subject: An Introduction To Unified Threat Management [print this page] Enterprise networks are always vulnerable and prone to external threats from virus attacks, network intrusion, spams, worms etc. Different network security technologies were introduced in recent years to safeguard the network from these attacks in order to preserve enterprise resources.
Separate modules for protecting the network from viruses and worms were designed, enabling phishing attacks and pharming to be hindered in order to secure credentials of the user. Then there came firewalls, which secured the ports from unauthorized access and keep the network working by determining the ports which should be let open to outsiders and which shouldn't be. All these technologies were working just fine until the infrastructural complexity was not too high. As the size of networks grew, maintenance of these technologies separately, became difficult. It was desired to have a consolidated technique which could cater to all the needs and requirements related to network security. So, the concept of Unified Threat Management or UTM was introduced.
A UTM provides the following solutions related to network security in an enterprise network:
Firewalls
Web/URL filtering
Anti-Spam
Anti-Virus
Network Intrusion/Spyware Protection
VPN or Virtual Private Network
and possibly any other type of service related to enterprise.
UTM adds on the advantage of managing multiple devices from a central location and flexible grouping policies can be created for the same from a central management console. It's a preventive as well as reactive protection system which even provides protection for various infrastructural elements including business applications and services.
Generally, three types of UTM systems are there based on:
Hardware, which are special appliances configured with ASIC chip sets, capable of monitoring multiple threats simultaneously.
Software based UTM, which are hosted on standard computer servers with a certain configuration. It requires separate software-based security systems, like network security operating system, firewalls etc. to be installed on the same server and configured for securing number of users and applications based on the configuration.
Distributed UTM, which requires separate hardware-software coupled security monitors, each having its own functionality. Even though, these devices work separately still a common controlling interface is there which makes this tailored system as one single module.
UTM systems provides a complete solution for businesses which makes it easy for IT workforce to configure and maintain the entire network architecture from different threats and issues.