Security

Security software

Part of a Group Review

Lumension application control review

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

Lumension Application Control is a strong whitelisting solution with broad file coverage, excellent reporting, and a complete set of Windows file definitions that can be used to spot potentially troublesome changes to system files. Its one noteworthy shortcoming is the inability to create whitelisting rules based on the digital signatures of application publishers.

Lumension ConsoleLumension, which is the product of the marriage of PatchLink and SecureWave, is the parent of several security components and modules, including Application Control, device control, data protection, vulnerability assessment, patching, and antivirus.

Application Control is essentially the latest incarnation of SecureWave's Sanctuary, an application whitelisting product that has been on the market for more than six years. Application Control can be purchased separately, but it is intended to be a primary part of the Lumension Endpoint Protection solution, which includes Lumension AntiVirus, or the Lumension Endpoint Security Solution Pack, which includes Lumension Device Control. Application Control and Device Control share the same management console.

The server side management console, called Lumension Endpoint Security Management, serves multiple components, so it's inherently a bit busier than its counterparts in whitelisting-only products. However, Lumension allows customers to use as many management servers as they need, without paying any server licences, a key advantage when trying to scale out an enterprise deployment or address performance or management issues.

Lumension, like SignaCert, comes with a complete set of standard file definitions (SFDs) for Windows 2000 to Windows 7 operating systems, prescanned and prehashed. These "gold" definitions are useful for noting deviations from the Microsoft defaults. Like all of the competitors in this roundup, Lumension can scan one or more existing computers to automatically generate whitelist execution rules, using the Scan Explorer feature.

Lumension Database ExplorerUnlike most of the other competitors, Lumension can create whitelisting rules for all file types, although it defaults to executables only. The Exe Explorer feature will reveal individual files and their attributes found during the scan or already stored in the database. Files are identified by the normal file attributes (such as name or size) and SHA-1 hashes. Additionally, Lumension allows you to define path rules (allow only) and trusted users who can run anything (called Local Authorisation). Unfortunately, Lumension does not support whitelisting using publisher digital signatures, which is a significant omission in an otherwise very good product.

Identified files are then collected into one or more file groups, custom or predefined, for example, 16-bit, Accessories, Boot files, Logon files, Windows Common, or a trust but watch lists. File groups can be further subdivided. You could have, say, a collective group called Adobe that covers all Adobe files and subgroups for each of Adobe's various products, such as Adobe Reader and Adobe AIR. Lumension's Database Explorer lets the administrator view the various file groups and add identified files screen image.

Users, computers, and groups can be imported from the local Windows SAM (Security Accounts Manager) database, Active Directory, or Novell's eDirectory (Lumension and SignaCert are the only products in this review to integrate with eDirectory), and then linked to one or more file groups, along with whether that particular file group can be authorized (allowed to run) or unauthorized (prevent execution). Any file or file group not explicitly marked as Authorised is considered unauthorised. Like Bit9's Parity, Lumension can send an alert if a particular unauthorised executable becomes popular with too many users too fast. Called "Spread Check" in Lumension, this feature is designed to contain malware outbreaks.

Lumension Log ExplorerDialog messages are customisable. Users and administrators can quickly deny all unauthorised applications, modules (Visual Basic), and scripts (JavaScript and VBScript only) in an emergency. Each managed computer checks in for a new policy at every boot-up, and if the user is offline and unable to connect to the network, an admin can provide a new set of permissions (execute or not execute) that can be manually imported.

While the Report menu option shows system status information, such as when the client's policy was last updated or which server the client got its policy from, queries are both numerous and extremely flexible in Lumension's Log Explorer. Log Explorer shows whitelisting events and provides a good number of "query templates" that are useful in pulling needed information out of the log file. Each built-in query can easily be edited by clicking and choosing various fields of data, as well as dates, conditions, schedules, and formats (XML, CSV, HTLM). Plus, you can right click any event and turn it into a blacklisted or whitelisted file belonging to one or more file groups screen image.



Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500
Advertisement
Advertisement

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *