Perimeter
10/12/2011
04:48 PM
Rob Enderle
Rob Enderle
Commentary
Connect Directly
RSS
E-Mail
50%
50%

McAfee + NitroSecurity: SIEM Merger Done Right

McAfee showcases the perfect security company merger by bringing out a SIEM offering that better anticipates an increasingly hostile world

One of the big problems with security solutions in business is that they are largely ad-hoc. This means different layers are often added without much consideration for interoperability, and the end result is exploits that otherwise might have been caught are missed because they pass between the reporting gaps of the various systems. Security information and event management (SIEM) products are designed to close these gaps by connecting all of the products and showcasing trends so that an attack -- regardless of the attack vector -- can be more rapidly identified and mitigated.

The advantage of having a vendor-independent SIEM solution is that it gives you a better choice of the parts. The disadvantage is that the independent vendor generally has trouble maintaining high integration with new features because they aren’t in the development loop for the products they are integrating with, and are always playing catch-up. In a slow-moving market, this is an acceptable trade-off; unfortunately, the security market is no longer slow-moving, which likely goes to the core of why McAfee bought Nitro Security.

According to IDC, the SIEM market alone is currently more than $1 billion total and growing at an aggressive 22 percent. This is likely because of the proliferation of point-security solutions that now need to be better integrated in order to be made effective. This is coupled with the massive increase in visible threats, which many of us believe are underreported, but have crossed industry and government sites and penetrated organizations that were thought secure enough. SIEM products have a strong value proposition: They create visibility across the IT infrastructure, limit risk, and provide analytics that can identify threats and help fund mitigation efforts. In short, they provide the missing situational awareness needed to address what has become a complex threat landscape, and help make better decisions with regard to how to best protect the business.

I think the key to why McAfee bought NitroSecurity is the need for speed. It already tied back into some of its other offerings, but these offerings were being changed at an increasing rate, and for the links back into NitroSecurity to function optimally, McAfee would need an integrated suite. The only way to get this result effectively while maintaining product development security was to buy NitroSecurity and use it to link its ePO, McAfee Risk Advisor, and GTI offerings.

This now will increasingly look like an end-to-end suite so that buyers aren’t left with timing integration gaps between McAfee's and NitroSecurity's products.

This was also one of the easiest types of integration mergers to do, one where the product was already partially integrated with the planned suite of offerings and where the integration issues are likely already known.

Most software acquisitions occur between products that were never intended to work together, and then fail because folks eventually find out it is generally better to start from scratch than to try to integrate products that were never designed to be integrated.

In this case, NitroSecurity’s SIEM offering was designed to be integrated with McAfee's products, making the integration comparatively easy and speeding time to market. The end result is a solution that is and will remain more agile and better able to respond to a world of increasing and ever more aggressive threats.

Rob Enderle is president and founder of The Enderle Group. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3352
Published: 2014-08-30
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh...

CVE-2014-3908
Published: 2014-08-30
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2010-5110
Published: 2014-08-29
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.