, spurred by the need to support multiple branch offices and a rapid rise in telecommuting, has opened enterprises to more network vulnerabilities than ever before. This trend will only continue.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
The only sensible thing to do is to secure each individual system. In the past, the applications that were available to secure individual workstations were not well-suited for the enterprise environment. They lacked centralized management capabilities, required end-users to have extensive knowledge of security issues, and needed administrators to install and configure them.

A new suite from InfoExpress, CyberArmor Personal Firewall 1.1, is designed to protect the end-user system while allowing centralized policy management. The dynamic, granular security policy capabilities of CyberArmor make it a perfect fit for enterprise security, earning it a score of Very Good.

CyberArmor consists of four components: Policy Manager, CyberArmor, CyberServer, and CyberConsole. Only two of these components, Policy Manager and CyberArmor, are required for functionality, but the remaining components allow administrators to update, install and monitor the system while giving them enough warning to react to attacks or suspicious behavior. We recommend installing the additional components because they add the features and functionality that make this product ideal for the enterprise environment.

Policy Manager lets administrators create and edit security profiles, configure run-time settings for users, and create self-extracting CyberArmor installers with predefined security policies. These security policies can control network or system actions through defined profiles.

Network profiles specify what network activity is allowed in and out of the user's system, with the default policy set to allow traffic to pass through the firewall. System profiles specify which system operations can be performed on the user's system. For example, a system profile can be configured to prevent e-mail attachments with specific extensions or even specific file names from being executed, which should help prevent the spread of viruses. These policies have very granular settings, making it easy to incorporate CyberArmor in even the most complex security infrastructure.

CyberArmor is the client program installed on end-user systems. The executable is created by an administrator through the Policy Manager program. Administrators can then push automatic policy updates to systems via an HTTP server, meaning no user action is required.

Giving its notice

CyberArmor also can report suspicious activity to a server residing on the back end. When the system boots up, the application launches and runs in the background, monitoring traffic at both the application and individual packet level. CyberServer receives notifications from CyberArmor when suspicious activities occur or when routine updates have been configured by the administrator. CyberServer runs on Windows NT as a service and records notifications in a database.

CyberArmor can be configured to report only specific activity back to the CyberServer, and the communications can be encrypted. But the encryption is based only on an encryption key created by the administrator who configures the policy and must be the same key for all systems. This method of security is less than robust; it wouldn't take much for a malicious hacker to crack the code.

Additionally, allowing such notifications to be exchanged via the Internet opens another hole in the corporate firewall, thereby increasing security risks.

With these drawbacks in mind, whether or not to use CyberArmor's notification capability is a judgment call that each administrator will have to make. We would like to see an improved communication mechanism between CyberArmor and CyberServer, such as SSL (Secure Sockets Layer), in future versions, .

As administrators use Policy Manager to configure multiple security policies, CyberArmor scans these policies and detects them through administrator-defined triggers, which need to be active on the end-user's system.

The default Pre-Filter profile is always active and protects the system against numerous attacks predefined in the application. An Internet Filter, a VPN Filter, and a Corporate Network Filter can all be configured with different security settings catered specifically for the access required by each network connection.

CyberConsole allows administrators to examine the CyberServer database to see what is occurring on remote systems and to generate reports. CyberConsole reads the database and tracks which incidents administrators have processed already. This allows them to see what is occurring on end-user systems and catch attacks while they are in progress, protecting the company from the possible loss of valuable sensitive and proprietary information.

One problem we encountered in our testing of the CyberArmor suite was with services did not respond on the same port as the initial request. This tool uses a state table to track incoming and outgoing requests but only for those communications that use the initial port throughout the process, such as HTTP on port 80.

The most frequently used service with this problem is FTP. InfoExpress has included special rules for FTP servers to fix this problem, but other services, such as NetMeeting, will not work in this release. You should carefully examine what services your company uses to ensure CyberArmor will support them and will provide your end-users with the functionality they expect.

CyberArmor provides a way to secure end-user systems in a distributed environment. It is well-suited for protecting individual systems with remote access to the internal corporate network as well as for an additional layer of security systems directly connected to the corporate network. The tremendous granularity supported in security policy configuration and its ease-of-use would benefit corporate security solutions.




Return to the End-user firewall package.


Mandy Andress is chief security officer for Evant ( www.evant.net ) and president of ArcSec Technologies ( www.arcsec.com ). She can be reached at mandy@arcsec.com.



  BOTTOM LINE
CyberArmor Personal Firewall 1.1
BUSINESS CASE
InfoExpress provides an ideal solution for enforcing the corporate security policy on individual systems inside and outside the internal corporate network, helping to reduce the overall security risk associated with providing remote access to the enterprise via the Internet.

TECHNOLOGY CASE
Centralized management and reporting, granular policy control, automatic policy updates, and upcoming cross-platform support make CyberArmor a dream come true for harried IT departments.

PROS

+ Granular policy control

+ Centralized management


CONS

- No support for varying port services

- Weak security in threat-reporting mechanism


COST
CyberArmor: $49 per seat; CyberServer: $4,995 per server (includes one PolicyManager); CyberConsole: $295 per seat; Policy Manager: $995 each

PLATFORMS
CyberArmor: Windows 95/98/2000 and Windows NT, Linux (August); CyberServer: Windows 2000 and Windows NT; CyberConsole: Windows 95/98/2000 and Windows NT; PolicyManager: Windows 95/98 and Windows NT

COMPANY
InfoExpress, Inc., Mountain View, Calif.; (650) 623-0260; www.infoexpress.com


RELATED SUBJECTS

Security


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no