FireEye

FireEye

Targeted cyber attack countermeasures "FireEye Network Security"

Network Security uses a unique virtual execution engine (MVX) that does not rely on signature matching and intelligence-driven detection technology to deal with unknown and advanced attacks. By implementing Network Security, you can achieve faster detection, more accurate alerts, and noise reduction than ever before. By detecting threats that cannot be dealt with by conventional security solutions, customers can focus on responding to alerts about critical threats while reducing the operational management burden associated with frequent false positives.

Web traffic (HTTP) entrance countermeasures

Network Securityanalyzes and detects attacks from web traffic with its proprietary Virtual Execution Engine (MVX). Attacks from web traffic mainly include attacks that exploit vulnerabilities that occur while users are browsing the Internet, malware downloads, drive-by downloads, and watering hole attacks.

FireEyeNetwork Security analyzes traffic using its unique flow analysis technology, so it can accurately detect advanced malware that is difficult to detect by inspecting individual files, such as malware that uses drive-by downloads.
By linking with alliance partner products, it also supports inspection of SSL (encrypted) communication.

Exit measures for all communications (regardless of port number)

The primary purpose of Network Security is to prevent information leaks by detecting and blocking infected terminals from communicating with C&C servers. Network Security can detect and block infection based on new C&C server information found in MVX in the appliance and signatures from FireEye's cloud DTI.

Deployment options

Inline (L2 transparent, Fail-Open compatible)
Monitoring (SPAN/TAP/Mirror)