Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    ContentWatch Security Appliance Offers Filtering, Anti-malware

    Written by

    Matthew Sarrel
    Published December 4, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Many businesses need to keep employees safe on the Internet and require solutions to monitor and, in some cases, block activity. The reasons vary: regulatory compliance, data loss prevention, information security policy and even HR policy.

      A powerful driver for these solutions is the ability to limit or restrict bandwidth usage based on content categories or media type so that Jane in research can browse the Web looking for information on competitors’ products, but Bob in accounting can’t stream live video of the Victoria’s Secret fashion show.

      In this space, ContentWatch is offering a 1U (1.75-inch) appliance, the ContentProtect 300, that provides solid filtering and anti-malware protection. The CP 300 also integrates with various directory services.

      There are a lot of options available in this market, ranging from simple URL filtering solutions to solutions bundled with other perimeter protection services such as anti-malware all the way up to UTM (unified threat management) offerings with full perimeter security. Which architecture appeals most to you will be dictated by your existing security solutions and whether you want to augment or replace them.

      Historically, Web content filtering solutions relied on static lists of URLs that were pushed out by the provider much the way anti-virus signatures are. There are a number of drawbacks to this method-it only works with a frequently updated database (and no database of all the content on the Web can ever be completely up-to-date). There are also some easy ways around filters like this, such as using a “safe” domain (such as blogspot) to host “non-safe” content (such as pornography).

      Click here to see an eWEEK Labs walk-through of the ContentProtect 300.

      Therefore, good solutions not only filter on the text string of the URL but also conduct some sort of page-based content analysis on the fly. This analysis can be conducted on the actual device or somewhere out in the cloud. Administrators need to balance settings to provide enough protection while not scanning so deeply that the Web browsing experience is compromised.

      Along with the filtering and anti-malware features, the ContentWatch CP 300 includes bandwidth management and application control. The integration with directory services such as LDAP allows businesses to set and enforce Internet usage policy by person rather than the usual way, which is by MAC or IP address. Rules governing content, application and bandwidth usage can be set for individuals and groups. Administration can be done via browser or SSH (Secure Shell), and larger organizations have the option of managing multiple ContentProtect boxes through a single interface.

      I installed the CP 300 following the clearly written Quick Start guide, configuring it first from a workstation directly attached via cross-over cable and then moving it onto my Secure Web Gateway testbed to sit between the external firewall and the testbed’s Ethernet switch. Ports are clearly labeled and located on the front of the unit. The device includes a hardware bypass so that network traffic continues to pass through it even if it fails. A helpful and informative wizard walked me through initial configuration, although I was disappointed that there was no way to configure SMTP authentication when configuring e-mail alerts.

      Main Categories: Report, Manage and Admin

      The main Web GUI is separated into three main categories: Report, Manage and Admin. Another drawback to the product is that there is no context-sensitive help-clicking the Help button downloads and opens a PDF of the manual. The streamlined GUI is easy to use, yet at times it felt poorly organized. For example, configuring bandwidth utilization for the WAN link is, for some baffling reason, under Admin, Configuration, Miscellaneous. Other than a few quirks, everything is where you’d expect it to be, the GUI is responsive, and reporting is excellent.

      I synchronized the CP 300’s user directory with my LDAP server and started to build policies under the Manage tab. I put users in groups, created rules for time of day, content category and traffic shaping, and then assigned those rules under the Policy Manager. It seemed a bit cumbersome at first, but this modular approach makes it very easy to tweak policy later.

      To make it easier to get started, ContentWatch provides several ready-made policies, ranging from denying all access to monitor-only. In most businesses, a good place to start is with Moderate settings, which block certain Web content categories, allow IM and prevent users from bypassing the device through proxying.

      Those default rules did a great job when I ran through my usual content filtering tests. Google, Dogpile and Yahoo Safe Search was enforced automatically using my Moderate policy, all of the usual porn sites I test with were stopped, and all of the external proxying sites were blocked. I was impressed that many of my efforts to get around filtering using foreign languages were blocked as well, although I did eventually get to native-language Japanese pornography.

      A major disappointment hit when I subverted the filter entirely by accessing well-known pornography sites through Internet archive sites like archive.org. Administrators who want to completely lock down Web use can always block everything and only allow whitelisted sites. In addition, the page that appears when content is blocked informs the user why-for example “filter avoidance real-time filter”-and provides a link to a spyware removal tool. This page can be customized easily.

      The CP 300 excels at reporting. Reports can be sorted by user, IP address, site, application (other than browser) and bandwidth used. I could find specific threats such as spyware or viruses that were blocked, the sites that attempted to serve them, and the workstation or user who browsed that page. Any report can be displayed as a table, pie or bar chart; searched and filtered; and exported to Excel.

      The CP 300 retails for $2,995 for the hardware; the software subscription depends on the number of nodes supported and whether it’s one, two or three years.

      Matthew D. Sarrel is executive director of Sarrel Group, an IT test lab, editorial services and consulting company in New York.

      Matthew Sarrel
      Matthew Sarrel
      Matthew D. Sarrel, CISSP, is a network security, product development, and consultant based in New York City. He is also a technical writer.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.