Help To Combat The Next Big Blended Threat

Security console consolidation aids IT staff in monitoring hybrid attacks

No one knows when it will happen, but most security experts expect that the day is coming--and soon--when a sophisticated "blended threat" attack will again wreak havoc on businesses' networks. Last year, Nimda and Code Red were the first to combine virus and worm propagation techniques with automated hacking capabilities in separate deadly programs, causing billions of dollars in damage to companies. Now, antivirus vendors are enhancing their security monitoring and management consoles to make it easier and more affordable for IT managers to thwart future attacks.

By introducing a new desktop firewall last week, McAfee Security, a division of Network Associates Inc., is enabling IT staff to monitor personal firewalls through its e-Policy Orchestrator console, which supports antivirus management. IT managers can view from one place viruses that are invading their networks via E-mail, as well as attack programs that gain entry through users' Web-browsing activities or other infected systems on the network. The catch: The integrated suite supports only McAfee security products. It's a trade-off--the software costs thousands of dollars less than more-sophisticated integrated security consoles from companies such as BMC, eSecurity, and Tivoli that support offerings from many vendors.


More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

The added capability may lead Affinity Health System to re-evaluate a previous decision not to install McAfee personal firewalls on users' desktops to thwart blended threats and other attacks.

Deploying personal firewalls on each desktop is expensive, but worse, it presents "another management nightmare" without a centralized monitoring capability, says Doug Shew, project leader at the Menasha, Wis., health-care company. Shew uses e-Policy Orchestrator to manage McAfee antivirus software across 2,500 desktops, and that's helped reduce overhead for policy-administration and virus-definition updates, he says.

Companies can buy the desktop firewall as part of the e-Policy Orchestrator suite for $50 per node, or by itself for $30 per node, for 51 to 100 systems.

This week, McAfee also will debut ThreatScan, software that scans for specific vulnerabilities that may leave systems open to hybrid threats. ThreatScan can be managed by ePolicy Orchestrator, so administrators can efficiently determine what operating systems and patches have been deployed, as well as find potentially susceptible open ports, file shares, FTP, Telnet, and Microsoft Internet Information Services configurations. ThreatScan is priced at just over $20 per node for 25 to 500 nodes.

There's good reason to stockpile defenses against blended threats, says Roger Thompson, director of malicious code research for TruSecure Corp., a risk-management company. "Nimda was listed as version 0.5 by its author," Thompson says, "so it's reasonable to expect a version 1.0."


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links