Application whitelisting review: CoreTrace Bouncer
- 04 November, 2009 22:13
- Comments
CoreTrace's Bouncer 5 is application control and more. Bouncer is the only product in InfoWorld's review that successfully protected against buffer overflows. It also offers unique write protection of whitelisted files and does a nice job of handling updates to controlled applications.
A great-looking GUI, good reporting, and secure sessions between clients and the management server round out the rich feature set. However, Bouncer doesn't cover all program file types, notably those written in interpreted languages such as Python, PHP, or Java.
Started in early 2008, Bouncer is made up of a Windows XP Embedded management appliance and supports clients running Windows NT 4 SP6a and later and Solaris 7 through 10. The extra features and security considerations put into this product are evident from the start.
Logging into Bouncer's Control Center management console screen image requires a two-factor USB access token and either physical access to the management appliance or a Remote Desktop Protocol (RDP) session. Connections between the management console and clients are IPSec protected with PKI certificates. This is all automated in the setup of clients and server, and it does not use the normal Windows implementations.
The use of client certificates also aids monitoring. Clients can get new IP addresses, new network interfaces, new names, and so on, yet still be identified and tracked through the use of the certificate. Clients automatically check back in to the management console every 60 seconds using heartbeat packets across two high-numbered UDP ports, or you can schedule the connections for finer-grained control.
Managed computers are collected into groups known as Security Configurations. In fact, calling groups of computers Security Configurations is one of the few minor weaknesses of an otherwise top-of-the-class product. To be fair, Security Configurations are really the grouping of computers along with their defined treatment. But a simpler label would avoid potential confusion.
Three Security Configurations are provided out of the box -- All Installed Systems, Pending Systems, and Unsecured Systems -- but administrators are encouraged to make their own custom groupings. Each Security Configuration (i.e., group) will have its own Bouncer settings and Policy Components defined.
Policy Components are built around the concept of trusted change. Administrators can define Trusted Applications (applications that are allowed to run), Trusted Digital Signatures (all applications signed by the same digital signature can run), Trusted Network Shares (any application in a trusted location can run), and Trusted Users (trusted users can run any program). Each managed computer will inherit the policy components defined for its Security Configuration.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Leaving your job? Take your data with you
-
The Case for Real-Time Networking
CIOs are facing several powerful trends and inflection points that are defining the new IT landscape, including cloud computing, virtualization, the consumerization of IT, smart computing, and communications to collaboration. Taken individually, each one of these trends will have significant ripple effects throughout the planning and operations of IT network infrastructure. In aggregate, they will have an even more dramatic impact on the way that future network architectures need to be planned and designed. Read on. -
Managing IBM License Complexity
IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on. -
A Technical Overview of the Oracle Exadata Database Machine and Exadata Storage Server
Businesses today increasingly need to leverage a unified database platform to enable the deployment and consolidation of all applications onto one common infrastructure. Whether OLTP, DW or mixed workload a common infrastructure delivers the efficiencies and reusability the datacenter needs – and provides the reality of grid computing in-house. Read on.
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 All-In-One Desk Reference for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Microsoft Office
-
Windows 7 for Dummies®








Comments
Post new comment