Saturday,18 January, 2025

Subscribe to Newsletter

HOME
  NEWS
  Knowledge Center
 
News

Cisco Security Introduces Open Source Application Detection and Control

Published Feb 26, 2014

Harnessing the power of open source and community, Cisco announced that the company is delivering the ability to create and integrate new open source application identification capabilities into its Snort engine through the release of OpenAppID. Open source application detection and control allows users to create, share and implement custom application detection so that they can address new app-based threats as quickly as possible.

Open source application detection and control is enabled by Cisco’s new OpenAppID application-focused detection language. OpenAppID provides application visibility, accelerates development of application detectors, and controls and empowers the community to share detectors for greater protection. As new applications are developed and introduced into corporate environments at an unprecedented rate, this new language provides users with increased flexibility to control new or custom apps on the network. OpenAppID is especially important for organizations utilizing custom-built or specialized applications and those in highly regulated industries that require the highest levels of identification and control.

“As a long-time Snort user, we rely on the flexibility, transparency and control that open source tools give us to better protect our entire environment,” said Kevin A. Kerr, Chief Information Security Officer and Senior Advisor, Risk Management at Oak Ridge National Laboratory. "While proprietary systems leave us beholden to update cycles and priorities, open source allows us to tailor protection at our convenience. By delivering application detection and control to the open source community, Cisco is empowering users with the ability to create custom application detectors and take action to address new threats in real time."

OpenAppID will accelerate and expand the breadth of application detection, by facilitating open community sharing and enhancement of new application detectors. It also supports the following critical capabilities:

• Application Detection/Reporting OpenAppID enables Snort users to utilize the new OpenAppID detectors to detect and identify applications, and to report on application use.
• Application Context associated with network intrusion events By providing application-layer context with security-related events, OpenAppID helps to enhance analysis and speed remediation.
• Actionable Application Detection and Control OpenAppID enables Snort to block or alert on detection of certain applications. This helps to reduce risks by managing total threat surface.

Martin Roesch, creator of Snort and Vice President and Chief Architect, Cisco Security Business Group, said, “Open source is very important because it creates real collaboration and trust between vendors and the experts that are tasked with addressing advanced and aggressive threats. By open sourcing application visibility and control, Cisco is empowering the community to create technically superior solutions to address their most complex and unique security challenges.”

As part of this announcement, Cisco is delivering a special release of the Snort engine that includes the new OpenAppID preprocessor. This enables the Snort community to begin working with OpenAppID to build application detectors. Included with a future general release of Snort, the OpenAppID-enabled preprocessor supports:

• Detection of applications on the network
• Reporting on the usage statistics of apps (traffic)
• Blocking of applications by policy
• Extensions to the Snort rule language to enable application specification
• Reporting of an “App Name” along with IPS events

In addition, a library of more than 1,000 OpenAppID detectors will be available at no charge through the Snort community at http://www.snort.org. Any community member may contribute additional detectors, including end user organizations with custom applications that are not commercially available.

Cisco's commitment to open source security projects, including Snort and ClamAV, provides users and developers the ability to engage and strengthen their solutions, while demonstrating technical excellence and providing rapid threat protection. The acquisition of Sourcefire has strengthened Cisco's extensive contributions to the open source software development community.



Rate This:

Posted by VMD - [Virtual Marketing Department]


Poll
What is your favourite search engine?
Google
Yahoo
Bing

Most Viewed
  Riverbed Launches Industry’s Most Complete Digital Experience Management Solution

  Credence Security to Address Growing Market for GRC Solutions in Middle East Through Partnership with Rsam

  New Mimecast Archive Cloud Capability Streamlines GDPR Management for Email

  Planning and Scheduling Software–Helping Manufacturers Keep Their Customers Happy

  Farsight Security and Infoblox Provide Zero-Hour Protection Against Cyberattacks Due to New Domains

  Fujitsu Launches High-Security Biometric Authentication Solution for Active Directory IT Environments

  Rackspace Wins 2017 Red Hat Innovator of the Year Award

  ServiceNow Survey Shows 2018 as the Year of Automation for Routine Enterprise Work

  4 Tech Hacks to Faster Customer Onboarding

  New Mimecast Report Detects 400% Increase in Impersonation Attacks