29
Local Edition Everything You Want To Know About Sourcefire Session ID 14PT Alex Kirk, CSE

Cisco livelocal2014 whysourcefire

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Cisco livelocal2014 whysourcefire

Local Edition

Everything You Want To Know About Sourcefire

Session ID 14PT

Alex Kirk, CSE

Page 2: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Agenda

•  Introduction

•  History of Sourcefire

•  Security for the Real World

•  Better Together

•  Product Demo

•  Conclusion

2

Page 3: Cisco livelocal2014 whysourcefire

Local Edition

History of Sourcefire

Page 4: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

“Security DNA”

4

Page 5: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

The Marty Roesch Story

5

Page 6: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

RNA/FireSight

6

Page 7: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Multi-Gigabit Platforms

7

Page 8: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Collective Security Intelligence

8

Page 9: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Our First Sandbox

9

Page 10: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Zero to NGFW in 12 Months

10

Page 11: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

We Even Acquired A Company!

11

Page 12: Cisco livelocal2014 whysourcefire

Local Edition

Security for the Real World

Page 13: Cisco livelocal2014 whysourcefire

Local Edition

“The network discovery is primarily passive for Sourcefire RNA…it can tell what OS version is on a server, what services it’s running, and the specific versions of each service. With the information from RNA, I can correlate events to determine any impact.”

Senior Network Engineer ReD Retail Decisions

Page 14: Cisco livelocal2014 whysourcefire

Local Edition

“Mapping a username to an IP address was taking us away from a backlog of other important tasks. With Sourcefire RUA, what used to take up to an hour now takes just a second or two.”

Security Engineer AutoTrader.com

Page 15: Cisco livelocal2014 whysourcefire

Local Edition

“VeriSign MSS manages more than 20 different products for our customers… the technical support we receive from Sourcefire is unsurpassed.”

Network Security Manager VeriSign

Page 16: Cisco livelocal2014 whysourcefire

Local Edition

“Without Sourcefire, we would have never passed the [PCI] audits, which could have led to regulatory fines or loss of business with our partners.”

Network Security Administrator The Banker’s Bank

Page 17: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Retrospective Detection

17

Page 18: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Security for the Real World

18

Page 19: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

An Example – Heartbleed

19

Page 20: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Real-World Adversaries

20

Page 21: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Open APIs

21

Page 22: Cisco livelocal2014 whysourcefire

Local Edition

Better Together

Page 23: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Cisco Sees More

23

Page 24: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Smart Management Is Keeping The Brains Around

24

Page 25: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Device Access Will Be Web 2.0, Not Java

25

Page 26: Cisco livelocal2014 whysourcefire

© 2014 Cisco and/or its affiliates. All rights reserved. Presentation_ID Cisco Public Local Edition

Internet of Things

26

Page 27: Cisco livelocal2014 whysourcefire

Local Edition

Demo

Page 28: Cisco livelocal2014 whysourcefire

Local Edition

Page 29: Cisco livelocal2014 whysourcefire