Endpoint Protection

 View Only
  • 1.  Need a info about Symantec ATP.

    Posted May 24, 2015 12:05 PM

    Hello everyone,

    Please share me detailed information about Symantec Advanced Threat Protection included in SEPM12.1 RU6.

     



  • 2.  RE: Need a info about Symantec ATP.

    Posted May 24, 2015 12:07 PM
    Advanced protection consists of IPS, sonar, firewall, download insight, and application and device control. What exactly are you looking for on it? These features have been available since 12.1 was released. Our are you referring to the ATP appliance?


  • 3.  RE: Need a info about Symantec ATP.

    Posted May 24, 2015 12:12 PM

    ATP.jpg



  • 4.  RE: Need a info about Symantec ATP.

    Posted May 24, 2015 12:20 PM

    Ok

    See here for details:

    http://www.symantec.com/advanced-threat-protection/

    http://www.symantec.com/about/news/release/article.jsp?prid=20140505_01

    It's basically newer service to detect unknown attacks....think similar to Fireeye and what they do. Detection and response, forensics, data correlation, etc.



  • 5.  RE: Need a info about Symantec ATP.

    Posted May 25, 2015 03:37 AM

    See This

    Integration with Symantec Advanced Threat Protection: Endpoint (ATP: Endpoint)

    ATP: Endpoint is an on-premises virtual appliance that detects advanced threats on endpoints in your network. ATP: Endpoint delivers actionable data so that you can quickly analyze and respond to the threats. You can select threats to block and add them to the ATP: Endpoint policy. When ATP: Endpoint sends the policy to the Symantec Endpoint Protection Manager, read-only file fingerprints from ATP: Endpoint appear in the system lockdown configuration. You can also configure Symantec Endpoint Protection Manager client groups to use ATP: Endpoint for reputation queries and submissions.

    Configuring client groups to use private servers for reputation queries and submissions

    https://support.symantec.com/en_US/article.HOWTO111068.html

    Interaction between system lockdown and ATP: Endpoint blacklist rules

    https://support.symantec.com/en_US/article.HOWTO111075.html

    What's new in Symantec Endpoint Protection 12.1.6

    https://support.symantec.com/en_US/article.HOWTO111067.html

    see chetan articles

    https://www-secure.symantec.com/connect/articles/symantec-releases-symantec-endpoint-protection-12161686000-121-ru6



  • 6.  RE: Need a info about Symantec ATP.

    Broadcom Employee
    Posted May 25, 2015 09:47 AM

    Hi,

    Symantec Advanced Threat Protection: Endpoint (ATP: Endpoint) is a virtual appliance that detects advanced threats on Symantec Endpoint Protection clients in your network. Advanced threats are those that typically bypass traditional protection technologies. The ATP: Endpoint server acts as an intermediary for Symantec Insight. ATP: Endpoint analyzes reputation data from Symantec Insight combined with submitted client detection data.

    You can configure Symantec Endpoint Protection Manager to redirect the reputation queries and submissions from clients in a client group to ATP: Endpoint.

    Under Clients --> Group --> Policies --> External Communication Settings --> Private Cloud.

    Through this location can configure client groups to use private servers for reputation queries and submissions

    You can direct client reputation queries (Insight lookups) from a group to a private intranet server. The private server can be the Symantec Advanced Threat Protection: Endpoint appliance or the Symantec Insight for Private Clouds server that you purchase and install separately in your network. 

    The following are the private server options for groups:

    • Symantec Advanced Threat Protection: Endpoint

      This option redirects the reputation queries and submissions from clients in the group to ATP: Endpoint. ATP: Endpoint then sends the queries and submissions to Symantec. ATP: Endpoint servers gather data about client detections and provide forensic analysis. This option redirects antivirus, SONAR, and IPS submissions, but it does not redirect file reputation submissions. Symantec does not directly receive reputation queries or submissions from clients in the group.

    • Symantec Insight for Private Clouds

      This option redirects the reputation queries from clients in the group to a private Insight server. The private Insight server stores a copy of Symantec's Insight reputation database. The private Insight server handles the reputation queries rather than Symantec's Insight server. When you use a private Insight server, clients continue to send submissions about detections to Symantec. Typically you use a private Insight server in a dark network. In that case, Symantec cannot receive any client submissions.

    You can also copy the private server configuration to other client groups.

    You can specify multiple private servers to load balance network traffic. You can also specify multiple groups of servers to manage failover.

    Note:

    If you enable private servers for groups, 12.1.5 and earlier clients in those groups cannot use Symantec servers if the designated private server is not available. 12.1.5 and earlier clients cannot use the priority list and must be configured to use a single server.

     

    To configure client groups to use a private server for reputation queries and submissions

    1. In the console, go to Clients and select the group that should use the private server list.
    2. On the Policies tab, click External Communications Settings
    3. On the Private Cloud tab, click Enable private servers to manage my data.
    4. Depending on which type of server you use, click Use an Advanced Threat Protection server for Insight lookups and submissions or Use a private Insight server for Insight lookups.You should not mix server types in the priority list.
    5. Click Use Symantec servers when private servers are not available if you want clients to use Symantec servers for reputation queries and client antivirus and SONAR submissions.Clients always send file reputation submissions to Symantec.
    6. Under Private Servers, click Add > New Server.
    7. In the Add Private Server dialog, select the protocol and then enter the host name for the URL.
    8. Specify the port number for the server.
    9. To designate this server as the single server that 12.1.5 and earlier clients use, click Use this server as the private Insight server for 12.1.5 clients and earlier. The 12.1.5 and earlier clients cannot use a server list, so you must specify which server these legacy clients should use.
    10. To add a priority group, click Add > New Group.
    11. To apply the settings to additional client groups, click Copy settings. Select the groups and locations, and then click OK.


  • 7.  RE: Need a info about Symantec ATP.

    Posted Jun 01, 2015 01:00 AM

    Afaik this ATP exist in both VA and physical type and is based on sandboxing technology (similar mould to APT competitors out there...Fireeye,websense,lastline etc)

    the one 'integrated' with SEPM is definitely the VA type (cloud) and would allow the files submission to be tested on it

     

    i not sure how details the report or feedback would be....has yet to test it :)

     

     

    regards