Symantec Client Security 2.0

Opinion
Oct 14, 20042 mins

* The Reviewmeister continues his tour of endpoint security products

Symantec’s Client Security 2.0 combines anti-virus with firewall technologies.

Because setting up and deploying software that touches every client on your corporate network is no trivial matter, we assessed how each vendor handled this daunting process.

For Symantec, we followed the installation instructions but found various components not always showing up in the console, and the client firewall was not being deployed when we pushed software to clients. We ended up re-installing all Symantec server components from scratch, which resolved many issues.

For the firewall client component, we spoke with Symantec support and found that this is not installed by default. We needed to create a custom installation path. We would like to see the firewall component installed by default, not just the anti-virus software.

To test policy functionality, we attempted to create and deploy a policy that would block all inbound traffic except remote desktop, block outbound traffic to Port 23 on remote systems, block Netcat from binding to Port 468, and block Solitaire (sol.exe) from running. 

To block outbound telnet connections, Symantec was successful at blocking Port 23 outbound.

Our attack testing against each client was designed to exercise the defenses we expected to find.

We tested application control features by running an application that accessed the network in a way prohibited by policy. We tested intrusion detection by performing a port scan. We tested intrusion prevention by running a Universal Plug and Play Protocol (UPNP) attack. We tested defense resilience by performing a “coarse uninstall” of the product. We defined a coarse uninstall as the deletion of files from the product’s program files folder. We deleted all the files we could, as an attacker would.

Symantec handled execution containment and detected the network intrusion. Plus, we couldn’t uninstall Symantec. For the full report, go https://www.nwfusion.com/reviews/2004/0920rev.html

Neal Weinberg

Neal Weinberg is an experienced technology journalist with in-depth knowledge of cybersecurity, networking, cloud, wireless, IoT, IT careers, AI, robotics, digital transformation, and self-driving vehicles. Before becoming a freelance writer, he spent 17 years as executive features editor for NetworkWorld. Prior to his time at NetworkWorld, Neal was business editor at Middlesex News. He studied at the University of Massachusetts in Amherst. His work has been published in Tech Target, Information Week, Robotics Business Review, and other publications.

More from this author