Intrusion response dips down to end-user level
Automated Security Manager technology enables real-time response at desktop
Computerworld - The need for companies to respond in real time to both external and internal network attacks is fueling interest in automated intrusion-response technologies.
Enterasys Networks Inc. this week started shipping software designed to target the systems of individual users in the event of an attack, without disrupting the rest of the network.
Andover, Mass.-based Enterasys' new NetSight Atlas Automated Security Manager (ASM) works with the company's Dragon intrusion-detection system and its network switches. Together, the products allow companies to automatically identify a network port from which an attack is originating, quarantine users that are vulnerable and make policy changes without broad disruption.
The ASM technology is the first to give companies this sort of granular control when responding to network attacks, said Stan Schatt, an analyst at Forrester Research Inc. in Cambridge, Mass.
"This is a pretty powerful kind of improvement," Schatt said. With this technology, "you are not going to have to cut off an entire port if you see an intruder."
The new capability builds on the intrusion-response functions already enabled by Enterasys, said Bob Hartland, director of IT at Baylor University in Waco, Texas.
The university is using Enterasys technology to apply policies and block certain kinds of traffic on its dormitory networks. "We apply policy to ports that blocks everyone with the policy group equally," Hartland said. The more sophisticated response enabled by ASM will allow Baylor to apply such policies as needed at an individual user level, he said.
Eaton Vance Distributors Inc. in Boston is planning to utilize Enterasys' dynamic intrusion-response capabilities to monitor core applications.
"As a financial services company, we have to be very careful about who has access to what," said Vinnie Cottone, Eaton Vance's vice president of infrastructure services. Enterasys' technology will help the company become more proactive by "letting us know who's on our network, what kind of access they have and what they are doing with that access," he said.
Enterasys' moves to incorporate more security functions in its network technology are similar to those being made by other vendors, most notably Cisco Systems Inc.
"What they are doing is integrating security into the infrastructure itself from a switching perspective," Schatt said.
Pricing information wasn't immediately available.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts