Aladdin’s environment consists of the eSafe appliance plus Spyware Neutralizer, an agentless central console for automatically removing spyware from infected clients. The eSafe appliance stopped 68 out of 70 malware instances.
The eSafe device uses a combination of signatures, heuristics, behavior blocking, exploit recognition and blacklisting to keep spyware off the network. The blacklists identify Object-IDs of known malicious ActiveX objects, as well as malicious URLs and IP addresses. By recognizing their protocols, eSafe blocked all phone-attempts in our tests.
The eSafe system worked with alacrity. It introduced an average latency of 18 msec for Internet traffic containing nonexecutable files. For executables (including spyware) of various sizes, eSafe took 70 msec to 150 msec to perform its analysis.
For each malware detection, the device records date, time, source IP address, protocol ID, type of violation and the name of the spyware instance or exploit. The system can integrate with network-management systems via SNMP and syslog.
The standard eSafe appliance is a 1U device, and Aladdin offers several sizes, up to a fully populated IBM BladeCenter that Aladdin says can handle 42,000 HTTP connections per second. Spyware-definition updates are typically distributed every few days, but high threat levels can prompt Aladdin to send updates several times a day. The appliance checks for updates every few hours, and users can configure this interval. The appliance includes antivirus and antispam protections, which were not tested.
Previous: FaceTime | Next: Barracuda >




