Internet.com ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














ISP Equipment

Networking

FireEye Announces Bot Prevention System

This unusual system studies bots by allowing them to infect virtual machines, then destroys the machines and the bots within them, and uses the data against the flood.

by Alex Goldman
ISP-Planet Managing Editor
[September 27, 2007]
Email a colleague

This is the year of the bot. Like an unending flood, we are told, the bots are coming. Just when you have your anti-spyware in place, your anti-spam in place, and are a veteran anti-virus fighter, a new threat emerges.

Bots are the virus evolved. In the past, service providers tracked them by looking for the website that was commanding them, but the latest generation are a P2P headless beast.

In the past, systems also tracked anomalous behavior, but Ashar Aziz, CEO of FireEye, says that defining anomalous behavior is problematic. "The idea is that anomalous behavior may be malicious, but the challenge is that slightly anomalous behavior happens all the time. The network changes, anyway, over time. There is a possibility of false alerts and also missed attacks."

Do not adjust your appliance
Rather than block suspicious behavior, the Botwall 4000 series of appliances from Menlo Park, Calif.-based FireEye redirect unusual traffic to a virtual system. If the traffic infects that system, it is not passed on to the end user and the infected virtual machine is torn down. It is simply a computer session that can be eliminated with a command.

"Ashar and the engineering team have created a complete virtual architecture," explains Phillip Lin, FireEye director of product marketing. We do full installs at various patch levels. We've added instrumentation to allow you to see what's going on inside the virtual machine.

Aziz adds that all software is licensed. Most clients have site licenses, so this architecture is not a problem. "Bots target widely deployed software," he adds. "Unusual software may be the target of a human attack but not of a malware attack. Even Apple software, which is widely deployed, is generally not a target."

So how does all of this fit in a pizza box? "Unlike virtualization servers," explains Lin, "we destroy bot-infected virtual victim machines and recreate new ones instantly for further analysis."

Join the Botwall
Once a bot is identified, the appliance analyzes what it's caught and transmits metadata to all other Botwall appliances worldwide. FireEye's goal is to create a global network so that service providers and enterprise customers can see and understand bot activity worldwide in real time.

But surely service providers will be reluctant to share information? "We generally trade metadata," says Aziz. "We do not exchange information about the victims of infection. The victim data is retained by the ISP."

The company aims to be able to serve the largest ISPs and enterprises. "Our key intellectual property is scalable to thousands and tens of thousands and millions of flows and to multiple gigabit traffic flows," notes Aziz.

Pricing and availability
The company has three products in its Botwall series, all available now:

Model Number
Customer
Bandwidth
Hardware Price
(one time fee)
Software and Support Price
(annual fee)
4100 SME 200 Mbps $10,000 $10,000
4200 Medium-sized business 1 Gbps $20,000 $20,000
4700 Large enterprise and major service providers 10 Gbps $60,000 $60,000

—End

Related articles:
  [Aug. 30, 2007] As Threats Change, ISPs Need New Software
  [March 26, 2007] You Cannot Trust Your Infected Customers
  [Sept. 26, 2006] InterCloud Security Service

 

 

ISP News
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

More >


ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly


Best of ISP-Planet

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Intel PDF: Virtualization Delivers Data Center Efficiency
Intel eBook: Managing the Evolving Data Center
Microsoft Article: BitLocker Brings Encryption to Windows Server 2008
Symantec eBook: The Guide to E-Mail Archiving and Management
Microsoft Article: RODCs Transform Branch Office Security
Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
Avaya Article: Advancing the State of the Art in Customer Service
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Avaya Article: Avaya AE Services Provide Rapid Telephony Integration with Facebook
Go Parallel Article: Getting Started with TBB on Windows
HP eBook: Storage Networking , Part 1
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Seminar: Efficiencies in Hardware/Software Virtualization
HP Webcast: Disaster Recovery Planning
Go Parallel Video: Performance and Threading Tools for Game Developers
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
IBM TCO eKIT: Your IT Budget is Under Attack, Get in Control
IBM Energy Efficiency eKIT: Learn How to Reduce Costs
30-Day Trial: SPAMfighter Exchange Module
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Microsoft Article: Silverlight Streaming--Free Video Hosting for All
Featured Algorithm: Intel Threading Building Blocks - parallel_reduce
HP Demo: StorageWorks EVA4400
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES