SourceFire IPS

 

SourceFire IPSBuilt on Snort, the de facto standard for intrusion detection and prevention (IDS/IPS), Sourcefire IPS™ (Intrusion Prevention System) is the foundation of the award-winning Sourcefire 3D® System. Sourcefire IPS uses a powerful combination of vulnerability- and anomaly-based inspection methods—at line speeds up to 10Gbps—to analyze network traffic and prevent threats from damaging your network. Additionally, when Sourcefire IPS is deployed with the Sourcefire SSL Appliance, the benefits of the IPS are extended to SSL-encrypted traffic.

 

Whether deployed at the perimeter, in the DMZ, in the core, or at critical network segments, Sourcefire’s easy-to-use IPS appliances provide comprehensive threat protection. Sourcefire IPS contains multiple default policies for out-of-the box blocking, drawing from a comprehensive library of open Snort rules. Open rules allow customers to verify that rules address the vulnerabilities for which coverage is claimed and to create new rules or modify existing ones to protect custom applications and systems. Sourcefire’s IPS can be deployed in inline blocking and/or passive alerting modes, and can remediate attacks using external devices, such as firewalls, routers, patch management systems, and more.

Key Sourcefire IPS Capabilities

• Snort IPS detection engine
• Snort rule set offers protection from constantly evolving vulnerabilities
• Open rules language—view, edit, and create Snort rules
• Operates on physical and virtual Sourcefire 3D Sensors
• Reports, alerts, and dashboards
• Multiple default IPS policies
• Packet-level forensics
• Sophisticated, customizable workflows
• Protection Against Known and Unknown Threats
• Protection for Physical and Virtual Environments
• Centralized Event Aggregation and Analysis
• Reports, Alerts, and Dashboards
• Real-Time Network Intelligence
• Automated Impact Assessment
• Automated IPS Tuning

Sourcefire’s IPS appliances provide comprehensive threat protection against:

• Worms
• Trojans
• Backdoor attacks
• Spyware
• Port scans
• VoIP attacks
• IPv6 attacks
• DoS attacks
• Buffer overflows
• P2P attacks
• Statistical anomalies
• Protocol anomalies
• Application anomalies
• Malformed traffic
• Invalid headers
• Blended threats
• Rate-based attacks
• Zero-day threats
• TCP segmentation and IP fragment

 

Product Type

 3D5003D10003D2000
MODEL3D5003D10003D2000
Supported Line Speed (IDS/IPS)5Mbps45Mbps100Mbps
 3D21003D25003D3500
MODEL3D21003D25003D3500
Supported Line Speed (ISD/IPS)250Mbps500Mbps1Gbps
 3D45003D65003D9900
MODEL3D45003D65003D9900
Supported Line Speed (IDS/IPS)2Gbps4Gbpsup to 10Gbps