<- HomeHome

-> SitemapSitemap

-> Contact UsContact Us

Solutions


eEye Products:
Enquiry

eEye Solutions:
Maintaining Business Continuity

eEye Information:
Datasheets

 


eEye Digital Security — Maintaining Business Continuity Policy

  As governments and the private sector face a growing threat of cyber attacks and network security vulnerabilities, organizations must focus not only on protection, but minimizing downtime. Today’s business environment necessitates 24x7 availability of critical applications, forcing IT administrators to perform maintenance and security updates in an ever-shrinking window of time.

These factors contribute to a broader issue – business continuity – that is taxing the IT infrastructure and challenging management on how to maintain 100% availability service levels.

Organizations must adopt a multi-layered approach to network security to create protection redundancies such that if a threat passes through one level, it is stopped at the next. An ideal solution must not only integrate multiple security levels, but must be scalable to address the security needs of both small and large organizations, yet not be intrusive to slow employee productivity. With the converging management of IT operations and security, a central interface must provide a comprehensive overview of the aggregate IT status, as well as a means to quickly remediate attempted attacks to avoid disruptions and costly downtime. eEye Digital Security understands this challenge and addresses it with a multi-tiered intrusion prevention solution including each of the following:

  • Non-signature based Intrusion Prevention System, or IPS
  • Rules Based IPS
  • System Level Firewall
  • Application Level Firewall
  • Local Vulnerability Assessment
  • Non-intrusive, Fast and Accurate Process Activity Monitoring

Other factors contributing to application and systems downtime may be mitigated through use of a proactive, multi-tiered security prevention plan, including:

Panic Patching
A critical component to maintaining business continuity is preventing security threats from comprising critical systems. As new vulnerabilities are discovered and patches are released, organizations are challenged on how to best deploy these updates, which frequently require a re-boot as part of the patch 'fix'. The planned process becomes useless, however, when new critical security vulnerabilities are announced requiring immediate fixes. The challenge is to avoid panic patches, performing updates only on regularly scheduled intervals.

‘Zero-day’ Attack
The window of time to remediate new vulnerabilities has shrunk to just hours, compared to months in the past. With this shrinking window, network security policies must include a component to provide immediate protection from new vulnerabilities as they are announced, to protect you on the ‘zero-day’ after such an announcement. This then enables you to perform only scheduled patch updates on your timeframe.

eEye Digital Security's products optimize business continuity by greatly reducing the need for panic patches by protecting you against a 'zero-day' vulnerability attack. This is accomplished through Blink®, eEye's unique intrusion prevention system with the capability to assess and prevent an attack without relying on signature profiles to identify and stop malicious code.

eEYE APPROACH

eEye Digital Security has developed a systematic approach to address the challenges with maintaining business continuity. This vulnerability management workflow enables you to align eEye's innovative approach to network security to the real business risks facing your organization, including preventing unscheduled downtime and maintaining service levels associated with application and systems availability.

Discover
The critical first step in identifying, checking and tracking all of the servers, workstations and devices that are attached to your network. All systems and devices can contribute to security threats and ultimate downtime so must be identified and audited.

Audit
The linchpin of the entire vulnerability management process, which entails checking all operating systems, hardware configurations and application configurations. This phase must be fast, non-intrusive, customizable, centrally organized and remotely maintained.

Delegate
Upon completion of a given vulnerability assessment, remediation activities are prioritized and assigned to team members. Rules can be created to automatically delegate security events as tasks according to severity level, origin or vulnerability type.

Remediate
Now it is time to take action, and begin dialogues on how to best remediate the discovered vulnerabilities through a combination of technology, processes, policies and training. As vulnerabilities can impact the entire organization, this step will typically be a multi-departmental effort.

Report
Whether monitoring specific machine information, providing executive level views or communicating other important data, reporting is an important element that must be evaluated along with everything else.

Adapt
The final stage for this workflow comprises the ongoing review of data collected from each preceding stage, and modifying your work flows and security measures to continue increasing security, improving performance and reducing the likelihood of unauthorized security breach.

SOLUTION ARCHITECTURE

Consistent with eEye’s best practices approach to threat management and network security, the architecture of eEye’s business continuity solution is multi-tiered, starting with a comprehensive assessment and audit of all security threats on all network assets. This is accomplished through a Retina® Network Security scan.

Blink® performs the necessary intrusion prevention protection through the deployment of an agent on each identified network asset. This way each network asset, including mobile workers and wireless devices, may be reported upon, audited and logged, providing the necessary real-time protection each time a network connection is performed.

These events are logged and easily managed through REM™ Event Manager, a central management console, capable of real-time integration through pre-built APIs to larger IT management interfaces including CA’s UniCenter, IBM’s Tivoli and HP’s OpenView. As a whole, this architecture provides the means to holistically view your security resources, and to adapt your security solution over time to provide the optimal level of protection.

 

 

 

 

Top of Page

 

 

 

| Home | Company Profile | News | Solutions | Support | Contact Us | Partners | ©2009 Virus Defence Bureau
6/34 Christensen Street, Cheltenham, VIC 3192 Australia Tel +61 03 9556 4900   Email:support@virusdefence.com.au