Reviews - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Cisco Small Business Advantage
  • Register for WES 2010 by February 19 and save $400.
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Seagate® Barracuda® drives fit every desktop need.
  • MSP Partners helps solution providers stay competitive.
  • Learn more about EnterpriseDB @ the Postgres Center
  • Earn 40-50% margins. Zenith open houses show how.
  • CDW Healthcare offers the IT solutions you need.
  • One number. One voicemail. Sprint Mobile Integration.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • Give your customers more with LSI 6Gb/s solutions.






  • Channel Insider conferred 75 awards to vendor, distribution, solution provider and industry groups for performance excellence. Check out all the winners in the 28 Bull’s Eye Award categories.
    >> Bull’s Eye Central


     

    Symantec's DeepSight Threat Management System

    in Reviews


    Article Rating:starstarstarstarstar / 0
    Article Views: 1738

    Rate This Article:
    Add This Article To:
    Symantec's DeepSight Threat Management System 5.0 adds anti-virus data to its mix.

    Symantec Corp.'s DeepSight Threat Management System has added anti-virus data to its mix, bringing the product up to par with competitors. IT managers at large corporations that traditionally mine application and operating system vendor sites for known vulnerabilities should consider adding DTMS 5.0 to their security assessment tools.

    DTMS 5.0, which is an early-warning vulnerability and malicious code monitoring system, is based on data gathered from more than 20,000 sensors scattered throughout the world. The product was released in September at a base price of $15,000. Costs rise depending on the number of users, and Symantec has also released an optional $9,995 custom reports module that let us ably slice and dice vulnerability data in tests.

    The biggest weakness we saw in the product is that it required us to manually select the technologies in our network. We want to see DTMS integrate with any number of inventory systems currently on the market to automate configuration. DTMS should also be integrated with any number of vulnerability assessment tools.

    EXECUTIVE SUMMARY
    DeepSight Threat Management System 5.0

    Symantec's threat monitoring service provides a nice extension to vulnerability assessment tools, even if it lacks integration with systems and inventory management tools. Despite its integration shortcomings, which competitors also possess, we think the heads-up information DTMS 5.0 provides outweighs the configuration headaches.

    Resource Library:
    KEY PERFORMANCE INDICATORS
    USABILITY FAIR
    CAPABILITY EXCELLENT
    PERFORMANCE GOOD
    INTEROPERABILITY POOR
    MANAGEABILITY FAIR
    SCALABILITY EXCELLENT
    SECURITY GOOD
  • PRO: Consolidates information from thousands of sources to warn of threats that are easy to miss.

  • CON: Lack of integration with other management tools.
  • EVALUATION SHORT LIST
    Internet Security Systems' X-Force Threat Analysis Service

    To be clear, though, DTMS is an early-warning system, and, as such, it attempts to recognize potential threats for which no attack signature or published exploit yet exists. Because vulnerability scanners rely on known signatures and configuration profiles, DTMS is a nice complement to vulnerability assessment tools that may be in use.

    For comparison, we recommend IT managers look at Internet Security Systems Inc.'s X-Force Threat Analysis Service. Although we think the X-Force service's forecasting features aren't very useful, the service has had anti-virus information for some time. In addition, ISS is a stickler for detail, and the expert analysis it provides is top-notch.

    Sign In, Please

    In some respects, it couldn't be easier to set up DTMS. All we had to do was point our browser at the product URL and sign in with account credentials. However, large organizations should factor in plenty of time to set up the system to monitor for vulnerabilities and malicious code because each operating system and application must be hand-entered into what DTMS calls a technology list.

    The list is is populated with pick lists, which made it relatively easy for us to define the product and version that we wanted the system to track.

    After setting up our technology lists and our urgency (as ranked by Symantec) and reliability (ranging from conflicting reports to confirmed by vendor), operating the product was easy. However, keeping the system up-to-date as applications and operating systems change is likely to be difficult.

    DTMS 5.0 augments threat and vulnerability assessment rankings by adding anti-virus information, so IT managers should be able to spot threats more accurately than when using the previous version of the service. A statistical engine works over the data using information from field sensors. DTMS issues an alert if more than one sensor starts to read more than three times the standard deviation of its base line.





    Discuss Symantec's DeepSight Threat Management System
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Reviews Articles          >>> More By Cameron Sturdevant
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How much time do you spend hunting for enterprise IT content?
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com
     
    Should You Be Using “up.time”?
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and along with best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Free Trial Download Here (Virtual Appliance available)
    Managed service providers are using regulatory compliance and industry standards to win business and give customers peace of mind. Join host Larry Walsh of Ziff Davis Enterprise and his guests on Friday, February 19, 2010, at 1:00 pm ET for a discussion of “Compliance as a Service.”
    Register Today