Senforce has released the latest version of its software for protecting corporate data on mobile computers, as well as desktops.
Features added to Endpoint Security Suite 3.0 include making it harder for users to change or accidentally mess up their security settings, and letting administrators block data transfers to specific peripherals.
The suite of client-server software includes client code for a firewall, connectivity controls, and theft protections, and a server-based management application that lets administrators centrally create security policies and then apply these to individual clients or to groups. The client code enforces the policies.
One new feature in the firewall is the ability to block specific types of traffic from the client. The previous release could block unsolicited traffic coming to the client. Also new is the ability to block communications by client-based Bluetooth radios, infrared, and Firewire, according to policy. Previously, the software could block wireless LAN communications if, for example, a wired connection was available to the client device.
Also new is the ability to decree that specific local storage devices, including USB thumbdrives or an Apple iPod, can be used only as read-only devices, so no data can be transferred. The previous release could only block the use of such devices for any purpose.
“You can still use an external mouse, for example,” says Kip Meacham, director of product management for the Draper, Utah software vendor. “But if the user adds a device that uses a file system, we can control the use of it based on our policy controls.”
Also new is an Advanced Encryption System (AES) wrapper around the encryption key used in Microsoft Encrypting File System, which is a file folder and encryption engine that ships with Windows 2000 and XP on PCs.
This gives the Endpoint Security software surprising control over the device: if a laptop is stolen, and the thief reconnects to the Internet, the software automatically “calls” the Senforce server, and downloads an updated policy that blocks access to the encryption key, preventing the thief from unscrambling local data. A policy can also be set so that, if the thief never reconnects on the net, the client code will automatically revoke encryption key rights after a certain period of time.
In version 3.0, Senforce also has introduced a scripting tool with its client code. Programmers can use Java, Visual Basic or other common scripting languages to create small reporting programs running on the client. If a user adds a new USB storage device, it can trigger a script that executes on the Senforce client. The client then reports the incident or behavior back to the server.
Endpoint Security Suite 3.0 is available now. Pricing for the full suite starts at $69 per user, with volume discounts. Senforce offers a 30-day free trial.




