NitroSecurity / 2011   500+ customersMcAfee acquisitionNitroView   logs + context + riskPortsmouth, New HampshireNitroSecurity / 2011   500+ customersMcAfee acquisitionNitroView   logs + context + riskPortsmouth, New Hampshire

Company / Cybersecurity / The archive

NitroSecurity Taught the Alarm to Ask Why

The Portsmouth company turned security logs into a live ranking of danger. McAfee bought it in 2011 after three years as a partner - and after trying the technology on its own network.

A security alarm is a peculiar invention: the better it works, the more often it asks to be ignored. By 2011, companies could collect floods of messages from firewalls, servers, applications and intrusion detectors. The hard part was deciding whether a strange login was a minor nuisance or the beginning of a very expensive afternoon. NitroSecurity built its business in that gap. Its NitroView system gathered events, searched them quickly and tried to tell security teams what mattered first.

In one minute
  • NitroSecurity made SIEM, log management and intrusion prevention products for enterprise security teams.
  • It said it served more than 500 organizations by 2011, including Sonus Networks, Green Mountain Coffee Roasters and Credit Union 24.
  • A 2010 review listed NitroView ESM and ELM appliances starting at $39,995.
  • McAfee announced its acquisition in October 2011 and completed it that November.

The company’s roots were less glamorous than the phrase “security intelligence.” A 2005 presentation traced its technology to the Idaho National Engineering and Environmental Laboratory, where a fast embedded database had been built for the data demands of the nuclear power industry. That database, NitroEDB, was commercialized for equipment makers in 1999. NitroGuard, an intrusion prevention product, followed in 2001. The sales deck showed racks of hardware and a promise to watch traffic as it moved. It was a world of boxes, packets and signatures, not dashboards with reassuringly rounded corners.

Rack-mount security appliance pictured in a 2005 NitroSecurity product presentation
A security product with the personality of a filing cabinet. This rack-mount appliance appeared in a 2005 NitroGuard presentation; its job was to notice trouble before anyone noticed the box.

The problem with a thousand true alarms

Early security management systems were good at proving that something happened. They could preserve logs for auditors and show an analyst a list of events. But a list can be a very elegant way to avoid a decision. NitroSecurity’s pitch was that a suspicious event should arrive with context: which machine was involved, how valuable it was, what vulnerabilities it carried and what else had happened nearby. A security team could then spend its limited attention on a probable problem rather than on every blinking light.

NitroView Enterprise Security Manager, or ESM, was the analysis console. Enterprise Log Manager, or ELM, kept and retrieved the underlying records. Version 8.4, released in 2010, tied the two more closely so an analyst could move from a correlated event to the log entry behind it. This mattered for both incident response and compliance: a hospital or payment processor might need to respond to an attack today and explain the record months later. NitroGuard remained the intrusion prevention arm of the product family.

The NitroView idea
CollectFirewalls, systems, applications, identity records and network devices send events.
ConnectCorrelation adds asset value, vulnerabilities, identity and surrounding activity.
DecideAnalysts investigate a ranked risk and can trace it back to the logs.

The customer list helps explain the appeal. Sonus Networks chose NitroView’s SIEM and log management tools in 2011 to support real-time security and its Sarbanes-Oxley compliance work. NitroSecurity also named Green Mountain Coffee Roasters and Credit Union 24 among new enterprise accounts that year. It said its installed base topped 500 organizations across energy, healthcare, education, finance, government, retail, hospitality and managed services. These were very different businesses with a common problem: they owned more security data than any person could read.

500+Organizations claimed by NitroSecurity in 2011
$39,9952010 starting price for ESM + ELM appliances in an independent review
3 yearsMcAfee alliance before the acquisition

What the faster machine could not fix

NitroSecurity liked to talk about speed. Its 2011 ESM X3 appliance was advertised at twice the speed of the ESM 5000 series. The Receiver 4500 targeted the hundreds of thousands of devices found in public-sector and SCADA networks. Its NitroRSC engine scored risk using asset value, vulnerabilities and events. Later that year, the Advanced Correlation Engine, or ACE, put heavy analysis on a dedicated appliance so that replaying old data would not pause collection of new data. This was an architectural answer to a mundane truth: the network does not stop producing evidence while an analyst runs a difficult query.

But speed was only half the argument. An InfoWorld review of NitroView ESM and ELM praised flexible console views, graphs and adaptive baseline alerts. It also found weak auto-discovery, limited alert notification methods and a busy, complex interface. That is a useful corrective to the fantasy that a better algorithm makes an enterprise product effortless. A security team still had to deploy it, configure it and live in it. The review listed the two-appliance setup from $39,995; public evidence does not reveal what a particular customer finally paid.

“Customers are trying to manage too much data.”Dave Anderson, McAfee, 2011

Those limits mattered in a market crowded with choices. ArcSight, Q1 Labs, LogRhythm, Splunk, LogLogic and RSA all sold versions of the promise to make security data useful. NitroSecurity’s distinction was the combination of fast event storage, network visibility and risk context, including information from intrusion prevention and, later, applications and databases. It was a specialist with a credible claim on the moments when a security operations center had to ask, “What should we look at first?”

The buyer had already moved in

McAfee did not meet NitroSecurity at the negotiating table. The firms had worked together for three years through McAfee’s Security Innovation Alliance. NitroView exchanged information in both directions with McAfee’s ePolicy Orchestrator, or ePO. More strikingly, McAfee had run NitroSecurity’s technology internally as its own SIEM before announcing the deal. For an acquirer hoping to join security products into a single management story, this was unusually practical evidence: the plumbing existed, and the buyer had felt the product’s weight on its own floor.

The moment was favorable. On October 4, 2011, McAfee announced it would acquire NitroSecurity. IBM announced its Q1 Labs deal the same day. HP had bought ArcSight the year before. Large security vendors were deciding that event analysis belonged in the middle of their portfolios. McAfee had endpoint and network products, but it lacked a SIEM of its own. NitroSecurity had the missing console. The purchase price was not disclosed.

McAfee completed the acquisition in late November. NitroView became the foundation of McAfee Enterprise Security Manager, while the NitroSecurity team entered McAfee’s risk and compliance operation. An independent company’s name receded, but its central idea survived: a security event becomes more useful when the system can say what asset it touched, how vulnerable that asset is and what happened around it.

A lesson hidden in the wiring

There is a temptation to summarize NitroSecurity as a successful exit. The more portable lesson is smaller. The company solved a specific frustration, showed its work in the product and integrated with a larger buyer before asking that buyer to imagine a combined future. A team building enterprise software today can copy the sequence: start with an expensive daily decision, join the data required to make it, and prove the integration in an actual environment. That only works where customers can supply clean enough signals and staff who will act on the ranking. Otherwise a clever score is one more number on the wall.

NitroSecurity’s old appliances look severe now. The question they posed is still lively. When every machine can shout, who earns the right to interrupt a person?