Stonesoft Corporation

Last updated
Stonesoft Corporation
Company type Division
Industry Network Security
Founded Helsinki, Finland (1990 (1990)) [1]
FounderIlkka Hiidenheimo
Hannu Turunen
FateAcquired by McAfee (2013)
Headquarters,
Finland
Area served
Worldwide
Key people
Ilkka Hiidenheimo
(Chairman & CEO)
Juha Kivikoski
(COO)
Mikael Nyberg
(CFO) [2]
Jarno Limnéll
(Cyber Security Director [1] )
Products Network security
Firewall
IPS
VPN
Security appliances
Virtual appliances
Number of employees
222 (Dec 2011) [3]
Parent Forcepoint
Website stonesoft.com

Stonesoft Corporation was a public company that developed and sold network security solutions based in Helsinki, Finland. It was publicly owned until 2013 when it was acquired by Intel's subsidiary McAfee. [4]

Contents

Stonesoft conducted business globally, with a regional headquarters in Atlanta, Georgia, United States, and sales offices throughout Europe, the Middle East, and China.

In July 2013, McAfee, a part of Intel Security, completed a tender offer to acquire all Stonesoft products and technologies. Stonesoft became a part of the McAfee Network Security Business Unit. Stonesoft firewall products were renamed McAfee Next Generation Firewall. McAfee sold Stonesoft to Forcepoint in January 2016. [5]

History

Founded in 1990, [1] Stonesoft started as a systems integrator in the Nordic regions of Europe. In 1994 it introduced StoneBeat, a technology for creating a high availability pair of firewalls in an active-passive configuration. In 1999, the company extended StoneBeat with a patented load balancing clustering technology, [6] launching StoneBeat FullCluster. It was one of the first technologies certified in Check Point's OPSEC program. [7]

In 2001, Stonesoft expanded its product set into the firewall/VPN space, becoming a direct competitor to Check Point. The StoneGate Firewall/VPN was launched on March 19, 2001. In January 2003, the company introduced the first virtual firewall/VPN solution, for IBM mainframes. [8]

In 2010, the company released information via CERT-FI [9] on Advanced Evasion technique (AETs) that met with skepticism in the community. Further AETs were released in 2011, and eventually verified by independent labs and researchers. [10] [11] [12]

In 2012 "Stonesoft" replaced the "StoneGate" product name. From now on, Stonesoft is used both as the company and product name. [13]

Products

Its product portfolio includes firewall/VPN devices, IPS (intrusion detection and prevention systems), and SSL VPN systems, [14] each available as hardware appliances, software, and VMware-certified virtual appliances. [15]

Each of the components, as well as third-party devices, can be managed from the Stonesoft Management Center. [16] The product portfolio differentiates through unique clustering and load balancing technologies based on the company's older StoneBeat technology, originally developed for Check Point FireWall-1.

Stonesoft's current product portfolio can be divided into five major categories: [14]

Controversy

In 2008, the Helsinki Court of Appeal issued a decision in a case brought against Stonesoft and several members of its management team. The court "held that two members of the company's board of directors and a former CEO through gross negligence had failed to give a profit warning in due time". [17] The issue at hand was discrepancies between the profitability forecasted in the company's year 2000 interim reports and the actual state of the company at that time. The reports indicated the company was sound and profitable, yet "a profit warning should in fact have been issued". [17] The District Court of Helsinki had originally dismissed the claims in a decision on November 15, 2006. [18]

Advanced Evasion Techniques

In 2010 Stonesoft informed the public about a new evasion technique that can bypass security defences. Stonesoft defines the Advanced Evasion Techniques (AETs) as "virtually limitless in quantity and unrecognizable by conventional detection methods. They can work on all levels of the TCP/IP stack and work across many protocols or protocol combinations." [12]

According to Max Nyman, Stonesoft Corporation's Senior Marketing Manager, AETs can deliver malicious code without detection and without leaving trace. [19]

On July 23, 2012 Stonesoft released a free tool that enables organisations to test their network security. [20]

Related Research Articles

<span class="mw-page-title-main">McAfee</span> American global computer security software company

McAfee Corp., formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American global computer security software company headquartered in San Jose, California.

SonicWall is an American cybersecurity company that sells a range of Internet appliances primarily directed at content control and network security. These include devices providing services for network firewalls, unified threat management (UTM), virtual private networks (VPNs), virtual firewalls, SD-WAN, cloud security and anti-spam for email. The company also markets information subscription services related to its products. The company also assists in solving problems surrounding compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Payment Card Industry Data Security Standard (PCI-DSS).

Cisco PIX was a popular IP firewall and network address translation (NAT) appliance. It was one of the first products in this market segment.

Smoothwall is a Linux distribution designed to be used as an open source firewall. Smoothwall is configured via a web-based GUI and requires little or no knowledge of Linux to install or use.

<span class="mw-page-title-main">LogMeIn Hamachi</span> Virtual private network application

LogMeIn Hamachi is a virtual private network (VPN) application developed and released in 2004 by Alex Pankratov. It is capable of establishing direct links between computers that are behind network address translation (NAT) firewalls without requiring reconfiguration. Like other VPNs, it establishes a connection over the Internet that emulates the connection that would exist if the computers were connected over a local area network (LAN).

Fortinet, Inc. is a cybersecurity company with headquarters in Sunnyvale, California. The company develops and sells security solutions like firewalls, endpoint security and intrusion detection systems. Fortinet has offices located all over the world.

<span class="mw-page-title-main">Check Point</span> Israeli security company

Check Point Software Technologies Ltd. is an American-Israeli multinational provider of software and combined hardware and software products for IT security, including network security, endpoint security, cloud security, mobile security, data security and security management.

Trusted Information Systems, Inc. (TIS), was a computer security research and development company during the 1980s and 1990s, performing computer and communications (information) security research for organizations such as NSA, DARPA, ARL, AFRL, SPAWAR, and others.

VPN-1 is a firewall and VPN product developed by Check Point Software Technologies Ltd.

<span class="mw-page-title-main">Ivanti</span> American IT software company

Ivanti is an IT software company headquartered in South Jordan, Utah, United States. It produces software for IT Security, IT Service Management, IT Asset Management, Unified Endpoint Management, Identity Management and supply chain management. It was formed in January 2017 with the merger of LANDESK and HEAT Software, and later acquired Cherwell Software. The company became more widely known after several major security incidents related to the VPN hardware it sells.

<span class="mw-page-title-main">McAfee VirusScan</span> Antivirus software

McAfee VirusScan is an antivirus software created and maintained by McAfee. Originally marketed as a standalone product, it has been bundled with McAfee LiveSafe, McAfee AntiVirus Plus, McAfee Total Protection and McAfee Gamer Security since 2010. McAfee LiveSafe is antivirus protection that defends against viruses, online threats, and ransomware with online and offline protection integrates antivirus, firewall and anti-spyware/anti-ransomware capabilities.
In 2006, British telecom company BSkyB started offering Sky Broadband customers a branded version of VirusScan for free upon broadband modem installation.

Vyatta is a software-based virtual router, virtual firewall and VPN product for Internet Protocol networks. A free download of Vyatta has been available since March 2006. The system is a specialized Debian-based Linux distribution with networking applications such as Quagga, OpenVPN, and many others. A standardized management console, similar to Juniper JUNOS or Cisco IOS, in addition to a web-based GUI and traditional Linux system commands, provides configuration of the system and applications. In recent versions of Vyatta, web-based management interface is supplied only in the subscription edition. However, all functionality is available through KVM, serial console or SSH/telnet protocols. The software runs on standard x86-64 servers.

Secure Computing Corporation (SCC) was a public company that developed and sold computer security appliances and hosted services to protect users and data. McAfee acquired the company in 2008.

<span class="mw-page-title-main">TriGeo Network Security</span>

TriGeo Network Security is a United States–based provider of security information and event management (SIEM) technology. The company helps mid market organizations proactively, protects networks and data from internal and external threats, with a SIEM appliance that provides real-time log management and automated network defense - from the perimeter to the endpoint.

<span class="mw-page-title-main">NetScreen Technologies</span> American technology company that was acquired by Juniper Networks

NetScreen Technologies was an American technology company that was acquired by Juniper Networks for US$4 billion stock for stock in 2004.

<span class="mw-page-title-main">Cyberoam</span> Computer security company

Cyberoam Technologies, a Sophos subsidiary, is a global network security appliances provider, with presence in more than 125 countries.

The following outline is provided as an overview of and topical guide to computer security:

Forcepoint is an American multinational corporation software company headquartered in Austin, Texas, that develops computer security software and data protection, cloud access security broker, firewall and cross-domain solutions.

<span class="mw-page-title-main">RTX Corporation</span> American multinational aerospace and defense conglomerate

RTX Corporation, formerly Raytheon Technologies Corporation, is an American multinational aerospace and defense conglomerate headquartered in Arlington, Virginia. It is one of the largest aerospace and defense manufacturers in the world by revenue and market capitalization, as well as one of the largest providers of intelligence services. In 2023, the company's seat in Forbes Global 2000 was 79. RTX manufactures aircraft engines, avionics, aerostructures, cybersecurity solutions, guided missiles, air defense systems, satellites, and drones. The company is also a large military contractor, getting a significant portion of its revenue from the U.S. government.

References

  1. 1 2 3 "Stonesoft appoints Jarno Limnéll as Director, Cyber Security". Reuters.com. 24 May 2012. Archived from the original on 27 May 2012. Retrieved 29 January 2018.
  2. "McAfee Next Generation Firewall and McAfee Firewall Enterprise - Intel Security". Stonesoft.com. Retrieved 29 January 2018.
  3. "Annual Report 2011" (PDF). Stonesoft.com. Archived from the original on 25 April 2012. Retrieved 29 January 2018.{{cite web}}: CS1 maint: bot: original URL status unknown (link)
  4. "Press Releases". Stonesoft.com. Retrieved 29 January 2018.
  5. "Acquisition of Stonesoft (McAfee Next Generation Firewall) and Sidewinder (McAfee Firewall Enterprise) - Forcepoint". blogs.forcepoint.com. Retrieved 29 January 2018.
  6. "United States Patent: 6856621 - Method of transmission of data in cluster environment". Patft.uspto.gov. Retrieved 29 January 2018.
  7. "Technology Partners". Check Point Software. Archived from the original on 4 March 2012. Retrieved 29 January 2018.
  8. "Error". 3 April 2011. Archived from the original on 3 April 2011. Retrieved 29 January 2018.[ dead link ]
  9. Viestintävirasto. "Viestintävirasto -". www.cert.fi. Retrieved 29 January 2018.
  10. "The BIG Question". Isaca.org. Archived from the original on 29 January 2018. Retrieved 29 January 2018.
  11. "Maybe the initial discoveries were just the tip of an iceberg". Icsalabs.com. Archived from the original on 29 January 2018. Retrieved 29 January 2018.
  12. 1 2 "Should you panic? An Advanced Evasion Techniques overview". Thetechherald.com. 17 February 2015. Archived from the original on 29 January 2018. Retrieved 29 January 2018.
  13. "Taloussanomat". Ilta-Sanomat (in Finnish). 2023-05-17. Retrieved 2023-05-17.
  14. 1 2 "McAfee Next Generation Firewall and McAfee Firewall Enterprise - Intel Security". Stonesoft.com. Retrieved 29 January 2018.
  15. "Virtual Appliances - Solution Exchange". Vmware.com. Retrieved 29 January 2018.
  16. "McAfee Next Generation Firewall and McAfee Firewall Enterprise - Intel Security". Stonesoft.com. Retrieved 29 January 2018.
  17. 1 2 "D&I Q4, 2008" (PDF). www.dittmar.fi. Archived from the original (PDF) on 20 July 2011. Retrieved 15 January 2022.
  18. "THE DECISION OF THE HELSINKI COURT OF APPEAL CONCERNING ALLEGED DELAY OF STONESOFT'S PROFIT WARNING IN FEBRUARY 2001". EuroInvestor.
  19. Eduard Kovacs (14 June 2012). "Softpedia Exclusive Interview: Max Nyman on Advanced Evasion Techniques". Softpedia.com.
  20. "Stonesoft Pen Testing Tool Uses Advanced Evasion Techniques, Firm Says". Securityweek.Com. 23 July 2012. Retrieved 29 January 2018.