Sourcefire boasts strong IPS management toolset

Reviews
Jan 21, 20087 mins

3D System helps companies make sense of security data

SourceFire’s most recent release of its 3D System certainly puts the company on the right track to making network intrusion-detection/prevention systems useful tools in the enterprise. In the Sourcefire 3D System Version 4.7, we found substantial progress in areas specific to management and configuration of the IPS, along with newly integrated tools which link user information to security incidents

Sourcefire‘s most recent 3D System release certainly puts the company on the right track to making network intrusion-detection/prevention systems much more useful tools in the enterprise. In the Sourcefire 3D System Version 4.7, we found substantial progress in areas specific to management and configuration of the IPS, along with newly integrated tools which link user information to security incidents.


How we tested Sourcefire

Archive of Network World tests

Subscribe to the Network Product Test Results newsletter


Sourcefire’s 3D System includes detection engine software for IDS/IPS, service and vulnerability discovery (called Realtime Network Awareness), and user-to-IP address mapping (called Realtime User Awareness) and the hardware to run all the software components. The same Sourcefire software can also be run on hardware from Crossbeam, Nokia, and Nortel. The Sourcefire bundle also includes a management system – we used the Defense Center 1000 in our test but the company also offers a DC3000 version geared toward very large networks.

Two of the most important changes in 3D System Version 4.7 lie in the RNA and RUA components. When we looked at the RNA in its first releases, we found its ability to provide network visibility by passively discovering systems, applications and vulnerabilities useful. However, RNA was not integrated into IDS and IPS policy definition at that point. In this release, Sourcefire finally brings RNA into the big picture by letting the network manager easily use RNA-discovered information to refine IDS and IPS policy and build compliance policies. For example, RNA can recommend enabling and disabling IDS rules based on the services and systems actually running on the network — helping to simplify and speed the process of tuning the IDS policy. 

Another addition to the 3D System is Netflow analysis, which did provide traffic and service information in our test network, but required a cumbersome deployment. Netflow analysis takes advantage of the ability of routers and switches to collect and forward information about which hosts are on the network and what they’re doing — an alternative to full-fledged RNA analysis that would be useful in very distributed networks or ones where IDS monitoring is technically impractical. 

Our disappointment in Netflow wasn’t in its functionality, but in the way that Sourcefire chose to implement the collection. Rather than simply following the normal practice of collecting Netflow messages from switches or routers, Sourcefire sensors have to watch the Netflow traffic as it passes by — which might be of value in some networks where Netflow is already being used and IDS sensors are watching the management traffic, but is likely to get in the way of normal operations in others, as it did in ours.

INTRUSION-PREVENTION SYSTEMS Sourcefire 3D System 4.7

Sourcefire


4.0
Price:3D2100 sensor, $15,995; DC1000, $16,995; RNA for 100 hosts, $3,000; RUA for 100 hosts, $900; Netflow for five exporters, $14,975
Pros:New features extend analysis and compliance options to make IDS/IPS easier and faster to use; NetFlow and RUA tools add security data to the mix in a tightly integrated way.
Cons:NetFlow deployment model may not work for everyone; RUA roughly integrated in this first version; Snort detection engine needs updating.
The breakdown
Intrusion protection 20%4Scoring Key: 5: Exceptional4: Very good3: Average2: Below average1: Subpar or not available
Vulnerability detection 20%3

Network awareness 20%

4.5
User awareness 20%4
SIM/SEM 20%4.5
TOTAL SCORE4.0

RUA uses three main techniques to try and associate a person with an IP address at a particular moment in time. Those techniques are packet capture of different logins (including Windows domain login and applications such as those supporting POP and IMAP), direct integration with an Active Directory server (via an installed agent on the server), and LDAP lookups to a directory. 

The idea is that when the network manager sees an IDS or IPS event, it may be very useful to know who was using the particular laptop or desktop when the event occurred. RUA user information can also be used in Sourcefire’s compliance toolkit, built-in to the 3D Management System. For example, certain kinds of compliance events such as running peer-to-peer applications might only affect a particular group of users who shouldn’t be using them according to company policy.

While RUA was pretty good (although not perfect) at identifying who was using a particular laptop, it wasn’t clear just how useful and reliable the user identity information would be in operating an IPS. In well-managed Windows networks where compliance is a main concern, RUA could be a fantastic tool. RUA will be less useful in heterogeneous networks or ones where the IPS is protecting servers rather than client users, because RUA won’t have useful user information.

Sourcefire has pushed other “user-centric” features throughout 3D System Version 4.7 to take advantage of the information available in RUA, such as creating on-the-fly user profiles, but it’s hard to predict which will bring the most value. It is likely that RUA’s integration into the 3D System will continue to be refined as network managers provide feedback on what works, and what doesn’t, with the RUA integration.

Other small additions to the IDS and IPS analysis tools also represent a big step forward in system usability. For example, when viewing a specific IDS or IPS event, the network manager is only one click away from enabling or disabling rules, turning on IPS drop mode, adding rate thresholds or suppressing false positives for a particular IP address. Sourcefire also continues in its quest to flesh out the “manager of managers” capabilities in 3D System, which allow multiple management consoles to report and aggregate data up to a higher-level manager.

One area that didn’t see any real change in this product was in the detection engine. Sourcefire’s IDS and IPS detection is based on Version 2 of the Snort engine, written by the same engineers. That Camembert is getting a bit too runny to still be on the shelves. However, Snort and the Sourcefire rule set are in need of updating. (Learn more about IDS products from our IDS Buyer’s Guide.) 

We tested the Sourcefire IPS using the same methodology we used in testing IPS in our recentUTM firewall test. (Learn more about UTM products from our UTM Buyer’s Guide.)  Using the Sourcefire-recommended aggressive IPS policy, the sensor caught only 12% of client attacks and 25% of server attacks — a slightly lower rate than our top finishers, but in line with what most other IPS products we tested did. Sourcefire told us that a rewrite of the Snort engine, Version 3, will be folded into the 3D product this summer.

Sourcefire has really changed the IPS game the last few years by focusing on the management features rather than on tweaking its own Snort detection engine. That’s a bet that has paid off, as network managers have found that better manageability, rather than better detection, gives more value in an IDS and IPS deployment. While Sourcefire will have to turn back to improving their detection capabilities eventually, the leaps forward in management within this new release make Sourcefire 3D a cutting-edge security toolkit.

Snyder is a senior partner at Opus One, a consulting firm in Tucson, Ariz. He can be reached at Joel.Snyder@opus1.com.

Snyder is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.