Threat Control
Today, IT needs a way to control threats that originate on the LAN. Such a solution must detect anomalies on the network and allow IT the option to automatically contain such threats.
It must detect malware – even malicious code never seen on the network before – and prevent it from propagating. It must also detect other anomalies, whether it’s a zero-hour attack, an attack launched from a printer or VoIP phone, or a rogue user connecting in via an open jack.
A full network access control and LAN security platform must also detect and block other sources of threats, such as invalid protocol headers that might indicate an attack.
In addition to essential network access control capabilities, malware control and application protection are fundamental to LAN security. To be effective, a LAN-based threat control solution must meet the following requirements:
- Operate inline to see the anomalous traffic
- Recognize zero-hour attacks
- Operate close to the host
- Granularly block bad traffic
- Minimize false positives and tuning
- Recognize and block attacks launched from non-user network devices
The LANShield product family protects against both known and unknown threats, providing more accurate detection with blocking at a finer level of granularity than security tools operating at lower layers. Incident reporting is based on knowledge of user transactions, and the LANShield product family can stop traffic on a per-user or per-application basis if malware is detected. Attempts to use printers or VoIP phones as a launch point for attacks are also prevented by limiting the protocols those devices can run and the network destinations they can reach.
Recognizing the unique challenges local networks pose, ConSentry Networks engineered its LANShield silicon architecture and LANShield products from the ground up to provide network access control that secures the LAN from the inside out. Combining LAN speed, deep-packet inspection and anomaly detection algorithms, the LANShield product family meets all the requirements for a LAN-based threat control solution.
» Download the Threat Control Solution Brief
|