Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Network Associates upgrades intrusion detection software suite

Today's breaking news
Send to a friendFeedback


SANTA CLARA - Network Associates this week introduced a revamped version of its intrusion detection software suite, including the company's first tool designed to watch network traffic for what might be hacker activity.

The network agent, which initially runs on Windows NT and will later be ported to Solaris, complements the CyberCop Intrusion Protection Suite 5.0's agents for monitoring desktops and servers as well as the suite's management console.

However, Network Associates still lacks an easy way for its customers to update its intrusion detection knowledge base of known hacker and denial-of-service attacks, of which about 250 are included. Currently, the company's PGP division - which sells CyberCop - needs to completely rewrite its software each time it wants to add "attack signatures" to the knowledge base, and the company only does that every three to six months. Observers say that isn't often enough considering the rate at which new forms of attack are discovered.

"CyberCop is still half-baked," says Gartner Group security analyst John Pescatore. "Network Associates is still considerably behind Internet Security Systems and Axent Technologies in the area of [intrusion detection]."

The new edition of CyberCop is a big improvement over previous versions.

In addition to the new CyberCop Network agent software, the suite's management console has been upgraded. The console, which receives reports from the network- and host-based agents, now has a more powerful data warehouse for storing and analyzing information. The warehouse is now based on Microsoft SQL Server 7.0, whereas earlier versions used Microsoft Access.

However, the console can't yet relate events sent from CyberCop Network and the host-based agents, known as CyberCop Monitors, to determine possible connections between attacks detected in the network or on servers or PCs.

"That's something we'd like to do down the road, but we're not there yet," says Kara Stanislawczyk, product marketing manager of CyberCop Intrusion Protection Suite.

Network Associates is also cognizant of its shortcomings in the attack signature area. "The signature is hard-coded into the agent software and we have to upgrade it entirely to do updates," Stanislawczyk acknowledges. "But we are working on changing that."

Version 5.0 of CyberCop has gained some flexibility, though, by providing a way for customers to change default settings related to the 250 attack signatures. For example, CyberCop 5.0 has a default setting to alert an administrator after seeing 100 port scans (which usually signals an attacker scanning for vulnerabilities), but enables the administrator to change the default setting to 50 port scans before an alert is issued.

Network Associates is charging $4,700 for CyberCop Network for one to four servers under a two-year license. CyberCop Monitor, now available on Windows 2000 in addition to NT and Solaris, costs $102 per node for 100 nodes under a two-year license.

Skinny VirusScan

Also last week, Network Associates aired a slimmed-down version of its VirusScan antivirus software.

Developed by the company's McAfee division, the new VirusScan offering weighs in at 3M bytes, one-fifth the size of the regular edition of VirusScan. The lighter weight makes the software easier to distribute to remote desktops.

The trade-off is that the skinny VirusScan lacks some of the other's features, such as the ability to scan mail attachments before opening them (to prevent people from forwarding infected attachments).

"For remote sites, this slimmed-down version of VirusScan, which costs the same as the regular version, deals with the problem of getting the software out there because it took too long to deploy at 15 megabytes," says Ryan McGee, a McAfee product marketing manager.

Network Associates: www.nai.com

RELATED LINKS

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.