TippingPoint to push into Euro security market

NEWS
American IT security firm TippingPoint is gearing up to begin selling its range of network intrusion prevention systems in Europe.

The company raised over £14m in funding from investors earlier this month, and is planning to spend a considerable chunk of this revenue on expanding into European countries.

ZDNet UK has learned that TippingPoint will open its European headquarters in Amsterdam within two weeks and is already planning to hire staff for other regional offices.

TippingPoint's intrusion prevention systems, sold under the UnityOne brand, analyse network traffic looking for patterns that suggest a cyberattack is taking place, and take action to stop the attack by inspecting the packets flowing across the network and dropping those which it decides are not legitimate.

TippingPoint says this ability to recognise suspicious network behaviour makes makes more sense than security systems that are just based on patches against specific known threats. With so many new vulnerabilities being found in software products each week, the firm says it is all but impossible for IT managers to keep patching against them all.

As an example, TippingPoint cites this August's spate of virus attacks. Both the MSBlast and the Nachi/Welchia worms took advantage of a security hole in various versions of Windows and Windows Server 2003 that had been first disclosed in mid-July. The company claims that no PCs on networks protected by UnityOne were compromised by either virus.

Speaking at NetEvents earlier this month, Marc Willebeek-LeMair, TippingPoint's chief technology officer, warned companies not to rely on intrusion detection systems (IDS) that only alert an IT department to the existence of a problem, rather than address it.

"If you're hit by a worm, all an IDS will do is tell you that 'by the way, you've got a worm in your system that's run riot through thousands of your machines, and I just wanted you to know that,'" Willebeek-LeMair said.

Willebeek-LeMair did add that IDSs have a role as auditing tools, allowing an IT manager to see how his network security is performing -- a point backed up by other experts.

"Saying that IDSs have no place is like saying 'we won't put weapons experts into this country to measure what threat it poses, we'll just invade it,'" insisted Dominic Storey, European technical director for Sourcefire, before adding: "Oops, that just happened." Sourcefire develops Snort, the open-source IDS technology.

UnityOne can also be used to block peer-to-peer applications, making it a popular choice for some American universities -- one of which managed to claw back 45 percent more bandwidth by blocking P2P traffic.

Current prices for the UnityOne range vary from $24,995 (£14,779) to $99,995 (£51,125).

Talkback

I have been involved as a consultant with putting in solutions for IPS and a major drawback to these solutions is they have evolved from IDS and must route between 2 NICS and are notoriously inaccurate.

If there is an interface exposed on an IPS then it can be targeted, and brought down easily.
Also the inability of these software based IPS solutions to handle large DDOS attacks like synfloods mean they are like using some gum to stop a dam.

The only solution worthy of mention to date is an IPS solution from Toplayer Networks which can be deployed in the enterprise or at ISP's as it is L2 and does not interfere with BGP routing. and can handle in excess of 800K syn's/sec on the current platform.
They just released a new product IPS 5500 which can handle synfloods of 2M synsec which a few of my customers are keen to test out.

So it is time for the PC based solutions to stop clouding the market and stick to doing IDS, which they havent even got right 4 years later.
Havent really heard of Tipping point but from what I have heard it is hard to get one of their people to even explain how they deal with a specific threat scenario,

via Facebook 13 November, 2003 20:17
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 hour ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

4 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

5 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

5 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

6 hours ago by via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

8 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

13 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

16 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

17 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

18 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

19 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

20 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

20 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

20 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

21 hours ago by Moley on ACTA: Facts, misconceptions and questions