Risk
7/31/2006
07:41 AM
50%
50%

FireEye Unveils NAC

FireEye announced the availability of the FireEye 4200 appliance

MENLO PARK, Calif. -- FireEye, Inc., a pioneer in Network Access Control (NAC) technology, today announced the availability of the FireEye 4200 appliance-the first agentless NAC solution that leverages innovative virtualization technology to stop machines infected with worms and other malicious network-borne malware from accessing and damaging enterprise networks. Simple, yet extremely accurate, the FireEye appliance quarantines systems infected with known or unknown malware. The unique and unprecedented FireEye 4200 technology is the industry's most accurate and easily deployed NAC security appliance available on the market today.

"After looking at competitive NAC solutions, we selected FireEye because of their completely unique approach to securing the internal wireless network," said Fred Archibald, network manager at the department of Electrical Engineering and Computer Sciences at the University of California, Berkeley, a premier FireEye customer. "Other solutions we evaluated were tedious and time-consuming to deploy and manage. FireEye's agentless, easy to configure solution is extremely accurate in stopping attacks, and eliminates client support issues. Based on this, FireEye was the clear choice when selecting our NAC solution."

The FireEye Attack Confirmation Technology (FACT) Engine FireEye 4200 is equipped with the FireEye Attack Confirmation Technology (FACT) engine, which uses patent-pending virtualization technology to assess suspect machine network traffic and then provides conclusive attack confirmation prior to taking any quarantine actions or denying access to the network, thus eliminating the need to resolve false positives. Once a machine has been deemed infected with worms, network-borne malware, or zero-day attacks, it is immediately quarantined, protecting internal network resources from the damage of a serious attack.

"When compared with other products, we found that FireEye has a unique and interesting approach to Network Access Control (NAC) not found in current products on the market today," said Chris Motta, senior director, Information Technology at Redback Networks Inc. (NASDAQ: RBAK), a leading provider of next-generation broadband networking systems and another FireEye inaugural customer. "Where most Network Access Control (NAC) products are often considered 'network bottlenecks,' requiring a large amount of time and energy to maintain, FireEye's Network Access Control (NAC) solution monitors our network, serving as a highly-effective 'trap' for rapidly propagating viruses and worms, without the need for constant maintenance and updating. In addition, FireEye's virtualization technology adds to the product's robust capabilities and is, quite simply, unlike any other Network Access Control (NAC) solution we've reviewed."

FireEye Inc.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.