Latest news
- No client software needed. Only a standard browser (Internet Explorer, Firefox, Safari, etc.) is required. Makes it easy-to-use for end-users.
- Fine-grained access control. Access can be granted to each user to only specific applications. For example, access by finance employees can be restricted to financial applications and data. Granularity includes by time of day, day of week, user group, by application or resource group.
- Capacity expansion as needed, including instantaneous increase for business continuity during disaster-recovery periods.
- Integration with authentication infrastructure, such as Active Directory, LDAP, RADIUS, and multi-factor authentication, such as smart cards and RSA tokens. For example, can integrate with User Groups and Group Policy Objects in Active Directory.
- Dramatically reduced deployment and upgrade costs. Administrators install and update/upgrade at only the central location.
- Much improved security with ‘host checks’ for required security posture of both managed and extranet end-points. A vendor’s computer, for example, must have up-to-date anti-virus signatures before it will be permitted access to the approved applications for that vendor.
- Ease-of-installation, typically in a couple of hours or less, and ease-of-administration, changing access policies and installing or modifying services (ie, access to applications).
- Lower capital cost, since only once appliance is needed. Where needed, full site-to-site connectivity can be implemented using two appliances, in addition to providing secure remote access for individuals using the same appliances.
- Secure encrypted communications from public locations such as wireless hotspots at cafes, hotels and airports. All data is encrypted by the browser on the host computer, precluding eaves-dropping at wireless hotspots, and even by (god forbid) spyware on the host computer!
What do you think is going to be next milestone in the development of SSL VPN products?
SSL VPNs will evolve with expanded host checks and more granular application of access policies depending on the security posture of each end-point. SSL VPNs are deployed today as ‘proxy appliances’, not at the gateway. They will incorporate more gateway like features, including firewall and anti-malware scanning. Perhaps the most important technology that will be integrated into SSL VPNs is bandwidth acceleration to provide seemingly higher capacity and response times. Already easy to deploy and administer, we expect SSL VPNs will further improve on their ease-of-use and ease-of-administration.
Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





