Sourcefire Black Logo
   HOME

TheInfoList



OR:

Sourcefire, Inc was a technology company that developed
network security Network security consists of the policies, policies, processes and practices adopted to prevent, detect and monitor unauthorized access, Abuse, misuse, modification, or denial of a computer network and network-accessible resources. Network securi ...
hardware and software. The company's Firepower network security appliances were based on Snort, an
open-source Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use the source code, design documents, or content of the product. The open-source model is a decentralized sof ...
intrusion detection system An intrusion detection system (IDS; also intrusion prevention system or IPS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically rep ...
(IDS). Sourcefire was acquired by Cisco for $2.7 billion in July 2013.


Background

Sourcefire was founded in 2001 by
Martin Roesch Martin Roesch founded Sourcefire in 2001 and served as its Chief Technology Officer until the company was acquired by Cisco Systems on October 7, 2013 for $2.7B. Roesch now serves as CEO of Netography which raised $45M in Series A funding in Nov ...
, the creator of Snort. The company created a commercial version of the Snort software, the Sourcefire 3D System, which evolved into the company's Firepower line of network security products. The company's headquarters was in
Columbia, Maryland Columbia is a census-designated place in Howard County, Maryland. It is one of the principal communities of the Baltimore–Washington metropolitan area. It is a planned community consisting of 10 self-contained villages. Columbia began with ...
in the United States, with offices abroad.


Financial

The company's initial growth was funded through four separate rounds of financing raising a total of $56.5 million from venture investors such as
Sierra Ventures Sierra Ventures is an American venture capital firm based in San Mateo, California. It is focused on early stage emerging technology companies. History The firm was founded by Peter Wendell in 1982 in Menlo Park, California. Early investments i ...
,
New Enterprise Associates New Enterprise Associates (NEA) is an American-based venture capital firm. NEA focuses investment stages ranging from seed stage through growth stage across an array of industry sectors. With ~$25 billion in committed capital, NEA is one of the w ...
,
Sequoia Capital Sequoia Capital is an American venture capital firm. The firm is headquartered in Menlo Park, California, and specializes in seed stage, early stage, and growth stage investments in private companies across technology sectors. , Sequoia's total a ...
, Core Capital Partners, Inflection Point Ventures, Meritech Capital Partners, and Cross Creek Capital, L.P. In 2005, Check Point Software attempted to acquire Sourcefire for $225 million, but later withdrew its offer after it became clear US authorities would attempt to block the acquisition. The company completed an
initial public offering An initial public offering (IPO) or stock launch is a public offering in which shares of a company are sold to institutional investors and usually also to retail (individual) investors. An IPO is typically underwritten by one or more investment ...
in March 2007, raising $86.3 million. In August of the same year, Sourcefire acquired
Clam AntiVirus Clam AntiVirus (ClamAV) is a free software, cross-platform Antivirus software, antimalware toolkit able to detect many types of malware, including computer virus, viruses. It was developed for Unix and has third party versions available for IBM AI ...
. Sourcefire rejected an offer of $187 million in May 2008 from security appliance vendor
Barracuda Networks Barracuda Networks, Inc. is a company providing security, networking and storage products based on network appliances and cloud services. The company's security products include products for protection against email, web surfing, web hackers ...
, who had offered to pay US$7.50 per share, amounting to a 13% premium of their then-current stock price. Sourcefire announced its acquisition of the cloud-based antivirus firm
Immunet Immunet is a free, cloud-based, community-driven antivirus application, using the ClamAV and its own engine. The software is complementary with existing antivirus software. In January 2011 Immunet was acquired by Sourcefire. The application is f ...
in January 2011. Revenue for the fourth quarter of 2012 was $67.4 million compared to $53.2 million in the fourth quarter of 2011, an increase of 27%. Revenue for the year ending December 31, 2012 was $223.1 million compared to $165.6 million for 2011, an increase of 35%. International revenues were $74.4 million, up 77% over 2011. As of December 31, 2012, the company's cash, cash equivalents, and investments totaled $204.0 million. Sourcefire received SC Magazine's 2009 "Reader Trust" award for best intrusion detection and
intrusion prevention system An intrusion detection system (IDS; also intrusion prevention system or IPS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically rep ...
(IDS/IPS) for Snort and Network World's "2009 Best of Tests" award for the Sourcefire 3D System. The company placed in the "Leaders" Quadrant in the 2012
Gartner Gartner, Inc is a technological research and consulting firm based in Stamford, Connecticut that conducts research on technology and shares this research both through private consulting as well as executive programs and conferences. Its clients ...
Magic Quadrant Magic Quadrant (MQ) is a series of market research reports published by IT consulting firm Gartner that rely on proprietary qualitative data analysis methods to demonstrate market trends, such as direction, maturity and participants. Their anal ...
competition for intrusion detection and prevention system appliances, and received
ICSA Labs ICSA Labs (International Computer Security Association) began as NCSA (National Computer Security Association). Its mission was to increase awareness of the need for computer security and to provide education about various security products and te ...
' certification for the full line of Firepower (formerly 3D) appliances. Sourcefire was given a top "recommend" rating in 2012 for fastest and most accurate IPS detection from NSS Labs. Firepower was also ranked by NSS Labs at the top of their 2012 "Security Value Map" in security effectiveness and total cost of ownership. On July 23, 2013,
Cisco Systems Cisco Systems, Inc., commonly known as Cisco, is an American-based multinational corporation, multinational digital communications technology conglomerate (company), conglomerate corporation headquartered in San Jose, California. Cisco develo ...
announced a definitive agreement to acquire Sourcefire for $2.7 billion.


Products


Firepower

The Sourcefire Firepower line of appliances are designed to form part of a layered security defense. They can be deployed as: * Next-Generation
Intrusion Prevention System An intrusion detection system (IDS; also intrusion prevention system or IPS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically rep ...
(NGIPS), with network visibility into hosts, operating systems, applications, services, protocols, users, content, network behavior and network attacks and malware. * Next-Generation
Firewall Firewall may refer to: * Firewall (computing), a technological barrier designed to prevent unauthorized or unwanted communications between computer networks or hosts * Firewall (construction), a barrier inside a building, designed to limit the spre ...
(NGFW) with NGIPS, incorporating access and application control, threat prevention and firewall capabilities * Next-Generation Intrusion Prevention System with integrated: :* Application control :*
Malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depri ...
protection :*
URL A Uniform Resource Locator (URL), colloquially termed as a web address, is a reference to a web resource that specifies its location on a computer network and a mechanism for retrieving it. A URL is a specific type of Uniform Resource Identifie ...
filtering * Advanced Malware Protection Appliance for dedicated inline network protection against advanced malware.


Advanced Malware Protection

Sourcefire Advanced Malware Protection (AMP) offers malware analysis and protection for networks and endpoints using
big data Though used sometimes loosely partly because of a lack of formal definition, the interpretation that seems to best describe Big data is the one associated with large body of information that we could not comprehend when used only in smaller am ...
analytics to discover, understand and block advanced malware outbreaks, advanced persistent threats (APTs) and targeted attacks. AMP enables malware detection and blocking while provisioning continuous analysis and retrospective alerting, using Sourcefire's cloud security intelligence. Advanced Malware Protection can be deployed inline via a
product key A product key, also known as a software key, serial key or activation key, is a specific software-based key for a computer program. It certifies that the copy of the program is original. Product keys consist of a series of numbers and/or letters ...
on NGIPS, dedicated AMP Firepower appliance or on endpoints, virtual and mobile devices with FireAMP.


Snort

Snort is an open source network intrusion prevention and detection system utilizing a rule-driven language, which combines signature, protocol and anomaly based inspection methods. Developed in tandem with the Snort open source community, its developers claim it is the most widely deployed intrusion detection and prevention technology worldwide.


Immunet

Immunet uses the cloud
virus definition Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware. Antivirus software was originally developed to detect and remove computer viruses, hence the nam ...
s along with virus definitions from Clam AntiVirus which is an open source (
GPL The GNU General Public License (GNU GPL or simply GPL) is a series of widely used free software licenses that guarantee end users the four freedoms to run, study, share, and modify the software. The license was the first copyleft for general u ...
) anti-virus toolkit primarily used on UNIX operating systems designed for e-mail scanning on e-mail gateways. It provides a number of utilities including a
multi-threaded In computer science, a thread of execution is the smallest sequence of programmed instructions that can be managed independently by a scheduler, which is typically a part of the operating system. The implementation of threads and processes dif ...
daemon Daimon or Daemon (Ancient Greek: , "god", "godlike", "power", "fate") originally referred to a lesser deity or guiding spirit such as the daimons of ancient Greek religion and mythology and of later Hellenistic religion and philosophy. The word ...
, a
command-line interface A command-line interpreter or command-line processor uses a command-line interface (CLI) to receive commands from a user in the form of lines of text. This provides a means of setting parameters for the environment, invoking executables and pro ...
scanner and tool for automatic database updates. The core of the package is an anti-virus engine available in a form of a
shared library In computer science, a library is a collection of non-volatile resources used by computer programs, often for software development. These may include configuration data, documentation, help data, message templates, pre-written code and subr ...
. Immunet was provided in two versions, Free and Plus. As of June 10, 2014, Immunet Plus is no longer available, replaced with Immunet Free, supported by Cisco. /sup>


Sourcefire Vulnerability Research Team

The Sourcefire Vulnerability Research Team (VRT) was a group of network security engineers which discovered and assessed trends in hacking activities, intrusion attempts, and vulnerabilities. Members of the Sourcefire VRT include the
ClamAV Clam AntiVirus (ClamAV) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses. It was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, macOS, OpenVMS, ...
team as well as authors of several standard security reference books and articles. The Sourcefire VRT is also supported by the resources of the open source Snort and
ClamAV Clam AntiVirus (ClamAV) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses. It was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, macOS, OpenVMS, ...
communities. The group focuses on developing vulnerability-based rules to protect against emerging exploits for Sourcefire customers and Snort users. The VRT has provided zero-day protection for outbreaks of
malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depri ...
, including
Conficker Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008. It uses flaws in Windows OS software and dictionary attacks on administrator passw ...
, Netsky, Nachi, Blaster, Sasser,
Zotob "The Zotob worm and several variations of it, known as Rbot.cbq, SDBot.bzh and Zotob.d, infected computers at companies such as American Broadcasting Company, ABC, CNN, The Associated Press, ''The New York Times'', and Caterpillar Inc." — ''B ...
, Nachi among others. The VRT also delivers rules that provide same day protection for Microsoft Tuesday vulnerabilities, develops the official Snort rules used by the Sourcefire 3D System, develops and maintains the official rule set of Snort.org, and maintains shared object rules that are distributed for various platforms in binary format. Following the Cisco acquisition of Sourcefire in 2014, the VRT combined with Cisco's TRAC and SecApps (Security Applications) group to form Cisco Talos.


See also

*
Antivirus software Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware. Antivirus software was originally developed to detect and remove computer viruses, hence the nam ...
*
Intrusion detection system An intrusion detection system (IDS; also intrusion prevention system or IPS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically rep ...
(IDS) * Real-time adaptive security


Notes


References


External links

*
Snort homepageClamAV homepage
{{Antivirus software 2001 establishments in Maryland Computer security software companies Software companies established in 2001 American companies established in 2001 2013 mergers and acquisitions Free software companies Software companies based in Maryland Companies based in Columbia, Maryland Companies formerly listed on the Nasdaq Cisco Systems acquisitions Software companies of the United States