HomeinetSymantec Detect Respond and Recover your data faster

Symantec Detect Respond and Recover your data faster

Symantec: IT departments – and the businesses they support – are facing challenges on many fronts around the question “is the business secure from cyberattacks?” as the complexity of IT rapidly evolves to include mobile rollouts, new cloud implementations, and Software Defined Data Centers. IT departments rely on security departments, which must deal with disconnected security architectures and operate with reduced funding, and often with a lack of resources for incident investigation, which prevents them from handling them effectively. 

symantec

The fact is that attackers know this and are constantly looking for ways to extend their access into the IT environment. As a result, many organizations are left exposed and at risk.

It’s also the nature of the attacks that’s causing concern. Today’s attackers are moving beyond traditional defenses, launching ever more sophisticated and targeted attacks that leverage malware variants to evade traditional signature-based security technologies. The result is that many companies have created multiple security products that don’t communicate with each other, which is not enough for businesses. Instead, security managers are constantly wondering if their network has been compromised, how widespread the threats are, and what parts of the infrastructure have been compromised.

All of this means that the traditional approach to controlling security in the corporate network is no longer enough. Because although advanced network threat detection technologies are effective in detecting unknown and zero-day malware, they do not cut off detected threats, but most likely allow malicious files to pass through the internal network and to other endpoints. As a result, security departments do not know what happens to the malware that is detected – so there is a possibility that a more complex and sophisticated attack has been created in the corporate environment.

With endpoints providing the launching pad from which an attacker can launch an attack, detecting today’s targeted attacks and Advanced Persistent Threats (APTs) requires a comprehensive, multi-layered approach that detects malicious activity across the network and endpoints. Organizations often rely on technologies that are not designed to work in conjunction with other solutions, with few resources to piece together their security – instead of focusing on more strategic security initiatives.

What can be done to neutralize threats, close these gaps, and keep businesses secure?

Symantec’s response is the creation of Managed Security Services – Advanced Threat Protection (MSS-ATP). The solution is based on Symantec’s alliance with leading network security vendors Palo Alto Networks, Cisco (Sourcefire) and CheckPoint. The alliance provides two-way integration of endpoint security solutions and network security vendors, while leveraging Symantec’s leading global threat intelligence network (GIN). MSS ATP enables organizations to rapidly detect, investigate and remediate unknown and zero-day attacks that compromise security technologies. In essence, MSS-ATP:

  • Empowers the security operations team to understand complex targeted attacks operating at the network and endpoint levels
  • Correlates effectively, allowing security teams to quickly prioritize without spending time (and money) investigating less important incidents
  • It leverages existing investment in network security and endpoint solutions, while leveraging enterprise-level global threat content from Symantec's global threat intelligence network (GIN).

In other words, this solution is much more than just a technology: it is about a holistic security approach based on Intelligence, leveraging leading technologies and existing investments.

MSS -ATP leverages Symantec’s cloud-based MSS threat detection platform that aggregates and correlates unfiltered alerts from a range of technologies, using the global threat detection network to identify patterns associated with malicious activity. It then leverages business-centric contextual intelligence to ensure incidents are prioritized based on potential financial impact to the business.

Additionally, MSS-ATP also leverages cloud-based reputation technology for file inspection. This helps reduce false positives by leveraging the reputation of potentially malicious files. Symantec’s Insight file reputation database identifies files and dozens of related elements such as age, source and footprint in the global community. All of this information is used by complex algorithms that determine each file’s risk level, or “security score.” If the file is low risk, MSS-ATP issues an informational alert. If the file is assessed as high risk, a Critical Alert signals further investigation as necessary.

In short, with MSS-ATP, Symantec addresses the unmet need for rapid incident detection, prioritization, and remediation across multiple security platforms, leveraging leading technologies and capabilities, and leveraging the global content focused threat intelligence network.

Security collaboration and security ecosystems are becoming increasingly important to enterprises. Symantec's MSS-ATP solution is leading this effort to ensure that its customers and their needs are supported.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS