Isn't my firewall
enough protection?
Probably not. While many organizations rely on their
firewall to protect them from Internet attacks, it is not
enough. A fully closed firewall would protect your network, but
it would also close the Internet to your network. So a port or
ports must be opened in the firewall to provide a path for
communication with outside users. These open ports enable
an intruder to go in and out of the holes unchallenged.
How do I protect my
servers?
You could implement an Intrusion Detection Systems (IDS).
These systems provide another layer of protection, but they only
record the event, not prevent it. They
simply page the network administrator and alert him of the intruder's
presence so that the compromised port or ports can be shut down.
However, these systems can waste significant security administrator time
responding to false-positive alerts.
You might consider a server based Intruder Prevention System.
However, Its server centric design increases initial installation
and on-going administration costs. Even more importantly, while
server based IPS solutions are
effective at protecting the servers on the network, they do not
protect the network itself. The network is still vulnerable to
malicious intruders. Something more is needed.
Hang up on Hackers.
The Econet.com SentinelIPS takes
Intrusion Prevention to the next level. The SentinelIPS
protects the open ports on your firewall by quickly identifying hackers and
permanently blocking them from communicating with your servers. The Sentinel is unique because it detects and responds to an attack
while the attack is in progress. Its proprietary technology actually
recognizes the attack and stops it before any malicious packets reach
your internal network elements. Sentinel effectively "hangs up"
on the attacker suspending the attack. It is a true threat management - assessment,
detection, and remediation system in one managed solution.
The Econet.com SentinelIPS inspects all
Internet traffic entering your network for malicious code, prohibited
behaviors, malformed packets, and hack attempts. Once an
attack is profiled, SentinelIPS drops all packets from the offending IP Address, including
the initial request packets, so fast that the destination IP address
appears dead or unused.
During that time, SentinelIPS has
inspected the packet, correlated it, logged the event, copied the
packet for administrative use, sent an alert to the network
administrator, the packet dropped and a new rule written to exclude
the source IP address from accessing the network.
To the perpetrator, your Internet Gateway IP address will appear to be
dead or unused.
What is it?
The Econet.com SentinelIPS is both an
appliance and a security management service. Its standard features include
24/7 monitoring of the device, remote management services, update
services, upgrades and enhancements. There is not hardware or
maintenance contracts to buy. We simply install the SentinelIPS
outside your firewall and configure it to your network protection
specifications. From then on, you simply pay a low monthly fee
for each month that you keep the SentinelIPS in place.
Your security administrator can access the EcoNet Sentinel's easy-to-use administration tool
using any authenticated web browser. There, he can unlock IP
addresses, create white lists, set up priority alerts, and review
standardized reports on network activity.
