Skip to main content

IM Gets A Safety Net

Instant messaging in the enterprise means a lot more than emoticon smiley faces: It's no LOL matter.

Every IM poses a potential threat to a company's legal compliance, network and data security or business policies. Unified SecurityGateway (NYSE: GTW) (USG) is Belmont, Calif.-based FaceTime Communications Inc.'s solution for securing realtime communications, which can be the trickiest network traffic to control.

The USG appliance connects to the SPAN/TAP port of a switch. Two additional Ethernet ports are also connected: a management port and a proxy port to connect internal IM clients to the device, which is preloaded with Linux and has two 1.6GHz dual-core processors and 4 Gbytes of memory.

The management interface is Web-based. Reviewers first configured network settings, adding domain information and primary DNS, and set up authentication againstMicrosoft (NSDQ: MSFT) Active Directory. Deployment in the lab also involved creation of policy groups, including one for a less restrictive policy (Admins) and one more restrictive (Users).

Policy setup was easy to navigate. Clicking on the Admins or Users group names brought up the policy configuration screen. From there, access and restrictions were configured for the more popular (and some not so well known) IM applications, P2P software, malware/adware and Web filters. Testers left the Admin group with access to the more mainstream applications, while the Users group was completely locked down.

In testing, clients accessing blocked sites were given a default warning message indicating that corporate policy did not allow access to those sites. The warning is customizable and can include graphics, such as the company's logo. Additionally, an e-mail alert can be sent to the user's mailbox. IM restrictions were set up to flag for specific words in the chat. When the specific word was typed, a system-generated message came on screen stating the policy was violated.

IM management is pretty detailed. There is a "spIM" setting, which is used to combat IM spam. A challenge response can be enabled to prevent bots from spamming IM sessions. IM chat is logged through IM transcript reports, listing the username, IP address and all text of the chat session.

Web filtering is set up by default though synchronization with the Secure Computing Control list. With filtering, there are the options of blocking, allowing access or "coaching." The coaching feature enabled the system to send a warning suggesting the user should not access the questionable site but did not block access to the site. Filtering can also block specific files.

P2P and malware filtering features give as much administrative control as Web and IM filtering and are as easy to configure.

With P2P filtering, the version of P2P software allowable can be defined. For example, if there is a known vulnerability in a particular version of an application that is allowed on the network and there is another version of the software patched against that vulnerability, administrators can give access only to the more secure version.

USG is priced at $24,995—that includes support for 1,000 users and full functionality. The system is scalable for an enterprise with more than 10,000 users. Solution providers can integrate the device in a network that has a firewall or an enterprise antimalware system already intact.

With a solution like USG, in conjunction with a strongly defined and consistently applied technology usage policy, solution providers can offer a formidable defense in the rapidly evolving and constantly challenging realm of realtime communications.

By Samara Lynn, ChannelWeb

Comments

Popular posts from this blog

Want To Get Answering Machine For Your IM?

Computer's personal often face problems when they have to take a break from their PC for some time and can’t answer to emails and instant messages. Actually, for email you can set up an autoresponder if you use Outlook software, and there’s a way out for gmail, too. But what can you do with your instant messenger? I have a lot of IM accounts for any purposes with different people in each account. So what utility can tell these people that I am out on a vacation or down with fever? Answer.im comes to the rescue by setting up an automated web based answering machine for your instant messenger. It works with MSN, ICQ, AIM, Yahoo and Google Talk as of now. How it Works Setting it up is very simple. First, hop over to http://answer.im/. Then, select your IM network (like GTalk, Yahoo, etc). Fill in your username and password and hit Login. Features Now, you can customize your automated reply and select the status you would like your account to remain at. Since the service is web based, ...

Durov: The phone of the richest man in the world was hacked through WhatsApp.

The founder of "VKontakte" and Telegram Pavel Durov said that back in November 2019 he warned about the vulnerability of the WhatsApp application, through which hackers hacked the smartphone of the richest man on the planet Jeff Bezos. Durov wrote about it in his Telegram-channel. Earlier, the company Facebook, which owns WhatsApp, noted that the businessman's mobile phone was hacked because of vulnerabilities in the operating system from Apple. At the same time, Durov is convinced that the problem is not iOS. " WhatsApp in its marketing campaign uses the words 'end-to-end encryption' as a magic spell, which itself should ensure the security of all communications. But this technology alone cannot guarantee absolute confidentiality," says the founder of Telegram. One of the drawbacks of end-to-end encryption, he says, is that backups of transmitted data are often not encrypted. In addition, says Durov, each application has "ways around...

Primus to Provide VoIP for MSN Messenger

Primus Telecommunications Group, Inc. has entered into an agreement with Microsoft Corp. to provide Voice-over-Internet Protocol (VoIP) services for MSN Messenger Service customers. Marketed as "PrimusTalk," once a user has logged into MSN Messenger Service, calls can be made by clicking on the "Make a Phone Call" link. A phone dialer will appear where a call can be made to any number -- national, international or mobile. The McLean, Va.-based Primus will provide PrimusTalk service as an Internet telephony application that can be accessed by any user accessing MSN Messenger Service. Specifically, the PC-to-phone service will be integrated with the MSN Messenger Service as an option that may be accessed by users of Microsoft client software programs. "Primus is leading the way to a carrier class era of converged communications solutions," said John Melick, co-president of Primus and one of the principal developers and implementers of the company's VoIP ...