下载本文档
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
依旧是全球最大的公司APRIL
1982
/
FOUNDED#1
SECURITY
COMPANY
IN
THE
WORLD
378
/FORTUNE
500
9,800
/
EMPLOYEES
WORLDWIDE2,700
/
GLOBAL
PATENTSLARGEST
CIVILIAN
IN
LIGENCE
NETWORKGLOBAL
HEADQUARTERS
/
MOUNTAIN
VIEW,
CA2EnterpriseSecurityMessageMgmt
&
ArchivingAvailability
&CompliancePC
DesktopProtectionPC
Desktop
StorageEnterpriseSecurity
&
Application
MgmtEnd
PointCompliance
&Denter
MgmtGlobalIn
ligence
&
Managed
ServicesEncryption,
Authentication&
Data
ProtectionLifecycle
Management
DLPVirtualization
SaaSArchivingMobileManagementIdentity
ManagementMobile
Data
ProtectionUnifiedSecurity1990’s
2000
2002
2003
2004
2005
2006/72008/92010
2012
2013
2014过往多年企业收购历史Copyright
©
2015
Symantec
Corporation3过往多年企业收购历史Copyright
©
2015
Symantec
Corporation4过往多年企业收购历史Cyber
Security
ServicesThreat
ProtectionUnified
Securityytics
PlatformInformation
ProtectionCopyright
©
2015
Symantec
Corporation5启动全新的企业Cyber
Security
ServicesMonitoring
,
Incident
Response,
Simulation,
Adversary
Threat
In
ligenceAdvanced
Threat
Protectionacross
all
Control
PointsIntegrated
Forensicsand
Remediation
within
each
Control
PointProtectionof
On
Premise,
Virtual,
and
Cloud
Server
WorkloadsCloud-based
Management
for
Endpoints,
D
enter,
and
GatewaysUnified
SecurityBig
data
security ytics;
available
to
customersin
self-service
modeemetry
andLogCollectionandManagementUnified
IncidentManagementand
CustomerHubInline
Integrationwith
Detection
andProtection
EnginesGlobalThreatIn
ligenceAdvanced
Threatand
BehavioralyticsThreat
Protection
Information
ProtectionENDPOINTS
D
ENTER
GATEWAYS
DATA
ACCESSIntegrated
Data
and
Identity
ProtectionCloud
Security
Broker
for
Cloud
and
Mobile
AppsCloud-based
Key
ManagementCloud- ,
Mobile-
ArchitectureUsersDataAppsCloudDevicesNetworkDenterCopyright
©
2015
Symantec
Corporation6Symantec合作伙伴培训2015-1
v2.0.2Presenter’s
Title
Here培训日程Copyright
©
2015
Symantec
Corporation81Symantec企业2Symantec
Endpoint
Protection终端安全3Symantec
D enter
Security数据中心安全4Symantec
Advanced
Threat
Protection
高级
保护Symantec企业9当前企业安全环境者的变化更加迅速数字 在上升更智能零日安全不同类型的结构都在5
of
6
largecompaniesattacked317M
newmalwarecreated1M
newthreatsdaily60%
ofattacksed
SMEs113%increase
inransomware45X
moredevicesheldhostage28%
of
malwarewas
VirtualMachine
AwareTop
5unpatched
for295
days2424all-timehighHealthcare+
37%Retail+11%Education+10%ernment+8%Financial+6%Source:
Symantec
Internet
Security
Threat
Report
2015ISTR互联网安全
报告中文报告
:hs/1sjOGyULCopyright
©
2015
SymantecCorporation10重要的趋势变化在重塑企业安全市场终端安全市场的再次复兴Rapid
shift
to
mobile
andIoT逐渐消亡的企业边界Decreasinglyrelevant
with
“fuzzy”
perimeter云服务被越来越多的采用Enterprise
data
and
applications
moving
to
cloud服务开始取代传统的“盒子”Security
as
a
Service;
box
fatigue网络ernments
and
regulators
playing
ever
larger
role11Copyright
©
2015
SymantecCorporationSymantec
企业安全|
技术被广泛认可#1
share;AAA
ratingninequarters
in
a
row终端安全#1
share;
100%
uptime
with<0.0003%
FPs
5
years
in
a
row邮件安全#1
DLP
share;100%
of
Fortune
100数据保护#1share6Blookups/day服务13B
validations
everyday100%
uptime
last
5
years与认证管理安全服务12
Yrs
Gartner
MQ
leader30B
logsyzed/dayCopyright
©
2015
SymantecCorporation12Symantec
企业安全|
独一无二的视野5千7百万传感器部署在157
国家与地区1.75亿终端1.82亿
web
每年被3.7万亿行的安全元数据100Billionmore/month9响应中心500+rapid
security
responseteam30%全球企业的相互通信邮件被
扫描1.8BillionwebrequestsCopyright
©
2015
SymantecCorporation13Symantec
企业安全|
解决方案防护解决方案ENDPOINTS
D
ENTER
GATEWAYSAdvanced
Threat
Protection
Across
All
Control
PointsBuilt-In
Forensicsand
Remediation
Within
Each
Control
PointIntegrated
Protection
of
Server
Workloads:
On-Premise,
Virtual,
and
CloudCloud-based
Management
for
Endpoints,
D
enter,
and
Gateways的安全分析平台Log
andemetryCollectionUnified
IncidentManagement
andCustomer
HubInline
Integrationsfor
Closed-loopActionable
In
ligenceRegional
andIndustryBen
arkingIntegrated
ThreatandBehavioralysis信息防护解决方案DATA
IDENTITIESIntegrated
Data
and
Identity
ProtectionCloud
Security
Broker
for
Cloud
and
Mobile
AppsUser
andBehavioral
yticsCloud-based
Encryption
and
Key
ManagementUsersDataAppsCloudEndpointsGatewaysData
Center计算机相关安全服务Monitoring,
Incident
Response,
Simulation,
Adversary
Threat
InligenceCopyright
©
2015
SymantecCorporation14Cyber
Security
ServicesUnified
Securityytics
PlatformInformation
ProtectionDATA
IDENTITIESThreat
ProtectionENDPOINTS
D ENTER
GATEWAYS防护Copyright
©
2015
SymantecCorporation15即使使用最好的防护技术,仍然不能
所有StopingAttacksUnderstandingWhere
ImportantData
Is
&
Who
CanAccess
It准备
防护
检测Finding
Incursions响应Containing
&RemediatingProblems恢复RestoringOperations安全防护技术依旧很重要……但用户还需要做好被 的准备Copyright
©
2015
SymantecCorporation16防护需求
|
更完整的管理生命周期17Source:
Gartner预防、Proactive
riskysisPredict
attacksBaseline
systemsPrevent
issuesDivert
attackersHarden
and
isolate
systemsContain
issuesConfirm
and
prioritize
riskDetect
issuesRemediate/
Make
changeDesign/
Model
change响应、、防护检测、Investigate/
ForensicsAdvanced
ThreatProtectionCopyright
©
2015
Symantec
CorporationSymantec
防护|技术发展所有安全控制点中集成ATP高级
防护在所有控制点中内置取证与修复功能在本地、虚拟化和云环境中的数据中心上实现服务器负载防护提供终端、数据中心及网关的云端管理功能集成,包括网关自身部署在云端将移动设备、PC
&MAC的终端安全、终端管理、终端加密及高级防护集成AdvancedThreatProtectionNetwork/GatewaysDataCenterEndpointsCopyright
©
2015
SymantecCorporation18保护引擎检测引擎Symantec防护|
创新且被证明的技术信誉检查InsightDetermines
the
safety
of
files
&
websites
usingthe
“wisdom
of
thecrowd”ysis,heuristics,
and
link
followingto
find edthreats分析SkepticUses
predictive高级
检查for
malware
ysisCynicCloud
based
sandboxingand
detonation
engine事件关联分析SynapseCorrelates
securityevents
across
thecontrol
pointsPEPBlocks
exploits
ofknown
&unknownvulnerabilities行为分析SONARFinely
tuned
and
highlyperformant
engine
thatenables
flightrecorder-likesystem
monitoringCopyright
©
2015
SymantecCorporation19Symantec防护|
关键信息汇总高级
防护Global
In
ligenceExported
DataCloud
SandboxAdvanced
Threat
ProtectionCorrelation
PrioritizationEndpointNetwork3rd
partyofferings取证与修复技术Endpoint
Protection
(SEP)FlightRecorderIoC Repair
andSearch
RemediationProactiveExploit
ProtectionGlobal
In
ligenceed
Attack
Visualization服务器工作负载保护D enter
Security
(DCS)File
IntegrityMonitoringApplication Control
&Hardening
ComplianceCopyright
©
2015
SymantecCorporation20Symantec
Endpoint
Protection终端安全Latest
Available
Version:
12.1.6
MP1aSEP最好的企业终端安全网络保护Blocks
malwarebefore
it
spreadstoyour
machineand
controlstraffic高级
代码扫描Blocks
suspiciousfiles
–
even
thosewith
no
fingerprint–
before
theycan
run
and
stealyour
dataInsight文件信誉Safety
ratings
forevery
singlesoftware
file
onthe
planet,
anduses
this
to
blocked
attacksSONAR行为控制Blocks
softwarewith
suspiciousbehaviors
tostopadvanced
threats强力修复工具Aggressive
SMRtechnology
rootsoutentrenchedinfections
and
killsthem
in
secondsCopyright
©
2015
SymantecCorporation22Symantec
─文件信誉一种
性的基础技术,基于Symantec全球1.75亿个终端的安全评级信息(信誉)提供对新
的预先保护。Insight技术集成在SEP12.1中,通过文件信誉对可能存在
进行判断,包括的验证与豁免,同时提升性能。EXEDLLCOMHashSourceCountRatingAF34CD150MTrustedEA2101D120MTrusted5FAEE67Bankofnikolai.ru6malicious23FB12372unprovenCopyright
©
2015
Symantec
Corporation23Symantec—文件信誉Insight
–
优化扫描技术Skips
any
file
we
are
sure
is
good,leading
to
much
faster
sc
s传统扫描方式H
as
•t
o•scan
•ever
y
•fi
le通过Insig
ht实现的更快速文件扫描
所有终端侧的安全防护与清除技术在执行修复及移除操作前检测文件的信誉,确保不删除错误文件
Symantec一个提交系统检测每定义签名的文件信誉信息,已确保没有错误数据Insight用以消除误报Copyright
©
2015
SymantecCorporation24行为分析检测技术•可以的检测。但是其外观,以躲避基于特征制造者的目标,即欺骗、
、故意破坏以及诽谤却一成不变。SONAR在进程运行时
其行为,例如,尝试更改浏览器主页,安装浏览器
,击键以及其他近1400项行为。基于人工智能的分类引擎人工编写的行为特征基于行为的策略锁定Norton
CommunityWatchOpt
in
program
to
collectanonymous
dataWorld’s
largest
nexus
of
behavioral
profilesMachine-Learning
Engineyzes
behavioral
patternsClassification
RulesClassifies
Applications
asGood
or
BadCopyright
©
2015
SymantecCorporation25容易被忽视的...SEP还可以提供Tightlycontrolapplicationsthrough
advancedwhi isting
andblacklisting系统锁定Monitor
andcontrolapplicationsbehavior应用控制Restrict
and
enableaccess
to
thehardwarethatcanbe
used设备控制Ensures
endpointsare
protected
andcompliant完整性报告与分析Multi-dimensionalysis,
robustgraphical
reporting,and
an
easy-to-usedashboardCopyright
©
2015
SymantecCorporation26系统锁定,应用程序黑白白主要用于白
用于系统应用的锁定控制,通过扫描指定终端的,对扫描的不允许员工安装的应用运行后在下发至策略中执行锁定。这是时只有被允许(
过 的)的应用程序才可以执行。Copyright
©
2015
SymantecCorporation27可自定义的主机完整性检查无比强壮的完整性检查功能自定义检查语法,If…Then…Else配置检查项目包括:预定义的安全检查模版,如终端安全策略等表/Registry
entries—exist,
specificvalue,文件/Files—exist,
date,size,checksum,more补丁/Patches
installed进程/版本/Process
running,OS
version
More检查失败的修复措施执行 表修改、运行
、 执行安装程序Copyright
©
2015
SymantecCorporation28SEP依旧是终端安全技术市场的
者*Source:
Gartner,
Inc.,
Magic
Quadrant
for
Endpoint
Protection
Platforms,
January
2015Forrester
Research,
Inc.,
The
Forrester
Wave™:
Endpoint
Security,
Q1
2013IDC
Market
Share
ysis:
Worldwide
Endpoint
Security2014-2018
Forecast
and
2013
Vendor
Shares,
August
2014#1Protection#1Performance#1IDC
Market*
ShareA
Leader*Gartner
MQ&Forrester
WaveGlobal
MarketChina
MarketCopyright
©
2015
SymantecCorporation29SEP在多个机构的获得认可Copyright
©
2015
SymantecCorporation30Linux
Operating
systemsCentOS6U4,
6U5;
32-bit
and
64-bitDebian
6.0.5
Squeeze;
32-bit
and
64-bitFedora
16,
17;
32-bit
and
64-bitNovell
Open
Enterprise
Server
(OES)
2
SP2and
2SP3running
SUSE
Linux
EnterpriseServer
(SLES)
10
SP3;
32-bit
and
64-bitNovell
Open
Enterprise
Server
(OES)11
and
11
SP1
running
SUSE
Linux
Enterprise
Server(SLES)
11
SP1
and
SP2;
64-bitOracle
Linux
5U8,
5U9,
6U2,
6U4,
6U5;
64-bitRed
HatEnterprise
Linux
Server
(RHEL)
5U7
-
5U10,
6U2
-
6U5;
32-bit
and
64-bitSUSE
Linux
Enterprise
Server
(SLES)
10
SP3,
10
SP4,
11
SP1
-11
SP3;
32-bit
and
64-bitSUSE
Linux
Enterprise
Desktop
(SLED)
10
SP3,
10
SP4,
11
SP1
-
11
SP3;
32-bit
and
64-bitUbuntu
Server11.10,
12.04,
12.04.2,
13.04;
64-bitUbuntu
Desktop
11.10,
12.04,
12.04.2,
13.04;
64-bitSEP丰富的操作系统平台支持Windows
Embedded
Point
of
Service
( OS)
(32-bit,
SP3)Windows
Embedded
Standard
7
(32-
and
64-bit)Windows
Embedded
POSReady
7
(32-
and
64-bit)Windows
Embedded
Enterprise
7
(32-
and
64-bit)Windows
Embedded8
Standard
(32-
and
64-bit)Windows
Embedded8.1
Industry
Pro
(32-
and
64-bit)Windows
Embedded
8.1
Industry
Enterprise
(32-
and
64-bit)Windows
Embedded8.1
Pro(32-
and
64-bit)Windows
Operating
system
(desktop)Windows
XP
Home
or
Professional
(32-bit,
SP3;
64-bit,
allSPs)Windows
XP
Embedded
(SP3)Windows
Vista
(32-bit,
64-bit)Windows
7
(32-bit,
64-bit,
RTM
and
SP1)Windows
7
Embedded
StandardWindows
8
(32-bit,
64-bit)Windows
8
Embedded(32-bit)Windows
8.1
(32-bit,
64-bit,
including
Windows
To
Go)Windows
8.1
update
for
April
2014
(32-bit,
64-bit)Windows
8.1
update
for
August
2014
(32-bit,
64-bit)Windows
8.1
Embedded(32-bit)Windows
10Embedded
operating
systemWindows
Embedded
Standard
(WES)
2009
(32-bit,
SP3)Windows
Embedded
POSReady
2009
(32-bit,
SP3)Windows
Operating
system
(server)Windows
Server
2003
(32-bit,
64-bit,
R2,
SP1
or
later)Windows
Small
Business
Server
2003
(32-bit)Windows
Server2008
(32-bit,
64-bit,
R2,
SP1,
and
SP2)Windows
Small
Business
Server
2008
(64-bit)Windows
Essential
Business
Server
2008
(64-bit)Windows
Small
Business
Server
2011
(64-bit)Windows
Server
2012Windows
Server
2012
R2Windows
Server
2012
R2
update
for
April
2014Windows
Server
2012
R2
update
for
August2014Mac
Operating
systemMac
OS
X
10.8,
10.9,10.10Copyright
©
2015
SymantecCorporation31关于SEP一些你可能不知道的…Reduced-size
client
installation
package
&
reduced-size
definitionsSupport
for
Windows
Embedded
write
filtersIntegration
with
Symantec
Advanced
Threat
Protection:
EndpointSystem
lockdown
enhancementspile
for
Symantec
Endpoint
Protection
client
for
LinuxPower
Eraser
can
now
be
run
from
the
Symantec
Endpoint
Protection
Manager
consoleThe
Host
Integrity
policy
is
now
included
with
Symantec
Endpoint
ProtectionAutomated
removal
of
competitive
Anti ,
60+
vender,
300+
versionSupport
VMWare
vShield
Endpoint,
Performance
improvement
…
…Copyright
©
2015
SymantecCorporation32精简客户端与更新精简客户端会比标准客户端减少80-90%的磁盘空间占用,因为其只配置了近期的
定义信息。适用于
系统或VDI虚拟桌面等对
控空间较敏感的系统vShieldManagerSVAvShield
NetworkProduction
NetworkCVESylink提供vShield
Endpoint支持管理通讯共享通讯通过SAV虚拟
共
享每一个VM的扫描结果,一个VM进行扫描时将预先检查在SVA的共享信息中
是否存在已扫描过的结果,优化资源消耗Copyright
©
2015
SymantecCorporation34第 安全 自动移除,60+
vender,
300+
versionSEP可以在安装客户端时自动移除系统自带的其他安全详细的支持列表可以参考:http:
/docs/TECH195029(同时SEP提供竞争性报价,如可以提供 的其他安全
的合同,SEP将可使用更低的价格报价)*
Restriction*
ReKaspersky
AnCopyright
©
2015
Symantec
Corporation34Endpoint
ProtectionExpand
support
for
embeddedReduce
the
content
sizeWrite
filter
supportWindows
10
and
2015
supportClient
and
management
server
supportATP
EndpointInsight/submissions
redirection
and
failoverRetrieve
afilefrom
endpointBlacklistingBase-liningSEP–
12.1.6
(1H
2015)Protection
ImprovementsSystem
LockdownIntegrationwithInsightcheckingTrusted
Installers/UpdatersEnhanced
Usability
/ReducedAttack
SurfaceProactive
Exploit
Prevention*Reduced
attack
surfaceEDR
Capabilities*Network
/IsolationEnhancedclient-side
d ollection
via
SONARRemediationEvidence
of
Compromise
(EOC)
searchSEP
-
Lamb hini
(2H
2015)1H20152H20151H20162H2016ATP:
Endpoint
EnablementReal-time
client
communicationAdditional
emetryAdditional
EDR
Capabilities*Advanced
RemediationSecure
Virtual
ContainersMemoryCaptureLive
D
aptureSEP
(1H
2016)可能随时发生变化,以上 参考Copyright
©
2015
Symantec
Corporation35PEP
主动 利用防护每次一个新的进程被启动,就会
PEP程序We
modify
the
process
to
randomize
memory
layoutExploits
often
rely
on
specificmemory
locationsWe
hook
APIs
and
monitor
the
process
to
identifyexploit
techniques
and
block
themExploits
use
a
common
set
of
techniques
to
take
controlPEP降低了新的或旧的
被利用可能These
gaps
allow
attackers
to
take
controlThese
gaps
don’t
exist
in
more
modern
OSesFor
example,
Apple
won’t
let
code
run
unless
it
is
signed;Windows
will
run
any
code
anytimeProtection
provided
byPEP
(partial
list)Java
Security
Manager
protectionData
Execution
Prevention
(DEP)
onAddress
Space
Layout
Randomization
(ASLR)
onerwriteStructured
Exception
HandlinProtection
(SEHOP)Heap
Spray
Allocation
mitigationBottom-up
heap
randomizationNullPageReturn-Oriented-Programming
(ROP)
preventionLoadLib
prevention
on
shared
foldersProactive
Exploit
Prevention(PEP),
已知及未知的漏利用Copyright
©
2015
Symantec
Corporation36F&R
取证与修复Enterprise
Detection
andRemediation
(EDR)Once
an
attack
makes
it
inYou
want
to
findit
fastYou
want
to
neutralize
itYou
want
to
understand
the
scopeYou
want
to
collect
forensic
dataYou
want
to
remediateand
restoreCustomers
need
endpoint
tools
to
automate
this
processMore
importantly,
whenwe
want
to
have
these
sarovide
Incident
Response
on
retainer,ls
at
our
disposalFile
systemOur
EFA
componentsecurely
tracks
allfile
detailsRegistrySONAR
tracks
allregistry
changesMemorySONAR
has
directaccess
to
all
memory;enhancing
to
enablegreater
search
capabilityFile
accessAutoProtect
&SONARsee
all
file
access
eventsNetworkVantage
IPS
seesall
network
connectionsand
all
layers
of
trafficBehaviorSONAR
tracks
thousandsof
application
behaviorsin
the
kerneland
inusermodeForensics
&RemediationCopyright
©
2015
Symantec
Corporation37用户需要快速了解,响应并修复发现的安全问题,这方面的需求被称为EDR但 还是 非常多的问题与质疑…••无法衡量SEP是否用好与坏,目前是否是最优的架构及配置呢?在虚拟化环境下需要做什么特别的配置吗?
优化性能呢?上个月
事件8k+,这个月12k+,这证明企业安全环境越来越差了吗?SEP无法正常升级,磁盘空间被大规模占用?有办法解决吗?SEP安装后系统的启动速度,与运行速度都大幅度降低!SEP对一些
漏报,而其他安全
可以检测出来!除去故障类问题( )多数用户的SEP问题集中在两个方面:当前SEP系统运行是否在最佳状态,策略设置是否合理没有方法判断,如何优化难于着手。SEP的服务交付标准没有清晰定义,单从SEP的事件数量变化难于衡量安全效率。Copyright
©
2015
Symantec
Corporation381.当前SEP系统运行是否在最佳状态,优化难于着手有些资源是可以充分利用的SEP所有版本的 说明,新功能说明以及操作系统支持情况说明http:
/docs/TECH163829SEP最佳实践文章集合http:
/docs/TECH181685Symantec™Endpoint
Protection
12.1.6安装和管理指南http:
/docs/DOC8645通过SEP 或者记录
非公司允许的应用 使用http:
/docs/TECH97618Symantec
的安全防护配置建议http:
/docs/TECH173752SEP
Review
and
Report报告PPT模版ht
/s/1i3KSV1zBest
PracticeInstallation
planningUpgrade
planningAdministrationPolicy
configurationFirewall
and
intrusion
preventionSecurityThreat
remediationVirtualizationOther
resourcesSEP地址:代码:T201410221424Copyright
©
2015
Symantec
Corporation39例:SEP有漏报!客户环境中的SEP被正确使用了吗?问题1:当企业网络中部署Web
,用户终端要通过 并使用
口令 网络,SEPM中配置了对应终端与服务器的Web 的有效用户名口令。这时SEP那些功能不能正常使用?问题2:SEP12.1对比SEP11.x最大的功能改变在哪里?以上两个问题答案是一样的:Insight文件信誉SONAR行为控制Insight与SONAR
分别从文件信誉与行为特征方面检测 代码,弥补传统定义检查的不足,但Insight的数据更新不通过LiveUpdata完成,且由于工作机制问题导致其无法在认证
环境下使用。SONAR的正常工作需要依赖Insight的数据,如果SEP无法获取Insight数据,SONAR也将无法正常工作。这种情况
需要将制定的URL地址在用户的Web 侧进行例外这些URL时不进行认证。配置,设置白 允许用户终端在通过Web详细信息可以参考以下KB:http:
/docs/TECH162286Copyright
©
2015
Symantec
Corporation402.SEP的服务交付标准没有清晰定义,难于衡量安全效率建议从两个指标维度进行数据分析:环境指标:服务器指标:DB数据库配置参数、数据库备份调度任务、SEPM应用及操作系统日志分析,用于衡量服务器运行状态是否稳定;终端指标包括终端类型(部门)分布、SEP终端安装率、SEP当前版本分布、SEP
签名版本分布、
定义更新频率、全盘扫描频率、
IPS签名版本、策略下发版本分布、安全扫描成功率,安全策略配置分布等指标,用于判断部署SEP的客户端是否达到了所希望的标准(比例或阀值)。服务器与客户端之间通讯参数调整,服务器与客户端带宽环境;改善优化SEP相关策略与环境:分析原因如:网络带宽导致更新问题、策略推送时间问题、用户长时间出差
漫游等。根据没有达标的原因通过SEP策略调整与管理 ,加强终端管理与安全优化。环境指标
改善优化SEP相关策略与环境原因分析Copyright
©
2015
Symantec
Corporation412.SEP的服务交付标准没有清晰定义,难于衡量安全效率事件指标:安全事件与安全日志的分析,例如,各个部们安全数据分布,由各个SEP组件
的
,次数,受影响主机数量及比例,HI主机完整性检查情况,的类型,
严重Helpdesk事件处理量等。染数量,未清除
代码类型统计、数量统计,针对新型
代码的提交分析。改善优化SEP以外的其他安全控制措施:主要事件的来源分析,网络事件以IP为主,但多数事件需要从
分析
代码事件的来源,例如网络共享、邮件、上网浏览
、U盘
;对未完全清除的
代码应该重点关注后期查杀;基于分析结果,可对SEP的
系统(非SEP)进行调研与改善;这也是多数情况下帮助客户发现安全问题,引入新的安全解决方案的切入点!事件指标改善优化SEP以外的其他安全控制措施原因分析Copyright
©
2015
Symantec
Corporation42关于SEP
RISK
LOGS的分析计算机名源风险名称出现次数文件路径说明实际的操作所需的操作次要操作事件日期事件时间域用户名服务器客户端组源计算机名源计算机IP应用程序名称应用程序哈希哈希算法公司版本文件大小检测原因最小敏感度级别允许应用程序的原因Web域站点者普及率信誉最先看到的URL跟踪状态事件结束日期时间戳操作系统代码 源分析中文件路径信息是最关键最主要判断信息,例如,如果发现的问题来自于浏览器
目录则 代码可能来自于Web
,Outlook临时 则有可能是邮件传入,H:I:盘符根 可能来源是USB,//
.X来源是某一台主机文件共享,但要排除某些 对所有文件 的问题,所以一般建议分析前对一个终端产生非常大量事件的情况预先进行排除,或者在源中对只保留自动防护的事件数据。通过网络
的
代码也会在Log的来源字段显示,需要在SEP中开启来源追溯。对判断代码事件的传播有所帮助。如果被 程序存在签名信息,这些也会存在相关信息,多用于辅助判断 来源Web
的事件中会包含详细的目标信息,用于具体事件详细分析Insight文件信誉数据会在此显示根据客户端组可以分析被客户端分布情况Copyright
©
2015
Symantec
Corporation43ITytics
2.1
forSEPCopyright
©
2015
SymantecCorporation44MSSQLSEPMDBITA
DBOLAPCubesReporting
ServicesRaw
LogsIT
ytics独立于SEPM的安装,且它对SEP用户完全免费,但它需要独立的SQLServer工作环境,所以唯一可能需要考虑的就是服务器与SQL的成本IT ytics主要用于日志数据分析、报表输出、SEP合规与环境数据分析等使用场景,节省大量手工数据处理的时间,IT
ytics直接从SEPM数据库 数据,并进行挖掘分析,Online ytical
Processing
Server
提供 数据分析模型安装文件及文档在SEP12.1.5及以后版本的Tools
下根据事件来源向客户建议新的方案Copyright
©
2015
SymantecCorporation45代码与 来源于Web /应用程序代码与
来源于邮件代码与来源于NAS文件共享代码与来源于企业 应用代码与来源于SharePointSymantec
Advanced
Threat
Protection:NetworkSymantecMessaging
Gateway
/
8340
&
8380Symantec
Web
Gateway串联阻断、旁路检测、
集成,适用与NAT或 环境Symantec
D enterSecurity:
DataStore
Unified
ProtectionThreat
Protection
-Content
FilteringDLP
IntegrationData
Insight
–EncryptionUnified
Policy
andAdministrationAcross
Critical
Applications
&
DataMessaging
(Exchange)NAS
–
FilersNetAppSharePointCloud
AppsDSS
Deployed
across
Virtual
&CloudSecurity
Response
Insight
Reputation通过以下位置你可以随时
测试 并获取LicenseSymantec
Messaging
Gateway
(虚拟机版本)https:/
/Vrt/offer?a_id=93532Symantec
Security
for
Exchangehttps:/
/Vrt/offer?a_id=20032Symantec
Protection
Engine
for
Cloud
Serviceshttps:/
/Vrt/offer?a_id=146739Symantec
Protection
Engine
for
Network
Attached
Storagehttps:/
/Vrt/offer?a_id=146740Symantec
Protection
for
SharePoint
Servershttps:/
/Vrt/offer?a_id=132710Copyright
©
2015
SymantecCorporation46关于Symantec
Advanced
ThreatProtection:Network会与ATP:Endpoint及ATP:年下半年发布.提供同时在2015的控制界面关于Symantec
D enter
Security:DataStore会在2015年四季度发布,提供与D enter:Server,
ServerAdvanced相同的管理控制台与界面为什么 不再提及SNAC?Copyright
©
2015
SymantecCorporation47移动办公变成IT发展趋势移动设备不但需要在企业网络中使用,也需要在企业网络外使用公有云服务被 的采用,PaaS,SaaS平台被越来越多的使用,企业数据中心在外延那如何确保终端部署了必要的,达到了合规策略?以网络为控制点的准入技术正在向以应用自身为控制点的技术转移,通过跨多应用的集中控制实现企业应用 的基本准入控制。同时通过SAML将公有云,本地系统,控制 。包括对终端的合规性检查、安全 安装检查也将在未来在Portal、SSO与
移动设备与PC的认证过程中实现。根本的原因,企业网络边界在逐渐的消亡!!!关于现有SEP现有的用户,你可以做的…客户自行
的情况,通过巡检服务帮助用户发现问题,提供额外的维保或驻点服务已经在帮助用户进行服务的情况,基于
之前谈到的内容,发掘新的服务价值服务内容可以包含:SEP基于最佳实践的巡检,SEP环境指标与事件指标梳理,ITA数据分析平台建设,SEP定期报告与日志分析,SEP 驻场服务对于目前没有能力交付服务的合作伙伴,通过引入Symantec
Professional
Services,由的Consulting
Service
协助合作伙伴向用户交付标准化的服务内容,完成交付的同时培训合作伙伴,确保日后的持续交付能力。根据服务过程中的事件分析,向用户提供新的方案,寻找新的业务机会!当然通过用户现有已
的SEP,能做的还不止这么多…Copyright
©
2015
SymantecCorporation48MDM
is
Free!!从现有开始您将可以获取免费的Symantec
MDM移动设备管理解决方案的使用权,它与其他您在使用的Symantec
一样将包含完整的7*24小时售后技术支持服务,帮助您的企业提高移动生产力。只要您的企业现已 以下产品并处于维保期限内,同时License数量等于或超过1000个,便符合资格。Symantec
IT
Management
Suite
7.5Symantec
Client
Management
Suite
7.5Symantec
Endpoint
Protection
12.1Symantec
Protection
Suite
Enterprise
Edition
4.0只要您企业所使用的上述 持续 维保服务,您将持续获得MDM的持续的使用权获取License地址:
/li
censemgmt/MDMLanding.jspCopyright
©
2015
SymantecCorporation49的Web管理界面,集成化的解决方案,用户可以利用MDM在其基础上增加所需组建Device
Management(MDM)针对移动设备的配置、控制和管理企业应用商店分发应用及内容基于设备的策略App
Management&Protection
(MAM)安全配置与管理移动应用及其数据基于应用的策略(移动应用的封装打包)增强安全的企业应用包含Workforce
AppsWorkforce
Apps配置管理Symantec企业相关移动应用包含Work
Mail,WorkWeb和Work
FileApp及邮件
网关Threat
Protection让移动设备远离及有风险的应用。集中的移动安全管理基于设备安全态势实施控制策略Symantec
Mobility
SuiteCopyright
©
2015
Symantec
Corporation50在MDM基础上的Upselling,每个模块都可以单独销售即使客户没有MDM或在使用其他的EMM或MDM,(MAM由于国内Android碎片化问题谨慎
)Symantec
D数据中心安全enter
SecurityLatest
Available
Version:
6.5v6.6
will
be
on
September
2015数据中心的发展 的方向所有的基础设施资源都将被虚拟化以服务的方式提供(Delivered
as
Service)数据中心完全可通过软件实现自动化的管控SDDC中安全技术的发展最重要的
变化是交付方式,而不是交付内容,定义的安全控制,加速部署时间是SDDC中安全防护的关键。Copyright
©
2015
SymantecCorporation52Symantec
Denter
Security
:
ServerServersPhysical&Virtual
ServeDCS:Server*在新的DCS6.6中,用户即使没有现在无 的虚拟主机 防护与也可以使用
S实防护无
的
防护与(集成Insight)网络
防护基于Hypervisor安全虚拟设备提供虚拟主机保护第一家安全厂商宣布全面支持NSX持续保护无论虚拟主机是否发生迁移,安全控制自可动部署充分集成Symantec现有技术优势
代码防护与Insight在Guest主机内实现
文件增强的扫描缓存技术,网络
防护技术集成通过Operations
Director实现多项安全控制措施的自动化部署,该组建免费集成在所有DCS
中全新Web管理界面将DCS所有解决方案将都由其
管理,包括DCS:
Data
store,
Server,
Server
Advanced在内V(SoftwaS
ecCopyright
©
2015
SymantecCorporation53DCS:
Server技术原理Security
AdminTrafficSteeringSymantec
Denter
ConsoleSecurity
PolicyNSXControllerCopyright
©
2015
SymantecCorporation54代码安全防护工作流程*VMware
重新分配
GVM
X
到
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026统编版六年级下册《鲁滨逊漂流记(梗概与节选)》精读教案(含课件+整本书阅读与乐观精神+教学反思)
- 甘肃定西市临洮中学2025-2026学年高二下学期期末考试物理试题(含答案)(二)
- 2026年辽宁省灯塔市高二生物下册期末考试模拟测试卷含完整答案(夺冠系列)
- 2026 事业单位 政府服务中心考前模拟训练卷含答案
- 2026 河南 事业编综合岗结构化面试高频强化训练卷含答案
- 2026下半年高中物理教资面试光学理论题库
- 木结构-施工组织设计
- 2026年网箱养殖工职业技能等级认定(五级)操作技能考前冲刺试题
- 2025年江苏省兴化市高二历史上册期末考试真题(模拟题)附答案
- 2025年江苏省丹阳市高二生物上册期末考试模拟卷附答案(考试直接用)
- 2026年中国家用电风扇市场现状规模及前景动态预测报告
- 2026-2027学年三年级上册数学第二单元AB测试卷人教版
- 2026年注册安全工程师考试金属非金属矿山(中级)安全生产专业实务核心试题附答案
- 2026年党纪党规知识竞赛考试多选题200题含答案
- 水利工程施工质量检验与评定规范第2部分建筑工程
- 人工智能在小学数学与科学教学评价中的应用与实践教学研究课题报告
- 养老机构服务管理手册(标准版)
- 《老年人活动策划与组织》智慧健康养老专业全套教学课件
- 2025-2030中国燕窝市场供需现状分析及投资盈利性风险预警研究报告
- 2025~2026学年贵州省贵阳市第十九中学上学期期中考试八年级数学试卷
- 医院员工手册 职工工作手册
评论
0/150
提交评论