Solutions: Xceedium GateKeeper Technology

Home » Solutions » Xceedium GateKeeper Technology

Xceedium GateKeeper Technology

Learn More - Download

The PCI Kit
Forrester:The Top 10 Things
You Should Know About PCI
Compliance

Aberdeen:Protecting Card
Holder Data

Xceedium:PCI Compliance -
Technical Note

Xceedium Resources
Xceedium:GateKeeper PCI
Brochure

Xceedium:LeapFrog
Prevention Whitepaper

Xceedium's flagship product, Xceedium GateKeeper, cost-effectively and unobtrusively allows organizations to secure their IT environments from System, Network and Database Administrators using command line or application interfaces from any location either internal or external. The Xceedium GateKeeper implements and automates controls – and the testing of these controls – for these high-risk privileged and external users.

The GateKeeper's unique technology delivers the most powerful compliance solution on the market for privileged and external users that includes: centralization of access, compartmentalization, containment, comprehensive tracking, monitoring and alerting, as well as automated reporting.


Xceedium GateKeeper Technology Summary

Function Benefit Value Proposition
Control access to systems and applications from any location
  • Containment
  • Secure communications
  • User accountability
  • Real-time remediation
  • Reduce cost and complexity of maintaining access controls
  • Protects confidential information during transit
  • Increases system and application security
  • Enforces segregation of duties at the network and
    system level
  • Provide robust event logging
  • Real-time alerting
  • Keystroke and session recording
    to support investigations
  • Centralized tracking of user
    activities
  • Increases efficiency and effectiveness of investigations
    and monitoring activities
  • Reduces response time to incidents
  • Comprehensively Monitor and track privileged users
  • Reduces cost of remediation and security violations
  • Produce standard and custom reports Automate the testing of controls with reports directed to roles, functional area, dashboards, forensics, scorecards, etc.
  • Reduces cost of remediation and security violations
  • Provide ad-hoc and role-based reports
    • Expand capabilities of existing access control and
    monitoring solutions
    • Layer on top of and add value to: CITRIX SIM SIEM

  • Centralization of Heterogeneous Infrastructure

    • IT operations platform that allows these users to easily do their jobs
    • Security policy creation and enforcement
    • Tracking of all user events and activities for all devices and systems, including keystroke logging and session recording


    Compartmentalization Access Method – Reverse Port Tunneling

    • Reverse Port Tunneling access methodology provides compartmentalization to the port level
    • Lack of visibility to unauthorized areas of the infrastructure
    • Application Isolation
    • No footprint on the network

    Using a Reverse Port Tunneling access methodology, the Xceedium GateKeeper enables granular compartmentalization for each user at the device, system, port and application level, as well as centralized SSL encryption for all access methods. The Xceedium GateKeeper provides dual layer encryption, which is a simple and unobtrusive way to phase out client-side access to legacy systems (i.e. legacy POS systems.) It can also provide clear text protocol conversion if required by the customer (i.e. SSH-to-Telnet.)


    Containment – LeapFrog Prevention™ Technology

    • LeapFrog Prevention Technology
    • Lockdown containment to authorized areas
    • Appliances
    • Servers-windows, Unix, Linux, Citrix
    • Flexible white list and black list
    • Real-Time Alerting
    • Remediation

    Xceedium's patent-pending LeapFrog Prevention technology detects and prevents violations of the access security policy with a violations model that includes the ability to define commands and key words that are prohibited from use (with a white list or black list). If a particular action is a violation, Xceedium GateKeeper prevents it from being completed and issues real-time alerts. Additionally, LeapFrog Prevention socket filter technology enables the Xceedium GateKeeper to monitor and enforce policy at the socket layer, as well as prevent and track all user violations. When a user attempts to open a socket to another device or server on the network using interactive protocols or commands, GateKeeper blocks use of the protocol to prevent "leap-frogging" to other unauthorized devices. LeapFrog Prevention technology is available for Windows, Linux, Solaris, AIX and all network devices/appliances.


    Monitoring and Alerting

    • Connections are monitored and reported in real-time
    • Proof of containment
    • Email notification
    • Real-time alerting of violation attempt
    • Silent Alerts Available
    Xceedium GateKeeper provides an end-to-end view of privileged user activity at all levels, including the command line level, and a complete audit trail that crosses over the many different components and systems and artificial boundaries established in the enterprise. The Xceedium GateKeeper also delivers real-time alerting and remediation.


    Tracking and Logging

    • End-to-end view of all activity, in one central place, at the source IP address level
    • User activity is tracked and logged, including the date and time the user logged into a specific device and the access method. Additionally, the duration of the session is audited and tracked for future review and to validate compliance
    • Detailed audit capabilities that deliver not only keystroke logging but session recording
    Additionally, keystroke logging and full CLI session recording ensure that all user activity is tracked, including the date and time the user logged into a specific device and the access method used. The duration and content of the session is logged/recorded for both in-band and out-of-band.


    Reporting

    • Standardized report templates allow auditors and regulators quick access to familiar reports and evidence

    Xceedium provides easy-to-produce reports that assist companies in validating that they have met PCI compliance requirements. These centralized reports deliver information on individuals, groups, devices, protocols, violations, etc. and are combined with flexible filtering to make it possible to easily produce the comprehensive audit reports needed to satisfy PCI compliance requirements.


    Toll Free: 877-636-5803 | info@xceedium.com
    © 2008 Xceedium, Inc. Privacy Policy | Terms of Service