Why Websense Enterprise Beats SurfControl Web Filter VS Websense A Proven Enterprise Solution Founded in 1994, Websense is the world s leading Web filtering provider and is the preferred vendor of the Fortune 500, the Nikkei 225 and the FTSE 100. Websense Enterprise software is used by more than 20,000 organizations worldwide, encompassing 15.8 million employees. The flexible architecture of Websense allows it to adapt to your unique network configuration and provide maximum speed and security regardless of whether you have 50 or 50,000 users. Some of our leading customers include: ADP Sara Lee Conoco Oil Aurora Healthcare Southwest Airlines Levi Strauss Kimberly Clark Corp. T-Mobile Choice of Standalone or Integrated Deployment With No Difference in Features Websense provides the flexibility of either a standalone or integrated deployment. Standalone offers ease of installation, while an integrated approach enables seamless integration with your existing network infrastructure. More importantly, you get the same Websense features and benefits, no matter which deployment option you choose. Websense advantages: Manages other protocols in addition to HTTP (eg. IM, P2P, streaming media, etc.) Flexible filtering options - includes filter by time-of-day, timebased quotas, continue/defer, multiple Yes Lists, and file-type management for users/groups Bandwidth management limits use of network applications (e.g. streaming media) in real-time based on available bandwidth Enterprise scalability up to tens of thousands of users Comprehensive, up-to-date database of 5+ million sites organized into 80+ categories, encompassing 50+ languages Adaptive feedback loop categorizes new or unrecognized sites using artificial intelligence and human review (WebCatcher) Ability to manage embedded URLs (e.g. Google cache pages, Akamai-based content) Blocks spyware and malicious mobile code Websense Multi-Layer Protection Websense Enterprise is the only solution that combines best-of-breed Web filtering with additive and integrated protection at the network and desktop. It allows organizations to easily manage and report on emerging threats "outside the browser" such as instant messaging, streaming audio and video, peer-to-peer, spyware, malicious mobile code and non-business related applications. Real-time web-based reporting Enables Human Resources, IT, Legal and other department managers to quickly and easily discover trends and identify risks (Explorer) Standard support is included with subscription SurfControl Web Filter VS is Not Suitable for Enterprises Web Filter VS, a standalone proxy server, was launched in November 2001 and represents SurfControl s first offering for the enterprise market. However, VS does not include much of the functionality required by large enterprises. For instance, it lacks the ability to manage non-http protocols, such as instant messaging, peer-to-peer and streaming media. VS also does not allow for flexible management of employee Internet usage. Identifies and manages hacking, games and other inappropriate applications on the desktop by category (CAM) ----------------------------------------- Please note that the information contained in this document is intended to provide general guidance in support of Websense product evaluations, and the use of this document and the information contained herein is limited to Websense employees, our partners and our existing and potential customers. The transmission of this document or any information contained herein to any other parties is expressly prohibited. The information contained herein is believed to be true and accurate at the time it was compiled, and any statements concerning the business operations, product offerings or features of our competitors reflect our good faith efforts to compile such information. The information contained in this document does not constitute any guaranty or warranty with respect to any of the information contained herein, and all such information is subject to change without notice. October 2003
Websense v5 Explanation & Benefit Dynamic Protocol Management Dynamic Protocol Management allows IT managers to manage employee access to a wide variety of protocols such as instant messaging, streaming media and certain applications that tunnel over port 80. Therefore it provides core EIM benefits (productivity, network resources, legal liability) outside the browser to other network apps such as peer-to-peer programs. Another value Websense provides is automatic updates to the protocol lists. It also enables you to manage users/groups/workstations by both category and protocol for any time range. Bandwidth Optimizer Bandwidth Optimizer allows IT managers to set dynamic limits on nonwork-related bandwidth use until network conditions allow more open access. You can manage by users/groups and by protocol. For instance, you can block shopping sites when the total network bandwidth exceeds 50% or block Windows Media Player when this protocol usage exceeds 20% of available network bandwidth. Bandwidth Optimizer lets organizations balance responsible use of network applications with proper network bandwidth for business-critical applications. Central Policy Distribution Websense Central Policy Distribution allows large corporations and distributed enterprises to quickly and easily "push out" centralized Websense policies to multiple Websense servers via a GUI interface. This is done through a one-step replication of policy settings to a server distribution list, which eliminates the need to manually recreate policies among multiple Websense servers. Beneficial for large customers and multinationals. File Type Management Websense can manage and report on internet access by file type. You can control access to file types by logical groups such as Audio, Video or Executables. You can also control access to files by Web site category for instance, block audio files from executing on sports sites, but allow them on financial sites. File type categorizations are provided by Websense and can be updated nightly as part of the regular database download. Client Application Manager (CAM) Client Application Manager extends the value of EIM to the desktop. CAM is an application based on the Websense Client Foundation, which includes the CAM Database of applications, inventory, management and reporting features. Manage applications by policy at the desktop Provide a last line of defense against malicious applications and viruses. Find users in your network who have hacking applications. Lockdown desktops so no new software can be added. Determine the correct number of software licenses needed, based on usage. In the event of a virus outbreak, this feature enables CAM customers to push out a policy to all of their CAM desktops stopping the virus from executing. Operates on a filename basis. Real-Time Analyzer The Real-Time Analyzer is an interactive, Web-based display of real-time network utilization. Views include wellness, top 10 URLs, categories, users, as well as trends and system statistics. Includes the ability to drill down into access logs. A quick and easy way to discover problems and trends on your network as well as show the value of Websense. Risk Reports Risk Reports provide executives and those involved in corporate policy definition with a quick, high-level view of potential areas of risk and loss that can be managed by Websense. Especially when combined with the Real-Time Analyzer, Risk Reports can quickly demonstrate the need for, and value of, Websense Enterprise. SurfControl Web Filter VS SurfControl s VS product does not have the capability to manage non- HTTP protocols. SurfControl s Bandwidth Prioritization is a very simplistic approach to managing bandwidth. Basically it just slows the download process of specified sites based on their priority rating (1 to 5). This feature does not dynamically determine access based on network conditions. Furthermore, users that try and access these sites are not warned beforehand that a Web page will load much slower, which can result in more calls to your IT help desk. Since WebFilter VS does not manage non-web-based protocols, Bandwidth Prioritization applies to HTTP-based protocols only. With SurfControl, you must specify each individual file type extension to manage. SurfControl does not provide categorizations or file type groups (and does not even allow them to be created by administrators).
Feature Comparison Chart - Websense vs. SurfControl VS Websense v5 SurfControl VS Enterprise Features Choice of integrated or standalone deployment Provides EIM protection at the gateway, network, and desktop level Central policy distribution Enterprise scalability Policy based by users/depts Only with LDAP Remote management Directory Services Support: LDAP NTLM Protocol Management Manage other non-http protocols (e.g. IM, P2P, streaming media) Manage protocols and applications that tunnel over HTTP (port 80) Dynamic updates to protocol list Manage by both category and protocol Can be applied to users/groups, or workstations for any time-range User-friendly block message Bandwidth Management Dynamic allows adaptive policies based on network load Bandwidth Prioritization just slows Web page download Manage by users/groups Manage by protocol Employees are notified (via block page) when they reach bandwidth limits File Type Management Filter by file type (keyword) Manage access by Web site category and File Type group (ex: block audio files from running on sports sites but allow on financial sites) Provides automatic updates to File-Types database Other Flexible Filtering Features Filter by time-of-day Continue/defer Time-based quotas Yes Lists Transparent ID Custom keyword lists Customizable block pages Database of Internet Sites Global only; no users/groups Number of sites 5+ million 5+ million Number of manageable categories 80+ 41 Daily, incremental downloads Blocks pop-up ads and banner ads Blocks spyware and malicious mobile code Manages embedded URLs (Google cache pages, Akamai content, etc.) Adaptive database - ability to categorize new or unrecognized sites Reporting (WebCatcher) Number of reports 80+ 55 Real-time analysis (RTA) Risk reports Network User/Group support Forensics for HR, Legal, and other department managers Support Support and maintenance included with subscription Additional 25%
Websense Master Database Comprehensiveness: The Master Database consists of more than 5 million sites and 1.1 billion active Web pages, encompassing 50+ languages. Websense has developed a hybrid solution to Internet filtering, which results in the most comprehensive and precise filtering database of Internet sites in the industry. Freshness: Every effort is made to ensure that the Master Database contains only active URLs. Complex aging programs continually identify URLs and IP addresses that no longer exist. These dead sites are then removed from the database. To date, more than 1.3 million dead links have been removed. Accuracy: Validated by etesting Labs, the Websense Master Database is the highest quality database in the EIM space. The third-party test determined that Websense was the only product that had 90% or better coverage in six major categories of content. Granularity: The Websense Master Database is organized into 80 categories. The Most Scalable and Reliable Database in the Industry Websense Enterprise works in conjunction with the Websense Master Database to effectively manage employee Internet use. The Master Database is developed through the use of automated mining tools and algorithmic classifiers to ensure scalability. When necessary, human review is then used to ensure accuracy. Thus, this hybrid solution utilizes both dynamic filtering to maximize recall, and a comprehensive database or control list at runtime to maximize precision. Why is database reliability important? Database completeness, accuracy and freshness minimize over- and under-blocking. This reduces the burden on the administrator, since more effective filtering results in fewer complaint calls from end-users. SurfControl s Database SurfControl s database contains 5+ million sites. However, it is important to note that the growth of its database has been due to its acquisitions of Little Brother, CyberPatrol, and CSM, thus resulting in duplicates in its database. A scientific study conducted by etesting Labs found that SurfControl did not block 7.5% of pornography sites, which amounts to 15 million missed pages. The following are the percentage of sites in other major categories that were not blocked by SurfControl: Entertainment: 14% Sports: 8% Gambling: 35% Job Search: 28% Shopping: 23% Adaptability through WebCatcher Contrary to SurfControl s claim of it being just a fancy Submit-A-Site feature, WebCatcher is a highly adaptive tool that is able to categorize new or unrecognized sites. Through WebCatcher, the Websense Database adapts to surfing patterns of the Websense customer community. WebCatcher anonymously aggregates and categorizes sites that are new or unrecognized. These sites are then added to the Master Database. This results in a database with more robust language support and an extremely high coverage of sites that end-users actually visit. There is no adaptive filtering solution for Web Filter VS. SurfControl s Virtual Control Agent (VCA) is only available for its standalone product.
The Importance of Database Granularity Granularity and ability not to over- or under-block sites has been mentioned as a key criterion for companies looking to implement EIM software. Having additional categories enables you to be more specific not only with the sites you block, but also with the sites you allow. The ability to manage with more sophistication or granularity in filtering options is important for corporations who want to maintain a balanced work/life environment for their employees. The database provides customers the flexibility to match categories to their corporate policies. Furthermore, database usage studies of our customers have found that the average number of categories filtered is 36. SurfControl makes a misleading claim that they have 130 subcategories. However, only 40 categories are manageable by the user the 130 subcategories are not product categories at all, simply statements of what is included within each of the 40 manageable categories. Websense Category SurfControl Category Websense Category SurfControl Category Abortion Advocacy Racism/Hate Hate* Pro-choice Religion Religion Pro-life Non-Traditional Religions Religion* Advocacy Groups Traditional Religions Religion* Adult Material Adult/Sexually Explicit* Shopping Shopping Adult Content Adult/Sexually Explicit* Internet Auctions Shopping* Nudity Adult/Sexually Explicit* Real Estate Real Estate Sex Adult/Sexually Explicit* Social Organizations Sex Education Sex Education Professional and Worker Lingerie & Swimsuit Glamour and Intimate Apparel Service and Philanthropic Business & Economy Social and Affiliation Financial Data & Services Finance & Investment Society & Lifestyles Lifestyle & Culture* Drugs Drugs, Alcohol & Tobacco* Alcohol/Tobacco Drugs, Alcohol & Tobacco Abused Medication Drugs, Alcohol & Tobacco* Gay & Lesbian Issues Lifestyle & Culture* Prescribed Medications Health & Medicine Personals/Dating Personals & Dating Supplements/Unregulated Compounds Restaurants & Dining Food & Drink Marijuana Drugs, Alcohol & Tobacco* Hobbies Hobbies & Recreation Education Personal Web Sites Hosting Sites Cultural Institutions Arts & Entertainment* Special Events Educational Institutions Education* Sports Sports Educational Materials Education* Sport Hunting/Gun Clubs Reference Materials Reference Tasteless Hate*; Violence/Offensive Entertainment Arts & Entertainment* Travel Travel MP3 Vehicles Motor Vehicles Gambling Gambling Violence Violence/Offensive Games Games Weapons Weapons Government Government & Politics Premium Groups: Health Military Government & Politics* Internet Radio & TV Streaming Media* Political Groups Government & Politics* Peer to Peer File Sharing Streaming Media* Health & Medicine Personal Network Storage/Backup Illegal/Questionable Criminal Skills Internet Telephony Computing & Internet* Information Technology Computing & Internet* Streaming Media Streaming Media* Computer Security Advertisements Advertisements Hacking Hacking Freeware/Software Download Computing & Internet*; Shopping Proxy Avoidance Systems Remote Proxies* Instant Messaging Search Engines & Portals Search Engines Message Boards & Clubs Usenet New Web Hosting Hosting Sites Online Brokerage & Trading Finance & Investment* URL Translation Sites Remote Proxies* Pay-to-Surf Computing & Internet* Internet Communication Spyware Web Chat Chat Malicious Web sites Hacking## Web-based Email Web-based Email Kids Sites Job Search & Career Job Search Development Photo Searches Militancy/Extremist Hate* Reference News & Media News/Arts & Entertainment Law Alternative Journals * Category is broader than Websense category and may encompass two or more Websense categories. ## SurfControl says it blocks malicious Web sites through its 'Hacking Sites' category, but these are sites that provide hacking tools, not necessarily sites that contain malicious mobile code. Any type of site (e.g. sports, news) can be infected.