Innovative, High-Density, Massively Scalable Packet Capture and Cyber Analytics Cluster for Enterprise Customers The Enterprise Packet Capture Cluster Platform is a complete solution based on a unique capture and storage architecture. The system is managed by a Dell-based, 2U rackmount system which offers high-speed packet recording with real-time analytics and visualization. Data is then distributed to a cluster of rackmount nodes with massive high-speed storage. This system is designed for applications that demand high-speed data recording and extensive storage, such as cyber forensics, cyber security, and big data analytics. The 2U Enterprise Packet Capture Cluster Platform has a variety of powerful features: Lossless Packet Capture Forensic, retrospective functionality of lossless packet capture from 1Gbps to 10Gbps Time stamping of 150 nanoseconds Metadata Indexing and Logging System 5-tuple indexing IP address source/destination, port source/destination, protocol (IP, UDP, ICMP) Indexing of MAC source/destination IPFix record generation NetFlow recording RFC anomaly logging File exfiltration and infiltration hash logging Session and connection logging http, ftp, grid ftp logging UID event correlation RESTful search query access using easy BPF+ metadata descriptors Page 1 of 5 Lossless packet capture to 10Gb/s 5-Tuple indexing Simultaneous search IPFix record generation RFC anomaly logging File download hash logging Session logging http, ftp, grid ftp logging
(features continued) Lightweight, MapReduce Architecture Scalable to 16 nodes, including storage nodes Packet processing is distributed to cluster nodes Dynamic node management Data Storage and Forensic Timeline Features From a minimum of 80TB storage per cluster node, compression / amplification could extend to 1.6PB Overall storage amplification up to 16x (depending on percentage of traffic with SSL encrypted or compressed packet payloads) Forensic timeline that is scalable, distributed, and searchable over days, weeks, months even years! Queries respond with stream-based extracted packets, so analysis can occur in parallel with data retrieval Massive queries over large timelines respond quickly, even as the timeline increases Federated search both within a cluster, and across multiple clusters Web GUI and RESTFul Interface Log and metadata information visualization, search, and packet viewing MapReduce support of multiple clusters Node management Remote access, automation, and control through your analytics application and framework To learn more about the Enterprise Packet Capture Cluster Platform and other packet capture solutions, visit us at alliance-it.com. To discuss solutions for your specific needs, please give us a call at (410) 712-0270. 2U master node and packet processing cluster node(s) Scalable to 16 nodes Scalable to petabytes of packet store Lightweight MapReduce architecture Real-time analytics for any volume Fast, scalable, distributed search and extract, even as timelines increase Federation of multiple clusters Page 2 of 5
SYSTEM SPECS Packet Capture Interfaces and Capture Rate (With Simultaneous Search / Extract) Timestamping Total Timline Capture Total Indexing and Meta Data Total Extraction Data API/REST and Web GUI Control Node Physical 4 x 1G ports (up to 4Gbps line rate lossless capture with no cluster nodes) 2 x10g ports (up to 5 Gbps aggregate lossless capture rate with no cluster nodes) With 2 cluster nodes or more, 10Gbps aggregate rate. Additional cluster nodes increases the forensics timeline 150 nanoseconds Up to 80TB (RAID 5) before in-line compression/amplification up to 1.6PB Up to 5.7TB (RAID 1) or 3.4TB (RAID 5) Up to 5.7TB (RAID 1) RJ-45 1G LAN port H: 8.73 cm (3.44 in.) x W: 44.40 cm (17.49 in.) x D: 68.40 cm (26.92 in.) 7010 Hi Tech Drive, Hanover, MD 21076 Phone: 1 (410) 712-0270 www.alliance-it.com This document is for informational purposes only. Updates and changes can occur without notice. All logos, trademarks, and service marks are the property of their respective owners. Page 3 of 5
CAPTURE, INDEXING, AND SEARCH EXTRACTION Page 4 of 5
CAPTURE, INDEXING, AND DISTRIBUTED SEARCH EXTRACTION Page 5 of 5