Sophos Application Whitelisting: Advanced Server Protection Made Simple
Sophos Application Whitelisting: Advanced Server Protection Made Simple
Whitelisting
Advanced Server Protection made simple
By Gail Ferreira, Sr. Product Marketing Manager, ESG
Overview:
The Challenge of Protecting Servers Sophos Server Lockdown
Servers, with their business critical applications, are prime targets for attack. Protecting integrates application whitelisting
the integrity of these applications and maintaining the uptime of the servers that run them with advanced anti-malware and
remains a top concern of any organization today. Traditionally, organizations have deployed runtime behavior analysis to deliver
endpoint security to protect their servers. But endpoint security falls short in that protection, powerful server-specific protection
requiring extensive configuration and optimization for server performance, which makes for while still keeping it simple to
a complex process. deploy and maintain.
Highlights:
• Single-click Server Lockdown
Application Whitelisting creates a whitelist of authorized
Application whitelisting is increasingly finding its way into server environments as a applications automatically
recommended method to keep advanced and unknown threats from executing on servers. • Automatic trust rules,
Whitelisting uses a default-deny approach to help organizations keep their operating managed on your behalf
system secure, as well as specific business applications being used on each server. Rather by Sophos, allow trusted
than focusing only on trying to detect malware and prevent it from running, application applications and updaters to
whitelisting instead prevents all untrusted and unknown applications from running. This execute without interference
offers proactive, comprehensive protection against known and unknown threats because it
ensures that only authorized applications are able to run on the system. • Add your own trust rules with
ease, without unlocking the
As Gartner recently stated, “It is much more effective to apply a default deny application server
control model to server workloads than it is on end-user-facing endpoints… The use of
whitelisting to control what executables are run on a server provides a powerful security • Lock down servers without
protection strategy.” 1 taking them offline or rebooting
1
Gartner, Market Guide for Cloud Workload Protection Platforms, March 2016, Neil MacDonald and Peter Firstbrook.
3. Automatically developing trust rules to ensure that only trusted sources can update
those whitelisted applications. This trust between applications controls which
executables can update existing applications. Sophos creates a data feed on trusted
applications which automatically configures how the installed applications can be
updated. Thus Windows updates or application upgrades are allowed to run without
interference, but not ransomware.
4. Completing the lock down process, ensuring that only those approved applications are
able to execute – eliminating tedious and time-consuming ongoing manual configuration
and rule-setting.
Note: In addition to the trust rules applied and maintained by Sophos, customers can
add their own allow (trust) rules in the Sophos management console if needed to authorize
additional software to run — without needing to unlock the server. Similarly, you can also
block software that has previously been whitelisted/authorized, simply by adding it to the
policy.
Once the server has been locked down, Sophos’ context-aware security engine continuously
monitors the system to prevent content-based attacks, utilizing anti-malware and HIPS
behavior analysis to protect against memory and run-time attacks. In lockdown mode, only
the baseline applications and all associated files and scripts can execute; they cannot be
replaced or tampered with, except by trusted updaters. New applications will not be able to
run unless allowed by the Sophos Central admin.
Server Management
Status
Sophos Central
Lock/Unlock Servers
Apply additional trust rules, if desired Apply rules on
Monitor Server Lockdown events
Server Authority
Whitelisting
Does it need to be Create a profile/ Add to
whitelisted? Is it malicious? fingerprint executable whitelist Apply rules on
Server Authority
File .exe .exe .exe
Create Enforce
trust rules trust rules
Server
Applying Trust
Other innovative features from Sophos work together to give you the broadest protection for
your servers, for the data they contain, and for the business-critical applications that they
run. These features include:
5. Peripheral Control, preventing USB devices from propagating malware or exfiltrating data.
Conclusion
Today’s environment urges you to protect your organization’s servers from zero-day and
advanced threats while ensuring the performance of critical applications is unaffected.
Sophos application whitelisting (Server Lockdown) provides simple yet powerful server
protection. Let Sophos do the work with a single click rather than manually cataloguing and
configuring all the application components to set up default deny policies. Know that you
have a known good state that is maintained by ServerAuthority.
Sophos Server Protection takes advantage of a broad variety of techniques to protect your
servers. We have discussed application whitelisting, but Sophos also integrates server
anti-malware, HIPS behavior analysis, and Malicious Traffic Detection to protect servers,
countering threats with the most effective approach for each potential vector of attack.
Sophos Server Protection is optimized for servers, not end user systems, and leverages
SophosLabs for real-time threat intelligence. Take advantage of its optimized performance
and effective protection for your servers, and enjoy unprecedented ease of use and
management.
United Kingdom and Worldwide Sales North American Sales Australia and New Zealand Sales Asia Sales
Tel: +44 (0)8447 671131 Toll Free: 1-866-866-2802 Tel: +61 2 9409 9100 Tel: +65 62244168
Email: [email protected] Email: [email protected] Email: [email protected] Email: [email protected]
Oxford, UK
© Copyright 2016. Sophos Ltd. All rights reserved.
Registered in England and Wales No. 2096520, The Pentagon, Abingdon Science Park, Abingdon, OX14 3YP, UK
Sophos is the registered trademark of Sophos Ltd. All other product and company names mentioned are
trademarks or registered trademarks of their respective owners.