Skip Links

Network World

  • Social Web 
  • Email 
  • Close

MI5 attacks botnets

Secure Web gateway discovers, blocks bot activity
By Tim Greene , Network World , 06/21/2007

MI5 Networks is adding botnet protection to its secure Web gateway appliance, making it possible to detect and block the malicious activity of corporate machines commandeered as launch pads for spam and distributed denial-of-service attacks.

Webgate 3.0 software includes MI5’s homegrown antibot software and gives customers the option to buy URL filtering, antivirus and antispyware as well.

Webgate appliances can also deploy agents to infected machines that automatically clean them of spyware.

These devices fall into the category of secure Web gateways and compete against gear made by Blue Coat Systems, Secure Computing, IronPort and WebSense, among others, says Peter Firstbrook, an analyst with Gartner.

The gateways perform URL filtering, neutralize malware and control peer-to-peer applications, Firstbrook says, and he credits MI5 as delivering a high speed, high capacity hardware platform compared to competitors.

The devices can be deployed inline to block malicious traffic or out of band from a switch monitoring port where they can block traffic via TCP resets.

The antibotnet technology combines signature matching with behavioral activity to identify machines that seem to have been taken over for use in botnets. This may include known botnet command and control signaling, extensive port scanning and attempts to generate floods of traffic to single IP addresses.

The new software release supports options to buy URL, virus and spyware filtering software and update services. MI5 teams up with IBM for URL filtering, with Sophos for antivirus and with Sunbelt Software for antispyware software.

MI5 sells its Webgate appliances in five different models based on throughput ranging from 25M to 1Gbps. The smallest device costs $2,500 and a year’s worth of antispyware and antibotware costs $1,000. Antivirus also costs $1,000 and URL filtering costs $2,000.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous

Join the Discussion