End point security

From Wikipedia, the free encyclopedia

End-point-security is an information security concept that basically means that each device (end-point) is responsible for its own security.

Traditionally, firewalls, central virus scanners and other intrusion detection or intrusion prevention devices were held responsible for securing an end-point. However with the SSLVPN, the intrusion prevention systems in the perimter become ineffective as SSLVPN can be controlled at the two end points one being the desktops and other outside the user control in the internet space.

End point security places the onus of security on the device itself. Real-life examples of this happening can be best seen with Broadband users' increasing use of desktop firewalls, spam and antivirus software.

A variant of the End point security is the on demand end point of security. In this concept the server sends activex or java component which does the following in the client pc's :

Profiling of the client environment from perspective of firewall, antivirus, patches etcc.
memory protection program to create virtual desktop whose memory is different from that of the host system.
deletes all data on exit.