As you might know Microsoft is (beta) releasing a new product called Forefront Threat Management Gateway (Forefront TMG) code name "Stirling". Forefront TMG is the successor of ISA server 2006. Being in the technology an security business I couldn't resist myself to test drive it on a virtual Hyper-V guest.
The reason I couldn't resist myself is simple Forefront TMG completes the circle. It can work together with Forefront Client Security, another Microsoft Anti-Virus desktop product.
What makes Forefront TMG an intresting product is that is has built in HTTP traffic scanning for malware and signatures. It introduces an extra layer of defense. Which is needed because rolling out and testing important updates for windows or other import products like Adobe and SUN (Java) takes time. And in that time clients may get infected or worse.
But the good news doesn't stop there. It's also able to detect infected or not properly protected clients and put them in quarantine and more. And if you check my previous post you'll see it works very well and is more then welcome.
Another good thing is that Microsoft release updates for Forefront TMG in sync with their own update services. So it will be a must have from a security perspective.
What's nice as well that is 100% Hyper-V compatible. Making a test scenario very easy.
Offcourse antivirus protection on ISA server or firewall level is already possible but not with interaction with desktop software. In the mean time you can use a product like GFI webmonitor or similar
A good step Microsoft took to a safer digtal world.
What do you think?
Blog Archive
Showing posts with label Forefront. Show all posts
Showing posts with label Forefront. Show all posts
Monday, November 10, 2008
Thursday, October 30, 2008
Malware and Trojans via Google search results
Last Wednesday I received a Google alert. My name Martijn van Halen in combination with the company where I work Payvision had a new google alert. I have registered several alerts since it provides me with a way to detect what people write about me or Payvision. Always handy.
This time the alert looked like somebody wrote something about me. But when I clicked I was redirected and confronted with the Antivirus 2009 product. This product had some bad press releases lately since it's a Trojan. It pretends to be good but contains a virus itself. It's a tricky one since it states that your computer might be affected and that they have a cure.
They try to lure you in downloading and executing an exe. Our Forefront client security protects us from this kind of Trojans. But still how it uses a personal approach is very nasty. They crafted a page that would be picked up by Google and hope that you go to their site.
With Forefront threat management gateway it produces the following warning:

So what do you do in such a case?
This time the alert looked like somebody wrote something about me. But when I clicked I was redirected and confronted with the Antivirus 2009 product. This product had some bad press releases lately since it's a Trojan. It pretends to be good but contains a virus itself. It's a tricky one since it states that your computer might be affected and that they have a cure.
They try to lure you in downloading and executing an exe. Our Forefront client security protects us from this kind of Trojans. But still how it uses a personal approach is very nasty. They crafted a page that would be picked up by Google and hope that you go to their site.
With Forefront threat management gateway it produces the following warning:

So what do you do in such a case?
- First I reported the search result with Google. They removed the link from the search result the same day. Good work Google.
- The URL's used I pinged to determine the IP. That IP I check with http://www.ripe.net. To find out who own the IP or netblock and mailed the abuse and technical contact.
- After that I reported the website via the Internet Explorer Phising filter.
That's more or less I could do. Let's hope it helps other users and that the servers or domains become inactive.
Let me know if you ever experienced such a thing.
Tuesday, September 16, 2008
Compliancy, innovation and security
In this first in-dept topic I will try to cover the impact compliancy can have on security and innovation.
Many companies store customer data like privacy information such as names, email addresses, addresses, phone numbers. But that's not all companies that sell or provide online services might store purchase and payment information like credit card or bank details.
The whole process of obtaining, retrieving and storing the data can be a potential risk and needs to be conform a standard defined by a compliancy institution. Popular certifications and compliancy standards are Sarbanes Oxley, PCI DSS and ISO standards.
It's obvious that compliancy affects many employees, procedures and systems. Therefor it's important to know what is in scope and what not. In my experience I find it use full to set all Internet facing systems in scope. Threating all Internet facing systems the same way as defined by the compliancy standard is a good security practice.
Internet facing systems include mail, voip services, websites and remote access. If these systems must be compliant.
You don't want to be in the middle of a migration when the auditor is looking behind your back. So planning upgrades to new versions or introducing new services need to be between visits of auditors. At least that is what I suggest.
It might be worth to upgrade to a new version or introduce new systems before the auditor comes. If your schedule finds time for planning, deploying, testing and updating documents needed for compliancy.
Upgrades (Microsoft products) that provide better security and are mostly appreciated by auditors are:
With the right hardware investment Vista provides a faster and better more secure computer environment. Especially the dreaded UAC which is a really good security feature against, scripts, virus and trojans.
Forefront client security with WSUS and MOM
This gives you full control over the computers in your network.
Thank you for reading. Let me know if this works for you.
Many companies store customer data like privacy information such as names, email addresses, addresses, phone numbers. But that's not all companies that sell or provide online services might store purchase and payment information like credit card or bank details.
The whole process of obtaining, retrieving and storing the data can be a potential risk and needs to be conform a standard defined by a compliancy institution. Popular certifications and compliancy standards are Sarbanes Oxley, PCI DSS and ISO standards.
It's obvious that compliancy affects many employees, procedures and systems. Therefor it's important to know what is in scope and what not. In my experience I find it use full to set all Internet facing systems in scope. Threating all Internet facing systems the same way as defined by the compliancy standard is a good security practice.
Internet facing systems include mail, voip services, websites and remote access. If these systems must be compliant.
You don't want to be in the middle of a migration when the auditor is looking behind your back. So planning upgrades to new versions or introducing new services need to be between visits of auditors. At least that is what I suggest.
It might be worth to upgrade to a new version or introduce new systems before the auditor comes. If your schedule finds time for planning, deploying, testing and updating documents needed for compliancy.
Upgrades (Microsoft products) that provide better security and are mostly appreciated by auditors are:
- Exchange servers upgraded to Exchange server 2007
- Introducing Office Communicator 2007 and services
- Windows XP to Windows Vista
- Forefront client security
- Removes relaying options on your external SMTP server by introducing the transport role.
- Adds advanced anti spam functions
- Advanced antivirus system with forefront for exchange
- Improved global security with roles and rewritten services and structure
Introducing Office Communicator 2007 and services
- Secure voip services
- Encrypted instant messaging (no need for MSN, skype or other)
- Improved secure communication
Also a drawback which is more externally connected Internet facing IP's and services.
Windows XP to Windows VistaWith the right hardware investment Vista provides a faster and better more secure computer environment. Especially the dreaded UAC which is a really good security feature against, scripts, virus and trojans.
Forefront client security with WSUS and MOM
This gives you full control over the computers in your network.
- Security state assessment and alert reporting
- Enforced real-time antivirus scanning with daily updates
- WSUS for scheduled enforced centrally managed updates
- AD Group Policy Objects for controlling forefront protected computers
Thank you for reading. Let me know if this works for you.
Labels:
AD,
compliancy,
exchange 2007,
Forefront,
GPO,
microsoft,
Office communicator,
PCI DSS,
Security,
upgrading,
Vista,
WSUS
Subscribe to:
Posts (Atom)