Think Inside The Box!

Because the architecture of the modern computer system is, and will most likely continue to be, decentralized with the addition of more remote components incoroprated into the total system solution

  • internet portals
  • distributed services
  • offshore solutions
  • mobile workforce
  • telecommuting
  • global marketplace

Secutrity auditing must be incorporated to insure that the system is not compromised by unauthorized software.

ProActive Secure Systems products are designed to enable you to secure your system from unauthorized software regardless as to how it was installed.

Frequently Asked Questions

Click on questions of interest:

How will the ProActive Secure Systems Audit protect my system?

The ProActive Secure Systems Audit will protect your system by continuously evaluating if any objects deemed to be security exposures are added, modified or deleted on a monitored system.

How does ProActive Secure Systems Audit work?

The ProActive Secure Systems Audit uses baseline data gathered when the system's installed components are in a steady state. That is, when all operating system and value added components have been installed in a controlled environment (where communications channels to external networks are disabled) and only authorized components are installed from trusted distributions.

I have a firewall and antivirus solution deployed on my system, why do I need to use the ProActive Secure Systems Audit?

The ProActive Secure Systems Audit is a component of a total security plan which includes antivirus and firewall products. It complements these other components to add additional security to the monitored system.

Although anti-virus software does a good job of blocking known problems there could be problems that are not yet detected which may not be blocked. There's more, some viruses disable your anti-virus software so they can operate undetected.

Zero-day exploits may not be filtered when they are first released or you may not have updated the anti-virus signature file before being infected.

Targeted trojans are designed to install and go undetected by anti-virus systems and once installed harvest confidential data.

Rootkits are another example of unauthorized software that can be installed and may not be detected by anti-virus software. In the case of DRM [Digital Rights Management] software they may be installed when you use an otherwise legitimate product and may not be recognized as being a problem.

That is not to say that you will not need anti-virus and firewall products on your machine. They provide an invaluable service that are your first line of defense and no system should be without them. The ProActive Security Audit is a second line defense aimed at insuring that no unauthorized software that has been installed on your system remains undetected.

ProActive Security Audit is used to supplement antivirus and firewall appliances to insure your system is protected by a comprehensive security solution.

How are targets determined to be security exposures?

The ProActive Secure Systems Audit determines an object to be a security exposure if either of two conditions exist; the object is capable of operating on it's own without assistance from any other component, and/or, the object can be used by another component to perform some operational functionality.

How different do files have to be in order to detect tampering?

The ProActive Secure Systems Audit is able to detect changes as small as one bit differing between two objects. This fine granularity ensures that the audit is able to detect any changes to objects targeted to be monitored.

Why is the ProActive Secure Systems Audit better at protecting my system?

The ProActive Secure Systems Audit uses cryptographic security digests thus greatly decreasing the possibility that a specially crafted object can escape detection. These security digests are used along with other profile metrics to detect any modification to the monitored environment that are known to impact the system's security.

Can the ProActive Secure Systems Audit be used to measure the security impact of installed software?

The ProActive Secure Systems Audit provides baseline files in XML format so that the raw data can easily be imported into most popular database, spreadsheet and statistical applications. These data contain references to every component on the system deemed to be of interest form a security perspective. Statistical analysis can be applied using before and after baseline data to highlight areas of interest.

Can the ProActive Secure Systems Audit be used to insure that employees do not install unauthorized software on their workstations?

Absolutely! The ProActive Secure Systems Audit detects any modification to the monitored environment deemed to affect the security of the system since the environment was baseline without regard to how the change originated.

Unauthorized software can come in many forms. Games and screen savers are a common form of virus transport as a lot are downloaded from the internet and are not from legitimate software distributors.

A primary reason for using the ProActive Secure Systems Audit is that it is totally impartial. It's detection ability is not influenced by the mode of operation by which the environment was modified.

I bought software from eWidgits [a reputable software manufacturer] and the audit tells me that the eWidgit dynamic link library has changed since it was baselined. How can I let the audit know that this is legitimate software?

You can exclude components from the audit that you know to be legitimate.

Before doing so you should be absolutely certain that the component is functioning as designed and is not a compromised version of the component. One way hackers use to cloak the presence of malicious payloads is to replace a known system component with a modified component that has additional nefarious functionality. Components should only be loaded from authentic manufacturer distributions! If in doubt contact the components distributor or manufacturer to determine if the component is supposed to be modified dynamically. For detailed instructions go to Exclusions.

How can I contact a ProActive Secure Systems representative to answer questions I have?

A ProActive Secure Systems regional representative can be contacted by proceeding to the Contacts page on this site and sending an email to the nearest representative.

How can I buy a ProActive Secure Systems Audit System?

The ProActive Secure Systems Audit can be purchased by proceeding to the Purchase Products page on this site and following the directions given there.