- How to make new stuff from your piles of obsolete tech
- Why your computer sucks
- 10 recession-proof IT skills
- Juniper execs share network vision
- 9-year-old plots his fifth Microsoft certification
IronPort Systems Wednesday said it has improved its S-Series family of Web security appliances by adding filters for preventing corporate Web surfers from being victimized by botnets.
The gateway appliances make use of what IronPort calls URL Outbreak Detection and Botsite Defense to recognize a botnet "object" or an attempt by a Web page to redirect a browser to a malicious site.
"We would either block the Web page or the object itself," says Samantha Madrid, IronPort product manager. Managers can set up customizable notifications for users as alerts to let them know why a Web page was blocked, she adds. The page could be associated with either a known malware distribution site or a legitimate site that has been compromised and forced to dispense malware until it’s fixed.
IronPort, a Cisco business unit, has tracked millions of bots but because of their dynamic quality, the technique used to identify them relies
more on recognizing behavior evidenced by the Web page and the browser rather than a code signature.
"This Web Reputation analysis isn’t signature-based," Madrid says, but relies more on analyzing global Web traffic. (Compare
Secure Web gateway products.)
The S-Series Web security appliances start at $7,000.
Comments (1)
Promising solution ... and every vendor should follow itBy xmachine on March 19, 2008, 9:31 amIf every security product vendor including firewalls, IDS's, Web content filtering include a botnet-traffic prevention module, will save the Internet. Because it...
Reply | Read entire comment
View all comments