NetWitness’ tools, which enable security technicians to collect and analyze detailed information about network events, are frequently used to help automate the incident response process. Those tools will now become part of the family of monitoring applications offered by RSA, the security division of EMC, which also offers security information and event management (SIEM), data leak prevention (DLP), and security data warehousing tools.
Terms of the deal were not announced, but EMC said the transaction "is not expected to have a material impact to revenue or [earnings per share] for the full 2011 fiscal year."
NetWitness has made a name for itself during the past few years as a tool used mostly by line-level technicians for identifying new attacks and malware that have penetrated enterprise defenses. It was one of the first vendors to encourage security professionals to assume that they've already been hacked, rather than to spend all of their time focusing on defending a perimeter.
"The intensity and sophistication of advanced adversaries and zero day malware challenge every organization to rethink traditional approaches to network security," said Tom Heiser, president of RSA, in a statement. "NetWitness has redefined the security landscape, providing a powerful solution for organizations seeking to gain immediate insight, precise clarity, and timely closure in the face of the toughest cyberthreats."
NetWitness will become a core element of RSA’s Advanced Security Management Solutions, providing real-time visibility into network activity and adding efficiency to incident investigations, EMC says.
"By combining the NetWitness network monitoring and analysis technology with RSA’s enVision platform, RSA [DLP] and RSA CyberCrime Intelligence service, security teams can achieve deep insight into the security posture of their organizations," the company said in a statement. "The precise intelligence and visibility that NetWitness provides, coupled with the RSA Archer eGRC platform, enables organizations to apply business context to security information for better identification and prioritization of security risks while improving and streamlining the incident management process."
Analysts and other observers generally offered a favorable view of the merger between RSA and NetWitness.
"With NetWitness, RSA gains a well-reputed security analysis and visualization platform that has become popular with investigative security professionals that value more than just insight into a more complete context of threat activity," says Scott Crawford, an analyst at Enterprise Management Associates, in his blog.
Crawford suggests that the NetWitness technology will partner well with RSA's enVision -- its SIEM product -- as well as its recently acquired Archer Technologies unit, which makes governanance, risk, and compliance (GRC) tools.
"Less obvious, however, may be the opportunity for NetWitness to take advantage of EMC’s Greenplum acquisition for data warehousing," Crawford says. "Security analysis platforms such as NetWitness collect and record significant amounts of fundamental data directly from infrastructure. This volume of raw data collected 'off the wire' can require substantial resources for data management. Greenplum’s support for performance may also be engaged to optimize NetWitness security analytics or data fusion with enVision, Archer, or other resources."
Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Fundamentals of User Activity Monitoring
Benchmarking normal activity and then monitoring for users who stray from that norm is an essential strategy for getting ahead of potential data and system breaches. But choosing the right tools is only part of the effort. Without sufficient training, efficient deployment and a good response plan, attackers could gain the upper hand.
Does SIEM Make Sense For Your Company?
A security information and event management system serves as a repository for all the security alerts and logging systems
from a firm's devices. But this can be overkill for a company that is understaffed or has overestimated its security information needs. In this report, we discuss 10 questions to ask yourself in determining whether SIEM makes sense for
you--and how to pick the right system if it does.
Monitoring Tools and Logs Make All The Difference
It's no longer a matter of "if" you get hacked, but when. In this special report, we take a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape.
Other reports from the Security Monitoring Tech Center:
| Sponsored by: |
Security Management 2.0: Time to Replace Your SIEM?
Is it time? Are you waving the white flag? Has your first gen SIEM failed to meet expectations despite your investment? If you are questioning whether your existing product or service can get the job done, you are not alone. Read this Securosis white paper to learn how easy it can be to replace your SIEM with a next generation solution.
IT Executive Guide to Security Intelligence: Transitioning from SIEM to Total Security Intelligence
Read this whitepaper to learn how adopting a next generation SIEM solution provides security intelligence, to allow organizations to maintain comprehensive and cost-effective information security. Discover how security intelligence enables critical concerns in five key areas: Data silo consolidation, threat detection, fraud discovery, risk assessment/risk management, and regulatory compliance.
The Return on Security of QRadar: Improving Operational Efficiencies in Federal Government
In this study, IANS interviewed two Q1 Labs customers using QRadar to assess their Return On Security (ROS). The two customers were providers of service to the U.S. Government and had highly secure environments dealing with extremely sensitive data. The data yielded from the interviews showed substantial benefit to the organizations for the cost, both in money and staff time.
SANS What Works Webcast: Worldwide Retailer Boosts Privacy with Security Intelligence
A leading retailer with stores worldwide was seeking a more innovative tool to protect customer privacy and intellectual property. PCI compliance mandated log collection, but a vast number of different tools generated an overwhelming amount of log data, making it difficult for the small security team to review it effectively. The solution the company chose had to fit into a diverse network, provide intelligent reporting and offer a centralized management console.
Learn How Security Intelligence Can Help Combat WikiLeaks Stuxnet and Advanced Threats
WikiLeaks and Stuxnet have illustrated a few fundamental IT security issues that have underscored the need for Total Security Intelligence to counter advanced threats and to detect anomalous behavior. See how government and commercial organizations are using QRadar as an integral component of their IT security program to identify emerging threats based on context and situational awareness.
MORE NEWSFEED >>>