Application whitelisting review: Lumension Application Control
- 04 November, 2009 22:13
- Comments
Lumension Application Control is a strong whitelisting solution with broad file coverage, excellent reporting, and a complete set of Windows file definitions that can be used to spot potentially troublesome changes to system files. Its one noteworthy shortcoming is the inability to create whitelisting rules based on the digital signatures of application publishers.
Lumension, which is the product of the marriage of PatchLink and SecureWave, is the parent of several security components and modules, including Application Control (covered in this review), device control, data protection, vulnerability assessment, patching, and anti-virus.
Application Control is essentially the latest incarnation of SecureWave's Sanctuary, an application whitelisting product that has been on the market for more than six years. Application Control can be purchased separately, but it is intended to be a primary part of the Lumension Endpoint Protection solution, which includes Lumension AntiVirus, or the Lumension Endpoint Security Solution Pack, which includes Lumension Device Control. Application Control and Device Control share the same management console.
The server-side management console, called Lumension Endpoint Security Management screen image, serves multiple components, so it's inherently a bit busier than its counterparts in whitelisting-only products. However, Lumension allows customers to use as many management servers as they need, without paying any server licenses -- a key advantage when trying to scale out an enterprise deployment or address performance or management issues.
Lumension, like SignaCert, comes with a complete set of standard file definitions (SFDs) for Windows 2000 to Windows 7 operating systems, prescanned and prehashed. These "gold" definitions are useful for noting deviations from the Microsoft defaults. Like all of the competitors in this roundup, Lumension can scan one or more existing computers to automatically generate whitelist execution rules, using the Scan Explorer feature.
Unlike most of the other competitors, Lumension can create whitelisting rules for all file types, although it defaults to executables only. The Exe Explorer feature will reveal individual files and their attributes found during the scan or already stored in the database. Files are identified by the normal file attributes (such as name or size) and SHA-1 hashes. Additionally, Lumension allows you to define path rules (allow only) and trusted users who can run anything (called Local Authorization). Unfortunately, Lumension does not support whitelisting using publisher digital signatures, which is a significant omission in an otherwise very good product.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Six tips for choosing a unified threat management (UTM) solution
- Keeping up With Ever-Expanding Enterprise Data - 2010 IOUG Database Growth Survey
- Best practices for a Data Warehouse on Oracle Database 11g
- Email Encryption/Decryption and Signing integrated into a comprehensive content security solution
- Leverage Economic Advantages in Storage Management
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Office 2007 for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Computers for Seniors for Dummies, 2nd Edition
-
Microsoft Office
-
Windows 7 for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies












Comments
Post new comment