Top Banner
Building an Integrated Security System Microsoft Forefront code name “Stirling” Ravi Sankar Technology Evangelist | Microsoft http://ravisankar.spaces.live.com/blog
23

Building an Integrated Security System Microsoft Forefront code name “Stirling”

Feb 25, 2016

Download

Documents

IMELDA

Building an Integrated Security System Microsoft Forefront code name “Stirling”. Ravi Sankar Technology Evangelist | Microsoft http://ravisankar.spaces.live.com/blog. Agenda. Security and Access Challenges Forefront Today Forefront Codename “ Stirling ” Comprehensive Protection - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Building an Integrated Security SystemMicrosoft Forefront code name “Stirling”

Ravi SankarTechnology Evangelist | Microsofthttp://ravisankar.spaces.live.com/blog

Page 2: Building an Integrated Security System Microsoft Forefront code name “Stirling”

AgendaSecurity and Access ChallengesForefront TodayForefront Codename “Stirling”

Comprehensive ProtectionSimplified ManagementCritical Visibility

DemoQ&A

Page 3: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Security And Access Challenges

More usersMore locations/devicesIntranet/Extranet access

Full connectivity is riskyPoor apps integration Lack of scalability

Changing legal rulesChanging business rulesLimited granularity

Growing Mobility Traditional VPNs Inadequate

Difficult to Enforce Policies

More advancedIncreased volumeProfit motivated

Many point products Poor interoperability Lack of integration

Multiple consolesUncoordinated reportsComplex and costly

Escalating Threats Fragmented Security Difficult to Manage and

Deploy

Security challenges

Access Challenges

Page 4: Building an Integrated Security System Microsoft Forefront code name “Stirling”

A comprehensive line of business security products that helps you gain greater protection and secure access

through deep integration and simplified management

Network EdgeServer ApplicationsClient And Server OS

Page 5: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Management And VisibilityDynamic Response

Network EdgeServer Applications

Client And Server OS

vNextAn Integrated

Security System

Page 6: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Integrated protection across clients, server and edgeDynamic responses to emerging threatsNext generation protection technologies

Comprehensive

Protection

Manage from a single role-based consoleAsset and policy centric modelIntegrates with your existing infrastructure

SimplifiedManagemen

t

Know your security state in real-time View insightful reportsInvestigate and remediate security issues

CriticalVisibility

An Integrated Security System that delivers comprehensive, coordinated protection with simplified management and critical visibility

across clients, servers, and the network edge

Page 7: Building an Integrated Security System Microsoft Forefront code name “Stirling”

ComprehensiveProtection

Page 8: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Comprehensive ProtectionIntegrated security systemSilo’d Best of Breed Solutions are not enough

Customers do this today and still have security issuesManual coordination is difficult and often incompleteExpensive and difficult to understand if “I’m secure”

Stirling and Dynamic Response are the answerLayered Protection across the organizationProtection technologies that work togetherProtection technologies that share security state informationProtection technologies that take action together

Customers need anIntegrated Security System

Stirling’s protection technologies work together to better protect customers

Page 9: Building an Integrated Security System Microsoft Forefront code name “Stirling”

DNS Reverse Lookup

Client Event Log

Edge Protection

Log

Network Admin

Edge Protection

Client Security

Hours

DEMO-CLT1 Andy

DesktopAdmin

Manual: Launch a scan

WEB

Malicious Web Site

Phone

Manual: Disconnect the Computer

Zero Day ScenarioToday

Page 10: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Security Assessments Channel

2-3 min

TMG identifies malware on DEMO-CLT1 computer attempting to propagate (Port Scan)

Security Admin

Network Admin

DEMO-CLT1 Andy

DesktopAdmin

Malicious Web Site

WEB

Forefront TMG Client

Security

CompromisedComputer DEMO-CLT1High FidelityHigh SeverityExpire: Wed

CompromisedUser: AndyLow FidelityHigh SeverityExpire: Wed

Stirling Core

NAPActive

Directory

Forefront Server

for:Exchange

, SharePoi

ntOCS

FCS identifies Andy has logged on to DEMO-

CLT1

Alert

Scan Computer

Block Email

Block IM

Reset Account

Quarantine

Zero Day ScenarioWith Stirling and Dynamic Response

Page 11: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Enterprise Security

Too much or too little data

Efficient and focused investigation

Today

High rates of false positive/negative

Manual enterprise wide response

Monitoring Low visibility on enterprise security

Standard channel for security information

Share contextual Information

Automatic responseand shield up

Detection

ProtectionInvestigatio

n

StirlingDynamic Response

Stirling delivers:Better Protection - Faster Response - Lower Cost

Page 12: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Stirling Protection Technologies

vNextvNext

vNext

NEW

AntivirusAntispyware

Host Firewall

NAP IntegrationVulnerability

Assessment & Remediation

Exchange Protection

Content Filtering

SharPoint Protection

Firewall

Web AV

Remote Access

Dynamic ResponseCoordinated Defense Adaptive InvestigationInformation Sharing

Content Filtering

And More…

Page 13: Building an Integrated Security System Microsoft Forefront code name “Stirling”

SimplifiedManagement

Page 14: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Security ManagementToday

Jumping between consoles waste timeEach console has its own policy paradigmProduct’s are in silos with no integration

Lack of integration with infrastructure generate inefficienciesDifficult to know if solutions are protecting from emerging threats

Management Console

Management Console

Management Console

Reporting Console Reporting Console Reporting Console

Console

Endpoint Protection

Server Application Protection

Network Edge Vulnerability Assessment

Page 15: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Simplified Management With StirlingProtect your business with greater efficiency

One console for simplified, role-based security management

Define one security policy for your assets across protection technologies

Deploy signatures, policies and software quickly

Integrates with your existing infrastructure: SCOM, SQL, WSUS, AD, NAP, SCCM

Page 16: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Critical Visibility And Control

Page 17: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Know your security state

View insightful reports

Investigate and remediate security risks

Critical Visibility And ControlKnow where action is required

Page 18: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Stirling Beta 1

DEMO

Page 19: Building an Integrated Security System Microsoft Forefront code name “Stirling”

RoadmapH2 2008

Client andServer OS

ServerApplications

Network Edge

IntegratedSecurity System

NEW

NEW

NEX

TN

EXT

NEW

NEX

T

Codename “Stirling”

NEWBETA

H1 2008 H1 2009

Page 20: Building an Integrated Security System Microsoft Forefront code name “Stirling”

SummaryStirling is an Integrated Enterprise Security System that delivers comprehensive, coordinated protection with simplified management and critical visibility across clients, servers, and the network edge Dynamic, coordinated responses to threats

Focus on protecting assetsManage security, not security productsCoherent and meaningful reports

Page 21: Building an Integrated Security System Microsoft Forefront code name “Stirling”

Next StepsBecome experts in existing Forefront products

Install Stirling Beta

Give us feedback!

Page 22: Building an Integrated Security System Microsoft Forefront code name “Stirling”

22

Q & A

Page 23: Building an Integrated Security System Microsoft Forefront code name “Stirling”

© 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after

the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.