Jump to content

Symantec Endpoint Protection

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by WikiGopi (talk | contribs) at 15:59, 29 July 2016 (Updated Internal link). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Symantec Endpoint Protection
Developer(s)Symantec Corporation
Stable release
12.1.7004.6500 (Release), RU6 MP5[1] / 28 June 2016
Operating systemMicrosoft Windows, Mac OS X and Linux
PlatformIA-32 and x86-64
TypeAntivirus and personal firewall
LicenseTrialware
Websitewww.symantec.com/business/endpoint-protection

Symantec Endpoint Protection, developed by Symantec Corporation, is an antivirus and personal firewall software for centrally managed corporate environments providing security for both servers and workstations.

Version history

Symantec AntiVirus Corporate Edition was the previous software from Symantec in this market, its last release was version 10.2 MP1, (10.2.4).

Initially Symantec Endpoint Protection (SEP) software, revision 1.0, was released September 23, 2007 and was labeled version 11. In 2009 a Small Business Edition (SBE) of SEP (version 11) was introduced[2] in addition for seats/nodes <=100 and labeled version 12. In 2011 both software lines were updated to version 12.1. 2015, SEP SBE 12.1 was discontinued and replaced by SEP SBE version, reflecting changes in licensing (from perpetual to subscription) and shifting focus from on-premises to cloud-managed business.[3]


Symantec Endpoint Protection, current version history:

  • Version 12.1 RTW (12.1.671.4971), 5 July 2011 (release to world, initial SEP 12.1 version)
  • Version 12.1 RU1 (12.1.1000.157), 17 November 2011
  • Version 12.1 RU1 MP1 (12.1.1101.401), 8 May 2012
  • Version 12.1 RU2 (12.1.2015.2015), 15 November 2012 [4]
  • Version 12.1 RU2 MP1 (12.1.2100.2093), 9 April 2013
  • Version 12.1 RU3 (12.1.3001.165), 6 June 2013 [5]
  • Version 12.1 RU4 (12.1.4013.4013), 5 November 2013
  • Version 12.1 RU4a (12.1.4023.4080), 13 February 2014
  • Version 12.1 RU4 MP1 (12.1.4100.4126), 19 March 2014
  • Version 12.1 RU4 MP1a (12.1.4104.4130), 16 April 2014 [6]
  • Version 12.1 RU4 MP1b (12.1.4112.4156), 29 July 2014 [7]
  • Version 12.1 RU5 (12.1.5337.5000), 18 September 2014 [8]
  • Version 12.1 RU6 (12.1.6168.6000), 9 May 2015 [9]
  • Version 12.1 RU6 MP1 (12.1.6306.6100), 28 July 2015 [10]
  • Version 12.1 RU6 MP1a (12.1.6318.6100), 03 August 2015
  • Version 12.1 RU6 MP2 (12.1.6465.6200), 02 October 2015
  • Version 12.1 RU6 MP3 (12.1.6608.6300), 04 November 2015 [11]
  • Version 12.1 RU6 MP4 (12.1.6860.6400), 16 March 2016 [12]
  • Version 12.1 RU6 MP4 (12.1.6867.6400), 18 April 2016 [13]
  • Version 12.1 RU6 MP5 (12.1.7004.6500), 28 June 2016

System support

Endpoint Protection supports Windows 10, Red Hat Enterprise Linux (RHEL) 7.0 and 7.1, & Oracle Linux (OEL) 6U5 Since 12.1.6168.6000 [14] Windows 8.1 & Windows Server 2012 R2 (Since 12.1.4013.4013), Windows 8 & Windows Server 2012 (Since 12.1.2015.2015), Windows 7, Windows Server 2008, Windows Server 2008 R2,[15] Windows Server 2003, Windows Vista, Windows XP SP1 or higher, and Windows 2000 - and several distributions of Linux.[15] 64-bit versions of Windows XP, Vista and Windows 7 are supported as well, but Itanium and PowerPC processors are not supported.[15]

Security Concerns and Controversies

July 2016 - Google Project Zero Team has seen serious vulnerabilities with Symantec's Endpoint Protection products.[16][17] The code has been found to have flaws in the Decomposer component, which surpasses various file formats that includes archive files like.zip and .rar.[18]

This enforces a process of remote code execution to create computer worms to execute and interfere with the local network without the knowledge of users.[19][20]

Features

Firewall
Endpoint incorporates a rules-based firewall, as well as an anti-malware technique that Symantec calls "generic exploit blocking". The firewall is based on technology developed by Sygate Technologies, who were purchased by Symantec. Generic exploit blocking is a technique that attempts to proactively blocks malware from exploiting unpatched vulnerabilities.[21]
Proactive protection
Endpoint uses Symantec's TruScan technologies to attempt detection of unknown malware. It analyzes both "safe" and "negative" behaviors of unknown applications.[22] It also integrates Symantec's Deepsight honeypot sensors to warn of emerging threats and provide threat advisories.[23] Proactive Threat Protection feature is supported on server operating systems in version 12.1 and above.[24]
Intrusion prevention
Endpoint is able to create and enforce rules on client computers. For example, it can prevent clients from writing files to a USB flash drive. Intrusion prevention also works as IDS. Policies are enforced by TruScan. The IPS functionality acts as a first line of defence against network based attacks.[25]

References

  1. ^ "Symantec Endpoint Protection - Changelog". Symantec. Retrieved 2015-10-02.
  2. ^ "Symantec Endpoint Protection". Symantec.com. 2011-10-04. Retrieved 2011-10-18.
  3. ^ "Symantec Endpoint Protection". Symantec.com. 2015-11-06. Retrieved 2015-11-06.
  4. ^ "Latest Symantec Endpoint Protection Released - SEP 12.1 RU2 and SEP 11.0 RU7 MP3". Symantec.com. 2012-11-15. Retrieved 2013-11-12.
  5. ^ "Latest Symantec Endpoint Protection Released - SEP 12.1.RU3". Symantec.com. 2013-06-06. Retrieved 2013-11-07.
  6. ^ "Symantec Endpoint Protection 12.1 Release Update 4 Maintenance Patch 1A". Symantec.com.
  7. ^ "About the SYM14-013 Symantec Endpoint Protection zero-day vulnerability". Symantec.com.
  8. ^ "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  9. ^ "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  10. ^ "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  11. ^ "Enterprise Support - Symantec Corp. - Technical Solution". Symantec.com.
  12. ^ "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  13. ^ "Enterprise Support - Symantec Corp. - Technical Solution". symantec.com.
  14. ^ https://support.symantec.com/en_US/article.HOWTO111067.html
  15. ^ a b c "Symantec Endpoint Protection". Symantec.com. Retrieved 18 October 2011.
  16. ^ "Symantec and Norton security products contains security vulnerability- Explained Detailed". "US-CERT". Retrieved 2016-06-05.
  17. ^ "Symantec bugfest highlights the dangers of security software". Retrieved 2016-07-05.
  18. ^ "Google Found Disastrous Symantec and Norton Vulnerabilities That Are 'As Bad As It Gets'". Retrieved 2016-06-29.
  19. ^ "Symantec may actually help hackers, Homeland security warns". Retrieved 2016-07-07.
  20. ^ "Symantec admits it won't patch 'catastrophic' security flaws until mid-July". Retrieved 2016-07-07.
  21. ^ "Data Sheet: Endpoint Security" (PDF). Retrieved 2011-10-18.
  22. ^ Ramon Ray (2007-12-30). "How Symantec Is Changing to Better Meet Small Business Needs". Smallbiztechnology.com. Retrieved 2011-10-18.
  23. ^ "Enpoint Security White Paper" (PDF). Retrieved 2011-10-18.
  24. ^ http://www.symantec.com/business/support/index?page=content&id=TECH92440
  25. ^ Sarrel, Matthew (2007-12-13). "Symantec Endpoint Protection 11 Review & Rating". PCMag.com. Retrieved 2011-10-18.