LANDesk Endpoint Security Audit 2.5 Danny Huang LANDesk Jan 2014 What Endpoint Security Audit can do for you? IT Security Audit for enterprises Data Loss Tracking Critical file leak: • Copy • Print • Email • IM • … User Behavior Checking Unrelated to work things • Game • Surf web • IM chatting • Stock trading Reduce Risks Enforce Security Policy: • USB Block • Unsafe APP • … Enforce Policy Increase Productivity 2 Monitoring & Controlling LANDesk Software Confidential LANDesk Desktop Management / Security / Audit Solutions 3 Manage Security Audit Before Happening After LANDesk Management Suite LANDesk Security Suite LANDesk Security Audit LANDesk Software Confidential Lifecycle Security Audit Turn ON User login Document Create, Edit, Delete… User logout Turn Off Print, Copy… Game, Surf web, IM… 4 LANDesk Software Confidential Logging user all operation 360° Security Audit App Audit Doc Audit - App usage - Active Window Title - Screenshots - File operation - Print Security Audit Network Audit Operation Audit - Surf web - Email - IM chatting - On/Off Login/Logout - USB Usage - Copy/ Paste ESA Pro 3.0 5 LANDesk Software Confidential Product roadmap Marketing Trial File Opt, Screenshot, Print Log Web Access Log Mail Log Critical File Read Log Application, Active Title Log Clipboard, USB Disk Log Logon/logoff, System Change Log Web Access Log (Trail) 6 BYOD / Cloud Clients Mobile Device Audit Log LANDesk Software Confidential Software usage logging Get better understand how end user are using software. 7 LANDesk Software Confidential Turn ON/OFF, Login/Logoff logging Get better understand how end user are using their computers. Work at weekends 8 LANDesk Software Confidential Surf web logging Get better understand how end user are using network. Web title, URL, Port, time… Surf web logging, even not in Corp network 9 LANDesk Software Confidential File operation logging File name, folder, operation, time, user… 10 LANDesk Software Confidential Print logging Get better understand how end user are using printer. Doc name, printer name User, IP, Pages 11 LANDesk Software Confidential Active window title logging Windows title, process name, time, user… 12 LANDesk Software Confidential Application usage logging App name, time, version… 13 LANDesk Software Confidential Screenshot logging 14 LANDesk Software Confidential Screenshot logging Screenshot can be triggered by time, specified application. For example: only when end user use Skype will do screenshot. Can search picture content, high compressed picture save storage space. Picture can be showed as video, and can be exported. Web 15 eMail LANDesk Software Confidential IM Word Screenshot logging Replay IM (Skype / QQ / MSN) chatting. 16 LANDesk Software Confidential Screenshot logging Online video 17 LANDesk Software Confidential Turn ON/OFF Login/Logout Logging Turn On, Login Lock screen, Login 18 LANDesk Software Confidential System information change logging In another network Business trip… In different time zone, abroad… Change: Hostname, IP, Time zone… 19 LANDesk Software Confidential USB device usage logging Get better understand how end user are using USB device. USB storage plug in/out Name and Type 20 LANDesk Software Confidential Clipboard logging Copy files from local and network drives Copy Content File name, Content 21 LANDesk Software Confidential IM chatting logging Chatting content File transfer 22 LANDesk Software Confidential User: From, To, Group User abnormity behavior logging High light User abnormity behavior 23 LANDesk Software Confidential User abnormity behavior logging Search by user, IP, keyword and export to CSV files All behavior relate to the keyword“QQ” 24 LANDesk Software Confidential Log query Create queries by different parameters 25 LANDesk Software Confidential User abnormity behavior alert Alert rule、 email template, Alert admin by email 26 LANDesk Software Confidential User abnormity behavior alert email Watching movie in work time IM Chatting in work time 27 LANDesk Software Confidential Multiple logging rule for different BU/User Individual enable/disable logging Move to different groups 28 LANDesk Software Confidential Up to 10000 nodes, low net work usage Support multiple file servers Use different logging rule to lower net work usage 29 LANDesk Software Confidential LANDesk ESA topologic logging ESA File Servers PC / NC Notebook Client Desktop management ESA console LDMS console 30 Core Server LANDesk Software Confidential ① All log keep in DB/file server ② Support up to 10000 clients Supported platforms Server: • Windows Server 2008 R2 or higher • SQL Server 2005SP3 / 2008 R2 or higher • .NET Framework 4.0 or higher Client: • Windows XP / Vista / Windows 7 / 8 Support language : • Server:English / Japanese / Chinese • Client: English / Japanese / Chinese 31 LANDesk Software Confidential Medalsoft Consulting Services Profile: › › › › › Founded: 2011 CAGR: 25% Shanghai: 25+ people, Shenzhen Branch: 10+ people Tokyo Office: 2+ people Target: › To be a top 10 professional solution provider in Cloud Computer area in China. › To be listed in OTC SH within 3-5 years Products & Solutions: › SharePoint / Office 365 Consulting Services & Apps › BPM Consulting Services › ESA & ITAM & ITSM Solutions (LANDesk) Clients & Partners: › 100+ Clients › Customer Satisfaction: 99% › Microsoft, LANDesk, Kingsoft (China), FlowPotal BPM (China), Clover-Sun (Japan) LANDesk Software Confidential Our Products & Solutions Enterprise Information Portal (SharePoint & SharePoint Online) EIP Medalsoft BPM ITIL Business Process Management LANDesk Software Confidential IT Asset Management IT Service Management Endpoint Security Audit - PC Operation Logs Work with LANDesk Endpoint Security Audit: › › › › Released ESA 2.x version. Won more than 10+ clients (20000 nodes+) in China. More than RMB2,000,000 revenue contributed indirectly. Technical Support to Japan team & South Asia team. Asset Lifecycle Management: › More than 10+ ALM projects delivered. › More than RMB3,000,000 revenue contributed indirectly. › Delivered Almost 80% ALM projects in China. Management Suite: › › › › More than 50+ LDMS projects’ support provided. More than 10+ projects delivered (Customization Development). More than RMB3,000,000 revenue contributed indirectly. Technical support to South China & East China teams Service Desk: › Started LDSD Consulting Services from 2013 › Started one LDSD project in 2013 LANDesk Software Confidential LANDesk Software Confidential