Sourcefire debuts anti-malware software FireAMP for enterprise
- 24 January, 2012 07:40
- Comments
Sourcefire today announced anti-malware software for Windows-based devices that combines signature- and behavior-based detection methods to identify malicious code trying to invade the enterprise network, tracking it down through cloud-based analysis.
The lightweight Windows-based software, called FireAMP, can identify malware and block it, says Alfred Huger, vice president of development at Sourcefire's cloud technology group. Once a specific threat is identified, which involves analyzing it on the fly through the FireAMP cloud-based infrastructure, another step can be taken to immediately figure out if that same malware has struck other enterprise computers.
SECURITY ROUNDUP: Anonymous attacks DOJ, RIAA sites; Israeli-Palestinian cyberconflict escalates
Huger acknowledges that the 7MB FireAMP agent software will detect and block a wide range of malware through both signature and behavior-based methods, but it won't recognize every threat when it first hits the enterprise network. FireAMP represents the development of the anti-malware software Sourcefire acquired in its acquisition of startup Immunet a year ago.
The basic idea behind FireAMP is that it can make the job of tracking down any infected computers fairly simple because FireAMP works by "capturing all endpoint data and putting it in the cloud," explains Huger. "We keep an image of all file behavior in your computers in the cloud. We know when a file gets put there." Therefore, FireAMP would be able to tell when malware, in the form of a malicious file, made its way into someone's computer, and there would be a way to trace an originating point.
FireAmp's continuous tracking of file activity means that if there's an infection outbreak, once the malware specimen is identified, it's going to be possible to give security managers immediate feedback on when and how that infection spread to specific enterprise computers. "Our goal is which systems need remediation or which need to re-image," says Huger. "When there is a system compromised, this is an efficient way to address it."
"The average number of infections is 10," says Huger about how virus outbreaks typically occur, noting that staff in information-technology departments find one of their biggest struggles is tracking down infected computers that fly in under the radar of traditional antivirus software.
Huger also notes that FireAMP is "not competing with antivirus vendors," but is trying to be complementary to antivirus software. FireAMP's approach is said to be closer to that of FireEye, which blocks based on behavior, but here too, Huger compared the two approaches as somewhat complementary.
Sourcefire's FireAMP software at present is only available for Windows, but the security firm is considering something similar for Android later this year. In addition, FireAMP today works with its own management console, but in the future Sourcefire anticipates further integration into some of its other products, such as Defense Center. FireAMP, which costs about $30 seat annually, is available now.
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security.
Read more about wide area network in Network World's Wide Area Network section.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Sourcefire shipping its first two app-aware, next-gen firewalls
- Windows Research Center - Network World
- New Facebook attack targets e-cash users
- Security roundup: Anonymous attacks DOJ, RIAA sites; Israeli-Palestinian cyberconflict escalates
- Sourcefire acquires Immunet for cloud-based anti-malware
- Security Research Center - Network World
- FireEye malware blockers don't rely on signatures
- 8 useful Google Android resources
- LAN & WAN Research Center - Network World
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
EMC 15-Minute Guide to Smarter Backup Transform your future
Backup and recovery has become fundamental part of business and an essential element of information management. Information is useless to customers, employees, or business partners can't access it when it is needed. Availability and integrity of information, of the lack of, can directly impact revenues and profits - as well as company reputations. Read more. -
A buyer’s guide to application lifecycle management (ALM) solutions
This buyer's guide describes the key criteria for application lifecycle management (ALM) solutions for today's high-performance teams. It includes key considerations for enhancing your single- or multi-vendor ALM environment. -
IDC Case Study - EMC IT Increasing Efficiency, Reducing Costs, and Optimising IT with Data Deduplication
This IDC Buyers Case Study: Explores the benefits EMC realised from the use of a range of EMC's own backup and recovery solutions that leverage deduplication technology; Identifies the unique backup challenges for different computing environments and how data deduplication can address these environments; Highlight EMC's legacy backup environment and the changes EMC made as part of a transformation process to increase efficiency, reduce cost and optimise IT - as part of its journey to the private cloud.
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies








Comments
Post new comment