
Wave Endpoint Monitor | Wave Systems Corp. 2012
ESC 2.9.5 Client Manual
6. Wave Endpoint Monitor
Wave Endpoint Monitor (WEM) is an additional product that can use ESC to help you detect Advanced
Persistent Threats (APTs) that would otherwise go unnoticed for long periods of time and cause severe
damage and data loss. An APT could be a rootkit, and could even reside in infected firmware. To combat
this, Wave utilizes tamper-resistant storage locations on the TPM called Platform Configuration
Registers (PCRs). Each is used to securely collect hash information about a computer’s pre-OS
environment. This information is compared to a known set of trusted values. Malware cannot tamper
with the quotes sent to the server, as the quotes are signed by a private key that never leaves the TPM.
WEM provides customizable alerts, providing administrators real time warnings so they can take action
immediately when threats occur.
6.1. Client Requirements
Broadcom TPMs require firmware version 1.2.7.13 or higher. Other TPMs may require the latest
firmware update.
6.2. Additional WEM requirements
Please reference the ERAS/WEM TPM Deployment Guide, ERAS 2.9 Installation Guide and WEM
Administrator Manual for more clarification and information specific to installation and use of WEM.
Komentáře k této Příručce