FireEye Announces the General Availability of Network Threat Prevention Platform with IPS

Today we announced the FireEye Network Threat Prevention Platform with IPS will be available to customers worldwide starting June 2, 2014. This product is available as an add-on license to the FireEye Network Threat Prevention Platform (NX series) appliances, giving customers a holistic view of multi-vector attacks that goes well beyond what conventional intrusion prevention system (IPS) tools offer. The Network Threat Prevention Platform with IPS uses FireEye’s patented Multi-Vector Virtual Execution (MVX) engine technology to better protect systems from known and unknown threats while reining in false-positives. With this new addition, security teams now get compliance and true security in a single box.

Network Threat Prevention Platform with IPS has been in beta for the past several months, including with The Italian Ministry of Foreign Affairs, who had this to say about the new platform add-on:

“We have chosen the FireEye Network Threat Prevention Platform with IPS because it is a solution that allows us to combine advanced threat protection with compliance-driven security needs. We will be able to provide our security team greater visibility into network threats and more effective data to act on by significantly reducing false-positives and -negatives.”

We also heard two interesting anecdotes from other beta customers illustrating how the combination of the FireEye MVX engine with IPS greatly reduces the overhead on security:

  • A large university experienced 732 events per day which we were able to validate and confirm down to 32 being true positives.
  • One large health care provider experienced 1,400 events per day that we then pared down to just 40 as being true positives.

How does Network Threat Prevention Platform with IPS work? When network traffic triggers a signature-based alert, the MVX engine evaluates the traffic in a “real world” environment to confirm whether the threat is real, greatly improving the signal-to-noise ratio. In addition to passing a true alert directly to the alert management system, as traditional IPS does, the MVX engine inspects the corresponding network traffic within instrumented, virtual-machine environments. The MVX engine evaluates activity across the multiple avenues used in advanced attacks. That analysis is integrated with host-based detection and other components of the broader FireEye platform.

For more information on the FireEye Network Threat Prevention Platform with IPS, visit: https://www.fireeyesolution.com/products-and-solutions/network-threat-prevention-platform.html

Strategic Analysis: As Russia-Ukraine Conflict Continues, Malware Activity Rises

Cyber conflicts are a reflection of traditional, “real life” human conflicts. And the more serious the conflict in the “real world,” the more conspicuous its cyber shadow is likely to be. So let’s look at a serious, current international conflict – the one between Russia and Ukraine – to see if we can find its reflection in cyberspace.

One of the most reliable ways to discover computer network operations is to look for malware “callbacks” – the communications initiated from compromised computers to an attacker’s first-stage command-and-control (C2) server. At FireEye, we detect and analyze millions of such callbacks every year.

Table 1, below, shows the top 20 countries to receive first-stage malware callbacks over the last 16 months, according to the latest FireEye data.

ru1

Table 1 – Callback Infrastructure: the Last 16 Months

As we track the evolution of callbacks during this period, we see a likely correlation between the overall number of callbacks both to Russia and to Ukraine, and the intensification of the crisis between the two nations. The two key indicators we see are:

  • In 2013, Russia was, on average, #7 on this list; in 2014, its average rank is #5.
  • In 2013, Ukraine was, on average, #12 on this list; in 2014, its average rank is #9.

The biggest single monthly jump occurred in March 2014, when Russia moved from #7 to #3. In that same month, the following events also took place in Russia and Ukraine:

  • Russia’s parliament authorized the use of military force in Ukraine;
  • Vladimir Putin signed a bill incorporating the Crimean peninsula into the Russian Federation;
  • The U.S. and EU imposed travel bans and asset freezes on some senior Russian officials;
  • Russian military forces massed along the Ukrainian border; and
  • Russian energy giant Gazprom threatened to cut off Ukraine’s supply of gas.

The graphs below provide a closer look at the crucial month of March 2014, specifically comparing it to malware callback data from February.

Figure 1 shows a significant rise in malware callbacks to Russia from three of the top four source countries in February: Canada, South Korea, and the U.S. (Great Britain had a slight decline).

ru2

Figure 1 – Callbacks to Russia in Feb/Mar 2014: Top Four Countries

Figure 2 depicts the same, general rise in callbacks to Russia from many other countries around the world.

ru3

Figure 2 – Callbacks to Russia in Feb/Mar 2014: Rest of World

Figure 3 shows that the sharp rise in callbacks to Russia in March 2014 was seen in every FireEye industry vertical.

ru4

Figure 3 – Callbacks to Russia in Feb/Mar 2014: Industry Verticals

Tables 2 and 3, below, compare the rise in callbacks to Russia and Ukraine against the rise in callbacks to other countries for February and March 2014. It is important to note that nearly half of the world’s countries experienced a decrease in callbacks during this same time frame.

Table 2 shows the countries that received the highest increase, from February to March 2014, in the number of source countries sending callbacks to them. Ukraine and Russia both placed in the top ten countries worldwide, with Ukraine jumping from 29 source countries to 39, and Russia moving from 45 to 53.

ru5

Table 2 – Callbacks in 2014: Number of Source Countries

Table 3 shows the increase in the number of malware signatures associated with the callbacks to each country for February and March 2014. Ukraine does not appear in the top ten (it tied for #15), but Russia was #4 on this list (again, nearly half of the world’s countries showed no increase or a decrease).

ru6

Table 3 – Callbacks in 2014: Number of Malware Signatures

It is not my intention here to suggest that Russia and/or Ukraine are the sole threat actors within this data set. I also do not want to speculate too much on the precise motives of the attackers behind all of these callbacks. Within such a large volume of malware activity, there are likely to be lone hackers, “patriotic hackers,” cyber criminals, Russian and Ukrainian government operations, and cyber operations initiated by other nations.

What I want to convey in this blog is that generic, high-level traffic analysis – for which it is not always necessary to know the exact content or the original source of individual communications – might be used to draw a link between large-scale malware activity and important geopolitical events. In other words, the rise in callbacks to Russia and Ukraine (or to any other country or region of the world) during high levels of geopolitical tension suggests strongly that computer network operations are being used as one way to gain competitive advantage in the conflict.

In the near future, we will apply this methodology to other global occurrences to further identify patterns that could provide valuable advanced threat protection insights.

The PLA and the 8:00am-5:00pm Work Day: FireEye Confirms DOJ’s Findings on APT1 Intrusion Activity

Yesterday, the U.S. Department of Justice (DOJ) announced the indictment of five members of the Second Bureau of the People’s Liberation Army (PLA) General Staff Department’s Third Department, also known as PLA Unit 61398. This is the same unit that Mandiant publicly unmasked last year in the APT1 report. At the time it was originally released, China denounced the report, saying that it lacked sufficient evidence. Following the DOJ’s indictment, however, China’s usual response changed from “you lack sufficient evidence” to “you have fabricated the evidence”, calling on the U.S. to “correct the error immediately.” This is a significant evolution in China’s messaging; if the evidence is real, it overwhelmingly demonstrates China’s unilateral attempts to leapfrog years of industrial development — by using cyber intrusions to access and steal intellectual property.

The evidence provided in the indictment includes Exhibit F (pages 54-56), which shows three charts based on Dynamic DNS data. These charts indicate that the named defendants (Unit 61398 members) were re-pointing their domain names at a Dynamic DNS provider during Chinese business hours from 2008 to 2013. The China work day, particularly for government offices, is very predictable, as noted on this travel site:

“Government offices, institutions and schools begin at 8:00 or 8:30, and end at 17:00 or 17:30 with two-hour noon break, from Monday to Friday. They usually close on Saturday, Sunday and public holidays.”

What Exhibit F shows is a spike of activity on Monday through Friday around 8am in Shanghai (China Standard Time), a roughly 2-hour lull at lunchtime, and then another spike of activity from about 2pm to 6pm. The charts also show that there were very few changes in Dynamic DNS resolution on weekends.

At Mandiant (now a FireEye company), we can corroborate the DOJ’s data by releasing additional evidence that we did not include in the APT1 report. In the APT1 report, we specified the following:

  • Over a two-year period (January 2011 to January 2013) we confirmed 1,905 instances of APT1 actors logging into their hop infrastructure from 832 different IP addresses with Remote Desktop.

  • Of the 832 IP addresses, 817 (98.2%) were Chinese and belong predominantly to four large net blocks in Shanghai which we will refer to as APT1’s home networks.

  • In order to make a user’s experience as seamless as possible, the Remote Desktop protocol requires client applications to forward several important details to the server, including their client hostname and the client keyboard layout. In 1,849 of the 1,905 (97%) APT1 Remote Desktop sessions we observed in the past two years, the keyboard layout setting was “Chinese (Simplified) — US Keyboard.”

One thing we did not originally provide was an analysis of the time of day and day of week that these 1,905 Remote Desktop (RDP) connections occurred. However, when we look at these connections in bar chart format, obvious patterns appear:

rdp-analysis-fig1Figure 1: APT1 Remote Desktop login times distributed by hour of day (China Standard Time)

 

rdp-analysis-fig2Figure 2: APT1 Remote Desktop login times distributed by day of week (China Standard Time)

Essentially, APT1 conducted almost all of the 1,905 RDP connections from 2011 to 2013:

  • (1) On week days (Monday through Friday),
  • (2) between 8am and noon, 2pm and 6pm, and 7pm and 10pm CST.

On some occasions, APT1 personnel appear to have worked on weekends, but these are minor exceptions to the norm. Consider the following evidence together for the 1,905 RDP connections:

  • 98.2% of IP addresses used to log in to hop points (which help mask the real point of origin to victim organizations) were from Shanghai networks
  • 97% of the connections were from computers using the Simplified Chinese language setting
  • 97.5% of the connections occurred on weekdays, China Standard Time
  • 98.8% of the connections occurred between 7am and midnight China Standard Time
    • 75% occurred between 8am to noon or between 2pm to 6pm
    • 15% occurred between 7pm and 10pm

The simplest conclusion based on these facts is that APT1 is operating in China, and most likely in Shanghai. Although one could attempt to explain every piece of evidence away, at some point the evidence starts to become overwhelming when it is all pointing in one direction. Our timestamp data, derived from active RDP logins over a two year period, matches the DOJ’s timestamp data, derived from a different source — active Dynamic DNS re-pointing over a five year period. These data sets show that APT1 is either operating in China during normal Chinese business hours or that APT1 is intentionally going to painstaking lengths to look like they are.

The data used to produce the charts above are archived in raw format and we are confident that any computer networking expert would certify them as genuine and non-fabricated in a court of law. But, that isn’t really the issue. The real issue is: will this activity continue and for how long? Regardless, FireEye remains focused on how these threats evolve over time, in order to reduce the time from “detect” to “fix”, as these and other actors continue targeting potential victims.

Real-World Tests, Real-World Results: Are You Building Another Maginot Line?

Today we are releasing “Cybersecurity’s Maginot Line: A Real-world Assessment of the Defense-in-Depth Model.” The report is a first-of-its kind analysis of real-world data spanning more than 1,217 organizations in 65 countries across more than 20 industries. It reveals a deeply flawed defense-in-depth model, at least as it’s commonly deployed. In short, most of today’s top-selling security tools fail to protect 97 percent of organizations that deploy them.

The only true test of a product is in a real-world setting. Our data comes from organizations testing FireEye network and email appliances, but not yet fully protected by the FireEye platform. Because FireEye sits behind all conventional security defenses, the tests provide a unique vantage point to observe other security layers in action.

In other words, any threats observed by FireEye in these tests have passed through all of an organization’s other security layers.

We call this state of affairs the new Maginot Line. That’s because it reminds us of France’s famed 940-mile string of deep-earth bunker fortresses, anti-tank obstacles, and barbed-wire entanglements built to fend of Germany in the run-up to World War II.

It was expensive and futile. Germany sidestepped the line using a novel blitzkrieg-style attack through Belgium. The French military, which had diverted much of its budget to the line, could not mount an effective defense.

Today, many organizations face a similar problem. They spend billions of dollars every year on defense-in-depth IT security architecture. And attackers are easily stepping around them.

As our report shows, it doesn’t matter what types of signature-based firewall, intrusion prevention system (IPS), Web gateway, sandbox, and endpoint systems make up your Maginot Line. Attackers are circumventing them all.

So what should organizations do? For one, they need a new approach to securing their IT assets. For many, that means reducing waste on redundant, backward-looking technology and redeploying those resources on defenses designed to find and stop today’s advanced attacks.

DoJ Indicts Chinese Military Hackers: First Impressions

Today, the US Department of Justice (DoJ) took actions previously unseen in the world of computer security. The press release announcing the activity noted the following:

“A grand jury in the Western District of Pennsylvania (WDPA) indicted five Chinese military hackers for computer hacking, economic espionage and other offenses directed at six American victims in the U.S. nuclear power, metals and solar products industries.”

The accompanying indictment begins with the following excerpt:

“From at least in or about 2006 up to and including at least in our about April 2014, members of the People’s Liberation Army (“PLA”), the military of the People’s Republic of China (“China”), conspired together and with each other to hack into the computers of commercial entities in the Western District of Pennsylvania and elsewhere in the United States.”

These two sentences are packed with meaning for anyone who has been working to counter the Chinese digital threat, either within, or on behalf of, victim organizations. First, the indictment zeroes in on the military aspect of the threat. DoJ isn’t talking about nebulous “Chinese hackers,” perhaps working as contractors for hire. These are PLA troops, some of whom are pictured in the indictment wearing their uniforms. Second, these sentences confirm the temporal span of the activity, roughly an eight year period. This is a sustained, persistent, resourced campaign. Third, they emphasize economic espionage against commercial American targets, not targets in the US military or intelligence communities. The US government has always been clear that it will not tolerate Chinese hacking to financially and scientifically accelerate Chinese economic growth.

For those of us who worked on exposing this threat over the years, the indictment contains many other relevant details. We read that the five defendants “worked together and with others known and unknown to the Grand Jury for the PLA’s General Staff, Third Department (“3PLA”), a signals intelligence component of the PLA, in a Unit known by the Military Unit Code Designator 61398 (“Unit 61398”), and in the vicinity of 208 Datong Road, Pudong District, Shanghai, China.” This is exactly the same unit, designation, and location identified in the 2013 Mandiant report, APT1: Exposing One of China’s Cyber Espionage Units. This statement is the first open, unclassified, official confirmation of the core attribution element in the Mandiant report. It shows that APT1 aka United 61398 aka the Second Bureau of the Third Department of the General Staff Directorate of the PLA is a threat to US economic and security interests.

There are many other aspects of the indictment that I find fascinating, but in the interest of time I will mention one other. Paragraph four states the following:

“During the period relevant to this Indictment, Chinese firms hired the same PLA Unit where the defendants worked to provide information technology services. For example, one SOE involved in trade litigation against some of the American victims mentioned herein hired the Unit, and one of the co-conspirators charged herein, to build a ‘secret’ database to hold corporate ‘intelligence.’”

This is a remarkable statement, because it may answer one of the burning questions those of us analyzing the problem have often asked: how does stolen Western data pass from the Chinese military to the Chinese private sector? According to the indictment, a State Owned Enterprise (SOE) simply hires Unit 61398 to provide IT services, and the military hackers leave the “intelligence” behind in a “database” for the benefit of the SOE.

As the story develops over the coming days, I will keep an eye on it and report back as newsworthy items appear.

Operation Saffron Rose

There is evolution and development underway within Iranian-based hacker groups that coincides with Iran’s efforts at controlling political dissent and expanding offensive cyber capabilities. The capabilities of threat actors operating from Iran have traditionally been considered limited and have focused on politically motivated website defacement and DDoS attacks.

Our team has published a report that documents the activities of an Iran-based group, known as the Ajax Security Team, which has been targeting both US defense companies as well as those in Iran who are using popular anti-censorship tools to bypass Internet censorship controls in the country.

This group, which has its roots in popular Iranian hacker forums such as Ashiyane and Shabgard, has engaged in website defacements since 2010. However, by 2014, this group had transitioned to malware-based espionage, using a methodology consistent with other advanced persistent threats in this region.

It is unclear if the Ajax Security Team operates in isolation or if they are a part of a larger coordinated effort. We have observed this group leverage varied social engineering tactics as a means to lure their targets into infecting themselves with malware. They use malware tools that do not appear to be publicly available. Although we have not observed the use of exploits as a means to infect victims, members of the Ajax Security Team have previously used exploit code in web site defacement operations.

The objectives of this group are consistent with Iran’s efforts at controlling political dissent and expanding offensive cyber capabilities, but we believe that members of the group may also be dabbling in traditional cybercrime. This indicates that there is a considerable grey area between the cyber espionage capabilities of Iran’s hacker groups and any direct Iranian government or military involvement.

Although the Ajax Security Team’s capabilities remain unclear, we believe that their current operations have been somewhat successful. We assess that if these actors continue the current pace of their operations they will improve their capabilities in the mid-term.

To view a full version of the report on “Operation Saffron Rose,” please visit: https://www.fireeyesolution.com/resources/pdfs/fireeye-operation-saffron-rose.pdf.

Managed Defense – Reducing the Time to Detect and Resolve Threats

Working in FireEye Managed Defense presents an interesting perspective into some of the most advanced threats. Our service meshes a team of experts with a powerful technology stack. We combine host- and network-based forensic technologies with highly experienced and skilled analysts, incident responders, and reverse engineers around the clock and across the globe. The foundation of Managed Defense is our partnership with our customers to detect evil and contain compromise. We work together to investigate the compromise, determine a remediation strategy, extract intelligence, and deploy new intelligence into our operations. This ability to leverage expertise to create intelligence and apply it consistently to the endpoint and to network traffic enables our team to adapt and respond quickly. In the face of a campaign like Operation Clandestine Fox, it ensures our clients are protected from even the most advanced attacker groups.

The last 10 days have shown us once again why our mission of defeating the adversary is so critical. On Friday, April 25, we discovered a new IE 0-day exploited as part of a campaign later dubbed Operation Clandestine Fox. In this post, we present an inside look into the discovery and exploitation of this vulnerability and how we were able to help not only the original Managed Defense customer but also others.

The Initial Detection

This story begins on April 25, when a group of our analysts working with a Managed Defense client detected an active APT backdoor using one of the many indicators of compromise (IOCs) we check for within Managed Defense

At first glance, it might have been reasonable to characterize the initial compromise as fairly typical. We knew at the time that the attackers had been able to deploy at least one backdoor, and were communicating interactively with it to escalate the attack. After containing the host, the usual questions emerged:

  • How was the machine compromised?
  • Was the scope of the compromise limited to a single host?
  • What did the attackers accomplish?
  • Who was the Threat Actor behind the attack?

That evening, a deeper analysis of the host revealed that the backdoor was resident only in memory and communicating out to remote attacker infrastructure. While we had seen similar malware variants, analysis of JavaScript and Flash objects from this host indicated that we were possibly at the forefront of discovering a previously unknown vulnerability being exploited.

Evaluating the malware and the tactics employed pointed to a threat group that we had seen before. This group had been the first group to have access to a select number of browser-based 0-day exploits (e.g. IE, Firefox, and Flash) in the past. They are extremely proficient at lateral movement and are difficult to track, as they typically do not reuse command and control infrastructure.

Expanding Detection Across Managed Defense

The new 0-day was, of course, the big news. But just as important to our Managed Defense customers were lesser-known details that we tend to dig up every day on threats big and small.

For instance, during the early stages of investigation, we produced evidence of the targeted spear phishing campaign that served as the initial attack vector. The campaign morphed four times, altering the content and remote locations of the payloads. Not only were we able to help our initial client detect and contain the threat, but continuously updating our applied intelligence led to other detections of the same campaign elsewhere.

Immediately after we deployed host-based indicators for the first-stage backdoor as well as network-based indicators for the command and control (C2) channels, we found a compromise at two additional Managed Defense customers. This meant we could pivot quickly into a focused investigation and response for our other customers – all of this in a matter of hours.

The analysis performed within the first few hours allowed our team to deploy these network-based indicators across the globe and ensure that we were positioned between our customers and their adversaries to detect the attack early in the attack lifecycle. Not long after, as an added countermeasure, we further augmented our detection capability by deploying host-based indicators specifically focused on rapidly surfacing additional variants of the first-stage backdoor. All told, we built new intelligence around the phishing emails, the backdoors used, use of the 0-day exploit, and evidence of backdoor installation via an in-memory mutex. This is handy as memory-only enterprise sweeps are much faster than filesystem ones.

Within 24 hours, we had gathered and reviewed results from nearly a million endpoints across the Managed Defense customer base. The additional activity we observed solidified our theory that at least one APT threat actor group was broadly and aggressively targeting an array of key industries, including aerospace, energy, financial, and the federal sector.

We published all of the intelligence we could glean as the investigation progressed so our customers could have insight on the threat actor and their tactics. This also supported customers discussing the threat with their peer groups to help drive the ultimate goal of protection, remediation and recovery.

Our work here resulted in new detection capabilities to find compromise through the attack lifecycle, ranging from initial targeting to successful exploitation and subsequent escalation through the establishment of more persistent backdoors. Thanks to our rapid deployment of relevant intelligence across our platform and the quick action of our clients, the eleven Managed Defense clients targeted by this campaign were all able to successfully contain the compromises at the initial stage, preventing further attacker activity within client environments.

Looking Back (and Forward)

Given the relative ubiquity of the vulnerability and the scope of the opportunity presented to attackers, we were unsurprised to see the attackers carry on through the week of April 28th. The Managed Defense team continued to work with our customers in a few ways:

  • We continued to monitor our customers’ global infrastructure 24×7 for related activity;
  • Over the course of 7 days, we published compromise reports that described related attacker activity at a dozen unique enterprises, spanning multiple industries;
  • We were easily able to pivot into Incident Response where necessary and applied additional horsepower to analyze a variety of forensic artifacts and accelerate response time;
  • We published additional intelligence to our customers so that each team could augment their own legacy detection capabilities and potentially prevent compromise.

With Microsoft’s recent patch release, we’ve already witnessed a shift in attacker activity, including a substantial decrease in phishing activity. This once wide-open door is closing shut, but we know our adversaries’ unrelenting search for new attack surfaces undoubtedly continues. For those of us in Managed Defense, events like those detailed above are common occurrences, but they nonetheless serve as inspiring reminders of the gravity of our mission: to help protect our clients from skilled and determined adversaries. The best analysts in the industry, a global deployment of detection technology, superior threat intelligence, and an ability to rapidly escalate and deploy that new intelligence, when combined with the close partnerships we have with our clients ensures we are well prepared for the inevitable next round of attacks.

 

Live from Infosecurity Europe 2014: Cybersecurity Experts Come Together

Infosecurity Europe 2014 was the place to be for any major player in the world of cybersecurity, and live from the show floor; the FireEye Blog team had a front seat to some exciting conversations. Paul Dwyer, director at FireEye, had the opportunity to sit down with a number of influencers and ask questions that were on all of our minds.

In this first podcast in the series, Amar Singh, senior analyst at KuppingerCole, and founder of ARK Advisors discusses the threat of malware, and also touches on the subject of industrial espionage. Click here to listen to the full podcast. Bruce Hallas, founder and curator of The Analogies Project, a not-for-profit venture designed to help the information security community communicate and engage more effectively with stakeholders, joined Paul in our next podcast. Hallas discussed the significance of generational cybersecurity, and outlined the key behaviors and security working practices of generations Y and Z. Click here to listen to the full discussion.

First Base Technologies CEO Pete Wood also sat down with us for a chat, and shared his thoughts on how an information security function evolves to become business-led. Mr. Wood was also asked about the current business security model, and whether cybersecurity should be considered a Board Level issue. Click here to listen.

Finally, FireEye Director of Technology Strategy EMEA, Jason Steer had the chance to speak with Brian Honan from BH Consulting about the recent Internet Explorer (IE) browser vulnerability, as well as the importance of separating networks into different segments. Listen to the full podcast here.

Did you attend Infosecurity Europe 2014? Chime in and let us know what you thought of the event and the topics discussed. Leave us a comment below.

Reporting on Key Issues in Cybersecurity: Panel Discussion with Renowned EMEA Reporters

Last week, FireEye held a panel podcast featuring renowned reporters covering Europe in advance of the highly anticipated Infosecurity Europe conference.

The panel includes reporters from some of the most credible publications covering information security, including Eleanor Dallaway from Infosecurity Magazine, John Leyden from The Register, Tom Brewster, a freelance journalist for TechWeek Europe and Guardian, and Dan Raywood, editor of IT Security Guru.

In the podcast the panelists discuss key issues in cybersecurity today, including the recent Heartbleed controversy. They also touch on why Infosecurity Europe is crucial for the information security community, and hint at what we can expect from the big event.

To listen to the full podcast, click here.

FireEye Enters Agreement to Acquire nPulse Technologies

Today, I’m excited to announce that we’ve entered an agreement to acquire nPulse Technologies, the performance leader in network forensics. The acquisition is expected to close during the second quarter of 2014, subject to standard closing conditions. nPulse has the fastest solution available for high-speed full packet capture and indexing. By combining the nPulse products with the FireEye platform, we’re building enterprise forensics capabilities that will enable incident investigation and remediation that no other security vendor can match. When combined with Mandiant services and the services capabilities of our partners, we’ll be able to provide customers complete visibility into the network with quality analytics that accelerate the path from detection to resolution. This acquisition is a vital part of our long-term strategy to build a single security platform that protects against the most advanced threats and offers customers one solution to detect, contain, resolve and prevent threats.

With the acquisition, FireEye will further expand its security platform with the following:

  • FireEye will offer the industry’s first Enterprise Forensics solution with a unified view of network to endpoint forensics, enabling enterprises to minimize risk and drive down mean time to resolution.
  • The Enterprise Forensics solution, coupled with the FireEye threat analytics solution, will form a comprehensive intelligence platform.
  • The FireEye Network Threat Prevention Platform combined with newly introduced IPS capabilities and the addition of nPulse’s forensics will offer a comprehensive threat management platform.
  • The Enterprise Forensics solution together with FireEye Managed Defense™ will enable the industry’s most advanced managed service capabilities, bringing together deep visibility and rich context from Enterprise Forensics with active defense capabilities of the Managed Defense portfolio.

The New Reality of IT Security
Our Mandiant services team has investigated thousands of breaches and from this experience we know that no matter how good your defenses, with users in the system, every organization has some malicious code within their network. In fact, we know the median number of days attackers were present on a victim’s network before being discovered was 229 days in 2013. But today, when a data breach can result in being called to testify in front of Congress, every organization should be prepared to answer questions about how an attacker got into their network and what data was impacted. Preventing malicious code from entering the network is always key, but now we need to know more - when the malicious code appeared, how the network was compromised and if any data was removed. This is the new reality of enterprise security.

Enterprise Forensics - A Black Box For Your Network

Previously adding enterprise forensics involved building a customized solution that correlated data from multiple point products monitoring different parts of the network and across endpoints. Overwhelmed by cost and complexity, many organizations simply put this off, leaving a wide hole in their IT security and response capabilities. After entering into a technology partnership with nPulse Technologies earlier this year, we saw how our joint customers benefited from bringing together nPulse network information with FireEye threat intelligence and endpoint data.

With this acquisition, FireEye will combine nPulse network forensics with the endpoint products acquired from Mandiant to incorporate attack information from the host, endpoint, network and cloud. We like to think of enterprise forensics as adding a flight data recorder – or a black box – to the network. With complete visibility into the network, the FireEye platform will be able to produce higher quality alerts to help protect against threats as well as quickly quantify the impact of a breach following the discovery of malware on a network. With big-data analytics and real-time capabilities, FireEye will offer enterprise forensics that help answer the most important questions an organization has after a breach.

nPulse extends our reach into an organization’s history because it can log all network activity for as long as they choose to retain that data. With the industry’s fastest lossless, intelligent capture and retrieval, nPulse gives us the ability to “go back in time” to see the full extent of how malicious code behaved on the network. By being the first to deliver end-to-end (network and endpoint) detection and forensics at scale, FireEye enables enterprises to minimize risk by quantifying the impact of a breach while accelerating detection and resolution from days to a matter of minutes. For our Mandiant team and partners, this means we can deliver better service and more comprehensive incident response capabilities.

And most importantly, by reducing incident investigation time, providing validated breach information and improving the quality of alerts, our customers and clients can reduce their exposure to attacks while substantially reducing operational expenses.

At FireEye we’re building the most comprehensive security platform and I look forward to welcoming the nPulse Technologies team to the FireEye family. In the short term after the acquisition, nPulse will continue to operate normally and current customers should expect no disruption in current capabilities and service. Over the coming months after the acquisition, we’ll work to combine the nPulse products with the FireEye platform and bring enterprise forensics to all our customers and partners. Once again, FireEye is leading the way to solve the most complex and time-consuming security challenges.

 

Forward-Looking Statements
This blog post contains forward-looking statements about the expectations, beliefs, plans, intentions and strategies of FireEye relating to its pending acquisition of nPulse. Such forward-looking statements include statements regarding the impact of the pending acquisition of nPulse on FireEye’s competitive position, future product offerings and potential benefits of current and future product offerings. These statements reflect the current beliefs of FireEye and are based on current information available to us as of the date hereof, and FireEye does not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made. The ability of FireEye to achieve these business objectives involves many risks and uncertainties that could cause actual outcomes and results to differ materially and adversely from those expressed in any forward-looking statements. These risks and uncertainties include market adoption of FireEye’s virtual machine-based security platform; the termination of FireEye’s pending acquisition of nPulse if FireEye and nPulse fail to satisfy the conditions for closing in the definitive agreement; the failure to achieve expected synergies and efficiencies of operations between FireEye and nPulse; the ability of FireEye and nPulse to successfully integrate their respective technologies, products, personnel and operations; FireEye’s ability to attract and retain new customers and expand and train its sales force; the failure to timely develop and achieve market acceptance of combined products and services; the potential impact on the business of nPulse as a result of the pending acquisition; the loss of any nPulse customers; the ability to coordinate strategy and resources between FireEye and nPulse; the ability of FireEye and nPulse to retain and motivate key employees of nPulse; general economic conditions; as well as those risks and uncertainties included under the captions “Risk Factors” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” in FireEye’s Form S-1 filed with the Securities and Exchange Commission on April 22, 2014, which is available on the Investor Relations section of FireEye’s website at investors.fireeye.com and on the SEC website at www.sec.gov. Any future product, feature, or related specification that may be referenced in this blog post are for information purposes only and are not commitments to deliver any technology or enhancement. FireEye reserves the right to modify future product or service plans at any time.