2005-03-19

Meeting with Sourcefire

Myself and four co-workers met with Tony Leona and a systems engineer named Rich from Sourcefire today at their satellite office in Tyson's Corner. First, I couldn't work on the 14th floor of a building like that because I would be staring out the window all day. What a view!

Second, you guys in the corporate world have it made. Nice and clean buildings with little deli's in the building. A lot of times the federal government is like, well, Uncle Buck. You don't like his accomodations but hey, he pays the bills.

Anyway, the purpose of our visit was to learn more about Sourcefire's Defense Center appliance and what it provides with data feeds from the RNA and IDS appliances. With the infatuation with ArcSight at this time, there didn't seem to be alot to gain from adding this device. However, the impact field could be useful to identify holes in the perimeter if and only if the RNA is able to "see" nodes correctly. We didn't know the RNA is sold on a "by node" basis, meaning you purchase a license for say, 10,000 nodes discovered on your network. $mart, very $mart. An added bonus is the Visualizer 3-D analyzer which is free for as many workstations as you want.

I was more interested in hearing about the IPS capability of the Sourcefire IDS 1000, which we already have (just one though for lab testing). To my suprise, the appliance is IPS capable and needs only a $300 fail open card. We will definitely pursue this and test the 1000's ability to mitigate.

With ISS RealSecure failing from grace rapidly, I think the Sourcefire Defense Center (DC) package provides an excellent alternative. A key feature is the DC's ability to push out policies and rules to Sourcefire sensors. Obviously, Sourcefire only offers the convienience of pushing updates to Sourcefire sensors, but I can't blame them for basic business tactics. The DC also allows SSL connections from any host added to its ACL. This is similar to a Niksun NetDetector, which I've had experience with. I'm sure other devices offer this, but I'm not familiar with them (remember I'm new to this field!).

You can read more about Sourcefire products and case studies by downloading some white papers from their Resource page.

NTR

2005-03-16

Richard Bejtlich

I had the distinct honor of meeting Mr. Richard Bejtlich on Monday for lunch. I first heard about Richard from Keith Jones, author of "The Anti-Hacker Toolkit", in a Foundstone course Keith was teaching. Keith told me I should contact Richard to discuss Snort and open source tools for network security monitoring. I never was able to get in touch with Keith after the class was over to get Richard's contact information, but it worked out in the end.

Richard gave a presentation at the February ISSA-NOVA meeting on network security monitoring. I contacted him after the meeting to see if we could get together, not thinking he would actually be available for a peon like me. :) But, I had to ask because the worst he could say was no. To my delight he wanted to meet for lunch, although it did take almost a month for us to set up a date and time.

Richard is very personable and exudes intelligence. I felt dumb just sitting at the same table with him. He brought a co-worker, I guess to make sure I wasn't some pyscho or stalker. We talked about my company and the customer we are on contract with. I talked about the frustration my shop has with the customer's security policies. We talked about network appliances such as the Niksun Net Detector and Sand Storm Net Entercept. Richard asked about providing some training for my group and I think it would be great. I am going to talk with my manager about scheduling some dates if possible. I know we would have to set up two dates to get everyone in.

To give Richard's book a plug, it is called "The Tao of Network Security Montioring, Beyond Intrusion Detection". It is an excellent resource for any information security professional, new or experienced. Richard also has a new book coming out later this year with Keith Jones called "Real Digital Forensics", which will be interactive and allows readers to actually work out some digital forensic cases. I can't wait for that!