Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JoSec
Collaborator

Host IPS

Is adding Host IPS on the roadmap for endpoints? This would be beneficial as another layer to prevent an exploit of the system.

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

I would say the entire SandBlast Agent suite functions as a host IPS.
What precise functionality do you perceive as missing?

0 Kudos
JoSec
Collaborator

The ability to provide prevention at the network layer prior to any code execution on the host itself. 

0 Kudos
PhoneBoy
Admin
Admin

Not exactly sure how that would work since code would have to execute code on the host itself to process packets from the network.
A properly configured desktop firewall (which we do offer) can help limit what is processed by the host.
Also, if the traffic is encrypted, there's not much to process until the packets are decrypted, where our existing SandBlast Agent protections will help.

0 Kudos
IP2
Explorer

Would a standalone sandblast agent on a remote laptop outside the corporate network provide CVE specific IPS type protection?

For example, the Log4j IPS on the Security Gateway product:

https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0936.html

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Behavioural protection in prevent mode provides coverage here, stay tuned for some specific compliance enhancements in this regard.

Otherwise comparative like-to-like gateway protection for roaming users would be the Harmony Connect solution for a layered defense.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events