Analytics
1/9/2014
01:35 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

Tripwire Announces Technology Partnership With CORE Security

Partnership provides threat and vulnerability risk management to mutual customers

PORTLAND, OREGON -- January 9, 2013 -- Tripwire, Inc., a leading global provider of risk-based security and compliance management solutions, and CORE Security, a leading provider of predictive security intelligence solutions, today announced a technology partnership and integration that provides comprehensive threat and vulnerability risk management to mutual customers. The integration unites vulnerability information with network topology from firewalls and routers, and then validates the vulnerability information and potential attack paths in live or simulated penetration tests. The collaboration is part of Tripwire's Technology Alliance Partner (TAP) program, designed to allow a wide variety of vendors to collaborate with Tripwire to deliver innovative security solutions.

"We are looking forward to building on our relationship with CORE Security," said Rod Murchison, vice president of product management and technology alliances for Tripwire. "Our integration with CORE Insight Enterprise makes it possible for enterprises to go beyond finding and fixing vulnerabilities to operating their vulnerability management programs at peak efficiency."

Large enterprises need to gather, analyze and prioritize an overwhelming amount of vulnerability and network topography data and combine it with cyberattack domain expertise in order to gain a comprehensive understanding of the security risks facing their most critical assets. To decrease the cost and complexity of risk-based security management, enterprises need the ability to effectively prioritize threats in the context of business, regulatory compliance and operational metrics.

The integration combines vulnerability information from Tripwire® IP360&trade with detailed exploit and network topology data from CORE Insight to model threat scenarios and enable vulnerability validation and proactive remediation. With this integration, mutual customers gain the ability to:

· Discover complex attack paths that expose vulnerability risks to other areas of the business.

· Validate vulnerability findings with directed simulation and/or live tests of exploitable conditions.

· Model the impact of remediation actions on the security posture of the business.

"The most common mistake organizations make is to take a reactive posture to imminent security threats to critical assets. Enterprises must go on the offensive by thinking like an attacker, and then they can preempt attacks rather than wait to deal with their consequences," said Eric Cowperthwaite, vice president of advanced security and strategy at CORE Security. "We are very pleased to partner with Tripwire and help organizations of all sizes better protect themselves against outside attacks through the use of our combined technologies and processes, providing an even stronger solution to this problem."

For more information about the integration between CORE Security and Tripwire IP360, please visit: http://www.tripwire.com/register/tripwire-ip360-and-core-insight-enabling-predictive-security-intelligence/.

About CORE Security

CORE Security is the leading provider of predictive security intelligence solutions for enterprises and government organizations. We help more than 1,400 customers worldwide preempt critical security threats throughout their IT environments, and communicate the risk the threats pose to the business. Our patented, proven, award-winning enterprise solutions are backed by more than 15 years of applied expertise from CoreLabs, the company's innovative security research center. For more information, visit www.coresecurity.com.

About Tripwire

Tripwire is a leading global provider of risk-based security and compliance management solutions, enabling enterprises, government agencies and service providers to effectively connect security to their business. Tripwire provides the broadest set of foundational security controls including security configuration management, vulnerability management, file integrity monitoring, log and event management. Tripwire solutions deliver unprecedented visibility, business context and security business intelligence allowing extended enterprises to protect sensitive data from breaches, vulnerabilities, and threats. Learn more at www.tripwire.com, get security news, trends and insights at http://www.tripwire.com/state-of-security/ or follow us on Twitter @TripwireInc.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0761
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

CVE-2014-0762
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows physically proximate attackers to cause a denial of service (infinite loop or process crash) via crafted input over a serial line.

CVE-2014-2380
Published: 2014-08-27
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

CVE-2014-2381
Published: 2014-08-27
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.

CVE-2014-3344
Published: 2014-08-27
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq31129, CSCuq3...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.