Next-GenerationIntrusion Detection & PreventionManuel Minzoni, Brand ManagerITWAY VAD
AgendaYour Security ChallengesAbout SourcefireA New ApproachHow It WorksProducts & ServicesQuestions & Next Steps
Your Security Challenges
Let’s Solve ProblemsWhat are your challenges?How are they being addressed today?What’s your ideal solution?What is your timeframe?
Today’s Reality“Begin the transformation to context-aware and adaptive security infrastructure now as you replace legacy static security infrastructure.”Neil MacDonaldVP & Gartner FellowSource: Gartner, Inc., “The Future of Information Security is Context Aware and Adaptive,” May 14, 2010 Dynamic ThreatsOrganized attackersSophisticated threatsMultiple attack vectorsStatic DefensesIneffective defensesBlack box limits flexibilitySet-and-forget doesn’t work
Company Overview & Performance
Annual Revenue GrowthFYE: December 31($MM, GAAP)$103.5CAGR 77%$75.7$55.9$44.9$32.9$16.7$9.5$1.9
Sourcefire Worldwide LocationsEducation &Professional ServicesLivonia, MIEMEA HQWokingham, UKJapan SalesTokyo, JapanCentral Europe SalesFrankfurt, GermanyWorldwide HQColumbia, MDAmericas Sales Vienna, VASouthern Europe SalesParis, FranceAsia Pacific HQSingaporeSouth American Sales Sao Paulo, BrazilANZ SalesSydney, Australia
Firemen Principles
About SourcefireTo be the leading provider of intelligent cybersecurity solutions for the enterprise.Mission:Founded in 2001 by Snort Creator, Martin Roesch, CTOHeadquarters: Columbia, MDFocus on enterprise and government customersGlobal Security Alliance ecosystemNASDAQ: FIRE
Powered by Snort®Global standard for Intrusion Detection and Prevention
World’s largest threat  response community
Interoperable with other security products
Owned and controlled by Sourcefire, Inc.
www.snort.orgBacked by the VRT™150+Private &PublicThreatFeedsSnort & ClamAVCommunityInsight20,000MalwareSamplesper DayAdvanced Microsoft & Industry DisclosureSourcefireVulnerability Research Team (VRT) Research & Analysis“Best-in-Class”Threat Protection
Competitor Landscape
Gartner 2010 IPS Magic QuadrantFACT:Sourcefire has been a leader in Gartner’s IPS Magic Quadrant since 2006. The Magic Quadrant is copyrighted 6 December 2010 by Gartner, Inc. and is reused with permission. The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner's analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the "Leaders" quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Sourcefire Insights Versus McAfee“[McAfee] isn’t considered widely by enterprises and channel partners as a strong network network security provider.”  - Gartner 2010 IPS MQ Report[ability to execute]Larger channel & support infrastructureKey Sourcefire advantages:✔ Open detection engine & rules✔ Real-time impact assessment ✔ Automated IPS tuning
✔ Broad third-party integration
 ✔ Virtual IPS offerings[completeness of vision]Broader product portfolio
NSS Labs Group IPS TestBlock Rate ComparisonSource:  Graphic used with permission by NSS Labs. “Network Intrusion Prevention Systems Comparative Test Results,” December 2009.
NSS Labs Group IPS TestResistance to EvasionJuniper missed 60% of evasionsTippingPoint missed 80% of evasionsCisco missed 100% of evasionsSource:  Graphic used with permission by NSS Labs. “Network Intrusion Prevention Systems Comparative Test Results,” December 2009.
About the TestPublished December 201011 vendors evaluated1,179 live exploits75 anti-evasion test casesNo cost to vendors to participateSourcefire Test ResultsRecommend ratingBest overall detectionBest vulnerability coverageBest vendor-stated vs. actual performanceNo evasionsSecond-Annual NSS Labs IPS Group Test
Best Overall DetectionSecond Straight Year!98%97%95%94%93%91%85%83%79%63%43%Graphic by Sourcefire, Inc. Source data from NSS Labs “Network IPS 2010 Comparative Test Results.”
Best Vulnerability CoverageSecond Straight Year!SourcefireVendor 2Vendor 3Vendor 4Vendor 5Vendor 4Vendor 6Vendor 7Vendor 8Vendor 9Vendor 6Vendor 10Vendor 10Vendor 11
Best Vendor-Stated vs. Actual PerformanceSecond Straight Year!Sourcefire’s 2G IPS achieved 3.2G for 161% of vendor-stated performance100% Performance BaselineMost IPS products achieved well below vendor-stated performance claimsGraphic by Sourcefire, Inc. Computations derived from NSS Labs “Network IPS 2010 Comparative Test Results.”
Anti-Evasion TestingSourcefireVendor 2Vendor 3Vendor 4Vendor 5Vendor 6Vendor 7Vendor 9Vendor 10Vendor 11Vendor 8
IPS Solutions
Unique Solutions for Unique MarketsNGIPSSecurity Specialists Feature RichIPSSourcefire IPS PortfolioNetwork GeneralistsSimplicityIPSx
Sourcefire IPS Solutions Portfolio
Target Markets
Solution Ingredients+=IPSx SolutionIPSx SensorsDC750x+=IPS SolutionDefense Center3D Sensors+Network   Application   Behavior   Identity =NGIPS Solution3D SensorsDefense CenterAwareness Bundle
Appliances / 3D8000 Series
Introducing…Sourcefire 3D8000 Series“Speed Meets Flexibility”
3D8000 Series Performance
3D8000 Series Product LineAll 3D8000 Series chassis support lights out management, solid state drives, redundant power, and an LCD interface.
ModularChoose number and type of portsLower Entry PricesExpandableAdd ports as neededScalableAdd processing power as neededHardware Platform Sets New Standard for Security Appliances
SSL Appliance
SSL Blind SpotsNetwork and security appliances are blind to the contents of SSL-encrypted communications
Common Control/ManagementDecrypted (Inspected)Non-SSLSSLSession 2Session 1Deployment Mode:Inbound SSL InspectionThe Security StackIPS/IDS/DLP/Forensics/SIEMTransparent SSL ProxyWeb Servers(SSL Servers)Web Browser(SSL Client)Internet/WAN
Common Control/ManagementDecrypted (Inspected)Non-SSLSSLSession 2SSL ProxySession 1Deployment Mode:Outbound SSL InspectionThe Security StackIPS/IDS/DLP/Forensics/SIEMTransparent SSL ProxyWeb Browser(SSL Client)Web Servers(SSL Servers)Internet/WANSSL Server
SSL Appliance Features and Benefits
A New Approach
Traditional IPS vs. Next-Generation IPSTraditional IPSNext-Generation IPS Closed& BlindOpen & CustomizableArchitectureNone orLimitedVisibility & IntelligenceAwarenessHuman IntensiveSelf Tuning &PrecisionAutomation
Next-Gen IPS – Open Architecture  Powerful Engine & RulesAdaptableCustom fit to networkComprehensive coverageOpen CommunityInformation sharingShared protectionProtection Against Advanced Persistent Threats (APT)
Next-Gen IPS – The Power of AwarenessNetworkKnow what’s there, what’s vulnerable, and what’s under attackApplicationIdentify change and enforce policy on hundreds of applicationsBehaviorDetect anomalies in configuration, connections and data flowIdentityKnow who is doing what, with what, and where
Next-Gen IPS – Highly Automated OperationCorrelate Attacks toTargets
Intelligent EventReduction
Intelligent Tuning
Operational Efficiency

Sourcefire Webinar - NEW GENERATION IPS

  • 1.
    Next-GenerationIntrusion Detection &PreventionManuel Minzoni, Brand ManagerITWAY VAD
  • 2.
    AgendaYour Security ChallengesAboutSourcefireA New ApproachHow It WorksProducts & ServicesQuestions & Next Steps
  • 3.
  • 4.
    Let’s Solve ProblemsWhatare your challenges?How are they being addressed today?What’s your ideal solution?What is your timeframe?
  • 5.
    Today’s Reality“Begin thetransformation to context-aware and adaptive security infrastructure now as you replace legacy static security infrastructure.”Neil MacDonaldVP & Gartner FellowSource: Gartner, Inc., “The Future of Information Security is Context Aware and Adaptive,” May 14, 2010 Dynamic ThreatsOrganized attackersSophisticated threatsMultiple attack vectorsStatic DefensesIneffective defensesBlack box limits flexibilitySet-and-forget doesn’t work
  • 6.
  • 7.
    Annual Revenue GrowthFYE:December 31($MM, GAAP)$103.5CAGR 77%$75.7$55.9$44.9$32.9$16.7$9.5$1.9
  • 8.
    Sourcefire Worldwide LocationsEducation&Professional ServicesLivonia, MIEMEA HQWokingham, UKJapan SalesTokyo, JapanCentral Europe SalesFrankfurt, GermanyWorldwide HQColumbia, MDAmericas Sales Vienna, VASouthern Europe SalesParis, FranceAsia Pacific HQSingaporeSouth American Sales Sao Paulo, BrazilANZ SalesSydney, Australia
  • 9.
  • 10.
    About SourcefireTo bethe leading provider of intelligent cybersecurity solutions for the enterprise.Mission:Founded in 2001 by Snort Creator, Martin Roesch, CTOHeadquarters: Columbia, MDFocus on enterprise and government customersGlobal Security Alliance ecosystemNASDAQ: FIRE
  • 11.
    Powered by Snort®Globalstandard for Intrusion Detection and Prevention
  • 12.
    World’s largest threat response community
  • 13.
    Interoperable with othersecurity products
  • 14.
    Owned and controlledby Sourcefire, Inc.
  • 15.
    www.snort.orgBacked by theVRT™150+Private &PublicThreatFeedsSnort & ClamAVCommunityInsight20,000MalwareSamplesper DayAdvanced Microsoft & Industry DisclosureSourcefireVulnerability Research Team (VRT) Research & Analysis“Best-in-Class”Threat Protection
  • 16.
  • 17.
    Gartner 2010 IPSMagic QuadrantFACT:Sourcefire has been a leader in Gartner’s IPS Magic Quadrant since 2006. The Magic Quadrant is copyrighted 6 December 2010 by Gartner, Inc. and is reused with permission. The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner's analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the "Leaders" quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
  • 18.
    Sourcefire Insights VersusMcAfee“[McAfee] isn’t considered widely by enterprises and channel partners as a strong network network security provider.” - Gartner 2010 IPS MQ Report[ability to execute]Larger channel & support infrastructureKey Sourcefire advantages:✔ Open detection engine & rules✔ Real-time impact assessment ✔ Automated IPS tuning
  • 19.
  • 20.
    ✔ VirtualIPS offerings[completeness of vision]Broader product portfolio
  • 21.
    NSS Labs GroupIPS TestBlock Rate ComparisonSource: Graphic used with permission by NSS Labs. “Network Intrusion Prevention Systems Comparative Test Results,” December 2009.
  • 22.
    NSS Labs GroupIPS TestResistance to EvasionJuniper missed 60% of evasionsTippingPoint missed 80% of evasionsCisco missed 100% of evasionsSource: Graphic used with permission by NSS Labs. “Network Intrusion Prevention Systems Comparative Test Results,” December 2009.
  • 23.
    About the TestPublishedDecember 201011 vendors evaluated1,179 live exploits75 anti-evasion test casesNo cost to vendors to participateSourcefire Test ResultsRecommend ratingBest overall detectionBest vulnerability coverageBest vendor-stated vs. actual performanceNo evasionsSecond-Annual NSS Labs IPS Group Test
  • 24.
    Best Overall DetectionSecondStraight Year!98%97%95%94%93%91%85%83%79%63%43%Graphic by Sourcefire, Inc. Source data from NSS Labs “Network IPS 2010 Comparative Test Results.”
  • 25.
    Best Vulnerability CoverageSecondStraight Year!SourcefireVendor 2Vendor 3Vendor 4Vendor 5Vendor 4Vendor 6Vendor 7Vendor 8Vendor 9Vendor 6Vendor 10Vendor 10Vendor 11
  • 26.
    Best Vendor-Stated vs.Actual PerformanceSecond Straight Year!Sourcefire’s 2G IPS achieved 3.2G for 161% of vendor-stated performance100% Performance BaselineMost IPS products achieved well below vendor-stated performance claimsGraphic by Sourcefire, Inc. Computations derived from NSS Labs “Network IPS 2010 Comparative Test Results.”
  • 27.
    Anti-Evasion TestingSourcefireVendor 2Vendor3Vendor 4Vendor 5Vendor 6Vendor 7Vendor 9Vendor 10Vendor 11Vendor 8
  • 28.
  • 29.
    Unique Solutions forUnique MarketsNGIPSSecurity Specialists Feature RichIPSSourcefire IPS PortfolioNetwork GeneralistsSimplicityIPSx
  • 30.
  • 31.
  • 32.
    Solution Ingredients+=IPSx SolutionIPSxSensorsDC750x+=IPS SolutionDefense Center3D Sensors+Network Application Behavior Identity =NGIPS Solution3D SensorsDefense CenterAwareness Bundle
  • 33.
  • 34.
  • 35.
  • 36.
    3D8000 Series ProductLineAll 3D8000 Series chassis support lights out management, solid state drives, redundant power, and an LCD interface.
  • 37.
    ModularChoose number andtype of portsLower Entry PricesExpandableAdd ports as neededScalableAdd processing power as neededHardware Platform Sets New Standard for Security Appliances
  • 38.
  • 39.
    SSL Blind SpotsNetworkand security appliances are blind to the contents of SSL-encrypted communications
  • 40.
    Common Control/ManagementDecrypted (Inspected)Non-SSLSSLSession2Session 1Deployment Mode:Inbound SSL InspectionThe Security StackIPS/IDS/DLP/Forensics/SIEMTransparent SSL ProxyWeb Servers(SSL Servers)Web Browser(SSL Client)Internet/WAN
  • 41.
    Common Control/ManagementDecrypted (Inspected)Non-SSLSSLSession2SSL ProxySession 1Deployment Mode:Outbound SSL InspectionThe Security StackIPS/IDS/DLP/Forensics/SIEMTransparent SSL ProxyWeb Browser(SSL Client)Web Servers(SSL Servers)Internet/WANSSL Server
  • 42.
  • 43.
  • 44.
    Traditional IPS vs.Next-Generation IPSTraditional IPSNext-Generation IPS Closed& BlindOpen & CustomizableArchitectureNone orLimitedVisibility & IntelligenceAwarenessHuman IntensiveSelf Tuning &PrecisionAutomation
  • 45.
    Next-Gen IPS –Open Architecture Powerful Engine & RulesAdaptableCustom fit to networkComprehensive coverageOpen CommunityInformation sharingShared protectionProtection Against Advanced Persistent Threats (APT)
  • 46.
    Next-Gen IPS –The Power of AwarenessNetworkKnow what’s there, what’s vulnerable, and what’s under attackApplicationIdentify change and enforce policy on hundreds of applicationsBehaviorDetect anomalies in configuration, connections and data flowIdentityKnow who is doing what, with what, and where
  • 47.
    Next-Gen IPS –Highly Automated OperationCorrelate Attacks toTargets
  • 48.
  • 49.
  • 50.
  • 51.
    Custom Fit SecurityReal Time, All the Time!
  • 52.
  • 53.
    Intelligent Correlation tothe TargetBlockedEventLogged3D SENSORAttack Is Correlated to TargetsDEFENSE CENTER3D SENSORLINUXSERVERLinux server not vulnerableWINDOWSSERVERAttackBlockedWindows server vulnerable3D SENSOR3D SENSORLatest Windows attack targets Microsoft Windows Server and Linux Server. Attacks are correlated to targets. High-priority event generated for Windows Server target.
  • 54.
    Abnormal Behavior Logged&Alerts Triggered3D SENSORDEFENSE CENTER3D SENSORITRemediatesHosts3D SENSOR3D SENSORHostsCompromisedAbnormal Behavior DetectedNew rogue host connects internally. Sourcefire detects new host and abnormal server behavior. Defense Center triggers alerts for IT to remediate.New Asset DetectedIntelligent Anomaly Detection
  • 55.
    Compliance Event Logged& User Identified3D SENSORDEFENSE CENTER3D SENSORIT & HRContact User3D SENSOR3D SENSORP2P App TriggersWhitelist ViolationIntelligent Application ViolationSecurity team uses compliance whitelists to detect IT policy violations. Host detected using Skype. User identified and then contacted by IT and HR.
  • 56.
  • 57.
  • 58.
    Next-Generation IPSAwareness TechnologiesNetworks Apps Behavior UsersDefense CenterManagement ConsoleIntrusion PreventionSSL InspectionVirtualization
  • 59.
    Virtual Appliances forVMware & XenSourcefire Virtual 3D Sensor™Identical IPS Sensor functionalityAvailable throughputs: 5, 45, 100, 250 & 500 MbpsSourcefire Virtual Defense Center Management ConsoleIdentical Defense Center functionality, except no Master Defense Center (MDC) modeManages both physical and virtual IPS 3D Sensors
  • 60.
    Sourcefire’s “Secret Sauce”Passivenetwork intelligenceFuels powerful IPS automation:Impact FlagsAutomated IPS TuningCompliance Rules & White ListsNetwork Behavior AnalysisDetects hundreds of operating systems and applicationsWhat is RNA?
  • 61.
    Real-Time User Awareness(RUA)“Mapping a username to an IP address was taking us away from a backlog of other important tasks. What used to take up to an hour now takes just a second or two.”Tamara Fisher,AutoTrader.comRUA gives “personality” to security and compliance events!Clicking on a username reveals full name, telephone number, email, and departmentResolve security events more quickly when time is of the essenceIntegrated into all Sourcefire 3D Sensors
  • 62.
    Sample Sourcefire DetectionHundredsof Apps, OS’s & Devices!Operating SystemsApplicationsNetwork InfrastructureConsumer
  • 63.
    Sourcefire Appliance ProductLinesVirtual AppliancesSourcefire Defense Center®DC10003D9900 10 GbpsDC30003D65004 GbpsDC5003D45002 Gbps3D35001 Gbps3D2500 500 MbpsSourcefire 3D®Sensor 3D2100 250 MbpsPERFORMANCE3D2000 100 Mbps3D100045 Mbps3D5005 MbpsSourcefire SSL Appliance
  • 64.
    Physical Appliances ProductLineDefense Centers3D Sensors
  • 65.
    3D System 4.10HighlightsExpanded Application & User AwarenessDetect Facebook, Blackberry, Hotmail & moreNmap update detects 2,500+ operating systemsEncrypted RUA communicationsEnhanced Deployment & OperationInline IPS test modeSupport for auth. SMTP gateways & web proxiesImproved Third-Party IntegrationDirect database access for third-party reportingSupport for SNMP pollingSupport for new Crossbeam productsImproved Performance & UsabilityImproved GUI performanceTrack reviewed events by userSimpler installation of customer SSL certificatesRefer to “What’s New in 3D System 4.10” document for more information
  • 66.
  • 67.
    Comprehensive EcosystemSIEM /Log ManagementNetwork InfrastructureConfiguration ManagementIncident ManagementSystems ManagementVulnerability Management
  • 68.
    Sourcefire ServicesCustomer Support24x7phone, email, and web support
  • 69.
    Advanced hardware replacementTraining& CertificationPublic and on-site training
  • 70.
    Sourcefire & SnortcertificationsProfessional ServicesAssistance with installation and optimization
  • 71.
    Knowledge transfer andbest practices“I can’t say enough about the guys from Support. The phone gets picked up the moment I call. They stick with an issue diligently and make sure I get what I need. No other company has given me that level of service.”Robert WagnerSenior Security Architect
  • 72.
    Why Sourcefire? Poweredby SnortDriven by AwarenessBest-in-Class DetectionOpen ArchitectureHighly AutomatedStop Doing Things the “Old Way!”Try the “Next Generation” in Intrusion Detection & Prevention.
  • 73.

Editor's Notes

  • #2 Customize your name, title, and prospects logo.
  • #3 Tailor your agenda for the meeting.This is the structure of the presentation.
  • #4 Let’s discuss the challenges you are facing.
  • #5 Start the conversation focusing on the prospect. What is the purpose of the meeting? If there are new people in the room this is a great time to white board all the issues from everyone and clearly identify future talking points in the presentation.
  • #6 The network security model is broken!The attackers are well financed, motivated, and sophisticated in their methods of breaking into networks.How do you defend a network that is in a constant state of flux?Your set-and-forget IPS is not going to stop the attackers.We need to come up with a different solution to effectively protect our information…
  • #13 According to Gartner’s lead IPS analyst, Greg Young….Detection is the most important feature of an IPS system.Sourcefire maintains a leadership position in providing the best detection through our Vulnerability Research Team (VRT).We have access to exploit and threat data from:The Snort ecosystem – Engineers submitting PCAPs and rules to VRTThe ClamAV project – where we receive over 20,000 malware samples per dayMicrosoft’s MAPP program – early disclosure of vulnerabilitiesand numerous private threat feedsOur VRT team reverse engineers exploits, analyzes vulnerability data, and creates rapid IPS rules to help you properly defend your dynamic network.
  • #31  Three models being launched – 10, 20, 40 gigabits of throughput Third party validation by NSS over the past couple of weeks Real-world performance numbers magnitude higher than competition (can use example of other competitors claiming 15G and only testing 1.9G Design of the platform is stackable, giving us capability to support 80G of throughput with over 50G of real-world inspection Stacking is supported  1U to 1U and 2U to 2U Software updates expected later in 2011 will allow stacking of up to four 2U chassis for 80 Gbps / 56 Gbps NSS tested. These performance numbers for the 8U stacked configuration have been verified, although the software does not yet officially support that configuration.
  • #32  Recap of the new models being offered starting first week of May Reduction of slots on 8260 is due to stacking with additional 2U chassis All support Lights out management (serial console over Ethernet), solid state drives, hot-swappable redundant power for reliability and LCD for ease of deployment
  • #33 Need to discuss types of network modules supported, including 40G later in 2011
  • #39 We mentioned that the security model was broken. We need new, innovative ways to defend our information that resides on our networks!Let’s explore the new approach.
  • #40 Let me introduce you to the key capabilities required in the Next-Generation IPS solution.In doing so, we’ll compare the NGIPS to traditional IPS systems that you can acquire today.ArchitectureMost traditional IPS systems are a black box, with static rules/signatures.The architectures are closed, and the ability to precisely tailor the detection is often limited.One size fits all is not a workable architecture given today's advanced threats.The Next-Gen IPS should have an open architecture – how the product performs is exposed to the user and the ability to customize the detection and prevention to fit your needs is never compromised by a “black box” architecture.AwarenessTraditional IPSes are comprised of detection engines with a given set of rules….will do simple pattern matching to detect intrusions. Their intelligence is extremely limited.A Next-Generation IPS must be smart. Not only should the IPS detect a variety of attack methods, but it should also correlate attacks to the targets on your network to ensure precise detection, while minimizing false alarms or blocking good traffic.AutomationTraditional IPSes require a significant number of resources to “tune” the IPS to your network and to analyze the volume of alerts generated by the system. Lack of precision has become so problematic that most customers give up and use the vendor’s default rules and hope the system will stop the attacks. While the vendors can’t possibly enable rules that work out of the box in a comprehensive way to provide appropriate protection.The Next-Generation IPS is smart enough to automatically configure itself based on the knowledge of what is running on the network. As your network configuration changes, it adapts the rules to precisely protect your network….no more guess work, no more extra effort.The intelligence also reduces false alarms by over 90%.With a Next-Generation IPS you can effectively defend your network while maintaining operational costs from spiraling out of control, and/or sacrificing security.
  • #42 The Next-Generation IPS is contextually aware and adaptive.In Sourcefire’s system, we infuse the IPS system with deep intelligence about the users, their usage, behavior, and data:The system then automatically customizes the detection and makes prevention recommendations based on what’s running on your network.The system monitors the applications running on your system, so that you can flexibly enforce the appropriate detection and compliance.The system enables you to detect compromise of your key systems and assets by constantly monitoring change of behavior and configuration.And finally, give you the ability to associate all detection to a specific user name and contact info. Sourcefire brings you a super-intelligent IPS system that is fully integrated and always on 24/7.
  • #43 The results of leveraging a Next-Generation IPS are:Precision – correlating attacks to the targeted network device has given our customers over 90% alarm reduction.Self-configuring detection. The Next-Gen IPS system automatically configures the detection to specifically what's running on your network. As your network changes…so does your detection.The system allows you to prevent intrusions without an army of engineers and gives you the confidence to know that an intelligent system is helping you defend your network.
  • #44 Let’s look at the system in action.
  • #45 This scenario shows us an external Microsoft attack targeting multiple systems.The system correlates the attack to the target and blocks the attack from impacting the Windows server (or potentially vulnerable system).
  • #46 The following scenario shows:A new device shows up on the LAN and is detected.The device attacks internal servers, and the system detects change in behavior on the compromised systems.The system alerts the change and directs the IT team to remediate the server and clients affected by the attack.
  • #47 In this last scenario we illustrate application violation.A user starts using SKYPE, and the system detects the unauthorized application usage.Alerts are logged and escalated to IT and HR to remediate the offending use of SKYPE.Sourcefire’s Next-Generation IPS provides a rich set of prevention functionality in a fully integrated system.
  • #49 Let’s look at the products that make up our Next-Generation IPS.
  • #50 The first component of the solution is our IPS sensors that are delivered as appliances ranging from 5Mbps to 20Gbps.Our awareness technologies are delivered as software. You can load them on our appliances or on your preferred device.Our system can also be deployed on a virtualized platform, running VMware or XEN.We offer a separate SSL inspection appliance to perform IDS/IPS on encrypted traffic.And finally we have our Defense Center (DC) that provides:Command and Control of our sensors in your networkEvent management and correlationThe DC can be set up in a HA mode and layered into a Master DC for enterprise scale.All DCs have built-in data management functions to manage 100s of millions of events.
  • #59 Our philosophy is to have an open architecture and open ecosystem.Our Next-Generation IPS is designed with open APIs to interact with all of the best-of-breed technologies that you have already deployed in the multiple areas.Openness provides you with realistic, deployment flexibility.
  • #61 Sourcefire has been leading the IDS/IPS market in innovation….Starting with the industry’s de-facto standard engine – SNORTThe most powerful, flexible detectionAn intelligence-driven system that provides robust security while controlling costs associated with the deployment.If you’re serious about defending against today’s sophisticated attacks, a Next-Generation IPS is a must.Thank you for your time…..are there any questions?