Beware of sneaky fees for open-source security products
The most popular open-source security products – virus scanners, spam filters, intrusion-detection and -prevention (IDS/IPS) engines, and vulnerability management tools – require a fairly constant stream of updates to their internal rules databases to stay useful and abreast of the latest threats.
These rules updates have different names depending on the products, but they’re very distinct from software updates. Rules updates for ClamAV and SpamAssassin are still free, at least for now. Indeed, one of the astonishing things about the ClamAV project – certainly the most frequent updater of rules – how long the team has been able to keep updates free (although contributions are solicited). Because these updates consume a lot of time, many enterprise network managers have shied away from ClamAV in the fear that the updates will slow down or, one day simply stop.
Sourcefire (maintainer of the Snort IDS) and Tenable Network Security (maintainer of the Nessus vulnerability-management scanner) have opted for a mixed commercial and freeware approach to releasing their rules. Recognizing that a major part of the value of these applications is in their frequent rules updates, both companies have made timely updates subject to a modest subscription fee. If a company is willing to wait, it can have the updates at a later date for free.
A subscription fee caters to enterprise-class customers who are willing to pay for security products and need current updates, but prefer open source. Those fees can go into paying people to maintain the rules databases, a fairly thankless job where remuneration is the key to consistency and currency.
Armed with open source>




