The worms that threatened Windows computers last week made clear once again that vulnerable desktops and laptops pose a serious threat to network security – but the answer to shoring them up remains murky.
Vendors are developing such a wealth of products and security architectures for keeping potentially infected machines off the network and shutting down badly behaving ones that customers might have trouble figuring what is best for them, experts say.
“Everyone is rushing into network access control, and there are still a lot of start-ups coming in,” says Chris Liebert, senior network security analyst for The Yankee Group.
Seventy-four percent of 304 IT executives surveyed by IDC say they expect to spend more on this type of endpoint security within the next two years, and 15.5% say they expect the increases to be large or very large.
The two vendors carrying the most clout in this area are Cisco and Microsoft, which have announced and started to implement their respective plans for ensuring individual devices meet network security policies. Their products are so pervasive that many customers might be swept along by their endpoint security plans, Liebert says.
Both companies have compiled long lists of vendors that agree to support their schemes, making them more attractive to customers who already own gear made by these security partners.
Cisco’s Network Admission Control (NAC) requires all-Cisco networks with all the gear upgraded to a certain software revision. Microsoft’s Network Access Protection (NAP) is based on software in Windows clients and servers that relies on cooperation of hardware vendors for enforcement.
Others in security arena
Network vendors Juniper and Nortel have their own endpoint security schemes, as do a host of security vendors including Check Point, Endforce, Vernier, Nitro Security, Mazu and LANCope. Many remote access VPN vendors have their own endpoint security software that determines whether machines are admitted to VPNs but that don’t fit into larger endpoint security frameworks for corporate networks.
|
Security specialist Symantec recognizes the importance of such technology, as demonstrated by its planned purchase of Sygate, announced last week . Sygate has arguably one of the best-developed endpoint protection offerings, says Chris Christiansen, an analyst with IDC.
The common thread among these products is that a central server scans machines before they gain network access to see, for example, if they have personal firewalls properly configured and running, anti-virus software updated and running, and properly patched operating systems. “It comes down to checking the endpoints with a client to see if they are compliant with a policy that says they are safe to be admitted to the network,” Christiansen says.
If not, the security gear can deny access, send a message telling what remediation is needed, direct the remote machine to a site where it can get what it lacks, or grant access to a quarantined network segment where the machines have limited rights.
Some gear also can monitor traffic within corporate networks, and recognize abnormal traffic and shut it down. This is the goal of NAP and NAC, and is what some security vendors offer now. Vernier’s EdgeWall gear, for instance, recognizes and quarantines suspect traffic while allowing normal traffic to continue.
Customers have a long list of options to wade through, and their decision is made more complex by the many alliances among vendors to support each other’s products, Liebert notes.
Sygate, for example, supports a battery of products from other vendors, including Alcatel, Aruba Wireless Networks, Aventail, Cisco, Enterasys, Extreme Networks, HP, iPass, Juniper, Microsoft and Nortel. Check Point supports Enterasys, Foundry Networks and Nortel, among others. Nortel supports Sygate, Symantec, Check Point, Microsoft, Network Associates, Trend Micro and others.
While it seems hopelessly confusing, the purpose of this web of alliances is to make things simpler for end users, says Sygate President and CEO John De Santis.
The goal is to support endpoint security right away regardless of whose equipment makes up a customer’s network, he says. This falls in line with an IDC study that says enterprise customers are cool now and will remain reluctant to go forward with endpoint security schemes that lock them in to buying all their network gear from a single vendor.
The goal is for industry standards that will make compatibility issues melt away, De Santis says. “We’re pushing for industry compliance,” he says.
In the meantime, businesses should weigh just how comprehensive their endpoint protection should be, Yankee’s Liebert says. She recommends companies answer the following questions to help decide what they need:
How many potentially vulnerable machines are on the network and what risk that poses?
How sensitive is the data being transmitted from remote locations and what is the cost of its being compromised?
Has the business suffered an outbreak before?
Is there a high turnover rate among employees who might later attack the network?




