Protection Engine for Cloud Services

 View Only
  • 1.  Is SPE more effective than SEP?

    Posted Feb 19, 2014 04:40 PM

    We are implementing a file upload through HTTP and store files on Windows attached drive.  Security folks at the company insist that the Protection Engine is more effective than Endpoint Protection.  They said there are proven cases that infected files can be uploaded and won't be caught by SEP but will be prevented by SPE.  

    Is that true?  Thanks.



  • 2.  RE: Is SPE more effective than SEP?
    Best Answer

    Posted Feb 19, 2014 05:00 PM

    Not sure how since they use the same defs. SPE is morefor scanning those NAS type devices.

    SEP can also be configured to scan network shares although it's better to use a product designed to do that

    http://www.symantec.com/docs/HOWTO79585



  • 3.  RE: Is SPE more effective than SEP?

    Posted Feb 19, 2014 05:08 PM

    Thanks for the quick update.  That's my understanding too.  I can understand the case where files are saved into database where scan engine is the only way to go.  But in our case, the files are stored on shared drive and they can also be quite large.  Since all servers have SEP installed, I assume they are protected.  Having them pass through scan engine, and not to cache the whole file in server memory seems quite a hassle, and duplicated effort.

    Is there a way to get an official confirmation on this?



  • 4.  RE: Is SPE more effective than SEP?
    Best Answer

    Posted Feb 20, 2014 05:33 AM

    SPE does not do any of the additional features of SEP, such as hueristics and behavioral etc.  It's just pure signature based.

     

    SPE scans the file stream itself, which means that the infection will be picked up and removed before the file even lands inside your network.  In that regard, its a much better product for file upload websites etc.  My recommendation in your situation will be to implement SPE.



  • 5.  RE: Is SPE more effective than SEP?

    Posted Feb 20, 2014 10:41 AM

    Thanks, that's our internal argument as well.  Now each file is quadruple scanned because one of our UI have to use temp location, then pass through SPE, another SEP at final destination and finally whenever whoever trying to access whaterver.  Talking about security indecision



  • 6.  RE: Is SPE more effective than SEP?

    Posted Feb 20, 2014 12:07 PM

    To be honest if they're all using Symantec products there's no point.  The extra scanning is just increasing transaction latency.  Traditionally a different AV product is used somewhere down the line to spread out the risk a bit.