tgreene
Executive Editor

Net access security plans sow confusion

News
Aug 22, 20055 mins

The worms that threatened Win­dows computers last week made clear once again that vulnerable desktops and laptops pose a serious threat to network security – but the answer to shoring them up remains murky.

Vendors are developing such a wealth of products and security architectures for keeping potentially infected machines off the network and shutting down badly behaving ones that customers might have trouble figuring what is best for them, experts say.

“Everyone is rushing into network access control, and there are still a lot of start-ups coming in,” says Chris Liebert, senior network security analyst for The Yankee Group.

Seventy-four percent of 304 IT executives surveyed by IDC say they expect to spend more on this type of endpoint security within the next two years, and 15.5% say they expect the increases to be large or very large.

The two vendors carrying the most clout in this area are Cisco and Microsoft, which have an­nounced and started to implement their respective plans for ensuring individual devices meet network security policies. Their products are so pervasive that many customers might be swept along by their endpoint security plans, Liebert says.

Both companies have compiled long lists of vendors that agree to support their schemes, making them more attractive to customers who already own gear made by these security partners.

Cisco’s Network Admission Con­trol (NAC) requires all-Cisco networks with all the gear up­graded to a certain software revision. Microsoft’s Network Access Pro­tection (NAP) is based on software in Windows clients and servers that relies on cooperation of hardware vendors for enforcement.

Others in security arena

Network vendors Juniper and Nortel have their own endpoint security schemes, as do a host of security vendors including Check Point, Endforce, Vernier, Nitro Security, Mazu and LAN­Cope. Many remote access VPN vendors have their own endpoint security software that determines whether machines are admitted to VPNs but that don’t fit into larger endpoint security frameworks for corporate networks.

What’s the worry?An IDC survey of 304 corporate IT executives asking them to rank their top concerns about securing workstations and laptops came up with these results:
1Unauthorized access.
2Virus protection.
3Enforcement of security policies.
4Cost of owership
5Securing remote access
6Limiting security rights to unauthorized users.
7Centrally managing security policies.
8Development issues
9

Securing e-mail.

Security specialist Symantec recognizes the importance of such technology, as demonstrated by its planned purchase of Sygate, announced last week . Sygate has arguably one of the best-developed endpoint protection offerings, says Chris Christiansen, an analyst with IDC.

The common thread among these products is that a central server scans machines before they gain network access to see, for example, if they have personal firewalls properly configured and running, anti-virus software updated and running, and properly patched operating systems. “It comes down to checking the endpoints with a client to see if they are compliant with a policy that says they are safe to be admitted to the network,” Christiansen says.

If not, the security gear can deny access, send a message telling what remediation is needed, direct the remote machine to a site where it can get what it lacks, or grant access to a quarantined network segment where the machines have limited rights.

Some gear also can monitor traffic within corporate networks, and recognize abnormal traffic and shut it down. This is the goal of NAP and NAC, and is what some security vendors offer now. Vernier’s EdgeWall gear, for instance, recognizes and quarantines suspect traffic while allowing normal traffic to continue.

Customers have a long list of options to wade through, and their decision is made more complex by the many alliances among vendors to support each other’s products, Liebert notes.

Sygate, for example, supports a battery of products from other vendors, including Alcatel, Aruba Wireless Networks, Aventail, Cisco, Enterasys, Extreme Networks, HP, iPass, Juniper, Microsoft and Nortel. Check Point supports Enterasys, Foundry Networks and Nortel, among others. Nortel supports Sygate, Symantec, Check Point, Microsoft, Network Asso­ciates, Trend Micro and others.

While it seems hopelessly confusing, the purpose of this web of alliances is to make things simpler for end users, says Sygate President and CEO John De Santis.

The goal is to support endpoint security right away regardless of whose equipment makes up a customer’s network, he says. This falls in line with an IDC study that says enterprise customers are cool now and will remain reluctant to go forward with endpoint security schemes that lock them in to buying all their network gear from a single vendor.

The goal is for industry standards that will make compatibility issues melt away, De Santis says. “We’re pushing for industry compliance,” he says.

In the meantime, businesses should weigh just how comprehensive their endpoint protection should be, Yankee’s Liebert says. She recommends companies an­swer the following questions to help decide what they need:

  • How many potentially vulnerable machines are on the network and what risk that poses?

  • How sensitive is the data being transmitted from remote locations and what is the cost of its being compromised?

  • Has the business suffered an outbreak before?

  • Is there a high turnover rate among employees who might later attack the network?