|
Solution
Sygate Magellan maintains the
most complete, accurate, and detailed information about the current
state of the network, enabling organizations to monitor continuously
their network assets' level of policy compliance. Sygate Magellan
tracks all IP-addressable devices on a network, identifies when
those devices appear or disappear, logs the software that runs
on them, probes their configurations and capabilities, and characterizes
their de facto compliance.
Benefits:
Minimizes Network Downtime and
Business Disruption
Ensures timely discovery of compromised and rogue devices before
they can be exploited to bring down networks and application services.
Reduces Security Costs
Automates detection of rogue devices and compliance checking of
all devices.
Ensures Regulatory Compliance
Ensures compromised and rogue devices do not escape the information
protection process
Creates an audit-quality historical log of changes to the network,
devices, and security policy.
How it works:
Magellan has a distributed, appliance-based
architecture comprising three elements: multiple Sygate Discovery
Engines which detect and probe the network for Network Dark Matter™,
the Sygate Correlator which aggregates information gathered by
Sygate Discovery Engines, and the Java-based Magellan User Interface
(MUI) which administrators use to manage Magellan and view its
reports.
Intelligent probes use a combination
of credentialed and non-credentialed techniques in a ‘cascade'
fashion to ensure detailed information is gathered without crashing
systems. Once this information is collected, the system automatically
classifies devices into functional groups.
The administrator can use this
discovered information to assign business priority and policy
compliance attributes to specific applications and Operating Systems
(e.g. forbidden, required, permitted), from which compliance reports
can be generated and remediation plans can be drafted.
Magellan manages a standard RDBMS
database of all connected devices, which stores changes, additions,
and deletions to their configurations over time. This database
can be mined by the Analysis tools in the MUI and by external
report writers to generate customized reports. With its open architecture,
Sygate Magellan is extensible to include feeds from external information
sources, including Enterprise System Management and Asset Management
Systems.
Key discovery functions
include:
Automated Discovery
- Comprehensive census of any network-attached, IP-addressable
device
- Intelligent probes with an option to use credentials to
optimize performance and accuracy with minimal impact to application
services
- In-depth identification of each device includes IP address,
MAC address, open ports, active services, NetBIOS name, Current
Domain, SNMP MIB info, OS fingerprint.
- Distributed discovery enables device discovery beyond firewall
and NAT devices
- Device classification automatically organizes discovered
devices into function-specific sets such as firewall, web
server, database, or workstations
- LAN sensors, part of the Sygate Secure Enterprise solution,
monitor ARP traffic to identify, in real–time, all IP-addressable
devices trying to connect to the network. Sygate Magellan
automatically stores this information, by subnet, and uses
it to schedule follow-up probing.
Compliance
Security managers can measure
progress toward full policy compliance on all connected devices.
- Maintain an audit-quality historical log of changes to the
network, security policy, and the operation of the product
– monitoring capabilities that are key to effective governance
- Present a high-level dashboard with graphs/charts to show
aggregate analysis of compliance, manageability, and census
of IP addresses, devices, Operating Systems, and services.
- Capture user-defined policies for applications, patches,
operating systems, services
- Capture user-defined business value for assets
- Identify devices that could be managed by Sygate Secure
Enterprise – the most comprehensive solution for endpoint
security
Data Analysis and Reporting
Sygate Magellan provides pre-defined
reports, drill-down capabilities, access to external report writers,
and data export features. Security and network administrators
can use these capabilities to define metrics of network integrity,
measuring the costs and impacts of network events, and answer
key questions such as:
- What is on my network today?
- What has changed on my network?
- What devices are manageable/unmanageable?
- What devices are compliant/non-compliant?
- What devices are business-critical?

|