Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Cyberoam.

1 Cyberoam - Unified Threat Management Cyberoam Endpoint ...
Author: Deborah Naomi Simon
0 downloads 15 Views

1 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Cyberoam - Endpoint Data Protection

2 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Agenda of Presentation About Elitecore Technologies EPDP Components Licensing Product Walk-Thru

3 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. About Elitecore Technologies  Established in 1999  400+ Employees  ISO 9001:2000 certified company  Backed by World’s Largest Private Equity Group ($90bn)  Sales, Distribution Channel & Customers across 75+ countries  Communication - Networks – Security -Cyberoam - Network to Endpoint Security -CRESTEL - Telecommunication OSS BSS -EliteAAA - Telecommunication -24online - Bandwidth Management Solution

4 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Cyberoam - Endpoint Data Protection

5 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. EPDP Components o EPDP Server HDD capacity requirement formula –Avg. log size : 5MB/User (8 hours) –Example: Logging enabled for 400 users for 2 weeks(400u*5MB)*14days=28GB minimum reserved free HDD space. Recommended HardwarePentium IV 2GHZ/512MB Memory/50GB HDD space DatabaseSQL Server 2000 SP4 or above / SQL Server 2005 SP1 or above MSDE SP4 / SQL Server 2005 Express OSWin2000 SP4/XP SP2/2003 SP1/Vista & Win 7 (32-bit)

6 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. EPDP Components (cont..) o EPDP Console o EPDP Agent Recommended Hardware Pentium III 1GHZ/256MB Memory/4 GB HDD space DatabaseNA OSWin2000 SP4/XP/2003/2008/Vista & Win 7 (32-bit) Recommended Hardware Pentium III 500 MHZ/128MB Memory/1 GB HDD space DatabaseNA OSWin 2000/XP/2003/2008/Vista & Win 7 (32-bit)

7 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. 1.Device Management o Access policy for storage devices, communication devices, dialup connection, USB device, network devices etc. 2.Application Control o Application access policy for virtually any application residing on a user’s machine. 3.Asset Management o Inventory management. o Patch management. o Vulnerability management. o Remote software deployment. Licensing Modules

8 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. 4.Data Protection & Encryption o Document Control. o Encryption over Removable Devices. o Email Control. o IM Control. o Printer Control. o Shadow Copy. Note: Pricing is based on per user licensing. Licensing Modules (cont..)

9 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Agent Installation methods Direct InstallationManual installation of agent using “agent install generator”. Remote InstallerPush agents on user’s machine using inbuilt remote installer utility. Admin access to the machine required. Logon Script Implementation Push agents from domain controller using login scripts.

10 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Product Walk-Through

11 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Console Login & Dashboard

12 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Role based administration

13 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Computer/User level policies Computer level policies are applicable to all users logging in from the computer. o Cyberoam EPDP scans all the user logins once a computer is visible in the console. o All the users will then be visible in the ‘Users’ tab. o Admin can assign different policies for each user logging in from the same machine. o Some features are not available in user based policies.

14 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Logging is enabled by default for everyone. Default Policy

15 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Sample Events Log Logging of basic events along with time stamps o system startup/shutdown o login/logoff o dialups o patches applied o software deployed. Application logs showing application name, start/stop time along with time stamps.

16 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Logging of shared resources accessed on the computer by other users/computers. Logs creating, accessing, modifying, renaming, copying, moving, deleting, restoring, uploading of documents over fixed disk, floppy disk, CD-ROM, removable & network disks. Sample Events Log (cont..)

17 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Logs showing all documents, images printed along with the printer used (i.e. local, network, shared or virtual) & the time stamp. Sample Events Log (cont..) Logging of removable storage plugged in/out on the computer

18 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Sample Events Log (cont..) Hardware & Software change log.

19 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Audit Log Cyberoam EPDP records the policy changes made at the computer/user level, group level or at the network level.

20 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Monitoring Logs (Instant Message) Logs chat conversations of various messengers like Yahoo, MSN, ICQ, QQ, Skype etc. Instant Messaging (IM) Logs Chat conversation logs File upload, download Search on  Content of chat conversation  UserId/Nickname

21 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Monitoring Logs (Emails) Logs incoming/outgoing SMTP, POP3, Exchange emails & outgoing Lotus, Webmail emails. Email logs Email content, attachment Protocols: SMTP/POP3 Applications – Exchange, Lotus Notes Webmail – Hotmail, Yahoo Mail Search email by  Application, sender/recipient  Subject & Attachment – File name, extension, size

22 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Basic Policy 1.Basic The administrator can regulate the computer operation rights of a user. It helps restrict the end user not to easily change the system settings preventing them from performing malicious activity.

23 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Basic Policy 2.Device control policy Allows the administrator to block storage, communication, dial in, USB & network level devices.

24 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Basic Policy 3.Application control policy Allows the administrator to limit the use of unwanted applications. Application grouping: Tools  Classes Management  Applications

25 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 1.Email Policy Email policy prevents data leaked via emails. It can control outgoing emails based on sender, recipient, subject line, attachment type, size etc.

26 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 2.IM File IM policy is used to control the communications over instant messengers. The administrator can monitor/control files transferred via IM preventing data leakage through IM channels.

27 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. 2.IM File (cont..) Monitoring files by taking a backup of the files tranfferred over IM

28 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 3.Printing Policy Printing policy is used to control the use of different kinds of printers such as local, shared, network and virtual printers to prevent information leakage. Printing policy to block access to all printers Printing policy to allow access to network printer only. Enable ‘Record Mode’ to log the image or doc that is being printed. All recorded images can be viewed from Event Logs  Printing

29 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 4.Removable storage policy To prevent information leakage through removable devices, System administrator can apply removable-storage policy and assign different rights to removable storages. Also, the files can be encrypted when writing to the removable storages, only authorized agents can decrypt the files. Removable storage grouping: Tools  Classes Management  Applications

30 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 4.Removable storage policy (Encryption) The files can be encrypted when writing to the removable storages, only authorized agents can decrypt the files. Contents of the original file to be copied to the USBContents of the encrypted file when opened from the USB

31 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Advanced Policy 4.Removable storage policy (Disk Encryption) To prevent data leakage through removable storage, one can encrypt the entire USB disk. Thereafter, any files copied to the USB would be encrypted. Only authorized agents with ‘decrypt when reading’ rights would be able to view the original content. Removable storage grouping: Tools  Classes Management  Removable StorageFor Disk Encryption plug the USB on the Cyberoam EPDP Server

32 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Asset Management 1.Asset Management Cyberoam’s Asset Management module for Windows enables organizations to simplify tracking of their hardware and software asset location, configuration, version tracking, and historical information, allowing streamlined IT infrastructure management.

33 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Asset Management 2.Patch Management End Point Data Protection Solution frequently checks for Windows operating system patches. It automatically downloads, distributes, and installs the patches if one is found, to the machines on which the agents are installed.

34 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Asset Management 3.Vulnerability Management Vulnerability check function automatically scans the internal network computers and process analysis to help System administrator to check and trace the vulnerability problems. Follow the resulting suggestion to take timely response measures to enhance the security of all internal computers.

35 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Asset Management 4.Deployment Management System administrator can install software, run an application, and deploy files to agent through Endpoint Data Protection console. Software can be installed to the agent by simply creating a deploy task.

36 Cyberoam - Unified Threat Management Cyberoam Endpoint Data Protection Cyberoam © Copyright 2010 Elitecore Technologies Ltd. All Rights Reserved. Thank You Contact us on [email protected] Thank You