* Endpoint security more important than ever
endif; ?>According to a recent cyber-crime survey, the ambitious industry efforts afoot to protect your organization’s network against Internet infections are right on the money.
According to a recent cybercrime survey, the ambitious industry efforts afoot to protect your organization’s network against Internet infections are right on the money.
As we’ve frequently noted, “endpoint-security” offerings guard against infections that remote and mobile users might pick up from the Internet then pass along to your corporate network. This can result in costly server or network downtime.
Among the many companies offering solutions to this problem are Cisco with its Network Admission Control (NAC) initiative, Microsoft with its Network Access Protection (NAP) effort, iPolicy with its Intrusion Prevention Firewall, and service providers Fiberlink, iPass and GoRemote. The delivery approaches are many and varied, but they carry a common theme: If a user’s client computer isn’t clean, it isn’t granted a connection to the network.
Never have these safeguards been more important. For the first time, viruses and denial-of-service attacks have outpaced the theft of proprietary information in terms of their cost to organizations, according to the 2004 Computer Security Institute (CSI)/FBI Computer Crime and Security Survey.
The cost of viruses to U.S. organizations jumped to $55 million last year, according to the survey. Second most costly was denial-of-service attacks ($26 million), followed by proprietary data theft ($11.5 million).
Endpoint-security products and services provide a policy-enforcement platform that helps ensure that devices connecting to your network meet administrator-defined requirements, such as compliance with a certain version of anti-virus software, a certain operating system version and operating system patches, for example.
Some recent news about quashing malicious packet signatures: Bundled into the new Cisco Integrated Services Routers (ISR), which we wrote about last month, is the ability to dynamically load and enable in Cisco IOS Software any or all of the 740-plus signatures previously only supported in Cisco’s stand-alone IDS Sensor appliance. The router-based Cisco IOS Dynamic Intrusion Prevention System feature operates in-line, so each signature can be configured to send an alarm, drop the packet, or reset the connection to tackle a security issue immediately, in real time.
You can dynamically upload new signatures from the Cisco Web site without requiring a change in software image, according to the company.




