SonicWALL Email Security - Info-Point

Transcription

SonicWALL Email Security - Info-Point
SonicWALL Email Security – das
müssen Sie wissen
Sven Janssen
Channel Sales Manager
Agenda
ƒ Email Security Markt
ƒ SonicWALL Email Security Demo
ƒ SonicWALL Email Security Produktlinie
ƒ Preise & Verfügbarkeit
ƒ Wettbewerb
ƒ Vorteile für SonicWALL Channel Partner
2
CONFIDENTIAL All Rights Reserved
Email Security heute:
Bedrohungen nehmen zu
ƒ Aufkommen an Emails steigt
ƒ Bedrohungen durch Email
nehmen zu und Attacken
werden gefährlicher
ƒ Hybrid-Angriffe
ƒ Angriffe auf die
Unternehmensinfrastruktur
The value of email to an organization mandates a strategic and sustained
approach to creating a hygienic and secure messaging infrastructure.
– META Group, 2005 Delta
3
CONFIDENTIAL All Rights Reserved
The @ in action
Disguising the URL
<a
href="http://internal/login/update/accounts/se
curid/secureupdatecode=3D849E459FB77A
C8C5783450459c3849aa23cd94834839913
449913445223cd9483991344523D@http://
www.sisterstuff.com/images/index.html">http
://internal/loginupdate.htm</a>
Display Link: http://internal/loginupdate.htm
Status Bar: http://internal/login/update/accounts/securid/secureupdatecode=3D849E...
Reality: http://www.sisterstuff.com/images/index.html
4
CONFIDENTIAL All Rights Reserved
onMouseOver
Shows a false URL in
the status bar of the
user’s email application
<A onmouseover="window.status
'https://www.paypal.com/cgi-bin/webscr?cmd_login-run'; return true“ onmouseout
"window.status='https://www.paypal.com/cgi-bin/webscr?cmd=_login-run'“
href "http://leasurelandscapes.com/snow/webscr.dll">
https://www.paypal.com/cgi-bin/webscr?cmd_login-run</A>
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run
5
CONFIDENTIAL All Rights Reserved
http://signin.ebay.com/ws/eBayISAPI.dll?...
6
CONFIDENTIAL All Rights Reserved
PHISH
7
CONFIDENTIAL All Rights Reserved
Email Security heute…
ƒ Viele Kunden haben Email-Gateways als Lösung für AntiSpam, Anti-Virus und/oder Policy-Management
ƒ ABER …
ƒ
ƒ
ƒ
ƒ
ƒ
8
Lösungen sind nicht effektiv genug / zu viele “False Positives”
fehlende Email Compliance
“one size fits all” Richtlinie für das gesamte Unternehmen
Kompliziertes Management der Lösung
Zu viele Hersteller
CONFIDENTIAL All Rights Reserved
Email Security Markt
9
CONFIDENTIAL All Rights Reserved
Gartner Magic Quadrant 2005
10
CONFIDENTIAL All Rights Reserved
SonicWALL Email Security
ƒ
ƒ
ƒ
ƒ
11
Für KMU, Mittelstand und große Unternehmen
Verfügbar als Software- ODER Appliance-Lösung
Arbeitet mit jedem Email-system (SMTP) & Verzeichnisdiensten (LDAP)
Sehr große Flexibilität
ƒ Gruppen, Abteilungen und einzelne User
CONFIDENTIAL All Rights Reserved
Vorteile
ƒ Best-of-Breed Email Threat Protection
ƒ Anti-Spam, Anti-Virus, Anti-Phishing, DHA/DoS Protection, etc
ƒ Email Content Compliance
ƒ Unternehmensvorschriften sowie rechtliche Regularien
ƒ Einfach zu installieren und zu verwalten
ƒ Set up in ca. 30 Minuten
ƒ 10 Minuten Verwaltungsaufwand pro Woche
ƒ 98% Anti Spam Erkennung
ƒ 0% False/Positiv
ƒ > 40% mehr Performance gegenüber dem Mitbewerb
12
CONFIDENTIAL All Rights Reserved
Typisches Email Data Center
Typical Mail Data Center
13
CONFIDENTIAL All Rights Reserved
SonicWALL Email Security –
Schutz vor ALLEN Email Gefahren
Typical Mail Data Center
Mail Data Center Consolidated with
SonicWALL Email Security
14
CONFIDENTIAL All Rights Reserved
Vorteil für Solution Provider
ƒ
Umfassende Email Security Lösung für SMB & Enterprise Markt
ƒ
Neue Umsatzmöglichkeiten:
ƒ Upsell an existierende Kunden
ƒ SMB Kunden, die schon eine Firewall besitzen
ƒ Neue Kunden:
ƒ Vergrössern des Projekts, bei dem es zunächst nur um FW/VPN geht
ƒ
15
Preis-/Leistungsverhältnis der Lösung
ƒ Kunde hat optimalen TCO und ROI
CONFIDENTIAL All Rights Reserved
SonicWALL
Email Security
Produktlinie
16
CONFIDENTIAL All Rights Reserved
Email Security Produktlinie
# Users
< 50
< 100
< 250
< 1000
SMB
SonicWALL Email Security
(SMB Appliances)
200
300
SonicWALL Email Security
Software – Enterprise
17
CONFIDENTIAL All Rights Reserved
X
X
5000+
Enterprise
400
500
SonicWALL Email Security
(Enterprise Appliances)
SonicWALL Email Security
Software
< 5000
X
6000
8000
X
X
X
SonicWALL Email Security
Produktlinie
Product Name
Functionality
Email Security 200, 300, 400 & 500 (SMB
appliances)
ƒ MTA
ƒ DHA/DoS protection
ƒ Policy Management
ƒ LDAP Synchronization
ƒ Management
ƒ Reporting
ƒ Etc
ƒ Anti-Spam (1 year)
ƒ Anti-Phishing (1 year)
ƒ Software/firmware updates (1
Email Security 6000 & 8000 (Enterprise
appliances)
Email Security Software (for Windows OS)
Email Security Software–Enterprise (for Windows
OS)
Email Protection Subscription and Dynamic 8x5
Support for …*
Email Protection Subscription and Dynamic 24x7
Support for …*
year)
ƒ 8x5 OR 24x7 support (1 year)
ƒIncludes RMA for Appliance
* Erforderlich für Appliance- und Software-Lösung
18
CONFIDENTIAL All Rights Reserved
Email Security – Pricing
# Users (Software & Appliance)
< 50
< 100
< 250
< 1000
< 5000
5000+
Appliance Model
200
300
400
500
6000
8000
Software Price*
$995
$1,595
$3,495
$7,495
$14,995
$22,995
$1.674
$2.394
$4.794
$9.594
$19.194
$31.194
Email Protection Subscription
and Dynamic 8x5 Support for …**
$600
$800
$1,700
$3,100
$6,700
$10,700
Email Protection Subscription
and Dynamic 24x7 Support for
…**
$720
$1,000
$2,100
$3,900
$8,300
$13,300
(for Windows software)
Appliance Price
(SonicWALL OS + Hardware)
* Single Server License
** Erforderlich für Appliance- und Software-Lösung
19
CONFIDENTIAL All Rights Reserved
Email Security Produktfunktionalität
# Users (Software & Appliance)
< 50
< 100
< 250
< 1000
< 5000
5000+
Appliance Model
200
300
400
500
6000
8000
– Hard Drive (GB) & RAID
80
80
2 x 80
2 x 80
2 x 160
2 x 160
– Hot Swap Drives / Redun. Power
20
X
Inbound/Outbound in 1 server
X
X
X
X
X
X
Anti-Spam, Anti-Phishing
X
X
X
X
X
X
DHA/DoS Protection
X
X
X
X
X
X
Multi-Layered Commercial AV
Avail.
Avail.
Avail.
Avail.
Avail.
Avail.
Compliance & Archiving
Avail.
Avail.
Avail.
Avail.
Avail.
Avail.
LDAP
X
X
X
X
X
X
Per User Settings & Quarantine
X
X
X
X
X
X
Clustering & Remote Clustering
X
X
X
X
X
X
Per User Score Settings
X
X
X
X
X
X
CONFIDENTIAL All Rights Reserved
Effektiver Schutz
Cognite: End-to-End Attack
Monitoring System
Der gesamte Lebenszyklus eines E-Mails muss überwacht
werden, um Angriffe effektiv zu stoppen und False Positives
zu verhindern
21
CONFIDENTIAL All Rights Reserved
22
CONFIDENTIAL All Rights Reserved
Compliance Anforderungen
ƒ Regulatorische
ƒ Öffentlicher Sektor (HIPAA, GLBA, SoX, CA SB 1386, Basel II)
ƒ Privater Sektor (Visa CISP, NASD 3010, ISO/IEC 17799)
ƒ Interne Anforderungen (CI)
ƒ Email Policies (blocken v. exe-Dateien, unpassende Sprache)
ƒ Schutz von Werten / Eigentum (Kundenlisten, Patente)
ƒ Confidential Information (Finanzdaten, Kundedaten)
23
CONFIDENTIAL All Rights Reserved
Relevant Regulations – Part 1
Regulation
Applies to …
Requires …
Email Requirements
HIPAA (Health
Insurance
Portability and
Accountability
Act)
Healthcare providers
(medical, dental, etc),
insurance companies,
pharmaceutical,
companies that offer
health insurance
Secure Protected
Health Information
(PHI) of individuals
-Identify PHI in
GLBA (GrammLeach-Bliley
Act)
Anyone that maintain
personal financial
information (Financial
services; stores CC info)
Protect consumers’
personal financial
information (PFI), such
as: account numbers
and balances, CC#,
SSN
Any publicly traded
company or private
company intending to go
public within 1-3 years
Keep all information
relevant to financial
information
SOX
(SarbanesOxley Act of
2002)
24
CONFIDENTIAL All Rights Reserved
emails
-IF transmitted over
Internet, secure the
content
-Identify PFI in
emails
-IF transmitted over
Internet, secure the
content
-Archive email
Relevant Regulations – Part 2
25
Regulation
Applies to …
Requires …
Email Requirements
State Privacy Laws
(CA SB 1386 & AB
1950 / NY Bill
A04254 / IL H.B.
1633 / FL H.B. 481 /
TX S.B. 122 + ~25
other states and
Federal bill)
Any entity that does
business with state
residents
Secure the personal
information of state residents,
such as SSN & Driver's
license number
-Identify consumer
Credit Card Security
(VISA CISP,
Mastercard Site
Data Protection
Program)
Anyone that stores VISA
or Mastercard credit card
information
FERPA (Family
Educational Rights
and Privacy Act)
Any public
school/university, any
private school that
receives funds from US
Dept of Education and
state/local education
agencies
Some require notification if
information becomes
unsecure
Never send cardholder
information via unencrypted
email
information in emails
-IF transmitted over
Internet, secure the
content
-Identify CC info in
emails
-IF transmitted over
Internet, secure the
content
CONFIDENTIAL All Rights Reserved
Prohibits disclosing the
contents of a student’s
records, without the consent
of the student or of the parent
of the minor student
-Identify student
information in emails
-Block or review the
emails
Relevant Regulations – Part 3
26
Regulation
Applies to …
Requires …
Email Requirements
USA PATRIOT Act:
Section 326
All industries that deal
with consumers
Activities deemed suspicious
by law enforcement (ranging
from book selections in public
libraries to unusual cash
transactions) may be the
subject of investigations that
require IT to track, interpret,
and report on customer data.
-Archive email
Sec 17a-4,
NASD3010
(Supervision),
NASD3110 (Books
and Records),
NASD3013
Anyone that trade of
securities of any type
OR a member of the
National Association of
Stock Dealers (NASD)
Save emails for 6 years
-Archive email for 6
Safe Harbor
(European)
Anyone that obtains,
owns, or licenses
personal/private
information about
residents of the EU
Protect personal information of
EU residents
CONFIDENTIAL All Rights Reserved
years
-Identify personal
information in emails
-IF transmitted over
Internet, secure the
content
Interne compliance Richtlinien
ƒ
Unterschiedlich je nach Unternehmen, aber überall nötig
ƒ Abhängig von Unternehmensstruktur
ƒ
BEISPIELE
ƒ “disclaimer” in ausgehenden Emails bei bestimmten / allen usern
ƒ Policy nach LDAP-Gruppen/usern
ƒ Grössenbeschränkung von ein- und ausgehenden Emails
ƒ Aufsetzen einer policy und monitoring in Approval Box
ƒ Sprachgebrauch in Emails
ƒ Policies mit Unterstützung von Dictionaries
ƒ Approval Box oder Meldung an HR
ƒ Monitoring nach bestimmten Dokumenten
ƒ Policy zur Suche nach Schlagwörtern “confidential”, etc.
ƒ Suche nach “Projektnamen” etc.
ƒ Unterbinden von schädlichen EXE.-Dateien
ƒ blocken oder aussondern von .EXE, .PPS, etc.
27
CONFIDENTIAL All Rights Reserved
Flexibles Policy System
28
CONFIDENTIAL All Rights Reserved
SonicWALL Email Security –
Wettbewerb
SMB
• Barracuda
• Symantec
• Trend Micro
• GFI
• SurfControl
• gehostete Lösungen
• Postini
• MessageLabs
29
CONFIDENTIAL All Rights Reserved
Enterprise
• CipherTrust
• IronPort
• Proofpoint
SonicWALL Wettbewerbsvorteile
30
ƒ
SMB Markt …
ƒ effektiver / bessere Performance
ƒ “False Positive” Rate
ƒ Einfach zu verwalten
ƒ Optimales Preis-/Leistungsverhältnis
ƒ TCO, ROI und features
ƒ
Enterprise Markt …
ƒ effektiver / bessere Performance
ƒ Enterprise-Erfahrung von Mailfrontier
ƒ “False Positive” Rate
ƒ Einfach zu verwalten
ƒ Optimales Preis-/Leistungsverhältnis
ƒ TCO, ROI und features
CONFIDENTIAL All Rights Reserved
SonicWALL / Barracuda
Barracuda
200
Disk Space
LDAP
Per User
Clustering
Per User
Scores
AV
Price
31
SonicWALL
200
X
X
X
X
X
80GB
Open Source
Commercial
(optional)
$1,395
US pricing
$1,395
CONFIDENTIAL All Rights Reserved
Barracuda
300
Disk Space
SonicWALL
300
10GB 80GB
LDAP
Per User
Clustering
Per User
Scores
US pricing
AV
Price
X
X
Open Source
Commercial
(optional)
$1,995
$1,995
US pricing
US pricing
Referenzen – Enterprise Kunden
Consumer Goods
Retail
Pharmaceutical
Hospitality
Healthcare
Media/Publishing
32
Transportation
Aerospace/Defense
CONFIDENTIAL All Rights Reserved
Entertainment
Automotive
Financial Services
Technology
Nonprofit
Technology
Media/Publishing
Manufacturing
Education
Retail
Consumer Goods
Government
Awards & Reviews
NetworkWorld Top-Rated Enterprise Anti-Spam Software
“…MailFrontier’s ASG put up some impressive results in terms of blocking
spam and letting legitimate mail pass.” - Sept 15, 2003
Recommends MailFrontier be included on “Short List” of products evaluated
for large-scale, high-performance anti-spam systems – December 20, 2004
InfoWorld Rated Excellent
“MailFrontier's provides excellent accuracy, easiest install and
lots of control to the admin.” – September 27, 2004
Recommended
“MailFrontier's hands-off approach can help ease the administration
burden on IT departments. – June 7, 2004
IT WEEK Editor’s Choice: 5 out of 5 Stars
“MailFrontier Gateway Appliance m500 setup was easy…and took less than an hour...lt really blocks
all unwanted email.” – June 6, 2005
Network Computing Editor’s Choice
“MailFrontier installed in a snap…spam engine design is simple, but highly effective…reporting features
were the best in class.” - November 24, 2005
33
CONFIDENTIAL All Rights Reserved
Awards & Reviews
Network Computing “…war in 20 Minuten
aufgesetzt und hat mit seiner leichten Konfiguration,
der guten Trefferquote und seinen detaillierten
Berichten überzeugt.”
34
CONFIDENTIAL All Rights Reserved
Danke
www.sonicwall.com