by Christine Perey and Travis Berkley

IM management tools

Reviews
Jun 28, 200414 mins

Taking the mess out of instant messaging.

We take a close look at four very good products that can help network managers improve control and reduce potential risks of IM on a corporate network: Akonix’s L7 Enterprise, FaceTime Communications’ IM Auditor, IM-Age Software’s IM Policy Manager and IMlogic’s IM Manager.

Instant messaging has established a foothold in corporations. It’s easier and faster to check an IM client to see if someone is online and shoot off a quick question than to send an e-mail and wait for a response. But the unanswered question is how companies should manage the security, liability and productivity risks of IM and ensure compliance with federal and corporate policies, while supporting this maturing avenue for real-time or just-in-time information exchange.


IM monitoring and management buyer’s guide

Find the tool that best matches your criteria.


While major corporate IM platforms address monitoring and management, a lot of IM usage in business comes from the three public IM services: AOL Instant Messenger, Yahoo Messenger and Microsoft MSN Messenger. A new set of IM management products have arrived to address the monitoring and management of IM, whether it’s an enterprise platform or a public service.

We took a close look at four very good products that can help network managers improve control and reduce potential risks of IM on a corporate network. We looked at Akonix’s L7 Enterprise, FaceTime Communications’ IM Auditor, IM-Age Software’s IM Policy Manager and IMlogic’s IM Manager. Using these products, a business can gain control over how IM is being used without having to do a “forklift upgrade” to their IM system.

All the products we tested do the basics very well, and will meet many enterprise needs. The products log traffic, apply required policies and forward messages for delivery, if appropriate. They all were very adept at the most basic function of logging traffic into a database for later review. This core function is treated so straightforwardly by all four products that it is almost mundane.

Each product also offers unique features that might make it a good fit for your enterprise network. All four products are mature enough for an enterprise deployment.

That said, we award the Clear Choice Award to Akonix’s L7 Enterprise for offering a little more. From the extra details of its policy management, to the ability to automatically run and deliver customized reports, Akonix came out ahead of the other platforms.

A fine-toothed comb

Each system we tested offers administrators a complete set of policies and configurations, immediately available upon installation. While this is a great start, we found that L7 Enterprise goes a step further by offering customization of specific users groups. With L7 Enterprise an administrator can create detailed rules and policies. This difference is most noticeable in managing file transfers. While the policies in the other three products amount to yes/no propositions, Akonix lets administrators govern file transfers by type, size or time of day. For example,with the other three products you would be hard-pressed to create a single policy rule to allow only the marketing group to send PDFs and JPEGs between 8 a.m. and 5 p.m.

Akonix also included the ability to apply these rules based on IP address, IM handle and other standard user identity management systems. This is particularly useful if you have roaming users with laptops. Their credentials and screen names won’t change, but there might be times when you want to add restrictions (such as when they are connected through a VPN).

The other three products also offer solid policy management. For example, IMlogic has a default rule set that is globally applied. System administrators then can create user groups to which they can apply different settings. The file transfer policy is yes/no but can be applied on a group-by-group basis. Likewise, you can create a different list of words and phrases to block different groups or departments. You also can customize your disclaimer text for each group. For content filtering, lists of words, phrases or URLs can be created to trigger additional actions (alerts to the administrator, for example).

The message can be blocked, although no differentiation is made between inbound and outbound. The system can notify the sender of an infraction and send an e-mail to system administrators or make an entry into the Windows event log. These filtering rules can be applied to specific groups, universally or individually per user.

FaceTime’s IM Auditor boasts similar capabilities. A set of global permissions is applied by default until an administrator creates groups to further customize the permissions. Again, file transfer permissions are yes/no, and can be applied to each group differently. One interesting addition in IM Auditor is a policy for whether the IM clients can use the built-in audio and video features, or play the built-in games. Another interesting difference is that FaceTime separates content-filtering functions from system-administration functions and makes them part of the global reviewer’s functions. A global reviewer can create words and phrases to watch for, and specify a group or groups to which a new rule is applied. The policy can include whether a message should be blocked inbound and/or outbound, and whether someone should be alerted by e-mail when an infraction occurs.

IM-Age lets system administrators create customized rule sets for different groups of users. IM-Age calls these configurations, because the rule sets also might include instructions on how the IM-Age client should behave. The word-blocking function groups the words and phrases into categories (such as project codes, sales or foul language) to make it easier to apply to different groups. However, you can use the word-blocking function only when using the IM-Age client, and then only on outbound, encrypted traffic. As with the other products, IM-Age disclaimers and infraction messages are fully customizable on a group-by-group basis.

Putting it together

The initial installations, for the most part, are trivial. FaceTime has further streamlined the process by offering its IM Guardian in a fully integrated network appliance (the RTG500) running hardened Linux. All you do is turn it on, give it an IP address and away it goes, monitoring your IM traffic. FaceTime’s user interface was exceptionally elegant and easy to use. The other companies we tested say they are not far behind in bringing similar network appliances to the market, but also say that sometimes “just a gateway” is not enough. Savvy users who can find ways to circumvent a central gateway server might find ways to bypass your policies. That is one reason why IM-Age says it feels strongly about using a client, thus enabling IM management regardless of where or how that machine is networked.

We also discovered a lot of smaller products or options that add to the IM monitoring and management big picture. FaceTime offers IM Guardian for monitoring at the edge, and IM Auditor is its policy engine. In addition to the L7 Enterprise server, Akonix adds Rogue Aware, Enforce and Compliance Manager (we did not test these three components).

IMlogic did a good job of keeping the picture simple for buyers – its IM Manager is more of a one-stop offering for IM monitoring, risk management and policy compliance enforcement. But IMlogic still offers IM Detector (which we did not test) at no additional cost to detect and stop stubborn users who try to circumvent your policies.

Akonix, FaceTime and IMlogic had virtually the same requirements when installing on a Windows platform. We installed them on Windows 2003 Standard Server and loaded Microsoft’s SQL Server 2000 Standard Edition on top of it.

IMlogic and FaceTime also use the Internet Information Server components of Windows, and IMlogic also uses the Windows Message Queuing services. Beyond that, each of these three products installed with virtually no problems. IM-Age did require an additional server to install Microsoft’s Internet Security and Acceleration server, so there was a little more work upfront. But to offset this, IM-Age includes product installation as part of the purchase price.

Adding encryption

IM-Age seems well designed for companies in which a network manager can install a run-time executable application on every client system and in which the mandate is to manage all IM traffic, whether users are attached to a LAN or on a third-party network. The IM-Age client also can be deployed in stealth mode.

Another characteristic that differentiates IM-Age is the encryption of IM traffic. If this is required in your environment, look no further than IM-Age. A 448-bit Rolling Salt Blowfish encryption engine is integrated into the managed clients, offering a significant benefit when users are transmitting sensitive information via IM, whether over a LAN or the Internet.

This encryption also is extended to unmanaged clients through a free, downloadable reader. A URL for the reader is sent to the user across the network as part of the active IM session. The unmanaged user clicks the link to accept the decryption engine download and the key to the local system for the duration of the session. The reader overlays the decrypted text on the IM client, denoting it with a padlock icon to remind the user that the message is encrypted. During testing, we noticed no perceivable slowdowns when encryption was enabled.

Directory assistance

All four systems we tested leveraged existing enterprise directory and user management systems, firewalls and other network and communications administration tools to varying degrees. Akonix and FaceTime had directory integration and synchronization functions that could tie into several directory systems, including Windows Active Directory and Sun ONE Directory. Akonix also synchronizes with Novell’s eDirectory, and FaceTime can synchronize with IBM’s Lotus Domino. Akonix also can import and synchronize with multiple directories simultaneously.

IMlogic also performed directory import and synchronization. But this is very basic, and limited to generic Lightweight Directory Access Protocol. We found this was every bit as functional as the other vendors’ products. But because the system is more generic, a system administrator has to know enough about the local directory service to answer a few questions, such as port and object classes.

Although IM-Age doesn’t synchronize directories, it does deal with directory information. It will report a user’s credentials, but they are authenticated to a local machine, regardless of the enterprise directory being used. This means system administrators cannot import user accounts ahead of time, but once a user connects to the system, the information is correct.

What about the user?

The four products all did a very good job remaining transparent and running in the background. Whether the products were in use did not change how the IM clients are used or how they function. When infractions occurred, IMs would be sent to the offending user. Blocked file transfers would look to the external sender as if the internal recipient simply declined the transfer. If the internal user attempted a file transfer that was not allowed by policy, an infraction IM would be sent. In the case of IM-Age users running the client, a pop-up window alerted them as soon as they brought up the File selection dialog box.

All the products can customize the messages that are sent back to the offending IM user, whether internal (and managed) or external (unmanaged). This lets the system administrator decide how much detail is appropriate when alerting the user to an infraction. Akonix uses the “toaster” display in MSN to send the infraction notices. The little pop-up window that appears near the system tray becomes the bearer of unpleasant news, rather than an IM.

Reviewing IM archives

To comply with federal or industry rules (or just good housekeeping), it may be necessary to look for content that has been logged by these products. All four products have reviewer functions built in, but the feature sets vary quite a bit.

Akonix uses a Windows program that can create a summary or detailed reports, and charts and graphs. A wizard assists in creating a report to find required data. Customized reports can be saved for later use. Once a report is saved, it can be scheduled to run as needed. The report can be created as a PDF, Crystal Report or HTML, and can be saved to disk or e-mailed from a locally installed MAPI client.

As flexible as the rest of L7 Enterprise is, it was a little difficult to search for content on an ad hoc basis, unless it was included as a blocked keyword. Another shortcoming with Akonix is that there are basically two levels, either read-only or full access. However, the reporting tool is very easy to use and generates very attractive reports.

IMlogic’s IM Manager is more detailed with reviewer levels, and provides four basic functions – query the logs, edit annotations to conversations, view an audit trail (essentially a review of the reviewer) and manage keywords. The reviewer in IM Manager can create keywords to watch for, but not block. For example, you might not want to prevent employees from using the phrase “stock split,” but you might want to see how it is being used.

Reports cannot be saved or scheduled. But like everything else in IM Manager, the easy-to-use Web interface lets you run reports from anywhere.

FaceTime’s IM Auditor is even more detailed. Not only can there be global reviewers, but FaceTime introduces the concept of a group supervisor.

This distinction gives reviewer privileges that are limited in scope, rather than function, to a defined group. For example, you might have separate reviewers for each of the sales, marketing and engineering groups who only can see conversations for each department’s users, and another global reviewer, who has access to everything.

IM Auditor also can give end users the ability to search over their own conversations. While IM Auditor doesn’t store separate keywords from the blocked list, it does provide the ability to search for ad hoc text.

Much like IM Manager, IM Auditor cannot save or schedule these reports, but its Web-based interface lets you run reports from any browser.

IM-Age offers a Web interface and a Windows application. While the Web-based version allows use from anywhere, the Windows application is easier to use. It provides search capabilities to reviewers and end users, limiting only the scope of what is seen based on authentication. Again, these queries cannot be saved or scheduled.

But the combination of access methods provides good accessibility. One extra and unique feature in IM-Age is the ability to generate an ad hoc query as a raw SQL statement. While this is extremely powerful and flexible, it would almost certainly be too complex for all but the most experienced network managers.

Something for everyone

All the systems we tested were designed to monitor and manage IM traffic, such that companies can permit their employees to use public IM services for business purposes without exposing the company to unnecessary risks, and to ensure compliance with industry, government or corporate guidelines. Akonix’s L7 Enterprise offers the best overall package, but FaceTime and IMlogic also have very strong packages, delivering solid performance that won’t disappoint. And if you need to encrypt your IM traffic,give IM-Age a look.

L7 EnterpriseOVERALL RATING
4.5
Company: Akonix Cost: $3,850 for 50 users; additional costs for Enforcer and Compliance Manager. Pros: Robust and flexible policy manage-ment system, plug-in architecture, support for multiple operating systems, directory services vendors and IM platforms; anti-virus engine tightly integrated into package. Cons: Complex application could require instruction, time to set up correctly; no choice in anti-virus vendor.
IM Auditor, Guardian and RTG500 OVERALL RATING
3.8
Company: FaceTime Communications Cost: IM Auditor: $25,000 for 500 users; IM Guardian: starts at $2,500; RTG500: starts at $5,000. Pros: Easy to use, intuitive Web interface; DMZ/ border product available as software (Guardian) or hardened Linux appliance (RTG500); can create separate reviewers with limited scope for group management; flexibility in anti-virus engine. Cons: Policies lack detail; management of anti-virus not integrated into interface, cannot save or schedule reports.
IM Policy ManagerOVERALL RATING
3.8
Company: IM-Age Cost: $2,000 per year for Server Console (not required for client install only, but used for management and data storage); $15 per user, per year; data hosting also $15 per user, per year. Pros: Combination gateway and optional client application allows monitoring by users not on enter-prise network; only system tested that can encrypt IM sessions and file transfers. Cons: Installing client requires access to all employee computers; lacks integrated anti-virus and spim control systems.
SIM Manager 6.0 OVERALL RATING
3.8
Company: IMlogic Cost: $2,500 for 100 users. Pros: Comprehensive offering, including gateways between IM services for multi-IM environments and federation between corporations; easy installation and management via Web interface; relationships with all IM industry players assures maintenance of control as IM systems evolve. Cons: Lack of fine detail in policy control, cannot save or schedule reports.
The breakdown  AkonixFaceTimeIM-AgeIMlogic
Policy control and granularity 30%543.54
Logging/archiving/reporting 30%4.53.543.5
Installation 15%4444
User experience 10%4444
Directory integration 5%5414
Non-IM authentication 5%4454
Unique features 5%4353
TOTAL SCORE4.53.83.83.8
Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Consistently subpar