Forefront Client Security is a time saver for busy administrators, but may not be a definitive answer for enterprise malware protection
Microsoft has rolled out a new subscription-based, Windows-centric, antimalware tool called Forefront Client Security (FCS). The company touts FCS as significant upgrade from its freely available Windows Defender program mainly due to an accompanying centralized management console.
However, FCS as a desktop malware tool is not as effective as a gateway-based tool, mobile users have to return to the office to acquire administrative changes, and it doesn’t have the sort of selective blocking capabilities offered with newer versions of competitive products.
How we did it
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter
Additionally, the FCS Security Agent code does not thwart spam or phishing attempts. In Microsoft’s ForeFront security scheme, detection of these things are handled at the gateway level with the company’s ForeFront security add-on to Exchange 2007. (See the most recent test.)
FCS Security Agent
The client-side FCS Security Agent runs as a background service on Windows 2000, Windows XP, Windows Server 2003, and Windows Vista. Daily, or on a schedule we established using the console, each agent scanned its computer in either “quick” (checking only running processes, registry, start menu and operating-system directories) or “full” (checking running processes, registry, start menu and all directories) fashion.
FCS checked e-mail attachments when we opened them but didn’t scan incoming e-mail streams for malware.
The daily scans are a supplement to FCS’ real-time examination of incoming EXE, DLL, OCX and other executable files as it hunts for spyware. When an agent detected an incoming spyware instance in our tests, the agent terminated the associated running process, deleted the spyware instance’s files and cleaned up the registry.
For rootkits (which modify the registry to cause Windows to run the spyware perpetually), the agent cleaned up what it could and signaled the operating system to finish the cleanup and removal effort the next time the machine was rebooted.
Overall, it successfully stymied 95% of the malware we threw at it, missing only such recently written malware efforts as Prorat Trojan and Torpig.b . A 95% success rate is about average for the antimalware industry.
We found the FCS Security Agent is virtually undetectable by the user, except when it’s scanning the computer (an operation you may well want to schedule for nonpeak hours, anyway).
Significantly, the agents did not crash once in the lab. A crash, because it destroys a user’s productivity, would have been the kiss of death for FCS.
FCS Management Console
The central console works closely with Active Directory. We found distributing client-side agents to Windows PCs in an Active Directory organizational unit to be straightforward and painless. With a single click, we configured the deployed agents to never show even a single dialog box to users.
Via the console, we also designated certain clients (power users) to be able to run the agent manually, which let those users see an application window similar to Windows Defender.
The FCS console displays an intuitive dashboard showing current and historical network security status. The FCS event logging and alerting feature embodies Microsoft Operations Manager (MOM) 2005 technologies to collect events and data from FCS Security Agents.
SQL Server Reporting Services help produce FCS reports, and FCS uses SQL Server components for the storage and reporting of malware event data. The good news here is that you don’t need separate MOM 2005 or SQL Server licenses to get these capabilities.
Through the console, we globally scheduled either full or quick scans for clients within an AD organization unit for all of our test machines. We could also instruct all computers or a single computer to perform an on-demand scan for spyware.
FCS relies on Microsoft’s Windows Server Update Services (WSUS) to obtain the latest spyware definitions. WSUS, downloadable from microsoft.com, is caching server software you run on one or more machines, and that aids Microsoft Update’s automatic delivery of patches to Windows computers. The update process worked flawlessly in our four tests.
For users who travel frequently and thus lose access to WSUS servers, we configured the client-side agents to obtain spyware definition updates directly from Microsoft Update. However, non-VPN-equipped mobile users didn’t get our administrative changes to FCS policies until those users returned to the office and logged on to the local network.
We set FCS to automatically approve all such updates. In a separate test, we told FCS that we wanted to manually approve the updates before their dispersal. Both schemes worked well, but we’d recommend the former setting as a matter of course.
Each morning, the central console produced a useful report showing the previous day’s malware activity. For trending purposes, FCS maintains a 30-day archive, which we were able to see in the console’s reports. FCS reports include an alerts summary, a computers summary, a deployment
|
| ||||||||||||||||
| ||||||||||||||||
FCS Security Agent
The client-side FCS Security Agent runs as a background service on Windows 2000, Windows XP, Windows Server 2003, and Windows Vista. Daily, or on a schedule we established using the console, each agent scanned its computer in either “quick” (checking only running processes, registry, start menu and operating-system directories) or “full” (checking running processes, registry, start menu and all directories) fashion.
FCS checked e-mail attachments when we opened them but didn’t scan incoming e-mail streams for malware.
The daily scans are a supplement to FCS’ real-time examination of incoming EXE, DLL, OCX and other executable files as it hunts for spyware. When an agent detected an incoming spyware instance in our tests, the agent terminated the associated running process, deleted the spyware instance’s files and cleaned up the registry.
For rootkits (which modify the registry to cause Windows to run the spyware perpetually), the agent cleaned up what it could and signaled the operating system to finish the cleanup and removal effort the next time the machine was rebooted.
Overall, it successfully stymied 95% of the malware we threw at it, missing only such recently written malware efforts as Prorat Trojan and Torpig.b . A 95% success rate is about average for the antimalware industry.
We found the FCS Security Agent is virtually undetectable by the user, except when it’s scanning the computer (an operation you may well want to schedule for nonpeak hours, anyway).
Significantly, the agents did not crash once in the lab. A crash, because it destroys a user’s productivity, would have been the kiss of death for FCS.
FCS Management Console
The central console works closely with Active Directory. We found distributing client-side agents to Windows PCs in an Active Directory organizational unit to be straightforward and painless. With a single click, we configured the deployed agents to never show even a single dialog box to users.
Via the console, we also designated certain clients (power users) to be able to run the agent manually, which let those users see an application window similar to Windows Defender.
The FCS console displays an intuitive dashboard showing current and historical network security status. The FCS event logging and alerting feature embodies Microsoft Operations Manager (MOM) 2005 technologies to collect events and data from FCS Security Agents.
SQL Server Reporting Services help produce FCS reports, and FCS uses SQL Server components for the storage and reporting of malware event data. The good news here is that you don’t need separate MOM 2005 or SQL Server licenses to get these capabilities.
Through the console, we globally scheduled either full or quick scans for clients within an AD organization unit for all of our test machines. We could also instruct all computers or a single computer to perform an on-demand scan for spyware.
FCS relies on Microsoft’s Windows Server Update Services (WSUS) to obtain the latest spyware definitions. WSUS, downloadable from microsoft.com, is caching server software you run on one or more machines, and that aids Microsoft Update’s automatic delivery of patches to Windows computers. The update process worked flawlessly in our four tests.
For users who travel frequently and thus lose access to WSUS servers, we configured the client-side agents to obtain spyware definition updates directly from Microsoft Update. However, non-VPN-equipped mobile users didn’t get our administrative changes to FCS policies until those users returned to the office and logged on to the local network.
We set FCS to automatically approve all such updates. In a separate test, we told FCS that we wanted to manually approve the updates before their dispersal. Both schemes worked well, but we’d recommend the former setting as a matter of course.
Each morning, the central console produced a useful report showing the previous day’s malware activity. For trending purposes, FCS maintains a 30-day archive, which we were able to see in the console’s reports. FCS reports include an alerts summary, a computers summary, a deployment summary, a malware summary, a security state assessment (identifying clients that have missed security updates) and a security summary (containing top-level data from the other reports).
FCS lacks at least one feature some antimalware vendors offer that categorizes malware for filtering purposes. Some of these categories are: Adult material, advocacy groups, illegal drugs, gambling, games, illegal or questionable activities, job search, Web chat and extremism. The use of malware categories lets an administrator block or allow Web site access at a rather fine level, according to specific corporate policies.
In contrast to the desktop client approach offered by FCS, a gateway-based malware filter insulates your entire network, protecting even NT, 98 and ME machines. Depending on the gateway filter you choose, it can keep all users (even Mac OS X and Linux) from browsing adult, militant or gambling sites. You never worry that some clients have an out-of-date spyware-definition file. The gateway approach thwarts rootkits without requiring client computer rebooting (in fact, there’s no removal/cleanup effort at the client at all).
Users can’t employ the task manager to halt the antimalware processes. A gateway is simpler to administer, and desktop machines and servers don’t have to shoulder the extra burden of detecting and removing spyware. For these reasons, we believe the gateway approach is far superior to the individual desktop removal/cleanup approach overall.
We concluded that FCS is suitable for small- to medium-sized organizations with few mobile users or mobile users who return to the office frequently. Administrators must also be aware that, even with a central console for administering FCS security agents, deploying many agents onto desktop PCs represents yet one more computer program whose execution you’re duplicating across all the Windows computers on your network. Before investing in FCS, you’ll want to look into antimalware gateway-architecture devices that sit between your network and the Internet to keep malware off your network altogether.
Barry Nance runs Network Testing Labs and is the author of Introduction to Networking, 4th edition, and Client/Server LAN Programming. His e-mail address is barryn@erols.com.
Nancy is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.




