Symantec Endpoint Protection

Symantec Endpoint Protection

Symantec Endpoint Protection GUI, version 11 (OS: Windows)
Developer(s) Symantec Corporation
Stable release
14.0
Operating system Microsoft Windows, Mac OS X and Linux
Platform IA-32 and x86-64
Type Antivirus and firewall
License Trialware
Website www.symantec.com/business/endpoint-protection

Symantec Endpoint Protection, developed by Symantec Corporation, is an antivirus and personal firewall software for centrally managed corporate environments providing security for both servers and workstations.

Version history

Symantec AntiVirus Corporate Edition was the initial software from Symantec in this market, its last release before discontinuation was version 10.2 MP1, (10.2.4). Its successor Symantec Endpoint Protection (SEP) software was released September 23, 2007 and labeled version 11. In 2009 a Small Business Edition (SBE) of SEP (version 11) was introduced[1] in addition for seats/nodes <=100 and labeled version 12. In 2011 both software lines were updated to version 12.1. In 2015 SEP SBE 12.1 was discontinued and replaced by SEP SBE version, reflecting changes in licensing (from perpetual to subscription) and shifting focus from on-premises to cloud-managed business.[2] SEP was updated from version 12.1 to version 14.0 October 28, 2016 introducing several improved and new detection features.

Symantec Endpoint Protection, current version history:

System support

Endpoint Protection supports Windows 10, Red Hat Enterprise Linux (RHEL) 7.0 and 7.1, & Oracle Linux (OEL) 6U5 Since 12.1.6168.6000 [15] Windows 8.1 & Windows Server 2012 R2 (Since 12.1.4013.4013), Windows 8 & Windows Server 2012 (Since 12.1.2015.2015), Windows 7, Windows Server 2008, Windows Server 2008 R2,[16] Windows Server 2003, Windows Vista, Windows XP SP1 or higher, and Windows 2000 - and several distributions of Linux.[16] 64-bit versions of Windows XP, Vista and Windows 7 are supported as well, but Itanium and PowerPC processors are not supported.[16]

Security concerns and controversies

July 2016 - Google Project Zero Team has seen serious vulnerabilities with Symantec's Endpoint Protection products.[17][18] The code has been found to have flaws in the decomposer component, which allows analysis of various archive formats like.zip and .rar.[19]

This enforces a process of remote code execution to create computer worms to execute and interfere with the local network without the knowledge of users.[20][21]

These issues were fixed in release, 12.1.7004.6500 (12.1 RU6 MP5). [22]

Features

Firewall
Endpoint incorporates a rules-based firewall, as well as an anti-malware technique that Symantec calls "generic exploit blocking". The firewall is based on technology developed by Sygate Technologies, who were purchased by Symantec. Generic exploit blocking is a technique that attempts to proactivly blocks malware from exploiting unpatched vulnerabilities.[23]
Proactive protection
Endpoint uses Symantec's TruScan technologies to attempt detection of unknown malware. It analyzes both "safe" and "negative" behaviours of unknown applications.[24] It also integrates Symantec's Deepsight honeypot sensors to warn of emerging threats and provide threat advisories.[25] Proactive Threat Protection feature is supported on server operating systems in version 12.1 and above.[26]
Intrusion prevention

Endpoint is able to create and enforce rules on client computers. For example, it can prevent clients from writing files to a USB flash drive. Intrusion prevention also works as IDS. Policies are enforced by TruScan. The IPS functionality acts as a first line of defence against network based attacks.[27]

Generic Exploit Mitigation

Generic Exploit Mitigation prevents common vulnerability attacks in typical software applications, including the following types of protection: - Java exploit prevention, - Heap spray mitigation, and - Structured exception handling overwrite protection (SEHOP). The protections apply to the specific applications that are listed in the Intrusion Prevention policy. SEP downloads the application list as part of its LiveUpdate content.[28]

References

  1. "Symantec Endpoint Protection". Symantec.com. 2011-10-04. Retrieved 2011-10-18.
  2. "Symantec Endpoint Protection". Symantec.com. 2015-11-06. Retrieved 2015-11-06.
  3. "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  4. "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  5. "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  6. "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  7. "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  8. "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  9. "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  10. "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  11. "About the SYM14-013 Symantec Endpoint Protection zero-day vulnerability". Symantec.com.
  12. "Symantec Endpoint Protection 12.1 Release Update 4 Maintenance Patch 1A". Symantec.com.
  13. "Latest Symantec Endpoint Protection Released - SEP 12.1.RU3". Symantec.com. 2013-06-06. Retrieved 2013-11-07.
  14. "Latest Symantec Endpoint Protection Released - SEP 12.1 RU2 and SEP 11.0 RU7 MP3". Symantec.com. 2012-11-15. Retrieved 2013-11-12.
  15. https://support.symantec.com/en_US/article.HOWTO111067.html
  16. 1 2 3 "Symantec Endpoint Protection". Symantec.com. Retrieved 18 October 2011.
  17. "Symantec and Norton security products contains security vulnerability- Explained Detailed". "US-CERT". Retrieved 2016-06-05.
  18. "Symantec bugfest highlights the dangers of security software". Retrieved 2016-07-05.
  19. "Google Found Disastrous Symantec and Norton Vulnerabilities That Are 'As Bad As It Gets'". Retrieved 2016-06-29.
  20. "Symantec may actually help hackers, Homeland security warns". Retrieved 2016-07-07.
  21. "Symantec admits it won't patch 'catastrophic' security flaws until mid-July". Retrieved 2016-07-07.
  22. https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160628_00
  23. "Data Sheet: Endpoint Security" (PDF). Retrieved 2011-10-18.
  24. Ramon Ray (2007-12-30). "How Symantec Is Changing to Better Meet Small Business Needs". Smallbiztechnology.com. Retrieved 2011-10-18.
  25. "Enpoint Security White Paper" (PDF). Retrieved 2011-10-18.
  26. http://www.symantec.com/business/support/index?page=content&id=TECH92440
  27. Sarrel, Matthew (2007-12-13). "Symantec Endpoint Protection 11 Review & Rating". PCMag.com. Retrieved 2011-10-18.
  28. "Enterprise Support - Symantec Corp. - Technical Solution" (PDF). symantec.com.
This article is issued from Wikipedia - version of the 11/2/2016. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.