Sourcefire Tool Promises IPS Flexibility

執筆者
Brian Prince
Brian Prince
Published: Sep 17, 2007
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Sourcefire is rolling out the latest version of Sourcefire 3D System, affording customers a new level of protection with what it calls an adaptive intrusion prevention system.

Unlike traditional IPS products, 3D System Version 4.7, announced Sept. 17, enables users to optimize the security and performance of their IPS systems based on the actual network assets they are protecting, said Sourcefire officials. The company has also released two other new products: Sourcefire RUA (Real-Time User Awareness) and Sourcefire NetFlow Analysis.

Sourcefire RUA links user identity to security and compliance events, pairing user names with host IP addresses involved in security and compliance events. Sourcefire NetFlow Analysis extends the reach of the companys Sourcefires NBA (Network Behavior Analysis) tool to corners of the network where Sourcefire Real-Time Network Awareness Sensors do not exist.

Steve Piper, director of product marketing at Sourcefire, headquartered in Columbia, Md., said the technology will allow the company to leapfrog ahead of the competition.

Click here to read about Sourcefires acquisition of ClamAV.

“Most of our IPS competitors provide a one-size-fits-all default IPS policy for use by everyone,” he said. “In contrast, Sourcefires IPS constantly adapts to customer networks, through our RNA-Recommended Rules capability, so that the IPS is always optimized with rules that are aligned with the resources being protected.”

Hence the title, Adaptive IPS technology. Organizations can tighten network security by leveraging endpoint intelligence aggregated by Sourcefire RNA, Nessus, Nmap and other endpoint intelligence tools to propose, enable or disable Snort IPS rules based on the actual assets protected on the network, Sourcefire officials said.

“For example, if a customer doesnt have any Macintosh computers on the network, then why consume IPS resources by enabling rules for Macs?” Piper asked. “But if one day a Mac suddenly appeared on the network, RNA would detect it, and then recommend Snort IPS rules to protect Macs.”

Advertisement

The Sourcefire 3D System 4.7 release, including Sourcefire RUA and Sourcefire NetFlow Analysis, is available now through Sourcefire or through Sourcefire Solutions Network channel partners, company officials said.

Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。