Setting and enforcing security policy on your network endpoints could be key to making it through your next compliance audit. In our Clear Choice Test of endpoint security products that provide policy enforcement mechanisms, each product was required to identify systems out of policy compliance and take action to remediate that condition.
On a more complex level, we created a wish list of policy enforcement checks the products should offer, including being able to identify missing operating system and application patches and noncompliant system security settings, limiting access to these systems and creating reports to analyze noncompliant clients and the remediation actions taken to get them back in line. (See “How we did it”. )
Beyond the basics of policy-based end point security
Keeping endpoint security secure
Radio: Behind the scenes of our test
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter
We made this wish list with the understanding that no one product would meet all of our requirements, but were open to vendors submitting product combinations that collectively did.
Because no security product added to a corporate network should pose a security risk, we also tried to poke holes in the products’ own security architecture (see story ).
From a field of 13 vendors invited to participate in the test, Check Point, Cisco , Citadel, InfoExpress, Senforce, Trend Micro and Vernier Networks (in cooperation with PatchLink) agreed to let their products be tested. Elemental Security, EndForce, McAfee, Sygate, SecureWave and StillSecure declined. The Vernier Networks/PatchLink combination came out on top because of its sound performance in all categories. This joint submission excelled in remediation, providing the ability to block network access and automatically fix out-of-compliance systems, and it was among the most resilient of the packages tested.
Senforce was a close second with its strong host-centric approach, using only client software and not an additional in-line network device like many of the other products we tested. Trend Micro performed very well overall, falling down only in its ability to meet all of our policy management requirements where it could use some improved customization functionality.
Citadel is a strong product but needs more focus in the compliance arena, which the company says it has built into Version 4.0, which began shipping after we’d completed testing. Cisco performed well from a technical standpoint but could use improvement in reporting and overall usability. Check Point is a solid performer but needs improvements in reporting and support for more detailed custom policy checks.
Similar to the results of our first round of endpoint security product testing, where we focused on products that took action when the endpoint was under attack (see here ), we also felt this time that while InfoExpress’ product has a strong technology base, its usability and documentation still needs vast improvement.
Because we had focused requirements for each product, we were unable to test all of the unique features offered by vendors that fell outside the scope of this test (see Extra Features story ).
Vernier/PatchLink
The Vernier Networks and PatchLink submission comprised the Vernier EdgeWall 7000i – an in-line device that enforces policy compliance – and the PatchLink Update Server and corresponding endpoint agent software that together facilitate compliance checks and provide the means to remediate systems.
Installation went very smoothly, especially considering we were getting two products to interoperate. We ran into only one issue with the EdgeWall 7000i relating to network address translation ( ) being enabled by default, a condition we did not need because we were using the device as a bridge. After easily disabling NAT, everything worked as expected.
The EdgeWall 7000i can do its own vulnerability checks by scanning the endpoints, but we relied primarily on the PatchLink Update Server for our testing checks. PatchLink Update includes checks for a number of anti-virus packages and all Windows security updates out of the box. For spyware detection, the EdgeWall 7000i identifies some malicious traffic – a process that let it spot the spyware we used in our testing. Additionally, PatchLink offers a spyware module that can identify spyware running on endpoint systems, but we did not test that software.
USB access can be disabled with the Vernier/PatchLink combination, and we were able to successfully block and control traffic as dictated in our application control tests with the EdgeWall 7000i product.
The PatchLink Development Kit lets you create your own custom policy and remediation packages, providing the most flexible custom check functionality of all the products we tested.
These products will enforce policy compliance checks over VPN connections, an important consideration if you have a mobile workforce. But this combination does not work if the endpoint is online but not connected to the corporate network.
Because Vernier requires that you set up multiple configuration levels – you have to set up distinct security profiles, identity profiles, connection profiles and access policies – tracking them and mapping them to one another can get confusing. A different process layout in the management GUI might make this more intuitive.
When a system comes online, it is immediately checked and can automatically be placed in a network access policy bucket. For our testing, we set up three access policies -full access for a compliant system; limited access for an out-of-compliance system that includes a line to the Internet for remediation purposes; and a restricted group for systems that did not have the PatchLink agent installed, providing a link to download and install the agent using the EdgeWall 7000i URL redirection functionality.
The PatchLink Update Server provides the ability to immediately remediate issues using the mandatory baseline configurations, while the EdgeWall 7000i covers the network enforcement component. When we brought a system online that did not have the PatchLink agent installed, we opened the browser and were redirected to the link to download and install the PatchLink agent.
Once the agent was installed and running, the missing patches and system security configurations were automatically deployed based on the mandatory baseline settings configured in the PatchLink Update Server. Once the system met the compliance requirements, it was given full access to the test environment, as expected.
Vernier/PatchLink does not provide an alerting mechanism when out-of-compliance systems come online, but it does provide a number of reporting options. Through PatchLink Update Server, you can get a complete history of remediation actions taken for a system, and the EdgeWall 7000i provides reports on the overall compliance status of systems that came online.
Senforce
Senforce Endpoint Security Suite has five main components. The Policy Distribution Service runs on a Windows server and communicates with the clients, deploying policy, and retrieving policy and log data from the distributed clients. The Management Service controls user policies, policy storage and report generation. The Policy Editor is the user interface for policy creation and management. The Client Location Assurance Service cryptographically guarantees a system is actually on the corporate network, making the system less susceptible to spoofing attacks. Finally, the comprehensive Senforce Security Client – which includes a host-based firewall program – is the agent that runs on monitored endpoints to enforce policy and control remediation processes.
We had the most difficulty with this installation process. We first attempted the distributed install but could not get the components communicating properly over SSL. We then ran the single server install but the database became corrupt and was missing critical data for the product to run. Senforce technical support did not have an explanation for this issue but helped resolve the problem quickly. after starting over a third time, we were finally able to get a clean install and move forward with our test. We did not encounter any other server operation issues once installation was completed. Documentation was adequate, but the dual-column newsletter format was difficult to follow at times when reading online.
Policies out of the box dictate how the system can check anti-virus signatures, missing patches and application control (for example, allowing or disallowing certain types of application traffic). The Senforce Security Suite successfully passed all supported policy checks in our test.
Policies can be checked over VPN connections if the product is placed in-line behind the termination point, and enforcement also works when the client is not directly connected to the corporate network. You also have the ability to create custom checks via the product’s powerful scripting engine.
Policies are created in the Policy Editor, which has a great interface and was relatively intuitive. When we did run into issues, the documentation filled in the gaps quite well.
We did have issues installing this client software via a network share. Because the program installs Microsoft’s Network Driver Interface Specification (NDIS) driver, the network connection is interrupted in the process. Other products that have this configuration warn you not to install the software over the network. Senforce should include a similar warning.
We refer to this as a host-centric solution to the problem we posed in this test because systems identified to be out of compliance then are controlled by the firewall on the agent itself. (Check Point and Citadel function in a similar fashion.) This host-centric approach worked very well in our tests. However, it can cause problems if the host is attacked and the Senforce Security Client is somehow disabled or removed. In our testing, some clients were easily disabled. Even though the Senforce Security Client was not one of them, it is still an issue that should be considered. Without the client, policy checks are no longer performed. With the network device products, attackers still have an additional layer of protection to bypass.
The custom scripting capabilities provided for the policy checks and remediation measures make this product very flexible. These scripts even give you the ability to download and execute programs necessary for remediation. A system that is out of compliance can be set to block all traffic or run a custom quarantine rule set that only allows access to defined locations on the corporate network or the Internet, or within a home network.
The Security Suite does not include alerting features. Reports are viewed through a Web-based system, but you do not have the ability to export them in any manner other than saving the Web page. The default reports included are a combination of graphs and reports, but we would like to see easier customization capabilities. The reports provide a lot of information but not a centralized view of remediation history or detailed status/history of all systems.
Trend Micro
We tested the Trend Micro Network VirusWall 2500 with OfficeScan 7 Corporate Edition Anti-Virus software. VirusWall 2500 is an in-line device that will allow or deny network access as defined by the policy set on the Trend Micro device itself. Systems that attempt access are scanned for vulnerabilities (missing patches, vulnerable services) when they come online. All of these checks and balances worked as advertised in our test.
You do not have the ability to create custom policy checks with this offering nor does the compliance protection work when the endpoint is not directly connected to the corporate network. Trend Micro’s combination will work over VPNs and integrates tightly with several of the major VPN gateways for anti-virus checks.
This product was easy to set up and very intuitive to use – one of the best overall experiences we had during testing.
If a system comes online that is out of compliance, the end user can see an error and be redirected to a URL defined by the administrator when he opens a browser. One thing we would like to see is a message in the pop-up that says, “Open your browser for more information,” because the end user is not specifically directed to open the browser.
Because VirusWall 2500 and its policy enforcement capabilities are tightly integrated with OfficeScan, missing anti-virus software can be easily linked to and installed. Plus, detected viruses can be automatically removed. Other vulnerabilities, such as missing patches, must be remediated in other ways, such as through Windows Update.
Trend Micro’s reporting and alerting capabilities are the best of the products tested. We could easily set up the system to send the administrator e-mail or alerts when an out-of-compliance system came online. We could generate one-time or scheduled remediation reports to see the history of actions taken over time and export them to PDF or other file formats. We also could generate a report that showed online and offline computers with outdated components.
Cisco
Cisco submitted two products. One is Cisco Clean Access server, technology that runs on an in-line device and drives the endpoint policy compliance functions, in conjunction with Cisco Trust Agent (CTA [part of CCA]) software sitting on the client machines.
The other is Cisco Secure Agent (CSA), which comprises management server software and client-side code, a host-based agent technology that monitors the system for malicious activity.
Installation of CCA was complicated. We wanted the in-line device running in bridge mode, just passing traffic and not performing any NAT. The documentation was a bit confusing regarding this particular setup, which required that the management server reside on a different subnet. Calls to support helped us iron out these architecture issues, as well as a few smaller implementation issues we encountered.
For our policy enforcement checks, CCA could correctly identify anti-virus signatures, including default profiles for the three major anti-virus providers, and missing operating system patches. Network traffic was controlled according to our defined policies. Operating system security settings are checked via Nessus scans launched from the CCA appliance at the time the endpoint device comes online.
Custom checks, which allow for monitoring of registry keys, files and processes, can be built via the CCA management console. Overall, these custom checks were very easy to set up.
One of our policy checks was to make sure the endpoint was running the defined personal firewall program, usually achieved by making sure a certain application or process was running on the system in most of the products. Cisco supports this policy check and provides out-of-the-box policies written for the CSA agent. The use of other personal firewalls can be enforced using custom checks in CCA. However, Cisco policy check customization could be improved with the addition of a more detailed scripting engine.
This Cisco combination also can identify spyware, control USB thumb drives, and enforce more application, registry and process security, providing protection while the endpoint is on and off the corporate network.
The CCA can conveniently be used as a VPN termination point. Future releases will integrate closely with the Cisco VPN Concentrator.
Compliance is enforced by defined policies, which reside on the CCA appliance. Using the CCA management interface, you can set up a number of remediation or enforcement policies based on status such as authenticated user, unauthenticated user, vulnerabilities in scan results and failed compliance checks.
If a user is not authenticated to the network through the CCA appliance, you can limit access only to the specific areas of the network. Authenticated users then can undergo more strenuous checks and be granted wider access to network resources. The CTA software sitting on each endpoint provides access to the host, and the ability to look at files, processes and registry keys. If CCA identifies a problem, the out-of-compliance system can have an installation file uploaded to the system, receive an alert message or be sent to a URL.
The end user must manually initiate the installation of software that would bring the endpoint back into compliance. While the endpoint machine in question is waiting to be put in compliance, the server blocks all network traffic except that which is specifically allowed, such as to Windows Update to get missing security patches.
Reporting could be vastly improved in both CCA and CSA. With CCA, you can view the system logs on the server to view key events, but the system itself does not generate reports. You can view scan results and compliance check results by individual endpoint system. Failed scans can have entries sent to the CCA event log, but you cannot generate reports to show current status of all computers online, history or trends.
Citadel
Citadel’s software-based answer to our test case was to put its Hercules agents on the endpoint machines to detect vulnerabilities and use its ConnectGuard module – which has client and server components – to force remediation. The Hercules agent running on each endpoint system performs its own analysis based on vulnerability information collected by its own scan. Out-of-the-box checks include identifying if several of the major anti-virus products are running, spyware, missing patches and operating system security settings.
An appliance version of the product also began shipping with Hercules 4.0 earlier this month.
The Hercules installation went very well, and we did not encounter any issues. Documentation is excellent, and the management interface is intuitive and easy to use.
With the version of the product we tested, Citadel provides remedies for thousands of known vulnerabilities, but you also have the ability to define your own vulnerability checks and custom remediation actions in the management.
The ConnectGuard module provides the enforcement mechanism for noncompliant systems, blocking outbound traffic using the Citadel client running on the endpoint until it is configured back into compliance. In the version we tested, remediation had to occur at the time of compliance check. In Hercules Version 4.0, administrators will have the option to receive a report on a system’s compliance and schedule remediation tasks to occur at a later time.
For reporting, Hercules uses a Web-based Crystal reports engine, so you can export to numerous formats. The product contains one of the strongest reporting modules, including full remediation history and out-of-compliance status. Additional reporting functionality is expected to be added in Version 4.0. Hercules does not provide an alerting mechanism.
Check Point
Check Point’s Integrity 6.0 is a software-based offering that expanded beyond its early days as a personal firewall to encompass policy checks and enforcement mechanisms.
Installation went smoothly. We created a default install package for the client and generated our own security policy and enforcement checks. By default, Integrity includes checks for major anti-virus providers.
You also can create custom enforcement checks using the management interface to check for things such as registry keys, rogue files or disallowed processes. Missing patches and operating system updates are not covered by default, but you can add custom checks to cover them.
Application access is controlled through standard firewall rules and application control mechanisms. Spyware can be alerted on using Check Point’s SmartDefense Program Advisor service. USB checks are not supported.
All tests of supported policy checks were successful.
Integrity does provide protection when not connected to the corporate network and works over VPN connections.
Non-compliant systems can be observed, warned or restricted to connections except those explicitly allowed. Administrators can provide links to necessary files or upload files to the system to be executed by the user to remediate identified issues. In our test of these features, we were appropriately redirected to the network sites defined in our policy check. For example, we were redirected to the Windows Update site when the missing Windows patch was detected on the system.
Similar to our comments in our first round of testing, Integrity reporting could be improved. Basic reports are provided through the Web-based reporting engine but cannot be exported. You can get a report for out-of-compliance systems and can view an enforcement graph for remediation history, but not a full report. Integrity does not provide any alerting functionality.
InfoExpress
The InfoExpress CyberGatekeeper server is the central communication point of this appliance-based product, providing the policies to the CyberGatekeeper agents running on the endpoint systems and generating reports through its Web-based engine. The server handles the policy enforcement through one of the many modules the product supports, which includes LAN (puts switch ports in a remediation virtual LAN) bridge (allows/blocks traffic as defined by policy), and Extensible Authentication Protocol (authenticates users).
To create and modify policy, administrators use Policy Manager, which runs on a computer separate from the server. Administrators publish new policies to the central server for distribution to the clients. For our testing, we used the server in LAN and bridge compliance mode. Setup was straightforward as soon as we received updated documentation that matched the product, but there still were significant errors in the documentation.
The CyberGatekeeper’s primary focus is on audit and compliance checks. Unlike many of the other products we tested, this agent does not have a built-in firewall, but it is designed to be flexible and accommodating in its checks so you can run any anti-virus or host-based security protection you want in your environment.
Subsequently, it did not pass many of our host-based compliance checks, such as USB thumb drive access, spyware infection and operating system security checks (although these can be created manually). We were able to control application compliance by executable or process name.
Enforcement can be set to work over VPN connections, which works best with the server setup in bridge mode. Enforcement does not work when not connected to the network. The policy manager provides a lot of flexibility but could be more intuitive, especially the screen used to upload new policies to the server.
Once a non-compliant system is identified, a message can be displayed to the end user, he can be redirected to a URL, or the system can be placed in a different VLAN depending on which enforcement module you are running. Users can be redirected to a URL that launches a download of missing software, but the installation process is manual.
Reporting could be improved. Some basic reports are available on the Web-based reporting server, which are exportable to CSV files for offline processing. A remediation history report is not available, nor is any alerting for compliance issues. You can get a report of system status, why a system is in a deny policy state, but this is not easy to read and does not provide trending information to view status over time in a single report.
Conclusion
While most of the endpoint policy enforcement products we tested cover the basics, they still have a long way to go to become core components of a company’s security infrastructure. It will be interesting to watch these products evolve to address the expanding compliance needs and the requirement to fit into a current security and network infrastructure.
One common area we can point to is the surprising lack of alerting capabilities and the ever-present need for improved reporting techniques. These components are especially key in compliance products, as the audit trail is critical.
Additionally, many of the products also contain the ability to perform compliance checks based on file or process name. These checks easily could be bypassed with a file or process name change. We’d like to see these products be based on some sort of checksum to prevent this from occurring. We also would like to see improved end-user communications to make them aware when a system is out of compliance. Most products provide redirects within the Web browser, but this is not available if the user is accessing the network through a different application.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Consistently subpar | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Andress is president of ArcSec Technologies, a security company focusing on product reviews and analysis. She can be reached at mandy@arcsec.com. Thayer is a private network security consultant in Mountain View, Calif. He can be reached at rodney@canola-jones.com.
Andress and Thayer are also a members of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.




