AGAT

Categories
Uncategorized Skype for Business SkypeShield

SphereShield enables internal use of Ethical Wall for Skype for Business

Following SkypeShield’s successful launch of the Federation Ethical Wall solution, customers have been requesting the ability to use the same functionality internally, applying specific rules between different users or groups. SkypeShield has therefore extended the Ethical Wall to support controlling internal traffic as well as external.

SkypeShield’s Ethical Wall offers granular control over federation to address security and data protection when federating with external companies. Now, SkypeShield offers the ability to use the same functionality internally, applying specific rules between different users or groups in the same company.

The new user interface of the Ethical Wall has a clean and simple interface allowing control of each activity and the ability to control communication direction. For example, it is possible to allow one side only to start a chat with the other side.

These new capabilities support blocking a specific group in the company to communicate with another group in the same company. For example, a certain employee group may be prevented from calling management level group, or communication may be blocked between the procurement group and the tender writing groups.

The new feature therefore helps in implementing compliance regulation in companies.

SkypeShield’s Ethical Wall offers the following features:

  • Defines granular policy rule based on a user/group communicating with a specific company (SIP domain) or another group in the same company
  • Provides independent control of each activity : IM, audio, video, conference (meeting), desktop sharing, file transfer
  • Blocks presence information from external users depending on policy
  • Supports one way initiation of communication. For example, it blocks external users from initiating an IM conversation while still allowing internal users to initiate and communicate with external users.
  • Changes policy for users that are added to contact list. Allows user some local policy management by applying different policies based on inclusion in a user’s contact list. This way, by adding the federated user to the internal user’s contact list, the policy will allow more federation such as presence information.
  • Enforces policy in the DMZ and blocks non-approved traffic from entering the network
Categories
Uncategorized MDM Microsoft Lync Skype for Business SkypeShield

How to deal with security vulnerabilities while publishing Skype for Business

Microsoft’s aggressive move of switching the enterprise world from its old branded unified communications platform (Lync) to Skype for Business, has not solved entirely all the security vulnerabilities arising from connecting mobile and other external devices to the corporate network.

Here are some security vulnerabilities arising from external access to Skype for business that organizations should pay attention to:

  • Account lockout – someone who knows your user name can lock your internal account by sending failed login attempts. Generic solutions fail to monitor all authentication channels exposed, including SIP and SOAP. SkypeShield offers a unified monitoring and protection solution.
  • Malicious code accessing internal server – In order to support guests joining meetings, some service support anonymous access. From a security perspective, there are requests that can reach the web servers in the domain without the need to authenticate and without inspection. SkypeShield offers a four-layer application firewall for Skype for Business including session termination, application and protocol inspection and rewriting requests.
  • Password theft from infected device – A valid employee can use any device, including his personal device that might be jail broken or infected, to connect to the network. In such a case, domain credentials can fall to the wrong hands. Even with an MDM solution implemented, there is no control when using a non-managed device. Protect yourself by using device access control and limit the usage only to devices with MDM.
  • Exposing emails – If calendar information is enabled on the organization’s Skype for Business clients, someone with valid credentials can have access to all emails. SkypeShield offers a solution for protecting the corporate Exchange by blocking any Exchange request, unless coming from a registered device and from a Skype for Business client.
  • Data and privacy information exposed – While implementing federation trust with external companies, privacy (availability) and server information data is exposed. The federation is available globally for all company members with all federated external companies with no control over the different modalities allowed, such as file sharing. Deploying SkypeShield ethical wall handles these issues by defining granular control based on user, groups and companies based policies.
  • Data loss prevention (DLP) – As the usage of Skype for Business extends outside the network boundaries, enabling communication with external parties via federation meetings poses some serious security and data protection risks. This arises from the fact that data flow between parties is very accessible and easy to use at any time, any place, and by any device.Preventing data leaks going through Skype for Business is a serious challenge because of the variety of mobile, Web and desktop clients Skype for Business offers and because of the SIP protocol in use by the clients. SkypeShield offers a new concept based on a server side inspection covering all of the data channels. The DLP solution supports both a built in DLP engine as well as integration with commercial DLP vendors.

SkypeShield is continuously adding security layers to make sure your company can allow external access to Skype for Business with the highest level of protection available.