Security Expert Karen Scarfone analyzes top comprehensive Encryption Products
Security Expert Karen Scarfone analyzed several top full encryption products on the market one by one, and determined which one may be the most suitable for your company.
Full encryption (FDE) is widely used in a variety of desktop and mobile device operating systems. This technology can encrypt all static data on the hard disk to protect important information and prevent leaks.
There are various types of Full-disk encryption software products on the market. Some are bundled with other condoms, some are independent, and some are built into the operating system. This article focuses on the analysis of non-bundled solutions (independent and built-in operating systems ). This is not to say that the bundling solution is inferior; however, the criteria required to evaluate the bundling solution are much wider than the pure FDE solution.
Five leading commercial FDE products on the market are: Check Point full-disk encryption products, Dell data protection and encryption products, McAfee full data protection products, Sophos SafeGuard and Symantec Endpoint Encryption Products. It is worth noting that Dell products can be used either on Dell hardware or on non-Dell hardware. There are also several popular open-source FDE solutions, including DiskCryptor. Finally, there are solutions provided by the operating system, such as Apple FileVault 2 and Microsoft BitLocker.
All these FDE solutions have been widely used, and FDE products have been available for only a few years. These products provide basic FDE functions to protect static data on desktops, laptops, and certain mobile devices. Some can also be used on servers, but since they are mainly protected by desktops and laptops, this article will focus on these computer platforms.
As there are so many FDE products on the market, it may not be easy to find a product suitable for enterprises. Fortunately, there are many mature products to choose from. You can also refer to the seven major criteria for distinguishing FDE products.
First standard: Device deployment
The FDE software provided by the operating system seems to have a significant advantage in device deployment because the software has been installed as part of the operating system. However, this is not the case.
In the FDE deployment environment, it is often much more difficult to configure software and strictly manage configurations than to install software. If users can modify the FDE configuration, they may inadvertently or intentionally weaken or disable this technology, making it useless. Users can launch denial-of-service attacks on their systems as long as they delete the encryption key or otherwise make unwise changes to the configuration.
The commercial FDE product provides the remote deployment function, so that the system administrator does not need to view each end user device. This saves valuable time and is also essential for remote users (such as remote office staff and long-time travel staff. To some extent, Microsoft BitLocker provided by the operating system can be managed through Group policies, but it is actually used for local management, just like Apple FileVault 2. Open-source products usually require local installation and configuration. They generally assume that regular end users do not change the FDE configuration.
Second Standard: Product Management
For FDE, management is not completely limited to FDE configuration. Management needs to be considered in many aspects, including key rotation, password change, patch installation, and password upgrade (such as increasing the key length and adopting new encryption algorithms ).
For the enterprise's FDE deployment environment, the importance of centralized management cannot be emphasized too much. The main cost of FDE lies not in the software, but in management and support. Because the initial cost of a solution is low, it does not mean that the actual operation cost will be relatively low in the long run. Open-source solutions generally do not provide any form of centralized management. As a result, management and support are particularly costly, especially in large enterprises.
One of the most surprising aspects of FDE is that the products provided by operating systems are often considered difficult to manage and supplemented by other FDE products. Some commercial products tested in this article can actually add management functions to the FDE provided by the operating system, such as Dell data protection and encryption products, McAfee comprehensive data protection products and Sophos SafeGuard. From a performance perspective, this advantage-the ability to use native FDE features while ensuring that a single and powerful centralized management framework has been deployed to meet both FileVault and BitLocker needs.
Third standard: Compatibility
In terms of compatibility with the existing environment, many enterprises should be most concerned about how the FDE solution handles devices that enter sleep or standby mode (usually laptops ). The problem is that a laptop in this mode will be lost or stolen. If FDE does not provide powerful protection for the data stored in the computer, sensitive data can be easily leaked.
Because compatibility varies with products and operating systems (or even environments ), it is strongly recommended that enterprises use each FDE solution they consider to test their devices-whether it is a native operating system solution (Microsoft BitLocker and Apple FileVault 2 ), third-party solutions (Check Point full-disk encryption products, Dell data protection and encryption products, McAfee full data protection products, Sophos SafeGuard and Symantec Endpoint Encryption Products), or open-source solutions (DiskCryptor ). In this way, they can understand the performance of various FDE solutions in their particular environment during computer sleep or standby.
There may also be conflicts between FDE software and applications that directly access the hard disk-some are obvious, such as disk utilities, some are not obvious, such as some asset management programs. It is strongly recommended that enterprise organizations test each FDE product that is intended to be purchased against any applications that may directly access the hard disk, identify any incompatibility, and then contact the manufacturers of the affected products, ask for possible solutions.
Fourth standard: Verify service integration
It is generally recommended that enterprise organizations use MFA for FDE, so that products that completely repeat operating system password verification are generally not accepted. FDE software should have its own authentication mechanism, or use enterprise-level MFA, such as the Active Directory, smart card or password token (the latter is preferred ). All commercial products mentioned in this Article support multi-factor verification, including smart cards and password tokens. Dell data protection and encryption products are particularly worth mentioning, the reason is that it also supports biometric feature recognition technology. For Apple's FileVault 2 and Microsoft's BitLocker features, there are limited options for verification services, unless FileVault or BitLocker also uses third-party commercial products that can add centralized management and other features.
Fifth standard: Key Recovery
Password Key Recovery is a particularly important management function of FDE, because if the password recovery fails or is impossible, the affected users will never be able to access all locally stored data. Complex centralized key recovery functions are only available for commercial additional products. FileVault provides centralized key recovery: It stores the recovered key in Apple and allows users to call Apple to recover the key. However, it may be in violation of the enterprise's security policy to ask a third party to keep the encryption key. Therefore, when evaluating potential products, enterprises must pay attention to where to restore the key storage. When Microsoft BitLocker is used independently, it does not provide any centralized key management.
Commercial Products support centralized key recovery activities performed by administrators. Some products also support self-service recovery, such as Check Point full-disk encryption products and Symantec Endpoint Encryption Products. It is important to carefully assess the security of each restoration solution.
For example, self-help recovery products may require users to answer questions, such as their preferred colors or pet names. Criminals can exploit these problems to obtain the user's password without authorization, thus avoiding FDE on the user's device. When evaluating the key recovery plan, the enterprise organization should first determine whether the key is restored to a user or an administrator (or both ).
Sixth Standard: Mitigating brute force attacks
To deal with brute-force password attacks, the most common mitigation method is to extend the interval between verification attempts and suspend verification attempts for a period of time, or erase the data on the device after multiple failed attempts. If a single factor (password) Verification is used, any such mitigation method is urgently needed. In addition to the full-disk Check Point encryption product and Symantec Endpoint Encryption product, other products mentioned in this article cannot provide mitigation methods to deal with brute-force attacks, so it is important to ask the vendor for detailed information in this regard.
Seventh standard: cryptographic algorithms
Considering the current situation of cryptographic technology, FDE products generally adopt Advanced Encryption Standard (AES) algorithms, preferably a 256-bit key. All products mentioned in this article use AES and support 256-bit keys.
In addition, it is recommended to formally evaluate FDE products and determine whether their cryptographic mechanisms are secure and reliable, which is actually required by some enterprise organizations. The most common certification is the Federal Information Processing standard (FIPS) 140-2 compliance certification. For information on FIPS-2 compliance certification, see here (http://searchsecurity.techtarget.com/feature/The-fundamentals-of-FDE-Comparing-the-top-full-disk-encryption-products ).
Some products do not comply with FIPS 140-2, such as Symantec terminal encryption and Apple FileVault 2 for Yosemite, because these are new products (launched by the end of 2014 ). These products are waiting for FIPS-2 testing, so they are expected to pass compliance certification in the near future. Open-source products such as DiskCryptor do not comply with the FIPS-2 standard, most likely because of the financial burden of obtaining certification. Therefore, enterprise organizations that need to Use FIPS compliance products may have to invest in the authentication process for these open-source products if they want to implement open-source products.
Another aspect to consider is the password key storage location, local or remote; if stored locally, where is stored on the device. For example, Dell data protection and encryption products and Microsoft BitLocker can use the local Trusted Platform Module (TPM) to provide powerful protection for stored data. If the key is stored locally and the stored key is not properly protected, attackers can restore the key and avoid the protection mechanism provided by FDE, thus breaking through the security defense line of the device.
Conclusion
All the software described in this article can provide basic FDE products. Whether the product is suitable for enterprises is determined by the availability of comprehensive software management functions. For example, although many enterprises already have the FDE software provided by the operating system, they still purchase FDE because of the many difficulties they face in managing the FDE provided by the operating system. There are also some open-source products that provide free FDE functions, but they lack management functions, which are most suitable for personal and one-time systems, and not suitable for standard enterprise deployment environments.
Among many commercial products, no product has obvious advantages. Each enterprise needs to compare products horizontally to determine which one is most suitable for their own requirements. In many cases, this means purchasing products from the same vendor that provides other security products used within the enterprise. If any commercial product is used in the FDE deployment environment of the entire enterprise, the enterprise should feel relaxed.