查看: 6179|回复: 33
收起左侧

[转帖] What's new in Sophos Endpoint Security and Control 10?

  [复制链接]
firefox3
发表于 2012-4-13 10:24:00 | 显示全部楼层 |阅读模式
本帖最后由 firefox3 于 2012-4-13 10:28 编辑

What's new in Sophos Endpoint Security and Control 10?

With the release of Sophos Endpoint Security and Control 10 (licensed as Sophos Endpoint Protection 10) there are many new features and improvements.

This article is provided to give you an overview of the benefits of upgrading to Endpoint 10. For further information please see the release notes, product documentation and specific articles.

Known to apply to the following Sophos product(s) and version(s)
Sophos Endpoint Security and Control 10.0

New Features
The list below contains all of the 'new' features in Endpoint 10. Don't forget to also read what improvements we've made.

Sophos Patch Assessment1
The new patch assessment feature allows you to deploy an agent to endpoint computers that will identify missing patches and send this information back to the server, where you can view it in Sophos Enterprise Console.
Patch assessment monitors the most widely used products from Adobe, Apple, Citrix, Microsoft and others. SophosLabs rates patches as critical, high, medium and low and tells you which threats a patch prevents so you can easily identify the most important ones.
Web Filtering1
You can now restrict access to certain categories of websites in order to control web usage and avoid any impact on workplace productivity.
Like web content scanning, this feature supports the five major browsers: Internet Explorer, Firefox, Chrome, Safari, and Opera.
Can be used in two different configurations:
Endpoint only to control use of inappropriate websites which requires no extra hardware or software.
Web Protection Suite combines our web appliance and endpoint web filtering. Policy syncs immediately with Endpoints through the cloud eliminating backhauling and reducing the number of needed gateway appliances.
Integrated encryption
Full-disk encryption integrated into Endpoint 10 with no separate deployment or console required. Easily install full-disk encryption to your computers in just six clicks. Then check status, policy and user activity simply in our console.
Please note that integrated Full Disk Encryption is not yet available in Enterprise Console 5.0; it will be available in Enterprise Console 5.1, currently scheduled for release in the second quarter of 2012.
1The Patch Assessment and Web Control features are not included with all licenses. If you want to use them you may need to customize your license. For more information please see Pricing & Editions - Customize your security in 2 simple steps.

Improvements
Console installer
Fewer restarts required when upgrading.
The Upgrade Advisor is not a separate program and now runs during the installation and hence does not have to be run before the installer.
New Installer Framework. There are now multiple Microsoft installer (MSI) files that gives you greater control of the installation. Also if you need to install the database via scripts they are automatically extracted and available if required.
During the installation you can select an existing SQL Server instance for the Sophos database or choose to create a new SOPHOS instance. You cannot create a SQL instance of another name during the installation of the Console.
Console
Search function in console to locate a computer, by hostname or IP address, or range of computers by hostname. You can access the menu option from the console under: Edit | Find a computer (Ctrl+F). You can even use wildcards (*, ?) to find a range of computers matching the search term.
Import or export exclusions from an Anti-Virus and HIPs policy
Multiple selection of alerts and errors is now supported.
SMTP server authentication.
Management Console has a new color scheme and iconography, but there is no significant change to the layout.
Now that we have introduced new features that generate events, we have given the event viewers more prominence in the console. You launch an event viewer from the Events menu in the taskbar at the top of the console.
Endpoint
Faster start-up/boot times for computers.
Increased on-access and on-demand scanning performance.
Web content scanning protection has been re-written and is no longer dependent on Browser Helper Objects (BHO) that are only applicable to Internet Explorer. Web content scanning now supports all leading browsers Internet Explorer, Firefox, Chrome, Safari and Opera and with no BHO dependency making it more secure and tamperproof.
Buffer Overflow Protection (BOPs) for Vista/ Windows 7 clients (which runs on 64-bit computers).
The on-access scanner default settings are now set for best protection. The table below shows a comparison between the current default settings and the default setting of the previous version of Sophos Anti-Virus.
NOTE: The settings shown below are for a new install of Enterprise Console v5 and Sophos Anti-Virus v10. If you perform an upgrade your existing policy settings will be used.

Option        Setting is selected?
                        SAV 9.7        SAV 10.x
on-read                  Yes                      Yes
on-write                  No                      Yes
on-rename         No                      Yes
'Automatically clean up items that contain virus/malware'        No        Yes
For more information please see: Recommended on-access scanning settings for 10.x
On-demand and scheduled scanning: The option to 'Automatically clean up items that contain virus/malware' is enabled for new on-demand scans. Right-click scans and Scan my computer will still retain the old setting and do not provide automatic clean up.
Endpoint changes to functionality that affects menus and terminology
The following menu options and wording have also been changed:

'Scan for suspicious files (HIPS)' has changed to 'Scan for suspicious files' as the scanning of suspicious files is not done at run-time like HIPS detections are.
'Suspicious behavior' has been changed to 'Behavior Monitoring'
Behavior Monitoring is now split into five options (three options were present in 9.7)
'Alert only' options exist for both suspicious behavior and BOPS.
NOTE: If you selected the 'Alert only' option in version 9.7 both HIPs and BOPs settings will inherit the 'Alert only' option.
'Alert only' option only relates to suspicious behavior and does not relate to malicious behavior.
Disabling ‘malicious behavior’ will disable HIPS scanning.
The 'Options' tab under on-access settings has been removed and the settings previously shown there have moved to the 'Scanning' tab.
Virus alerting to the end user
Whether a threat has been cleaned up or not the end user will see a balloon message advising of the detection and that it has been moved to the quarantine manager.


We have designed the alerting this way as, and to not show a success or failure message due to:

At the time of the alert it is not possible to determine the precise outcome of the cleanup routine - if one is set. Hence for best protection it is advisable to alert the end user.
A secondary message to advise of the outcome could, in certain scenarios, bombard the user (i.e. file infectors).
And remember you can always disable balloons altogether if you like.

Virus reporting to the console
Due to the change in enabling automatic cleanup, virus alerts that correspond to a threat that has been successfully dealt with, will not appear on the console Dashboard and there will no warning shown against the computer (because there is no action required on your part). However you will see detections and actions under the computer details for a computer for reference and the detections will appear in any threat reports you run.

If you need more information or guidance, then please contact technical support.

----------------------------------------------------------------------------------------------------------------
最后贴一张图

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
imut
头像被屏蔽
发表于 2012-4-13 10:31:24 | 显示全部楼层
反过来
firefox3
 楼主| 发表于 2012-4-13 10:33:40 | 显示全部楼层
本帖最后由 firefox3 于 2012-4-13 10:35 编辑
imut 发表于 2012-4-13 10:31
反过来


有时间的吧
其实我关注的是最新版的HIPS,最后贴的图看到HIPS增加了很多新东西
仯釕↘①訜執著
发表于 2012-4-13 10:47:31 | 显示全部楼层
也不翻译成中文。。 还好谷歌自带了翻译器。。不过翻译的不准确。。!
firefox3
 楼主| 发表于 2012-4-13 10:53:13 | 显示全部楼层
仯釕↘①訜執著 发表于 2012-4-13 10:47
也不翻译成中文。。 还好谷歌自带了翻译器。。不过翻译的不准确。。!

原汁原味最好了
猪头无双
头像被屏蔽
发表于 2012-4-13 11:07:10 | 显示全部楼层
我是来求PM我一个神KEY的当然这么做是不对的
firefox3
 楼主| 发表于 2012-4-13 11:09:05 | 显示全部楼层
猪头无双 发表于 2012-4-13 11:07
我是来求PM我一个神KEY的当然这么做是不对的

你这么做是不对的,我当然不会PM你的

评分

参与人数 1人气 +1 收起 理由
猪头无双 + 1 你懂得的,3Q

查看全部评分

じ☆ve楓少ツ
发表于 2012-4-13 12:17:54 | 显示全部楼层
呵呵,这也是我一直坚持10的原因,10的改进非常大。注意一点,默认是不开启拓展包的,需要手动打开,会加大检测率,当然了,误报也会增加。
英九
发表于 2012-4-13 12:19:43 | 显示全部楼层
什么是新在Sophos端点安全和控制10? 随着版本的Sophos端点安全和控制10(Sophos端点保护的10行货),有许多新的功能和改进 这篇文章是提供给你一个升级到10端点的好处概述。如需进一步信息,请参阅发行说明,产品文档和具体条款。 已知适用于以下的Sophos产品(S)和版本(S) Sophos的端点安全和控制10.0 的新功能, 下面的列表包含所有的“新”的特点。端点10。不要忘了,也读我们已经取得了哪些改进。 Sophos的的补丁Assessment1 新的补丁评估功能允许您部署一个代{过}{滤}理端点电脑将标识缺少的修补程序,此信息发送到服务器,在这里你可以查看在Sophos Enterprise Console中。 补丁评估监控的Adobe,苹果,思杰,微软和其他使用最广泛的产品。SophosLabs的利率作为关键,高,中,低,告诉你一个补丁可以防止哪些威胁,所以你可以很容易地找出最重要的。补丁 的Web Filtering1 现在,你可以限制访问某些类别的网站,以控制网络的使用情况,并避免任何对工作场所的生产力的影响, 如网页内容扫描,此功能支持的五大浏览器:IE浏览器,火狐浏览器,Safari浏览器, 可以在两个不同的配置使用和Opera。 : 只有端点控制使用不适当的网站,不需要额外的硬件或软件。 Web安全保护套件,结合我们的网络设备和端点网页过滤。政策与端点同步立即通过消除回程和减少所需的网关设备的数量。云 集成加密, 磁盘加密,没有单独部署或需要控制台集成到端点10。全磁盘加密很容易地安装到您的计算机在短短半年人次。然后检查状态,政策和用户的活动,只是在我们的控制台, 请注意,是尚未在Enterprise Console 5.0提供集成的全磁盘加密;在Enterprise Console 5.1,目前预计在第二季度发布,这将是2012年。 1The补丁评估和网络控制功能,不包括所有许可证。如果你想使用它们,你可能需要定制您的许可证。欲了解更多信息,请参阅定价与版本- 2个简单的步骤自定义你的安全。 改进 Console安装 升级时需要重新启动。 升级顾问是一个单独的程序,现在运行在安装过程中,因此没有被运行前 新的Installer 安装程序。框架。现在有多个Microsoft安装程序(MSI)文件,让你更好地控制安装。如果你还需要安装数据库,通过自动提取,如果需要的脚本。 在安装过程中,你可以选择一个现有的SQL Server实例的Sophos数据库,或选择创建一个新的SOPHOS实例。你不能创建安装在控制台的另一个名字的SQL实例。 控制台 在控制台的搜索功能,找到一台电脑,主机名或IP地址,或由主机电脑的范围。你可以从控制台访问的菜单选项下:编辑|查找计算机(按Ctrl + F)的。你甚至可以使用通配符(*),找到了一系列的搜索词相匹配的计算机。 现在支持 导入或从防病毒和HIPS策略出口排除警报和错误的多重选择。 SMTP服务器认证 管理控制台。一个新的配色方案和肖像,但没有显着变化的布局。 现在,我们已经推出了新功能,生成事件,我们已在控制台事件观众更突出。从“事件”菜单中启动事件查看器,在控制台顶部的任务栏。 端点 电脑的更快start-up/boot倍。 增加访问和按需扫描性能。 网页内容扫描保护已重新编写而不再依赖于浏览器辅助对象(BHO),只适用于Internet Explorer中。网页内容扫描 缓冲区溢出保护(BOPS)(其中64位计算机上运行VISTA / Windows 7客户端现在支持所有领先的浏览器,IE浏览器,火狐,Chrome,Safari和Opera并没有BHO的依赖,使其更加安全和防篡改。 现在最好的保护)。按访问扫描默认设置。下表显示了当前的默认设置和默认设置的先前版本的Sophos反病毒之间的比较 注:所示的设置是新安装了Enterprise Console的V5和Sophos反病毒V10。如果您执行升级您现有的策略设置将被使用。 选项设置选择?                         SAV反病毒9.7 SAV反病毒10.X 读是是 上写否是 重命名的是 '自动清除包含病毒/恶意软件的项目“否是 有关详细信息,请参阅:10.x的按访问扫描设置 启用新的按需扫描按需和预定扫描:选择“自动清除包含病毒/恶意软件”的项目推荐。右键单击扫描,扫描我的电脑仍然会保留旧的设置,并没有提供自动清理 功能影响的菜单和术语 下面的菜单选项和措辞。端点变化也有所改变:“扫描可疑文件(HIPS)的“改为”扫描可疑文件“扫描可疑文件在运行时没有做过类似HIPS的检测是 “可疑行为”已经改变 现在的“行为监控行为监控分裂成五个选项(三选项9.7) '存在两个可疑行为和BOPS,仅限警报“选项。 注意:如果您选择“提醒只有”在版本9.7中的选项,臀部和国际收支设置将继承“仅限警报”选项。 “仅限警报'选项只涉及到可疑行为,并没有涉及到的恶意行为。 禁用“恶意行为”,将禁用HIPS的扫描。 “选项”选项卡下的访问设置已被删除,先前的研究显示,设置有移动的扫描“标签。 病毒警报 威胁是否已清理或不是最终用户会看到一个气球消息通知检测,它已被转移到检疫经理到最终用户。 我们设计的报警方式,由于不显示成功或失败的消息: 在警报时,它是不可能确定的清理例程精确的结果-如果设置。因此,最好的保护,这是明智的提醒最终用户。 次要的消息,告知结果,在某些情况下,可以轰炸的用户(即文件感染者)。 记住你总是可以完全禁用气球,如果你喜欢。 病毒报告 由于控制台的变化,在实现自动清理,对应一个已经被成功地处理了威胁的病毒警报,将不会出现在控制台上的仪表板和有没有警告对电脑(因为有需要在没有行动您的一部分)。然而,你将看到下的计算机的详细信息,以供参考计算机检测和行动,并检测会出现在任何威胁报告您运行。 如果您需要更多信息或指导,那么请联系技术

saky20008
发表于 2012-4-13 12:21:49 | 显示全部楼层
不知道有什么改进
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-8 06:17 , Processed in 0.133806 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表