Application security

Opinion
Oct 19, 20043 mins

* The Reviewmeister tests application control endpoint security products

Application control endpoint security products can limit the programs that can run on your network. We tested three of them, and each takes a different approach.

WholeSecurity’s Confidence Online takes a behavior-based approach and monitors application activity. If the application starts exhibiting malicious behavior, the process/program can be logged or killed, depending on how the policy is defined. 

SecureWave’s Sanctuary uses a whitelist, which lets the client only run applications that have been explicitly allowed to run, launch or execute. You can define these applications based on file name, file path and cryptographic hash, for example. This approach can be difficult to administer because you need to know explicitly which applications are good and bad.

Finjan Software’s Vital Security for Clients takes an approach that falls in between the other two.

We found WholeSecurity to be the strongest performer because of its behavior-based approach and ease of use.

The setup and configuration of the Finjan and WholeSecurity servers/consoles installation went smoothly. We followed the installer and the documentation for the server, used a downloadable client program and did not encounter any major issues.

The SecureWave installation process was not all that difficult but was time-consuming because it required reading the manual to understand how everything worked and what needed to be done. But we found the SecureWave documentation to be clearly written, detailed, accurate and easy to understand. Finjan and WholeSecurity provide adequate documentation, without standing out as either stellar or grossly lacking.

WholeSecurity and SecureWave were tested on their product’s ability to block specific applications such as sol.exe and telnet.exe from running, if defined that way.

For SecureWave, we profiled the system and set sol.exe as a disallowed application. This program failed to launch, as expected. Telnet also was set as a disallowed application. Again, this program failed to launch, as expected.

WholeSecurity monitors applications for unusual or malicious activity. You also can specify programs that should not run. We specified that sol.exe and telnet.exe should not be allowed to execute, a rule that was successfully followed.

Finjan monitors active content, such as Javascript, in HTML tags, so it would not work with any of our policy tests. You can choose to allow, block or monitor active content in runtime.

Finjan, SecureWave and Whole Security don’t help defend against network attacks because there is no network protection (firewall, intrusion detection or intrusion prevention ). But all products kept operating when we tried to coarsely de-install them.

The one consistent area of improvement for all products in this space is reporting. Every product needs better, detailed reporting system.

For the full report, go to https://www.nwfusion.com/reviews/2004/0920revtest2.html

Neal Weinberg

Neal Weinberg is an experienced technology journalist with in-depth knowledge of cybersecurity, networking, cloud, wireless, IoT, IT careers, AI, robotics, digital transformation, and self-driving vehicles. Before becoming a freelance writer, he spent 17 years as executive features editor for NetworkWorld. Prior to his time at NetworkWorld, Neal was business editor at Middlesex News. He studied at the University of Massachusetts in Amherst. His work has been published in Tech Target, Information Week, Robotics Business Review, and other publications.

More from this author