Skip Links

Network World

  • Social Web 
  • Email 
  • Close

FireEye network battles bots

Botwall Network puts malware appliances in service provider networks
By Tim Greene , Network World , 09/24/2007

FireEye is installing malware detectors in ISP networks so it can tell its corporate customers when their machines have been commandeered by bots.

The company has installed between 10 and 20 nodes of its Botwall appliances in the networks of five ISPs to locate bot command-and-control servers and individual zombie PCs that have been taken over by bots.

Called Botwall Network, the service reports which machines in customer networks are communicating with bot servers or are attempting to propagate bot maleware to other machines, says Ashar Aziz, president and CEO of FireEye.

The company recommends that these machines be reimaged to make sure the bot software is eliminated entirely.

“The idea is that by putting their appliances in with ISPs, they can see more traffic and can react better at client sites,” says Raffi Jamgotchian, CIO of Canaras Capital in New York City. Canaras has a FireEye appliance in its network to detect many kinds of malware, but the network service can help pinpoint bots, he says.

The network can also give a broader perspective on attacks, says John Oltsik, an analyst with Enterprise Strategy Group. For instance, if bot activity is detected in the Asia-Pacific region via Botwall Network, it can help customers in regions where the bot has not yet started to work to protect themselves, he says.

FireEye gear monitors network traffic looking for anomalies and suspicious traffic patterns, and when it identifies suspect code, runs it on virtual machines within the Botwall appliance to determine whether it is malicious and what it does when executed.

The devices can block malicious traffic using port blocking, null routing or TCP connection resets. They also log suspicious activity and actions they take and alert IT management to traffic it flags.

With Botwall Network, customers can let their FireEye appliances report suspicious behavior to the network to add data on overall global malware activity. FireEye will not reveal in which service provider networks it has established nodes of Botwall Network.

The approach is similar to Symantec’s DeepSight System, which also uses customer input to discover threat behaviors on the Internet, Oltsik says.

FireEye is also introducing two new Botwall appliances, the Botwall 4100 and the Botwall 4700. They have the same features as the company’s earlier Botwall 4200, but differ in performance.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.