What's new in Symantec Endpoint Protection 11.0
Question/Issue:
Symantec Endpoint Protection combines technologies from previous Symantec products in a new interface. This document describes what's new in this release.
Solution:
Product Overview
Symantec Endpoint Protection combines technologies from previous Symantec products in a new interface. These technologies are:
- Antivirus and Antispyware
Antivirus and Antispyware scan for both viruses and for security risks. Some examples of security risks are spyware, adware, and other files that can put a computer or a network at risk.
- Personal Firewall
The Symantec Endpoint Protection firewall provides a barrier between the computer and the Internet. The firewall prevents unauthorized users from accessing the computers and the networks that connect to the Internet. It detects possible hacker attacks, protects personal information, and eliminates unwanted sources of network traffic.
- Intrusion Prevention
The intrusion prevention system (IPS) is the Symantec Endpoint Protection client's second layer of defense after the firewall. The intrusion prevention system is a network-based system. If a known attack is detected, one or more intrusion prevention technologies can automatically block it.
- Proactive Threat Scanning
Proactive threat scanning uses heuristics to detect unknown threats. Heuristic process scanning analyzes the behavior of an application or process to determine if it exhibits characteristics of threats, such as Trojan horses, worms, or keyloggers. This type of protection is sometimes referred to as zero-day protection.
- Device and Application Control
Device-level control is implemented using rule sets that block or allow access from devices, such as USB, infrared, FireWire, SCSI, serial ports, and parallel ports. Application-level control is implemented using rule sets that block or allow the applications that try to access system resources.
New technology features for Symantec AntiVirus Corporate Edition customers
- Firewall
- Intrusion Prevention
- Proactive Threat Scanning
- Device and Application Control
New technology features for Symantec Client Security customers
- Proactive Threat Scanning
- Device and Application Control
Additional new features for all customers
- New client software user interface
The client user interface has been redesigned.
- Kernel-level rootkit protection
Rootkit protection is expanded to detect and repair kernel-level rootkits. Rootkits are the programs that hide from a computer's operating system and can be used for malicious purposes.
- New management console
The management console is redesigned and is called the Symantec Endpoint Protection Manager console.
- Roles based administration
Allows different administrators to access different levels of the management system based on their roles and responsibilities.
- Group Update Provider
Symantec Endpoint Protection clients can be configured to provide signature and content updates to clients in a group. When clients are configured this way, they are called Group Update Providers. Group Update Providers do not have to be in the group or groups that they update.
- Location awareness
Location awareness features expanded from what previously existed in the Symantec Client Security product. Symantec Endpoint Protection expands location awareness support to the group level. Each group can be divided into multiple locations; and when a client is in that location, policies can be applied to that location.
- Policy Based settings
Policies now control most client settings. Settings are now controlled with the policies that can be applied down to the location level. For example, consider two policies that affect LiveUpdate settings. One policy specifies how often LiveUpdate runs and controls user interaction. The other policy specifies the content that can be installed on client computers with LiveUpdate.
- Domains
Domains are now available for use. Domains let you create additional global groups. This feature is advanced and should be used only if necessary.
- Failover and load balancing
If you have a large network and need the ability to conserve bandwidth consumption, you can configure additional management servers in a load-balanced configuration. If you have a large network and need the ability to configure redundancy, you can configure additional management servers in a failover configuration.
- SQL Database support
Client information is now stored in a database on the management server. Legacy products stored information in the registry. Symantec Endpoint Protection Manager now stores all information about client computers in a SQL database (the embedded database or a Microsoft SQL database).
- Enhanced LiveUpdate
LiveUpdate now supports downloading and installation of a wide variety of content including definitions, signatures, white lists to prevent false positives, engines, and product updates.
Technical Information:
Technical Information
References:
This document is available in the following languages:
Document ID: 2007090318343048
Last Modified: 10/21/2008
Date Created: 09/03/2007
Product(s): Endpoint Protection 11
Release(s): Endpoint Protection 11.0