BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Better Security Management with a Consolidated View of AV and Vulnerabilities

Posted May 19, 2011    Alejandro DaCosta

We expect our smart phones to handle all of our business needs: phone calls, voicemail, email, and calendar functionality, at the very least. Why not expect the same consolidated approach with your security products? Take for example the relationship between vulnerabilities and malware. Most of the malware, trojans, worms, etc., get into a system by exploiting vulnerabilities in applications such as Adobe, IE, Firefox, etc. Vulnerabilities and malware really have a strong correlation and so should the products that manage each one. 

Here at eEye, we have taken this consolidated approach for years, first with the introduction of the REM management console and most recently with Retina CS. These consoles, at their core, allow an IT professional to easily manage endpoint protection agents as wells as vulnerability assessment data from a single location.

eEye’s unified approach comes with many benefits:

  • Lower total cost of ownership
  • One central console, a single server or appliance
  • Correlated reporting that includes vulnerability and attack data
  • Risk assessment of both vulnerability and attack data
  • A shorter learning curve with a single application
  • A single dashboard depicting your true security posture
  • Unfortunately, I have seen many environments where there is a disconnect between vulnerability management and endpoint protection. In some cases, vulnerability assessment is not part of the picture at all! These environments also tend to rely just on an anti-virus application for protection. This is equivalent to saying, “Let the vulnerabilities I don’t know of be exploited and let the malware be delivered. I only want to be protected against known threats and I want this protection to occur once the malware is on my system and has subsequently triggered a signature.”  I’m not saying that you should not have an anti-virus, but rather that your endpoint protection agent should combine an AV layer with other layers of protection.  These other layers should not be signature-based and should provide Zero-Day protection.  Blink, eEye’s endpoint protection solution, is a clear example of this. Blink takes a multi-layered approach to security and combines vulnerability assessment as part of its package. 

    Want a consolidated view of your environment? See an On-demand Demo of Retina CS.

    Leave a Reply

    Additional articles

    skeletonkey3_713678_713680

    Stopping the Skeleton Key Trojan

    Posted June 29, 2015    Robert Auch

    Earlier this year Dell’s SecureWorks published an analysis of a malware they named “Skeleton Key”. This malware bypasses authentication for Active Directory users who have single-factor (password only) authentication. The “Skeleton Key” attack as documented by the SecureWorks CTU relies on several critical parts.

    Tags:
    , , , , ,
    webinar 2

    On Demand Webinar: 10 Steps to Building an Effective Vulnerability Management Program

    Posted June 26, 2015    BeyondTrust Software

    In this on demand webinar, Cybersecurity Expert, Derek A.Smith will take you through his 10 steps for a successful vulnerability management program and how to get started now.

    Tags:
    , ,
    AHHA_PRO.LOGO

    Privileged Account Management – Another AH-HA in Cyber Security

    Posted June 25, 2015    Nigel Hedges

    I strongly believe that the Top 4 mitigation strategies don’t just simply apply to Australian organizations, it should be a global realization, a worldwide “ah ha!” for those still not quite understanding the importance here. Here’s a refresher (or intro) on the Top 4 mitigation strategies. Read on…

    Tags:
    , ,