Symantec offers Web Monitoring service to detect botnet activity

Wednesday, March 24, 2010 9:14
Posted in category Uncategorized

Symantec has announced a Web monitoring service intended to unearth evidence of botnet-related malware activity within an organization by continuously looking at outbound HTTP traffic for suspicious signs of Trojans on compromised computers trying to “call home” to their criminal controllers.

According to Grant Geyer, vice president of Symantec’s global managed security services, the around-the-clock monitoring service is an extension to Symantec’s current security services portfolio. The Web Monitoring service uses several ways to identity botnet-related traffic within an organization’s network, including capturing streams of log data from secure Web gateways, including those from Symantec, Blue Coat, Citrix and Imperva, and analyzing this at Symantec’s security operation centers (SOC). Symantec’s service, which relies on a specialized security appliance installed the customer’s network that can interact with the Symantec SOC, is also able to store logs for a minimum of 92 days.

[ InfoWorld's Roger Grimes explains how to stop data leaks in an enlightening 30-minute Webcast, Data Loss Prevention, which covers the tools and techniques used by experienced security pros. ]

Typically, botnets that can steal data are trying to hide their attempts to connect back to their controllers in the HTTP streams of the victim companies, Geyer says, and the Symantec Web Monitoring service is intended to catch that “first attempt to connect” in order to immediately notify the customer and start any remediation process necessary. Symantec declined to provide pricing.

Read more about wide area network in Network World’s Wide Area Network section.

Share This:
  • Facebook
  • Twitter
  • StumbleUpon
  • Reddit
  • Digg
  • LinkedIn
  • MySpace
  • del.icio.us

Related Posts

  1. WSO2 offers business activity monitoring and Gadget Server portal
  2. Rustock botnet responsible for 40 percent of spam
  3. Over 75,000 systems compromised by massive Kneber botnet
  4. Symantec buys encryption specialist PGP for $300 million
  5. Symantec to buy VeriSign’s security unit for $1.3B, reports say
You can leave a response, or trackback from your own site.

Leave a Reply