Approach and Deployment
The BOUNCER approach to application whitelisting reflects the three fundamental precepts of endpoint security:
A BOUNCER deployment uses a multi-tiered, yet simple architecture that consists of three components:
- The BOUNCER Client:
A lightweight software agent that resides on each individual endpoint at the lowest level of the operating system.
- The BOUNCER Manager:
A hardened device that sits seamlessly between the endpoint and the secure console.
- The BOUNCER Console:
The secure, simple interface that ties it all together, providing a single point of contact for all the endpoints protected by BOUNCER.
Infrastructure Features
- NEW Trusted Change:
Grant users trusted ways in which they can upgrade their systems or install new, approved applications. New in version 5, you can designate trusted ActiveX installations, digital signatures, and more.
- Scalable Architecture:
BOUNCER grows with your enterprise, with additional consoles, managers, and clients that are easy to deploy with automatic installation of endpoints in minutes — no hand-tooling of whitelists necessary.
- End-to-End Encryption:
All communications are fully encrypted from the console to the endpoint.
- End-to-End Authentication:
Embedded digital certificates authenticate all applications and components.
- Snapshot System Status:
BOUNCER tracks all managed components, giving you get real-time availability reports.
- Client Failover:
Clients are designed to communicate with a rollover manager if communications to the licensing manager fails.
- Network Security:
The system operates without interference with other installed security products such as firewalls, intrusion detection systems, and private VPN clients.
- Minimal Network Impact:
Limited traffic between components ensures network bandwidth is available for company needs.
Installation and Setup Features
- Plug-and-Play Secure Installation:
System components locate and authenticate each other for simple installation and setup, now fully automated in BOUNCER 5.
-
Flexible Software License Management:
Install, uninstall, and upgrade software using the embedded license management system.
- Minimal Client Impact:
Reboot of remote clients is not required during installation and, once operational, the client has minimal performance impact.
- Secure Online Support:
Download authenticated software from CoreTrace and rollout software upgrades and updates to all components.
- Self-Contained:
All software required to license, install, and configure the clients can be pre-loaded on the manager.
System Administration Features
- Optional Active Directory Integration:
Leverage your investment in Active Directory to take advantage of even more rapid "push" deployment and provisioning of Trusted Users.
- Two-Factor Administrator Authentication:
Electronic tokens in conjunction with an extended passphrase control access to the system.
- Two-Level Administration:
The system supports regular (limited-privilege) and master (full-privilege) levels of system administration.
- Centralized or Decentralized:
The security group can be managed from a single console or multiple consoles.
- Complete Accountability:
The system logs all administrative actions to maintain accountability over configuration.
- Emergency Administration:
The system supports an optional fail-safe (single privilege) level of system administration for disaster recovery.
Policy Administration Features
- Efficient Group Management:
Once endpoints have been automatically installed, they are managed as a collection, allowing you to perform a wide array of administrative functions as one unit.
- Automatically Generated File Policies:
Automatically create unique file policies for platforms as configured, complete with file digests.
- Custom Policies:
Administrators can modify default policies or build new policies to meet specific needs.
- Security Subgroups:
A large security group can be subdivided into smaller, more manageable administrative subgroups.
- User Transparency:
Changes to policy are dynamically implemented without a reboot or noticeable change on the user platform.
- Rapid Policy Deployment:
Changes to standard policies can be applied to thousands of clients across the enterprise in seconds.
- Disconnected Operation:
Policies continue to protect the user platform when it is ‘on the road‘ or in home use and not in communication with a manager.
Supporting & Related Resources
Looking for more or maybe something else? Try the CoreTrace Resources section.