Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Email Email  Print  Share


Sourcefire Uses Big Data Analytics To Stop Malware

Tags: , , , , , , , , , ,

Channel: Security, WAN Security, Data Protection, Cloud Computing

Cyber security vendor Sourcefire's latest product uses big data analytics methods to search data to discover patterns in malware attacks and intervene to stop them. The release of FireAMP comes the same week that Cisco Systems released its fourth-quarter 2011 Global Threat Report detailing how pervasive the malware threat is to organizations.

Cisco reports that in the fourth quarter of 2011, enterprise users experienced an average of 339 Web malware encounters per month. For all of 2011 the average was 362 per month. Cisco also reports that 20,141 unique Web malware hosts were encountered per month in 2011, up from 14,217 in 2010.

FireAMP features five main capabilities to detect and block malware. FireCloud is a cloud-based infrastructure offering advanced detection capabilities and leveraging big data analytics to identify and score malware threats. File Trajectory tracks file movement within the enterprise, allowing organizations to identify the entry point and likely path the malware will take. File Analysis provides detailed information on malware behavior using the Sourcefire Vulnerability Research Team. Outbreak Control handles customer-defined detections that immediately block malware without requiring an update from an enterprise's security vendor. And Cloud Recall provides continuous in-the-cloud analysis of historical file activity to discover and remediate threats that were previously missed.

Sourcefire refers to "advanced malware," which it says has gotten more sophisticated in recent years. Gartner analysts Neil MacDonald and Peter Firstbrook note mass-propagated malware attacks being replaced by targeted attacks to fewer potential victims. The analysts also refer to the "dwell time" of malware attacks, in which a piece of malicious code can lie dormant on a network "for months or even years" before being activated and doing its damage.

Cisco released a study in July 2011 that documented the same trend of a decline in mass phishing attacks (a form of malware) and a rise in the volume of targeted attacks.

The new targeted variation of phishing is called spear phishing, which uses "customization methods superior to those used in mass attacks" and is likely to result in more people responding to the messages and being victimized, according to the report. The Cisco study said cyber criminals can actually make more money targeting a few victims that may have more resources to steal than targeting many people and making relatively little money per victim.

Big data is the industry term for the petabytes of data that are piling up inside of businesses and the analytics tools that are being deployed to manage that data, glean business intelligence from it, and, in the case of Sourcefire, use the technology to spot and block malware.

In December, the company started shipping its next-generation firewall built around its contextual-awareness technologies and delivering enterprise visibility, adaptive security and advanced threat protection. IDC says the main advantage of next-generation firewalls is the ability to granularly control application traffic by user. The additional visibility and awareness into behavioral patterns, hosts and operating systems help move the Sourcefire system beyond a signature-based approach.

Learn more about Data Encryption by subscribing to Network Computing Pro Reports (free, registration required).

Related Stories

Related Reading


More cloud-computing Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers