FireEye

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
FireEye, Inc.
Public
Traded asNASDAQFEYE
Russell 1000 Component
IndustryComputer security
Founded2004
FounderAshar Aziz
HeadquartersMilpitas, California, United States
Key people
Kevin Mandia, CEO
ProductsCyber Security Hardware and Software
  • Email Security
  • Endpoint Security
  • File Security
  • Cross Vendor Management Interface
ServicesIT security Consulting Services
  • Incident Response
  • Vulnerability Testing
  • Preparedness Assessment
Revenue
  • Increase US $831 million
(2018)
Total assetsUS $2.69 billion (2018)
Number of employees
~3,000 (2017)[1]
Websitefireeye.com

FireEye is a public cybersecurity company headquartered in Milpitas, California.[2] It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks.[3] FireEye was founded in 2004. Initially, it focused on developing virtual machines that would download and test internet traffic before transferring it to a corporate or government network. The company diversified over time, in part through acquisitions. In 2014, it acquired Mandiant, which provides incident response services following the identification of a security breach. FireEye went public in 2013. USAToday says FireEye "has been called in to investigate high-profile attacks against Target, JP Morgan Chase, Sony Pictures, Anthem and others".[4] Yahoo Finance says FireEye is again the fastest-growing cyber security firm, according to Deloitte.[5]

Corporate history[edit]

FireEye was founded in 2004 by Ashar Aziz, a former Sun Microsystems engineer.[3][6] It received an early investment from the CIA's investment arm, In-Q-Tel, in 2009.[7] FireEye's first commercial product was not developed and sold until 2010.[8] That same year, FireEye expanded into the Middle-East.[9] This was followed by the opening of new offices in Asia Pacific in 2010,[10] Europe in 2011[11] and Africa in 2013.[12]

In December 2012, founder Aziz stepped down as CEO and former McAfee CEO David DeWalt was appointed to the position.[2][13][14] DeWalt was recruited in order to prepare the company for an initial public offering (IPO).[8][15] The following year, FireEye raised an additional $50 million in venture capital, bringing its total funding to $85 million.[16][17] In late 2013, FireEye went public, raising $300 million.[13]

At the time, FireEye was growing rapidly.[13] It had 175 employees in 2011, which grew to 900 by June 2012.[13] Revenues multiplied eight-fold between 2010 and 2012.[13] However, FireEye was not yet profitable, due to high operating costs, such as research and development expenses.[13]

In January 2014, FireEye acquired Mandiant for $1 billion.[18] Mandiant was a private company founded in 2004 by Kevin Mandia that provided incident response services in the event of a data security breach.[18][19] Mandiant was known for investigating high-profile hacking groups.[18] Before the acquisition, FireEye would often identify a security breach, then partner with Mandiant to investigate who the hackers were.[18] Mandiant became a subsidiary of FireEye.[18]

In late 2014, FireEye initiated a secondary offering, selling another $1.1 billion in shares, in order to fund development of a wider range of products.[20] Shortly afterward, FireEye acquired another data breach investigation company, nPulse, for approximately $60 million.[21] By 2015, FireEye was making more than $100 million in annual revenue, but was still unprofitable,[22] largely due to research and development spending.[6]

In January 2016, FireEye acquired iSIGHT Partners for $275 million.[23] iSIGHT was a threat intelligence company[24] that gathered information about hacker groups and other cybersecurity risks.[25] This was followed by the acquisition of Invotas, an IT security automation company.[26][27] DeWalt stepped down as CEO in 2016 and was replaced by Mandiant CEO and former FireEye President Kevin Mandia.[2][6] Afterwards, there was a downsizing and restructuring in response to lower-than-expected sales, resulting in a layoff of 300-400 employees.[28][29] Afterwards, profit and revenue increased on account of shifts to a subscription model and lower costs.[30]

Acquisitions[edit]

Announcement date Company Business Deal size References
December 30, 2013 Mandiant Information security $1 billion [31]
May 8, 2014 nPulse Technologies Information security $60 million [32]
January 2016 iSight Partners Cyber Threat Intelligence $275 Million [33]
February 2016 Invotas Security Orchestration [34]
October 2017 The Email Laundry Email Security [35]
January 2018 X15 Software Machine and Log Data Management $15 million in equity and $5 million in cash [36]

Products and services[edit]

FireEye started out as a "sandboxing" company.[37] Sandboxing is where incoming network traffic is opened within a virtual machine to test it for malicious software, before being introduced into the network.[18][22] FireEye's products diversified over time, in part through acquisitions.[2][37] In 2017, FireEye transitioned from primarily selling appliances, to a software-as-a-service model.[38]

FireEye sells technology products including network, email and endpoint security, a platform for managing security operations centers called Helix, consulting services primarily based on incident response, and threat intelligence products.[39][40]

The Central Management System (CMS) consolidates the management, reporting, and data sharing of Web MPS (Malware Protection System), Email MPS, File MPS, and Malware Analysis System (MAS) into a single network-based appliance by acting as a distribution hub for malware security intelligence.[41]

The FireEye Cloud crowd-sources Dynamic Threat Intelligence (DTI) detected by individual FireEye MPS appliances, and automatically distributes this time sensitive zero-day intelligence globally to all subscribed customers in frequent updates. Content Updates include a combination of DTI and FireEye Labs generated intelligence identified through research efforts.

Operations[edit]

FireEye is known for uncovering high-profile hacking groups.[2]

2008-2014[edit]

In October/November 2009, FireEye participated in an effort to take down the Mega-D botnet (also known as Ozdok).[42] On March 16, 2011, the Rustock botnet was taken down through an action by Microsoft, US federal law enforcement agents, FireEye, and the University of Washington.[43] In July 2012, FireEye was involved in analysis[44] of the Grum botnet's command and control servers located in the Netherlands, Panama, and Russia.[citation needed]

In 2013, Mandiant (before being acquired by FireEye) uncovered a multi-year espionage effort by a Chinese hacking group called APT1.[45]

In 2014, the FireEye Labs team identified two new zero-day vulnerabilities – CVE-2014-4148 and CVE-2014-4113 – as part of limited, targeted attacks against major corporations. Both zero-days exploit the Windows kernel. Microsoft addressed the vulnerabilities in their October 2014 Security Bulletin.[46] Also in 2014, FireEye provided information on a threat group it calls FIN4. FIN4 appears to conduct intrusions that are focused on a single objective: obtaining access to insider information capable of making or breaking the stock prices of public companies. The group has targeted hundreds of companies, and specifically targets the emails of C-level executives, legal counsel, regulatory, risk, and compliance personnel, and other individuals who would regularly discuss confidential, market-moving information.[47] Also in 2014, FireEye released a report focused on a threat group it refers to as APT28. APT28 focuses on collecting intelligence that would be most useful to a government. Specifically, FireEye found that since at least 2007, APT28 has been targeting privileged information related to governments, militaries, and security organizations that would likely benefit the Russian government.[48]

2015[edit]

In 2015, FireEye confirmed the existence of at least 14 router implants spread across four different countries: Ukraine, Philippines, Mexico, and India. Referred to as SYNful Knock, the implant is a stealthy modification of the router’s firmware image that can be used to maintain persistence within a victim’s network.[49]

In September 2015, FireEye obtained an injunction against a security researcher attempting to report vulnerabilities in FireEye Malware Protection System.[50]

In 2015, FireEye uncovered an attack exploiting two previously unknown vulnerabilities, one in Microsoft Office (CVE-2015-2545) and another in Windows (CVE-2015-2546). The attackers hid the exploit within a Microsoft Word document (.docx) that appeared to be a résumé. The combination of these two exploits grant fully privileged remote code execution. Both vulnerabilities were patched by Microsoft.[51]

In 2015, the FireEye as a Service team in Singapore uncovered a phishing campaign exploiting an Adobe Flash Player zero-day vulnerability (CVE-2015-3113). Adobe released a patch for the vulnerability with an out-of-band security bulletin. FireEye attributed the activity to a China-based threat group it tracks as APT3.[52]

2016[edit]

In 2016, FireEye announced that it has been tracking a pair of cybercriminals referred to as the “Vendetta Brothers.” The company said that the enterprising duo uses various strategies to compromise point-of-sale systems, steal payment card information and sell it on their underground marketplace “Vendetta World.”[53] In mid-2016, FireEye released a report on the impact of the 2015 agreement between US President Barack Obama and Chinese President Xi Jinping that neither government would “conduct or knowingly support cyber-enabled theft of intellectual property” for an economic advantage. The security firm reviewed the activity of 72 groups that it suspects are operating in China or otherwise support Chinese state interests and determined that, as of mid-2014, there was an overall decrease in successful network compromises by China-based groups against organizations in the U.S. and 25 other countries.[54]

In 2016, FireEye announced that it had identified several versions of an ICS-focused malware – dubbed IRONGATE – crafted to manipulate a specific industrial process running within a simulated Siemens control system environment. Although Siemens Product Computer Emergency Readiness Team (ProductCERT) confirmed to FireEye that IRONGATE is not viable against operational Siemens control systems and that IRONGATE does not exploit any vulnerabilities in Siemens products, the security firm said that IRONGATE invokes ICS attack concepts first seen in Stuxnet.[55]

On May 8, 2016, FireEye detected an attack exploiting a previously unknown vulnerability in Adobe Flash Player (CVE-2016-4117). The security firm reported the issue to the Adobe Product Security Incident Response Team (PSIRT) and Adobe released a patch for the vulnerability in just four days later.[56]

In 2016, FireEye discovered a widespread vulnerability affecting Android devices that permits local privilege escalation to the built-in user “radio”, making it so an attacker can potentially perform activities such as viewing the victim’s SMS database and phone history. FireEye reached out to Qualcomm in January 2016 and subsequently worked with the Qualcomm Product Security Team to address the issue.[57]

In 2016, FireEye provided details on FIN6, a cyber criminal group that steals payment card data for monetization from targets predominately in the hospitality and retail sectors. The group was observed aggressively targeting and compromising point-of-sale (POS) systems, and making off with millions of payment card numbers that were later sold on an underground marketplace.[58]

FireEye's firm Mandiant was hired by Russia's Alfa Bank to locate information on connections to Trump's servers and was also hired by Equifax to determine source of data breach and in both cases, Mandiant did not find anything conclusive. [59][60]

2017[edit]

In 2017, FireEye detected malicious Microsoft Office RTF documents leveraging a previously undisclosed vulnerability, CVE-2017-0199. This vulnerability allows a malicious actor to download and execute a Visual Basic script containing PowerShell commands when a user opens a document containing an embedded exploit. FireEye shared the details of the vulnerability with Microsoft and coordinated public disclosure timed with the release of a patch by Microsoft to address the vulnerability.[61]

2018[edit]

In 2018, FireEye helped Facebook identify 652 fake accounts.[62]


References[edit]

  1. ^ FireEye 2017 Annual Report, FireEye
  2. ^ a b c d e Hackett, Robert (May 6, 2016). "FireEye Names New CEO". Fortune. Retrieved September 18, 2018.
  3. ^ a b Springer, P.J. (2017). Encyclopedia of Cyber Warfare. ABC-CLIO. p. 109. ISBN 978-1-4408-4425-6. Retrieved September 18, 2018.
  4. ^ "FireEye has become Go-to Company for Breaches". USA Today. Retrieved 21 May 2015.
  5. ^ "FireEye Fastest Growing Cyber Security". Yahoo Finance. Retrieved 2015-11-20.
  6. ^ a b c Anderson, Mae (August 24, 2018). "FireEye is tech firms' weapon against disinformation, staffed with 'the Navy SEALs of cyber security'". latimes.com. Retrieved September 18, 2018.
  7. ^ Takahashi, Dean (November 18, 2009). "CIA's In-Q-Tel funds FireEye anti-botnet security firm". VentureBeat. Retrieved September 18, 2018.
  8. ^ a b "FireEye shares double as hot security firm goes public". USA TODAY. September 20, 2013. Retrieved September 22, 2018.
  9. ^ Enzer, Georgina. "FireEye Inc steps into the Middle East". ITP.net. Retrieved September 18, 2018.
  10. ^ "Security Watch: FireEye appoints first ever Asia Pac president". CSO. November 15, 2018. Retrieved November 15, 2018.
  11. ^ Brewster, Tom (March 17, 2011). "FireEye looks to break into UK". IT PRO. Retrieved September 18, 2018.
  12. ^ Doyle, Kirsten (August 7, 2013). "FireEye opens local office". ITWeb. Retrieved September 22, 2018.
  13. ^ a b c d e f Owens, Jeremy C.; Delevett, Peter (September 20, 2013). "FireEye's price more than doubles on Wall Street after eye-popping IPO". The Mercury News. Retrieved September 22, 2018.
  14. ^ "FireEye names former McAfee exec Dave DeWalt as CEO, plans IPO". Reuters. November 28, 2012. Retrieved September 18, 2018.
  15. ^ Kelly, Meghan (August 5, 2013). "FireEye brings more legitimacy to new security solutions with IPO filing". VentureBeat. Retrieved September 22, 2018.
  16. ^ Westervelt, Robert (January 10, 2013). "FireEye Scores $50M Funding, Beefs Up Executive Team". CRN. Retrieved September 22, 2018.
  17. ^ Bort, Julie (January 10, 2013). "Now Worth $1.25 Billion, FireEye Is The Next Hot Enterprise Startup To Watch". Business Insider. Retrieved September 22, 2018.
  18. ^ a b c d e f Perlroth, Nicole; Sanger, David (January 3, 2014). "FireEye Computer Security Firm Acquires Mandiant". The New York Times. Retrieved September 18, 2018.
  19. ^ Reuters (January 2, 2014). "FireEye Buys Mandiant For $1 Billion In Huge Cyber Security Merger". Business Insider. Retrieved September 22, 2018.
  20. ^ Merced, Michael J. de la (March 10, 2014). "With Its Stock Riding High, FireEye Sells More Shares for $1.1 Billion". DealBook. Retrieved September 22, 2018.
  21. ^ Miller, Ron (May 6, 2014). "FireEye Buys nPulse Technologies For $60M+ To Beef Up Network Security Suite". TechCrunch. Retrieved September 18, 2018.
  22. ^ a b Weise, Elizabeth (May 20, 2015). "FireEye has become go-to company for breaches". USA TODAY. Retrieved September 18, 2018.
  23. ^ Finkle, Jim (January 20, 2016). "FireEye buys cyber intelligence firm iSight Partners for $200 million". U.S. Retrieved September 22, 2018.
  24. ^ Hackett, Robert (January 20, 2016). "FireEye Makes a Big Acquisition". Fortune. Retrieved September 22, 2018.
  25. ^ Kuchler, Hannah (January 20, 2016). "FireEye bulks up for 'cyber arms race'". Financial Times. Retrieved September 22, 2018.
  26. ^ Morgan, Steve (February 2, 2016). "FireEye acquires Invotas; Who's next?". CSO Online. Retrieved September 22, 2018.
  27. ^ Beckerman, Josh (February 2, 2016). "FireEye Buys Invotas International". WSJ. Retrieved September 22, 2018.
  28. ^ Wieczner, Jen (August 5, 2016). "What FireEye's Stock Crash Says About Hacking". Fortune. Retrieved September 22, 2018.
  29. ^ Owens, Jeremy C. (August 4, 2016). "FireEye plans layoffs as new CEO takes the helm, stock plunges". MarketWatch. Retrieved September 22, 2018.
  30. ^ Sharma, Vibhuti (October 30, 2018). "FireEye earnings boosted by lower costs, higher subscriptions". Reuters. Retrieved November 15, 2018.
  31. ^ Perlroth, Nicole; Sanger, David E. (2014-01-02). "FireEye Computer Security Firm Acquires Mandiant". The New York Times.
  32. ^ Miller, Ron (May 8, 2014). "FireEye Buys nPulse Technologies For $60M+ To Beef Up Network Security Suite". TechCrunch.
  33. ^ http://investors.fireeye.com/releasedetail.cfm?ReleaseID=951017
  34. ^ http://investors.fireeye.com/releasedetail.cfm?releaseid=952747
  35. ^ "The Future is Bright for FireEye Email Security « The Future is Bright for FireEye Email Security". FireEye. Retrieved 2018-07-12.
  36. ^ https://www.fireeye.com/company/press-releases/2017/FireEye_Announces_Acquisition_of_X15_Software.html
  37. ^ a b Oltsik, Jon (October 15, 2015). "FireEye Myth and Reality". CSO Online. Retrieved September 18, 2018.
  38. ^ "Cybersecurity Firm FireEye's Revenue Beats Street". Fortune. July 1, 2017. Retrieved September 22, 2018.
  39. ^ Casaretto, John (February 14, 2014). "FireEye launches a new platform and details Mandiant integration". SiliconANGLE. Retrieved September 22, 2018.
  40. ^ Kuranda, Sarah (November 30, 2016). "FireEye Brings Together Security Portfolio Under New Helix Platform". CRN. Retrieved September 22, 2018.
  41. ^ "FireEye Forecasts Downbeat Results for Current Quarter; Shares Tumble (NASDAQ:FEYE) - Sonoran Weekly Review". Sonoran Weekly Review. 2016-05-06. Retrieved 2016-05-06.
  42. ^ Cheng, Jacqui (November 11, 2009). "Researchers' well-aimed stone takes down Goliath botnet". Ars Technica. Retrieved 2009-11-30.
  43. ^ Wingfield, Nick (2011-03-18). "Spam Network Shut Down". Wall Street Journal. Retrieved 2011-03-18.
  44. ^ "FireEye Blog | Threat Research, Analysis, and Mitigation". Blog.fireeye.com. Archived from the original on 2013-01-31. Retrieved 2014-04-12.
  45. ^ Sanger, David E.; Barboza, David; Perlroth, Nicole (February 18, 2013). "China's Army Is Seen as Tied to Hacking Against U.S." The New York Times. Retrieved October 15, 2018.
  46. ^ "Microsoft Security Bulletin Summary for October 2014". Microsoft. Retrieved 21 June 2017.
  47. ^ Sullivan, Gail (2 December 2014). "Report: 'FIN4' hackers are gaming markets by stealing insider info". Washington Post. Retrieved 21 June 2017.
  48. ^ Fox-Brewster, Tom (29 October 2014). "'State sponsored' Russian hacker group linked to cyber attacks on neighbours". The Guardian.
  49. ^ Leyden, John (15 September 2015). "Compromised Cisco routers spotted bimbling about in the wild". The Register. Retrieved 21 June 2017.
  50. ^ Goodin, Dan (September 11, 2015). "Security company litigates to bar disclosure related to its own flaws". Retrieved September 12, 2015.
  51. ^ "Acknowledgments – 2015". Microsoft. Retrieved 21 June 2017.
  52. ^ "Security updates available for Adobe Flash Player". Adobe. Retrieved 21 June 2017.
  53. ^ Korolov, Maria (29 September 2016). "Diversified supply chain helps 'Vendetta Brothers' succeed in criminal business". CSO. Retrieved 21 June 2017.
  54. ^ Hackett, Robert (25 June 2016). "China's Cyber Spying on the U.S. Has Drastically Changed". Fortune. Retrieved 21 June 2017.
  55. ^ Cox, Joseph (2 June 2016). "There's a Stuxnet Copycat, and We Have No Idea Where It Came From". Motherboard. Retrieved 21 June 2017.
  56. ^ "Security updates available for Adobe Flash Player". Adobe. Retrieved 21 June 2017.
  57. ^ Goodin, Dan (5 May 2016). "Critical Qualcomm security bug leaves many phones open to attack". Ars Technica. Retrieved 21 June 2017.
  58. ^ Taylor, Harriet (20 April 2016). "What one criminal gang does with stolen credit cards". CNBC. Retrieved 21 June 2017.
  59. ^ http://fortune.com/2016/11/02/donald-trump-alfa-bank/
  60. ^ https://www.bloomberg.com/news/features/2017-09-29/the-equifax-hack-has-all-the-hallmarks-of-state-sponsored-pros
  61. ^ "CVE-2017-0199 Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API". Microsoft. Retrieved 21 June 2017.
  62. ^ Conger, Kate; Frenkel, Sheera (August 23, 2018). "How FireEye Helped Facebook Spot a Disinformation Campaign". The New York Times. Retrieved September 22, 2018.

External links[edit]