终端防护
和威胁防护
如今的无边界网络正在重新定义终端防护。随着各种终端随意访问网络,它们正在存储敏感的企业数据。因为 70% 的成功数据泄露始于终端,1 因此,终端安全防护方式可帮助阻止网络攻击。SandBlast Agent 是保护贵组织的高级终端防护和威胁防护解决方案。
1 “Cybercrime: The Credential Connection,” IDC

Webinar: "Endpoints at the Edge: The Stakes are Rising

创新型威胁防护技术
Uses static, dynamic, and behavioral detection and prevention technologies with advanced artificial intelligence to provide high catch rates and low false positives

见解深入的检测和响应
Assures continuous collection of comprehensive and complete raw forensics data, employing full attack remediation capabilities

完整的终端安全解决方案
Integrates into Check Point Infinity to get maximum prevention across all attack surfaces, shared intelligence, and a single point of management (cloud service or on premise)

SandBlast Agent 被 NSS 评定为“推荐”评级
这标志着我们自 2010 年起获得了第 18 个整体 NSS 推荐评级。
高级终端保护 (AEP) 测试重点:
- 100% HTTP 拦截率
- 100% 电子邮件拦截率
- 100% 离线威胁拦截率
- 100% 躲避拦截率
- 0% 误报
SandBlast Agent 功能
SandBlast Agent 是一个完整的终端安全解决方案,提供一系列的高级终端威胁防护功能,可令您在当今凶险的威胁环境下保持安全。
它提供一个综合系统,可主动防御、检测并修复善于躲避的恶意软件攻击。


Evasion-resistant sandbox technology detects malicious behavior and prevents potential attacks

Reconstructs downloaded files, delivering clean, risk-free files to users in real time

Protects and prevents vulnerable applications and systems from exploit attacks

Detects, contains, and remediates infected hosts

Blocks deceptive phishing sites and alerts on password reuse in real time

Prevents, detects, and remediates even the most evasive attacks

Detects and quarantines the most evasive ransomware variants

Records and analyzes all endpoint events to provide actionable attack forensic report
其他功能
Combines pre-boot protection, boot authentication, and strong encryption to make sure that only authorized users are given access to information stored on desktops and laptops.
Provides secure, seamless, and remote access to corporate networks.
Stops unwanted traffic, prevents malware, and blocks targeted attacks, ensuring protected computers comply with security requirements; assigns different security levels according to the compliance state of the endpoint computer.
Cloud Management or On-premise
SandBlast Agent offers unified, scalable, and granular management available as a cloud service or installed on your premise.
- Unified – Manage all your endpoint security needs from a single console
- Scalable – Use one management infrastructure to manage your endpoints, from a few to hundreds of thousand devices
- Granular – Choose the management granularity that fits your needs. Relay product best practices based on defaults; go deeper by configuring everything on your system, or anywhere in between
SandBlast Agent cloud management service is fully deployed,maintained, and optimized by Check Point enabling rapid deployment, elastic growth, constant server updates and location independent.
SandBlast Agent 选择和规格
Features |
Data Protection |
Basic |
Advanced |
Complete |
Unified Endpoint Security Advanced |
Unified Endpoint Security Complete |
---|---|---|---|---|---|---|
Deployment | ||||||
Agent | ||||||
Browser Extension | ||||||
Mobile App | ||||||
Reduce Attack Surface | ||||||
Endpoint Firewall | ||||||
Application Control | ||||||
Endpoint Compliance | ||||||
Port Protection (Peripheral control) | ||||||
Remote Access VPN | ||||||
Data Protection: Full disk and removable storage encryption | ||||||
Prevent Attacks Before They Run | ||||||
Endpoint Anti-Virus: Known signatures, heuristics | ||||||
Static Analysis: Machine learning-based prevention | ||||||
Anti-Exploit | ||||||
Zero-Phishing: Anti-phishing, credentials reuse prevention | ||||||
Threat Emulation (SandBox) | ||||||
Threat Extraction (Document sanitization) | ||||||
Runtime Detection and Protection | ||||||
Anti-Ransomware | ||||||
Behavioral Guard: Mutations of known malware, generic unknown malware | ||||||
Behavioral Guard: File-less attacks | ||||||
Anti-Bot: Malicious Command and Control (C&C) traffic detection | ||||||
Anti-Evasion: Evasion techniques detection | ||||||
Contain and Remediate | ||||||
Block traffic to Command and Control (C&C) servers | ||||||
Lateral movement prevention and infected machine isolation | ||||||
Process termination and file quarantine | ||||||
Encrypted file restoration | ||||||
Full attack chain sterilization | ||||||
Attack Investigation and Response (EDR) | ||||||
Forensics collection | ||||||
Automated event forensics analysis report | ||||||
Threat hunting | ||||||
Multi-surface attack immunization (IoC and IoA sharing) | ||||||
Cloud Management | ||||||
SandBlast Mobile (iOS and Android threat prevention) |
Forrester Research 将 Check Point 评为终端安全套件领导者
统一安全基础设施
SandBlast Agent 是 Check Point Infinity 的一款核心产品、一个完全整合式网络安全架构,可提供前所未有的保护,保护网络、终端、云端和移动设备免受第五代大型网络攻击。此架构旨在解决连通需求增长和安全性不足所带来的复杂问题。
即刻开启您的 SandBlast Agent 概念验证
“反勒索软件刀片是一项功能卓越的技术。 不仅可以保护您免受勒索软件侵害,而且不依赖于签名即可达到防御目的。这意味着,即使您断开网络连接,仍可免受未知变种的攻击。”
– Mississippi Secretary of State 首席技术官 Russell Walker
其它资源
下载文件
SandBlast Agent Solution Brief
Check Point SandBlast Agent: Earns NSS “Recommended” Status in AEP Test
Whitepaper: Enterprise Security Performance
Report: The Forrester Wave™: Endpoint Security Suites, Q2 2018
Endpoints at the Edge: The Stakes Keep Rising
Hybrid Threat Prevention: A Practical Approach to Cyber Security