symantec合作伙伴培训2015-1v2.0_第1页
symantec合作伙伴培训2015-1v2.0_第2页
symantec合作伙伴培训2015-1v2.0_第3页
symantec合作伙伴培训2015-1v2.0_第4页
symantec合作伙伴培训2015-1v2.0_第5页
免费预览已结束,剩余98页可下载查看

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

依旧是全球最大的公司APRIL

1982

/

FOUNDED#1

SECURITY

COMPANY

IN

THE

WORLD

378

/FORTUNE

500

9,800

/

EMPLOYEES

WORLDWIDE2,700

/

GLOBAL

PATENTSLARGEST

CIVILIAN

IN

LIGENCE

NETWORKGLOBAL

HEADQUARTERS

/

MOUNTAIN

VIEW,

CA2EnterpriseSecurityMessageMgmt

&

ArchivingAvailability

&CompliancePC

DesktopProtectionPC

Desktop

StorageEnterpriseSecurity

&

Application

MgmtEnd

PointCompliance

&Denter

MgmtGlobalIn

ligence

&

Managed

ServicesEncryption,

Authentication&

Data

ProtectionLifecycle

Management

DLPVirtualization

SaaSArchivingMobileManagementIdentity

ManagementMobile

Data

ProtectionUnifiedSecurity1990’s

2000

2002

2003

2004

2005

2006/72008/92010

2012

2013

2014过往多年企业收购历史Copyright

©

2015

Symantec

Corporation3过往多年企业收购历史Copyright

©

2015

Symantec

Corporation4过往多年企业收购历史Cyber

Security

ServicesThreat

ProtectionUnified

Securityytics

PlatformInformation

ProtectionCopyright

©

2015

Symantec

Corporation5启动全新的企业Cyber

Security

ServicesMonitoring

,

Incident

Response,

Simulation,

Adversary

Threat

In

ligenceAdvanced

Threat

Protectionacross

all

Control

PointsIntegrated

Forensicsand

Remediation

within

each

Control

PointProtectionof

On

Premise,

Virtual,

and

Cloud

Server

WorkloadsCloud-based

Management

for

Endpoints,

D

enter,

and

GatewaysUnified

SecurityBig

data

security ytics;

available

to

customersin

self-service

modeemetry

andLogCollectionandManagementUnified

IncidentManagementand

CustomerHubInline

Integrationwith

Detection

andProtection

EnginesGlobalThreatIn

ligenceAdvanced

Threatand

BehavioralyticsThreat

Protection

Information

ProtectionENDPOINTS

D

ENTER

GATEWAYS

DATA

ACCESSIntegrated

Data

and

Identity

ProtectionCloud

Security

Broker

for

Cloud

and

Mobile

AppsCloud-based

Key

ManagementCloud- ,

Mobile-

ArchitectureUsersDataAppsCloudDevicesNetworkDenterCopyright

©

2015

Symantec

Corporation6Symantec合作伙伴培训2015-1

v2.0.2Presenter’s

Title

Here培训日程Copyright

©

2015

Symantec

Corporation81Symantec企业2Symantec

Endpoint

Protection终端安全3Symantec

D enter

Security数据中心安全4Symantec

Advanced

Threat

Protection

高级

保护Symantec企业9当前企业安全环境者的变化更加迅速数字 在上升更智能零日安全不同类型的结构都在5

of

6

largecompaniesattacked317M

newmalwarecreated1M

newthreatsdaily60%

ofattacksed

SMEs113%increase

inransomware45X

moredevicesheldhostage28%

of

malwarewas

VirtualMachine

AwareTop

5unpatched

for295

days2424all-timehighHealthcare+

37%Retail+11%Education+10%ernment+8%Financial+6%Source:

Symantec

Internet

Security

Threat

Report

2015ISTR互联网安全

报告中文报告

:hs/1sjOGyULCopyright

©

2015

SymantecCorporation10重要的趋势变化在重塑企业安全市场终端安全市场的再次复兴Rapid

shift

to

mobile

andIoT逐渐消亡的企业边界Decreasinglyrelevant

with

“fuzzy”

perimeter云服务被越来越多的采用Enterprise

data

and

applications

moving

to

cloud服务开始取代传统的“盒子”Security

as

a

Service;

box

fatigue网络ernments

and

regulators

playing

ever

larger

role11Copyright

©

2015

SymantecCorporationSymantec

企业安全|

技术被广泛认可#1

share;AAA

ratingninequarters

in

a

row终端安全#1

share;

100%

uptime

with<0.0003%

FPs

5

years

in

a

row邮件安全#1

DLP

share;100%

of

Fortune

100数据保护#1share6Blookups/day服务13B

validations

everyday100%

uptime

last

5

years与认证管理安全服务12

Yrs

Gartner

MQ

leader30B

logsyzed/dayCopyright

©

2015

SymantecCorporation12Symantec

企业安全|

独一无二的视野5千7百万传感器部署在157

国家与地区1.75亿终端1.82亿

web

每年被3.7万亿行的安全元数据100Billionmore/month9响应中心500+rapid

security

responseteam30%全球企业的相互通信邮件被

扫描1.8BillionwebrequestsCopyright

©

2015

SymantecCorporation13Symantec

企业安全|

解决方案防护解决方案ENDPOINTS

D

ENTER

GATEWAYSAdvanced

Threat

Protection

Across

All

Control

PointsBuilt-In

Forensicsand

Remediation

Within

Each

Control

PointIntegrated

Protection

of

Server

Workloads:

On-Premise,

Virtual,

and

CloudCloud-based

Management

for

Endpoints,

D

enter,

and

Gateways的安全分析平台Log

andemetryCollectionUnified

IncidentManagement

andCustomer

HubInline

Integrationsfor

Closed-loopActionable

In

ligenceRegional

andIndustryBen

arkingIntegrated

ThreatandBehavioralysis信息防护解决方案DATA

IDENTITIESIntegrated

Data

and

Identity

ProtectionCloud

Security

Broker

for

Cloud

and

Mobile

AppsUser

andBehavioral

yticsCloud-based

Encryption

and

Key

ManagementUsersDataAppsCloudEndpointsGatewaysData

Center计算机相关安全服务Monitoring,

Incident

Response,

Simulation,

Adversary

Threat

InligenceCopyright

©

2015

SymantecCorporation14Cyber

Security

ServicesUnified

Securityytics

PlatformInformation

ProtectionDATA

IDENTITIESThreat

ProtectionENDPOINTS

D ENTER

GATEWAYS防护Copyright

©

2015

SymantecCorporation15即使使用最好的防护技术,仍然不能

所有StopingAttacksUnderstandingWhere

ImportantData

Is

&

Who

CanAccess

It准备

防护

检测Finding

Incursions响应Containing

&RemediatingProblems恢复RestoringOperations安全防护技术依旧很重要……但用户还需要做好被 的准备Copyright

©

2015

SymantecCorporation16防护需求

|

更完整的管理生命周期17Source:

Gartner预防、Proactive

riskysisPredict

attacksBaseline

systemsPrevent

issuesDivert

attackersHarden

and

isolate

systemsContain

issuesConfirm

and

prioritize

riskDetect

issuesRemediate/

Make

changeDesign/

Model

change响应、、防护检测、Investigate/

ForensicsAdvanced

ThreatProtectionCopyright

©

2015

Symantec

CorporationSymantec

防护|技术发展所有安全控制点中集成ATP高级

防护在所有控制点中内置取证与修复功能在本地、虚拟化和云环境中的数据中心上实现服务器负载防护提供终端、数据中心及网关的云端管理功能集成,包括网关自身部署在云端将移动设备、PC

&MAC的终端安全、终端管理、终端加密及高级防护集成AdvancedThreatProtectionNetwork/GatewaysDataCenterEndpointsCopyright

©

2015

SymantecCorporation18保护引擎检测引擎Symantec防护|

创新且被证明的技术信誉检查InsightDetermines

the

safety

of

files

&

websites

usingthe

“wisdom

of

thecrowd”ysis,heuristics,

and

link

followingto

find edthreats分析SkepticUses

predictive高级

检查for

malware

ysisCynicCloud

based

sandboxingand

detonation

engine事件关联分析SynapseCorrelates

securityevents

across

thecontrol

pointsPEPBlocks

exploits

ofknown

&unknownvulnerabilities行为分析SONARFinely

tuned

and

highlyperformant

engine

thatenables

flightrecorder-likesystem

monitoringCopyright

©

2015

SymantecCorporation19Symantec防护|

关键信息汇总高级

防护Global

In

ligenceExported

DataCloud

SandboxAdvanced

Threat

ProtectionCorrelation

PrioritizationEndpointNetwork3rd

partyofferings取证与修复技术Endpoint

Protection

(SEP)FlightRecorderIoC Repair

andSearch

RemediationProactiveExploit

ProtectionGlobal

In

ligenceed

Attack

Visualization服务器工作负载保护D enter

Security

(DCS)File

IntegrityMonitoringApplication Control

&Hardening

ComplianceCopyright

©

2015

SymantecCorporation20Symantec

Endpoint

Protection终端安全Latest

Available

Version:

12.1.6

MP1aSEP最好的企业终端安全网络保护Blocks

malwarebefore

it

spreadstoyour

machineand

controlstraffic高级

代码扫描Blocks

suspiciousfiles

–

even

thosewith

no

fingerprint–

before

theycan

run

and

stealyour

dataInsight文件信誉Safety

ratings

forevery

singlesoftware

file

onthe

planet,

anduses

this

to

blocked

attacksSONAR行为控制Blocks

softwarewith

suspiciousbehaviors

tostopadvanced

threats强力修复工具Aggressive

SMRtechnology

rootsoutentrenchedinfections

and

killsthem

in

secondsCopyright

©

2015

SymantecCorporation22Symantec

─文件信誉一种

性的基础技术,基于Symantec全球1.75亿个终端的安全评级信息(信誉)提供对新

的预先保护。Insight技术集成在SEP12.1中,通过文件信誉对可能存在

进行判断,包括的验证与豁免,同时提升性能。EXEDLLCOMHashSourceCountRatingAF34CD150MTrustedEA2101D120MTrusted5FAEE67Bankofnikolai.ru6malicious23FB12372unprovenCopyright

©

2015

Symantec

Corporation23Symantec—文件信誉Insight

–

优化扫描技术Skips

any

file

we

are

sure

is

good,leading

to

much

faster

sc

s传统扫描方式H

as

•t

o•scan

•ever

y

•fi

le通过Insig

ht实现的更快速文件扫描

所有终端侧的安全防护与清除技术在执行修复及移除操作前检测文件的信誉,确保不删除错误文件

Symantec一个提交系统检测每定义签名的文件信誉信息,已确保没有错误数据Insight用以消除误报Copyright

©

2015

SymantecCorporation24行为分析检测技术•可以的检测。但是其外观,以躲避基于特征制造者的目标,即欺骗、

、故意破坏以及诽谤却一成不变。SONAR在进程运行时

其行为,例如,尝试更改浏览器主页,安装浏览器

,击键以及其他近1400项行为。基于人工智能的分类引擎人工编写的行为特征基于行为的策略锁定Norton

CommunityWatchOpt

in

program

to

collectanonymous

dataWorld’s

largest

nexus

of

behavioral

profilesMachine-Learning

Engineyzes

behavioral

patternsClassification

RulesClassifies

Applications

asGood

or

BadCopyright

©

2015

SymantecCorporation25容易被忽视的...SEP还可以提供Tightlycontrolapplicationsthrough

advancedwhi isting

andblacklisting系统锁定Monitor

andcontrolapplicationsbehavior应用控制Restrict

and

enableaccess

to

thehardwarethatcanbe

used设备控制Ensures

endpointsare

protected

andcompliant完整性报告与分析Multi-dimensionalysis,

robustgraphical

reporting,and

an

easy-to-usedashboardCopyright

©

2015

SymantecCorporation26系统锁定,应用程序黑白白主要用于白

用于系统应用的锁定控制,通过扫描指定终端的,对扫描的不允许员工安装的应用运行后在下发至策略中执行锁定。这是时只有被允许(

过 的)的应用程序才可以执行。Copyright

©

2015

SymantecCorporation27可自定义的主机完整性检查无比强壮的完整性检查功能自定义检查语法,If…Then…Else配置检查项目包括:预定义的安全检查模版,如终端安全策略等表/Registry

entries—exist,

specificvalue,文件/Files—exist,

date,size,checksum,more补丁/Patches

installed进程/版本/Process

running,OS

version

More检查失败的修复措施执行 表修改、运行

、 执行安装程序Copyright

©

2015

SymantecCorporation28SEP依旧是终端安全技术市场的

者*Source:

Gartner,

Inc.,

Magic

Quadrant

for

Endpoint

Protection

Platforms,

January

2015Forrester

Research,

Inc.,

The

Forrester

Wave™:

Endpoint

Security,

Q1

2013IDC

Market

Share

ysis:

Worldwide

Endpoint

Security2014-2018

Forecast

and

2013

Vendor

Shares,

August

2014#1Protection#1Performance#1IDC

Market*

ShareA

Leader*Gartner

MQ&Forrester

WaveGlobal

MarketChina

MarketCopyright

©

2015

SymantecCorporation29SEP在多个机构的获得认可Copyright

©

2015

SymantecCorporation30Linux

Operating

systemsCentOS6U4,

6U5;

32-bit

and

64-bitDebian

6.0.5

Squeeze;

32-bit

and

64-bitFedora

16,

17;

32-bit

and

64-bitNovell

Open

Enterprise

Server

(OES)

2

SP2and

2SP3running

SUSE

Linux

EnterpriseServer

(SLES)

10

SP3;

32-bit

and

64-bitNovell

Open

Enterprise

Server

(OES)11

and

11

SP1

running

SUSE

Linux

Enterprise

Server(SLES)

11

SP1

and

SP2;

64-bitOracle

Linux

5U8,

5U9,

6U2,

6U4,

6U5;

64-bitRed

HatEnterprise

Linux

Server

(RHEL)

5U7

-

5U10,

6U2

-

6U5;

32-bit

and

64-bitSUSE

Linux

Enterprise

Server

(SLES)

10

SP3,

10

SP4,

11

SP1

-11

SP3;

32-bit

and

64-bitSUSE

Linux

Enterprise

Desktop

(SLED)

10

SP3,

10

SP4,

11

SP1

-

11

SP3;

32-bit

and

64-bitUbuntu

Server11.10,

12.04,

12.04.2,

13.04;

64-bitUbuntu

Desktop

11.10,

12.04,

12.04.2,

13.04;

64-bitSEP丰富的操作系统平台支持Windows

Embedded

Point

of

Service

( OS)

(32-bit,

SP3)Windows

Embedded

Standard

7

(32-

and

64-bit)Windows

Embedded

POSReady

7

(32-

and

64-bit)Windows

Embedded

Enterprise

7

(32-

and

64-bit)Windows

Embedded8

Standard

(32-

and

64-bit)Windows

Embedded8.1

Industry

Pro

(32-

and

64-bit)Windows

Embedded

8.1

Industry

Enterprise

(32-

and

64-bit)Windows

Embedded8.1

Pro(32-

and

64-bit)Windows

Operating

system

(desktop)Windows

XP

Home

or

Professional

(32-bit,

SP3;

64-bit,

allSPs)Windows

XP

Embedded

(SP3)Windows

Vista

(32-bit,

64-bit)Windows

7

(32-bit,

64-bit,

RTM

and

SP1)Windows

7

Embedded

StandardWindows

8

(32-bit,

64-bit)Windows

8

Embedded(32-bit)Windows

8.1

(32-bit,

64-bit,

including

Windows

To

Go)Windows

8.1

update

for

April

2014

(32-bit,

64-bit)Windows

8.1

update

for

August

2014

(32-bit,

64-bit)Windows

8.1

Embedded(32-bit)Windows

10Embedded

operating

systemWindows

Embedded

Standard

(WES)

2009

(32-bit,

SP3)Windows

Embedded

POSReady

2009

(32-bit,

SP3)Windows

Operating

system

(server)Windows

Server

2003

(32-bit,

64-bit,

R2,

SP1

or

later)Windows

Small

Business

Server

2003

(32-bit)Windows

Server2008

(32-bit,

64-bit,

R2,

SP1,

and

SP2)Windows

Small

Business

Server

2008

(64-bit)Windows

Essential

Business

Server

2008

(64-bit)Windows

Small

Business

Server

2011

(64-bit)Windows

Server

2012Windows

Server

2012

R2Windows

Server

2012

R2

update

for

April

2014Windows

Server

2012

R2

update

for

August2014Mac

Operating

systemMac

OS

X

10.8,

10.9,10.10Copyright

©

2015

SymantecCorporation31关于SEP一些你可能不知道的…Reduced-size

client

installation

package

&

reduced-size

definitionsSupport

for

Windows

Embedded

write

filtersIntegration

with

Symantec

Advanced

Threat

Protection:

EndpointSystem

lockdown

enhancementspile

for

Symantec

Endpoint

Protection

client

for

LinuxPower

Eraser

can

now

be

run

from

the

Symantec

Endpoint

Protection

Manager

consoleThe

Host

Integrity

policy

is

now

included

with

Symantec

Endpoint

ProtectionAutomated

removal

of

competitive

Anti ,

60+

vender,

300+

versionSupport

VMWare

vShield

Endpoint,

Performance

improvement

…

…Copyright

©

2015

SymantecCorporation32精简客户端与更新精简客户端会比标准客户端减少80-90%的磁盘空间占用,因为其只配置了近期的

定义信息。适用于

系统或VDI虚拟桌面等对

控空间较敏感的系统vShieldManagerSVAvShield

NetworkProduction

NetworkCVESylink提供vShield

Endpoint支持管理通讯共享通讯通过SAV虚拟

共

享每一个VM的扫描结果,一个VM进行扫描时将预先检查在SVA的共享信息中

是否存在已扫描过的结果,优化资源消耗Copyright

©

2015

SymantecCorporation34第 安全 自动移除,60+

vender,

300+

versionSEP可以在安装客户端时自动移除系统自带的其他安全详细的支持列表可以参考:http:

/docs/TECH195029(同时SEP提供竞争性报价,如可以提供 的其他安全

的合同,SEP将可使用更低的价格报价)*

Restriction*

ReKaspersky

AnCopyright

©

2015

Symantec

Corporation34Endpoint

ProtectionExpand

support

for

embeddedReduce

the

content

sizeWrite

filter

supportWindows

10

and

2015

supportClient

and

management

server

supportATP

EndpointInsight/submissions

redirection

and

failoverRetrieve

afilefrom

endpointBlacklistingBase-liningSEP–

12.1.6

(1H

2015)Protection

ImprovementsSystem

LockdownIntegrationwithInsightcheckingTrusted

Installers/UpdatersEnhanced

Usability

/ReducedAttack

SurfaceProactive

Exploit

Prevention*Reduced

attack

surfaceEDR

Capabilities*Network

/IsolationEnhancedclient-side

d ollection

via

SONARRemediationEvidence

of

Compromise

(EOC)

searchSEP

-

Lamb hini

(2H

2015)1H20152H20151H20162H2016ATP:

Endpoint

EnablementReal-time

client

communicationAdditional

emetryAdditional

EDR

Capabilities*Advanced

RemediationSecure

Virtual

ContainersMemoryCaptureLive

D

aptureSEP

(1H

2016)可能随时发生变化,以上 参考Copyright

©

2015

Symantec

Corporation35PEP

主动 利用防护每次一个新的进程被启动,就会

PEP程序We

modify

the

process

to

randomize

memory

layoutExploits

often

rely

on

specificmemory

locationsWe

hook

APIs

and

monitor

the

process

to

identifyexploit

techniques

and

block

themExploits

use

a

common

set

of

techniques

to

take

controlPEP降低了新的或旧的

被利用可能These

gaps

allow

attackers

to

take

controlThese

gaps

don’t

exist

in

more

modern

OSesFor

example,

Apple

won’t

let

code

run

unless

it

is

signed;Windows

will

run

any

code

anytimeProtection

provided

byPEP

(partial

list)Java

Security

Manager

protectionData

Execution

Prevention

(DEP)

onAddress

Space

Layout

Randomization

(ASLR)

onerwriteStructured

Exception

HandlinProtection

(SEHOP)Heap

Spray

Allocation

mitigationBottom-up

heap

randomizationNullPageReturn-Oriented-Programming

(ROP)

preventionLoadLib

prevention

on

shared

foldersProactive

Exploit

Prevention(PEP),

已知及未知的漏利用Copyright

©

2015

Symantec

Corporation36F&R

取证与修复Enterprise

Detection

andRemediation

(EDR)Once

an

attack

makes

it

inYou

want

to

findit

fastYou

want

to

neutralize

itYou

want

to

understand

the

scopeYou

want

to

collect

forensic

dataYou

want

to

remediateand

restoreCustomers

need

endpoint

tools

to

automate

this

processMore

importantly,

whenwe

want

to

have

these

sarovide

Incident

Response

on

retainer,ls

at

our

disposalFile

systemOur

EFA

componentsecurely

tracks

allfile

detailsRegistrySONAR

tracks

allregistry

changesMemorySONAR

has

directaccess

to

all

memory;enhancing

to

enablegreater

search

capabilityFile

accessAutoProtect

&SONARsee

all

file

access

eventsNetworkVantage

IPS

seesall

network

connectionsand

all

layers

of

trafficBehaviorSONAR

tracks

thousandsof

application

behaviorsin

the

kerneland

inusermodeForensics

&RemediationCopyright

©

2015

Symantec

Corporation37用户需要快速了解,响应并修复发现的安全问题,这方面的需求被称为EDR但 还是 非常多的问题与质疑…••无法衡量SEP是否用好与坏,目前是否是最优的架构及配置呢?在虚拟化环境下需要做什么特别的配置吗?

优化性能呢?上个月

事件8k+,这个月12k+,这证明企业安全环境越来越差了吗?SEP无法正常升级,磁盘空间被大规模占用?有办法解决吗?SEP安装后系统的启动速度,与运行速度都大幅度降低!SEP对一些

漏报,而其他安全

可以检测出来!除去故障类问题( )多数用户的SEP问题集中在两个方面:当前SEP系统运行是否在最佳状态,策略设置是否合理没有方法判断,如何优化难于着手。SEP的服务交付标准没有清晰定义,单从SEP的事件数量变化难于衡量安全效率。Copyright

©

2015

Symantec

Corporation381.当前SEP系统运行是否在最佳状态,优化难于着手有些资源是可以充分利用的SEP所有版本的 说明,新功能说明以及操作系统支持情况说明http:

/docs/TECH163829SEP最佳实践文章集合http:

/docs/TECH181685Symantec™Endpoint

Protection

12.1.6安装和管理指南http:

/docs/DOC8645通过SEP 或者记录

非公司允许的应用 使用http:

/docs/TECH97618Symantec

的安全防护配置建议http:

/docs/TECH173752SEP

Review

and

Report报告PPT模版ht

/s/1i3KSV1zBest

PracticeInstallation

planningUpgrade

planningAdministrationPolicy

configurationFirewall

and

intrusion

preventionSecurityThreat

remediationVirtualizationOther

resourcesSEP地址:代码:T201410221424Copyright

©

2015

Symantec

Corporation39例:SEP有漏报!客户环境中的SEP被正确使用了吗?问题1:当企业网络中部署Web

,用户终端要通过 并使用

口令 网络,SEPM中配置了对应终端与服务器的Web 的有效用户名口令。这时SEP那些功能不能正常使用?问题2:SEP12.1对比SEP11.x最大的功能改变在哪里?以上两个问题答案是一样的:Insight文件信誉SONAR行为控制Insight与SONAR

分别从文件信誉与行为特征方面检测 代码,弥补传统定义检查的不足,但Insight的数据更新不通过LiveUpdata完成,且由于工作机制问题导致其无法在认证

环境下使用。SONAR的正常工作需要依赖Insight的数据,如果SEP无法获取Insight数据,SONAR也将无法正常工作。这种情况

需要将制定的URL地址在用户的Web 侧进行例外这些URL时不进行认证。配置,设置白 允许用户终端在通过Web详细信息可以参考以下KB:http:

/docs/TECH162286Copyright

©

2015

Symantec

Corporation402.SEP的服务交付标准没有清晰定义,难于衡量安全效率建议从两个指标维度进行数据分析:环境指标:服务器指标:DB数据库配置参数、数据库备份调度任务、SEPM应用及操作系统日志分析,用于衡量服务器运行状态是否稳定;终端指标包括终端类型(部门)分布、SEP终端安装率、SEP当前版本分布、SEP

签名版本分布、

定义更新频率、全盘扫描频率、

IPS签名版本、策略下发版本分布、安全扫描成功率,安全策略配置分布等指标,用于判断部署SEP的客户端是否达到了所希望的标准(比例或阀值)。服务器与客户端之间通讯参数调整,服务器与客户端带宽环境;改善优化SEP相关策略与环境:分析原因如:网络带宽导致更新问题、策略推送时间问题、用户长时间出差

漫游等。根据没有达标的原因通过SEP策略调整与管理 ,加强终端管理与安全优化。环境指标

改善优化SEP相关策略与环境原因分析Copyright

©

2015

Symantec

Corporation412.SEP的服务交付标准没有清晰定义,难于衡量安全效率事件指标:安全事件与安全日志的分析,例如,各个部们安全数据分布,由各个SEP组件

的

,次数,受影响主机数量及比例,HI主机完整性检查情况,的类型,

严重Helpdesk事件处理量等。染数量,未清除

代码类型统计、数量统计,针对新型

代码的提交分析。改善优化SEP以外的其他安全控制措施:主要事件的来源分析,网络事件以IP为主,但多数事件需要从

分析

代码事件的来源,例如网络共享、邮件、上网浏览

、U盘

;对未完全清除的

代码应该重点关注后期查杀;基于分析结果,可对SEP的

系统(非SEP)进行调研与改善;这也是多数情况下帮助客户发现安全问题,引入新的安全解决方案的切入点!事件指标改善优化SEP以外的其他安全控制措施原因分析Copyright

©

2015

Symantec

Corporation42关于SEP

RISK

LOGS的分析计算机名源风险名称出现次数文件路径说明实际的操作所需的操作次要操作事件日期事件时间域用户名服务器客户端组源计算机名源计算机IP应用程序名称应用程序哈希哈希算法公司版本文件大小检测原因最小敏感度级别允许应用程序的原因Web域站点者普及率信誉最先看到的URL跟踪状态事件结束日期时间戳操作系统代码 源分析中文件路径信息是最关键最主要判断信息,例如,如果发现的问题来自于浏览器

目录则 代码可能来自于Web

,Outlook临时 则有可能是邮件传入,H:I:盘符根 可能来源是USB,//

.X来源是某一台主机文件共享,但要排除某些 对所有文件 的问题,所以一般建议分析前对一个终端产生非常大量事件的情况预先进行排除,或者在源中对只保留自动防护的事件数据。通过网络

的

代码也会在Log的来源字段显示,需要在SEP中开启来源追溯。对判断代码事件的传播有所帮助。如果被 程序存在签名信息,这些也会存在相关信息,多用于辅助判断 来源Web

的事件中会包含详细的目标信息,用于具体事件详细分析Insight文件信誉数据会在此显示根据客户端组可以分析被客户端分布情况Copyright

©

2015

Symantec

Corporation43ITytics

2.1

forSEPCopyright

©

2015

SymantecCorporation44MSSQLSEPMDBITA

DBOLAPCubesReporting

ServicesRaw

LogsIT

ytics独立于SEPM的安装,且它对SEP用户完全免费,但它需要独立的SQLServer工作环境,所以唯一可能需要考虑的就是服务器与SQL的成本IT ytics主要用于日志数据分析、报表输出、SEP合规与环境数据分析等使用场景,节省大量手工数据处理的时间,IT

ytics直接从SEPM数据库 数据,并进行挖掘分析,Online ytical

Processing

Server

提供 数据分析模型安装文件及文档在SEP12.1.5及以后版本的Tools

下根据事件来源向客户建议新的方案Copyright

©

2015

SymantecCorporation45代码与 来源于Web /应用程序代码与

来源于邮件代码与来源于NAS文件共享代码与来源于企业 应用代码与来源于SharePointSymantec

Advanced

Threat

Protection:NetworkSymantecMessaging

Gateway

/

8340

&

8380Symantec

Web

Gateway串联阻断、旁路检测、

集成,适用与NAT或 环境Symantec

D enterSecurity:

DataStore

Unified

ProtectionThreat

Protection

-Content

FilteringDLP

IntegrationData

Insight

–EncryptionUnified

Policy

andAdministrationAcross

Critical

Applications

&

DataMessaging

(Exchange)NAS

–

FilersNetAppSharePointCloud

AppsDSS

Deployed

across

Virtual

&CloudSecurity

Response

Insight

Reputation通过以下位置你可以随时

测试 并获取LicenseSymantec

Messaging

Gateway

(虚拟机版本)https:/

/Vrt/offer?a_id=93532Symantec

Mail

Security

for

Exchangehttps:/

/Vrt/offer?a_id=20032Symantec

Protection

Engine

for

Cloud

Serviceshttps:/

/Vrt/offer?a_id=146739Symantec

Protection

Engine

for

Network

Attached

Storagehttps:/

/Vrt/offer?a_id=146740Symantec

Protection

for

SharePoint

Servershttps:/

/Vrt/offer?a_id=132710Copyright

©

2015

SymantecCorporation46关于Symantec

Advanced

ThreatProtection:Network会与ATP:Endpoint及ATP:年下半年发布.提供同时在2015的控制界面关于Symantec

D enter

Security:DataStore会在2015年四季度发布,提供与D enter:Server,

ServerAdvanced相同的管理控制台与界面为什么 不再提及SNAC?Copyright

©

2015

SymantecCorporation47移动办公变成IT发展趋势移动设备不但需要在企业网络中使用,也需要在企业网络外使用公有云服务被 的采用,PaaS,SaaS平台被越来越多的使用,企业数据中心在外延那如何确保终端部署了必要的,达到了合规策略?以网络为控制点的准入技术正在向以应用自身为控制点的技术转移,通过跨多应用的集中控制实现企业应用 的基本准入控制。同时通过SAML将公有云,本地系统,控制 。包括对终端的合规性检查、安全 安装检查也将在未来在Portal、SSO与

移动设备与PC的认证过程中实现。根本的原因,企业网络边界在逐渐的消亡!!!关于现有SEP现有的用户,你可以做的…客户自行

的情况,通过巡检服务帮助用户发现问题,提供额外的维保或驻点服务已经在帮助用户进行服务的情况,基于

之前谈到的内容,发掘新的服务价值服务内容可以包含:SEP基于最佳实践的巡检,SEP环境指标与事件指标梳理,ITA数据分析平台建设,SEP定期报告与日志分析,SEP 驻场服务对于目前没有能力交付服务的合作伙伴,通过引入Symantec

Professional

Services,由的Consulting

Service

协助合作伙伴向用户交付标准化的服务内容,完成交付的同时培训合作伙伴,确保日后的持续交付能力。根据服务过程中的事件分析,向用户提供新的方案,寻找新的业务机会!当然通过用户现有已

的SEP,能做的还不止这么多…Copyright

©

2015

SymantecCorporation48MDM

is

Free!!从现有开始您将可以获取免费的Symantec

MDM移动设备管理解决方案的使用权,它与其他您在使用的Symantec

一样将包含完整的7*24小时售后技术支持服务,帮助您的企业提高移动生产力。只要您的企业现已 以下产品并处于维保期限内,同时License数量等于或超过1000个,便符合资格。Symantec

IT

Management

Suite

7.5Symantec

Client

Management

Suite

7.5Symantec

Endpoint

Protection

12.1Symantec

Protection

Suite

Enterprise

Edition

4.0只要您企业所使用的上述 持续 维保服务,您将持续获得MDM的持续的使用权获取License地址:

/li

censemgmt/MDMLanding.jspCopyright

©

2015

SymantecCorporation49的Web管理界面,集成化的解决方案,用户可以利用MDM在其基础上增加所需组建Device

Management(MDM)针对移动设备的配置、控制和管理企业应用商店分发应用及内容基于设备的策略App

Management&Protection

(MAM)安全配置与管理移动应用及其数据基于应用的策略(移动应用的封装打包)增强安全的企业应用包含Workforce

AppsWorkforce

Apps配置管理Symantec企业相关移动应用包含Work

Mail,WorkWeb和Work

FileApp及邮件

网关Threat

Protection让移动设备远离及有风险的应用。集中的移动安全管理基于设备安全态势实施控制策略Symantec

Mobility

SuiteCopyright

©

2015

Symantec

Corporation50在MDM基础上的Upselling,每个模块都可以单独销售即使客户没有MDM或在使用其他的EMM或MDM,(MAM由于国内Android碎片化问题谨慎

)Symantec

D数据中心安全enter

SecurityLatest

Available

Version:

6.5v6.6

will

be

on

September

2015数据中心的发展 的方向所有的基础设施资源都将被虚拟化以服务的方式提供(Delivered

as

Service)数据中心完全可通过软件实现自动化的管控SDDC中安全技术的发展最重要的

变化是交付方式,而不是交付内容,定义的安全控制,加速部署时间是SDDC中安全防护的关键。Copyright

©

2015

SymantecCorporation52Symantec

Denter

Security

:

ServerServersPhysical&Virtual

ServeDCS:Server*在新的DCS6.6中,用户即使没有现在无 的虚拟主机 防护与也可以使用

S实防护无

的

防护与(集成Insight)网络

防护基于Hypervisor安全虚拟设备提供虚拟主机保护第一家安全厂商宣布全面支持NSX持续保护无论虚拟主机是否发生迁移,安全控制自可动部署充分集成Symantec现有技术优势

代码防护与Insight在Guest主机内实现

文件增强的扫描缓存技术,网络

防护技术集成通过Operations

Director实现多项安全控制措施的自动化部署,该组建免费集成在所有DCS

中全新Web管理界面将DCS所有解决方案将都由其

管理,包括DCS:

Data

store,

Server,

Server

Advanced在内V(SoftwaS

ecCopyright

©

2015

SymantecCorporation53DCS:

Server技术原理Security

AdminTrafficSteeringSymantec

Denter

ConsoleSecurity

PolicyNSXControllerCopyright

©

2015

SymantecCorporation54代码安全防护工作流程*VMware

重新分配

GVM

X

到

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论