The policy rules that are created on a Firewall system are designed to do what they ought to do. But a system administrators policy rules may not be static all the time. Sometimes, they need to add temporary rules for a while, or allow some access privileges and then deny those privileges. Also many system administrators need a policy to allow access for some time ranges in a day, for example just for work-hours (9am-6pm). Sometimes, it is necessary for the system administrator to remove restrictions of a user without distrupting the overall firewall policy.
For these reasons, firewall systems depend on system administrators actively and waste effort to manage all those requests and privileges all the time. System administrator must respond to all those requests and be on the system. For this reason the system administrator should be working on the system all the time without spending time on validating and evaluating the overall IT systems security but just managing the firewall. This leads to many garbage policy rules over time, and also for the lazy system administrators to loosen the policy rules thus reducing the security of the system.
At this point, Labris product family offers the following features to system administrators:
"System administrator shall assign time ranges to policy rules and without user interaction, may change rules. For example, after workhours, let Internet access be allowed to all users, while in workhours, only allow web and mail access"
Labris Firewall and Labris Webfilter in the Labris Security Gateway appliance allows system administrators to create policy rules that are based on time ranges and allow easy management of security policy.
"System administrators shall allow users, whose are authenticated through various authentication schemes and privileges assigned, to access permitted areas. The user shall transfer and use privileges assigned on his/her behalf on any system and on any time from the terminal he is using at that moment."
System administrator, using Labris IFAT technology, may create dynamic and expiring firewall policy rules per user so that authenticated users can have the assigned privileges without asking for those privileges all the time from the system administrator.
"Users shall access news sites only for the lunch break"
Access privileges of groups of users to predetermined filtering profiles may be controlled by using time objects defining the allowed time ranges.
"Under heavy load of database attacks, without system administrator's intervention reject access requests of the attacker."
Labris Intrusion Detection and Prevention System can detect an attack real-time and without requiring system administrator intervention to prevent the attack.
"Administrators shall monitor all client hosts and every morning a report on systems' status about the updates and vulnerabilities be prepared."
Labris Security Scanner can provide periodically prepared status reports about the network, client and server hosts' vulnerabilities.
Even in networks with security systems installed, there exists many security problems. The main reason for this is systems that are not properly managed. With the average 8 hours of daily sleep and plus time spent in traffic, system administrators have 12 hours of work time at most. Labris products in all units are featuring time objects, to efficiently use the system administrators' time and save management time exceeding 8 hours of working time under normal working conditions.