February 21, 2003

Nothing to snort at

Security company Sourcefire has built a profitable business around open-source Snort technology

A common question raised about open source is, "How can you make money from free software?" It's a good question, but as Martin Roesch can attest, it does have a good answer.

If you happen to work in the security field, you might know Roesch's name or at least his work. You see, Roesch is the lead developer of Snort (www.snort.org), an incredibly popular open-source intrusion detection system.

Roesch became aware of the open-source movement in the 1990s. He read Eric Raymond's work, The Cathedral and the Bazaar, which described the community dynamic behind open source, and became fascinated with the concept of creating a "category killer" — a piece of software that creates a new standard in a particular area.

So he began creating an intrusion-detection tool, which he dubbed "Snort." After receiving much feedback and encouragement from the open-source community, he worked to expand the project, adding features that users wanted. Before long, Snort had matured to the point where it was looking like a potential category killer for intrusion detection.

But as Snort gained popularity in security circles, Roesch soon became aware of business issues regarding the project. Corporations wanted to use Snort, but they also wanted to buy Snort support contracts from a corporation backing the software. Businesses also wanted to see things such as simple Web interfaces and user training classes so that intrusion detection would become more about using security software and less about having a brilliant security person on staff who could figure out the best way to use complex tools.

Roesch decided this was an excellent business opportunity, so he founded the company known as Sourcefire (www.sourcefire.com) in 2001. Says Roesch, "We don't sell intrusion detection; we sell everything else."

Sourcefire provides the desired support and consulting functions to organizations using Snort, while providing tools to simplify the configuration process and manage the large quantity of data that Snort gathers. Among the additional capabilities offered by Sourcefire is an integrated database system, so there is no longer any need to labor to load the raw data in some external database to make it usable for analysis. Advances such as these make Snort much more appealing to the enterprise.

Sourcefire may have started as a handful of people operating out of Roesch's living room, but the business quickly caught on. In just two years, Sourcefire has grown to over 50 employees in three U.S. locations with established international distribution channels.

Sourcefire's example shows one way that businesses can grow around open-source software. By focusing on selling services, add-ons, and expertise, it is possible to grow a viable business. Sourcefire's customers win because they get the services and support they need for intrusion detection. Snort users win because Sourcefire continues to develop Snort, releasing improvements under an open-source license. Sourcefire wins because it can profit and grow. And the Internet wins because all sites have access to a powerful tool to aid in their security.

Now that's what I call a great solution.

Close

On Twitter now

Business

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Business Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2009 Infoworld, Inc.