Virtual Desktop Strategies

Sangfor Releases Extended Detection, Defense and Response (XDDR) Application Containment

Sangfor Technologies | September 17, 2021

Sangfor Technologies announced the release of their long-awaited extended protection solution, XDDR Application Containment. Based on Sangfor's XDDR security framework, Application Containment allows the network and endpoints (both on-premise or in-cloud) to work together to identify, control, and report on all applications running on endpoints, or using the network to communicate. Sangfor's XDDR provides an integrated solution that protects against ransomware, malware, APTs, phishing websites and email, and potentially malicious applications.

Controlling and enforcing internet access policies in the workplace has not been easy. Employees want access to the internet for personal use as well as their work, making overly restrictive security solutions difficult to implement and maintain. Organizations deploy proxy servers to control access to the internet and external applications. This access control is necessary to maintain productivity, ensure users do not access malicious sites and unknowingly download malware, and to maximize bandwidth utilization for critical business applications.  Many users employ VPN (virtual private network) technology, anonymous browsers, and other proxy avoidance applications to bypass organizational security and content filtering policies enforced by the proxy servers. Sangfor XDDR Application Containment solutions enable the organization to quickly create Proxy Avoidance Protection policies for blocking usage of proxy avoidance tools and applications on the endpoint.

Sangfor's NGAF (Next Generation Application Firewall), IAG (Internet Access Gateway) and Endpoint Secure products work cohesively to provide real-time visualization of all application communication throughout the entire network, quickly identifying proxy avoidance traffic. Proxy Avoidance Protection policies can quickly be built on the NGAF or IAG from Sangfor's extensive library of anti-proxy and proxy avoidance applications. These policies are then deployed by Endpoint Secure to block or monitor anti-proxy applications.

Organizations can also create whitelists and blacklists of applications in Application Containment. This gives administrators granular control of applications running on PCs, laptops, and servers to prevent installation of malware and ransomware, especially with users working from home, to prevent infection of corporate, enterprise, or organizational networks, resources, and critical assets. Peripheral Control manages access to connected USB devices to prevent data leakage.

Traditional extended detection and response (XDR) is network security technology designed to provide increased visibility, analysis functions and response to cyber-threats in the network, cloud, applications, and endpoints. XDR is positioned as the most sophisticated technology available but tends to be more marketing hype than reality, having been developed as the progression of EDR, or endpoint detection and response, to work with non-integrated network security products. Unlike XDR products, Sangfor XDDR Application Containment is the only true solution where network and endpoint work together to identify, control, and report on both allowed and malicious applications running on endpoints and communicating across the network. Sangfor NGAF, IAG and Endpoint Secure coordinate responses so Application Containment can provide real-time blocking and monitoring of unapproved or malicious applications.

Control can be regained from rogue applications delivered by ransomware, malware and APTs that users bring into networks. Sangfor Application Containment blocks the bypassing of internet access controls and prevents users from bringing them in again.

About Sangfor Technologies
Sangfor Technologies is a leading global vendor of IT infrastructure and security solutions, specializing in Cloud Computing & Network Security with a wide range of products & services including Hyper-Converged Infrastructure, Virtual Desktop Infrastructure, Next-Generation Firewall, Internet Access Gateway, Endpoint Protection, Ransomware Protection, Managed Detection and Response, WAN Optimization, SD-WAN, and many others.

Spotlight

When you install NAKIVO Backup & Replication on ARM-based NAS devices, an external Transporter is needed to work with VMware vCenters and ESXi hosts. This is to ensure smooth and efficient backup and replication processes for your VMware data.

Spotlight

When you install NAKIVO Backup & Replication on ARM-based NAS devices, an external Transporter is needed to work with VMware vCenters and ESXi hosts. This is to ensure smooth and efficient backup and replication processes for your VMware data.

Related News

Server Virtualization

Tachyum Demonstrates Support for Xen Hypervisor

businesswire | August 03, 2023

Tachyum® today announced that it has completed porting of all the software necessary for chip validation on the Prodigy FPGA prototype before it is sent for tape out with the successful running of the Xen hypervisor on a QEMU software emulator. Xen is a type-1 hypervisor providing services that allow multiple virtual machines to run on a single physical host system, sharing resources such as memory, processing and devices. Its bare metal capabilities allow the Xen hypervisor to communicate directly from the host’s hardware, acting like a lightweight operating system. It supports four types of virtualization: paravirtualization, full hardware virtualization, full virtualization with a set of paravirtualization drivers, and paravirtualization with hardware virtualization support. Tachyum demonstrated its support of XEN running in three different modes: Standard “dom0” mode – the most privileged domain and the only virtual machine that has direct access to hardware by default. From dom0, the hypervisor can be managed and unprivileged domains (domU) can be launched. Hyperlaunch – enabled seamless transition for existing systems that require a dom0. Provides a new general capability to build and launch alternative configurations of VMs, including support for static partitioning and accelerated start of VMs during host boot while adhering to the principles of least privileged. Dom0less – a set of Xen features that enable the deployment of a Xen system without a control domain (dom0). It is a hyperlaunch-like configuration with static partitioning without using dom0. This means that there are no virtual devices and hardware resources are statically assigned to a specific virtual machine using the passthrough method. “In order to assure that Prodigy truly becomes the means for transforming data centers into Universal Computing Centers, we need to ensure that it can properly handle any number of components, software and technology available now or in the future,” said Dr. Radoslav Danilak, founder and CEO of Tachyum. “By successfully running Xen in our Prodigy software emulator, we can confidently assure organizations that they will reap the full benefits of Prodigy when it becomes commercially available. I’m proud of the work of our highly skilled software team as they continue to complete the final components needed before tape out.” Prodigy delivers unprecedented data center performance, power, and economics, reducing CAPEX and OPEX significantly. Because of its utility for both high-performance and line-of-business applications, Prodigy-powered data center servers can seamlessly and dynamically switch between workloads, eliminating the need for expensive dedicated AI hardware and dramatically increasing server utilization. Tachyum's Prodigy delivers performance up to 4x that of the highest performing x86 processors (for cloud workloads) and up to 3x that of the highest performing GPU for HPC and 6x for AI applications. About Tachyum Tachyum is transforming the economics of AI, HPC, public and private cloud workloads with Prodigy, the world’s first Universal Processor. Prodigy unifies the functionality of a CPU, a GPGPU, and a TPU in a single processor that delivers industry-leading performance, cost, and power efficiency for both specialty and general-purpose computing. When hyperscale data centers are provisioned with Prodigy, all AI, HPC, and general-purpose applications can run on the same infrastructure, saving companies billions of dollars in hardware, footprint, and operational expenses. As global data center emissions contribute to a changing climate, and consume more than four percent of the world’s electricity—projected to be 10 percent by 2030—the ultra-low power Prodigy Universal Processor is a potential breakthrough for satisfying the world’s appetite for computing at a lower environmental cost. Prodigy, now in its final stages of testing and integration before volume manufacturing, is being adopted in prototype form by a rapidly growing customer base, and robust purchase orders signal a likely IPO in late 2024. Tachyum has offices in the United States and Slovakia.

Read More

Virtual Desktop Tools, Virtual Server Management

Anviz Launches Next-Gen OSDP-Powered Access Control Solutions, Setting New Industry Standards

prnewswire | July 11, 2023

Anviz, an industry leader in professional and converged intelligent security solutions, has announced the launch of its next-generation access control solutions powered by Open Supervised Device Protocol (OSDP). The two new offerings – the SAC921 single-door access controller and C2KA-OSDP RFID keypad reader – are future-proof systems packed with state-of-the-art technology and smart features. Both solutions seek to ensure customer safety and peace of mind, providing a comprehensive security solution for today's modern world. "Mounting concerns surrounding personal data security have raised awareness about the importance of digital safety in recent years, which is expected to drive significant changes in safety standards for data storage and transfer," said Felix, Product Manager of Anviz. "Aiming to take the lead in transforming how personal data is safeguarded, we launched our latest OSDP-based solutions equipped with tailor-made features for businesses looking for more advanced access control systems. We also believe SIA OSDP, the most widely-recognized standard for access control systems, will play a pivotal role in addressing security concerns by empowering manufacturers to offer enhanced security options with diverse functionalities to global users." SAC921 Single-door access controller SAC921 is a PoE-powered access control system that offers great flexibility and simplicity with a wider range of access control interfaces supporting alarm input, perimeter security, and device control. The SAC921 provides a revolutionary upgrade to the traditional Wiegand-based access control systems, significantly streamlining device operations while offering improved security features and better third-party compatibility. Due to the adoption of PoE, OSDP, and built-in management software, installation of the SAC921 is easier and more cost-effective. Via Anviz's CrossChex remote control system, users can also access a more comprehensive set of security options, such as personnel identity verification, access control, and time attendance management system, granting powerful and customizable security capabilities. C2KA-OSDP RFID keypad reader The C2KA-OSDP RFID keypad reader ushers in a new era of PIN code access, delivering unrivaled convenience for both credentialed users and visitors alike. The cutting-edge reader goes beyond traditional access control by supporting multi-factor authentication with seamless integration of various credentials and access methods. The keypad reader's breakthrough security capabilities are made possible by OSDP, securing connections and safeguarding against hacks. Unlike traditional Wiegand-based systems, OSDP-powered devices enable bidirectional communication between controllers and card readers using RS485, allowing for real-time monitoring of the card reader's status. This enables access control software to monitor, control, and encrypt data between the access control controller and card reader, delivering advanced tamper protection and usage tracking. OSDP's key value come from its superior flexibility. Data shared between OSDP access control and readers are no longer confined to fixed-length data fields, such as 24 or 36, with AES128 encryption ensuring higher data security. As a member of SIA, Anviz intends to introduce more SIA OSDP Verified products to the global markets, allowing customers worldwide to enjoy higher security, richer functionality, greater ease of use, and increased interoperability brought by OSDP. The packaged access control solution that combines the SAC921 access controller and C2KA-OSDP RFID keypad reader is scheduled to be launched in the second half of 2023. Anviz is also planning to upgrade its products to support greater compatibility with third-party solutions. This will be tailored to the needs of various industries, including education, government, commercial real estate, retail, manufacturing, healthcare, and hospitality users, allowing them access to a comprehensive and integrated security control experience. AboutAnviz Global Anviz is the leading security solution provider for the commercial market. We are providing smart solutions based on cloud and IoT technologies to SMB and enterprises clients globally. Security is crucial to any office or facility, every building needs a way to keep the space safe, and most organizations also need to restrict access to certain areas. Anviz is the first access control company to make use of biometrics-based, RFID cards, mobile access technology and specialized hardware to achieve space safety goals. The powerful security features with convenient and flexible system, provide office efficiency for enterprises small and large.

Read More

Server Virtualization, Security

Versa Networks Showcasing SSE and Zero Trust Everywhere at Black Hat USA 2023

businesswire | August 07, 2023

Versa Networks, the recognized leader of single-vendor Unified Secure Access Service Edge (SASE), today announced it will demonstrate the latest in Unified SASE security and networking services at Black Hat USA 2023 next week. The company’s security and networking experts will be available during the event to meet with attendees and discuss the latest in applying tightly integrated SASE services to solve their complex secure networking needs. Exhibiting at Black Hat USA 2023 in Booth 1389, Versa will demonstrate three main solutions to protect branches and remote workers: Secure Internet Access (VSIA): This solution ensures secure internet access for branches and remote workers by offering a range of security features, including: Web Filtering (SWG) to control and monitor web traffic; SaaS Application Security (CASB) for securing cloud-based applications; Data Leak Security (DLP) to prevent unauthorized data leakage; Anti-virus and Intrusion Prevention to protect against known threats; Malware and Ransomware Protection to safeguard against malicious software; and BYOD Access Management to regulate personal devices accessing the network. Zero Trust Network Access (Zero Trust Everywhere, VSPA): This solution replaces traditional VPNs and adopts a Zero Trust approach to provide secure network access for branches and remote workers. Secure SD-WAN: This solution transforms branch networks by delivering software-defined networking with built-in security features. It includes: MPLS Replacement for more efficient and cost-effective network connections; and Next-Gen Firewall (NGFW), Intrusion Detection/Prevention Systems (IDS/IPS), and Unified Threat Management (UTM) features integrated within the SD-WAN solution. The company will also host a presentation by Vikram Phatak, CEO of CyberRatings.org, a non-profit member organization that provides transparency and expert guidance on cybersecurity risks through research and objective product testing, on Aug. 10 at 11 am PDT at Versa’s booth. Mr. Phatak will discuss testing initiatives for SD-WAN, SSE Threat Protection and ZTNA. Attendees will learn from his expertise in developing testing methodologies and performing in-depth evaluations. Versa’s AI/ML-powered single-vendor Unified SASE delivers organically developed best-of-breed functions that tightly integrate and deliver services via the cloud, on-premises, or as a blended combination of both, managed through a single pane of glass. Versa delivers SASE services such as Secure SD-WAN, Next-Generation Firewall, Next-Generation Firewall as a Service, Cloud Network Firewall, Unified Threat Management (UTM) including Advanced Threat Protection (ATP), Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), Remote Browser Isolation (RBI), and User and Entity Behavior Analytics (UEBA). Versa’s single-vendor Unified SASE platform goes above and beyond management console automation by providing the ability to integrate networks, points of presence, policy definitions, application definitions, agent logic, and data lakes. Versa simplifies how enterprises protect and connect their users, devices and sites to workloads and applications anywhere, anytime to improve security posture and enhance user-to-application experience and operational efficiency. Gartner has identifiedVersa SASE as having the most SASE components out of all 56 vendors Gartner evaluated and named Versa as one of the vendors delivering single-vendor SASE. Dell’Oro Group has namedVersa the Unified SASE market share leaderfor two years in a row, while 650 Group has recognizedVersa as the market share leaderfor both Deployed SASE and Enabled SD-WAN since 2020. Also, KuppingerCole Analysts AG named Versa a leader in every evaluation category in itsSASE Integration Suites Leadership Compassreport. In addition, Frost & Sullivan honored Versa with itsSASE Global Enabling Technology Leadership Awardfor its industry-leading SASE solution. Enterprise Management Associates (EMA) also found thatVersa SASE has the most SASE supported functions,while theCIO CHOICE 2023 Honor and Recognitionprogram distinguished Versa SASE as the Most Trusted Brand by CIOs for SASE. About Versa Networks Versa Networks, the leader in single-vendor Unified SASE platforms, delivers AI/ML-powered SSE and SD-WAN solutions. The platform provides networking and security with true multitenancy, and sophisticated analytics via the cloud, on-premises, or as a blended combination of both to meet SASE requirements for small to extremely large enterprises and Service Providers. Thousands of customers globally with hundreds of thousands of sites and millions of users trust Versa with their mission critical networks and security. Versa Networks is privately held and funded by Sequoia Capital, Mayfield, Artis Ventures, Verizon Ventures, Comcast Ventures, BlackRock Inc., Liberty Global Ventures, Princeville Capital, RPS Ventures and Triangle Peak Partners.

Read More