{"id":19253,"date":"2018-01-08T13:04:48","date_gmt":"2018-01-08T09:04:48","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=19253"},"modified":"2018-01-08T13:04:48","modified_gmt":"2018-01-08T09:04:48","slug":"university-fortifies-protection-with-integrated-threat-defence","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/01\/08\/university-fortifies-protection-with-integrated-threat-defence\/","title":{"rendered":"University fortifies protection with integrated threat defence"},"content":{"rendered":"<p>Utrecht University, in the city of Utrecht in the Netherlands, serves more than 30.000 students annually and is ranked 47 on the Academic Ranking of World Universities. With extensive experience managing endpoint security, Utrecht University\u2019s IT Administrator Andreas Van Dijk oversees endpoint infrastructure decisions and implementation. Van Dijk is always looking to improve protection as well as reduce costs and improve efficiency within the university\u2019s infrastructure.<\/p>\n<p>Challenges:<strong> Blocking ransomware and keeping endpoint protection current<\/strong><\/p>\n<p>The need to abate the ongoing threat of ransomware and reduce the risk of damage from zero-day and other malware attacks drove Utrecht University to look for better endpoint protection. \u201cRansomware is not just a problem for companies,\u201d said Van Dijk. \u201cWe also wanted to upgrade from yesterday\u2019s technology to more current technology that incorporates more than signature-based malware detection.\u201d<\/p>\n<p><strong>Time for stronger endpoint protection<\/strong><\/p>\n<p>The university had relied on McAfee\u00ae endpoint protection since 2007, primarily because of its easy-to-use central management console, McAfee\u00ae ePolicy Orchestrator\u00ae (McAfee ePO&#x2122;) software, which enables management of multiple McAfee security solutions from a common interface. \u201cIt is incredibly helpful to have everything in one place, to be able to manage your endpoint environment from a single screen,\u201d says Van Dijk.<\/p>\n<p>So when McAfee introduced McAfee Endpoint Security, it sounded logical to Van Dijk and his colleagues at Utrecht University to upgrade their McAfee Complete Endpoint Threat Protection suite to take advantage of the improved detection and protection technology. \u201cOur goal is better protection and less time spent on remediation,\u201d explained Van Dijk. \u201cWe were especially interested in the McAfee Endpoint Security\u2019s behavioural detection technology that goes beyond. DAT signatures and Dynamic Application Containment (DAC) functionality as a safeguard to keep potential threats quarantined while they are being analysed.\u201d<\/p>\n<p><strong>Smooth migration to McAfee Endpoint Security<\/strong><\/p>\n<p>Utrecht University migrated to McAfee Endpoint Security, version 10.5 not long after it became available. The Threat Prevention module was implemented first across the university\u2019s IT department. That deployment went extremely smoothly as desktops were migrated in waves of 500 until all 10,000 endpoints were completed. \u201cBefore migration, we were concerned, since each of the university\u2019s faculty groups had its own specialised applications that could potentially be blocked,\u201d recalled Van Dijk. \u201cHowever, we had only a few minor incidents of blocked applications that we were able to rectify quickly. Within three weeks, all our endpoints were protected by McAfee Endpoint Security. We were very satisfied with the entire migration.<\/p>\n<p><strong>More robust protection from the start<\/strong><\/p>\n<p>Van Dijk and the infrastructure team noted the dramatic improvement in detection and prevention provided by McAfee Endpoint Security from day one. \u201cAs soon as McAfee Endpoint Security was deployed, it began detecting and blocking files that were already on workstations but should not have been,\u201d said Van Dijk. \u201cDuring the migration rollout, this happened almost every day. McAfee Endpoint Security improved our detection capabilities right from the start.\u201d<\/p>\n<p>\u201cMcAfee Endpoint Security also works very well against ransomware,\u201d added Van Dijk. \u201cWe used to see ransomware in waves &#8211; weeks with nothing and then a week with several occurrences. Since deploying McAfee Endpoint Security, we haven\u2019t had a single incident.\u201d<\/p>\n<p>In addition, Utrecht University is taking advantage of the DAC functionality, which is part of the Adaptive Threat Prevention Module in McAfee Endpoint Security, to immediately quarantine suspicious files as soon as they are encountered, before they can infect patient zero or its neighbours. \u201cDAC was one of the main reasons we went with McAfee Endpoint Security,\u201d claims Van Dijk. \u201cWe see DAC containing sketchy files and, when necessary, sending them to our McAfee Advanced Threat Defense sandbox appliance for analysis.\u201d<\/p>\n<p><strong>Faster time to protection, thanks to integration and McAfee Advanced Threat Defense<\/strong><\/p>\n<p>Utrecht University has also implemented McAfee Data Exchange Layer an open-source platform that connects security components for automated, real-time data exchange, and McAfee Threat Intelligence Exchange, which gathers and transmits local and global threat information to all security systems connected to the DXL framework. By adding McAfee Endpoint Security, which is built to leverage McAfee Data Exchange Layer, the university can protect itself faster when threats enter its environment.<\/p>\n<p>For instance, if a McAfee Endpoint Security-protected endpoint encounters a known malicious file stored in the McAfee Threat Intelligence Exchange database, the file will immediately be blocked from executing, not only on patient zero, but across all endpoints and all McAfee Data Exchange Layer-connected devices in the company\u2019s environment. If the file is unknown, it will be sent via McAfee Threat Intelligence Exchange to the McAfee Data Exchange Layer-connected McAfee Advanced Threat Defense appliance for in-depth analysis. Once analysed, the file\u2019s reputation will be shared throughout the environment.<\/p>\n<p>Van Dijk credits McAfee Advanced Threat Defense as an imported tool in the university\u2019s security arsenal. It meets the top security challenge &#8211; namely, increasing protection against zero-day and advanced attacks. McAfee Advanced Threat Defense combines in-depth static code and dynamic analysis (malware sandboxing) to detect such threats, especially those that use sandbox evasion techniques. \u201cMcAfee Advanced Threat Defense acts like a virtual machine that extracts the suspicious file, examines what happens when it executes, and analyses it while shielding our environment from adverse risk. It\u2019s really outstanding,\u201d said Van Dijk.<\/p>\n<p>Van Dijk was surprised, however, that McAfee Advanced Threat Defense isn\u2019t catching even more malware. \u201cWe realised that McAfee Advanced Threat Defense catches less malware than we expected because McAfee Endpoint Security blocks a lot as well, which reduces the number of files that McAfee Advanced Threat Defense sees,\u201d explains Van Dijk. \u201cMcAfee Advanced Threat Defense has caught some advanced malware, though, so we are very happy with it.\u201d<\/p>\n<p><strong>Allowing end-users to stay productive<\/strong><\/p>\n<p>With the protection provided by McAfee Endpoint Security, the university\u2019s IT department now spends less time remediating security incidents than before. More importantly, however, business users aren\u2019t interrupted; they can stay productive rather than having to wait for their infected computers to be fixed.<\/p>\n<p>Furthermore, users are not even aware when anti-malware scanning occurs because it has been set to occur when their machines are idle. During the McAfee Endpoint Security migration, Van Dijk recounts an application that a user wanted was blocked, so at the user\u2019s insistence, a security engineer uninstalled McAfee Endpoint Security from the user\u2019s PC. Unbeknown to the user however, the engineer reinstalled McAfee Endpoint Security remotely the next day. The oblivious user never realised McAfee Endpoint Security was back in place, transparently protecting his desktop. \u201cClearly, McAfee Endpoint Security was not the problem,\u201d said Van Dijk.<\/p>\n<p><strong>Easier Security Administration and Reduced Complexity<\/strong><\/p>\n<p>With McAfee Endpoint Security, McAfee Threat Intelligence Exchange, and McAfee Advanced Threat Protection, Utrecht University has bolstered its protection against the most dangerous threats to a considerable degree and spends much less time on remediation. What Van Dijk appreciates most about the integrated threat defence though, is that it acts as one united solution. \u201cThe tight integration of McAfee products and the ability to manage diverse aspects of security from one console makes administration so much easier,\u201d he said. \u201cMcAfee reduces complexity, which is always a good thing.\u201d    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Utrecht University, in the city of Utrecht in the Netherlands, serves more than 30.000 students annually and is ranked 47 on the Academic Ranking of World Universities. With extensive experience managing endpoint security, Utrecht University\u2019s IT Administrator Andreas Van Dijk oversees endpoint infrastructure decisions and implementation. Van Dijk is always looking to improve protection as [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":19254,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[205,608,57,15,29,93],"tags":[4826,4827,4828,4829,345,4830,4831,4832,4833,4834,1268,202,4835,4836],"class_list":["post-19253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","category-education","category-enterprise-security","category-netherlands","category-software","category-top-stories","tag-anti-malware-scanning","tag-dynamic-application-containment","tag-malware-detection","tag-malware-sandboxing","tag-mcafee","tag-mcafee-advanced-threat-defense","tag-mcafee-complete-endpoint-threat-protection","tag-mcafee-data-exchange-layer","tag-mcafee-endpoint-security","tag-mcafee-epolicy-orchestrator","tag-ransomware","tag-security-solutions","tag-threat-defence","tag-utrecht-university"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/19253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=19253"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/19253\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/19254"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=19253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=19253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=19253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}