|
Network Security
Customer Pain Points
- IDS/IPS systems and other security solutions fail to provide network engineers with the details they need to locate and correct the source of an attack. Without detailed network analysis, security solutions are incomplete.
- Firewalls and other perimeter defenses do not provide enterprise networks with the protection they need from viruses, DoS attacks, and other forms of malware. Especially in the age of mobile users, laptops, and wireless networking, the danger facing networks comes from the inside.
- Security breaches such as data theft are usually perpetrated by insiders.
- Network engineers need a multi-layer network analysis solution for digging into the problems that other security systems identify.
Without Expert network analysis, your security toolkit is incomplete.
WildPackets Solutions
* AiroPeek NX (superseded by OmniPeek. Find out which OmniPeek is right for you.)
Customer Satisfaction
- Network engineers and security officers get real-time data and analysis of network activity. Vital information about top talkers, bandwidth usage, and protocol usage is invaluable when trying to troubleshoot a security attack.
- Network engineers and security officers benefit from 24 x 7 network monitoring and automatic notification of problems. WildPackets offers filters, alerts, and Expert analysis of problems such as worms, traffic anomalies, and malfunctioning hardware.
- Network engineers and security officers can troubleshoot security attacks remotely, from anywhere on the network.
- Through WildPackets network forensics, network engineers and security officers can capture and record traffic to spot intermittent problems, to diagnose problems that have occurred in the past, and to collect digital evidence for investigations of security breaches and compliance failures.
The Challenge: Ongoing Virus Infections from Inside the Company
A mid-sized company continued to suffer from virus outbreaks on the corporate network, despite their best efforts to quarantine mysterious emails and other traffic at the firewall. As it turned out, most of these outbreaks occurred when well-intentioned company employees infected their laptops at home, and then returned to the office.
The Solution: Virus Monitoring and Detection with OmniPeek Filters
WildPackets allows network administrators to monitor for specific virus fingerprints anywhere on the network, all day, and every day. WildPackets will then notify via email, SMTP, or custom method when a security breach has occurred. OmniPeek users can set corporate policy centrally and roll it out across a large, distributed network.
Moreover, WildPackets allows network engineers to trace the spread and source of each infection. Some new viruses may still get through, and the ability to stop the spread and identify the areas for clean up is important, too. Some parts of the network may not be infected and those users need not be taken off line as part of the remedy.
Benefits: Real-time Identification of Attacks and Their Sources
- End users get peace of mind that someone is watching ‘inside’ their network.
- Network Analysts are notified immediately and can react in real-time to security breaches as they occur.
- Security policy can be implemented from a single, central location and applied consistently across the entire network.
- When IDS/IPS and other security problems identify an attack or suspicious activity, network engineers can use OmniPeek to drill down to the packet level and identify the problem.
- When integrated with a system from WildPackets’ partner A10 Networks, OmniPeek reports up-to-the-moment authentication information about the users launching and suffering from attacks. For example, network engineers can immediately see that the source of a SYN flood is joe@bigcompany.com, rather than an anonymous IP address.
|