BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Better Security Management with a Consolidated View of AV and Vulnerabilities

Posted May 19, 2011    Alejandro DaCosta

We expect our smart phones to handle all of our business needs: phone calls, voicemail, email, and calendar functionality, at the very least. Why not expect the same consolidated approach with your security products? Take for example the relationship between vulnerabilities and malware. Most of the malware, trojans, worms, etc., get into a system by exploiting vulnerabilities in applications such as Adobe, IE, Firefox, etc. Vulnerabilities and malware really have a strong correlation and so should the products that manage each one. 

Here at eEye, we have taken this consolidated approach for years, first with the introduction of the REM management console and most recently with Retina CS. These consoles, at their core, allow an IT professional to easily manage endpoint protection agents as wells as vulnerability assessment data from a single location.

eEye’s unified approach comes with many benefits:

  • Lower total cost of ownership
  • One central console, a single server or appliance
  • Correlated reporting that includes vulnerability and attack data
  • Risk assessment of both vulnerability and attack data
  • A shorter learning curve with a single application
  • A single dashboard depicting your true security posture
  • Unfortunately, I have seen many environments where there is a disconnect between vulnerability management and endpoint protection. In some cases, vulnerability assessment is not part of the picture at all! These environments also tend to rely just on an anti-virus application for protection. This is equivalent to saying, “Let the vulnerabilities I don’t know of be exploited and let the malware be delivered. I only want to be protected against known threats and I want this protection to occur once the malware is on my system and has subsequently triggered a signature.”  I’m not saying that you should not have an anti-virus, but rather that your endpoint protection agent should combine an AV layer with other layers of protection.  These other layers should not be signature-based and should provide Zero-Day protection.  Blink, eEye’s endpoint protection solution, is a clear example of this. Blink takes a multi-layered approach to security and combines vulnerability assessment as part of its package. 

    Want a consolidated view of your environment? See an On-demand Demo of Retina CS.

    Leave a Reply

    Additional articles

    powerbroker-for-mac-diagram-small

    PowerBroker for Mac: A Least-Privileged Apple a Day…

    Posted July 27, 2015    Jason Silva

    BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

    Tags:
    , ,
    PrivilegedAccountManagement

    On Demand Webinar – Now is the time for Privileged Account Management

    Posted July 24, 2015    BeyondTrust Software

    In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

    Tags:
    , ,
    dave-shackleford-headshot

    Privileged Account Management: The Time is Now

    Posted July 22, 2015    Dave Shackleford

    There’s plenty of problems we don’t have great options for in InfoSec today. Malware is a pain point that keeps evolving rapidly. 0-day exploits are tough to prepare for. Privileged account management? We got this. We know the root causes, we know how it manifests, we know how to get it under control effectively, and there are great technology solutions that are enterprise-class.

    Tags:
    , ,