Feeds

Sourcefire jumps into anti-malware market

Cyber-outbreak defence tech to shore up big biz

The Power of One eBook: Top reasons to choose HP BladeSystem

Sourcefire, the security biz behind the commercial versions of the open-source Snort intrusion-detection software, is bowling itself at enterprises and touting tech designed to quickly detect and block malware outbreaks.

FireAMP offers a malware discovery and analysis tool that offers visibility of threats and outbreak control. The technology offers a means to limit the damage from virus infections, which Sourcefire argues are more or less inevitable, especially in the face of ever more sophisticated and numerous threats.

Oliver Friedrichs, senior vice president of Sourcefire’s Cloud Technology Group, told El Reg that "threats are getting by existing defences". Sourcefire has positioned FireAMP to cover for the shortcomings of endpoint protection technology, rather than offering a replacement, at least with the first iteration of the technology.

"We're not necessarily interested in replacing anti-virus or building better mousetraps," explained Friedrichs, an ex-staffer at both Symantec and McAfe. "FireAmp could replace anti-virus, but it's not going to replace it immediately, especially because firms have invested in conventional security software. We're offering FireAMP as a way to shore up defences."

"We don't pretend our tool can detect 100 per cent of malware - nothing can," he added.

FireAMP uses data analytics to analyse and block malware. Security analysts can write their own signatures for digital nasties in much the same way that they create Snort attack signatures, albeit in a slightly different context. Sourcefire claims the cloud-based approach the technology uses is capable of identifying and scoring threats missed by other security layers.

Whitelisting

The technology can be used to block particular strains of malware without running system scans. It can equally be used to whitelist benign apps, an approach that helps to reduce the possibility of false positives.

Deploying the technology involves deploying a "flight-recorder"-like client agent on PCs, which allows firms to quickly figure out which process introduced malware into their environment and how malicious files subsequently spread on their network. This agent communicates with a cloud-based analysis engine and is designed to co-exist with any anti-virus or security software running on computers (so it unlike running two anti-virus clients on the same PC, a set-up that would always ends in tears).

Sourcefire's technology allows the "patient zero" of outbreaks that get missed to be later identified, Friedrichs explained, adding that this saves time on computer forensics. File trajectory technology bundled within FireAmp shows how malware spread across a firm, he said. Once problems are identified, remedial actions can be carried out from the FireAMP console.

FireAMP, which is based on technology Sourcefire acquired from Immunet last year, comes only a month after it released a next-generation application-aware firewall, twin moves designed to allow it to sell kit outside its traditional IDS niche.

FireAMP is been positioned against gateway technology designed to thwart botnets from the likes of FireEye or Damballa as well as malware/based analysis and forensics tools from HB Gary and Guidance Software. All these technologies aim to cover for the security shortcomings of anti-malware suites in one way or another. ®

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.