Home > Ask the Security Experts > Application Security Questions & Answers > What are common (and uncommon) unified threat management features?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are common (and uncommon) unified threat management features?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 March 2007
What are the common features in a UTM product, and which features are rare ones, or ones that you see being added in the future?

>
EXPERT RESPONSE
UTM, or unified threat management, is a term used to describe a firewall that combines multiple security features in one appliance. As a minimum, it must have the ability to perform network firewall functions, intrusion detection and prevention, as well as gateway antivirus scanning. Other common features found in UTMs include the filtering and controlling of a wide variety of network communications, such as Web, instant messaging and email traffic. The combination of multiple capabilities allows deep inspection of packets and real-time attack protection from layer two to Layer 7 of the Open System Interconnection (OSI) model. Some devices also offer VPN capabilities.

UTM appliances have quickly gained in popularity, partly because the all-in-one approach simplifies installation, configuration and maintenance. Such a setup saves time, money and people when compared to the management of multiple security systems. Instead of having several single-function appliances, all needing individual familiarity, attention and support, network administrators can centrally administer their security defenses from one box. Also, the multiple functions of UTM appliances have made it easier to convince management to replace older, more basic firewalls that cannot evaluate application-layer traffic.

A more recent UTM feature is the ability to inspect all network traffic, including encoded, compressed, encrypted and wireless traffic. Other newer enhancements include strong authentication controls as well as traffic anomaly detection. UTM's popularity will surely cause vendors to add new defense features. I can see extended log-analysis mechanisms, such as behavioral analysis of network traffic, becoming a common feature soon.

When you are evaluating a UTM, it is important to ensure that the device's different functionalities fulfill all of your security policy requirements. It's also important to make sure that the appliance is easy to use and keep up-to-date. Do not get caught up in the sales and marketing hype that tends to surround a lot of products in this area of network protection.

One drawback of an all-in-one device like a UTM is that it creates a single point of failure on your network. Should the product go down, it can create a major cap in your defensive posture. Good UTMs, however, have failover features that can allow connections to a secondary gateway if the primary one becomes unavailable. Effective UTMs also have plenty of processing power, so production won't be hindered when the devices look for both application-layer and content-based attacks. Some have predicted that purely software-based enterprise UTMs would emerge, but because they need to run on purpose-built security devices with a hardened operating systems designed to handle the role of real-time protection and control, I consider this scenario unlikely.

More information:

  • Lisa Phifer explains how unified threat management can fight spyware.
  • Find out which UTM offerings are the best fit for your organization.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    What risks do application virtualization products pose to enterprise security?
    Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
    How can quality assurance tools aid software development?
    Should UTM and Web security filtering software be used together?
    Is the iPhone amenable to any method of email encryption?
    What are effective ways to stop instant messaging (IM) spam?
    Is it impossible to successfully remove a rootkit?
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?

    Unified Threat Management (UTM)
    Should UTM and Web security filtering software be used together?
    McAfee adds NAC module, appliance for unified policy enforcement
    IBM announcements mark two years of ISS marriage
    Fortinet acquires database vulnerability scanner from IPLocks
    Verizon UTM service reflects telecom security push
    Firewall deployment options increase for enterprises
    Screencast: How to configure a UTM device
    Product review: Unified threat management (UTM) devices
    Interop: Vendors update software, demonstrate new security features
    Microsoft NAP-TNC compatibility won't speed adoption, users say

    Application Firewalls
    Check Point adds virtual firewall appliance
    Web application firewall deployments gain traction
    Positive changes coming to ModSecurity
    Best practices for application-level firewall selection and deployment
    PCI Council issues clarification on Web application security
    Will firewall technology have to adapt to applications that use port 80?
    NAC, disk encryption gaining attention, survey shows
    Comparative Product Review: Six Web Application Firewalls
    What evaluation criteria should be used when buying an enterprise firewall?
    What are the drawbacks to application firewalls?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Data Encryption Standard  (SearchSecurity.com)
    denial of service  (SearchSoftwareQuality.com)
    digital certificate  (SearchSecurity.com)
    disaster recovery plan  (SearchSecurity.com)
    distributed denial-of-service attack  (SearchSecurity.com)
    encryption  (SearchSecurity.com)
    integrated threat management  (SearchSecurity.com)
    Trojan horse  (SearchSecurity.com)
    trusted PC  (SearchSecurity.com)
    unified threat management  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts