Sourcefire today announced its latest solutions to address critical customer needs for virtualised security — FireAMP Virtual and Virtual Next-Generation Intrusion Prevention Systems with application control. These new solutions deliver Information Superiority by providing large enterprises and government organisations the visibility and control required to address the dynamic nature of constantly changing virtual deployments and evolving threats targeting those systems.
Sourcefire’s comprehensive approach connects physical and virtual security elements, while also integrating network and application awareness with big data analytics for increased security intelligence. Continuous monitoring and threat protection ensures that users can structure appropriate network defences and respond comprehensively and systematically across the entire security infrastructure.
“Any security control that depends on detecting information of interest from the network is ineffective in the virtual switch unless the control itself resides or can see the data traffic in the virtual network,” said Eric Ahlm, Research Director at Gartner. “The challenge is that not all network security controls have visibility into the virtual network that resides in the hypervisor. This can create blind spots in security controls that are monitoring only the physical network. Attacks that happen on the virtual switch will go undetected until they happen on a physical network with security controls.”
Sourcefire Virtual Real-Time Visibility, Control and Protection
FireAMP Virtual protects VMware virtual instances from advanced malware and stops threats that bypass other security layers. The technology leverages cloud-based detection capabilities to analyse and block malware and lets enterprises create custom signatures to address newly discovered threats. It also uses Cloud Recall™ to provide continuous analysis of historical file activity to discover and remediate threats that were previously missed. Designed for VMware environments, FireAMP Virtual increases efficiency through integration with the agentless VMware vShield architecture. Customers deploying both FireAMP and FireAMP Virtual benefit from having seamless visibility and control to identify and remediate advanced malware across their entire environment.
Virtual NGIPS overcomes the lack of visibility traditional physical intrusion prevention products have over virtualised environments, with the ability to deliver application control along with a virtual management console. Sourcefire Virtual NGIPS can inspect virtual machine (VM)-to-VM communications, providing full NGIPS capabilities to protect VMware-based virtual networks. It also provides optional URL filtering to reduce the surface area of attack.
“Sourcefire’s virtual solutions are just the latest example of our commitment to protecting our customers from the most sophisticated attacks – whether they target physical, mobile or virtual systems,” said Martin Roesch, founder, CTO and interim CEO of Sourcefire. “As with physical assets, security in a virtualised setting should be about more than just stopping attacks; you also need to continually drive visibility, control and management. Sourcefire’s virtual solutions give organisations the confidence to launch or expand virtualised systems by offering insight and protection throughout their changing enterprises.”