Posts

Showing posts with the label business

Sourcefire Is Now FIRE

With the appearance of Sourcefire as FIRE on the NASDAQ, I'd like to congratulate Marty Roesch and friends for bringing their company to the public market. I can't think of another company where one can chat with the CTO and founder in IRC. Several of you have asked for my thoughts on this development. I posted Thoughts on Sourcefire IPO in October and I don't see anything that changes those opinions. Since then, I've been working with several customers, including one who brought me to a Sourcefire sales demo. At that demo, and in meetings with other customers, the ability for a detection product to act like a Security Event Management / Security Information-Incident Management (SEM/SIM) solution repeatedly arose. Sourcefire's products can feed a SEM/SIM but their Defense Center is not a SEM/SIM. This is a big hurdle for Sourcefire. I don't see customers buying a Sourcefire intrusion sensor , and RNA , and a Defense Center , and then paying more m...

Single-Digit Security Service Providers

Yesterday I learned that more friends of mine from Foundstone have departed to start their own companies. I could probably list a dozen such companies with whom I do work, from whom I get leads, or to whom I pass leads. It seems this is a really popular way for security specialists to do work they enjoy without the burden of corporate management. I think clients like this approach because they always interact directly with the people doing the work. They can target specialists and only bring in the people they need. When I am hired for a project that extends beyond network-centric monitoring, response, and/or forensics, I call on one or more friends I trust. For example, one client needs help with monitoring, infrastructure, and applications, so I am driving to the client with the best guys I know for each subject. I wonder if it might be useful for all of us "single-digit security service providers" (i.e., those of us with less than ten employees) to meet, perhaps at B...

Thoughts on Check Point Acquisition of NFR

Earlier this year I covered Check Point 's attempt to purchase Sourcefire . Well, Check Point bought another vendor -- NFR -- for $20 million. Talk about market valuation; Sourcefire's sale price was $225 million. NFR is also down to 22 employees, according to the press release. Although the FAQ says Check Point intends to continue to sell, support, and develop an independent NFR Security product line. I doubt that will last. It doesn't make sense to buy the technology but not integrate it into Check Point's firewalls, and then discard the separate box. At this point it seems we're left with the following IDS/IPS vendors: Cisco 3Com (via Tipping Point ) Juniper Enterasys (Dragon) IBM (via ISS ) McAfee Sourcefire Let's see how that relates to the idea that all network security functions will collapse to switches . The first four sell switches, so I expect them to lead that drive. The fifth (ISS) is owned by IBM, who is more interested in services thes...

Bejtlich Cited in Sourcefire IPO Story

Bill Brenner published this quote in his story Sourcefire IPO could fuel Snort, users say : The infrastructure to support Snort isn't cheap and Sourcefire isn't flush with cash, said Richard Bejtlich, founder of the Washington, D.C.-based consultancy Tao Security. "The money to keep Snort thriving has to come from somewhere, and an IPO could give Snort more legs," he said. I based this thought on the following from Sourcefire's S-1, listed under Risks Related to Our Business: We have incurred operating losses each year since our inception in 2001. Our net loss was approximately $10.5 million for the year ended December 31, 2004, $5.5 million for the year ended December 31, 2005 and $2.9 million for the nine months ended September 30, 2006. Our accumulated deficit as of September 30, 2006 is approximately $40.3 million. It looks like Sourcefire's losses are narrowing, which points to future profitability. My point is that development of Snort and associated ...

Thoughts on Sourcefire IPO

In the spirit of not trying to repeat what everyone else blogs, I'll keep this post on the Sourcefire IPO brief. The must-read post belongs to Mike Rothman -- great work Mike. I'm excited by this development. I'll probably even buy some Sourcefire stock, just so I can attend the shareholders meeting. I've never owned stock in a friend's company, so this would be novel enough to justify the purchase. However, in the long term I expect Sourcefire to be acquired anyway. I stand by my ideas that all network security functions will collapse to the switch , something Richard Stiennon called Secure Network Fabric . This means Sourcefire either needs to sell switches that compete with Cisco (unlikely) or be bought by Cisco (possibly) or a Cisco competitor (probably). Customers are growing increasingly disillusioned with buying more and more point products. If they simply perceive that existing equipment (switches and routers) can be upgraded to implement new securi...

Counterpane Bought: Investors Relax

Eighteen months after MCI bought MSSP NetSec , another telecom has bought another MSSP. This time, BT bought Counterpane . I guessed that Counterpane was desperate . At least the investors who poured four rounds of venture capital into Counterpane can realize some sort of return. The announcement concluded with this statement: As at 31 December 2004 the audited gross assets of the business were $6.8m. That doesn't sound very promising. I expect a good amount of reorganization and removal of personnel. BT will want the low-level analysts to stay, but some will probably leave. The middle-managers will want to stay, but BT will send them packing. Since Counterpane's brain trust has largely disappeared, they only need to keep Bruce Schneier as their "visibility guy" or "mantlepiece." Good luck to them -- I imagine they will be morphed into protecting BT's cloud . Update: After reading helpful comments and stories like this , it appears Counterpa...

Does SecureWorks-LURHQ Count as Consolidation?

I think it does. Managed network security services is one arena where size is always a factor, and bigger is usually better. With more employees you have more analysts per shift. You have more customers, so you see more of the Internet. With enough customers your view of the Internet begins to resemble a statistically significant sample, from which you can make inferences about the health of the global network. I thought this Dark Reading story on the merger (the new company will be called SecureWorks -- no more "how do I say LURHQ?") had an interesting quote: But all of this doesn't mean IBM-ISS isn't on SecureWorks' radar: Prince says SecureWorks' main competitors on the enterprise side are Symantec, VeriSign, and "now IBM." On the commercial side, it will be local telcos and other service providers, he says. Where is Counterpane? They must be desperate for a buyer. I expect to see more MSSPs combining to form Voltron as time progresses.

More Security Consolidation

By now you've heard that IBM is buying ISS for $1.3 billion. Wow. This is much larger than the purchases of Foundstone, @Stake and Guardent in 2004 by McAfee, Symantec, and VeriSign (respectively). Remember also in early 2005 that NetSec was bought by MCI, who was then bought by Verizon. IBM is an interesting buyer because it is a mammoth product and service vendor. I do not think of IBM as being a security product company, but I do think of them as an IT services company. It sounds like IBM will just push ISS products through its services group. I wonder where this leaves other product/service companies? Looking at my MSSP post , I have a few thoughts on the remaining MSSPs. I am guessing that Counterpane and Cybertrust (TruSecure) would desperately like to be purchased. LURHQ is also independent and available. The remaining MSSPs tend to be smaller, or already part of large product/service companies (e.g., Symantec). I know there are lots of MSSP readers of this blog. ...

ENIRA Partners with Lancope

I've wanted to say something about ENIRA for several months now, but I've been under a non-disclosure agreement. This morning, however, I noticed this press release which quotes me. What's the fuss? ENIRA is a nearby company (in northern Virginia) that sells a Network Response System . It's essentially an incident containment appliance that isolates hosts when directed to do so. It's neither an IDS nor firewall -- layer 3, 4, 7 (IPS), or otherwise. ENIRA learns your network topology by accessing infrastructure devices (switches, routers, firewalls, etc.) and implements a containment policy when told to isolate a host or segment. The isolation mechanism makes the best possible choices, based on any policies and restrictions you have provided. It keeps track of its actions and acts like a "network engineer in a box." I think this is a great network-centric incident response product. Lancope is going to use it to implement short-term incident cont...

Check Point Acquisition of Sourcefire Cancelled

According to Sourcefire's press release : Sourcefire, Inc., the world leader in intrusion prevention, today announced that, with the consent of the US government, Sourcefire and Check Point Software Technologies have opted to withdraw their merger filing with the Committee on Foreign Investment in the United States (CFIUS). Sourcefire will continue to operate as the industry's largest private Intrusion Prevention System (IPS) vendor. According to Check Point's press release : The companies have determined that it would be more effective to create a customer focused business partnership. "We've decided to pursue alternative ways for Check Point and Sourcefire to partner in order to bring to market the most comprehensive security solutions," said Gil Shwed, Check Point's CEO. Check Point and Sourcefire will continue to create and distribute the best security solutions in their respective spaces. They will work together on formulating a partnership strategy...

Feds Delay Check Point Acquisition of Sourcefire

Based on a friend's tip, I found myself looking for this press release , which reads in part: Check Point ® Software Technologies Ltd. (NASDAQ: CHKP), the world leader in securing the Internet, received notice its pending acquisition of Sourcefire ®, Inc. has moved into the investigative stage with the Committee on Foreign Investment in the United States ("CFIUS"). In order to clear the transaction with the United States Government, Check Point submitted two regulatory applications. Check Point received U.S. anti-trust approval and was advised that CFIUS would continue reviewing the application during a 45-day investigative period... Pursuant to the Exon-Florio legislation, CFIUS reviews proposed foreign acquisitions of U.S. companies in order to protect national security while maintaining the credibility of the United States open investment policy. The Exon-Florio legislation provides for a 30-day review following notification of a potential acquisition. CFIUS has the ...

Thoughts on CMP Acquisition of Black Hat

I just learned that CMP Media , publishers of IT magazines like Network Computing and IT Architect (formerly Network Magazine) just acquired Jeff Moss' Black Hat, Inc. for $10 million. I'm amazed that Black Hat went for that much. The organization may offer consulting , but it's mainly known for its conferences. Those conferences rely on instructors, none of whom are obligated to speak (as far as I know). Without any intellectual property, substantial workforce, or product lines, I'd say Black Hat did pretty well for itself! I did not realize until now that CMP also owns the Computer Security Insitutute , who runs their own security conferences . The CSI conference is a strange beast. I wouldn't consider William Safire to be a "security expert," but there he is appearing as a keynote CSI speaker. Perhaps Black Hat is supposed to pull in another sort of demographic, one without as much gray hair?

Bejtlich Quotes in Sourcefire Acquisition Story

Eric B. Parizo mentioned me in his story Snort users fear future under Check Point . One of the quotes appears as follows: Richard Bejtlich, principal with Washington, D.C.-based consultancy Tao Security, said many fail to realize just how expensive it is to support a product like Snort. "I've been to Sourcefire, and I've seen how many people they have working on the product and on signatures," Bejtlich said. "They have what seems like millions and millions of racks of equipment. I was surprised they were able to continue with Snort as they did." That should say "millions and millions of dollars of racks of equipment." I obviously haven't seen millions of racks of anything when I visit Sourcefire! Also, I appear to have been demoted at my own company. I am not a "principle" at TaoSecurity . My boss must be upset with my performance! :)

Thoughts on the Week's Security News

This was a busy week for me; I spent all week teaching (and all last week preparing) a private Network Security Operations class in California. I just flew back from LAX to Dulles this morning and I get on another plane tomorrow afternoon. I'm speaking in San Jose at a Cisco event, and then teaching a second private NSO class again next week. I've been tracking all of the week's security news. Thank you to those who thought I may have missed something. I didn't want to commit any thoughts to the blog without taking some time to ponder various events. Obviously the biggest news of the week was Checkpoint 's $225 million acquisition of Sourcefire . In short, I didn't see that coming. I have doubts about the future of Snort being a free product, let alone open source. I don't see anyone making the case to the board of a publicly traded company that part of that company's work is going to be given away for free, especially after spending $225 mill...

Verisign to Acquire iDEFENSE

The 45 survivors at iDEFENSE must be breathing a sigh of relief. Verisign will buy iDEFENSE for $40 million. That is $100 million less than the cost to acquire Guardent in December 2003. Verisign has over 3,500 employees according to its fact sheet , and it seems to be making ever bigger advances into the security market. I would be interested in hearing from any iDEFENSE insiders (anonymously here) what they think of this acquisition.

Launch of New TaoSecurity.com

Image
I am happy to announce the redesign of TaoSecurity.com as the corporate home of TaoSecurity. In the coming days and weeks I will transition old, more personalized content to the www.bejtlich.net domain. TaoSecurity is open for business, and I look forward to helping you with your security consulting and training needs. I have a ton of material to blog, including a wrap-up of BSDCan and some news items. I will be flying to San Francisco Tuesday and returning very early Thursday. Don't expect too many updates until I return home. Thank you!

Visiting Sourcefire

Image
Today I visited the Columbia, MD headquarters of Sourcefire with DC Snort Users Group founder Keith McCammon, pictured with me at left. We drove up from our Falls Church, VA office to meet with Sourcefire founder and Snort creator Marty Roesch. Sourcefire is housed in an Ikea-type building constructed to house optical networking start-ups during the dot-com craze. In addition to Sourcefire, Optical Capital Group Ventures and another company called Debt Shield share the space. We started our conversation with Marty by discussing the new VRT Certified Rules License Agreement . Marty said that Sourcefire isn't a "nameless, faceless company. Real people work here." He demonstrated Sourcefire's commitment to the security community by mentioning the change to the Audit clause , previously reported here. Marty reported that many companies, several of which he was previously unaware, have reported interest in Snort Integrator licenses. As of this afternoon almost ...

Lockheed Martin Acquires The Sytex Group

On Friday Lockheed Martin announced it is buying The Sytex Group for $462 million. Sytex's revenue for 2004 was $425 million, not much less than the asking price. It shows that service companies sell for much less than product companies. According to the cited story, about 85 percent of Sytex’s revenue comes from the US Department of Defense. I guess those contracts are not worth as much in forward-looking terms as one might expect?

Thoughts on MCI Acquisition of NetSec

I only recently learned that telecom giant MCI bought managed security services provider NetSec for $105 million . Other telecom companies might want to look at Lisa Phifer's Managed Security Service Provider Survey or Adam Stone's In MSSPs We Trust for acquisition candidates. I expect acquisitions to continue, as there are between one and two dozen small MSSPs available. There are also people like myself who know how to build MSSPs from the ground up (hint hint). :) Update: It must be confusing to work for NetSec. One minute you're working for MCI, the next you're working for Verizon !

Another Foundstone Spin-Off: Security Compass

I was happy to learn that another friend and ex-Foundstone colleague, Nish Bhalla, has started his own consulting company: Security Compass . Nish most recently contributed to the new book Buffer Overflow Attacks , which I plan to read. Nish is an expert on Web and application security, so if you need a customized, in-depth assessment of those services give him a call!