SOMERSET, N.J. – October 6, 2003 –
Netilla Networks, Inc., a leading provider of SSL VPN and secure application
access management solutions, today unveiled dynaTRUST, a comprehensive
policy management and enforcement operating system for secure application
access management. An evolution and extension of Netilla’s
existing SecureRealm Policy Framework, Netilla’s dynaTRUST
operating system lets enterprises provision dynamic trust-based access
to applications and data on the basis of four key variables: a user’s
identity, entitlements, environment and client integrity. In conjunction
with dynaTRUST, Netilla also announced it is working with leading
vendors to enforce endpoint security policies (see separate announcement
today).
Policy enforcement consists of an organization’s rules that
control the type of applications and resources that employees can access,
their authority to use network resources, and the security safeguards
required. Policy enforcement and management are becoming more important
as enterprises need to take into account more diverse sets of users,
such as remote users.
Unlike other SSL VPN products that merely allow remote users to connect
to their enterprise networks, the Netilla dynaTRUST O/S offers a policy-based
approach that governs access to applications by all authorized users – remote
and internal, trusted partner or employee. By simultaneously authenticating
users, enforcing policy and ensuring client integrity, Netilla dynaTRUST
will speed the evolution from today’s static access control to
the dynamic provisioning of trust-based access to network resources.
“The rapid growth of SSL VPNs for remote access is blurring
the traditional network perimeter, giving remote users an ‘express
lane’ connection that bypasses standard perimeter-defense mechanisms
such as firewalls,” said Bryan Bain, vice president of marketing
and business development at Netilla Networks. “Netilla dynaTRUST
handles this challenge by serving as a policy enforcement point to
grant secure access to both the nomadic fringe as well as the internal
user. Think of it as an ‘SSL VPN Plus,’ since it delivers
access to applications for all enterprise users, not just remote workers.”
"Policy-based application access systems that integrate endpoint
security assurance should see rapid acceptance," said David Thompson,
senior research analyst at META Group. "While more workers are
demanding flexible remote access options that enable access to their
business applications from any Web browser, enterprise IT managers
need to ensure that those remote clients, which are often not under
company control, still conform to their company's security policies
before being granted access to critical applications."
Enhanced Policy Enforcement
The Netilla dynaTRUST O/S is now being shipped as the standard operating
system for the Netilla Security Platform (NSP) appliances, available
in three classes. Authentication and user/group policy modules are
shipping now as part of the dynaTRUST O/S, while client integrity
and reporting modules will be included in the next release.
The system’s policy enforcement features include identity authentication,
role-based entitlements (directly interfacing with Microsoft Active
Directory), endpoint integrity validation and restoration, pass/fail
detection and logging. Should an endpoint be noncompliant with security
policy, dynaTRUST will automatically initiate a quarantine action,
take appropriate remedial action, re-check the host for compliance
and ultimately grant access. Thanks to Netilla’s technology alliances,
these remedial actions can include ensuring that personal firewalls
and/or antivirus programs are running; updating virus definitions,
host firewall policies, or host IDS signatures; inspecting Windows
version and configuration; and even downloading and installing Windows
patches. This automatic remediation improves overall IT cost-efficiency
while offering an extra layer of policy enforcement.
Netilla is working with these best-in-class technology leaders to
extend the capabilities of dynaTRUST:
Authentication: RSA Security, Aladdin, VASCO, ActivCard.
Endpoint Security/Client Integrity: Microsoft, Sygate, Symantec, WholeSecurity,
Zone Labs.
User/group policy store: Microsoft Active Directory.