SECURITY IMAGE

NAC targets rogue users

The need for firms to enforce security rules is driving uptake

Written by Dave Bailey

Earlier this year, antivirus specialist Sophos acquired US network access control (NAC) vendor Endforce. The move follows similar forays into the NAC market by rival antivirus vendor McAfee and network hardware firms such as Extreme Networks.

Butler Group security analyst Andy Kellett said the Sophos deal is part of a growing trend. “NAC certainly has a higher profile than it used to have and is aligning itself with a perceived need in the vendor community to provide a more rounded system.”

The term NAC applies to software or hardware systems that are designed to secure firms’ whole network infrastructures, end-to-end. Endforce’s flagship Endforce Enterprise product is a software-based NAC solution that protects networks from non-compliant or misconfigured endpoints. It is designed to work with the three main NAC architectures: Cisco Network Admission Control (NAC), Microsoft Network Access Protection (NAP), and Trusted Network Group’s Trusted Network Connect (TNC).

NAC aims to check and identify who is connecting to corporate networks, where they are connecting from and what they are connecting with. NAC should then be able to check that the device, whatever it is, has an up-to-date security profile. This profile could, for example, stipulate that the device’s operating system has the most up-to-date patches.

If the user works in the company, their access is based on a specific policy defined in the NAC system. Guests, temporary staff and contractors will be allowed access to only those parts of the network defined in the NAC policy system. A system missing critical patches or out-of-date antivirus signatures will be quarantined in an area with less access to the corporate network or even no access while it is updated to meet the NAC policy.

One of the main drivers for implementing NAC is the growing need for firms to provide secure remote and guest access to contractors and temporary staff. A recent survey conducted by independent B2B consultancy Loudhouse Research and commissioned by network security firm ConSentry found that half of the 200 senior security and network professionals interviewed saw temporary workers, guest users and contractors as network threats.

ConSentry’s director for Northern Europe, Alex Raistrict, said, “About 40 percent admitted they hadn’t got up-to-date network access policies in place.”

Corporate governance regulations that require firms to show they have implemented adequate security measures are also fuelling interest in NAC as a means of enforcing security policies and logging incidences where potential threats have been neutralised.

Despite these advantages, corporate adoption of NAC remains relatively slow. In the Loudhouse survey for ConSentry, nearly half of the respondents said they were not able to roll out NAC because of a “lack of resources”. And a recent study of 120 companies by the Aberdeen Group found that firms are wary of rolling out NAC because of its complexity and problems integrating with current infrastructure. 

Tags:

reader comments

related articles

Extreme closes NAC loophole

Network specialist Extreme announces upgrades to switch firmware 29 Jan 2007

 

Juniper NAC system is out

Unified Access Control network access control from Jupiter integrates Funk Soft tech 13 Nov 2006

Sophos targets network access control

Security vendor Sophos has bought US network access control specialist Endforce 15 Jan 2007

Network access controls evolve

Even if Cisco and Microsoft allow NAC and NAP to work together they may lose ground to rivals, reckons Martin Courtney. 18 Sep 2006

Nevis brings network access controller to UK

LANenforcer 1000 appliance can make sure up to 100 properly authenticated users have latest anti-virus and operating system patches. 06 Nov 2006

AEP NACpoint appliance guards network access

AEP says the kit can work seamlessly with Cisco, Enterasys, Extreme, HP and 3Com managed network switches 19 Sep 2006

Infosecurity teams still isolated

New research from Ernst & Young finds many security teams are still struggling to integrate with the business 10 Dec 2007

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim 24 Jul 2008

Juniper upgrades network access protection

Juniper updates its line of unified access control tools 04 Aug 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation