Open Source Subnet An independent Open Source community View more

Sourcefire Stays True To Its Roots

New cloud based anti-malware tool leans heavily on open source

Sourcefire is a security company that had its genesis in founder Marty Roesch's Snort open source intrusion detection system. Along the way Sourcefire has taken over the stewardship and introduced several other open source projects. One of the best known was the ClamAV anti-malware project. 

While Sourcefire has grown beyond Snort and ClamAV to a full range of commercial solutions, they have always stayed true to their open source roots.  A little while back they bought Immunet, another maker of an anti-malware solution.

Monday Sourcefire released FireAMP a cloud-based anti-malware security solution based on the Immunet technology with a healthy dose of the ClamAV technology as well.  FireAMP is a different kind of anti-malware security product. Unlike many of the traditional AV products that have moved to the cloud like Symantec, McAfee and Trend, FireAMP takes another approach. Rather than trying to block malware at the perimeter or as it tries to enter the endpoint. FireAMP instead sends information to Sourcefire's cloud by the on board agents where it is analyzed. If it is deemed malicious, you have the option of having Sourcefire remove it or just report on it.

I spoke today with Al Huger, Sourcefire's VP of Development for the Cloud Technology Group and a co-founder of Immunet.  Al said that FireAMP has open source software all through it. From a lot of the infrastructure it is built on, including some NoSQL database technology, to some ClamAV agent technology and other stuff, FireAMP wouldn't be possible without open source.  While FireAMP is still a product, there is certainly a service element to it. Part of a new class of cloud enabled product/services.  Whil not itself an open source solution, many of the components behind it are.  Huger said that of course using and supporting open source is a strong tradition within Sourcefire and will continue to be so.

I was glad to hear this, but frankly did not expect anything different. Roesch and the Sourcefire team have always displayed a deft hand in understanding and leveraging the open source community. While not an open source project in and of itself, it is good to see FireAMP continuing the Sourcefire tradition. 

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.
Must read: 10 new UI features coming to Windows 10