plixer Scrutinizer Competitor Worksheet Visualization of Network Health Unauthorized application deployments Detect DNS communication tunnels



Similar documents
Take the NetFlow Challenge!

Scrutinizer. Application traffic analytics, visualization and reporting tool

NetFlow The De Facto Standard for Traffic Analytics

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

Contents. System Requirements. Enhancements in SonicWALL Scrutinizer Scrutinizer

Flow Analysis Versus Packet Analysis. What Should You Choose?

Cisco IOS Flexible NetFlow Technology

HP Intelligent Management Center v7.1 Network Traffic Analyzer Administrator Guide

Introduction to Network Discovery and Identity

INCREASE NETWORK VISIBILITY AND REDUCE SECURITY THREATS WITH IMC FLOW ANALYSIS TOOLS

Plugging Network Security Holes using NetFlow. Loopholes in todays network security solutions and how NetFlow can help

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

Network as a Sensor and Enforcer Leverage the Network to Protect Against and Mitigate Threats

NetFlow-Lite offers network administrators and engineers the following capabilities:

HUNTING ATTACKERS WITH NETWORK AUDIT TRAILS

SolarWinds. NetFlow Traffic Analyzer. Evaluation Guide. Version 4.2

ICND2 NetFlow. Question 1. What are the benefit of using Netflow? (Choose three) A. Network, Application & User Monitoring. B.

Dell SonicWALL report portfolio

Apple Airport Extreme Base Station V4.0.8 Firmware: Version 5.4

Network as an Sensor & Enforcer

Cisco EXAM Enterprise Network Unified Access Essentials. Buy Full Product.

CTS2134 Introduction to Networking. Module Network Security

Scalable Extraction, Aggregation, and Response to Network Intelligence

NetFlow Tracker Overview. Mike McGrath x ccie CTO mike@crannog-software.com

Cisco NetFlow Generation Appliance (NGA) 3140

Flow Based Traffic Analysis

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release

Monitoring and analyzing audio, video, and multimedia traffic on the network

HUNTING ATTACKERS WITH NETWORK AUDIT TRAILS

Network Monitoring Comparison

Understanding Flow and Packet Deduplication

Network traffic monitoring and management. Sonia Panchen 11 th November 2010

Gaining Operational Efficiencies with the Enterasys S-Series

CHAPTER 1 WhatsUp Flow Monitor Overview. CHAPTER 2 Configuring WhatsUp Flow Monitor. CHAPTER 3 Navigating WhatsUp Flow Monitor

Network congestion control using NetFlow

NetFlow Analytics for Splunk

NetStream (Integrated) Technology White Paper HUAWEI TECHNOLOGIES CO., LTD. Issue 01. Date

Securing and Monitoring BYOD Networks using NetFlow

Implementing Cisco IOS Network Security

Secure Networks for Process Control

Overview of Network Traffic Analysis

F5 Silverline DDoS Protection Onboarding: Technical Note

Redefine Network Visibility in the Data Center with the Cisco NetFlow Generation Appliance

WhatsUpGold. v NetFlow Monitor User Guide

Passguide q

NetFlow Tips and Tricks

SonicOS 5.8: NetFlow Reporting

Hosting more than one FortiOS instance on. VLANs. 1. Network topology

11.1. Performance Monitoring

HP IMC User Behavior Auditor

and reporting Slavko Gajin

Network Management Deployment Guide

Interconnecting Cisco Networking Devices: Accelerated (CCNAX) 2.0(80 Hs) 1-Interconnecting Cisco Networking Devices Part 1 (40 Hs)

Flow Analysis. Make A Right Policy for Your Network. GenieNRM

How To Set Up Foglight Nms For A Proof Of Concept

A host-based firewall can be used in addition to a network-based firewall to provide multiple layers of protection.

Network Monitoring and Management NetFlow Overview

Introduction to Netflow

Using IEEE 802.1x to Enhance Network Security

Beyond Monitoring Root-Cause Analysis

Using IPM to Measure Network Performance

IBM Security QRadar SIEM Version (MR1) Tuning Guide

Dell SonicWALL Scrutinizer 15.5

Network Performance Monitoring at Minimal Capex

Running custom scripts which allow you to remotely and securely run a script you wrote on Windows, Mac, Linux, and Unix devices.

Configuring Personal Firewalls and Understanding IDS. Securing Networks Chapter 3 Part 2 of 4 CA M S Mehta, FCA

Course Overview: Learn the essential skills needed to set up, configure, support, and troubleshoot your TCP/IP-based network.

Cheap and efficient anti-ddos solution

Savvius Insight Initial Configuration

Cisco Wireless Control System (WCS)

Visualization, Management, and Control for Cisco IWAN

ANNEXURE TO TENDER NO. MRPU/IGCAR/COMP/5239

Wireshark Developer and User Conference

Recommended IP Telephony Architecture

Apache CloudStack 4.x (incubating) Network Setup: excerpt from Installation Guide. Revised February 28, :32 pm Pacific

Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

Course Contents CCNP (CISco certified network professional)

MSP. HOW MSPs Can Use Performance Monitoring to Create New Revenue Streams. [ WhitePaper ] Introduction

LiveAction: GUI-Based Management and Visualization for Cisco Intelligent WAN

Networked AV Systems Pretest

F5 BIG DDoS Umbrella. Configuration Guide

Procedure: You can find the problem sheet on Drive D: of the lab PCs. 1. IP address for this host computer 2. Subnet mask 3. Default gateway address

WhatsUp Gold vs. Orion

Configuring Network Address Translation (NAT)

Network Monitoring and Traffic CSTNET, CNIC

Securing Networks with Cisco Routers and Switches ( )

Case Study: Instrumenting a Network for NetFlow Security Visualization Tools

CISCO WIRELESS CONTROL SYSTEM (WCS)

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Network Management & Monitoring

SolarWinds Log & Event Manager

Overview of NetFlow NetFlow and ITSG-33 Existing Monitoring Tools Network Monitoring and Visibility Challenges Technology of the future Q&A

Extending Network Visibility by Leveraging NetFlow and sflow Technologies

How To Manage Sourcefire From A Command Console

Introduction to Cisco IOS Flexible NetFlow

Securing end devices

Network Agent Quick Start

mbits Network Operations Centrec

ALCATEL-LUCENT VITALSUITE Application & Network Performance Management Software

Transcription:

Scrutinizer Competitor Worksheet Scrutinizer Malware Incident Response Scrutinizer is a massively scalable, distributed flow collection system that provides a single interface for all traffic related to a potential threat. Even if the flows are being sent to different collectors, Scrutinizer will stitch the flows into a single report. Relying on only NetFlow, IPFIX, and even sflow, Scrutinizer can also be used to baseline and monitor for definable unwanted behaviors. Unauthorized application deployments Detect DNS communication tunnels Custom Report Filtering Custom reports allow the user to configure detailed reports by filtering on fields such as: IP Addresses, ranges, and subnets Port numbers and ranges Defined Applications, which include ranges of protocols Combine interfaces from multiple routers Any NetFlow or IPFIX exported field (e.g. HTTP Host, URL, packet loss, retransmits, etc.) VoIP Analysis Voice over IP (VoIP) Analysis is assisted in Scrutinizer by verifying: How much voice traffic is historically on the connection What devices are involved with the most VoIP traffic What QoS is being requested That the router is modifying DSCP values Visualization of Network Health Network Behavior Analysis Scrutinizer uses configurable algorithms to automatically alert you when trouble is recognized. Network Scans and DoS attacks Policy violations and internal misuse Poorly configured and unathorized devices Visualize Global Networks with Google Maps Scrutinizer offers advanced integration with the Google Maps API, which allows users to plot routers, switches, and device groups on an embedded Google map. This helps make highlevel network navigation a snap and provides a window into your Scrutinizer details.

Expansive Vendor Support - Incredible Value Scrutinizer supports all flow exports from all vendors adhering to Cisco NetFlow specifications or the IPFIX standard. As a result, it greatly enhances the reporting insight and quickens malware incident response efforts. Incident Response and Application Performance Because Scrutinizer aids in both Incident Response and Application Performance, it allows Security and IT professionals a way to double the value of the flows being received by all the collectors.

Work Sheet Take a few moments and fill out the following Competitor Work Sheet. NetFlow, sflow & IPFIX Flow View to see all fields in the raw flows Support for unlimited exporters and interfaces Support for Distributed Collectors Identify interface names using NetFlow or SNMP Support for multiple languages Define application groups using ranges of ports and IP addresses Display data in bits, bytes, backets, or percent Trend in, out, or both at the same time, in all reports Configurable time frame for DNS caching 100% support for Flexible NetFlow by breaking out details per template Support for Netstream, sflow (v2, v4, v5), J-Flow, IPFIX and AppFlow Support for NetFlow v1, v5, v6, v7, and v9 Run reports to find rogue DNS, DHCP, mail, etc., servers on the network Export data in csv format on all reports Granularity down to the second it was received Schedule email reports on demand Save filters on custom reports

NetFlow, sflow & IPFIX Include or exclude filters Filter for Host to Host and Subnet to Subnet Filter on any TCP flags Filter on any field exported (e.g. MAC address, VLAN, latency, etc.) Ability to add multiple interfaces across different routers to single report Run reports specific to an interface. IMPORTANT: As a host may have multiple routes to the same destination Trends Flow Sequence Number and detects dropped flaws Tells what devices are misconfigured when sending flows Support for IPv6 Mapping of network with links that change color based on utilization Ability to click on the links in the map to bring up the top conversations Integration with Google Maps Customize interface names and overwrite default SNMP if Alias name Customize interface speed, both in and out, with different values SNMP v1, v2, and v3 LDAP support Integration with any 3rd-party NMS solutions via cross-check Search for specific hosts or ports across all flow exporters and collectors

NetFlow, sflow & IPFIX MPLS reporting on subnets and tags Online technical video training Company has thousands of customers Dashboards: unique interface per login account Group-based user permissions IP grouping support Exclude transport protocols from being saved per interface, router, or globally (very important feature when VPNs and tunnels are involved). Ability to view individual Flow templates (NetFlow v9 and Flexible NetFlow) Ability to rename templates for future reference Ability to select which NetFlow templates to use in a report (important when collecting NetFlow from the Cisco ASA) Flow Volume Report Pair Volume (Volume of unique to/from address pairs Alarm for DDoS, DNS issues Host Flows (volume of flows per host) with unique destination: Flows Ratio Host Volume (volume of unique hosts per second) Top Subnets Top Domains Top Countries

NetFlow, sflow & IPFIX Report and trend on Microsoft Exchange logs Detect network scans (e.g. SYN, RST/ACK, XMAS, FIN, etc.) Alarm on saved filters (e.g. total traffic or per row) Constant automated DNS resolution for Flows received Alarming for high interface utilization Alarms for excessive traffic from a single host or application Top flow senders, application, etc. across hundreds of routers/ switches, while deduplicating flows Specify allowed subnets and alarm for rogue IP addresses Unique index per alarm (tells how many other alarms the host has violated) Alarm: Identify internal hosts communicating with known compromised internet sites. (Online IP reputation database) Alarm for BitTorrent, YouTube, Facebook, etc. use Support for NBAR via NetFlow (i.e. not SNMP) Mitigate issues by turning ports off on switches or making ACL changes Saves all the records, all the flows, all the time for as long as necessary (i.e. decades) Flow View Only Limited to 5 hours Set permissions per interface* Set permissions per router* Flow Expert in dashboard for advanced, proactive awareness of anomalies UltraSurf detection

NetFlow, sflow & IPFIX Dynamic advanced filtering options based on any flow template Flow Hopper shows the hop-by-hop path a flow takes through the network Advanced Reporting on Citrix NetScaler for AppFlow (URLs, latency, etc.) Support for Cisco ASA NSEL Performance Routing (PfR), Performance Monitoring, Smart Logging Telemetry (SLT), Cisco TrustSec, AVT Performance Agent and others 3rd-party integration with cross-platform fault index Latency and round trip time for all devices on the network Set interface speed per report Search IP addresses or ports across devices to track where it was seen The dynamic creation of reports based on any exported data (i.e. Element) Company acquired millions in Venture Capital Requires expensive Microsoft Database Support for Cisco ISE, Microsoft AD, Radies, etc. to correlate IP Addresses to Usernames *Requires Service Provider Module