WHAT S NEW IN WEBSENSE TRITON RELEASE 7.8
Overview Global organizations are constantly battling with advanced persistent threats (APTs) and targeted attacks focused on extracting intellectual property (IP). Scalable across existing platforms and network infrastructure, Websense TRITON security solutions combine real-time APT defenses, global security intelligence, file sandboxing and industry-leading data loss/data theft protection to provide the best defenses available. Websense TRITON Release 7.8 further enhances this technology leadership positon for those seeking to stay ahead of advanced threats with TRITON ThreatScope sandboxing technology, TRITON RiskVision threat monitoring capabilities, and many other new features and enhancements across Web and Email offerings. New For Web Security Websense TRITON ThreatScope Integration TRITON ThreatScope delivers advanced malware protection and detailed forensic reporting for Websense Web Security Gateway Anywhere customers. The following TRITON ThreatScope features are available as an add-on for those customers: File Sandboxing, to protect against malicious documents, extends the protection capabilities of Web Security Gateway Anywhere. Forensic Reporting provides details on the exact nature of the malicious files and the systems potentially impacted. TRITON ThreatScope offers additional features when combining Web Security Gateway Anywhere with Websense Email Security Gateway Anywhere in the TRITON Secure Gateway Anywhere bundle. Additional features included when adding Email Security Gateway Anywhere to a Web Security Gateway Anywhere deployment are: URL Sandboxing, to protect against malicious links from any device at any time. Threat Sandboxing, to protect against malicious email attachments, extends the protection capabilities of Websense email security solutions. Page 2
Websense TRITON RiskVision TRITON RiskVision is an easy-to-deploy threat monitoring solution that offers customers the ability to monitor and evaluate their exposure to advanced threats and data theft attempts without interfering with any existing infrastructure. TRITON RiskVision monitors inbound and outbound web traffic using Websense ACE (Advanced Classification Engine), Websense ThreatSeeker Intelligence Cloud, built-in data loss prevention (DLP) engine, and file sandboxing capabilities without blocking them. It provides full traffic analysis with the ability to run over 60 predefined and customizable reports, offering valuable insight into the current web security effectiveness for immediate response. Administrators also have the ability to set up automatic alerts for threat and suspicious activity. TRITON RiskVision can be deployed as a stand-alone product or alongside existing competitive solutions as well as other Websense solutions such as Web Security or Web Security Gateway. It is deployed on a Websense appliance in a TAP setting or with a Span port. Please see the TRITON RiskVision Datasheet for more information. Websense i500 /i500v Appliance (Cloud Assist Appliance) For Websense Cloud Web Security Gateway customers, the i500 cloud-assist appliance will provide an interesting deployment option to increase network traffic speed and improve control over what traffic gets sent to the cloud. This new appliance is specifically interesting for customers with networks in countries with national firewalls. The i500 appliance offers the following key benefits for Cloud Web Security Gateway customers: Control which traffic gets sent to the cloud and which traffic will be analyzed on-site. Increase network speed by sending traffic for fast analysis through the appliance rather than into the cloud. Provide protocol and application control through the built-in Network Agent. Ability to monitor and filter guest networks. Please refer to the i500 Appliance datasheet for more information. Page 3
SSL Performance Enhancements The computer landscape has changed to the point where almost 40 percent of web traffic is now SSL based, and visibility into SSL traffic has become a necessity for security conscious companies. To accommodate this market requirement, Websense has enhanced the SSL proxy with dynamic SSL performance. The SSL proxy is optimized for Websense V10000 and V5000 appliances, and provides additional enhancements for deployment with Websense V10000 G3 appliances ensuring fast and efficient inspection of SSL traffic. Authentication Enhancements Authentication of Macintosh users and the ability to apply policy run reports based on the user identity instead of IP addresses is now supported. New For Email Security Virtual Appliance Companies of all sizes have invested in VWware to maximize their hardware resources, provide redundancy, increase performance and scalability and reduce server and appliance footprint. With the Websense email security virtual appliance you can combine all the benefits of our Email Security Gateway and Email Security Gateway Anywhere solutions with your VMware (ESXi 4.01+) infrastructure. The Email Security Gateway Virtual Appliance is a one-time purchase with no maintenance required. The open virtualization format (OVF) file can be downloaded from MyWebsense. TRITON ThreatScope Integration TRITON ThreatScope delivers advanced malware protection and detailed forensic reporting for email. The following TRITON ThreatScope features are available to email security customers: URL Sandboxing, to protect against malicious links from any device at any time. Threat Sandboxing, to protect against malicious email attachments, extends the protection capabilities of Websense email security solutions. Forensic Reporting provides details on the exact nature of the malicious threat and the systems potentially impacted. Phishing Reports provide details on blocked phishing attacks, phishing targets and repeat phishing targets. End-User Education recognizes that educating end-users about phishing attacks is vital. By allowing phishing messages, where the malicious link has been rewritten and disarmed, to be delivered to end-users they are shown that even a legitimate looking email can be harmful. Clicking the now disarmed URL returns a customizable block page that further reinforces the end-user education. Page 4
Extended Administrator Roles IT organizational structures can include many different support roles, each requiring different levels of access. Extended administrator roles align Websense email security permissions with corporate support responsibilities. Extended Administrator Roles now include the following: Super Administrator has complete access to the system and manages all the admins. Security Administrator has access to all general settings and is able to add new domains and setup routes and preferences. Policy Administrator has access to setup filtering policies for specific policies. Since these policies are defined for users and groups, the policy administrator has permissions only to alter the policies of the group. Quarantine Administrator is provided access to manage specific queues and is able to troubleshoot from logs and release messages to the users from those specific queues. Reporting Administrator that has access to generate and schedule reports. Group Reporting Administrator that has access to generate and schedule reports only to specific groups. Read-Only Administrator has access to the service to read all configuration and settings, but cannot make any changes. Enhanced Reporting Visibility and awareness are vital for today s busy IT administrator. Websense email security increases the number of built-in reports, enhances many existing reports and adds new dashboard portlets to provide administrators the exact visibility the require in to their email security infrastructure. New presentation reports and dashboard portlets include: Inbound Spam Volume Inbound Commercial Bulk Volume Message Volume by Direction Inbound Volume by Type Top Mandatory TLS Domains And many more Page 5
Real-Time Monitor displays logs in real-time to assist with troubleshooting. Multiple verbose levels, combined with filtering, allow for displaying just the right amount of information. For example, only show log entries that have a specific sender or recipient email address. (See Below). Office 365 Support Websense email security now provides complete inbound and outbound email support for Office 365 and hosted Exchange customers. Websense enhances Office 365 with both our advanced email security based on the global threat awareness of ACE and ThreatSeeker Intelligence Cloud as well as the advanced malware capabilities of TRITON ThreatScope. For outbound email our award winning DLP solutions can help Office 365 customers meet their regulatory compliance in addition to protecting their vital intellectual property. Enforced Inbound TLS TLS is the most transparent form of email encryption and TLS adoption is increasing. Enforced Inbound TLS allows administrators to require that inbound connections from specified domains will only be accepted using TLS. When combined with outbound Mandatory TLS, Enforced Inbound TLS guarantees that all email communication between the specified domains is encrypted using TLS. Learn more at www.websense.com +1 800-723-1166 info@websense.com TRITON STOPS MORE THREATS. WE CAN PROVE IT. 2013 Websense, Inc. All rights reserved. Websense, TRITON and the Websense logo are registered trademarks of Websense, Inc. in the United States and various countries. All other trademarks are the properties of their respective owners. ENG-US. 10/10/13 Page 6