Home > Security News > Finjan adds DLP, content caching to Web security gateway
Security News:
EMAIL THIS

Finjan adds DLP, content caching to Web security gateway

By Neil Roiter, Senior Technology Editor, Information Security magazine
09 Feb 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Finjan's newest release has bolstered its position in the highly competitive Web security gateway market, layering in onboard content caching and basic data loss prevention (DLP) functionality in Secure Web Gateway version 9.2.

SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

The new features complement Finjan's antimalware protection, which combines its highly regarded real–time content inspection technology and optional antivirus modules (Kaspersky, McAfee, Sophos), application control for use of IM, Skype and P2P, and Web usage control (URL filtering, Web 2.0 sites).

Finjan Inc. is banking on offering a comprehensive one-appliance (their Vital Security Web Appliance NG-5100 and NG-6100), which it says is a cost-effective package that will appeal to enterprises in a tight economy.

"The challenges for CIOs and CISOs are budget issues in the global recession," said Yuval Ben-Itzhak, chief technology officer of Finjan. "That means saving power consumption, floor space and having fewer boxes in data center. Companies still have to run operations despite layoffs."

Web security gateway:
SaaS startups enter Web security gateway market: Web security vendors Zscaler Inc., Purewire Inc. enter growing Software as a Service (SaaS) space dominated by appliance vendors.

About half of Finjan's U.S. sales are channel-based, aimed primarily at companies with fewer than 5,000 employees. In Europe they do direct sales almost exclusively.

It doesn't expect its DLP capability to compete with major vendors in that market, such as Symantec/Vontu, McAfee Inc., Websense Inc., Trend Micro Inc. and Vericept Corp. It allows companies to frame inspection around keywords and patterns, but only along Web vectors, not email and desktops, probably the most critical channels high-end DLP products cover, with more sophisticated search algorithms, content and meta data tagging, etc.

The value, Finjan said, is to give organizations DLP capabilities while they implement complex, long-term projects, or basic functionality for those companies that shy away from big DLP projects.

Content caching is generally a key component of URL filtering solutions, typically requiring a third-party proxy, such as Blue Coat appliances, to accelerate Web page delivery. But Gartner analyst Peter Firstbrook doesn't think this is as big a deal as it once was.

"Caching is a feature that's becoming a nice to have rather than a must have," Firstbrook said. "Providing it keeps them from being excluded from deals where companies have done caching in the past with [Microsoft] ISA, Blue Coat or NetApp."

"But the caching component is less important than it used to be because most Web pages are dynamic anyway."

Finjan also offers a stand-alone Web-caching appliance.

SearchSecurity radio:

The Web gateway security market grew out of URL filtering, which many companies deployed to improve productivity by curtailing employees' browsing habits and enforcing policy by reporting on and/or blocking unacceptable sites, such as gambling and pornography. As employees started using uncontrolled apps such as IM and P2P, vendors added application control.

As the Web-borne malware supplanted email as the primary threat vector, Web Security vendors quickly realized that URL filtering provided very weak security and added gateway antimalware scanning.

Firstbrook believes the market remains strong.

"This is one of the market that will hold up quite well," he said. "Less than 20% of enterprises are filtering Web traffic for malware, and yet, that's where all the malware is coming from; 80% of the malicious sites are actually legitimate sites that have been compromised."



Tags: Web Application SecurityWeb Application and Web 2.0 ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Web Application Security
Preventing SQL injection attacks: A network admin's perspective
Cisco acquires SaaS security vendor ScanSafe
Web application firewall use goes beyond compliance, company finds
Gumblar Trojan drive-by exploits spike following Adobe update
Some Facebook applications lead to Russian attack sites
Barracuda acquires Purewire expanding Web security reach
An enterprise strategy for Web application security threats
Scanning with N-Stalker offers basic Web application security assessment
Attackers target PDF, DirectShow flaws with malicious banner ads
New Bahama botnet evades search engines, fuels click fraud

Web Application and Web 2.0 Threats
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Kaspersky system analyzes malicious URLs on Twitter for malware
Pushdo botnet uses Facebook to spread malicious email attachment
Do Facebook URL security concerns justify blocking social networks?
Gumblar Trojan drive-by exploits spike following Adobe update
Some Facebook applications lead to Russian attack sites
Massive phishing scheme affects Microsoft Hotmail accounts
Phishing websites, rogue antivirus skyrocket in 2009
An enterprise strategy for Web application security threats

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anonymous Web surfing  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cookie poisoning  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts