Showing posts with label AV/AS. Show all posts
Showing posts with label AV/AS. Show all posts

Friday, October 12, 2012

Anti-Virus Comparatives

Since the day Google announced Postini is going "EOL" in the coming year (to be replaced by Google Apps, which is far more inferior by many reports), many AV vendors have been chasing existing Postini customers, including us and our customers.


The above is a pretty good chart comparing the various AV products out there. Good for evaluating before making a final decision in months to come.

.

Wednesday, April 18, 2012

2012 Magic Quadrant for Unified Threat Management

We have been using SonicWall for a number of years and this is the brand we usually push to our customers.

Well done!


Wednesday, June 16, 2010

Red Condor Archive

It has been a while since I last looked at Red Condor. (Read here)


Red Condor released a new product offering last October - Red Condor Archive.

A secure message archiving service that helps organizations meet compliance regulations, e-discovery support requirements, and data storage and management best practices.

Key benefits of Red Condor Archive include:
* Archiving of all inbound and outbound messages, internal and external
* Unlimited storage at no additional cost
* All data searchable at all times
* Preservation of data
* Easy to use interface
* Instant set-up
* Replication to multiple data centers
* Role-based Administration Dashboard
* Individual End User search

Read more here.


I am always curious how a company can sustain its business by providing unlimited service/storage at no additional cost.

There can only be 2 explanations:
1. My maths is poor;
2. I have not been in this business long enough



PS: Red Condor is not the only company offering unlimited storage at no additional cost.


.

Wednesday, September 16, 2009

Cloudmark MobileAuthority Solution

Cloudmark solutions are not as widely adopted here in S'pore (as far as I know from my experience on the ground). I think mainly due to its pricing. I also think Cloudmark is targeting only the large deployment segment. Otherwise, it can't survive this long. :)

Anyway, I do know of a large deployment here for the Asia Pacific branch of a very big global network company. This deployment caters for the Japanese market, but the infrastructure is all here in S'pore.

Cloudmark has this solution for the mobile operators - MobileAuthority:

MobileAuthority provides mobile operators with three vital components to combat against messaging abuse and threats: actionable data, advanced content filtering, and messaging security expertise. These components work in tandem to ensure that mobile operators receive the most comprehensive and up-to-date messaging security protection for network optimization.

Pretty cool product. What caught my attention was this diagram:



Using a handphone can be so unsecured! There are some many potential "holes" to hack into.




Wednesday, September 9, 2009

Dell EMS Email Continuity




I chanced upon this site from Dell - Dell EMS Email Continuity. Hmm... I think this is an OEM from MessageLabs Email Continuity. 

What do you say?


Email Continuity


MessageLabs has this interesting offering - Email Continuity Service

This service provides on-demand email failover system that you activate when an outage occurs, enabling email users to continue sending and receiving messages through Outlook, Lotus Notes, web browser, or BlackBerry devices – without interruption.

MessageLabs Email Continuity Service supports Microsoft Exchange and Lotus Domino mail servers and also offers Blackberry integration.






Interesting solution. But seriously, how many takers will there be? 

The probability of activating this service is pretty low, unless your infrastructure has no high-availability and failover capabilities.


Tuesday, September 1, 2009

TrendMicro PortalProtect for Microsoft SharePoint




I received an marketing email. It led me to TrendMicro PortalProtect for Microsoft SharePoint. Read more here.

Wow! So many bad points about SharePoint:
  1. It's vulnerable to attack
  2. It's riskier than ever
  3. Your data is not secure



When a company needs to push out a product, it can really think of many bad points on others. :)

I would think any Portal solution out there are equally vulnerable - Sun Web Space Server, LifeRay and so on ... It's just that there is no AV/AS company interested enough to customize a solution for them.




Tuesday, August 18, 2009

Exchange with SendMail as MTA and MessageLabs as additional message filter

It is not uncommon to find an architecture like the one below:



I was involved with such deployment a year ago with a local corporation. The back-end is Microsoft Exchange.


Basically, there are 3 layers of messaging filtering:
1. MessageLabs Anti-Spam/Anti-Virus Filtering (Hosted/Cloud version)
2. TrendMicro InterScan Messaging Security Suite (In-house)
3. Symantec Mail Security for Exchange (In-house)


The primary idea behind choosing different vendors at different layers is to ensure that most (if not all) illegitimate emails are caught. 

This is what I call Total-Defense - you do not use the same key to lock all the doors in your house for convenience sake. 

Yes, I do agree that liaising with 3 different vendors is a nightmare. But for the sake of security, this is inevitable.


Ok, MessageLabs is now under Symantec umbrella. Maybe it's time to switch to Goggle Postini Service, or even ProofPoint SaaS Email Security Solutions. 

However, I am still not convinced with ProofPoint customer service support, especially in the APAC region.




Friday, August 14, 2009

MessageLabs TLS support

I continued to read up more on TLS following up with my customer's query. I know their solution is fronted with MessageLabs Anti-Spam/Anti-Virus Filtering Service. 

So in order to turn-on TLS on Sendmail to receive in-coming mails, I need to find out whether or not MessageLabs supports TLS communication.



Yes, it does. Read here.

MessageLabs is using this bombastic term - Email Boundary Encryption Service (End-to-End TLS Email Encryption). Wow!

Oh ya, forget to mention, you need to pay extra for this service. Nothing is free in this world. :)



Tuesday, August 4, 2009

Why TrendMicro IMHS is dropped? -Review!!

In my 3rd post on why TrendMicro IMHS was dropped, I mentioned the importance of visibility of the quarantined messages, especially in a hosted security solution. 

I still cannot believe that TrendMicro's hosted security solution is that bad, because I have very good impression of their technical support when my previous company used OfficeScan Client-Server Suite.

I must admit TrendMicro technical support is one of the better ones. 

So, I decided to conduct a review. 

I was saying the end-user Message Center was always empty for a particular user who we are very sure that his account receives a lot of spam emails daily. 



Yesterday, I log into the Administrator Console again. I clicked on Policy and bingo! I then realized most of the Action have been set to "Delete", by default, including Spam or Phish. No wonder no quarantined email was found for that user. 



So I went ahead to modify the Action from "Delete" to "Quarantine".






This morning, I checked the Message Center again. Yeah! The quarantined emails are shown.



Hmm... now I am left wondering why Spam or Phish emails are deleted by default. It's back to "Opt-In or Opt-Out" rule. I would say for emails, it should be a Opt-Out, rather than Opt-In. Why do you say?



Monday, August 3, 2009

Google Postini Service

We use Google Postini Service for our hosted security. It has been running for months. Today, Postini caught the 1st virus email. ( Should I say - finally? :> )


Anyway, catching the virus aside, what I like about Postini is how user-friendly it is. It's telling me my incoming email transaction daily. It's providing a high-level of transparency, which is what is required for any hosted service. 



Thursday, July 30, 2009

Why IronPort and Red Condor are dropped?

We wanted to evaluate Cisco IronPort Hosted Email Security, but they did not give us the chance. I was initially thrilled when I saw on their website "Try Before You Buy". I applied twice. No luck!



Our company policy is as such: Before we recommend a product to our customers, we'll evaluate internally first. The criteria is simple:
  1. Product capability and suitability
  2. Customer/Support service experience
  3. Pricing

Notice that we are very particular about service experience before any recommendation is made. If the experience with the pre-sales or sales is no good, we do not even proceed further. We are always against spending money on vendors who do not give a dime on customer service experience.

Honestly speaking, there are far too many comparable products out there in the market. The ones that support our customers best, we'll stick our heads with them. (even if their pricing might be the highest)

So, what about Red Condor? Why did we drop it?

Below is the email respond from Red Condor's Director Channel Management:
Regarding your reseller application: Red Condor is not currently signing resellers in Asia. We are in the process of reviewing this decision and to approach partners throughout Asia as we are expanding internationally.

It's a matter of presence. Red Condor is a relatively young company with main focus in the US/Europe markets. I think it will take them a couple of years before they get serious with the booming Asia market.

.

Wednesday, July 29, 2009

Why TrendMicro IMHS is dropped? -Reason 3

There must be visibility of the messages that are quarantined, especially in a hosted security solution. Otherwise, customers do feel uneasy. (This is really a feedback from our customers)

And this is something we look out for in evaluating a good hosted security product. Our company offers OpenMail. It is a secure-hosted environment for corporate customers. Internally, we subscribe to Google Postini Service for our own domain. We allow our customers to choose any hosted security product of their choice, if they want to have that extra layer of protection.

What we like about Google Postini Service is a daily Quarantine Summary email which each of us will receive.



If any of us detects that a genuine email has been detained, a simple click on "Deliver" will instruct Postini to deliver that email to our mailbox. There is also a Message Center for each user to manage his/her own quarantined emails.



In TrendMicro IMHS, there is this very nice Quarantines Settings module. Initially, it was not enabled, so we did not receive any Quarantine Summary email. However, even after we enabled it, we still receive nothing from IMHS. (Is it because we are testing with Free Trial account? We do not know why.)



Even when we log in as Administrator, there is no quarantined message being displayed for a particular user account which, we know for sure, receive lots of spam each day.




Yes, this particular user account does receive lesser spam when IMHS is activated during the trial period. However, if the visibility is not there, customer will never feel at ease.



Tuesday, July 28, 2009

Why TrendMicro IMHS is dropped? -Reason 2

In terms of look-and-feel, TrendMirco IMHS leaves a very good first impression.



Google Postini Service can never compete in terms of look-and-feel. Or rather, Google has never been bothered too much with slick design. They place their focus on functionalities instead.




For example, in IMHS, there is no way for administrator to know how many accounts he has created so far. I can understand that it's convenient for a CSV upload utility. It's helpful and most welcomed. However, after importing, there must be an intuitive way to show the list of imported users.



Google Postini Service's experience, again, is vastly different. A list of user accounts is shown distinctly. What's more? There is a way to adjust anti-spam for different categories (Sexually Explicit, Get Rich Quick, Special Offers, Racially Insensitive) at per-user level.




For each category filter, there is a way to set a base level (from Lenient to Aggressive).