- Microsoft will float cloud OS this month
- Top 16 Chinese iPhoneys
- Pimp your ride: Cool car technology
- Laptop stolen from McCain campaign
- Cisco, Microsoft roll out server, networking appliance
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Value of WDS
Sourcefire's most recent 3D System release certainly puts the company on the right track to making network intrusion-detection/prevention systems much more useful tools in the enterprise. In the Sourcefire 3D System Version 4.7, we found substantial progress in areas specific to management and configuration of the IPS, along with newly integrated tools which link user information to security incidents.
Sourcefire's 3D System includes detection engine software for IDS/IPS, service and vulnerability discovery (called Realtime Network Awareness), and user-to-IP address mapping (called Realtime User Awareness) and the hardware to run all the software components. The same Sourcefire software can also be run on hardware from Crossbeam, Nokia, and Nortel. The Sourcefire bundle also includes a management system – we used the Defense Center 1000 in our test but the company also offers a DC3000 version geared toward very large networks.
Two of the most important changes in 3D System Version 4.7 lie in the RNA and RUA components. When we looked at the RNA in its first releases, we found its ability to provide network visibility by passively discovering systems, applications and vulnerabilities useful. However, RNA was not integrated into IDS and IPS policy definition at that point. In this release, Sourcefire finally brings RNA into the big picture by letting the network manager easily use RNA-discovered information to refine IDS and IPS policy and build compliance policies. For example, RNA can recommend enabling and disabling IDS rules based on the services and systems actually running on the network — helping to simplify and speed the process of tuning the IDS policy.
Another addition to the 3D System is Netflow analysis, which did provide traffic and service information in our test network, but required a cumbersome deployment. Netflow analysis takes advantage of the ability of routers and switches to collect and forward information about which hosts are on the network and what they're doing — an alternative to full-fledged RNA analysis that would be useful in very distributed networks or ones where IDS monitoring is technically impractical.

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
Security Considerations When Deploying Remote Access SolutionsEffective network security is most successful when you use a layered approach, with multiple...

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Turning information into a Competitive AdvantageCompanies today are realizing that competitive advantage is harder to sustain when based solely on...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...
The Evolution of Network SecurityWe have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (3)
I agree with the test data - Sourcefire misses quite a few attacBy Anonymous on August 16, 2008, 2:09 amThe article mirrors my own testing. The Snort signature language is easy to learn, but it's not a very powerful signature language for educated users.
Reply | Read entire comment
IPSes aren't the same as Firewalls: yeah, I know.By Joel Snyder on January 23, 2008, 10:41 pmI am guessing (I can't tell for sure) that you're talking about the part of the test where we used the Mu-4000 to run various attacks through the IPS. I think...
Reply | Read entire comment
RE: Sourcefire boasts strong IPS management toolsetBy alvarius on January 22, 2008, 1:55 pmI find it peculiar that the author is putting an IPS product and a Firewall under the same umbrella. The fact that both products are capable of blocking traffic...
Reply | Read entire comment
View all comments