Monday February 06 , 2012
Text Size
   

Advanced Management Threat Solution


The Challenge

We all can read the headlines – organizations are being hit every day and we are in the middle of an ongoing cyber war.

The external threats are clear and present:

  • State-sponsored intrusions and data exfiltrations
  • Non-state actors and terrorist groups
  • Well-funded and highly-sophisticated organized crime and espionage rings

There are serious problems inside our organizations too:

  • Disgruntled employees
  • Criminals
  • Misconfiguration of systems and networks
  • User errors and lack of security awareness
  • Volumes of regulatory challenges

The Historical Response

Typical security investments to date have focused on creating islands or layers of protection by installing point solutions that detect a specific problem, issue or threat. Your adversaries don’t think about security as a set of “issues” for which there are multiple answers – they think about how to use the network to get to your data. An effective approach requires organizations to stop deploying point solutions that create protection gaps and overlaps, and start thinking about security as a single requirement.

 

The Solution

Similar to real world adversaries, Quantiq and NetWitness NextGen views security problems as interrelated and multidimensional, and takes a “record once, reuse many times” approach to network monitoring by solving disparate business problems using a singular enterprise infrastructure and extensible application framework. With ten years of development invested in the core, patented technology and proven experience with some of the most demanding government and private sector clients, NetWitness NextGen offers a powerful application framework and a distributed infrastructure that scales to meet any requirement.

Let us show you how NetWitness NextGen provides solutions for specific industry problems and for specific challenges. Also, please take the time to learn more about NextGen’s powerful distributed data capture infrastructure and extensible investigative application framework, including NetWitness® Live, our online threat intelligence service.

 

The Benefit
  • No Host-Agents Required
  • Solutions are offered as software and hardware
  • First and only available IPv6 session analysis product
  • FIPS 140 compliant communications infrastructure
  • Low-cost, scalable SAS storage - SAN supported
  • Supports live packet capture and packet file import
  • Provides full application layer analysis and content search
  • Available API/SDK
  • FlexParse™ enabled for total control of processing and analysis
  • Supports threat intelligence feeds from third parties
  • Provides protocol and application exploitation of: HTTP, FTP, TFTP, TELNET, SMTP, POP3, NNTP, DNS, HTTPS, SSL, SOCKS, SSH, Vcard, PGP, SMIME, REGEX, DHCP, NETBIOS, SMB/CIFS, SNMP, NFS, RIP, MSRPC, Lotus Notes®, TDS(MSSQL), TNS(Oracle®), IRC, Lotus Sametime®, MSN IM, RTP, Gnutella, Yahoo Messenger, AIM, SIP, H.323, Net2Phone®,Yahoo Chat, SCCP (Cisco® Skinny), Bittorrent, GTALK, Hotmail, Yahoo Mail, GMail, TOR Social Networking, Fast Flux and others.