|
Sourcefire Intrusion Agents
Combining
Open Source Roots with Proprietary Innovation to
offer the most effective real-time network defence
solutions on the planet
The Sourcefire's 3D System offers a fully integrated
real-time network defence infrastructure that
combines state-of-the-art monitoring, perimeter
defence, system management and real-time network
awareness. Sourcefire's 3D System allows users to
leverage essential security data more effectively,
reducing security costs and improving the
effectiveness of the security administrators. Now,
with the introduction of the Sourcefire Intrusion
Agent, organisations are finally able to gain many
of the benefits available with the Sourcefire 3D
System while protecting their investment in their
open source Snort deployments.
Beyond Basic Detection

The Sourcefire Intrusion Agent allows open source
Snort users to do more than just detect intrusions;
it enables a single Sourcefire Defense Center to
aggregate event information from one or more Snort
sensors alongside data from Sourcefire Intrusion
Sensors and Sourcefire RNA sensors. This allows:
| |
▪ |
Sophisticated
data analysis |
| |
▪ |
Comprehensive
reporting |
| |
▪ |
Impact
assessment & prioritisation
of events |
| |
▪ |
Integration
with 3rd party tools
such as SIM products |
| |
▪ |
Real-time
response to actual attacks |
The Sourcefire Intrusion Agent transmits events
generated by open source Snort sensors to the
Sourcefire Defense Center, where it can be tightly
integrated with the network and vulnerability
information provided by Sourcefire RNA Sensors to
create a persistent, comprehensive view of the
security events on your network. This provides a
level of contextual intelligence that finally
enables Snort users to protect the real assets on
their networks instead of merely attempting to
assess the hostility of the packets traversing the
network. The Intrusion Agent enables Snort users to
easily determine:
| |
▪ |
Whether or not
an attack poses an actual threat to the
target |
| |
▪ |
If the threat
violates your security policy |
| |
▪ |
How to
properly prioritize the response to events
|
| |
▪ |
The
appropriate action to take according to the
ABCs of Defense - Alert, Block, Correct
|
System Requirements
| |
▪ |
Snort 2.0 or
higher running on Red Hat Linux versions
7.2, 8.0, and 9.0
-or-
Snort 2.0 or higher running on Solaris
versions 8.0 AND 9.0
|
| |
▪ |
Sourcefire
Defense Center v.3.1 or higher |
|
|

 |