Bookmark this site

^Search our news archive of 5,951,862 headlines

Free Membership. »More
Last update: New York 18:26
London 23:26
Tokyo 08:26

Already registered?
One News Page » Category » Computer Industry » Wednesday, 4 November 2009 » Application whitelisting review SignaCert Enterprise Trust Services
Information / Related NewsOpen Full Story in New Window

Application whitelisting review: SignaCert Enterprise Trust Services

Industry Standard Reported by Industry Standard
 on Wednesday, 4 November 2009
 (2 weeks ago)
Related Tweets Related Tweets
Related Headlines Related Headlines
Open full story in new window Full news story

SignaCert was one of the first whitelisting products available, and it now boasts more than 1 billion predefined file signatures as part of its Global Trust Repository service.
It also offers file authenticity ratings, wide platform support, extensibility through XML, and excellent documentation.
SignaCert's significant weakness is that it does not natively block file executions -- the only product in InfoWorld's review that does not include this ability as a standard feature.
Instead of blocking unauthorized applications, SignaCert focuses on identifying deviations from trusted, predefined baselines of files and security configuration settings, specializing in midsize to large environments.
[ Read the Test Center review of application whitelisting solutions from Bit9, CoreTrace, Lumension, McAfee, SignaCert, and Microsoft.
Compare these application whitelisting solutions by the features.

SignaCert Enterprise Trust Services is composed of the SignaCert Enterprise Trust Server appliance, a huge predefined file hash database (cloud service and local), and a client that works across more operating systems (including Windows, Linux, Mac OS X, and Solaris) than any of the reviewed competitors.
SignaCert even claims to work across network device platforms, such as firewalls and routers, but I didn't test that functionality.
It's also the only product to monitor security configuration settings, as well as registry and file objects.
SignaCert's nonpersistent Java client is the most customizable client in this review.
You can tailor its behavior based on a variety of configuration settings (to cap CPU utilization, for example).
You can even build your own client to support whatever you want as long as it confirms to SignaCert's XML formatting.
SignaCert easily has the best documentation of any product in this review, including hundreds of pages on both client and server components.
SignaCert comes with a vast database of predefined file hashes collected directly from the vendors.
This used to be a unique feature for SignaCert, but Bit9 Parity and Lumension Application Control have followed suit.
SignaCert claims to cover a wider array of platforms with its predefined file signatures than these competitors, but I did not verify this claim.
 
 
 
 
SignaCert lets you collect your own baselines using a process it calls harvesting.
Unlike the baseline generation tools of many competitors, SignaCert's harvesting can easily report all file types, including the attributes of multiple hashes, location, publisher values, and even file permissions and ownership.
SignaCert collects four file hash measurements screen image -- MD5, SHA-1, SHA-256, and SHA-512 -- the most hash types of any product in this review.
Like Bit9, SignaCert applies trust values on files it recognizes and includes the location and collection method when calculating the trust value, called an Authenticity score.
Authenticity scores can range from 0 to 1000, with 1000 equivalent to completely trusted.
SignaCert prepopulates these scores, or customers can submit their own scores for newly collected files.
SignaCert may trail competitors in execution blocking, but it leads the way in baselining and compliance.
SignaCert includes out-of-the-box templates for various regulatory requirements (PCI, FDCC, SOX, NERC) covering not only files, but ports, services, and configuration settings.
Other vendors offer regulatory audits, but no other product defends ports, services, and configuration settings.
Monitoring for compliance is fairly simple.
Simply match a compliance template with one or more computers that you want to audit or survey.
Run a file scan before or after, and then compare the results.
You can run baseline or audit compliance reports ad hoc or on a scheduled basis, and you can save reports to multiple formats, including PDF and XML.
Alerts can be sent via e-mail, Windows event logs, SNMP, syslog, and more.
SignaCert comes with many predefined and customizable dashboard views screen image and reports, and output can even be connected to Remedy Help Desk solutions.
This story, "Application whitelisting review: SignaCert Enterprise Trust Services," and reviews of competing products from Bit9, CoreTrace, Lumension, McAfee, and Microsoft, were originally published at InfoWorld.com.
Follow the latest developments in information security and endpoint security at InfoWorld.com.


Twitter   Tweet the News!50
Twitter login: password:
Register to store your twitter account details
There don't appear to be any related tweets.
Be the first to tweet the news!
Recent related news
Industry Standard
2 days ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowOffice 2010 beta debuts major features
The just-released Microsoft Office 2010 beta shows Microsoft's vision for integrating Office with the... »related headlines & tweets»
Industry Standard
2 days ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowMicrosoft Office 2010: An Intriguing Beta
With the release of the Office 2010 beta, the general public finally gets to check out how Microsoft... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowReview: SharePoint Server 2010 beta pulls it all together
Microsoft's SharePoint Server 2010 is a significant improvement over SharePoint 07, providing IT... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowApplication whitelisting review: Bit9 Parity Suite
As many product vendors can readily tell you, this reviewer is the ultimate computer security cynic... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowInfoWorld review: Whitelisting security comes of age
Whitelisting security has always taken a backseat to blacklisting approaches. After all, when there... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowApplication whitelisting review: Lumension Application Control
Lumension Application Control is a strong whitelisting solution with broad file coverage, excellent... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowApplication whitelisting review: McAfee Application Control
McAfee Application Control 5.0 (due out Dec. 15) is the result of McAfee's acquisition of Solidcore... »related headlines & tweets»
Industry Standard
2 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowApplication whitelisting review: CoreTrace Bouncer
CoreTrace's Bouncer 5 is application control and more. Bouncer is the only product in InfoWorld's... »related headlines & tweets»
Industry Standard
3 weeks ago - Computer Industry
Information / Related NewsOpen Full Story in New WindowSonicWALL firewalls for less than $1,000
SonicWALL recently started shipping six new firewalls to replace the low-end of its product line. The... »related headlines & tweets»
Industry Standard
on October 21, 2009 - Computer Industry
Information / Related NewsOpen Full Story in New WindowGartner on cloud security: 'Our nightmare scenario is here now'
At the Gartner Symposium IT/Expo this week, thousands of IT managers packed into sessions on the... »related headlines & tweets»
Post this: FacebookFacebook  EmailE-mail  TwitterTwitter  MixxMixx  StumbleUponStumbleUpon  FriendFeedFriendFeed
Environmentally friendly: One News Page is hosted on servers powered solely by renewable energy
© 2009 One News Page Limited. All Rights Reserved.  |  About us  |  Press Releases  |  Terms and Conditions  |  Privacy Policy  |  Content Accreditation
News Tags  |  One News Page - Top Headlines RSS Feed Top News RSS Feed  |  News for my Website  |  Archive  |  Advertise  |  Help  |  Contact us  |  Bookmark
-