Specifications

RoamAbout Mobility System Software Configuration Guide 20-1
20
Configuring SODA Endpoint Security
for a RoamAbout Switch
SygateOnDemand(SODA)isanendpointsecuritysolutionthatallowsenterprisestoenforce
securitypoliciesonclientdeviceswithouthavingtoinstallanyspecialsoftwareontheclient
machines.MSScanbeconfiguredtorunSODAsecuritychecksonusers’machinesasa
requirementforgainingaccesstothenetwork.
About SODA Endpoint Security
TheSODAendpointsecuritysolutionconsistsofsixmodulesthatprovideondemandsecurity:
VirtualDesktopProtectsconfidentialdatabyvirtualizingthedesktop,applications,file
system,registry,printing,removablemedia,andcopy/pastefunctions.Alldataisencrypted
ontheflyandcanoptionallybeeraseduponsessiontermination.Thevirtual
desktopis
isolatedfromthenormaldesktop,protectingthesessionfrompreviousinfection.
HostIntegrityTeststhesecurityofthedesktoptodeterminehowmuchaccesstonetwork
resourcesthedeviceshouldbegranted.Hostintegritychecksinclude:
–Ensuringthatanantivirusproductisrunningwithupto
datevirusdefinitions
–Ensuringthatapersonalfirewallisactive
–Checkingthatservicepacklevelsaremet
–Ensuringthatcriticalpatchesareinstalled.
Customcheckscanbeimplementedbasedontheexistenceofspecificregistrykeys/values,
applications,files,oroperatingsystemplatforms.Networkaccesscanalsobepreventedbased
ontheexistence
ofspecificprocesses.
MaliciousCodeProtectionDetectsandblockskeystrokeloggersthatcaptureusernames
andpasswords,Trojansthatcreatebackdooruseraccounts,andScreenScrapersthatspyon
useractivity.
TheMaliciousCodemoduleintegratesaVirtualKeyboardfunctionthatrequiresusersto
inputconfidentialinformationsuchaspasswords
usingtheVirtualKeyboardwhenaccessing
specificWebsites,toprotectagainsthardwarekeystrokeloggers.Thismoduleusesa
combinationofsignaturesforknownexploitsandbehavioraldetectiontoprotectagainst
unknownthreats.
For information about... Refer to page...
About SODA Endpoint Security 20-1
Configuring SODA Functionality 20-4