- FTC targets prerecorded telemarketing drivel
- 16 hot roles for IT pros
- Securing SSLVPN with client certificates
- 13 desktop-virtualization tools
- 10 must-have virtualization tools
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
FireEye is installing malware detectors in ISP networks so it can tell its corporate customers when their machines have been commandeered by bots.
The company has installed between 10 and 20 nodes of its Botwall appliances in the networks of five ISPs to locate bot command-and-control servers and individual zombie PCs that have been taken over by bots.
Called Botwall Network, the service reports which machines in customer networks are communicating with bot servers or are attempting to propagate bot maleware to other machines, says Ashar Aziz, president and CEO of FireEye.
The company recommends that these machines be reimaged to make sure the bot software is eliminated entirely.
“The idea is that by putting their appliances in with ISPs, they can see more traffic and can react better at client sites,” says Raffi Jamgotchian, CIO of Canaras Capital in New York City. Canaras has a FireEye appliance in its network to detect many kinds of malware, but the network service can help pinpoint bots, he says.
The network can also give a broader perspective on attacks, says John Oltsik, an analyst with Enterprise Strategy Group. For instance, if bot activity is detected in the Asia-Pacific region via Botwall Network, it can help customers in regions where the bot has not yet started to work to protect themselves, he says.
FireEye gear monitors network traffic looking for anomalies and suspicious traffic patterns, and when it identifies suspect code, runs it on virtual machines within the Botwall appliance to determine whether it is malicious and what it does when executed.
The devices can block malicious traffic using port blocking, null routing or TCP connection resets. They also log suspicious activity and actions they take and alert IT management to traffic it flags.
With Botwall Network, customers can let their FireEye appliances report suspicious behavior to the network to add data on overall global malware activity. FireEye will not reveal in which service provider networks it has established nodes of Botwall Network.
The approach is similar to Symantec’s DeepSight System, which also uses customer input to discover threat behaviors on the Internet, Oltsik says.
FireEye is also introducing two new Botwall appliances, the Botwall 4100 and the Botwall 4700. They have the same features as the company’s earlier Botwall 4200, but differ in performance.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment