blog | it klinika - daredevil · 2016-12-07 · browser ips 18 network ips is stream-based...

68
Daredevil Davor Perat Senior Technology Consultant

Upload: others

Post on 02-Jun-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Daredevil

• DavorPerat

• SeniorTechnologyConsultant

Page 2: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Agenda

2

1234567

Threatlandscapeandtheendpoint

Protectingtheendpoint

Performanceorprotection,whychoose?

Virtualizedandembeddedsystemoptimization

Streamlinedmanagementandreportingacrossplatforms

Architectureoverview

Symantecproductintegrationandsupport

8 Additionalresourcesandsummary

Page 3: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

3

Let’sgetstarted!

Page 4: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

4

Threatlandscapeandtheendpoint

Page 5: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

InternetSecurityThreatReport:ISTRVolume21

5

KnownMalware NewMalware NetworkAttack SocialEngineering SystemTampering DataTheft Vulnerabilities

Symantecdiscoveredmorethan430millionnewuniquepiecesofmalwarein2015,up36%fromtheyearbefore.

Page 6: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

AnewZero-Dayvulnerabilitydiscoveredeveryweekin2015

6

Page 7: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

7

One of the largest civilian cyber intelligence networks3.7 Trillion rows of security-relevant data

175MConsumerand

Enterpriseendpointsprotected

57Mattacksensor

in157countries

182Mwebattacksblockedlastyear

Discovered

430millionnewuniquepiecesofmalwarelastyear

Billionsofemailtrafficscanned/day

1Billionwebrequestsscanneddaily

12,000Cloudapplicationsprotected

9 threatresponsecenters

Page 8: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Thethreatlandscapecontinuestoescalate

8Source:SymantecISTR2016

55%IncreaseinTargeted

Attacks

430Mnewpiecesof

malwarewerecreatedin2015

125%increaseofZero-Dayvulnerabilityfrom2014to2015

35%increaseof

ransomware in2015

InboundCommunication Payloadexecution Outbound

CommunicationPayloaddelivery

Page 9: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

HowSymanteccanhelpSymantecEndpointProtection14

9

UNRIVALEDSECURITY

BLAZINGPERFORMANCE

SMARTERMANAGEMENT

Stopstargetedattacksandadvancedpersistentthreatswithintelligentsecurityandlayeredprotectionthatgoesbeyondantivirus.

Performancesofastyouruserswon’tevenknowitsthere.

AsinglemanagementconsoleacrossWindows,Mac,Linux,andVirtualplatformswithgranularpolicycontrol.

SUPERIORPROTECTION BETTERPERFORMANCE EASYINTEGRATION&AUTOMATION

InboundCommunication Payloadexecution Outbound

CommunicationPayloaddelivery

Page 10: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SEPprotectsagainstalltypesofthreatsSEP14combinesCoreandNextGenerationtechnologies

10

Pre-ExecutionDetection

ProcessBehavior

ReputationExploitPrevention

NetworkIDS/IPS

App&DeviceControl

InsightFile / Domain Reputation

InsightSignerReputation

Advanced Machine Learning

Intelligent Threat CloudAlways Up to Date

ApplicationControl

DeviceControl

BPEsBehavioralSignatures

SONARBehaviors

Memory Exploit Mitigation

Firewall & Intrusion Prevention

SEP14

SEP14

SEP14

Emulator for crypto-malware

Page 11: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

MachineLearning

••Pre-executiondetectionfornewandevolvingthreats

ApplicationProtection••MemoryExploitMitigation

Emulator••Anti-evasiontechniquetodetecthiddenmalware

IntelligentThreatCloud

••Real-timecloudlookup,~70%reductionindefinitionsize

PerformanceEnhancements••Fasterreal-timevirusdetection

EnablingIntegrations••RESTAPIs••EnableBlueCoatintegrations

EnhancedAutomation••ExpandedLiveUpdatetodeliversecurityupdatesforWindowsclients

70%dropindailyupdates

CompeteAgainstTraps

CompeteAgainstCylance

StrongAnti-Evasion

EasyIntegrations

FasterandLightWeight Automation

SEP14NextGenerationProtectionTechnologiesandEnhancements

SuperiorProtection BetterPerformance EasyIntegration&Automation

Page 12: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

12

Protectingtheendpoint

Page 13: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Yourendpointsarethetarget

Malware

NetworkthreatsSoftwarevulnerability

Dataleakageandtampering

Page 14: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

NetworkThreatprotection

File-basedprotection

ApplicationandDeviceControlSystemLockdown

Hostintegrity

COMPLIANCE THREATPROTECTION

IntroducingSEP

CentralManagement

Page 15: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

FirewallCustomIPS

StreamLevelIPSBrowserProtection

AntiVirusAntiSpyware

HeuristicReputation

EmailScanning

WhitelistingBlacklistingDeviceControlSystemLockdown

Compliancecheck:• Standard• Template• Custom• Automation

Insight

Protectionlayers|Singleagent

Page 16: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

DownloadProtection

16

File-basedprotection

SONARisareal-timemonitoringheuristicsystemthattargetsmaliciousbehavior.ItleveragesInsighttoprovidezero-daythreatprotectionandsignature-lessmitigation.

SignatureengineisthetraditionalAntivirusfeaturematchingthreatsagainstsignatures.Itstillaccountsfor50%ofalldetectionsin2014.TheenginealsoleveragesInsightforfalsepositiveprevention.Signaturesareusedforfilesandemailsscans.

Downloadprotectionprotectsagainstnewandunknownfilesthattraditionalsignature-basedsecuritydoesnotdetect.Detectionsarebasedontheprevalence,age,sourceandoverallreputationgivenbyInsight.

Insight

SONAR(BehavioralHeuristic)

Signature

Zero-daythreatsandreducedfalsepositives

Page 17: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

17

File-basedProtection:Continued

StaticDataScanner

SDSEngine

Emulator:VMforpacked

threat

SAPE:Machine

learningengine

ITCS:Cloud- basedscanning

CoreDef-3:LightweightAVSignatures

• Emulator:Analyzethepayloadbyexecutingapackedthreatinalocalvirtualizedsandbox.

• SAPE:Determinesifafileisgoodorbadbasedonexperience,criteriasetbyanalysts,andbehavior.

• ITCS:Reducesresourceandstorageoverheadbykeepingthemostrelevantsignatureslocallyandapplyingsmallupdateswhenneeded.Allothersignaturesarehostedinthecloud.

• CoreDef-3:Traditionalantivirusenginethatcontainsalightersetofdefinitions.

Page 18: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

BrowserIPS

18

NetworkIPSisstream-basedfilteringthatusesgenericexploitblocking(GEM)toblockthreatsusingapublishedvulnerability.(OSILayer5)

CustomIPSallowsadministratorstocreateSNORTlikesignaturesatthepacketlevel(OSILayer2)

BrowserIPSprotectsagainstobfuscatedattacksatthebrowserlevel.(EncryptedJava,ActiveX,Flash,andmore).(OSILayer7).BrowserProtectionworkswithFirefoxandInternetExplorer.

NetworkIPS

CustomIPS

NetworkThreatProtection

Firewallprotectsagainstintrusionandgivescontroloverthedataenteringandleavingtheendpoint.

Page 19: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

NetworkThreatProtection

Application ••Insight,BrowserProtection,SONAR,VirusandSpywareProtectionandApplicationControl

Presentation ••BrowserProtectionandInsight

Session ••Firewalland IPS

Transport ••Firewall

Network ••Firewall

Datalink ••FirewallandCustomIPS

Physical ••DeviceControl

Page 20: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SystemLockdown

20

SystemLockdownleveragesApplicationControltowhitelistorblacklistasetofapplications.Commonlyusedinstaticenvironmentslikeembeddedsystemsandsecureworkstations.

DeviceControlblocksunauthorizedhardwaretobeconnectedtotheendpoint.Preventsdataleakageanddualhomingnetworks.

DeviceControl

ApplicationControl

ApplicationControlblocksunwantedapplicationsbasedonhashorfilename.

ApplicationandDeviceControl

Page 21: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Customrequirements

21

Customrequirementisa featurethatprovidesasimplemethodtoexecuteprogramsandscriptstoevaluateandremediateanyaspectoftheendpoint.

TemplaterequirementscanberetrievedviaLiveUpdatetoauditadvancedrequirements,suchaspasswordcomplexityorpresenceofasecondNICconnectedtothesystem.

Templaterequirements

Standardrequirements

Standardrequirementsinclude Endpointsecuritystatus,contentupdates,criticalpatches,andmore.

Hostintegrity

Hostintegrityauditstheendpointagainstrequirements.TheauditgivesaPASS ofFAILresult,whichistranslatedintoanautomatedremediation.

Page 22: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Insight

22

CALCULTINGSCORE-127 127

Insightisthelargestreputationdatafilesystemintheworldandleveragesmorethan175millionendpointstogatherinformationonbinaryexecutablefiles.

Age: Insightlooksathowlongafilehasbeencreatedbecausemalwaretendstobeverynewwheninfectingasystem.

Prevalence:Insightkeepscountofhowmanyendpointsranordownloadedagivenapplication.

SourceandSystemHygiene: Insightusesaratingsystem:Thenumberofsysteminfectionsandwherethethreatcamefromtodetermineanaccuratereputationscore.

PreviousConviction: Insightleveragestelemetryfromfeatureslikefile-basedprotection,IPSorSONARtodetermineifafilealreadyhadamaliciousbehavioronanothersystem.

Page 23: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ThreatspectrumvsSEPfeatures

23

KnownMalware NewMalware NetworkAttack SocialEngineering SystemTampering DataTheft Vulnerabilities

Signatures

Heuristic(SONAR)

Reputation(Insight)

IPS/Firewall

Applicationcontrol

Devicecontrol

HostIntegrity

IPS(GEM)

Heuristic(SONAR)

Reputation(Insight)

MachineLearning

Page 24: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Protectionacrosstheattackchain

24

InboundCommunication Payloadexecution Outbound

CommunicationPayloaddelivery

NextgenIPS

TamperProtectionandLockdown

ReputationMachineLearning(ML)

BehavioralML

AdvancedML*

AntiVirussignatures

StatefulFirewall

Browserprotection

Real-timeresponsetorapidlychangingthreatlandscape

Threatvectorlearningatscale

Next-genIPS

Applicationcontrol

Clustering

Emulationforcrypto-malware*

Signaturebased Nonsignaturebased Machinelearninganddeeplearning

MachineLearning

Network

BigData

Hardening

AV

MemoryExploitMitigation*

NewinSEP14

Page 25: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

25

Performanceorprotection.Whychoose?

Page 26: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

BLAZINGPERFORMANCEWITHINSIGHTUpto70%reductioninscanoverheadbyonlyscanningunknownfiles

26

TrustedbyInsight

Traditionalscan ScanpoweredbyInsight

Page 27: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ScanthrottlingScheduledscansuselessresourceswhenyouneedyoursystem

27

Idle Busy

SEPCPUUsage

SEPUsesupto75%

resources

SEPreducesits

resourcesusage

Scenario CPU/Disk User BestApp Balanced BestScan

BusyServer Busy Idle Throttled Throttled Running

UsingPC Busy Busy Paused Throttled Running

MovingMouse Idle Busy Paused Throttled Running

Lunchtime Idle Idle Running Running Running

Page 28: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ScanrandomizationPreventingtheAVstorm

28

Usability

CPU&I/O

Page 29: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ScanrandomizationPreventingtheAVstorm

29

Usability

CPU&I/O

Randomizationwindow

Page 30: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

30

Virtualizedandembeddedsystemoptimizations

Page 31: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Builtforallendpoints

31

Limitedstorage

Resourcesharing

Licensecost

Reduced-sizeclient:Smallerfootprintandlightercontentupdate.

CoreDef-3withsizeenhancement.ITCSenabled.

VDIspecificsettings

Page 32: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

EmbeddedandVDIclientinstallationpackage

• ContainsasmallersetofVirusandSpywarecontentdistributionfiles

• Containsareduced-packagesizethatincludesallfeatures:– VirusandSpyware*– Firewall– IPS– SONAR– SystemLockdown– ApplicationControl,andmore

• MoreNTFScompressionwherepossible

• Noinstallercache

32

Estimateddefinitionsize:

StandardClient EmbeddedandVDIClient

45 MB

45 MB

170 MB 75 MB

Page 33: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

EmbeddedandVDIVirusandSpywarecontent

• Distributedthreetimesperdayonweekdaysandonceadayonweekends

• Separatedownloadfromtheconsole

• Contentspecifictothelightweightclient

• Containslesssignaturesthanthetraditionalset

33

Page 34: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

IntelligentThreatCloudservicesdetails

34

ProjectedsizerangeofAV

definitionsonthelocaldisk.

Averagequerytimetothecloud

Performancedegradation?

Lessthan5%comparedtoSEP12.1.6scan1.7seconds75MB– 170MB

Page 35: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Clienttypesanddefinitionstypes

Copyright©2014SymantecCorporation

35

Standard EmbeddedandVDI Darknetwork

Definition type CoreDef-3 CoreDef-3withsizeenhancement

CoreDef-1.5

ITCSenabled Yes Yes No

Estimatedpackagesize(Networktraffic)

~45MB ~45MB ~360MB

Estimated definitionsizeondisk(Full.zip)

~170MB ~75MB >700MB

TheSEP12.xclientsusecoreDef-1.5.WhenyouupgradetheseclientstoSEP14,theyaremigratedtoCoreDef-3.

Page 36: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SEP 12.1Standard

SEP12.1Reduced

SEP 14Standard SEP14EmbeddedandVDI

Definition type CoreDef-1.5 CoreDef-3withsizeenhancement

CoreDef-3 CoreDef-3withsizeenhancement

ITCSenabled No No Yes Yes

Estimatedpackagesize(Networktraffic)

~360MB ~45MB ~45MB ~45MB

Estimated definitionsizeondisk(Full.zip)

~700 MB ~75mb ~170MB ~75MB

DifferencesbetweenSEP12.1andSEP14definitionsizes

36

Page 37: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Whatifyoucanskipallthe standard filesinaVM?

37

Bydefault,SEP14.xtrustsandskipsmostoftheOSandsomeapplications.TherearestillsomefilespresentintheVMtemplatethatarenotathreatandthosefilesarescannedoverandover.VirtualImageExceptionVIEsetsallthefilespresentontheVMtemplateastrustedbyaddingthemtothelocalSEPreputationstore.

Localreputation

store

Page 38: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

WhenaVIEenabledtemplateiscloned…Wescanverylittle

38

WhenthenewVMisbasedontheVIEtrustedimage,onlynewdocumentsandapplicationsarescanned.ThisreducedI/Oappliestobothreal-time,on-demand,andscheduledscans.

TrustedbyInsight

VIE VIE VIE VIE

TrustedbyVIE

Page 39: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SharedInsightCache

• SharedInsightCache(SIC)isaserverapplicationwhichcachesknowncleanfilesinordertooptimizescheduledscan performances.

• TheSICserverismainlydesignedforvirtualenvironments,butusageonphysicalsystemissupportedgiventhatnetworklatencyiskeptatanabsolutelow.

• TheSICserverkeepsarecordinmemory(RAM)offileswhicharevotedcleanbysystemperformingscans.

SICSHAREDINSIGHTCACHE

Page 40: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SEPforVDI

Copyright©2014SymantecCorporation40

Agent

••Features••SONARBehavior••IntrusionPrevention••BrowserProtection••Firewall••NetworkIPS••ApplicationDeviceControl••InsightReputation••ConsoletomanageSEP

Agentless

••Features••AgentlessAnti-Malware••Insightfilereputation••AgentlessNetworkIPS(requiresNSX)

••ConsoletomanageDCS

• WindowsDesktopSupportability:Windows7/Windows8• SystemRequirements:VMwareNSX/VMwareESXi5.5andVMwarevShield/ESXi5.1+

Page 41: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SharedInsightCache:HighLevel

VMCluster

Virtualfarm

VM VM VMVM VM VM

Virtualfarm

VM VM VMVM VM VM

File Hash DefVer Result

AE32D… 2011.1... Clean

B923E… 2011.1… Clean

F9123… 2011.1… Clean

C3FDA… 2010.2… Clean

SharedInsightCacheServer(SIC)

ThefirstSEPclientneedstoscanafileandqueriesSICandfindsnorecord.SEPscansthefileandsendstheresultstotheSIC.

SubsequentSEPclientsneedtoscanthesamefile.Theyquerythecacheserverandfindthefilehasalreadybeenscannedwiththesameversionofdefsandthefileisclean.SEPclientskipsscanningthefile.

41

Page 42: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Sharedinsightcachearchitecture

Insight SICServer SEPM

Reputation Cleanstate Logs

Page 43: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SymantecEndpointProtectionforVirtualDesktopInfrastructure(VDI)

43

Page 44: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Non-persistentVDIrefinements

– Shorterretentiontimeequalsmorelicensesavailable– SettheclientasVDIinthetemplate– ConfiguretheManagertosettheseparateretentionscheme

– SelectAdmin>Domainproperties

• VDIlicensingscheme

543

Page 45: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

45

Streamlinedmanagementandreportingacrossplatform

Page 46: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

RPM&DPKGDistros

SingleconsoleMultiplesagents

46

Policies

Reporting

Alerting

Management

Vista,7,8,10Server

Embedded

OSX10.6.810.10

Page 47: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Policies

• Centralconfiguration

• Locationawaresettings

• ManualgroupingorActiveDirectoryimport

• Treestructureinheritance

47

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl(SystemLockdown)

LiveUpdate

HostIntegrity

LocationSettings

Page 48: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Locationawareness

• Adaptsallpoliciesbasedonlocation• LocationdeterminationusesBooleanlogicandmultiplecriteriamakingimpossibleto“fake”alocation:Officelocation=Gatewaymacaddress+ConnectedtoSEPM+ResolveintranetsitetoagivenIP

48

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

LocationSettings

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

LocationSettings

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

LocationSettings

Office Home Travel

Page 49: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Reporting

• Threeviews:– Dashboard:Overview– Monitors:Tablesandlogs– Reports:Graphs

• Exports:– CSV,MHTML(alerts)

• Actionablereports:– Launchscan,update,andremediate

• Alerts:– Console– Email

49

Page 50: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Alertingandscheduledreports

• EmailorConsole

• Preconfiguredconditions

• Youcancreateyourownalertsforaselectednumberofevents

• Alertequalslivedatathatcanchangeovertime

• ScheduledreportequalsStaticdataatagivenpoint

50

Page 51: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ActiveDirectoryintegration

• Organizationalunitsynchronization– ClientgroupingmatchingActiveDirectory

– NosupportforActiveDirectorygroups

• ConsoleloginSSOPasswordchangeswhentheWindowsaccountchanges

51

ActiveDirectory

OU

UserMapping OUImport

Page 52: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Domains

• Canseparateentitieswhileusingthesamemanagementserver.

• Separate:– Policies– Groupsstructure– Reportingandalertingsettings

• MostlyusedbyserviceprovidersorlargeenvironmentwithmultipleITteams

52

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

DomainA DomainB

SEPManager

Page 53: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Accountdelegation

Consolewithmultipleaccesslevels:

SystemAdminhasaccesstoallsettings.

DomainAdminhasaccesstosettingsforasingledomain.

LimitedAdminhaslimitedaccesstosomesettingsforasingledomain

53

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

Virus&SpywareProtection

Firewall

IPSApplication&DeviceControl

(systemlockdown)

LiveUpdate

HostIntegrity

DomainA DomainB

SEPManager

Page 54: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

54

ProductIntegration

Page 55: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SymantecEndpointProtectionintegration

55

ThreatdetectionAdvancedreportingManagedServicesAgentSyslogServer

ITAnalytics

Page 56: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ManagedSecurityServices

NetworkSecurity

EndpointSecurity

SecurityIntelligence

Threatexperts

56

Automated triage workflow

RapidResponse| OperationalEfficiency| AttackVisibility

Page 57: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

MSSoverview

57

Page 58: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ITAnalyticsbenefits

Historicallogretention

Customizedreporting

Keyperformanceindicators

Granularloganalysis

58

Page 59: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Syslog

59

• SEPMcansendeventstoaSyslogserver.

• Eventscanbeparsedandgeneratealertsandticketswiththird-partyEventmanagementsolutions.

Page 60: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ExtendSEPcapabilitieswiththeSEPMAPIService

60

RESTfulAPI tobuiltintoSEPMtoenableProgrammaticintegrationwithSEP

CustomerBenefit:

üOrchestrate/automateSEPMfunctionalityfromotherapplicationsandscripts

üConnectSEPto3rd partyplatformsforcontrolornetworkplaneintegrationwiththeendpoint

Symantec Endpoint Protection ManagerClient Management

Reports &Analytics

PolicyControl

Application & Device Control

REST API’s

SEP14- API’sLogin &LogoutofSEPM

Obtain alistofgroups

Assignafingerprintlisttoagroupforsystemlockdown.

RetrievetheSymantecEndpoint Managerversioninformation

Add ordeleteablacklistasafilefingerprintlist

Page 61: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

61

ArchitectureOverview

Page 62: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SymantecEndpointProtection14.xArchitectureComponents

Windows Linux Mac Embedded

SEPM GUP LiveUpdateServer

SEPM Console

Virtual

*

*SEPMcanuseanembeddeddatabaseofMS-SQL.MS-SQLisrecommendedforlargerorganization1000+Endpoints

EventsandPolicy

Management

ContentUpdates

ContentDistribution

ProtectionandLogs

EndpointProtection

Internet

Page 63: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

Serverarchitectures

63

SINGLESITE

ü Smallenvironmentsü Simpletoimplementü Nofailover

ü Mediumtolargeenvironments

ü Providesfailoverü Requirestwoserversü MSSQLbackend

recommended

<1000Endpoints >1000Endpoints

MULTIPLESITES

ü Verylargeenvironmentü Providesfailoverü Providessitedisasterredundancyü Providesgeographicaladministrationdelegationü Requirestwoserverspersiteü MSSQLbackendmandatoryü Introducesdelayinlogvisibilityduetothe

replicationschedule

>50000Endpoints

Page 64: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

ContentDistributionmethods

SEPM

ü Directdistributiontoendpoints

ü Centralcontrolofcontentupdate

Internet

ü Rapiddeliveryü Recommendedfor

nomadusersü Nocentralcontrolof

contentused

GUP

ü ReducesWANusageü Actsasacontentproxyü Recommendedfor

scatteredenvironmentsü AnyclientcanbeaGUP

LiveUpdateServer

ü Providescontentvalidationscheduling

ü DistributecontenttononWindowsendpoints

Page 65: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

65

Additionalresources

Page 66: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

SymantecConnectForum

• Forumsannotatedbycustomers,staff,andpartners

• Videosandtutorials

• Earnrewards

66

Page 67: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

EducationServicesAbroadrangeoftrainingsolutionsto

helpyougetthemostoutofSymantecproducts.

• Achieveexpectedvalueforyourproducts.

• LearnhowSymantecproductscansolveyourbusinessproblemstodayandtomorrow.

• Gainbestpracticeinsighttokeepyourinvestmentsrunningsmoothlylong-term.

• Formoreinformationvisittraining.symantec.com

67

SymantecEducationServices OffersEffectiveProductTraining

Page 68: Blog | IT klinika - Daredevil · 2016-12-07 · Browser IPS 18 Network IPS is stream-based filtering that uses generic exploit blocking (GEM) to block threats using a published vulnerability

68