We feel that this is the next level of security after last years 'defense in depth' approach and negates issues such as remote access users, contractual staff walking in with untrusted machines and zero day.
Blink will replace many point solutions that may be deployed to deal with specific issues with multiple managers, local GUI's and policies.
Blink incorporates the following features and is deployed on each host within the enterprise with central enforcement of policy and local scanning and blocking of malicious activity.
Application Policy Control
Protection against abusive application behaviour, such as downloading files via P2P, Instant Messenger, running a port scan, and against application hijacking via DLL control hooking. By strictly monitoring approved applications, policies can be implemented and administered.
Anti-Spyware Protection
Blink will actively block malware instances from being loaded into memory and give the option to quarantine or remove the suspected code
Identity Theft Protection / Anti-Phishing
With its protocol analysis engine, Blink is able to detect and classify phishing attempts made via various protocols. This includes images used to convey phishing attacks such as Bank logos etc
System and Application Firewall Technology
Performing analysis of each packet of network traffic entering the system, Blink is able to allow or deny traffic based on a set of predetermined firewall rules
Generic Buffer Overflow Protection
Protection from unknown buffer overflow attacks against network application by simply analysing buffer size rules
Non-Signature Attack Prevention
Blink detects and blocks attacks without signature profiles translating into complete protection even when threats are wild before vendor patch/signature is released. Zero Day protection!
Inbound and Outbound Port Blocking
Connections are controlled based on protocol, port and communicating host address. This negates Trojan activity and worm propagation
Non-Intrusive Protocol Analysis
Blink examines network traffic before it reaches the application layer, preventing malicious activity before it can execute
This is a very well thought out solution and deals with many issues with a single deployment. It considers the status of the local host and blocks malicious code and activity irrespective of its type and route of access. It also assumes outbound activity as malicious, allows lockdown and, by analysing many layers determines risk before it can have any effect on the system, whether it is on the LAN or out of the office.
Please contact us on 01782 720229 if you would like to know more or email info@dayzerosecurity.com.
|