Find White Papers
Home
About Us
List Your Papers
    
> Third Brigade > 4 Key Qualities of Effective Host-Based Intrusion Prevention (HIP) Systems

4 Key Qualities of Effective Host-Based Intrusion Prevention (HIP) Systems

White Paper Published By: Third Brigade

Organizations that need to protect business critical applications, and sensitive data and hosts recognize that traditional network defenses can be readily bypassed by attackers. This white paper defines four key qualities of an effective host-based IPS.



Tags : 
intrusion prevention, network security, data protection, hacker detection, intrusion detection, ips, intrusion prevention systems, host-based ips

Third Brigade
Published:  Aug 21, 2009
Type:  White Paper
Length:  14 pages


The Four Key Qualities of Effective Host Intrusion Prevention (HIP) Solutions: Defining Deep HIP Organizations that need to protect sensitive information assets - in order to comply with corporate or regulatory policies, protect competitive advantage, or simply enable new business processes - have come to recognize Host Intrusion Prevention (HIP) as a critical component of a defense in-depth security strategy. This white paper explains what to look for in HIP products, and introduces the concept of "Deep HIP" as a means of characterizing effective solutions in this area.
TABLE OF CONTENTS EXECUTIVE SUMMARY.............................................................................................. 2
TODAY'S SECURITY BEST PRACTICES .................................................................. 3
A DEFENSE-IN-DEPTH STRATEGY IS IMPERATIVE ............................................................ 3 ECONOMICS OF THE SHRINKING PERIMETER................................................................... 3 HOST INTRUSION PREVENTION IS YOUR BEST, LAST LINE OF DEFENSE ............................ 4 BATTLEGROUND: WHERE DOES HIP MAKE SENSE ......................................................... 4
CONFUSION SURROUNDING HIP ............................................................................. 4
THE FOUR KEY QUALITIES OF EFFECTIVE HIP ..................................................... 6
1. COMPREHENSIVE PROTECTION.................................................................................. 6 2. HIGH PERFORMANCE................................................................................................ 8 3. ROBUST SECURITY................................................................................................... 8 4. LOW COST OF OWNERSHIP ....................................................................................... 9
LEARNING FROM FIRST GENERATION HIP APPROACHES ................................ 10
APPLICATION PROXY DATA FILTERING ......................................................................... 10 SYSTEM EXECUTION CONTROL ................................................................................... 10 ANALYSIS OF FIRST GENERATION APPROACHES ........................................................... 10
BRINGING IT ALL TOGETHER: DEFINING DEEP HIP............................................ 11
PROTECTING YOUR ORGANIZATION: THE NEED TO ACT NOW........................ 12
ABOUT THIRD BRIGADE ......................................................................................... 13 "Third Brigade", "Third Brigade, Inc.", "Payload Normalization", "Deep Security Solutions", and the Third Brigade logo are trademarks of Third Brigade, Inc. and may be registered in certain jurisdictions. Other Third Brigade graphics, logos, page headers, button icons, scripts, product names, and service names are trademarks or trade dress of Third Brigade. All other company and product names are trademarks or registered trademarks of their respective owners. The material provided in this document is for information purposes only. It is not intended to be advice. THIS DOCUMENT IS PROVIDED BY THIRD BRIGADE ON AN "AS IS" BASIS. THIRD BRIGADE MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, AS TO THE QUALITY, ACCURACY OR COMPLETENESS OF THE INFORMATION CONTAINED IN THIS DOCUMENT.
© Copyright 2005 Third Brigade Inc. www.thirdbrigade.com All rights reserved. - i -
Executive Summary
Unrelenting and increasingly sophisticated attacks against enterprise networks have dramatically raised organizations' IT security risks. With the relative ease that many types of attacks by-pass perimeter security, traditional perimeter based security approaches are no longer sufficient to adequately protect enterprise assets. To combat these threats, security professionals are implementing multi-layered defenses, with the last line of defense being implemented at the host itself. Host Intrusion Prevention (HIP) is the last line of defense in a comprehensive defense-in-depth security strategy. While the need for this last layer of defense is becoming increasing evident, there remains considerable confusion over what constitutes a HIP product. To be practical, HIP should be viewed as security c... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search