White Papers

Residing at the core of the threat prevention capabilities of Sourcefire Intrusion Sensors, Snort® threat detection and prevention components work together to reassemble traffic, prevent evasions, detect threats, and output information about the threats without creating false positives or missing legitimate threats.

Many network security vendors boast about their response times to the release of vulnerabilities—for instance, the monthly “Microsoft Tuesday”—when Microsoft announces many vulnerabilities and releases patches to end users. The Sourcefire Vulnerability Research Team™ (VRT) is the only network security research group that provides protection that verifiably defends against all possible attacks, before particular methods of attack are known, and without creating false positives or false negatives. The white paper details how Snort’s open rules give customers advantages they cannot get from other network security products.

By incorporating real-time network and user intelligence, an IPS can adapt to dynamically changing networks and threats. This helps to automate many of the cumbersome tasks that consume human effort, including IPS tuning, impact assessment and remediation helping to improve security, reduce risk, and lower total cost of ownership (TCO). Read how to derive more value from an IPS using measurements developed by the SANS Analysts team.

Next-Generation IPS (NGIPS) offers a logical and essential progression of capabilities needed to protect networks from emerging threats. Pioneered by Sourcefire, and now endorsed by Gartner, the NGIPS builds on typical IPS solutions by providing contextual awareness—about network activity, systems and applications, people, and more—to promptly assess threats, ensure a consistent and appropriate response, and reduce an organization’s security expenditures.