- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: Host IPS
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Host IPS
Is adding Host IPS on the roadmap for endpoints? This would be beneficial as another layer to prevent an exploit of the system.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would say the entire SandBlast Agent suite functions as a host IPS.
What precise functionality do you perceive as missing?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The ability to provide prevention at the network layer prior to any code execution on the host itself.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not exactly sure how that would work since code would have to execute code on the host itself to process packets from the network.
A properly configured desktop firewall (which we do offer) can help limit what is processed by the host.
Also, if the traffic is encrypted, there's not much to process until the packets are decrypted, where our existing SandBlast Agent protections will help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Would a standalone sandblast agent on a remote laptop outside the corporate network provide CVE specific IPS type protection?
For example, the Log4j IPS on the Security Gateway product:
https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0936.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Behavioural protection in prevent mode provides coverage here, stay tuned for some specific compliance enhancements in this regard.
Otherwise comparative like-to-like gateway protection for roaming users would be the Harmony Connect solution for a layered defense.
