Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Sourcefire boasts strong IPS management toolset

3D System helps companies make sense of security data
By Joel Snyder , Network World , 01/21/2008
  • Share/Email
  • Tweet This
  • Comment
  • Print

Sourcefire's most recent 3D System release certainly puts the company on the right track to making network intrusion-detection/prevention systems much more useful tools in the enterprise. In the Sourcefire 3D System Version 4.7, we found substantial progress in areas specific to management and configuration of the IPS, along with newly integrated tools which link user information to security incidents.


How we tested Sourcefire
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter

Sourcefire's 3D System includes detection engine software for IDS/IPS, service and vulnerability discovery (called Realtime Network Awareness), and user-to-IP address mapping (called Realtime User Awareness) and the hardware to run all the software components. The same Sourcefire software can also be run on hardware from Crossbeam, Nokia, and Nortel. The Sourcefire bundle also includes a management system – we used the Defense Center 1000 in our test but the company also offers a DC3000 version geared toward very large networks.

Two of the most important changes in 3D System Version 4.7 lie in the RNA and RUA components. When we looked at the RNA in its first releases, we found its ability to provide network visibility by passively discovering systems, applications and vulnerabilities useful. However, RNA was not integrated into IDS and IPS policy definition at that point. In this release, Sourcefire finally brings RNA into the big picture by letting the network manager easily use RNA-discovered information to refine IDS and IPS policy and build compliance policies. For example, RNA can recommend enabling and disabling IDS rules based on the services and systems actually running on the network — helping to simplify and speed the process of tuning the IDS policy. 

Another addition to the 3D System is Netflow analysis, which did provide traffic and service information in our test network, but required a cumbersome deployment. Netflow analysis takes advantage of the ability of routers and switches to collect and forward information about which hosts are on the network and what they're doing — an alternative to full-fledged RNA analysis that would be useful in very distributed networks or ones where IDS monitoring is technically impractical. 

Our disappointment in Netflow wasn't in its functionality, but in the way that Sourcefire chose to implement the collection. Rather than simply following the normal practice of collecting Netflow messages from switches or routers, Sourcefire sensors have to watch the Netflow traffic as it passes by — which might be of value in some networks where Netflow is already being used and IDS sensors are watching the management traffic, but is likely to get in the way of normal operations in others, as it did in ours.

INTRUSION-PREVENTION SYSTEMS

Sourcefire 3D System 4.7
Sourcefire


4.0
Price: 3D2100 sensor, $15,995; DC1000, $16,995; RNA for 100 hosts, $3,000; RUA for 100 hosts, $900; Netflow for five exporters, $14,975
Pros: New features extend analysis and compliance options to make IDS/IPS easier and faster to use; NetFlow and RUA tools add security data to the mix in a tightly integrated way.
Cons: NetFlow deployment model may not work for everyone; RUA roughly integrated in this first version; Snort detection engine needs updating.
The breakdown
Intrusion protection 20% 4 Scoring Key:
5
: Exceptional
4
: Very good
3
: Average
2
: Below average
1
: Subpar or not available
Vulnerability detection 20% 3
Network awareness 20%
4.5
User awareness 20% 4
SIM/SEM 20% 4.5
TOTAL SCORE 4.0
Click to see: Net results

RUA uses three main techniques to try and associate a person with an IP address at a particular moment in time. Those techniques are packet capture of different logins (including Windows domain login and applications such as those supporting POP and IMAP), direct integration with an Active Directory server (via an installed agent on the server), and LDAP lookups to a directory. 

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (3)
Login
Forgot your account info?

RE: Sourcefire boasts strong IPS management toolsetBy alvarius on January 22, 2008, 1:55 pmI find it peculiar that the author is putting an IPS product and a Firewall under the same umbrella. The fact that both products are capable of blocking traffic...

Reply | Read entire comment

IPSes aren't the same as Firewalls: yeah, I know.By Joel Snyder on January 23, 2008, 10:41 pmI am guessing (I can't tell for sure) that you're talking about the part of the test where we used the Mu-4000 to run various attacks through the IPS. I think...

Reply | Read entire comment

I agree with the test data - Sourcefire misses quite a few attacBy Anonymous on August 16, 2008, 2:09 amThe article mirrors my own testing. The Snort signature language is easy to learn, but it's not a very powerful signature language for educated users.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed