And consider industrial sabotage--intruders and disgruntled employees can take advantage of poor internal protection. The least obvious but most common security breach over the desktop is the innocent user downloading dangerous code.
You'd be negligent if you didn't protect your systems with proper host-based security. That's what makes a comprehensive desktop-centric security suite essential, even for the most cost-conscious companies.
Luckily, you don't need to spend wads of cash for decent desktop security. Plenty of tools are available for free or low cost. Spending a little on security software can save you untold dollars in the long run.
Our comprehensive desktop-security plan is four-pronged, consisting of software firewalls, encrypted channels, antivirus tools and user education. In fact, before you buy a single security item, you must have a user-education program and a system to enforce and maintain it.
The Always-On Alternative
Applications or drivers that run on the end user's PC--software firewalls--usually act as a kernel shim. The software intercepts the data being passed between the kernel and network card drivers, inspecting all network traffic passed through it.
There are two major types of software firewalls: port blockers and application blockers. Port blockers, which include the built-in Windows 2000/XP firewall and the IPtables on Linux, work just like gateway or Internet firewalls and can block communications only to or from specific TCP/UDP ports.
Regrettably, port blockers are useless on the desktop. For one thing, you'd have to open a wide range of ports for a user to take advantage of his or her most common applications. What's more, these firewalls can't distinguish between Internet Explorer and a hostile program sending traffic over Port 80.
Windows XP SP2 includes bug fixes, safeguards against hostile Web downloads and improved default settings. These may make your XP desktops safer, but they're not enough to keep users from making poor security decisions. And SP2 will do nothing to enhance security for Windows 2000. A low-end PC with Linux and IPtables loaded on it makes an excellent free gateway firewall for perimeter security. But for the desktop, we strongly recommend using an application-blocking firewall, such as ZoneAlarm or Sygate Personal Firewall Pro. For less than $50 a seat, these products offer excellent value.
Unfortunately, these firewalls ask on-screen if a particular application may have permission to access the Internet. Uneducated users tend to click "OK," leaving your system vulnerable to hostile code. On the upside, application blockers can detect some Trojan horse applications, protect themselves from being terminated by rogue programs, perform limited intrusion detection and shun the IP address of an attacker while performing privacy data scrubbing.
![]()
![]()
![]()
Affordable IT
Introduction
Desktop Management
Desktop Security
Patch Management
Storage
Whiteboxes & Used Gear
E-Mail
![]()
![]()
![]()
![]()
BP seeking Regional Desktop Coordinator in Houston, TX
Agilent Technologies seeking Marketing Manager in Melbourne, AU
Advancement Project seeking Junior Web Developer in Los Angeles, CA
Johns Hopkins Univ Carey Business School seeking Asst Dean for IS in Baltimore, MD
City of Westland seeking MIS Director in Westland, MI
For more great jobs, career-related news, features and services, please visit our Career Center.
Web Reputation Filters Battle the Latest Web Malware Threats
IronPort Web Reputation Filters™ are designed to combat the dynamic nature of malware. Today’s threats are no longer found as an email attachment. Instead, they are well orchestrated – utilizing social engineering techniques and target legitimate websites. As the first line of malware defense, IronPort Web Reputation Filters analyze more than 5 billion Web transactions daily – blocking up to 70 percent of malware at the connection level, prior to signature scanning. By leveraging its global footprint of URL traffic data IronPort’s Web reputation system is able to offer an industry-leading 60 percent higher malware catch rate than traditional signature scanners.

NOTE: Offer valid for U.S., U.S. possessions, & Canada only