Home > Security News > McAfee to acquire Solidcore Systems for whitelisting
Security News:
EMAIL THIS

McAfee to acquire Solidcore Systems for whitelisting

By Robert Westervelt, News Editor
15 May 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

McAfee Inc. plans to acquire Solidcore Systems Inc. in a $47 million deal that would add whitelisting technology to McAfee's software to protect embedded systems such as ATMs and point of sale devices.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

Solidcore sells dynamic whitelisting technology, which ensures that only good executable code can run on protected systems. The technology is used to protect servers, endpoints, embedded devices and mobile devices. It is used in many ATM's, point-of-sale terminals and Supervisory Control and Data Acquisition (SCADA) systems.

According to the terms of the deal, McAfee will pay $33 million in cash up front for Solidcore and an additional $14 million if certain financial targets are met. McAfee said it would incorporate Solidcore into its Risk and Compliance business unit.
Whitelisting:
Best practices for using restriction policy whitelists: Ed Skoudis discusses which systems should be considered for software restriction policy whitelists, and unveils how whitelisting can improve security.

The value of application whitelists: Although some may find Windows Vista's User Account Control feature annoying, it is really a variation of a security mechanism that is now re-emerging: the application whitelist.

Symantec CEO preaches new security model: In his first RSA Conference keynote as Symantec Corp.'s CEO, Enrique Salem made the case for an integrated approach to information security.

Whitelisting technology narrows the scope of many embedded systems to ensure that an attacker can't install malicious code, said Phil Hochmuth, a senior analyst at the Yankee Group.

"Whitelisting ensures the only thing those devices are doing are exactly the services you want to deliver," Hochmuth said. "In some ways, it should be more of a feature or component of a larger security product or offering as opposed to a stand alone type of technology."

Whitelisting has gained some prominence in recent years as some have sought an alternative to traditional antivirus software, said Andrew Braunberg, enterprise software and security research director at CurrentAnalysis Inc. Braunberg said Microsoft has seen the benefits of whitelisting. Solidcore competitor SignaCert is working with Microsoft to exchange whitelist methods for application developers to make sure any application running on top of Windows could be checked for integrity before it is run. Symantec said it would also use whitelisting in the upcoming version of its Norton antivirus software to improve performance.

"This is a good play for McAfee with PCI driving lot of security spend right now," Braunberg said. "It's also another sign that whitelisting is becoming more mainstream."
SearchSecurity radio:

McAfee said combining whitelisting with its blacklisting features adds real-time enforcement. In addition Solidcore offers File Integrity Monitoring (FIM) technology for Payment Card Industry Data Security Standards (PCI DSS) compliance. The technology could be used to ensure that companies maintain compliance.

McAfee said the acquisition will also result in new configuration management software as well as additional capabilities to secure virtual environments. In April, Solidcore released whitelisting that supports Microsoft Hyper-V. The technology can also be used in VMware implementations.

"Solidcore's industry-leading compliance and protection solutions will extend the current McAfee security portfolio beyond signature-based anti-malware with the addition of dynamic whitelisting and application trust technology," Dave DeWalt, president and chief executive officer, McAfee said in a statement.

Tags: Vulnerability Risk AssessmentConfiguration Management PlanningSecurity Testing and Ethical HackingSecuring Productivity ApplicationsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Vulnerability Risk Assessment
Screencast: How to launch an OpenVAS scan
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
Newest malware threats
Are Web application penetration tests still important?
PCI compliance requirement 6: Systems and applications
Cybercrime and threat management
The Pipe Dream of No More Free Bugs
Vulnerability Risk Assessment Research

Configuration Management Planning
Integrated change management reduces security risks
EMC adds configuration management with Configuresoft acquisition
Product Review: Shavlik's NetChk Compliance
Security services: Fiberlink's MaaS360 Mobility Platform
CISSP Essentials training: Domain 10, Operations Security
5 Steps for Developing Strong Change Management Program Best Practices
Misconfiguration issues could have contributed to Hannaford breach
Misconfigured networks create huge security risks
Private sector should learn from government insecurity
Compliance drives security configuration management
Configuration Management Planning Research

Security Testing and Ethical Hacking
H.D. Moore speaks about Metasploit Project deal, Release 3.3
Could Metasploit popularity erode?
Metasploit Project acquired by vulnerability management firm Rapid7
Should management processes change based on a patch release schedule?
Does an EULA make it truly illegal to decompile software?
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Security testing firm uncovers XML vulnerabilities
Screencast: Samurai offers pen-testing nirvana
The requirements needed to make an external penetration test legal
The Pipe Dream of No More Free Bugs

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts