|
The Code Red, Nimda, SQL Slammer, and Blaster worms had a dramatic impact on the Internet and on corporate LANs. Each found their way into the network and resulted in significant time lost while IT staff cleaned up and tried to mitigate the effects of these worms. And the next worm is just around the corner. While enterprise networks dramatically felt the impact of these worms, small and medium-sized networks were hit equally hard and the time lost cleaning up was felt even more dramatically. Today, the technology to effectively mitigate these threats is mature and readily available to small and medium-sized businesses (SMBs) through the Cisco Systems Threat Defense Bundle of network intrusion detection system (NIDS) and host intrusion protection system (HIPS) software. The IDS4215-CSA-BUN-K9 Cisco Threat Defense IDS 4215/Cisco Security Agent Bundle includes: one Cisco IDS 4215 appliance sensor, one Cisco Security Agent server, 10 Cisco Security Agent desktop agents, Cisco Threat Response software, and Cisco VMS-Basic. The Cisco IDS 4215 can monitor up to 80 Mbps of traffic and is suitable for T1/E1 and T3 environments. Additionally, multiple sniffing interfaces are supported on the IDS-4215 which allows the ability to simultaneously protect multiple subnets, thereby delivering five sensors in a single unit. At the endpoint, the deployment of a host intrusion prevention system can provide protection against both worms and viruses. The HIPS monitors processes on the host using a database of system policies. Rather than focusing exclusively on the attacks that are seen in the reconnaissance phases of network attacks, the Cisco Security Agent approaches the problem from the other direction. Cisco Security Agent prevents malicious activity on the host by focusing on behavior. By changing the focus to behavior, damaging activity can be detected and blocked - regardless of the attack. Cisco Security Agent uses predefined and user-defined security policies to determine whether a particular action or behavior is permitted. These policies are stored on a central management console that is tightly integrated with the Cisco VPN/Security Management Solution (VMS), part of the CiscoWorks software suite. The Cisco Security Agent Management Console provides a central location where policies can be defined and downloaded by Cisco Security Agent when the manager is polled. By default, Cisco Security Agent ships with predefined policies that prevent most types of malicious activity from occurring. Malicious activity, always undesired, requires little or no environmental tuning of the Cisco Security Agent. For applications requiring access to system resources, the system calls are intercepted by Cisco Security Agent, which then compares them against a cached policy. The agent correlates this particular OS call with others made by that application or process, and correlates these events to detect malicious activity. If the request does not violate policy, it is passed to the kernel for execution. If the request does violate policy, it is blocked, an appropriate error message is passed back to the application, and an alert is generated and sent from the agent to the Cisco Security Agent Management Console. |
||
There are no reviews for this product yet
There are no reviews for this product yet.
Be the first to write a premium review for this product.
Plus, if this is in one of our categories of the month you'll also go in the First Reviews Draw for the chance to win a bonus 2500 dooyooMiles.
This is your chance - Tell other people about this product from Cisco.
Technical Details for Cisco Threat Defense IDS 4215/Cisco Secu...
Products similar to Cisco Threat Defense IDS 4215/...
Juniper Networks Netscreen 25 baseline
Ethernet - Fast Ethernet
Belkin Expandview CAT5 Dual Input Remote Module
Belkin FireWire 3-Port PCI Card
Belkin Expandview CAT5 Dual Output Remote Module
Belkin FireWire Notebook Adapter
Belkin Hi-Speed USB 2.0 and FireWire PCI Card
Hi-Speed USB - IEEE 1394 (FireWire) - USB
Belkin Hi-Speed USB 2.0 Notebook Card
Belkin Omniview CAT5 KVM Extender
3Com Switch 5500G-EI 8-Port 1000Base-X Module
Belkin Hi-Speed USB 2.0 5-Port PCI Card
Hi-Speed USB - USB



