Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Check Point Software and MEMCO Software Introduce Hardened Firewall Option For FireWall-1

SeOS Secured! For FireWall-1 Available For Commercial Unix Systems

McLEAN, VA - April 14, 1997 - The first hardened firewall for popular commercial Unix systems will be unveiled today at the NCSA Firewall Web Internet Security show held here this week. This new software product, SeOS Secured! For FireWall-1(TM) , was developed jointly by computer security industry leaders, Check Point Software Technologies Ltd. (Nasdaq: CHKPF) and MEMCO Software Ltd. (Nasdaq: MEMCF).

SeOS Secured! For FireWall-1 enables users to securely run Check Point FireWall-1 on the same server as other applications with the assurance that access to the firewall will be limited to authorized users. SeOS Secured! For FireWall-1 also protects intranet firewalls and remote firewall management consoles within internal networks.

A hardened firewall is one that runs on a secure operating system and avoids unauthorized tampering with the firewall operation. Previously, hardened firewalls required a non-standard operating system or specialized hardware, but these approaches suffered from compatibility limitations with commercial applications. SeOS Secured! For FireWall-1 however, runs on standard hardware and commercial Unix systems, including HP-UX, SunOS and Sun Solaris . With Check Point FireWall-1 and SeOS Secured! For FireWall-1, customers have a secure and cost-effective firewall solution that is compatible with existing installations.

"Managers who need the strongest protection must not only have robust enterprise security software but must ensure that the underlying operating system is resistant to unwanted tampering by authorized individuals from inside the corporation," said Michael Zboray, Networking Technologies Research Director at Gartner Group.

Customer Scenarios

Used as a standalone Internet gateway, the Check Point FireWall-1 enterprise security solution, with its "Stateful Inspection" technology, intercepts all network communications before they reach the operating system. Therefore, FireWall-1 does not leave the underlying operating system vulnerable to attack, either by network users or Internet hackers.

However, as use of firewalls continues to expand, customers need to deploy firewalls securely in Internet and intranet environments. SeOS Secured! For FireWall-1 provides additional protection and security to help support this trend, including addressing the following customer scenarios:

Shared Servers - Companies increasingly need to host multiple applications on a shared Internet or intranet server. This scenario typically provides multiple administrators with access to all applications on the server, including the firewall. As access expands to multiple users, so do the threats from abuse of super-user (a.k.a. root) privileges, Trojan horse and back-door attacks. SeOS Secured! For FireWall-1 provides the highest level of security for firewalls on shared servers by ensuring that only authorized firewall administrators have access to the FireWall-1 configuration and operation controls.

Remote Management - Larger companies often use the FireWall-1 enterprise management console to centrally manage multiple firewall gateways throughout their organization. While the actual firewall gateways may be physically isolated, the management console is typically accessible on the system administrator's desktop. Installing SeOS Secured! For FireWall-1 on the remote management console ensures that only authorized FireWall-1 administrators can manage the FireWall-1 gateways.

High-Security Requirements - Government agencies and other high-security installations often require a secure operating system for all computing platforms. These are situations when all firewall access must be controlled and restricted. SeOS Secured! For FireWall-1 accomplishes the same end result as non-standard operating systems without the limitations or high costs.

"Our partnership with MEMCO Software provides customers with a solution that further strengthens the security of FireWall-1, especially in distributed environments where secure remote management is important," commented Asheem Chandna, director of business development.

Product Benefits

The primary benefits of the SeOS Secured! For FireWall-1 product are the following:

Security - SeOS Secured! ensures availability, reliability and integrity of FireWall-1 operation by controlling access to all FireWall-1 processes, configuration and audit files.

Accountability - With SeOS Secured!, FireWall-1 customers are supplied with additional auditing capabilities including identifying administrators using root by their true user name.

Flexibility - With SeOS Secured!, FireWall-1 customers can better leverage existing Unix systems by securely running FireWall-1 with other applications.

Cost Savings - SeOS Secured! enables implementing FireWall-1 (and other applications) on existing standard Unix systems without requiring the purchase of additional hardware/software firewalls and non-standard operating systems.

Ease Of Use - Installation and operation of SeOS Secured! is automated and requires no security knowledge. The resulting protection leverages the collective expertise of Check Point Software and MEMCO Software in securing FireWall-1 operation.

"SeOS Secured! provides customers with the flexibility to securely run FireWall-1 on shared commercial servers," commented Peter Harrison, MEMCO product manager, "saving them time and money."

SeOS Access Control

The foundation for SeOS Secured! For FireWall-1 is MEMCO's SeOS Access Control, a unique, patent-pending security solution. SeOS (Security for Open Systems) prevents unauthorized access to data and system resources on distributed client/server systems. SeOS prevents the abuse of root privileges and unauthorized user access, allowing legitimate users to work uninterrupted, and maintaining the confidentiality and integrity of critical business data and applications. SeOS security policies are consistently enforced and managed across mixed Unix systems, including HP-UX, IBM AIX, SunOS, SunSolaris, AT&T MP-RAS and Sinix. Support for Windows NT is planned in the second half of 1997.

SeOS Secured! hardens FireWall-1 by implementing a proactive security policy that protects all FireWall-1 resources. SeOS Secured! protects the processes, configuration files, data files, audit files and administrative utilities. Access is limited to specific users with specific rights—avoiding accidental or malicious abuse by Unix root users. All security-sensitive events are audited and tamper-proof.

Check Point FireWall-1

Check Point Software Technologies' award-winning Check Point™ FireWall-1™ enterprise security solution is a comprehensive application suite that integrates access control, authentication, encryption, network address translation, content security, auditing, and connection control. The suite is unified by Check Point's Open Platform for Secure Enterprise Connectivity (OPSEC) policy management framework which provides integration and enterprise management for FireWall-1 and many third-party network security applications. FireWall-1 provides support for more than 120 services, applications and protocols out of the box.

FireWall-1 is based upon the patented "Stateful Inspection" technology for intelligent network monitoring, which provides full application-layer awareness, delivering the highest level of security and inspecting each network communication before it reaches the operating system. Unlike an application gateway, Stateful Inspection does not require a separate proxy for every service to be secured and does not expose the operating system to attack. This results in improved performance, salability, and the ability to support new and custom applications much more quickly.

Product Availability

The SeOS Secured! For FireWall-1 option will be available from Check Point resellers worldwide beginning in the second quarter of 1997. The product is compatible with FireWall-1 version 2.1 and version 3.0 on HP-UX, SunOS and SunSolaris. Pricing for SeOS Secured! For FireWall-1 will be announced at a later date.

SeOS Secured! Partner Program

SeOS Secured! For FireWall-1 is the first product to result from MEMCO's SeOS Secured! partner program. The SeOS Secured! initiative targets vendors with business-critical software applications that run on open client/server systems, including firewalls, application servers, databases, Web servers and online commerce systems. The program provides software developers and application providers with the ability to increase the level of security offered to their customers. SeOS Secured! creates an environment that protects all resources belonging to an application (e.g., data, system files and processes) from inherent operating system vulnerabilities. The SeOS Secured! program provides partners with distinct competitive advantages, joint marketing activities and additional revenue opportunities.

About Check Point Software Technologies

Check Point Software Technologies Ltd. is the global network security software market share leader and inventor of the patented "Stateful Inspection" technology (U.S. Patent No. 5,606,668). According to a December 1996 report by the Yankee Group, the company's flagship product, Check Point FireWall-1, commanded 44% of the worldwide firewall market in the first half of 1996. FireWall-1 protects internal and external network communications for thousands of organizations of all sizes. Its products are sold worldwide through OEM partners, distributors, VARs, systems and network integrators and Internet Service Providers. The company has U.S. headquarters in Redwood City, California and international headquarters in Ramat-Gan, Israel. For product information, please visit our Web site at http://www.checkpoint.com , e-mail info@checkpoint.com , or call (800) 429-4391.

About MEMCO Software

A leading provider of advanced information security solutions, MEMCO Software offers a comprehensive product set designed to address enterprise security concerns. MEMCO's solutions effectively enforce, administer and control security and productivity in distributed environments. The Company successfully partners and integrates its products with leading providers of complementary technologies. MEMCO has also formed strategic distribution partnerships with Tivoli and Platinum Technology. The Company's international headquarters are in Tel-Aviv, Israel and New York City. For more information about MEMCO Software, please visit its Web site at http://www.memco.com .

 

###