Conceived by Intrinsic Security, FireBreak AntiWorm is an enterprise security service that provides active defense against automatically propagating network worms -- without the need for antivirus definitions. The system employs a distributed, scalable network of "tarpits" or "sticky honeypots" and a centrally managed reporting, control, and notification system to trap worms and help you identify their source.
FireBreak AntiWorm helps enterprise network administrators bridge the period of vulnerability known as the "patch gap" -- the time between announcement of an exploitable vulnerability and enterprise-wide deployment of patches to fix it. By trapping worms, slowing their spread, and alerting your staff to the worm sources, FireBreak AntiWorm reduces downtime due to worms.
Solution
Intrinsic Security approached illumineX seeking a technology partner to help them jumpstart a groundbreaking network security product.
illumineX helped Intrinsic Security select a technology foundation for the FireBreak AntiWorm system. Our enterprise distributed systems architects and software developers worked jointly with architects and engineers from our WebObjects Strategic Partner, CodeFab, to design and build the initial system. illumineX engineers deployed and managed the system on a large enterprise network.
In the first year of operation on a network with several Class B address blocks and nearly fifty thousand devices, worm outbreaks were detected by FireBreak AntiWorm an average of two days before they were detected by an industry leading IDS system. Combined with this early warning, the vital Intrusion Suppression capability of FireBreak AntiWorm allowed the very first client to reap significant gain from the system. Outbreaks were detected sooner and contained more easily.
These early results demonstrated product value early in the lifecycle of the product, providing technology validation to early customers, investors, and reseller partners for Intrinsic Security.