Network Behavior Analysis

  • Network Security Monitoring and Network Behavior Analysis technologies are the state of art methods for detecting operational and security problems in computer networks of all sizes. Even Gartner says it is no longer possible to rely on five to ten years old solutions (firewall, IDS/IPS, antivirus,...).
  • Systems based on these technologies works on the principle of detection of network anomalies and an undesirable behaviour, which is based on the permanent evaluation of network traffic statistics (NetFlow records). The main advantage over standard IDS and SNMP monitoring systems lies in the orientation on the overall behaviour of devices in a network. This enables administrators to get a real insight into the network and react to yet unknown or specific threats.
  • For a simple explanation of NetFlow can be said that these data flows are similar to phone-call listings - NetFlow is defined as a sequence of packets with the following information: destination/source IP address, destination/source port number and protocol type.

NetFlow

  • The deployment of NSM/NBA solutions is non-invasive, which means zero interference to the current network topology. Thus there can not be any problems such as network latency, network outages, etc. The passive probe (e.g. FlowMon ADS or NetHound BOX) monitors the data flows on the perimeter or in a problematic network branch.
  • These systems can be easily deployed in 20 minutes.

Take a look on a short presentation about NetFlow technology

How can you start to generate NetFlow data?

Find out if you are able to generate NetFlow data in your network. Learn more about the options of how to get NetFlow from your network.

Selected references:

dm drogerie markt, s.r.o.

Show reference

JIC - South Moravian Innovation Centre

Show reference

see all references

About NBA technology

All the solutions of AdvaICT are based on the technology of Network Behavior Analysis. Read more about the uniqueness of this technology.

more about NBA technology

Top network users

Did you know that up to two thirds of the total traffic in your network is generated by only a few users? Thanks to behavior profiles you have a permanent overview of the top users and their activities in your network. Top statistics also help to detect infected devices or users of P2P networks.

News

May 14, 2012
Since May 2012 the customers of AdvaICT can upgrade to FlowMon ADS version 3 for automatic traffic analysis and anomaly detection...
May 11, 2012
Since April 2012 AdvaICT is Registered Developer by Cisco.      

References

Ing. Martin Poláček, director of ICT at AGROFERT HOLDING, a.s., evaluates the FlowMon ADS solution deployed based on his six months experience:

“We have implemented the FlowMon ADS solution to increase security on control of our IT infrastructure. Thanks to the network traffic monitoring we superintend utilization of our data center and companies connected to the Internet. In case of issues related to the network we are able to diagnose their causes efficiently. In addition FlowMon ADS continuously evaluates all the network traffic and points out potential security incidents.”