SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Razorback project targets malware, zero-day exploits

Razorback project targets malware, zero-day exploits

By:  Ellen Messmer  On: 28 Jul 2010 For: Network World (U.S.) Creator
 

Sourcefire Inc.’s open source security project includes a defense routing system and could send potentially malicious files to a forensics tool. It is not designed to directly block malware but could work with anti-virus tools

Sourcefire Inc., best known for its Snort intrusion-prevention technology, Tuesday is unveiling a new open source  project called Razorback that's designed to spot malware and especially zero-day exploits.

"We want others to test it to see if our idea about this new protection framework is as innovative as we think it is," says Matt Watchinski, senior director on the Sourcefire vulnerability research team.

Columbia, Md.-based Sourcefire says Razorback is designed with a "defense routing system" that monitors for certain traffic types, such as HTTP, Web or SMTP-based e-mail, in order to forward mirrored data to any means of security analysis system that can be plugged into it.
More from IT World Canada
 
 
 
Security tools supporting Razorback could be either open-source or proprietary.

Razorback monitoring could be integrated directly into security gateways as well as deployed on standalone servers. A typical place to put the main Razorback monitoring component would be directly behind an antivirus filtering point, according to Sourcefire, which also shepherds the open source Clam A/V toolkit. Razorback could also work with security information and event management products.

Razorback "knows the resources in the organization that might have a specific interest in files, such as PDFs, for example," which could have malicious code embedded in them, Watchinski says. Razorback-monitored PDF files could be sent to a forensics tool that could analyze them for zero-day vulnerabilities or possible exploit code.

Razorback's "defense-routing system" is not necessarily real-time and it's not yet designed to directly block suspicious data.
The underlying idea of the open source project is to set up multiple paths to simultaneously transmit any mirrored data of specific security concern onward to designated security points for analysis, output and feedback to Razorback. On a more advanced level, these third-party Razorback-supported tools, after security analysis, could in theory assist Razorback in recommendations to take protective blocking measures or update threat determinations.

Today, Razorback has been developed to work with open source Snort and Clam A/V as well as other open source code, such as Postfix.

Sourcefire has no publicly stated intention as of yet to launch a commercial product based on Razorback. The company does say the defense sector is interested in development of the kind of defense-routing system that Razorback seeks to foster through open source.


Sign up for our Newsletters

 












Print |  Views: 1693   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




ellen messmer Ellen Messmer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

How not to get sued by open source coders
How not to get sued by open source codersA Fasken Martineau DuMoulin lawyer says many firms do not teach workers how to manage open source software. CIPPIC weighs in
Appeal court rules in favour of open source
Appeal court rules in favour of open sourceA court ruling in the U.S. says open source licensors have a say in how their software is modified and distributed. How developers can stay on the right side of the law
Why buy commercial products when there are open-source security tools?
Why buy commercial products when there are open-source security tools?Open source security tools abound, so take advantage of them and avoid paying for commercial products if open source fits your needs. That was the message from Matthew Luallen, president of consulting firm Sph3r3, who spoke at Monday's InfoSec Conference.
We’re not thieves. We just can’t read contracts (McAfee and Open Source)
i have borrowed a headline from an earlier posting by shane schick to discuss something i saw this week. mcafee filed a report last month with the securities and exchange commission that made a few statements about risks associated with their use of some open source software. these s
blog comments powered by Disqus