Sourcefire this week is expected to announce add-on software called Intrusion Agent for its intrusion-detection system freeware Snort. The add-on will let the freeware version of Snort work with an updated version of Sourcefire’s Defense Center management console, which has supported only the commercial Snort IDS until now.
Sourcefire this week is expected to announce add-on software called Intrusion Agent for its intrusion-detection system freeware Snort. The add-on will let the freeware version of Snort work with an updated version of Sourcefire’s Defense Center management console, which has supported only the commercial Snort IDS until now.
In the past, security managers using Snort typically have taken their own steps to integrate IDS information into management consoles of their own choosing, such as security event management products. Sold as an appliance, the Defense Center 3.2 console is now able to aggregate security-event information collected by both the commercial and freeware versions of the Snort sensor, which passively monitor for thousands of different attacks.
Defense Center 3.2 also can receive a continuous feed from Sourcefire’s passive scanning tool called Real-Time Network Awareness (RNA) to discover desktop and server operating systems and applications.
By comparing the attack alerts with the operating systems and applications on computers on the corporate network, Defense Center greatly reduces the false positives that are the bane of IDSs, the company says.
“It brings a new capability to IDS,” says Paul Pocialik, CEO of Reston, Va., systems integrator at Noblestar, which has used RNA since it was introduced at the end of last year.
While the RNA discovery tool used in conjunction with Snort doesn’t completely eliminate the problem of false positives with IDSs, it radically reduces them, he says. With the information on network assets provided by RNA, Defense Center can correctly prioritize security attacks.
Another early adopter of RNA and Defense Center 3.2, AutoTrader, an online car shopping site in Atlanta, says the value of IDS is in combining event information with knowledge about network resources. “RNA knows all about my servers, IDS knows what’s going across the wire, and correlating the two together to understand the impact is the real value,” says Matt Keogler, AutoTrader’s senior security and network engineer.
Defense Center 3.2 determines immediately if machines on the network are vulnerable – or potentially vulnerable – to an attack. It also cites if the event is relevant but the target is not vulnerable, plus classifications of notifications that can be color-coded with graphics.
Sourcefire’s CEO Wayne Jackson called these “impact flags,” adding, “It’s the notion of trying to make better sense of IDS output by correlating scanning data.”
Sourcefire has about 400 corporate customers that use the commercial version of Snort and an estimated 100,000 Snort freeware users, as evident from online downloads, Jackson says.
In the past, Sourcefire’s founder and CTO Marty Roesch has expressed ambivalence about whether Sourcefire will ever offer a commercial intrusion-prevention system (IPS) that blocks attacks. But Jackson says there should be no doubt about it. He says RNA working with Defense Center paves the way for Sourcefire to offer a commercial IPS by year-end.
Sourcefire Defense Center starts at $17,000.




