• No results found

Cyan Networks Secure Web vs. Websense Security Gateway Battle card

N/A
N/A
Protected

Academic year: 2021

Share "Cyan Networks Secure Web vs. Websense Security Gateway Battle card"

Copied!
5
0
0

Loading.... (view fulltext now)

Full text

(1)

URL Filtering

CYAN Secure Web Database - over 30 million web sites organized into 31 categories updated daily, periodically refreshing the data and removing ex-pired domains

WebSense Database - Daily updated database with over 40 millions web sites

Updates of the URL database are published on a daily basis - the frequency can be increased, but we did not have customer demands yet; the update of the AV database can be scheduled in minute inter-val - a reasonable minimum for sensitive environ-ments is, however, 4 hours.

Real-Time Security Updates - A customer security database automatically looks every 5 minutes for updates about new mobile malware code, spyware or phishing pages.

CYAN Secure Web provides categories that hold web sites with streaming information, etc. and provides a mechanism to prevent certain applica-tions like various audio/video clients to connect to the Internet

Bandwidth Filtering - Manage web pages with an impact on bandwidth, such as radio and internet TV, P2P, personal archiving sites, Internet mobile and multimedia streaming.

CYAN Networks believes that automatic categoriza-tion results in a false-positive rate not applicable for business environments; rather than pushing the technology to the customer all robots and agents are run solely in the laboratory of Cyan Networks - the result is reviewed and approved by personnel in order to maintain a high level of accuracy

Real-Time engine for Uncategorized - The inline categorization engine allows to categorize on the fly every sites not yet known to Websense.

Web 2.0 protection mechanisms are integrated Dynamic Malware Control - The dynamic engine al-lows to analyze the content of each single element crossing the gateway, searching for malicious code within the web pages.

Web 2.0 protection mechanisms are integrated (HTTPS Interception, AV scanning on downloads, content type limits) - additional protection mech-anisms are in the roadmap (full HTML/Script con-tent scanning, post request analysis, keyword scan-ning)

Real-Time engine for Web 2.0 - The inline categoriz-ation engine tries to categorize the dynamic page contents of site offering dynamic contents, such as social networks or portals.

Our robots analyze web content that is retrieved by

crawlers for harmful or infected pages ThreatSeeker™ Analytics - The threatseeker engine permits to execute a general control, in search of single elements with low significance that pose a threat when correlated.

(2)

Cyan Networks Secure Web

- how it works

Websense Web Security Gateway

- what they say it does

n.a. ThreatWatcher - Websense analyses the customer's Web Server and perform a multi-layered scan to find potential threats or vulnerabilities.

n.a. BrandWatcher™ - Websense warns customers

whom web site is under phishing or malware at-tacks.

Feature to anonymously report uncategorized URLs automatically is in the roadmap and will be avail-able soon

WebCatcher™ & ProtocolCatcher™ - Anonymously catch unknown sites and protocols and send them to Websense to categorize.

Application Blocking

Filtering applications embedded in HTTP transfers (application blocking) with thousands of patterns daily updated. Next release also include white & black listing on application blocking

Dynamic Protocol Management™ - Filter over 100 protocols in 12 categories.

Available via mime type analysis (true content type is inspected rather than relying on extensions) and part of the application blocking in order to control based on the "content meaning" rather than only on the type of data

File Type Manager - While granting site access, block of downloading file types such as audio, video files, executables, etc. …

IM applications can be controlled as allow/deny via the application blocking mechanism

IM Attachment Manager™ - Block attachments within IM applications.

HTTPS Interception

Interception of HTTPS, POP3S and IMAPS Interception of HTTPS HTTPS Interception is part of the product (without

additional cost!) which analyzes encrypted traffic; exclusions to the interception can be made for par-ticular target hosts and can be refined per

user/group

SSL Manager - The SSL management module per-mits to decrypt SSL sessions and look for potential malicious components or categorize the encrypted page content in Real Time.

Management (create/import) of a certification au-thority. Dynamic creation of signed certificates

n.a. Certificate validation and fine grain control of the user actions on inaccurate certificates (certificate policies)

(3)

Secure Web has integrated AV scanning engines as option (ESET NOD32, Sophos, AVIRA), but there is already a Clamav free AV engine on standard pack-age

Websense Web Security Gateway has integrated Authentium AV scanning engine

CYAN Secure Web blocks access to content that is infected by viruses, represents malware, etc. by ap-plying AV scanning on the traffic. Content is rather blocked than modified (by means of stripping out malicious pieces) - modification to content in the most cases leaves pages that cannot be rendered correctly by the browsers and results in a "dam-aged" display of the original page

n.a.

CYAN Networks scans multiple TB of Web content per month; Spyware is prevented by to connect to the Internet by multiple technical approaches (ap-plication blocking; IP blocking; HTTPS Interception)

Security Filtering - Websense scans weekly over 350 million web sites seeking and blocking mal-ware, spyware and phishing pages. It prevents also existing spyware applications from transmitting in-formation to third parties.

Reporting

CYAN Secure Web Report - web tool with more than 65 templates; different output formats (pdf, excel, HTML, csv, ...) and scheduler able to manage delivering to specific e-mail address

WebSense Presentation Report - Web tools for scheduled in-depth analysis with over 50 report templates to choose from in different formats (pdf, excel, etc. ...)

In case of missing reports CYAN Networks will cre-ate the corresponding templcre-ate and provide it in a software update; the database is in an open format - customers can use arbitrary tools to create re-ports themselves

n.a.

The reporting system supports different adminis-trative roles: admin, report manager, report viewer and observer (observer is required in the case 4-eyes-principle is turned on)

Delegated Reporting - Permit specific users to ac-cess to some web tools for creating reports based on specific users or groups.

Not yet supported Auditing - Audit and revision of all Websense policies changes.

a) anonymizing can be done in the activity logs, b)

the reporting system supports the 4-eyes-principle in order to blind user sensitive data and open the

Anonymous Logging - Optional functionality for maintaining anonymous the activity logs.

(4)

Cyan Networks Secure Web

- how it works

Websense Web Security Gateway

- what they say it does

System Features & Administration

CYAN Secure Web passes cached content always through all filters in order to apply different access restrictions on the content depending on the recipi-ent; anonymous proxies are part of the application blocking feature

Keyword Search, Cache & Proxy Avoidance - Enable search based on keyword. Websense filters also cached contents, translation sites, and Proxy Avoid-ance sites and Akamai protocols.

Authentication: MS Active Directory, NTLM trans-parent, Novell e-Directory, LDAPs, integration with MS ISA Server (upstream & downstream)

Authentication: MS Active Directory, NTLM trans-parent, LDAPs, integration with MS ISA Server (downstream only)

Protocols: HTTP, HTTPS, FTP, FTP over HTTP, IMAP,

IMAPS, POP3, POP3S, Protocols: HTTP, HTTPS, FTP, FTP over HTTP Deployment: Passthrough, Transparent, Proxy

cas-cading & conditional routing, Cisco WCCP support

Cisco WCCP support

Platform deployment: Linux, Windows, Proxmox PVE, VMware virtual appliance, Secure Web appli-ance series

Platform deployment: Vxxxxx appliance series & software mixed configuration based on Linux and Microsoft

Centrally administrated distributed installations are supported by Secure Web - due to complex and various installation requirements we provide this on a per-project basis

Delegated Administration - Allow managing sector, organization and remote server policies with a cent-ral distributed configuration.

Managing web access with a productivity focus is the main justification of Cyan Networks, providing a tool to create "Internet for Business"

Productivity Filtering - Manage web pages with bad impact on productivity, such as message and club board, advertisement, software/freeware down-loads, instant messaging, trading on-line and pay for visit sites.

SNMP Support is integrated in the appliance solu-tion; for Software-only installations SNMP is avail-able as a standard for all supported operating sys-tems and can be combined with the Secure Web in-stallation

SNMP Alerting - Permit to set thresholds for specif-ic events and to automatspecif-ically send them to other security systems through Simple Network Manage-ment Protocol (SNMP).

Bandwidth reduction is achieved by caching mech-anisms; a dynamic "content shaping" feature is on the roadmap

Dynamic Bandwidth Optimizer™ - Reduce and op-timize bandwidth resources giving priority and handling the traffic in real-time.

(5)

mode out of the box; a cluster can be extended by additional machines anytime in order to scale with growing number of users and/or bandwidths

1.000 users) and V5000 G2 (from 1.000 up to 10.000 users)

Secure Web appliance system configuration

References

Related documents

Description: Secure Web Gateway Market by Solution (Email Gateway, Data Loss Prevention, Social Media Control, Content Inspection Management), by Services (Consulting, Professional,

Define the WCCP service group Restart Content Gateway proxy..

The Websense ThreatSeeker™ Network adaptive security technol- ogy uses more than 50 million real-time data collecting systems that continuously monitor Internet

Websense is the first security vendor to address the risks of Web 2.0 by deploying ThreatSeeker analytics inline at the customer’s gateway, providing dynamic, adaptive

Websense Content Gateway In Your Network Workstation Websense Content Gateway Router Firewall Websense Web Security Gateway Internet Explicit Request Gateway... Installing

Understand how Content Gateway processes a Web request Understand how HTTPS packets are processed differently than HTTP packets.. Understand the format of ‘extended.log’

 Unable to communicate with the Websense Filtering Service..., page 10 Applies to: Websense Web Filter, Web Security, Web Security Gateway, and1. Web Security Gateway Anywhere,

Note: This document assumes that the administrator has deployed and configured Websense Content Gateway to proxy HTTP(S) and/or FTP traffic as outlined in the Deploying with