Border Defense Service
Financial gain is now driving the bad guys to become more and more persistent and creative in how they bypass standard security technology. As a result, threats against company networks from the internet are on the rise. On top of this, many companies today have multiple entrance points into their networks creating multiple areas of access, many of which are never monitored for malicious traffic or un-authorized users. Any application, any user, and any service can be allowed accesses to the network and its servers and workstations; many due to vulnerabilities, misconfigurations, or the simple nature of the technology. Realizing this security concern in many small, medium, and corporate networks, Network Strategies developed the Border Defense Service.
Our Border Defense Service utilizes leading edge, signature based, Intrusion Prevention System (IPS) security technology to enable us to monitor, proactively respond to, and eliminate threats to your network borders as they are happening. These systems are set up in-line to watch your network borders 24 hours a day, 7 days a week, 365 days a year and provide us with information on security events as they occur. The majority of attacks directed at a company’s network begin at some point with initial scanning and reconnaissance to find weaknesses in the outer defenses of the network. The Border Defender devices will alert us and at the same time block many of these recon attempts thus disabling the ability of the cracker to gain any knowledge of your network. If a cracker is into deeper phases of exploitation of the network, say attempting to exploit a vulnerability in a company IIS web server, the Border Defender will alert us to this exploitation if it is known and we will be able to stop it before they have a chance to follow through with the exploitation.
Our Border Defense systems are not just meant to protect from malicious traffic coming from the Internet, internal systems are also watched for malicious outbound traffic as well in the event that one becomes compromised and anti-virus, if present, fails to catch it. All too often, internal systems become infected with spyware and other malicious programs that send traffic outbound to unauthorized users on the Internet. With our Border Defense service, we also watch for and are able to potentially detect internal infected systems where anti-virus can often fail due to the increase of response time of receiving updates from anti-virus vendors.
An example deployment scenario is shown below. We can deploy and monitor the: Inside/Outside of the Firewall, WAN connections, DMZ’s, Wireless Networks, VLAN’s, Protected Servers, etc.
