Threat Prevention
Preempt zero-day attacks.
Suppress propagating worms.
Stop low-and-slow attacks.
Reduce APT risks.
SANS Critical Security Controls - See how NAC closes gaps.
Download »
EMA analyst report on assuring network access control (NAC) success. Download »
IDC analyst report on architecting a mobile security/BYOD strategy. Download »
Control who and what is accessing your network with CounterACT.
View the datasheet »
Learn more about ForeScout solutions by downloading the brochure. Download »
The Tolly Group evaluates
the leading NAC products
across 34 criteria points.
Download report »
Enable any means access to corporate network resources without compromising security. Download Snapshot»
Gartner 2012 NAC Magic Quadrant. Download Report»
CounterACT in Action Feature Film (<3 min) Watch Video»
Learn more about ForeScout solutions by downloading the brochure.
Download »
EMA analyst report on assuring network access control (NAC) success.
Download »
IDC analyst report on architecting a mobile security/BYOD strategy.
Download »
Preempt zero-day attacks.
Suppress propagating worms.
Stop low-and-slow attacks.
Reduce APT risks.
ForeScout’s patented ActiveResponse™ technology blocks zero-day threats, identifies and suppresses propagating worms, stops low-and-slow attacks and can be used as a layered defense against APTs – without signatures and false positives. Our unique technology does not require any form of maintenance, so the total value is significant while the total cost of ownership is very low.
Gone are the days when a firewall, an externally-facing IPS, and a well-managed anti-virus system constitute sufficient protection. While these layers of security are still valuable, attackers have found ways to work around them. Industry experts report that between 4% to 8% of all enterprise computers are infected, despite the presence of host-based security agents and sophisticated patch management practices.
Why are the bad guys winning? One reason is that new business models and competitive pressures are generating explosive growth in network connectivity, both internally (wireless networks, VPN, guest network access) and externally (links to customers and business partners). This has made the network perimeter all but disappear. As a result, IT security becomes more challenging as more attacks come from the “inside.”
A second reason why the bad guys are winning is the onslaught of unmanaged devices that are connecting to enterprise networks. These devices include smart printers (which can be compromised but cannot be secured via traditional antivirus), smart phones, employee-owned computers, contractors’ computers, specialized equipment, etc. This phenomenon has been called the “consumerization of IT”, and market analysts are claiming that it is one of the top three challenges that organizations need to work on in 2011.
Clearly, enterprises need a new approach to threat prevention.
One approach would be to purchase traditional signature-based intrusion detection systems and place them both at the perimeter (thus protecting the network against external attack) and in the interior (protecting the network against compromised endpoints). This is doable, but very costly. The management overhead of signature-based IPS systems is high, for the following reasons:
ForeScout’s patented ActiveResponse™ technology blocks both known and unknown attacks without signatures. This unique technology does not require any form of maintenance, so the total cost of ownership is very low. And since ForeScout products install out-of-band, IT managers find it far easier and more economical to deploy ForeScout threat prevention products.
ForeScout’s ActiveResponse™ technology lets you:
ActiveResponse™ technology is included in two different ForeScout products—one designed to protect your interior network, the other designed to protect your network perimeter:
ForeScout’s patented ActiveResponse™ technology blocks both known and unknown attacks without signatures. This unique technology does not require any form of maintenance, so the total cost of ownership is very low.
Here is how ActiveResponse works:
The first step for most network attacks is reconnaissance. In this step, an attacker (either human or automated) gathers information about the network’s configuration and vulnerabilities. ForeScout’s Active Response technology detects this reconnaissance and responds with counterfeit or “marked” information. Any subsequent attempt to use this marked information is proof of malicious intent. This allows ForeScout products that contain ActiveResponse technology to block the attack without the need for signatures, deep-packet inspection or manual intervention.
The following diagrams illustrate how ForeScout CounterACT Edge uses ActiveResponse to identify and stop an attack coming from outside the network. The same principles apply to attacks that originate within the network, which can be detected and blocked by ForeScout CounterACT.

ForeScout’s patented ActiveResponse™ technology delivers strong protection against network attacks with far lower management overhead than traditional signature-based IPS systems. Here are the benefits of products that contain ActiveResponse: