PDA

View Full Version : How HIP is this ?


StevieO
August 16th, 2005, 08:03 PM
I hadn't heard about this one until today. It sounds very interesting to me, see what you make of it !


Determina

Determina has brought to market a truly revolutionary host-based intrusion prevention system (HIPS) that eliminates the threat of the most dangerous class of software attacks. Based on many years of research at M.I.T., Determina new "Memory Firewall" technology is 100% effective against all types of memory-based attacks. Utilizing this unique technology, the Determina SecureCore product suite pro-actively protects systems software running on enterprise servers without signatures, training, policies, or false positives.

Solution Overview

Determina represents the next generation of intrusion prevention software that goes beyond mere detection and current "best-effort" prevention to fully eliminate the threat of the most critical software attacks. Determina utilizes unique patent-pending Memory Firewall technology which blocks attacks at the most fundamental level, by dynamically building a protective shield around programs while they run in computer memory. This groundbreaking approach has proven to be 100% effective against all memory-based attacks - such as Code Red, Blaster, Slammer and Sasser - without false positives or ongoing overhead.

Learn more about Determina Memory Firewall technology »

Determina SecureCore for " Zero-Touch " Security
Determina SecureCore provides a robust intrusion prevention system (IPS) software that can be deployed broadly across all enterprise servers. Determina offers key advantages over existing approaches, providing true "zero-touch" security for complete peace of mind:

Systematic - The only solution that systematically blocks an entire class of known and unknown attacks without signatures, training, policies or human intervention.

No Maintenance - The only solution that requires no ongoing maintenance to be effective. It deploys on a server in minutes and doesn't require training, tuning, or signature updates. It offers fool-proof security without associated operational costs.

Accurate - The only solution that is 100% accurate. It doesn't generate false positives or false negatives, only confirmed incidents of real attacks.

Pro-active - The only solution that fully blocks malicious code before execution, preventing even a single line of unintended code from executing.

http://www.determina.com/product/overview.asp


StevieO

Tassie_Devils
August 16th, 2005, 08:50 PM
Hi StevieO. :)

Upon reading, it appears it's orientated for a Network based system.

I downloaded the PDF Product Brochure which had the following info

-{ Quote: "Determina SecureCore Agents
Installs Easily: Installs in minutes with no configuration required.
Integrates with enterprise deployment systems.

Deploys Without Administrative Overhead: No signatures, policies,
training, or human intervention are required. Doesn't need to be updated
when new updates or service packs are installed.

Protects Immediately: 100% effective the moment that it's installed.
No setup or learning period is required.

Blocks Wide Range of Attacks: Blocks stack overflows, heap manipulation,
code injection, "return into libc," memory corruption, and other
common attack types.

Works Systematically: Protects systems software against all memory-
based attacks without any prior knowledge of specific attacks.

Stops Attacks Proactively: Stops an attack before it actually executes
a single line of malicious code on a server. Prevents Trojans or
backdoors from being installed.

Eliminates False Positives: Generates an alert only when there is an
actual attack.

Keeps Software Running: In most cases, keeps systems software
running in the face of attack through sophisticated remediation technologies.

Runs Standalone or Centralized: The system and application agents
can be deployed in a standalone single-server configuration, or integrated
with the Management Console for enterprise administration.

Logs Events: The local agent can log events in the Windows event
log.

Captures Forensics Data: Captures detailed forensic information
from blocked unknown attacks for later analysis.

Operates Transparently: Does not use any behavioral training or
learning that might interfere with applications, patches or service
packs.

Integrates with Microsoft Windows: Integrates seamlessly with
Microsoft® Windows including MSI install, event logs, and the
Microsoft Management Console.

Ensures Performance: A wide array of tests has shown negligible
performance impact on the running applications or services.

Alleviates Reactive Patching: Unscheduled, urgent patches are not
needed since SecureCore protects vulnerabilities prior to a patch
being installed.


Determina SecureCore Management Console
Manage Agents Centrally: Centrally deploy, manage and upgrade
thousands of agents from a single console. Change policies for a particular
application across hundreds of servers.

Access Via Web Browser: Access console from standard web
browsers without proprietary client software. Access from anywhere
across an enterprise or even outside the firewall.

Monitor Events in Real-Time: Monitor important events from all protected
servers in real-time from a single event display.

Generate SMTP Alerts: Notify the appropriate security professional
immediately when there has been an attack.

View Summary Reports: Summarizes data across the enterprise for
senior managers and executives and allows drill-down into the data by
time period and other dimensions for decision support.

Analyze Trend Reports: For managers or executives who want to
measure or track improvement over time, trending charts show performance
over time.

Organize Servers into Groups: Organize servers into logical groupings
and apply security settings across the entire group from one control
panel.

Assign Users and Roles: Assign different roles to administrators that
give them different levels of capability and privilege.

Keep Audit Trail: All configuration changes are logged to create a
comprehensive audit trail.

Communicate Securely: Authenticated 128-bit SSL encryption
between Agents and the Management Console." }-

I then went to 'more information' but had to fill in a form and in a 'Required Field' you had to give company name with all details. [did not do that btw ;) ]

Soooo based upon that premise, I conclude it's company/corporate orientated and can see nothing to indicate single/standalone PC. [although one part there it says 'Standalone' but are referring to a Server]

Cheers, TAS

sukarof
August 17th, 2005, 03:44 AM
Yup, looks like it is mainly targeted at companies, considering the price: $500

http://www.pcmag.com/article2/0,1759,1768259,00.asp

Tassie_Devils
August 17th, 2005, 10:37 AM
-{ Quote: "Yup, looks like it is mainly targeted at companies, considering the price: $500

http://www.pcmag.com/article2/0,1759,1768259,00.asp" }-

whoa sukarof, priced right out of this little black duck's league, lol.... I tried looking for a price on site, but you had to fill in form. Thanks for the info. ;)

Cheers, TAS