Find White Papers
Home
About Us
List Your Papers
    
> Internet Security Systems > Defining the Rules for Preemptive Host Protection

Defining the Rules for Preemptive Host Protection

White Paper Published By: Internet Security Systems

Protecting desktop and server, or host systems has rapidly become a high priority for organizations that want to ensure uptime and the availability of day-to-day business applications. Today's hybrid threats are growing faster, more complex and more destructive.



Tags : 
intrusion prevention, high availability, network security, iss, internet security, web security, malware, internet security systems

Internet Security Systems
Published:  Aug 21, 2009
Type:  White Paper
Length:  12 pages

Defining the Rules for Preemptive Host Protection:
Internet Security Systems' Multi-Layered Strategy
By Joshua CormanHost Protection Architect
Copyright© 2005 Internet Security Systems, Inc. All rights reserved worldwideDefining the Rules for Preemptive Host Protection: Internet Security Systems' Multi-Layered Strategy An ISS Whitepaper 1
INTRODUCTIONProtecting desktop and server - or "host" - systems has rapidly become a high priority for organizations that want to ensure uptime and the 1availability of day-to-day business applications. In 2003, the average cost of a virus disaster's impact rose approximately 23 percent, to $99,900 , a figure that's increased for eight consecutive years. Today's hybrid threats are growing faster, more complex and more destructive. Only InternetSecurity Systems (ISS) provides a multi-layered security solution that can provide the preemptive protection needed to stop these threats before theyimpact business operations. Firewall and vulnerability-centric intrusion prevention provide protection for attacks that originate at the network level, while behavior-based,application-level protection is needed to stop buffer overflow exploits and malicious programs spread via e-mail, Web browsing and other file-centricthreat vectors. The market's inability to identify and distinguish between these two primary threat vectors has resulted in confusion over whichtechnologies can most effectively prevent a particular attack on the host.®Proventia Desktop software protects host systems using a combination of personal firewall, intrusion prevention, buffer overflow exploit prevention,application control and virus prevention (VPS) - a brand new technology that uses patent-pending behavioral analysis to prevent worms, viruses,Trojans, and spyware. VPS technology fills the gap left open by traditional signature-based antivirus technology by stopping viruses and wormswithout needing a signature update. This whitepaper will identify common problems associated with effectively protecting host systems and define the components of ISS' ProventiaDesktop - a comprehensive solution offering a superior level of host protection. Understanding Modern Threats to the HostWhen researching threats to host systems, it is important to understand the primary phases of a successful attack. In one popular model, attacks onthe host are broken into three phases - penetration, launch and propagation - as shown in Figure 1.
Penetration Launch Propagation
NNeettwwoorrkk VVeeccttoorr
AApppplliiccaattiioonn VVeeccttoorr
Propagation Launch Penetration
Proactive Zone Danger Zone Proactive ZoneFigure 1: Phases of an Attack on the Host
1 ICSA Labs Virus Prevalence Survey 2003Defining the Rules for Preemptive Host Protection: Internet Security Systems' Multi-Layered Strategy An ISS Whitepaper 2
The compromise of a host which allows further malicious activity PPeenneettrraattiioonn to occur. Penetration can occur through e-mail, Web browsers, remote buffer overflow or various other methods.
The execution of the attack's malicious payload. LLaauunncchh Launch methods can range from a user double-click to remote memory buffer overflow.
Post-compromise activity intended to replicate, retrieve other PPrrooppaaggaattiioonn components, transmit data or enable remote control.
Table 1: Definitions of Host Attack PhasesProtecting hosts from threats used to be much simpler. Because hosts are now so interconnected, they have become susceptible to many more typesof attacks that threaten real-time business. Attacks target host systems using one of two major threat vectors: the network vector and the application vector, as illustrated in Figure 2. Similar to the spread of disease in biological pathology, attacks are carried by vectors to their targets.
MyDoomNNeettwwoorrkk VVeeccttoorrSasser
Bagle
MS Blaster
Netsky
Welchia
AApppplliiccaattiioonn VVeeccttoorr
Figure 2: Threat Vectors Used in Recent Attacks
The Network Threat VectorNetwork-based attacks utilize malicious network traffic to remotely compromise their target systems. Unlike other threats, network-based attacks canpenetrate, launch and propagate without human intervention. Network-based attacks on the host predominantly exploit vulnerabilities in protocolsand network-aware processes. These vulnerabilities are ty... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search